Unlocking method and related device
By establishing a short-range wireless communication connection and identity authentication between the terminal device and the smart lock, passive and contactless unlocking is achieved, solving the problem of poor user experience when users are unable to operate actively, and improving security and reliability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- HUAWEI TECH CO LTD
- Filing Date
- 2021-06-23
- Publication Date
- 2026-04-24
AI Technical Summary
When users find it inconvenient to perform explicit authentication, existing unlocking methods require users to take active steps, resulting in a poor user experience and security risks.
By establishing a short-range wireless communication connection between the terminal device and the smart lock, the terminal device performs identity authentication based on the collected authentication information, and notifies the smart lock to unlock after successful authentication, thus achieving passive and contactless unlocking.
It simplifies user operations, improves user experience, enhances the reliability and security of unlocking, and reduces the computational performance requirements of smart locks.
Smart Images

Figure CN115250452B_ABST
Abstract
Description
[0001] This application claims priority to Chinese Patent Application No. 2021103939717, filed on April 12, 2021, entitled "Unlocking Method and Related Device", the entire contents of which are incorporated herein by reference. Technical Field
[0002] This application relates to the field of security technology, and in particular to an unlocking method and related equipment. Background Technology
[0003] Currently, whenever a user uses a terminal device to perform a service that requires authentication, the terminal device prompts the user to actively authenticate through methods such as facial recognition or fingerprint recognition (i.e., explicit authentication methods). Only after the terminal device confirms successful authentication can the aforementioned service requiring authentication be completed.
[0004] However, in scenarios where explicit authentication is inconvenient for users, such as when a user is unlocking a smart lock using a terminal device, if the user is carrying heavy objects in both hands, it is inconvenient for the user to perform explicit authentication, resulting in the user being unable to unlock the lock effectively and experiencing a poor user experience.
[0005] Therefore, in the authentication process using terminal devices, how to simplify user operations while ensuring security is an urgent problem to be solved. Summary of the Invention
[0006] This application provides an unlocking method that allows users to unlock smart locks using terminal devices, simplifying user operations and improving user experience.
[0007] In a first aspect, embodiments of this application provide an unlocking method, which includes: a terminal device collecting first authentication information; the terminal device establishing a short-range wireless communication connection with a smart lock; the terminal device authenticating the user's identity based on the first authentication information; if the terminal device confirms successful authentication, the terminal device notifying the smart lock to unlock based on the short-range wireless communication connection; wherein, the device information of the terminal device is stored in the trusted device list of the smart lock.
[0008] The unlocking method provided in this application embodiment allows the terminal device to unlock the smart lock without receiving an active unlocking operation from the user, achieving a passive and seamless unlocking effect, simplifying user operation, and improving user experience.
[0009] In one possible implementation, the terminal device authenticates the user's identity based on the first authentication information. Specifically, this includes: if the terminal device passes the first service authentication within a first time interval before establishing a short-range wireless communication connection with the smart lock, then the terminal device still confirms successful authentication after establishing the short-range wireless communication connection with the smart lock; or, if the terminal device passes the first service authentication within a first time interval before establishing the short-range wireless communication connection with the smart lock, then after establishing the short-range wireless communication connection with the smart lock, the terminal device matches the first authentication information with pre-saved authentication information, and if the match is successful, confirms successful authentication.
[0010] In one possible implementation, the aforementioned first authentication information and the aforementioned pre-saved authentication information include passwords, fingerprints, facial images, swipe screens, and / or touch screen operations.
[0011] In one possible implementation, the first service mentioned above includes unlocking the terminal device when it is in a locked state.
[0012] In one possible implementation, the method further includes: if the terminal device fails to authenticate the user's identity based on the first authentication information, the terminal device collects the second authentication information and authenticates the user's identity based on the second authentication information.
[0013] In one possible implementation, the terminal device fails to authenticate the user's identity based on the first authentication information. Specifically, if the terminal device passes the authentication of the first service outside of a first time interval before establishing a short-range wireless communication connection with the smart lock, then the terminal device confirms that the authentication failed after establishing the short-range wireless communication connection with the smart lock.
[0014] In one possible implementation, the method further includes: if the terminal device successfully authenticates the user's identity based on the first authentication information, the terminal device collects second authentication information and authenticates the user's identity based on the second authentication information.
[0015] In one possible implementation, the terminal device collects second authentication information and performs user authentication based on the second authentication information. Specifically, this includes: the terminal device turning on its camera and capturing images through the camera; the terminal device matching the captured images with pre-recorded facial images; if the match is successful, the authentication is confirmed to be successful; or, if the terminal device is connected to a wearable device, the terminal device matching the biometric information collected in real time by the wearable device with the biometric information collected in advance by the wearable device; if the match is successful, the authentication is confirmed to be successful; or, the terminal device collecting the user's gait feature information; the terminal device matching the collected gait feature information with the gait feature information collected in advance by the terminal device; if the match is successful, the authentication is confirmed to be successful.
[0016] In one possible implementation, the communication types of the aforementioned short-range wireless communication connection include Near Field Communication (NFC), Bluetooth, Wi-Fi, and Infrared (IR).
[0017] In one possible implementation, after the terminal device establishes a short-range wireless communication connection with the smart lock, the method further includes: the terminal device receiving a first instruction sent by the smart lock, the first instruction being sent by the smart lock after detecting a voice unlock command issued by the user, the first instruction being used to instruct the terminal device to authenticate the user; or, the terminal device detecting a command issued by the user to unlock the smart lock using the terminal device; or, the terminal device receiving a second instruction sent by the smart lock, the second instruction being sent by the smart lock after detecting a user touching the smart lock, the second instruction being used to instruct the terminal device to authenticate the user; or, the terminal device determining that the distance between the terminal device and the smart lock is less than a first distance value based on the signal strength of the short-range wireless communication connection.
[0018] In one possible implementation, before the terminal device authenticates the user, the method further includes: the terminal device becoming a trusted device of the smart lock.
[0019] Secondly, embodiments of this application provide a terminal device, which includes: one or more processors and a memory; the memory is coupled to the one or more processors, the memory is used to store computer program code, the computer program code includes computer instructions, and the one or more processors are used to call the computer instructions to cause the terminal device to perform: collecting first authentication information; establishing a short-range wireless communication connection with a smart lock; authenticating the user's identity based on the first authentication information, and if the identity authentication is confirmed to be successful, notifying the smart lock to unlock based on the short-range wireless communication connection; wherein, the device information of the terminal device is stored in the trusted device list of the smart lock.
[0020] In one possible implementation, the aforementioned one or more processors are used to invoke the aforementioned computer instructions to cause the aforementioned terminal device to authenticate the user's identity based on the first authentication information. Specifically, this includes: if the terminal device passes the first service authentication within a first time interval before establishing a short-range wireless communication connection with the smart lock, then after establishing the short-range wireless communication connection, the terminal device still confirms that the authentication has been passed; or, if the terminal device passes the first service authentication within a first time interval before establishing the short-range wireless communication connection with the smart lock, then after establishing the short-range wireless communication connection, the terminal device matches the first authentication information with the pre-saved authentication information, and if the match is successful, confirms that the authentication has been passed.
[0021] In one possible implementation, the aforementioned first authentication information and the aforementioned pre-saved authentication information include passwords, fingerprints, facial images, swipe screens, and / or touch screen operations.
[0022] In one possible implementation, the first service mentioned above includes unlocking the terminal device when it is in a locked state.
[0023] In one possible implementation, the processors are further configured to invoke the computer instructions to cause the terminal device to perform: if the terminal device fails to authenticate the user's identity based on the first authentication information, collect the second authentication information and authenticate the user's identity based on the second authentication information.
[0024] In one possible implementation, the terminal device fails to authenticate the user's identity based on the first authentication information. Specifically, if the terminal device passes the authentication of the first service outside of a first time interval before establishing a short-range wireless communication connection with the smart lock, then the terminal device confirms that the authentication failed after establishing the short-range wireless communication connection with the smart lock.
[0025] In one possible implementation, the processors are further configured to invoke the computer instructions to cause the terminal device to perform: if the terminal device successfully authenticates the user based on the first authentication information, collect the second authentication information and authenticate the user based on the second authentication information.
[0026] In one possible implementation, the aforementioned one or more processors are used to invoke the aforementioned computer instructions to cause the aforementioned terminal device to collect second authentication information and perform identity authentication on the user based on the second authentication information. Specifically, this includes: the terminal device turning on its camera, collecting images through the camera, and matching the collected images with pre-recorded facial images; if the match is successful, the identity authentication is confirmed to be successful; or, if the terminal device is connected to a wearable device, the terminal device matching the biometric information collected in real time by the wearable device with the biometric information collected in advance by the wearable device; if the match is successful, the identity authentication is confirmed to be successful; or, the terminal device collecting the user's gait feature information, and matching the collected gait feature information with the gait feature information collected in advance by the terminal device; if the match is successful, the identity authentication is confirmed to be successful.
[0027] In one possible implementation, the communication types of the aforementioned short-range wireless communication connection include Near Field Communication (NFC), Bluetooth, Wi-Fi, and Infrared (IR).
[0028] In one possible implementation, after the terminal device establishes a short-range wireless communication connection with the smart lock, the aforementioned one or more processors are further configured to invoke the aforementioned computer instructions to cause the terminal device to perform: receiving a first instruction sent by the smart lock, the first instruction being sent by the smart lock after detecting a voice unlock command issued by the user, the first instruction being used to instruct the terminal device to authenticate the user; or, detecting a command issued by the user to unlock the smart lock using the terminal device; or, receiving a second instruction sent by the smart lock, the second instruction being sent by the smart lock after detecting an operation by the user touching the smart lock, the second instruction being used to instruct the terminal device to authenticate the user; or, determining that the distance between the terminal device and the smart lock is less than a first distance value based on the signal strength of the short-range wireless communication connection.
[0029] In one possible implementation, before the terminal device authenticates the user, the method further includes: the terminal device becoming a trusted device of the smart lock.
[0030] Thirdly, this application provides an unlocking method, which includes: a terminal device confirming successful explicit authentication and recording the moment of successful explicit authentication; the terminal device initiating implicit authentication; the terminal device detecting that the user is performing an operation requiring authentication; the terminal device obtaining the implicit authentication result and confirming whether the implicit authentication was successful based on the implicit authentication result; if so, the terminal device completing the service requiring authentication; wherein the time interval between the moment of successful explicit authentication and the moment the terminal device initiates implicit authentication is less than a first time threshold.
[0031] In one possible implementation, before the terminal device initiates implicit authentication, the method further includes: the terminal device saving the explicit authentication result; and / or, the terminal device saving third authentication information, which is used by the terminal device to perform explicit authentication.
[0032] In one possible implementation, the method further includes: if the terminal device confirms successful implicit authentication based on the implicit authentication result, and if the terminal device confirms successful explicit authentication based on the explicit authentication result, then the terminal device completes the business that requires authentication; or, if the terminal device confirms successful implicit authentication based on the implicit authentication result, the terminal device matches the third authentication information with the pre-entered authentication information, and if the match is successful, then the terminal device completes the business that requires authentication.
[0033] In one possible implementation, the method further includes: if the terminal device confirms that the implicit authentication has failed based on the implicit authentication result, the terminal device collects fourth authentication information and performs explicit authentication again based on the fourth authentication information. If the authentication is successful, the terminal device completes the business that requires authentication. The fourth authentication information includes a password, fingerprint, and facial image.
[0034] In one possible implementation, the terminal device initiates implicit authentication, specifically including: the terminal device turns on its camera, captures N first images through the camera, and matches all N first images with pre-recorded face images. If all matches are successful, the terminal device confirms successful face tracking and generates a first face tracking result, which indicates successful face tracking; the terminal device captures a second image through the camera and matches the second image with pre-recorded face images. If the match is successful, the terminal device confirms successful face comparison and generates a first face comparison result, which indicates successful face comparison.
[0035] In one possible implementation, the terminal device obtains the implicit authentication result and confirms whether the implicit authentication is successful based on the implicit authentication result. Specifically, this includes: the terminal device obtaining a first face tracking result and confirming that the face tracking is successful based on the first face tracking result; and / or, the terminal device obtaining a first face comparison result and confirming that the face comparison is successful based on the first face comparison result; and / or, the terminal device calculating the implicit authentication duration and confirming that the implicit authentication duration is less than a second time threshold, wherein the implicit authentication duration is the time interval between the moment of successful explicit authentication and the moment the terminal device obtains the implicit authentication result.
[0036] Fourthly, embodiments of this application provide a chip applied to a terminal device. The chip includes one or more processors, which are used to invoke computer instructions to cause the terminal device to perform a method as described in any of the possible implementations of the first or third aspect.
[0037] Fifthly, embodiments of this application provide a computer storage medium storing a computer program, the computer program including program instructions that, when executed on a terminal device, cause the terminal device to perform a method as described in any of the possible implementations of the first or third aspect.
[0038] Sixthly, embodiments of this application provide a computer program product that, when run on a computer, causes the computer to perform a method as described in any of the possible implementations of the first or third aspect. Attached Figure Description
[0039] Figure 1 This is a schematic diagram of an unlocking scenario provided by existing technology;
[0040] Figure 2 This is a schematic diagram of the architecture of an unlocking system provided in an embodiment of this application;
[0041] Figure 3 This is a flowchart illustrating an unlocking method provided in an embodiment of this application;
[0042] Figures 4A-4E This is a set of user interface diagrams prompting the user to unlock, provided in an embodiment of this application;
[0043] Figure 5 This is a flowchart illustrating another unlocking method provided in an embodiment of this application;
[0044] Figure 6 This is a flowchart illustrating another unlocking method provided in an embodiment of this application;
[0045] Figures 7A-7F This is a set of user interface diagrams for enabling implicit authentication function provided in the embodiments of this application;
[0046] Figure 8 This is a flowchart illustrating another unlocking method provided in an embodiment of this application;
[0047] Figures 9A-9C This is another set of user interface diagrams provided in the embodiments of this application;
[0048] Figure 10 This is a schematic diagram of the structure of a terminal device provided in an embodiment of this application;
[0049] Figure 11 This is a schematic diagram of the structure of another terminal device provided in an embodiment of this application;
[0050] Figure 12 This is a schematic diagram of the structure of a smart lock provided in an embodiment of this application;
[0051] Figure 13 This is a schematic diagram of the structure of another terminal device provided in an embodiment of this application. Detailed Implementation
[0052] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. In the description of the embodiments of this application, unless otherwise stated, " / " means "or," for example, A / B can mean A or B; "and / or" in the text is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Furthermore, in the description of the embodiments of this application, "multiple" refers to two or more than two.
[0053] It should be understood that the terms "first," "second," etc., in the specification, claims, and drawings of this application are used to distinguish different objects, not to describe a specific order. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or apparatuses.
[0054] In this application, the reference to "embodiment" means that a specific feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a mutually exclusive, independent, or alternative embodiment. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described in this application can be combined with other embodiments.
[0055] To facilitate understanding, some related concepts involved in the embodiments of this application will be explained first.
[0056] 1. Trusted Execution Environment (TEE)
[0057] A Trusted Execution Environment (REE) is a secure environment within a mobile terminal device. A Rich Execution Environment (REE) is a generic execution environment in mobile terminal devices, running a common operating system (OS), such as Android or iOS. The REE runs in an independent environment, operating in parallel with the common operating system and providing security services to it. The REE has its own execution controls, offering a higher level of security than the common operating system. The hardware and software resources accessible to the REE are separate from those of the common operating system.
[0058] A Trusted Execution Environment (TA) provides a secure execution environment for authorized Trusted Applications (TAs), while also protecting the confidentiality, integrity, and access permissions of the TA's resources and data. A TA includes internal and external application programming interfaces (APIs). The internal APIs primarily include APIs for key management, cryptographic algorithms, secure storage, secure clock resources and services, and trusted user interfaces. The external APIs are the underlying communication interfaces that allow client applications (CAs) running on general-purpose operating systems to access the services and data of the trusted application.
[0059] Trusted Execution Environments (TEEs) can be used in various scenarios, including content protection (e.g., preventing the theft of high-definition movies and music), mobile financial services (e.g., mobile payments), authentication (e.g., fingerprint and facial recognition), and confidential information protection (e.g., secure storage of keys and certificates). For example, sensitive information such as user identity, keys, and certificates requires high protection. TEEs can rely on encryption and integrity protection technologies to protect data and keys. A TEE stores sensitive information such as user identity, keys, and certificates in a secure area. This sensitive information can only be accessed or modified by trusted applications authorized by the TEE, and the TEE provides encryption and integrity protection mechanisms for the processing of this sensitive information. Simultaneously, keys stored in the TEE can be used to encrypt sensitive information such as contact lists and SMS messages stored in a general execution environment, ensuring the security of sensitive information stored in the general execution environment.
[0060] 2. Explicit authentication (also known as strong authentication)
[0061] Explicit authentication refers to a terminal device (such as a mobile phone) displaying a visible unlock prompt interface or issuing an unlock prompt voice when it detects that a user is attempting to unlock the terminal device. This prompts the user to choose which method (such as lock screen password, facial recognition, fingerprint recognition, etc.) to use for authentication. Only if the authentication is successful can the user unlock the terminal device.
[0062] 3. Implicit authentication
[0063] Implicit authentication refers to a terminal device (such as a mobile phone) detecting that a user is attempting to access an application (such as a gallery, messaging, or calling application) on the terminal device that requires authentication, or attempting to perform authentication-required transactions such as login or payment within an application on the terminal device (such as a shopping application). Instead of displaying a visible unlock prompt interface or issuing an unlock prompt voice, the terminal device determines whether authentication is successful based on pre-obtained implicit authentication results (such as face tracking results, face comparison results, implicit authentication duration, etc.). If authentication is successful, the user can then access the application or complete the authentication-required transaction within the application.
[0064] With the development of science and technology, there are increasingly more unlocking methods. Besides traditional methods (such as unlocking using physical keys, electronic access cards, digital combination locks, etc.), fingerprints, facial recognition, and other biometric information are now commonly used for unlocking. Some smart locks also support unlocking via an unlocking application on the user's terminal device. These smart unlocking methods are more convenient, faster, and more widely applicable than traditional methods. However, in situations where manual unlocking is inconvenient for users, such as when carrying heavy objects, making it difficult to actively control the terminal device, these smart unlocking methods are ineffective, resulting in a poor user experience.
[0065] Therefore, in the process of unlocking smart locks using terminal devices, simplifying user operations while ensuring security is an urgent problem to be solved.
[0066] The following describes one unlocking scenario in the existing technology.
[0067] Figure 1 An example of an unlocking scenario provided in the prior art is shown.
[0068] like Figure 1 As shown, the unlocking scenario can include the following three unlocking methods: unlocking with external objects (such as using physical keys, proximity cards, digital keypads, etc.), unlocking with biometric information (such as using faces, fingerprints, etc.), and unlocking with terminal devices.
[0069] External object unlocking: This unlocking method typically involves using one or more external objects to unlock traditional or smart locks. For example, a user can use a physical key to insert into the lock cylinder; another example is a user using a proximity card to establish a Near Field Communication (NFC) connection with the smart lock, after which the smart lock verifies the card's legitimacy when it approaches, and unlocks the lock if the verification is successful; yet another example is a user manually entering a password on a digital keypad to unlock the lock.
[0070] The drawback of using external objects for unlocking is that it requires manual unlocking, which is cumbersome and leads to a poor user experience when manual unlocking is inconvenient. Furthermore, users need to carry the external unlocking device with them, which can pose a security risk if lost.
[0071] Biometric unlocking: This unlocking method typically uses one or more biometric features to unlock the smart lock. For example, the smart lock can pre-register the user's facial or fingerprint information. When the user needs to unlock, the smart lock can match the user's facial (or fingerprint) information with the pre-registered information. If the match is successful, the lock can be unlocked.
[0072] The drawbacks of biometric unlocking are that it requires users to actively provide their biometric information, which is cumbersome and leads to a poor user experience when manual unlocking is inconvenient (e.g., when wearing a mask or gloves). Furthermore, relying on stored biometric information for unlocking has relatively poor security for several reasons: First, biometric information is susceptible to forgery; for example, unauthorized users might use fingerprint films or photographs instead of faces. Second, smart locks have limited computing power; the extraction and matching of biometric information requires significant computational resources, which may not meet user needs. Third, due to the limited security levels of smart locks, stored biometric information is vulnerable to theft.
[0073] Terminal device (also known as electronic device) unlocking: This unlocking method typically involves using a mobile terminal device such as a smartphone to unlock the smart lock. For example, the terminal device can establish a binding relationship with the smart lock in advance through an application (APP) installed on the terminal device. After receiving an unlocking operation from the user (such as the user clicking the "unlock" control on the terminal device's user interface), the terminal device can respond to this operation by sending an unlocking command to the smart lock, and the smart lock unlocks upon receiving the unlocking command from the terminal device.
[0074] The drawback of this terminal device unlocking method is that it requires the user to actively operate the terminal device, which is cumbersome and results in a poor user experience when it is inconvenient for the user to manually unlock the device (e.g., when the user is carrying heavy objects). Furthermore, if the user's terminal device is lost, requiring the user to actively operate it to unlock it could pose a significant security risk.
[0075] In summary, current unlocking methods primarily employ active unlocking, requiring users to take conscious action. This process is cumbersome, resulting in a poor user experience and low security. Therefore, a more secure, passive, and seamless unlocking method is needed to address these issues.
[0076] The "passive contactless unlocking method" mentioned in this application embodiment refers to a method in which the terminal device can unlock the bound smart lock without receiving user operation during the unlocking process.
[0077] This application provides an unlocking method. A terminal device can collect first authentication information. After establishing a short-range wireless communication connection (e.g., NFC, Bluetooth) between the terminal device and the smart lock, the terminal device can authenticate the user's identity based on the first authentication information. If the terminal device confirms successful authentication, it can notify the smart lock to unlock based on the short-range wireless communication connection. With the unlocking method provided by this application, the terminal device can unlock the bound smart lock without receiving an active unlocking operation from the user, achieving a passive, seamless unlocking effect, simplifying user operation, and improving user experience. Furthermore, the terminal device can authenticate the owner's identity based on multi-dimensional feature information, enhancing unlocking reliability and security. Simultaneously, the smart lock does not need to process multi-dimensional feature information, reducing the computational performance requirements of the smart lock.
[0078] It should be noted that the unlocking method provided in this application embodiment can be applied to a variety of unlocking scenarios, such as smart door lock unlocking, smart vehicle unlocking, smart screen unlocking and other smart home unlocking scenarios. This application embodiment does not limit the unlocking scenario.
[0079] To facilitate understanding of the embodiments of this application, the following describes the architecture of an unlocking system provided by the embodiments of this application.
[0080] Figure 2 An example of an unlocking system architecture provided by an embodiment of this application is illustrated.
[0081] like Figure 2 As shown, the unlocking system may include a terminal device 100 and a smart lock 200. The terminal device 100 can communicate with the smart lock 200 via a short-range wireless communication connection (such as NFC, Bluetooth, etc.), enabling the smart lock 200 to complete a series of operations such as establishing a binding relationship with the terminal device 100, authenticating the trusted device binding relationship, unlocking, and unbinding from the terminal device 100.
[0082] Terminal device 100 can also be referred to as user equipment (UE), access terminal, user unit, mobile device, user terminal, terminal, wireless communication device, user agent, or user apparatus. In the embodiments of this application, terminal device 100 is exemplified by a mobile phone. However, terminal device 100 can also be a portable electronic device such as a tablet computer, personal digital assistant (PDA), or laptop. The embodiments of this application do not limit the type, physical form, or size of terminal device 100.
[0083] The smart lock 200 can be installed on various devices (such as smart vehicles, home security doors, safes, suitcases, etc.). The smart lock 200 can have two states: unlocked and locked. Taking the smart lock 200 installed on a suitcase as an example, when the smart lock 200 is in the unlocked state, the suitcase is not closed, and the user can take out items from the suitcase or put new items into it; when the smart lock 200 is in the locked state, the suitcase is closed, and the user cannot take out items from the suitcase or put new items into it. This application does not limit the physical form or size of the smart lock 200.
[0084] It should be understood that Figure 2This is merely a schematic diagram of the unlocking system's architecture. The unlocking system may also include a greater number of terminal devices and smart locks. For example, one smart lock may be controlled by multiple terminal devices; or, for instance, one terminal device may control multiple smart locks. This application does not limit the number of terminal devices and smart locks included in the unlocking system.
[0085] The following describes the process of an unlocking method provided in an embodiment of this application.
[0086] Figure 3 The flowchart of an unlocking method provided in an embodiment of this application is illustrated by way of example.
[0087] like Figure 3 As shown, this unlocking method can be applied to unlocking systems that include terminal device 100 and smart lock 200. The specific steps of this method are described in detail below:
[0088] Phase 1: Establishing a Binding Relationship
[0089] S301, Terminal device 100 establishes a short-range wireless communication connection with smart lock 200.
[0090] Specifically, in this embodiment, the short-range wireless communication connection established between the terminal device 100 and the smart lock 200 takes NFC communication as an example. When the distance between the terminal device 100 and the smart lock 200 is within the NFC signal propagation distance (typically 0-10cm), the terminal device 100 can establish an NFC communication connection with the smart lock 200. Afterwards, the terminal device 100 and the smart lock 200 can transmit data and execute subsequent steps based on the aforementioned NFC communication connection.
[0091] It should be noted that the terminal device 100 and the smart lock 200 can also communicate with each other through other short-range wireless communication methods, such as Bluetooth, wireless fidelity (Wi-Fi), infrared (IR), etc. This application embodiment does not limit this.
[0092] In some embodiments, the terminal device 100 may be equipped with a first client, wherein the first client can be used by the terminal device 100 to manage and control the smart lock 200. For example, after the terminal device 100 establishes a short-range wireless communication connection with the smart lock, based on the short-range wireless communication connection, the terminal device 100 can use the first client to enable the smart lock 200 to complete a series of operations such as establishing a binding relationship with the terminal device 100, authenticating the trusted device binding relationship, unlocking, and unbinding from the terminal device 100.
[0093] It should be noted that the aforementioned first client may be an application related to the smart lock 200, a mini-program or quick app in a certain application, etc., and this application embodiment does not limit this.
[0094] S302, the smart lock 200 sends binding information 1 to the terminal device 100, wherein the binding information 1 carries the identification information, key information, etc. of the smart lock 200.
[0095] Specifically, after the terminal device 100 establishes a short-range wireless communication connection with the smart lock 200, the smart lock 200 can send binding information 1 to the terminal device 100 based on this connection. This binding information 1 can carry the smart lock 200's identification information, key information, etc. The identification information can be a unique identifier (UID) for the smart lock 200, indicating that it is smart lock 200. The key information can be a key associated with the smart lock 200's identification information. For example, for smart lock 200, the key associated with its identification information might be key 1, while for another smart lock, the key associated with its identification information might be key 2. That is, for different smart locks, different identification information leads to different associated keys.
[0096] S303, Terminal device 100 saves the above binding information 1.
[0097] Specifically, after receiving the binding information 1 sent by the smart lock 200, the terminal device 100 can save the binding information 1.
[0098] S304. Terminal device 100 sends binding information 2 to smart lock 200, wherein the binding information 2 carries the identification information, key information, etc. of terminal device 100.
[0099] Specifically, after the terminal device 100 establishes a short-range wireless communication connection with the smart lock 200, based on this connection, the terminal device 100 can send binding information 2 to the smart lock 200. This binding information 2 can carry the terminal device 100's identification information, key information, etc. The identification information can be the terminal device 100's Media Access Control (MAC) address, International Mobile Equipment Identity (IMSI), etc., indicating that the terminal device is terminal device 100. The key information can be a key associated with the terminal device 100's identification information. For example, for terminal device 100, the key associated with its identification information might be key 3, while for another terminal device, the key associated with its identification information might be key 4. That is, for different terminal devices, different identification information leads to different associated keys.
[0100] S305, Smart Lock 200 saves the above binding information 2.
[0101] Specifically, after receiving the binding information 2 sent by the terminal device 100, the smart lock 200 can save the binding information 2.
[0102] It should be noted that in some embodiments, steps S302-S303 may be executed after steps S304-S305; in other embodiments, steps S302 and S304 may be executed simultaneously, followed by steps S303 and S305. This application does not limit this aspect.
[0103] S306. Terminal device 100 sends a binding request to smart lock 200, wherein the binding request carries the identification information, key information, etc. of terminal device 100.
[0104] Specifically, terminal device 100 can send a binding request to smart lock 200 to request the establishment of a binding relationship with smart lock 200. The key information carried in the binding request can be the key itself associated with the identification information of terminal device 100, or it can be data encrypted using the private key of terminal device 100.
[0105] S307. The smart lock 200 determines whether the identification information and key information of the terminal device 100 carried in the above binding request are consistent with the identification information and key information of the terminal device 100 that have been saved. If they are consistent, it means that the terminal device 100 has passed device authentication and can establish a binding relationship with the smart lock 200.
[0106] Specifically, during step S305, the smart lock 200 stores the identification information and key information of the terminal device 100 carried in the binding information 2 sent by the terminal device 100. After receiving the binding request sent by the terminal device 100, the smart lock 200 can perform device authentication on the terminal device 100. That is, the smart lock 200 can determine whether the identification information and key information of the terminal device 100 carried in the binding request are consistent with the stored identification information and key information of the terminal device 100 (the key associated with the identification information of the terminal device 100). If they are consistent, it means that the terminal device 100 has passed device authentication (i.e., device authentication is successful) and can establish a binding relationship with the smart lock 200; if they are inconsistent, it means that the terminal device 100 has failed device authentication (i.e., device authentication failed) and cannot establish a binding relationship with the smart lock 200.
[0107] For example, the smart lock 200 can determine whether the identification information of the terminal device 100 carried in the above binding request is consistent with the identification information of the terminal device 100 that has been saved, by means of the following: the smart lock 200 can compare the identification information of the terminal device 100 carried in the above binding request with the identification information of the terminal device 100 that has been saved, and determine whether the two are consistent.
[0108] For example, the smart lock 200 can determine whether the key information of the terminal device 100 carried in the above binding request is consistent with the key information of the terminal device 100 that has been saved, in the following two ways:
[0109] Method 1: If the key information of the terminal device 100 carried in the above binding request is the key itself associated with the identification information of the terminal device 100, then the smart lock 200 can compare the key itself associated with the identification information of the terminal device 100 carried in the above binding request with the key information of the terminal device 100 that has been saved, and determine whether the two are consistent. If they are consistent, then it is determined that the key information of the terminal device 100 carried in the above binding request is consistent with the key information of the terminal device 100 that has been saved.
[0110] Method 2: If the key information of the terminal device 100 carried in the above binding request is data encrypted using the private key of the terminal device 100, this data can be called the first encrypted data. The smart lock 200 can then use a stored key associated with the identification information of the terminal device 100 to encrypt the same data, which can be called the second encrypted data. The smart lock 200 can then determine whether the first encrypted data and the second encrypted data are consistent. If they are consistent, it is determined that the key information of the terminal device 100 carried in the above binding request is consistent with the stored key information of the terminal device 100. For example, terminal device 100 can request random data from smart lock 200 in advance. After receiving the random data sent by smart lock 200, terminal device 100 can encrypt the random data using its private key to obtain first encrypted data. Smart lock 200 can then encrypt the random data using a key that has been stored and associated with the identification information of terminal device 100 to obtain second encrypted data. After that, smart lock 200 can determine whether the first encrypted data and the second encrypted data are consistent. If they are consistent, it is determined that the key information of terminal device 100 carried in the binding request is consistent with the key information of terminal device 100 that has been stored.
[0111] S308, smart lock 200 sends device authentication results to terminal device 100.
[0112] Specifically, after the smart lock 200 completes device authentication for the terminal device 100, it can send the device authentication result to the terminal device 100. The device authentication result is used to indicate whether the terminal device 100 has passed or failed device authentication.
[0113] S309. Based on the above device authentication results, terminal device 100 confirms that terminal device 100 has passed device authentication.
[0114] Specifically, after receiving the device authentication result sent by the smart lock 200, the terminal device 100 can determine whether it has passed or failed device authentication based on the authentication result. If the terminal device 100 passes device authentication, it can establish a binding relationship with the smart lock 200; if the terminal device 100 fails device authentication, it cannot establish a binding relationship with the smart lock 200.
[0115] S310, terminal device 100 and smart lock 200 are bound together.
[0116] Specifically, after confirming that it has passed device authentication, the terminal device 100 can establish a binding relationship with the smart lock 200.
[0117] It's easy to understand that the above description of the binding relationship establishment stage only uses the example of a single terminal device (terminal device 100) binding with the smart lock 200. In practical applications, the smart lock 200 may need to bind with multiple terminal devices. For example, when the smart lock 200 is a home door lock, it may need to bind with the terminal devices carried by all members of the household. In this case, the user carrying terminal device 100 can be granted administrator privileges, allowing other terminal devices to bind with the smart lock 200. Based on this, other users can be authorized to use the smart lock 200. Under the condition that terminal device 100 and other terminal devices have established short-range wireless communication connections with the smart lock 200, the possible implementation methods for other terminal devices to bind with the smart lock 200 include, but are not limited to, the following three:
[0118] Method 1: Terminal device 100 can use the verification code sent by smart lock 200 to establish a binding relationship between other terminal devices and smart lock 200. The verification code can be a QR code or a verification code, etc. For example, when the verification code is a QR code, other terminal devices can scan it. After scanning, the other terminal devices can save the identification information and key information of smart lock 200, and smart lock 200 can also save the identification information and key information of other terminal devices, thereby establishing a binding relationship between the other terminal devices and smart lock 200. Specifically, the verification code is sent from smart lock 200 to terminal device 100 after terminal device 100 sends a request to smart lock 200 to establish a binding relationship with smart lock 200.
[0119] Method 2: Terminal device 100 can receive user input of system account and password of other terminal devices. In response to this operation, terminal device 100 can send the system account and password of the other terminal devices to smart lock 200. Smart lock 200 can save the system account and password of the other terminal devices and send the identification information and key information of smart lock 200 to the other terminal devices. When the other terminal devices are logged into their system accounts, they can receive the identification information and key information of smart lock 200, thereby establishing a binding relationship between the other terminal devices and smart lock 200.
[0120] In some embodiments, when the system account of a terminal device that has already established a binding relationship with the smart lock 200 logs in on another terminal device, the other terminal device can directly establish a binding relationship with the smart lock 200 without the terminal device 100 needing to perform related operations before it can establish a binding relationship with the smart lock 200.
[0121] Method 3: When other devices are within the short-range wireless communication connection range of the smart lock 200, the terminal device 100 can receive user input of the identification information of other terminal devices. In response to this operation, the terminal device 100 can send the identification information of the other terminal devices to the smart lock 200. The smart lock 200 can save the identification information of the other terminal devices. Based on the short-range wireless communication connection, the smart lock 200 can receive and save the key information associated with the identification information of the other terminal devices. Then, it sends the identification information and key information of the smart lock 200 to the other terminal devices. The other terminal devices can also save the identification information and key information of the smart lock 200, thereby establishing a binding relationship between the other terminal devices and the smart lock 200.
[0122] In this embodiment, the smart lock 200 can store the identification information and key information (which can be collectively referred to as the device information of the terminal device) of the terminal device that has established a binding relationship with the smart lock 200 in the trusted device list of the smart lock 200.
[0123] It should be noted that the implementation of the binding relationship between the terminal device 100 and the smart lock 200 can also be in other ways, and this application embodiment does not limit this.
[0124] Phase Two: Unlocking Phase
[0125] S311, Terminal device 100 and smart lock 200 re-establish short-range wireless communication connection.
[0126] Step S311 is executed when the short-range wireless communication connection established between the terminal device 100 and the smart lock 200 is broken.
[0127] In some embodiments, the terminal device 100 and the smart lock 200 re-establish a short-range wireless communication connection (or the short-range wireless communication connection established between the terminal device 100 and the smart lock 200 is not disconnected after the terminal device 100 and the smart lock 200 establish a binding relationship). Further, the terminal device 100 may perform subsequent steps after detecting that the user carrying the terminal device 100 has used the terminal device 100 to unlock the smart lock 200, or after detecting that the distance between the terminal device 100 and the smart lock 200 is less than a preset distance threshold (also known as a first distance value). That is, the terminal device 100 performs subsequent steps after determining that the user carrying the terminal device 100 has the intention to use the terminal device 100 to unlock the smart lock 200.
[0128] The aforementioned terminal device 100 can detect that a user carrying the terminal device 100 is using the terminal device 100 to unlock the smart lock 200, which can be achieved in ways including but not limited to the following:
[0129] In one implementation, after detecting a voice unlock command issued by a user, the smart lock 200 can send a first instruction to the terminal device 100, which instructs the terminal device 100 to perform subsequent steps to unlock the smart lock 200.
[0130] In one implementation, after detecting a user's instruction to unlock the smart lock 200 using the terminal device 100, the terminal device 100 can execute subsequent steps to unlock the smart lock 200.
[0131] In one implementation, after detecting a user touching the smart lock 200, the smart lock 200 can send a second instruction to the terminal device 100. The second instruction is used to instruct the terminal device 100 to perform subsequent steps to unlock the smart lock 200.
[0132] In some embodiments, when the short-range wireless communication connection established between the terminal device 100 and the smart lock 200 is a Bluetooth communication connection, since the propagation distance of Bluetooth signals is typically between tens and hundreds of meters, it is generally impossible to effectively determine whether the user carrying the terminal device 100 intends to unlock the lock when the distance between the terminal device 100 and the smart lock 200 is relatively far. Therefore, the terminal device 100 and the smart lock 200 can determine the distance between them based on the Bluetooth signal strength. When the distance between the terminal device 100 and the smart lock 200 gradually decreases until the distance between the terminal device 100 and the smart lock 200 is less than a preset distance threshold, that is, when the terminal device 100 determines that the user carrying the terminal device 100 has the intention to use the terminal device 100 to unlock the smart lock 200, the terminal device 100 will continue to execute the subsequent steps.
[0133] S312, Terminal device 100 sends a trusted device binding relationship authentication request to smart lock 200, wherein the trusted device binding relationship authentication request carries the identification information, key information, etc. of terminal device 100.
[0134] Specifically, after the terminal device 100 establishes a short-range wireless communication connection with the smart lock 200, based on the aforementioned short-range wireless communication connection, the terminal device 100 can send a trusted device binding relationship authentication request to the smart lock 200. This trusted device binding relationship authentication request is used to instruct the smart lock 200 to determine whether the terminal device 100 is a terminal device that has already been bound to the smart lock 200. If the terminal device 100 is a terminal device that has already been bound to the smart lock 200, then the terminal device 100 is a trusted device.
[0135] S313. The smart lock 200 determines whether the identification information and key information of the terminal device 100 carried in the above trusted device binding relationship authentication request are consistent with the identification information and key information of the already bound terminal device 100. If they are consistent, it means that the terminal device 100 has passed the trusted device binding relationship authentication.
[0136] Specifically, during the process of establishing a binding relationship between the smart lock 200 and the terminal device 100, the smart lock 200 stores the identification information and key information of the terminal device 100. After receiving the aforementioned trusted device binding relationship authentication request sent by the terminal device 100, the smart lock 200 can perform trusted device binding relationship authentication on the terminal device 100. That is, the smart lock 200 can determine whether the identification information and key information of the terminal device 100 carried in the trusted device binding relationship authentication request are consistent with the identification information and key information of the already bound terminal device 100. If they are consistent, it means that the terminal device 100 has passed the trusted device binding relationship authentication. If they are inconsistent, it means that the terminal device 100 has failed device authentication.
[0137] The specific execution process of the smart lock 200 determining whether the identification information and key information of the terminal device 100 carried in the above-mentioned trusted device binding relationship authentication request are consistent with the identification information and key information of the already bound terminal device 100 can be referred to the relevant content in the aforementioned step S307, and will not be repeated here.
[0138] S314, the smart lock 200 sends the trusted device binding relationship authentication result to the terminal device 100.
[0139] Specifically, after the smart lock 200 completes the trusted device binding relationship authentication for the terminal device 100, it can send the trusted device binding relationship authentication result to the terminal device 100. The trusted device binding relationship authentication result is used to indicate whether the terminal device 100 has passed or failed the trusted device binding relationship authentication.
[0140] S315. Based on the above trusted device binding relationship authentication results, terminal device 100 confirms that the trusted device binding relationship authentication is successful.
[0141] Specifically, after receiving the trusted device binding relationship authentication result sent by the smart lock 200, the terminal device 100 can confirm whether the trusted device binding relationship authentication of the terminal device 100 has passed based on the aforementioned trusted device binding relationship authentication result. If the terminal device 100 confirms that the trusted device binding relationship authentication has passed (i.e., the trusted device binding relationship authentication is successful), it means that the terminal device 100 is a terminal device that has already completed binding with the smart lock 200, that is, the terminal device 100 is a trusted device. Therefore, the terminal device 100 can continue to execute subsequent steps. If the terminal device 100 confirms that the trusted device binding relationship authentication has failed (i.e., the trusted device binding relationship authentication fails), it means that the terminal device 100 is not a terminal device that has already completed binding with the smart lock 200, that is, the terminal device 100 is not a trusted device. Therefore, the terminal device 100 cannot continue to execute subsequent steps.
[0142] In some embodiments, if the first trusted device binding relationship authentication fails, the terminal device 100 can continue to execute step S312, that is, request trusted device binding relationship authentication from the smart lock 200 again, until the trusted device binding relationship authentication succeeds. For example, if the terminal device 100 is known to be a trusted device, but the trusted device binding relationship authentication fails due to some reason (such as a temporary malfunction of the smart lock 200), then the terminal device 100 can continue to execute step S312, that is, request trusted device binding relationship authentication from the smart lock 200 again, until the trusted device binding relationship authentication succeeds. However, for security reasons, a threshold number of failed trusted device binding relationship authentication attempts can be set (e.g., the threshold can be set to 3 times, 5 times, etc.). When the number of failed trusted device binding relationship authentication attempts reaches the above threshold, the smart lock 200 can stop responding to the trusted device binding relationship authentication request sent by the terminal device 100 and enter a locked state. At this time, the smart lock 200 cannot perform the unlocking action under the instruction of the terminal device 100. The user may only be able to unlock the smart lock 200 through other external unlocking objects (e.g., physical keys). In this way, brute-force attacks by unauthorized users can be prevented, and the security of the smart lock 200 can be improved.
[0143] S316, Terminal device 100 performs owner authentication based on multi-dimensional feature information.
[0144] Specifically, to ensure and improve the reliability and security of unlocking the smart lock 200 via the terminal device 100, the terminal device 100 can perform owner authentication based on multi-dimensional feature information to determine whether the user currently carrying the terminal device 100 is the owner. If so, the terminal device 100 can continue to execute subsequent steps, instructing the smart lock 200 to perform the unlocking action and complete the unlocking. Possible implementation methods for the terminal device 100 to perform owner authentication based on multi-dimensional feature information include, but are not limited to, the following four:
[0145] Method 1: Perform the owner identity authentication based on the continuous authentication time of the terminal device 100:
[0146] Specifically, before the terminal device 100 detects that the user carrying the terminal device 100 has the intention of unlocking the smart lock 200 using the terminal device 100, the user carrying the terminal device 100 can perform the owner identity authentication based on a certain method (such as lock screen password / fingerprint recognition / face recognition, etc.) to complete some operations on the terminal device 100 (such as mobile payment, opening a certain application, unlocking the terminal device 100 in the locked screen state, etc.). After the terminal device 100 confirms that the owner identity authentication is passed, the terminal device 100 can use the result of the passed owner identity authentication as the result of the passed owner identity authentication required when the user carrying the terminal device 100 unlocks the smart lock 200 using the terminal device 100. Assume that the moment when the terminal device 100 performs the owner identity authentication based on the continuous authentication time to complete unlocking the smart lock 200 using the terminal device 100 this time is t1, and the moment when the user carrying the terminal device 100 last performed the owner identity authentication based on a certain method to complete some operations on the terminal device 100 is t2, and the preset continuous authentication time threshold is T (such as 10 seconds, 30 seconds, 60 seconds, etc.). If the terminal device 100 confirms that T < t1 - t2, it means that the terminal device 100 confirms that the owner identity authentication is passed, that is, the terminal device 100 determines that the current user carrying the terminal device 100 is the owner; otherwise, it means that the terminal device 100 confirms that the owner identity authentication is not passed, that is, the terminal device 100 determines that the current user carrying the terminal device 100 may not be the owner.
[0147] Among them, before the terminal device 100 detects that the user carrying the terminal device 100 has the intention of unlocking the smart lock 200 using the terminal device 100, the user carrying the terminal device 100 can perform the owner identity authentication based on a certain method (such as lock screen password / fingerprint recognition / face recognition, etc.) to complete some operations on the terminal device 100 (such as mobile payment, opening a certain application, unlocking the terminal device 100 in the locked screen state, etc.), which may include but are not limited to the following implementation methods:
[0148] In one implementation, after the terminal device 100 detects the operation of the user entering the password, it can match the above password with the password saved in advance. If the match is successful, it confirms that the owner identity authentication is passed.
[0149] In one implementation, after the terminal device 100 detects the fingerprint of the user, it can match the above fingerprint with the fingerprint entered in advance. If the match is successful, it confirms that the owner identity authentication is passed.
[0150] In one implementation, after detecting a user's face image, the terminal device 100 can match the face image with a pre-recorded face image. If the match is successful, the device owner's identity authentication is confirmed.
[0151] In one implementation, after detecting a user's swipe and / or touch operation, the terminal device 100 can use a pre-trained model to identify the swipe and / or touch operation. If the identification is successful, the device owner's identity authentication is confirmed. The specific execution process of this implementation will be explained in detail below and will not be elaborated here.
[0152] Method 2: Authenticate the owner's identity based on the facial information (also known as facial image) collected in real time by the front-facing camera on the terminal device 100.
[0153] Specifically, if the terminal device 100 has already pre-registered the owner's facial information, as long as the front-facing camera on the terminal device 100 detects the user's facial information, the front-facing camera can collect facial information in real time. The terminal device 100 can use facial recognition technology, such as Swing facial recognition technology (a facial recognition technology based on the Java Swing framework), to match the collected facial information with the pre-registered owner's facial information. If the match is successful, the terminal device 100 confirms that the owner's identity authentication is successful, that is, the terminal device 100 determines that the user currently carrying the terminal device 100 is the owner. Otherwise, the terminal device 100 confirms that the owner's identity authentication is unsuccessful, that is, the terminal device 100 determines that the user currently carrying the terminal device 100 may not be the owner.
[0154] In one implementation, after the terminal device 100 detects that the user carrying the terminal device 100 intends to unlock the smart lock 200 using the terminal device 100, the terminal device 100 can turn on the camera to capture an image. The captured image is then matched with a pre-recorded facial image. If a match is found, the identity authentication is confirmed. If the camera fails to capture an image matching a pre-recorded facial image within a certain period, the terminal device 100 can confirm that the identity authentication has failed. In this case, the terminal device 100 can turn off the camera to prevent power consumption waste caused by prolonged camera operation.
[0155] Method 3: Authenticate the owner's identity based on biometric information collected in real time by accessory devices connected to the terminal device 100.
[0156] Specifically, when the terminal device 100 is connected to accessory devices (such as smart bracelets, smartwatches, smart glasses, and other wearable devices), the terminal device 100 can authenticate the owner's identity based on the biometric information (such as electrocardiogram, blood pressure, blood oxygen, pulse wave, etc.) collected in real time by the aforementioned accessory devices. This can include two processes: a training process (i.e., the process of collecting biometric information in advance and training the recognition model) and a recognition process (i.e., the process of using the trained recognition model to identify the biometric information collected in real time to confirm the owner's identity).
[0157] For example, taking a smart bracelet as an accessory device and an electrocardiogram (ECG) as the collected physiological characteristic information, the smart bracelet can collect and preprocess the ECG signal of the owner of the terminal device 100 (usually for 20-60 seconds). It then trains an ECG recognition model on the preprocessed ECG signal dataset. When the terminal device 100 needs to authenticate the owner (i.e., the terminal device 100 detects that the user currently carrying the terminal device 100 intends to unlock the device), and the user is wearing the aforementioned smart bracelet, the smart bracelet can authenticate the user's identity. The user's electrocardiogram (ECG) signal is collected (collection time can be 5s, 10s, etc.) and preprocessed. A feature vector V = [V1, V2, ..., Vn] is calculated for the preprocessed ECG signal, where n is a positive integer. This feature vector can include time-domain and / or frequency-domain feature data of the preprocessed ECG signal. The smart bracelet can input this feature vector into a pre-trained ECG recognition model to obtain a recognition result. The smart bracelet can then send this recognition result to a terminal device 100, which can use this result to verify the owner's identity. In one possible implementation, the recognition result can be a recognition accuracy rate. When the accuracy rate reaches or exceeds a preset threshold (e.g., 95%), it indicates that the owner's identity authentication is successful, meaning the terminal device 100 determines that the user currently carrying the terminal device 100 is the owner. Otherwise, it indicates that the owner's identity authentication is unsuccessful, meaning the terminal device 100 determines that the user currently carrying the terminal device 100 may not be the owner.
[0158] In some embodiments, accessory devices connected to terminal device 100 may only be responsible for collecting the user's biometric information during the training and recognition processes and sending the collected biometric information to terminal device 100, while other steps in the training and recognition processes can be performed by terminal device 100.
[0159] In other embodiments, the accessory device connected to the terminal device 100 can also collect the user's iris information. Unlike biometric information such as electrocardiogram, blood pressure, and pulse wave, the iris information of the same person remains unchanged at different times, similar to facial information and fingerprint information. Therefore, when the terminal device 100 performs owner authentication based on the user's iris information, similar to the process of facial recognition in method 2, the terminal device 100 can match the current user's iris information with the pre-recorded iris information. If the match is successful, it means that the terminal device 100 confirms that the owner authentication is successful, that is, the terminal device 100 determines that the user currently carrying the terminal device 100 is the owner. Otherwise, it means that the terminal device 100 confirms that the owner authentication is unsuccessful, that is, the terminal device 100 determines that the user currently carrying the terminal device 100 may not be the owner.
[0160] Since biometric information such as electrocardiogram, blood pressure, and pulse wave exists only in living individuals and is difficult to counterfeit, method 3 described above can improve the security of owner authentication. Furthermore, in one possible implementation, the terminal device 100 can perform owner authentication based on the user's biometric information periodically collected by accessory devices connected to the terminal device 100. This allows the terminal device 100 to continuously perform owner authentication.
[0161] It should be noted that the relevant algorithms (such as signal processing algorithms, machine learning algorithms, etc.) used in the above training process and the above recognition process can all utilize existing algorithms, and the embodiments of this application do not limit them.
[0162] Method 4: Authenticate the owner's identity based on the owner's behavioral characteristics of the terminal device 100 (such as touch screen and / or swipe screen behavior characteristics, gait characteristics, etc.):
[0163] Specifically, the terminal device 100 can collect the owner behavior feature data of the terminal device 100 in advance, and obtain a recognition model by training the collected owner behavior feature data of the terminal device 100. When the terminal device 100 needs to perform owner identity authentication, the terminal device 100 can use the trained recognition model to identify the user behavior features of the user currently carrying the terminal device 100, and confirm whether the owner identity authentication is successful based on the recognition result.
[0164] For example, taking the owner's behavior characteristics of terminal device 100 as touch screen and / or swipe screen behavior characteristics as an example, terminal device 100 can perform owner authentication through touch screen and / or swipe screen behavior characteristic recognition. Specifically, terminal device 100 can collect the touch screen and / or swipe screen behavior characteristic data of the owner of terminal device 100 in advance, and train the collected touch screen and / or swipe screen behavior characteristic data through relevant machine learning algorithms to obtain a touch screen and / or swipe screen behavior characteristic recognition model. When terminal device 100 needs to perform owner authentication (i.e., terminal device 100 detects that the user currently carrying terminal device 100 intends to unlock the device), and the user currently carrying terminal device 100 is performing touch screen and / or swipe screen behavior, terminal device 100 can use the trained touch screen and / or swipe screen behavior characteristic recognition model to identify the touch screen and / or swipe screen behavior characteristics of the user currently carrying terminal device 100 to obtain the identification result. Terminal device 100 can confirm whether the owner authentication is successful based on the above identification result. In one possible implementation, the above identification can be a binary classification result, which can be 1 or 0. For example, 1 can indicate that the owner's identity authentication is successful, meaning that the terminal device 100 will determine that the user currently carrying the terminal device 100 is the owner; 0 can indicate that the owner's identity authentication is unsuccessful, meaning that the terminal device 100 will determine that the user currently carrying the terminal device 100 may not be the owner. In another possible implementation, the above identification result can be an identification accuracy rate. When the identification accuracy rate reaches or exceeds a certain preset threshold (e.g., 95%), it indicates that the owner's identity authentication is successful, meaning that the terminal device 100 determines that the user currently carrying the terminal device 100 is the owner; otherwise, it indicates that the owner's identity authentication is unsuccessful, meaning that the terminal device 100 determines that the user currently carrying the terminal device 100 may not be the owner.
[0165] In some embodiments, the terminal device 100 can identify the user and obtain the identification result as long as it detects that the user has touched and / or swiped the screen, thereby completing the owner authentication and achieving the purpose of continuous owner authentication by the terminal device 100. Optionally, if the terminal device 100 detects that the user currently carrying the terminal device 100 intends to unlock the device, and the user is not currently touching and / or swiping the screen, the terminal device 100 can determine whether the time interval since the last successful owner authentication is less than a preset continuous authentication time threshold T (e.g., 10 seconds, 30 seconds, 60 seconds, etc.). If so, it indicates that the owner authentication is successful, that is, the terminal device 100 determines that the user currently carrying the terminal device 100 is the owner; otherwise, it indicates that the owner authentication is unsuccessful, that is, the terminal device 100 determines that the user currently carrying the terminal device 100 may not be the owner.
[0166] When the owner's behavioral characteristics of the terminal device 100 are gait characteristics, the terminal device 100 can perform owner authentication based on the posture and behavioral characteristic data of the owner of the terminal device 100 during walking, which are collected by sensors such as gyroscopes. That is, the terminal device 100 can perform owner authentication through gait feature recognition. The specific process is similar to the process of the terminal device 100 performing owner authentication based on touch screen and / or swipe screen behavior recognition, and will not be described in detail here.
[0167] In some embodiments, the service of unlocking the smart lock 200 using the terminal device 100 is defined as the unlocking service, and the services performed by the terminal device 100 other than the unlocking service are defined as other services (or the first service). To complete other services on the terminal device 100 (such as mobile payment, opening an application, unlocking the terminal device 100 when it is locked), the user carrying the terminal device 100 can perform owner authentication in a certain way (such as lock screen password / fingerprint recognition / face recognition / touch screen and / or swipe behavior recognition, etc.) to obtain the owner authentication result for other services and complete the owner authentication. Within a certain period of time after completing the owner authentication for other services (i.e., within the first time interval before the terminal device 100 and the smart lock 200 establish a short-range wireless communication connection), for example, within the time range of the aforementioned preset continuous authentication time threshold T, if the terminal device 100 detects that the user carrying the terminal device 100 intends to use the terminal device 100 to unlock the smart lock 200, the terminal device 100 can use the owner authentication result of the aforementioned other services as the owner authentication result of the unlocking service to instruct the smart lock 200 to perform the unlocking action and complete the unlocking. In one possible implementation, after completing the owner authentication for other services, within a certain period of time (e.g., within the aforementioned preset continuous authentication time threshold T), if the terminal device 100 detects that the user carrying the terminal device 100 intends to use the terminal device 100 to unlock the smart lock 200, the terminal device 100 can also match the authentication information collected during the owner authentication for other services (also known as the first authentication information) with the authentication information stored in advance by the terminal device 100. If the match is successful, it means that the terminal device 100 confirms that the owner authentication is successful and can execute subsequent steps to instruct the smart lock 200 to perform the unlocking action and complete the unlocking. In one possible implementation, after the terminal device 100 has completed the owner authentication for other services for a period of time (i.e., outside the first time interval before the terminal device 100 establishes a short-range wireless communication connection with the smart lock 200), for example, beyond the aforementioned preset continuous authentication time threshold T, if the terminal device 100 detects that the user carrying the terminal device 100 intends to unlock the smart lock 200 using the terminal device 100, then the terminal device 100 can choose to use the aforementioned method 2, method 3, and method 4, where the owner behavior of the terminal device 100 is walking behavior, to perform owner authentication. After confirming that the owner authentication is successful, the terminal device 100 can execute subsequent steps to instruct the smart lock 200 to perform the unlocking action and complete the unlocking.
[0168] The aforementioned first authentication information and the aforementioned pre-saved authentication information may include, but are not limited to, passwords, fingerprints, facial images, swipe screens, and / or touch screen operations.
[0169] In this application embodiment, the second authentication information may include, but is not limited to, the facial information in method 2, the biometric information in method 3, and the gait features in method 4.
[0170] In other embodiments, the terminal device 100 can determine the priority of using the four methods for owner authentication based on certain parameters. Then, the terminal device 100 can first select the method with the highest priority for owner authentication. If the owner authentication is successful, the terminal device 100 can continue to execute subsequent steps, instructing the smart lock 200 to perform the unlocking action to complete the unlocking. If the owner authentication fails, the terminal device 100 can then select the method with the next lower priority for owner authentication, and so on. That is, after the terminal device 100 uses the highest priority method among the four methods for owner authentication and determines that the owner authentication is successful, the terminal device 100 can continue to execute subsequent steps, instructing the smart lock 200 to perform the unlocking action to complete the unlocking. Otherwise, the terminal device 100 needs to select another method with a lower priority for owner authentication again.
[0171] For example, terminal device 100 can prioritize the four methods based on their accuracy. Higher accuracy means higher priority, and terminal device 100 will prioritize using that method for owner authentication. For instance, based on accuracy, the four methods can be ranked from highest to lowest priority: Method 1 > Method 2 > Method 3 > Method 4, where Method 1 has the highest priority, Method 4 has the lowest priority, and Methods 2 and 3 have priorities between the highest and lowest. It's easy to understand that terminal device 100 will prioritize using Method 1 for owner authentication. If the owner authentication is successful, terminal device 100 can continue with subsequent steps. If the owner authentication fails, terminal device 100 will use Method 2 to re-authenticate the owner. If the owner authentication is successful, terminal device 100 can continue with subsequent steps. If the owner authentication fails again, terminal device 100 will use Method 3 to re-authenticate the owner. If the owner authentication is successful, terminal device 100 can continue with subsequent steps. If the identity authentication fails again, the terminal device 100 will choose to use method 4 to re-authenticate the owner's identity. If the owner's identity authentication is successful, the terminal device 100 can continue to execute the subsequent steps. That is to say, only if the terminal device 100 has successfully authenticated the owner's identity using one of the above four methods, will the terminal device 100 choose to use another method with lower priority to authenticate the owner's identity again if the owner's identity authentication fails. Otherwise, the terminal device 100 can continue to execute the subsequent steps and instruct the smart lock 200 to perform the unlocking action to complete the unlocking.
[0172] In other embodiments, the terminal device 100 may determine, based on the security requirements of the application scenario, whether to use one of the four methods described above for owner authentication, or to use a combination of the four methods described above for owner authentication.
[0173] For example, in application scenarios with low security requirements (such as using terminal device 100 to open smart lock 200 installed on a bedroom door or smart lock 200 installed on a kitchen door), terminal device 100 can use one of the above four methods to authenticate the owner's identity. That is, as long as terminal device 100 determines that the user currently carrying terminal device 100 has passed the owner authentication using one of the above four methods, it means that terminal device 100 confirms that the owner's identity authentication is successful, and terminal device 100 can continue to execute subsequent steps, instructing smart lock 200 to perform the unlocking action to complete the unlocking.
[0174] For example, in application scenarios with high security requirements (such as using terminal device 100 to open smart lock 200 installed on a home security door or smart lock 200 installed on a smart vehicle), terminal device 100 can use several of the above four methods to comprehensively consider the owner's identity authentication. That is, only after terminal device 100 has used several of the above four methods to authenticate the owner's identity, and each method used by terminal device 100 can determine that the user currently carrying terminal device 100 has passed the owner identity authentication, does terminal device 100 confirm that the owner's identity authentication is successful, and only then can terminal device 100 continue to execute subsequent steps, instructing smart lock 200 to perform the unlocking action and complete the unlocking.
[0175] Furthermore, if the terminal device 100 fails to authenticate the owner's identity using one or more of the four methods mentioned above, meaning the terminal device 100 determines that the user currently carrying the terminal device 100 may not be the owner, in one possible implementation, the terminal device 100 can prompt the user to unlock the terminal device 100 using a lock screen password / face recognition / fingerprint recognition, etc. If the user successfully unlocks the terminal device 100, the terminal device 100 can continue to execute subsequent steps, instructing the smart lock 200 to perform the unlocking action and complete the unlocking. This avoids situations where the owner cannot successfully unlock the smart lock 200 due to certain objective factors (such as a small probability of incorrect judgment when the terminal device 100 performs owner authentication based on multi-dimensional feature information).
[0176] In some embodiments, if the terminal device 100 confirms that the owner's identity authentication has failed, it may prompt the user to use other methods to unlock the smart lock 200. These other methods may include, but are not limited to, the following:
[0177] In one implementation, such as Figure 4A As shown, terminal device 100 can prompt the user to unlock terminal device 100 when it is in lock screen state (e.g., Figure 4A The prompt 401 is displayed on the user interface 400 shown in the figure. Alternatively, the terminal device 100 may also prompt the user to unlock the smart lock 200 by issuing a voice (e.g., "Authentication failed, please try other methods to authenticate") or vibration.
[0178] In one implementation, such as Figure 4B As shown, a wearable device (e.g., [device name]) is connected to the terminal device 100. Figure 4B In the case of a smartwatch (as shown), the wearable device can prompt the user to unlock the terminal device 100 (e.g., a smartwatch that is currently locked). Figure 4BThe user interface 410 shows a prompt 411. Alternatively, the wearable device may also prompt the user to unlock the smart lock 200 by issuing a voice (e.g., "Authentication failed, please try other methods to authenticate") or vibration.
[0179] In one implementation, such as Figure 4C As shown, the smart lock 200 can prompt the user to unlock the terminal device 100, which is in a locked state, by issuing a voice (such as "Authentication failed, please try to unlock the phone").
[0180] After the user successfully unlocks the terminal device 100 from its locked state, the smart lock 200 uses the unlock result or the fingerprint or facial data used for unlocking to unlock it. Furthermore, the terminal device 100 may prompt the user to click to enter the relevant application for unlocking the smart lock 200 (e.g., ...). Figure 4D The "Unlock" application 421 displayed on the user interface 420 is used to manually complete the unlocking process. For example, as shown... Figure 4E As shown, when the user clicks to enter Figure 4D After the "unlock" application 421 is shown, the terminal device 100 can detect the user's targeting of the application. Figure 4E Clicking the "Unlock" option 431 displayed on the user interface 430 will, in response to this action, allow the terminal device 100 to notify the smart lock 200 to unlock based on the aforementioned short-range wireless communication connection.
[0181] In this application embodiment, the term "device owner" can refer to the owner of the terminal device 100, or to other trusted users carrying the terminal device 100 (such as family members or friends of the owner of the terminal device 100).
[0182] In the embodiments of this application, "the terminal device 100 performs owner authentication based on multi-dimensional feature information" can refer to the terminal device 100 performing owner authentication using one or more of the above-mentioned methods 1, 2, 3, and 4.
[0183] It should be noted that the embodiments of this application are merely examples of the above four methods to illustrate the process of owner authentication based on multi-dimensional feature information, and are not limited to the above four methods. Other methods may also be used for owner authentication based on multi-dimensional feature information, and the embodiments of this application do not limit them.
[0184] Steps S312-S315 described above are optional. For example, in some embodiments, steps S312-S315 may not be performed, that is, step S316 and subsequent steps can be performed after step S311 is completed.
[0185] S317. Terminal device 100 sends an unlocking request to smart lock 200, wherein the unlocking request carries an unlocking instruction corresponding to the owner's identity authentication decision result.
[0186] Specifically, after completing the owner authentication and confirming that the owner authentication is successful (i.e., the owner authentication is successful), the terminal device 100 can send an unlocking request to the smart lock 200. This unlocking request carries an unlocking instruction corresponding to the owner authentication decision result. The unlocking instruction corresponding to the aforementioned owner authentication decision result is used to instruct the user carrying the terminal device 100 to pass the owner authentication.
[0187] Based on the above unlocking request, S318 and smart lock 200 confirm that the owner's identity authentication is successful and obtain the unlocking result.
[0188] Specifically, after receiving the unlocking request sent by the terminal device 100, the smart lock 200 can confirm that the user carrying the terminal device 100 has passed the owner authentication based on the unlocking instruction corresponding to the owner authentication decision result carried in the unlocking request. Thus, the smart lock 200 obtains the unlocking result, which is used to instruct the smart lock 200 to perform the unlocking action.
[0189] In some embodiments, if the terminal device 100 completes owner authentication but confirms that the owner authentication failed (i.e., the owner authentication failed), the terminal device 100 may also send an unlocking request to the smart lock 200. This unlocking request carries an unlocking instruction corresponding to the owner authentication decision result. The unlocking instruction corresponding to the owner authentication decision result indicates that the user carrying the terminal device 100 has failed owner authentication. After receiving the unlocking request from the terminal device 100, the smart lock 200 can confirm, based on the unlocking instruction corresponding to the owner authentication decision result, that the user carrying the terminal device 100 has failed owner authentication. Thus, the smart lock 200 obtains an unlocking result, which indicates that the smart lock 200 does not need to perform an unlocking action. In this case, the terminal device 100 can repeat steps S316-S317 until the owner authentication is successful, at which point the smart lock 200 can perform the unlocking action. However, for security reasons, a threshold number of failed authentication attempts can be set (e.g., the threshold can be set to 3 or 5 times). When the number of failed authentication attempts reaches the threshold, the smart lock 200 can stop responding to the unlocking request sent by the terminal device 100 and enter a locked state. At this time, the smart lock 200 cannot perform the unlocking action under the instruction of the terminal device 100. The user may only be able to unlock the smart lock 200 through other external unlocking objects (e.g., physical keys). This can prevent brute-force attacks by unauthorized users and improve the security of the smart lock 200.
[0190] S319 and smart lock 200 execute the unlocking action and complete the unlocking.
[0191] Specifically, after obtaining the unlocking result, the smart lock 200 can determine whether to perform the unlocking action based on the unlocking result. If the unlocking result indicates that the smart lock 200 can perform the unlocking action, then the smart lock 200 performs the unlocking action and completes the unlocking, that is, the smart lock 200 switches from the locked state to the unlocked state. If the unlocking result indicates that the smart lock 200 does not need to perform the unlocking action, then the smart lock 200 does not perform the unlocking action and remains in the locked state.
[0192] In some embodiments, after obtaining the unlocking result, the smart lock 200 can convert the unlocking result into an electrical pulse signal, wherein the electrical pulse signal is used to trigger the smart lock 200 to perform an unlocking action. For example, if the unlocking result indicates that the smart lock 200 can perform an unlocking action, the smart lock 200 can convert the unlocking result into a high-level signal, and then the high-level signal can trigger the smart lock 200 to perform an unlocking action to complete the unlocking; if the unlocking result indicates that the smart lock 200 does not need to perform an unlocking action, the smart lock 200 can convert the unlocking result into a low-level signal, and then the low-level signal cannot trigger the smart lock 200 to perform an unlocking action, that is, the smart lock 200 does not perform an unlocking action.
[0193] It should be noted that this application embodiment only uses terminal device 100 as an example to describe the process of terminal device 100 instructing smart lock 200 to perform unlocking operation (i.e., the unlocking stage). The process of other terminal devices (such as terminal devices that have established a binding relationship with smart lock 200 through authorization by terminal device 100) instructing smart lock 200 to perform unlocking operation can also refer to the relevant content of the above steps S311-S319, and will not be repeated here.
[0194] In some embodiments, users can customize the time period during which the unlocking method provided in the unlocking phase described above can be used to open the smart lock 200. For example, when the smart lock 200 is a home door lock, during weekdays (Monday to Friday), users can set it so that the unlocking method provided in the unlocking phase described above can be used to open the smart lock 200 only for a certain period after get off work each day (e.g., within one hour after get off work); on weekends, users can set it so that the unlocking method provided in the unlocking phase described above can be used to open the smart lock 200 on both weekends; when away on a long business trip and no one is home, users can set it so that the unlocking method provided in the unlocking phase described above cannot be used to open the smart lock 200 during the entire business trip.
[0195] Phase Three: Unbinding Relationship Phase
[0196] S320, terminal device 100 and smart lock 200 re-establish short-range wireless communication connection.
[0197] Step S320 is executed when the short-range wireless communication connection previously established between the terminal device 100 and the smart lock 200 is broken.
[0198] S321-S322, Terminal device 100 receives an operation from the user to unbind terminal device 100 from smart lock 200. In response to this operation, terminal device 100 sends unbinding request 1 to smart lock 200, wherein the unbinding request 1 carries the identification information, key information, etc. of terminal device 100.
[0199] In some embodiments, the above-mentioned unbinding request 1 may also carry only the identification information of the terminal device 100.
[0200] S323, Smart Lock 200 deletes the identification information and key information of Terminal Device 100.
[0201] Specifically, after receiving the aforementioned unbinding request 1 sent by the terminal device 100, the smart lock 200 can delete the identification information and key information of the terminal device 100 based on the identification information and key information of the terminal device 100 carried in the unbinding request 1.
[0202] In some embodiments, if the above-mentioned unbinding request 1 only carries the identification information of the terminal device 100, the smart lock 200 can find the key information associated with the identification information of the terminal device 100 based on the identification information of the terminal device 100, and delete the identification information of the terminal device 100 and the key information associated with the identification information of the terminal device 100 together.
[0203] S324. The smart lock 200 sends a request to the terminal device 100 to unbind the relationship 2, wherein the request to unbind the relationship 2 carries the identification information and key information of the smart lock 200.
[0204] In some embodiments, the above-mentioned unbinding request 2 may also carry only the identification information of the smart lock 200.
[0205] It should be noted that in some embodiments, step S324 may also be executed before step S323. That is, the smart lock 200 may first send a request to the terminal device 100 to unbind the relationship, and then delete the identification information and key information of the terminal device 100. This application embodiment does not limit this.
[0206] S325. Terminal device 100 deletes the identification information and key information of smart lock 200.
[0207] Specifically, after receiving the above-mentioned unbinding request 2 sent by the smart lock 200, the terminal device 100 can delete the identification information and key information of the smart lock 200 based on the identification information and key information of the smart lock 200 carried in the above-mentioned unbinding request 2.
[0208] In some embodiments, if the above-mentioned unbinding request 2 only carries the identification information of the smart lock 200, the terminal device 100 can find the key information associated with the identification information of the smart lock 200 based on the identification information of the smart lock 200, and delete the identification information of the smart lock 200 and the key information associated with the identification information of the smart lock 200 together.
[0209] S326. The terminal device 100 and the smart lock 200 are unbound.
[0210] Specifically, after completing steps S321-S325, the terminal device 100 is unbound from the smart lock 200.
[0211] It should be noted that this application embodiment only uses terminal device 100 as an example to illustrate the unbinding relationship stage. The specific steps of other terminal devices (such as terminal devices that establish a binding relationship with smart lock 200 through authorization of terminal device 100) to unbind from smart lock 200 can also refer to the relevant content of steps S321-S326 above, and will not be repeated here.
[0212] This application provides an unlocking method whereby a terminal device can establish a binding relationship with a smart lock via a short-range wireless communication connection (such as NFC or Bluetooth). The terminal device can then authenticate the owner's identity based on multi-dimensional feature information. After successful authentication, the terminal device can unlock the smart lock. With this unlocking method, the terminal device can unlock the bound smart lock without requiring the user to actively perform the unlocking operation, achieving a passive and seamless unlocking effect, simplifying user operation and improving user experience. Furthermore, the terminal device's ability to authenticate the owner's identity based on multi-dimensional feature information enhances unlocking reliability and security. Simultaneously, the smart lock does not need to process multi-dimensional feature information, reducing the computational performance requirements of the smart lock.
[0213] The following describes the process of another unlocking method provided in the embodiments of this application.
[0214] Figure 5 The flowchart of another unlocking method provided in the embodiments of this application is illustrated by way of example.
[0215] like Figure 5 As shown, this unlocking method can be applied to unlocking systems that include terminal device 100 and smart lock 200. The specific steps of this method are described in detail below:
[0216] S501, Terminal device 100 establishes a short-range wireless communication connection with smart lock 200.
[0217] The specific execution process of step S501 can be referred to the above. Figure 3 The relevant content in step S301 of the illustrated embodiment will not be repeated here.
[0218] S502, Terminal device 100 and smart lock 200 establish a binding relationship.
[0219] The specific execution process of step S502 can be referred to the above. Figure 3 The relevant content in steps S302-S310 of the illustrated embodiment will not be repeated here.
[0220] S503, terminal device 100 and smart lock 200 perform trusted device binding relationship authentication.
[0221] The specific execution process of step S503 can be referred to the above. Figure 3 The relevant content in steps S312-S315 of the illustrated embodiment will not be repeated here.
[0222] It should be noted that step S403 is optional. For example, in some embodiments, step S503 may not be executed, that is, subsequent steps S504-S506 can be executed after step S502 is completed.
[0223] S504. The terminal device 100 performs owner authentication based on multi-dimensional feature information to determine whether the user currently carrying the terminal device 100 is the owner.
[0224] Specifically, after the terminal device 100 performs owner authentication based on multi-dimensional feature information, if it determines that the user currently carrying the terminal device 100 is the owner (i.e., the determination is successful), the terminal device 100 can send an unlocking request to the smart lock 200. This unlocking request is used to instruct the smart lock 200 to execute step S506. If it determines that the user currently carrying the terminal device 100 may not be the owner (i.e., the determination fails), the terminal device 100 can execute step S505.
[0225] The specific execution process of the terminal device 100 performing the owner authentication can be referred to the aforementioned. Figure 3 The relevant content in step S316 of the illustrated embodiment will not be repeated here.
[0226] S505, Terminal device 100 prompts the user to unlock terminal device 100 using methods such as lock screen password / face recognition / fingerprint recognition.
[0227] Specifically, when the terminal device 100 is in a locked state, if the terminal device 100 determines that the user currently carrying the terminal device 100 may not be the owner (i.e., the determination fails), the terminal device 100 can prompt the user to unlock the terminal device 100 using a lock screen password / face recognition / fingerprint recognition or other methods. If the user successfully unlocks the terminal device 100, the terminal device 100 can send an unlock request to the smart lock 200, which instructs the smart lock 200 to execute step S506.
[0228] In some embodiments, when the terminal device 100 is in an unlocked state, if the terminal device 100 determines that the user currently carrying the terminal device 100 may not be the owner (i.e., the determination fails), the terminal device 100 can automatically enter a locked state. Then, the terminal device 100 can prompt the user to unlock the terminal device 100 using a lock screen password, facial recognition, fingerprint recognition, or other methods. If the user successfully unlocks the terminal device 100, the terminal device 100 can send an unlock request to the smart lock 200, which instructs the smart lock 200 to execute step S506.
[0229] Optionally, when the terminal device 100 is in an unlocked state, if the terminal device 100 determines that the user currently carrying the terminal device 100 may not be the owner (i.e., the determination fails), the terminal device 100 may not enter the lock screen state, but instead prompt the user to authenticate their identity by entering a password or recognizing a face, fingerprint, or other means. If the authentication is successful, the terminal device 100 can send an unlock request to the smart lock 200, which is used to instruct the smart lock 200 to execute step S506.
[0230] In some embodiments, such as Figures 4B-4E The method shown prompts the user to complete the unlocking process.
[0231] S506, smart lock 200 executes the unlocking action and completes the unlocking.
[0232] Specifically, when the terminal device 100 determines that the user currently carrying the terminal device 100 is the owner through owner authentication (i.e., the determination is successful), or when the user currently carrying the terminal device 100 successfully unlocks the terminal device 100 through methods such as lock screen password / face recognition / fingerprint recognition, the smart lock 200 can execute the unlocking action after receiving the unlocking request from the terminal device 100, and complete the unlocking, that is, the smart lock 200 switches from the locked state to the unlocked state.
[0233] The specific execution process of step S506 can be referred to the above. Figure 3 The relevant content in steps S318-S319 of the illustrated embodiment will not be repeated here.
[0234] The above unlocking method is applied to scenarios where terminal device 100 uses implicit authentication to unlock smart lock 200. Below, we introduce another unlocking method. This method is applied to scenarios where terminal device 100 uses implicit authentication to complete authentication-required transactions such as login and payment in applications (e.g., shopping applications, payment applications). This eliminates the need for repeated explicit authentication when a user performs login or payment transactions, improving user experience while ensuring security.
[0235] The following describes the process of another unlocking method provided in the embodiments of this application.
[0236] Figure 6 The flowchart of another unlocking method provided in the embodiments of this application is illustrated by way of example.
[0237] like Figure 6 As shown, this method can be applied to terminal device 100, which may include: an application, a face authentication service module, a latent authentication service module, a Swing service module, an application TA, a face authentication TA, a latent authentication TA, and a Swing computation module. The specific steps of this method are described in detail below:
[0238] Phase 1: Conducting Continuous Implicit Authentication
[0239] S601-S603, the face authentication service module of terminal device 100 detects that explicit authentication is successful and sends the authentication success result to the face authentication TA. The face authentication TA saves the authentication success result and records the authentication success time.
[0240] Specifically, the face authentication service module of terminal device 100 can detect successful explicit authentication. For example, when terminal device 100 is initially in a locked screen state and detects a user performing an explicit authentication operation (such as face authentication), in response to this operation, terminal device 100 can determine whether the explicit authentication was successful. If the explicit authentication is successful, terminal device 100 unlocks and enters normal use mode. Afterwards, the face authentication service module can send an authentication success result to the face authentication TA. After receiving the authentication success result, the face authentication TA can save the authentication success result for a period of time (e.g., 3 seconds, 5 seconds, etc.) and record the moment of authentication success.
[0241] In this embodiment of the application, explicit authentication is taken as face authentication. Therefore, the terminal device 100 may include a face authentication service module and a face authentication TA.
[0242] In some embodiments, explicit authentication can also be fingerprint authentication. Therefore, the terminal device 100 may also include a fingerprint authentication service module and a fingerprint authentication TA.
[0243] S604, the face authentication service module of terminal device 100 sends an instruction to start implicit authentication to the implicit authentication service module.
[0244] Specifically, after executing steps S601-S603, the face authentication service module of the terminal device 100 can send an instruction to start implicit authentication to the implicit authentication service module.
[0245] Before executing step S604, the user needs to enable the implicit authentication function on the terminal device 100. Only then can the terminal device 100 execute step S604 and subsequent steps to complete the implicit authentication. Possible ways for the user to enable the implicit authentication function may include, but are not limited to, the following two:
[0246] Method 1: Enable the hidden authentication function uniformly in the "Settings" application.
[0247] like Figure 7A As shown, terminal device 100 can display a user interface 710 for showcasing applications on terminal device 100.
[0248] Terminal device 100 can detect user actions (e.g., clicks) on the "Settings" application icon 711, and in response to these actions, terminal device 100 can display, for example... Figure 7B The user interface 720 of the "Settings" application shown may include multiple menu options (such as "Airplane Mode", "Mobile Network", etc.).
[0249] For example, an implicit authentication management option 721 may be added to the embodiments of this application.
[0250] Terminal device 100 can detect user actions (e.g., clicks) on implicit authentication management option 721, and in response to such actions, terminal device 100 can display, for example... Figure 7C The user interface 730 shown may include a title 731 (e.g., "Hidden Authentication Management") and a return label next to the title, as well as an option name 732 (e.g., "Allow Hidden Authentication Function") and an option enable label 733. When the terminal device 100 detects that the user clicks or touches the enable label corresponding to the option name, the function corresponding to the option name is enabled or disabled.
[0251] For example, terminal device 100 can detect user actions (e.g., clicks) on tag 733, and in response to such actions, terminal device 100 can enable implicit authentication.
[0252] In this way, users can use implicit authentication to complete security and privacy-related operations such as login and payment on applications installed on terminal device 100. That is to say, only after the implicit authentication function is enabled can terminal device 100 execute step S604 and subsequent steps to complete implicit authentication.
[0253] Alternatively, the implicit authentication management option 721 can also be a sub-option of menu options such as "Account" and "Security & Privacy" in the user interface 720 of the "Settings" application.
[0254] Method 2: Enable implicit authentication in specific applications (such as shopping applications, payment applications, etc.).
[0255] After enabling implicit authentication in a specific application, terminal device 100 can only perform implicit authentication in that specific application and cannot perform implicit authentication in other applications.
[0256] Taking enabling implicit authentication on a payment application as an example, such as... Figure 7D As shown, the user interface 740 displayed on the terminal device 100 can be the main interface of the payment application.
[0257] Terminal device 100 can detect user actions (e.g., clicks) on the "My" option 741, and in response to these actions, terminal device 100 can display, for example... Figure 7E The user interface 750 corresponding to the “My” option shown may include multiple menu options (such as “Bills”, “Balance”, etc.).
[0258] For example, an implicit authentication management option 751 may be added to the embodiments of this application.
[0259] Terminal device 100 can detect user actions (e.g., clicks) on implicit authentication management option 751, and in response to these actions, terminal device 100 can display, as shown below. Figure 7F The user interface 760 shown may include a title 761 (e.g., "Hidden Authentication Management") and a return label next to the title, as well as an option name 762 (e.g., "Allow Hidden Authentication Function") and an option enable label 763. When the terminal device 100 detects that the user clicks or touches the enable label corresponding to the option name, the function corresponding to the option name is enabled or disabled.
[0260] For example, terminal device 100 can detect user actions (e.g., clicks) on tag 763, and in response to such actions, terminal device 100 can enable implicit authentication.
[0261] In this way, users can use implicit authentication to complete security and privacy-related operations such as login and payment on the payment application. That is to say, after the implicit authentication function is enabled, the terminal device 100 can execute step S604 and subsequent steps to complete implicit authentication.
[0262] Optionally, the implicit authentication management option 751 can also be a sub-option of the menu options such as "Bank Card" and "Settings" in the user interface 750 corresponding to the "My" option.
[0263] In some embodiments, if the terminal device 100 is not performing implicit authentication for the first time, the face authentication service module of the terminal device 100 may send a reset implicit authentication instruction to the implicit authentication service module.
[0264] In some embodiments, the terminal device 100 may execute step S604 first, and then execute steps S602-S603 after executing step S601, or execute steps S602-S603 and step S604 simultaneously. The embodiments of this application do not limit the order of executing steps S602-S603 and step S604.
[0265] S605-S609, the implicit authentication service module of terminal device 100 sends an initial face tracking execution command to the Swing service module. The Swing service module calls the camera to capture the initial face image of Swing and sends the initial face image of Swing to the Swing calculation module. After that, the Swing calculation module saves the initial face image of Swing and sends an initial face tracking completion command to the implicit authentication service module.
[0266] Specifically, after receiving the implicit authentication start command from the face authentication service module, the implicit authentication service module of terminal device 100 can send an initial face tracking execution command to the Swing service module. This command instructs the Swing service module to perform this face tracking initialization. Upon receiving this initial face tracking execution command, the Swing service module can use a camera (e.g., a Swing camera) to capture an initial face image and send it to the Swing computation module. Upon receiving the initial face image, the Swing computation module can save it, thus completing the face tracking initialization. Afterward, the Swing computation module can send an initial face tracking completion command to the implicit authentication service module, instructing it to perform subsequent steps.
[0267] In one possible implementation, the Swing operation module sends an initialization face tracking completion instruction to the implicit authentication service module. Specifically, the Swing operation module first sends the initialization face tracking completion instruction to the Swing service module, and then the Swing service module sends the initialization face tracking completion instruction to the implicit authentication service module.
[0268] The Swing computing module executes related algorithms using a TinyNeural-network Processing Unit (TinyNPU), which has ultra-low power consumption and can run continuously in a secure environment.
[0269] S610-S614, the implicit authentication service module of terminal device 100 sends an explicit authentication result verification instruction to the implicit authentication TA, the implicit authentication TA sends an explicit authentication result trusted query instruction to the face authentication TA, the face authentication TA sends the authentication success result and authentication success time to the implicit authentication TA, the implicit authentication TA confirms the explicit authentication success and saves the authentication success time, and then the implicit authentication TA sends an explicit authentication success confirmation instruction to the implicit authentication service module.
[0270] Specifically, after receiving the initialization face tracking completion instruction sent by the Swing operation module, the implicit authentication service module of the terminal device 100 can send an explicit authentication result verification instruction to the implicit authentication TA. This instruction instructs the implicit authentication TA to verify the explicit authentication result. After receiving the explicit authentication result verification instruction, the implicit authentication TA can send an explicit authentication result trust query instruction to the face authentication TA. This instruction instructs the face authentication TA to send the explicit authentication result to the implicit authentication TA. After receiving the explicit authentication result trust query instruction, since the face authentication TA's retention time for the authentication success result in step S603 is limited (i.e., the authentication success result is only retained for a short period of time), if the face authentication TA sends the authentication success result and the recorded authentication success time saved in step S603 to the implicit authentication TA, the implicit authentication TA can confirm the explicit authentication success and save the authentication success time. Otherwise, the implicit authentication TA can confirm the explicit authentication failure and will not execute all subsequent steps.
[0271] In this embodiment of the application, the purpose of the terminal device 100 first executing steps S604-S609 (i.e., starting and completing the face tracking initialization process) and then executing steps S610-S614 (i.e., the process of reliably querying the explicit authentication result) is to prevent the Swing service from being hijacked and the implicit authentication from starting too late.
[0272] S615-S618, the implicit authentication service module of terminal device 100 sends a command to start face tracking to the Swing service module. The Swing service module calls the camera to capture a Swing-tracked face image and sends the Swing-tracked face image to the Swing calculation module. Then, the Swing calculation module performs face tracking calculation based on the Swing-tracked face image to obtain the face tracking result.
[0273] Specifically, after receiving the confirmation instruction from the implicit authentication TA confirming successful explicit authentication, the implicit authentication service module of terminal device 100 can send a start face tracking instruction to the Swing service module. This instruction instructs the Swing service module to initiate the face tracking process. Upon receiving this start face tracking instruction, the Swing service module can use a camera (e.g., a Swing camera) to capture Swing-tracked face images. Capturing these images can be periodic, with a preset capture period (e.g., 1 second, 2 seconds, etc.). Each time a Swing-tracked face image is captured, the Swing service module sends it to the Swing computation module. Upon receiving the Swing-tracked face image, the Swing computation module performs face tracking calculations based on it to obtain the face tracking result. Each captured Swing-tracked face image can be referred to as the first image, and the total number of first images captured during the entire face tracking process can be N, where N is a positive integer.
[0274] The Swing operation module performs face tracking calculations based on the Swing-tracked face image to obtain the face tracking result. The specific execution process is as follows:
[0275] The Swing operation module can match each received Swing-tracked face image with the pre-saved Swing initial face image. If the match is successful every time, it means that the face tracking is successful; if the match fails once, it means that the face tracking has failed. Alternatively, if the Swing operation module does not receive a Swing-tracked face image within a certain period of time (e.g., 1 second, 2 seconds, etc.), it also means that the face tracking has failed.
[0276] If face tracking is successful, the Swing operation module can obtain face tracking result 1 (also known as the first face tracking result), which may include information indicating that face tracking was successful (such as the word "True").
[0277] If face tracking fails, the Swing operation module can obtain face tracking result 2, which may include information indicating face tracking failure (such as the word "False").
[0278] If the Swing runtime module confirms that face tracking has failed, it can stop performing face tracking calculations and notify the implicit authentication service module of the face tracking failure via the Swing service module, requiring a restart of face tracking. Afterward, the implicit authentication service module can continue to execute step S615 to instruct the Swing service module and the Swing computation module to continue face tracking.
[0279] Phase Two: Obtaining Implicit Authentication Results
[0280] S619, The application of terminal device 100 detects that the user has performed an operation to enter the application.
[0281] Specifically, the application of the terminal device 100 (such as a shopping application, a payment application, etc.) can detect the user's entry into the application. In response to the operation, the application can execute step S620, which instructs other modules of the terminal device 100 to complete the subsequent implicit authentication steps.
[0282] In some embodiments, step S619 is optional, that is, step S620 and subsequent steps can be performed after step S618 is completed.
[0283] S620-S624, the application of terminal device 100 sends a pre-acquisition implicit authentication result instruction to the implicit authentication service module. The implicit authentication service module sends a face image comparison instruction to the Swing service module. The Swing service module calls the camera to capture the Swing authentication face image and sends the Swing authentication face image and face image comparison request to the Swing computing module. Then, the Swing computing module compares the Swing initial face image and the Swing authentication face image to obtain the face comparison result.
[0284] Specifically, after detecting that a user has entered the application, the application of terminal device 100 can send a pre-acquisition implicit authentication result instruction to the implicit authentication service module. This instruction instructs other modules of terminal device 100 to pre-complete the face comparison process in the implicit authentication process. Upon receiving this pre-acquisition implicit authentication result instruction, the implicit authentication service module can send a face image comparison instruction to the Swing service module. This instruction instructs the Swing service module to initiate the face image comparison process. Upon receiving the face image comparison instruction, the Swing service module can use a camera (e.g., a Swing camera) to capture a Swing authentication face image (also known as a second image) and send the Swing authentication face image and face image comparison request to the Swing computing module. This request instructs the Swing computing module to complete the face image comparison based on the Swing authentication face image. Upon receiving the Swing authentication face image and face image comparison request, the Swing computing module can compare the Swing initial face image and the Swing authentication face image to obtain the face comparison result.
[0285] The Swing operation module compares the initial Swing face image with the Swing certified face image to obtain the face comparison result. The specific execution process is as follows:
[0286] The Swing operation module can compare the received Swing certified face image with the pre-saved Swing initial face image. If the comparison is successful, it means that the face comparison is successful and a face comparison result 1 (also known as the first face comparison result) is obtained. The face tracking result 1 can include information indicating that the face comparison is successful (such as the word "True"). If the comparison fails, it means that the face comparison fails and a face comparison result 2 is obtained. The face tracking result 2 can include information indicating that the face comparison fails (such as the word "False").
[0287] In some embodiments, the face comparison process described above can also be performed by the face service module and the face authentication TA, but the power consumption may be relatively high. Specifically, the application of the terminal device 100 can send a pre-obtain implicit authentication result instruction to the face authentication service module. After receiving the pre-obtain implicit authentication result instruction, the face authentication service module can call the camera to capture an authentication face image and compare the authentication face image with the face images pre-recorded in the system to obtain the face comparison result. Then, the face comparison result can be sent to the face authentication TA, which can save the face comparison result for subsequent use by the terminal device 100 to complete the implicit authentication process.
[0288] S625, The application of terminal device 100 detects that the user is performing an operation that requires authentication.
[0289] Specifically, the application of the terminal device 100 (such as a shopping application, a payment application, etc.) can detect when a user performs an operation that requires authentication (such as login, payment, etc.). In response to this operation, the application can execute step S626, which instructs other modules of the terminal device 100 to complete the subsequent implicit authentication steps.
[0290] S626, The application of terminal device 100 sends a command to the Swing computing module to obtain the implicit authentication result.
[0291] Specifically, after detecting that a user has performed an operation that requires authentication, the application of the terminal device 100 can send a command to the Swing computing module to obtain the implicit authentication result. This command is used to instruct other modules of the terminal device 100 to send the implicit authentication result (such as face tracking result, face comparison result, etc.) to the application.
[0292] The application of terminal device 100 can send a command to the Swing computing module to obtain the implicit authentication result in the following two ways, including but not limited to:
[0293] Method 1: The application on terminal device 100 can first send a command to application TA to obtain the implicit authentication result. Then, application TA can send the same command to implicit authentication TA. Finally, implicit authentication TA can send the same command to the Swing computing module. Since both application TA and implicit authentication TA run in a Trusted Execution Environment (TEE), this method offers high security.
[0294] Method 2: The application of terminal device 100 can first send a command to the implicit authentication service module to obtain the implicit authentication result. Then, the implicit authentication service module can send the command to the implicit authentication TA. Subsequently, the implicit authentication TA can send the command to the Swing operation module. Since the implicit authentication service module is at the system layer, there is no need to develop an application TA. Therefore, this method can reduce development costs and is easy to integrate.
[0295] S627, the Swing computing module of the terminal device 100 sends the face tracking result and face comparison result to the implicit authentication TA.
[0296] Specifically, after receiving the instruction to obtain the implicit authentication result, the Swing computing module of the terminal device 100 can send the face tracking result and the face comparison result to the implicit authentication TA.
[0297] The face tracking result is the face tracking result obtained by the terminal device 100 in step S618, and the face comparison result is the face comparison result obtained by the terminal device 100 in step S624.
[0298] S628-S629, the implicit authentication TA of terminal device 100 calculates the implicit authentication duration based on the already saved authentication success time. After that, the implicit authentication TA sends the face tracking result, face comparison result, and implicit authentication duration to the application.
[0299] Specifically, after receiving the face tracking result and face comparison result sent by the Swing computing module, the implicit authentication TA of the terminal device 100 can first calculate the implicit authentication duration based on the authentication success time already saved in step S613. The implicit authentication duration can be the time interval between the previously saved authentication success time and the implicit authentication TA receiving the face tracking result and face comparison result sent by the Swing computing module.
[0300] After calculating the implicit authentication duration, the implicit authentication TA can send the face tracking results, face comparison results, and implicit authentication duration to the application.
[0301] Optionally, the implicit authentication TA can also send the explicit authentication success result sent by the face authentication TA to the implicit authentication TA in step S612 to the application.
[0302] In some embodiments, the implicit authentication TA sending face tracking results, face comparison results, and implicit authentication duration to the application may specifically include: the implicit authentication TA first sending face tracking results, face comparison results, and implicit authentication duration to the implicit authentication service module, and then the implicit authentication service module sending the face tracking results, face comparison results, and implicit authentication duration to the application.
[0303] The S630 and terminal device 100 applications confirm successful implicit authentication based on face tracking results, face comparison results, and implicit authentication duration.
[0304] Specifically, after receiving the face tracking result, face comparison result, and implicit authentication duration sent by the implicit authentication TA, the application of the terminal device 100 can confirm whether the implicit authentication was successful based on the face tracking result, face comparison result, and implicit authentication duration.
[0305] The application can confirm the success or failure of face tracking through face tracking results, the success or failure of face comparison through face comparison results, and the validity of implicit authentication by judging whether the implicit authentication duration is less than the preset implicit authentication duration (also known as the second time threshold). If it is, it is valid; if not, it is invalid.
[0306] The aforementioned preset implicit authentication duration can be either the default value of the terminal device or a value set by the user.
[0307] The application can confirm the success of implicit authentication if face tracking is successful, face comparison is successful, and the implicit authentication duration is valid.
[0308] Optionally, for some application scenarios with relatively low security requirements, the application can also confirm the success of the implicit authentication if the face tracking is successful, the face comparison is successful, and / or the implicit authentication duration is valid.
[0309] Optionally, the application can also confirm the success of the previous explicit authentication based on the face tracking result, face comparison result, and implicit authentication duration, if the previous explicit authentication was successful. If so, the application can proceed with the next steps.
[0310] Alternatively, step S630 can also be executed via an application server, which offers greater security.
[0311] S631, the application of terminal device 100 completes the execution of business that requires authentication.
[0312] Specifically, once the application on terminal device 100 confirms the success of the implicit authentication, the application can complete the business that requires authentication. The user does not need to perform explicit authentication again. While ensuring security, this reduces the number of times the user needs to perform explicit authentication, thus improving the user experience.
[0313] In some embodiments, when the terminal device 100 detects that a user has performed an operation to enter an application, if the application requires user authentication before entry, the terminal device 100 may automatically execute step S627 (i.e., automatically return the face tracking result and face comparison result) and subsequent steps after completing step S624. After the terminal device 100 confirms that the implicit authentication is successful, the user can enter the application.
[0314] It should be understood that the execution Figure 6 The terminal device 100 shown is merely an example, and the terminal device 100 may have more than Figure 6 The more or fewer components shown can be combined into two or more components, or they can have different component configurations. Execution Figure 6 The various components of the terminal device 100 of the method shown can be implemented in hardware, software, or a combination of hardware and software.
[0315] The following describes the process of another unlocking method provided in the embodiments of this application.
[0316] Figure 8 The flowchart of another unlocking method provided in the embodiments of this application is illustrated by way of example.
[0317] like Figure 8 As shown, this unlocking method can be applied to terminal device 100. The specific steps of this method are described in detail below:
[0318] S801 and terminal device 100 confirm the success of the first explicit authentication and record the moment of the first explicit authentication success.
[0319] Optionally, the terminal device 100 may also save the initial explicit authentication success result, or it may save the authentication information used for the initial explicit authentication (such as facial or fingerprint information, collectively referred to as third authentication information). The retention period (also called the authentication cycle) for the initial explicit authentication success result or authentication information can be the default setting of the terminal device 100 (e.g., 3 seconds, 10 seconds, etc.) or a user-defined setting. If the timeout occurs, the terminal device 100 may automatically delete the initial explicit authentication success result or authentication information.
[0320] For example, Figures 9A-9B This is a possible user interface diagram illustrating how users can set authentication periods. For example... Figure 9A As shown, Figure 9A This is the user interface 910 displayed by terminal device 100 after enabling the implicit authentication function. Terminal device 100 can detect the user's operation (e.g., a click) on the "More Settings" option 914, and in response to this operation, terminal device 100 can display, as shown below. Figure 9B The user interface 920 shown allows users to customize the authentication period. For example, the terminal device 100 can default to an initial authentication period of 3 seconds, and users can change the default authentication period by selecting other authentication period options, thus enabling them to customize the authentication period.
[0321] The specific execution process of step S801 can be referred to the above. Figure 6 The relevant content in steps S601-S603 and steps S610-S614 in the illustrated embodiment will not be repeated here.
[0322] S802, Terminal device 100 initiates implicit authentication.
[0323] Specifically, after confirming the success of the first explicit authentication, and within the aforementioned authentication period (or the first time threshold), the terminal device 100 can initiate implicit authentication.
[0324] The implicit authentication process may include face tracking, face comparison, and other procedures. Specific details regarding the execution of the implicit authentication process can be found in the aforementioned documentation. Figure 6 The relevant content in steps S604-S624 of the illustrated embodiment will not be repeated here.
[0325] In some embodiments, if the terminal device 100 detects that the user has performed a screen lock operation during the implicit authentication process, in response to the operation, the terminal device 100 may interrupt the implicit authentication process and automatically restart implicit authentication after the terminal device 100 is unlocked again.
[0326] In other embodiments, if the terminal device 100 detects that the user performs an operation to switch applications or return to the main interface during the implicit authentication process, in response to this operation, the terminal device 100 may automatically continue the implicit authentication process, or the terminal device 100 may interrupt the implicit authentication process and display... Figure 9C The exemplary pop-up interface 930 shown is used to prompt the user whether to continue performing implicit authentication. If the terminal device 100 detects the user's operation on option 931, the terminal device 100 can continue performing implicit authentication in response to the operation.
[0327] It should be noted that the stealth authentication function can be applied to specific applications or across different applications; no specific limitations are made here.
[0328] S803, Terminal device 100 detects that the user is performing an operation that requires authentication.
[0329] The specific execution process of step S803 can be referred to the above. Figure 6 The relevant content in step S625 of the illustrated embodiment will not be repeated here.
[0330] S804. The terminal device 100 obtains the implicit authentication result and confirms whether the implicit authentication was successful based on the implicit authentication result. If it is successful, the terminal device 100 executes step S806; if it is not successful, the terminal device 100 executes step S805.
[0331] Specifically, after detecting that a user has performed an operation that requires authentication, the terminal device 100 can obtain an implicit authentication result in response to the operation. The implicit authentication result may include face tracking result, face comparison result, implicit authentication duration, etc. Then, the terminal device 100 can confirm whether the implicit authentication was successful based on the implicit authentication result. If it is successful, the terminal device 100 executes step S806; if it is not successful, the terminal device 100 executes step S805.
[0332] The specific execution process of the terminal device 100 obtaining the implicit authentication result and confirming whether the implicit authentication was successful based on the implicit authentication result can be referred to the aforementioned. Figure 6 The relevant content in steps S626-S630 of the illustrated embodiment will not be repeated here.
[0333] In some embodiments, after confirming the success of the implicit authentication, the terminal device 100 can further confirm the success of the first explicit authentication based on the result of the first explicit authentication. If successful, step S806 is executed; otherwise, step S805 is executed. This ensures that the user can complete the required authentication process only if both implicit and explicit authentication are successful, thus improving security.
[0334] In other embodiments, after confirming the success of the implicit authentication, the terminal device 100 can further authenticate based on the authentication information used for the first explicit authentication (such as facial or fingerprint information). For example, the terminal device 100 can match the facial image used for the first explicit authentication with a pre-recorded facial image. If the match is successful, the authentication is successful. After successful authentication, the terminal device 100 executes step S806; otherwise, it executes step S805. In this way, the user can only complete the required authentication process if both implicit and explicit authentication are successful, thus improving security.
[0335] Optionally, the result of successful implicit authentication can be used as the basis for executing step S806, or the result of successful first explicit authentication saved by the terminal device 100 in step S801, or the authentication information used for the first explicit authentication can be used as the basis for executing step S806.
[0336] S805, Terminal device 100 prompts the user to perform a second explicit authentication. If the authentication is successful, terminal device 100 executes step S806.
[0337] Specifically, if authentication fails, the terminal device 100 can prompt the user to perform a second explicit authentication, such as prompting the user to perform a second explicit authentication by entering a password, facial recognition, fingerprint recognition, etc. That is to say, the terminal device can collect fourth authentication information (such as the password entered by the user, fingerprint, facial image, etc.) and perform a second explicit authentication based on the fourth authentication information. If the explicit authentication is successful, the terminal device 100 can execute step S806.
[0338] S806, Terminal Equipment 100 completes the above-mentioned authentication-required business.
[0339] Specifically, if the terminal device 100 confirms the success of the implicit authentication or the success of the second explicit authentication, it can complete the aforementioned authentication-required business.
[0340] The structure of a terminal device 100 provided in the embodiments of this application is described below.
[0341] Figure 10 The structure of a terminal device 100 provided in an embodiment of this application is illustrated by way of example.
[0342] like Figure 10 As shown, the terminal device 100 may include: a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, a headphone jack 170D, a sensor module 180, buttons 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and a subscriber identification module (SIM) card interface 195, etc. The sensor module 180 may include a pressure sensor 180A, a gyroscope sensor 180B, a barometric pressure sensor 180C, a magnetic sensor 180D, an accelerometer sensor 180E, a distance sensor 180F, a proximity sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, etc.
[0343] It is understood that the structures illustrated in the embodiments of the present invention do not constitute a specific limitation on the terminal device 100. In other embodiments of this application, the terminal device 100 may include more or fewer components than illustrated, or combine some components, or split some components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.
[0344] Processor 110 may include one or more processing units, such as: application processor (AP), modem processor, graphics processing unit (GPU), image signal processor (ISP), controller, memory, video codec, digital signal processor (DSP), baseband processor, and / or neural network processing unit (NPU), etc. Different processing units may be independent devices or integrated into one or more processors.
[0345] The controller can serve as the central nervous system and command center of the terminal device 100. The controller can generate operation control signals based on the instruction opcode and timing signals to control the fetching and execution of instructions.
[0346] The processor 110 may also include a memory for storing instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. This memory can store instructions or data that the processor 110 has just used or that are used repeatedly. If the processor 110 needs to use the instruction or data again, it can retrieve it directly from the memory. This avoids repeated accesses, reduces the waiting time of the processor 110, and thus improves the efficiency of the system.
[0347] In some embodiments, the processor 110 may include one or more interfaces. Interfaces may include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface, etc.
[0348] The I2C interface is a bidirectional synchronous serial bus, including a serial data line (SDA) and a serial clock line (SCL). In some embodiments, the processor 110 may include multiple I2C buses. The processor 110 can couple to the touch sensor 180K, charger, flash, camera 193, etc., through different I2C bus interfaces. For example, the processor 110 can couple to the touch sensor 180K through the I2C interface, enabling the processor 110 and the touch sensor 180K to communicate through the I2C bus interface, thereby realizing the touch function of the terminal device 100.
[0349] The I2S interface can be used for audio communication. In some embodiments, the processor 110 may include multiple I2S buses. The processor 110 can be coupled to the audio module 170 via the I2S bus to enable communication between the processor 110 and the audio module 170. In some embodiments, the audio module 170 can transmit audio signals to the wireless communication module 160 via the I2S interface to enable the function of answering phone calls through a Bluetooth headset.
[0350] The PCM interface can also be used for audio communication, sampling, quantizing, and encoding analog signals. In some embodiments, the audio module 170 and the wireless communication module 160 can be coupled via the PCM bus interface. In some embodiments, the audio module 170 can also transmit audio signals to the wireless communication module 160 via the PCM interface, enabling the function of answering phone calls through a Bluetooth headset. Both the I2S interface and the PCM interface can be used for audio communication.
[0351] The UART interface is a universal serial data bus used for asynchronous communication. This bus can be a bidirectional communication bus. It converts the data to be transmitted between serial and parallel communication. In some embodiments, the UART interface is typically used to connect the processor 110 and the wireless communication module 160. For example, the processor 110 communicates with the Bluetooth module in the wireless communication module 160 via the UART interface to implement Bluetooth functionality. In some embodiments, the audio module 170 can transmit audio signals to the wireless communication module 160 via the UART interface to enable music playback through Bluetooth headphones.
[0352] The MIPI interface can be used to connect the processor 110 to peripheral devices such as the display screen 194 and the camera 193. The MIPI interface includes a camera serial interface (CSI) and a display serial interface (DSI). In some embodiments, the processor 110 and the camera 193 communicate via the CSI interface to enable the shooting function of the terminal device 100. The processor 110 and the display screen 194 communicate via the DSI interface to enable the display function of the terminal device 100.
[0353] The GPIO interface is configurable via software. It can be configured as a control signal or a data signal. In some embodiments, the GPIO interface can be used to connect the processor 110 to a camera 193, a display screen 194, a wireless communication module 160, an audio module 170, a sensor module 180, etc. The GPIO interface can also be configured as an I2C interface, an I2S interface, a UART interface, a MIPI interface, etc.
[0354] USB port 130 is a USB standard compliant interface, specifically a Mini USB port, Micro USB port, USB Type-C port, etc. USB port 130 can be used to connect a charger to charge terminal device 100, and can also be used for data transfer between terminal device 100 and peripheral devices. It can also be used to connect headphones for audio playback. This interface can also be used to connect other terminal devices, such as AR devices.
[0355] It is understood that the interface connection relationships between the modules illustrated in the embodiments of the present invention are merely illustrative and do not constitute a structural limitation on the terminal device 100. In other embodiments of this application, the terminal device 100 may also employ different interface connection methods or combinations of multiple interface connection methods as described in the above embodiments.
[0356] The charging management module 140 receives charging input from a charger. The charger can be a wireless charger or a wired charger. In some wired charging embodiments, the charging management module 140 receives charging input from the wired charger via the USB interface 130. In some wireless charging embodiments, the charging management module 140 receives wireless charging input via the wireless charging coil of the terminal device 100. While charging the battery 142, the charging management module 140 can also supply power to the terminal device 100 via the power management module 141.
[0357] The power management module 141 connects the battery 142, the charging management module 140, and the processor 110. The power management module 141 receives input from the battery 142 and / or the charging management module 140, providing power to the processor 110, internal memory 121, external memory, display screen 194, camera 193, and wireless communication module 160, etc. The power management module 141 can also monitor parameters such as battery capacity, battery cycle count, and battery health status (leakage current, impedance). In some other embodiments, the power management module 141 may also be located within the processor 110. In other embodiments, the power management module 141 and the charging management module 140 may be located in the same device.
[0358] The wireless communication function of the terminal device 100 can be implemented through antenna 1, antenna 2, mobile communication module 150, wireless communication module 160, modem processor and baseband processor, etc.
[0359] Antennas 1 and 2 are used to transmit and receive electromagnetic wave signals. Each antenna in terminal device 100 can be used to cover one or more communication frequency bands. Different antennas can also be multiplexed to improve antenna utilization. For example, antenna 1 can be multiplexed as a diversity antenna for a wireless local area network. In some other embodiments, the antennas can be used in conjunction with a tuning switch.
[0360] The mobile communication module 150 can provide solutions for wireless communication, including 2G / 3G / 4G / 5G, applied to the terminal device 100. The mobile communication module 150 may include at least one filter, switch, power amplifier, low noise amplifier (LNA), etc. The mobile communication module 150 can receive electromagnetic waves via antenna 1, and perform filtering, amplification, and other processing on the received electromagnetic waves before transmitting them to a modem processor for demodulation. The mobile communication module 150 can also amplify the signal modulated by the modem processor and convert it into electromagnetic waves for radiation via antenna 1. In some embodiments, at least some functional modules of the mobile communication module 150 may be housed in the processor 110. In some embodiments, at least some functional modules of the mobile communication module 150 and at least some modules of the processor 110 may be housed in the same device.
[0361] The modem processor may include a modulator and a demodulator. The modulator modulates the low-frequency baseband signal to be transmitted into a mid-to-high frequency signal. The demodulator demodulates the received electromagnetic wave signal into a low-frequency baseband signal. The demodulator then transmits the demodulated low-frequency baseband signal to the baseband processor for processing. After processing by the baseband processor, the low-frequency baseband signal is transmitted to the application processor. The application processor outputs sound signals through an audio device (not limited to speaker 170A, receiver 170B, etc.) or displays images or videos through the display screen 194. In some embodiments, the modem processor may be a separate device. In other embodiments, the modem processor may be independent of the processor 110 and may be housed in the same device as the mobile communication module 150 or other functional modules.
[0362] The wireless communication module 160 can provide solutions for wireless communication applications on the terminal device 100, including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), and infrared (IR) technologies. The wireless communication module 160 can be one or more devices integrating at least one communication processing module. The wireless communication module 160 receives electromagnetic waves via antenna 2, performs frequency modulation and filtering of the electromagnetic wave signals, and sends the processed signal to processor 110. The wireless communication module 160 can also receive signals to be transmitted from processor 110, perform frequency modulation and amplification, and convert them into electromagnetic waves for radiation via antenna 2.
[0363] In some embodiments, antenna 1 of terminal device 100 is coupled to mobile communication module 150, and antenna 2 is coupled to wireless communication module 160, enabling terminal device 100 to communicate with networks and other devices via wireless communication technology. Wireless communication technologies may include Global System for Mobile Communications (GSM), General Packet Radio Service (GPRS), Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), Time Division Code Division Multiple Access (TD-SCDMA), Long Term Evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technologies, etc. GNSS can include the Global Positioning System (GPS), the Global Navigation Satellite System (GLONASS), the BeiDou Navigation Satellite System (BDS), the Quasi-Zenith Satellite System (QZSS), and / or satellite-based augmentation systems (SBAS).
[0364] Terminal device 100 implements display functions through a GPU, display screen 194, and application processor. The GPU is a microprocessor for image processing, connected to the display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations and for graphics rendering. Processor 110 may include one or more GPUs, which execute program instructions to generate or modify display information.
[0365] Display screen 194 is used to display images, videos, etc. Display screen 194 includes a display panel. The display panel may be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a miniature LED, a microLED, a quantum dot light-emitting diode (QLED), etc. In some embodiments, terminal device 100 may include one or N displays 194, where N is a positive integer greater than 1.
[0366] Terminal device 100 can perform shooting functions through ISP, camera 193, video codec, GPU, display 194 and application processor.
[0367] The ISP (Image Signal Processor) is used to process data fed back from the camera 193. For example, when taking a picture, the shutter is opened, and light is transmitted through the lens to the camera's photosensitive element. The light signal is converted into an electrical signal, and the camera's photosensitive element transmits the electrical signal to the ISP for processing, transforming it into an image visible to the naked eye. The ISP can also perform algorithmic optimization of image noise, brightness, and skin tone. The ISP can also optimize parameters such as exposure and color temperature of the shooting scene. In some embodiments, the ISP can be set in the camera 193.
[0368] Camera 193 is used to capture still images or videos. An object is projected onto a photosensitive element by generating an optical image through the lens. The photosensitive element can be a charge-coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the light signal into an electrical signal, which is then passed to an ISP for conversion into a digital image signal. The ISP outputs the digital image signal to a DSP for processing. The DSP converts the digital image signal into image signals in standard RGB, YUV, or other formats. In some embodiments, the terminal device 100 may include one or N cameras 193, where N is a positive integer greater than 1.
[0369] A digital signal processor (DSP) is used to process digital signals. Besides digital image signals, it can also process other digital signals. For example, when terminal device 100 selects a frequency, the DSP can perform Fourier transforms on the frequency energy.
[0370] Video codecs are used to compress or decompress digital video. Terminal device 100 may support one or more video codecs. Thus, terminal device 100 can play or record videos in various encoding formats, such as Moving Picture Experts Group (MPEG) 1, MPEG 2, MPEG 3, MPEG 4, etc.
[0371] NPU stands for Neural Network (NN) Computing Processor. By borrowing the structure of biological neural networks, such as the transmission patterns between neurons in the human brain, it can rapidly process input information and continuously learn on its own. NPUs enable intelligent cognitive applications in terminal devices, such as image recognition, facial recognition, speech recognition, and text understanding.
[0372] The external storage interface 120 can be used to connect an external storage card, such as a Micro SD card, to expand the storage capacity of the terminal device 100. The external storage card communicates with the processor 110 through the external storage interface 120 to perform data storage functions. For example, music, video, and other files can be saved on the external storage card.
[0373] Internal memory 121 can be used to store computer executable program code, including instructions. Processor 110 executes various functional applications and data processing of terminal device 100 by running the instructions stored in internal memory 121. Internal memory 121 may include a program storage area and a data storage area. The program storage area may store the operating system, at least one application program required for a function (such as sound playback, image playback, etc.), etc. The data storage area may store data created during the use of terminal device 100 (such as audio data, phonebook, etc.). Furthermore, internal memory 121 may include high-speed random access memory and may also include non-volatile memory, such as at least one disk storage device, flash memory device, universal flash storage (UFS), etc.
[0374] Terminal device 100 can implement audio functions, such as music playback and recording, through audio module 170, speaker 170A, receiver 170B, microphone 170C, headphone jack 170D, and application processor.
[0375] The audio module 170 is used to convert digital audio information into analog audio signals for output, and also to convert analog audio input into digital audio signals. The audio module 170 can also be used for encoding and decoding audio signals. In some embodiments, the audio module 170 may be located in the processor 110, or some functional modules of the audio module 170 may be located in the processor 110.
[0376] The speaker 170A, also known as a "loudspeaker," is used to convert audio electrical signals into sound signals. The terminal device 100 can listen to music or make hands-free calls through the speaker 170A.
[0377] The receiver 170B, also known as the "earpiece," is used to convert audio electrical signals into sound signals. When the terminal device 100 answers a phone call or voice message, the receiver 170B can be brought close to the listener's ear to hear the voice.
[0378] Microphone 170C, also known as a "microphone" or "voice transducer," is used to convert sound signals into electrical signals. When making a phone call or sending a voice message, the user can speak by bringing their mouth close to microphone 170C, inputting the sound signal into microphone 170C. Terminal device 100 may be equipped with at least one microphone 170C. In some embodiments, terminal device 100 may be equipped with two microphones 170C, which, in addition to collecting sound signals, can also perform noise reduction. In other embodiments, terminal device 100 may be equipped with three, four, or more microphones 170C, which can collect sound signals, reduce noise, identify the sound source, and perform directional recording, etc.
[0379] The 170D headphone jack is used to connect wired headphones. The 170D headphone jack can be a USB 130 interface or a 3.5mm Open Mobile Terminal Platform (OMTP) standard interface, a CTIA (Cellular Telecommunications Industry Association of the USA) standard interface.
[0380] Pressure sensor 180A is used to sense pressure signals and convert them into electrical signals. In some embodiments, pressure sensor 180A can be disposed on display screen 194. There are many types of pressure sensors 180A, such as resistive pressure sensors, inductive pressure sensors, and capacitive pressure sensors. A capacitive pressure sensor may include at least two parallel plates with conductive material. When force is applied to pressure sensor 180A, the capacitance between the electrodes changes. Terminal device 100 determines the pressure intensity based on the change in capacitance. When a touch operation is applied to display screen 194, terminal device 100 detects the touch operation intensity based on pressure sensor 180A. Terminal device 100 can also calculate the touch position based on the detection signal from pressure sensor 180A. In some embodiments, touch operations applied to the same touch position but with different touch operation intensities can correspond to different operation commands. For example, when a touch operation with an intensity less than a first pressure threshold is applied to the SMS application icon, a command to view an SMS is executed. When a touch operation with an intensity greater than or equal to the first pressure threshold is applied to the SMS application icon, a command to create a new SMS is executed.
[0381] The gyroscope sensor 180B can be used to determine the motion attitude of the terminal device 100. In some embodiments, the gyroscope sensor 180B can determine the angular velocity of the terminal device 100 around three axes (i.e., the x, y, and z axes). The gyroscope sensor 180B can be used for image stabilization. For example, when the shutter is pressed, the gyroscope sensor 180B detects the angle of the terminal device 100's shake, calculates the distance that the lens module needs to compensate based on the angle, and allows the lens to counteract the shake of the terminal device 100 through reverse movement, thus achieving image stabilization. The gyroscope sensor 180B can also be used in navigation and motion-sensing game scenarios.
[0382] The barometric pressure sensor 180C is used to measure air pressure. In some embodiments, the terminal device 100 calculates altitude using the air pressure value measured by the barometric pressure sensor 180C to assist in positioning and navigation.
[0383] The magnetic sensor 180D includes a Hall sensor. The terminal device 100 can use the magnetic sensor 180D to detect the opening and closing of the flip cover. In some embodiments, when the terminal device 100 is a flip phone, the terminal device 100 can detect the opening and closing of the flip cover using the magnetic sensor 180D. Then, based on the detected opening and closing state of the cover or the flip cover, features such as automatic flip unlocking can be set.
[0384] The 180E accelerometer can detect the magnitude of acceleration of the terminal device 100 in various directions (generally three axes). When the terminal device 100 is stationary, it can detect the magnitude and direction of gravity. It can also be used to identify the posture of the terminal device 100, and can be applied to applications such as landscape / portrait switching and pedometers.
[0385] A distance sensor 180F is used to measure distance. The terminal device 100 can measure distance via infrared or laser. In some embodiments, during a shooting scene, the terminal device 100 can utilize the distance sensor 180F to measure distance for rapid focusing.
[0386] The proximity sensor 180G may include, for example, a light-emitting diode (LED) and a light detector, such as a photodiode. The LED may be an infrared LED. The terminal device 100 emits infrared light outward through the LED. The terminal device 100 uses the photodiode to detect infrared reflected light from nearby objects. When sufficient reflected light is detected, it can be determined that there is an object near the terminal device 100. When insufficient reflected light is detected, the terminal device 100 can determine that there is no object near the terminal device 100. The terminal device 100 may use the proximity sensor 180G to detect when a user holds the terminal device 100 close to their ear for a call, so as to automatically turn off the screen to save power. The proximity sensor 180G can also be used in holster mode and pocket mode for automatic unlocking and screen locking.
[0387] The ambient light sensor 180L is used to sense the ambient light intensity. The terminal device 100 can adaptively adjust the brightness of the display screen 194 based on the sensed ambient light intensity. The ambient light sensor 180L can also be used to automatically adjust the white balance when taking pictures. The ambient light sensor 180L can also work with the proximity sensor 180G to detect whether the terminal device 100 is in a pocket to prevent accidental touches.
[0388] The fingerprint sensor 180H is used to collect fingerprints. The terminal device 100 can use the characteristics of the collected fingerprints to achieve fingerprint unlocking, accessing application locks, taking photos with fingerprints, answering calls with fingerprints, etc.
[0389] Temperature sensor 180J is used to detect temperature. In some embodiments, terminal device 100 uses the temperature detected by temperature sensor 180J to execute a temperature handling strategy. For example, when the temperature reported by temperature sensor 180J exceeds a threshold, terminal device 100 reduces the performance of the processor located near temperature sensor 180J to reduce power consumption and implement thermal protection. In other embodiments, when the temperature is below another threshold, terminal device 100 heats battery 142 to prevent abnormal shutdown of terminal device 100 due to low temperature. In still other embodiments, when the temperature is below yet another threshold, terminal device 100 boosts the output voltage of battery 142 to prevent abnormal shutdown due to low temperature.
[0390] Touch sensor 180K, also known as a "touch panel," can be located on display screen 194. The touch sensor 180K and display screen 194 together form a touchscreen, also known as a "touch screen." Touch sensor 180K detects touch operations applied to or near it. The touch sensor can transmit the detected touch operation to the application processor to determine the type of touch event. Visual output related to the touch operation can be provided through display screen 194. In other embodiments, touch sensor 180K may also be located on the surface of terminal device 100, in a different position than display screen 194.
[0391] The bone conduction sensor 180M can acquire vibration signals. In some embodiments, the bone conduction sensor 180M can acquire vibration signals from the vibrating bone segments of the human vocal cords. The bone conduction sensor 180M can also contact the human pulse to receive blood pressure signals. In some embodiments, the bone conduction sensor 180M can also be incorporated into headphones to form bone conduction headphones. The audio module 170 can parse the voice signals from the vibrating bone segments of the vocal cords acquired by the bone conduction sensor 180M to realize voice functionality. The application processor can parse heart rate information from the blood pressure signals acquired by the bone conduction sensor 180M to realize heart rate detection functionality.
[0392] Buttons 190 include a power button, volume buttons, etc. Buttons 190 can be mechanical buttons or touch-sensitive buttons. Terminal device 100 can receive button input and generate key signal inputs related to user settings and function control of terminal device 100.
[0393] Motor 191 can generate vibration alerts. Motor 191 can be used for incoming call vibration alerts or for touch vibration feedback. For example, different vibration feedback effects can correspond to touch operations performed on different applications (such as taking photos, playing audio, etc.). Motor 191 can also correspond to different vibration feedback effects for touch operations performed on different areas of the display screen 194. Different application scenarios (such as time reminders, receiving messages, alarm clocks, games, etc.) can also correspond to different vibration feedback effects. The touch vibration feedback effect can also be customized.
[0394] Indicator 192 can be an indicator light, used to indicate charging status, power changes, or to indicate messages, missed calls, notifications, etc.
[0395] The SIM card interface 195 is used to connect a SIM card. The SIM card can be inserted into or removed from the SIM card interface 195 to make contact with and separate from the terminal device 100. The terminal device 100 can support one or N SIM card interfaces, where N is a positive integer greater than 1. The SIM card interface 195 can support Nano SIM cards, Micro SIM cards, SIM cards, etc. Multiple cards can be inserted into the same SIM card interface 195 simultaneously. The multiple cards can be of the same or different types. The SIM card interface 195 is also compatible with different types of SIM cards. The SIM card interface 195 is also compatible with external memory cards. The terminal device 100 interacts with the network through the SIM card to realize functions such as calls and data communication. In some embodiments, the terminal device 100 uses an eSIM, i.e., an embedded SIM card. The eSIM card can be embedded in the terminal device 100 and cannot be separated from the terminal device 100.
[0396] It should be understood that, Figure 10 The terminal device 100 shown is merely an example, and the terminal device 100 may have more than Figure 10 The more or fewer components shown can be combined into two or more components, or they can have different component configurations. Figure 10 The various components shown can be implemented in hardware, software, or a combination of hardware and software, including one or more signal processing and / or application-specific integrated circuits.
[0397] The structure of another terminal device 100 provided in the embodiments of this application is described below.
[0398] Figure 11 The structure of another terminal device 100 provided in an embodiment of this application is illustrated by way of example.
[0399] like Figure 11 As shown, the terminal device 100 may include: a communication module 101, a device authentication module 102, and a device owner identity determination module 103.
[0400] The communication module 101 enables the terminal device 100 to communicate with other devices. For example, in the methods provided in the various embodiments of this application, the terminal device 100 can use the communication module 101 to establish a short-range wireless communication connection with the smart lock 200, and based on this short-range wireless communication connection, the terminal device 100 and the smart lock 200 can transmit data.
[0401] The device authentication module 102 enables the terminal device 100 to authenticate with other devices and establish / de-bind relationships. For example, the terminal device 100 can use the device authentication module 102 to store the identification information and key information of the smart lock 200; for another example, the terminal device 100 can use the device authentication module 102 to send its own identification information and key information to the smart lock 200; for yet another example, the terminal device 100 can use the device authentication module 102 to determine whether it has passed device authentication based on the device authentication result sent by the smart lock 200, and if it has passed device authentication, the terminal device 100 can establish a binding relationship with the smart lock 200; and so on.
[0402] The owner identification module 103 enables the terminal device 100 to perform owner identification. The aforementioned owner identification module 103 may include, but is not limited to, the following four modules: owner non-persistent unlock state module, owner persistent unlock state module, owner biometric multi-factor identification module, and owner identity behavior identification module. Among these, the owner non-persistent unlock state module can implement the aforementioned... Figure 3 The textual description of step S316 in the illustrated embodiment describes the function of method 1; the aforementioned master continuous unlocking state module can achieve the aforementioned... Figure 3 The textual description of step S316 in the illustrated embodiment describes the function of method 2; the aforementioned host biometric multi-factor identification module can achieve the aforementioned... Figure 3 The textual description of step S316 in the illustrated embodiment describes the function of method 3; the aforementioned owner identity behavior recognition module can achieve the aforementioned... Figure 3 The function of method 4 in the textual description of step S316 in the illustrated embodiment.
[0403] For more details regarding the functions and working principles of the aforementioned terminal device 100, please refer to the relevant content in the above embodiments, which will not be repeated here.
[0404] It should be understood that, Figure 11 The terminal device 100 shown is merely an example, and the terminal device 100 may have more than Figure 11 The more or fewer components shown can be combined into two or more components, or they can have different component configurations. Figure 11 The various components shown can be implemented in hardware, software, or a combination of hardware and software.
[0405] The structure of a smart lock 200 provided in the embodiments of this application is described below.
[0406] Figure 12 The structure of a smart lock 200 provided in an embodiment of this application is illustrated by way of example.
[0407] like Figure 12 As shown, the smart lock 200 may include: a communication module 201, a device authentication module 202, an unlocking status control module 203, and a motor unlocking module 204.
[0408] The communication module 201 enables the smart lock 200 to communicate with other devices. For example, in the methods provided in the various embodiments of this application, the smart lock 200 can use the communication module 201 to establish a short-range wireless communication connection with the terminal device 100, and based on this short-range wireless communication connection, the smart lock 200 and the terminal device 100 can transmit data.
[0409] The device authentication module 202 enables the smart lock 200 to authenticate with other devices and establish / de-bind relationships. For example, the smart lock 200 can use the device authentication module 202 to store the identification information and key information of the terminal device 100; for another example, the smart lock 200 can use the device authentication module 202 to send its own identification information and key information to the terminal device 100; for yet another example, the smart lock 200 can use the device authentication module 202 to determine whether the identification information and key information of the terminal device 100 sent by the terminal device 100 are consistent with the identification information and key information of the terminal device 100 already stored in the smart lock 200. If they are consistent, it means that the terminal device 100 has passed device authentication and can establish a binding relationship with the smart lock 200; and so on.
[0410] The unlocking status control module 203 enables the smart lock 200 to determine whether an unlocking action can be performed. For example, the smart lock 200 can use the unlocking status control module 203 to determine whether the owner's identity authentication is successful based on the unlocking command corresponding to the owner's identity authentication decision result sent by the terminal device 100. If the owner's identity authentication is successful, it means that the smart lock 200 can perform the unlocking action.
[0411] The motor unlocking module 204 enables the smart lock 200 to perform unlocking actions. For example, the smart lock 200 can use the motor unlocking module 204 to receive the unlocking result sent by the unlocking status control module 203. The unlocking result carries information instructing the motor unlocking module 204 to perform unlocking actions. Based on the unlocking result, the motor unlocking module 204 can perform the unlocking action and complete the unlocking.
[0412] For more details on the functions and working principles of the smart lock 200, please refer to the relevant content in the above embodiments, which will not be repeated here.
[0413] It should be understood that, Figure 12 The smart lock 200 shown is merely an example, and the smart lock 200 can have more than... Figure 12The more or fewer components shown can be combined into two or more components, or they can have different component configurations. Figure 12 The various components shown can be implemented in hardware, software, or a combination of hardware and software.
[0414] The structure of another terminal device 100 provided in the embodiments of this application is described below.
[0415] Figure 13 The structure of another terminal device 100 provided in an embodiment of this application is illustrated by way of example.
[0416] like Figure 13 As shown, the terminal device 100 may include: application 301, face (or fingerprint) authentication service module 302, implicit authentication service module 303, Swing service module 304, application TA 305, face (or fingerprint) authentication TA 306, implicit authentication TA 307, and Swing operation module 308.
[0417] Application 301 runs at the application layer and can provide services to terminal device 100 through an application server (not shown in the figure). For example, application 301 can confirm whether implicit authentication was successful based on face tracking results, face comparison results, and implicit authentication duration.
[0418] The face (or fingerprint) authentication service module 302, the implicit authentication service module 303, and the Swing service module 304 run at the system layer. Among them, the face (or fingerprint) authentication service module 302 can be responsible for tasks such as determining whether explicit authentication is successful, the implicit authentication service module 303 can be responsible for tasks such as sending commands to start face tracking, and the Swing service module 304 can be responsible for tasks such as calling a camera (e.g., a Swing camera) to capture the initial Swing face image, Swing to track the face image, and Swing to authenticate the face image.
[0419] The application TA305, face (or fingerprint) authentication TA306, implicit authentication TA307, and Swing computing module 308 run in the security layer. Specifically, the application TA305 is responsible for sending commands to retrieve implicit authentication results; the face (or fingerprint) authentication TA306 is responsible for saving successful authentication results and recording the authentication time; the implicit authentication TA307 is responsible for calculating the implicit authentication duration; and the Swing computing module 308 is responsible for performing face tracking calculations to obtain face tracking results and performing face comparison to obtain face comparison results.
[0420] For more details regarding the functions and working principles of the aforementioned terminal device 100, please refer to the relevant content in the foregoing embodiments, which will not be repeated here.
[0421] It should be understood that, Figure 13 The terminal device 100 shown is merely an example, and the terminal device 100 may have more than Figure 13 The more or fewer components shown can be combined into two or more components, or they can have different component configurations. Figure 13 The various components shown can be implemented in hardware, software, or a combination of hardware and software.
[0422] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit it. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.
Claims
1. An unlocking method, characterized in that, The method includes: The terminal device collects the first authentication information when performing identity authentication for the first service; The terminal device establishes a short-range wireless communication connection with the smart lock; The terminal device confirms that an unlocking service needs to be performed. The unlocking service is different from the first service. The terminal device authenticates the user's identity based on the first authentication information. If the terminal device confirms that the identity authentication is successful, the terminal device notifies the smart lock to unlock based on the short-range wireless communication connection. The terminal device is a trusted device of the smart lock; Specifically, the terminal device performs user authentication based on the first authentication information, which includes: if the terminal device passes the first service authentication within a first time interval before establishing the short-range wireless communication connection between the terminal device and the smart lock, the terminal device will still confirm that the authentication has been passed after establishing the short-range wireless communication connection between the terminal device and the smart lock.
2. The method according to claim 1, characterized in that, The first authentication information includes password, fingerprint, facial image, swipe and / or touch screen operation.
3. The method according to claim 1 or 2, characterized in that, The first service includes unlocking the terminal device when it is in a locked state.
4. The method according to any one of claims 1-3, characterized in that, Before the terminal device notifies the smart lock to unlock based on the short-range wireless communication connection, the method further includes: If the terminal device fails to authenticate the user's identity based on the first authentication information, the terminal device collects the second authentication information and authenticates the user's identity based on the second authentication information.
5. The method according to claim 4, characterized in that, The terminal device failed to authenticate the user's identity based on the first authentication information, specifically including: Outside of the first time interval before the terminal device establishes the short-range wireless communication connection with the smart lock, if the terminal device passes the identity authentication of the first service, then after the terminal device establishes the short-range wireless communication connection with the smart lock, the terminal device confirms that the identity authentication failed.
6. The method according to any one of claims 1-3, characterized in that, Before the terminal device notifies the smart lock to unlock based on the short-range wireless communication connection, the method further includes: If the terminal device successfully authenticates the user's identity based on the first authentication information, the terminal device collects the second authentication information and authenticates the user's identity based on the second authentication information.
7. The method according to any one of claims 4-6, wherein the terminal device collects second authentication information and performs user identity authentication based on the second authentication information, specifically including: The terminal device turns on its camera and captures images through the camera. The terminal device then matches the captured images with pre-recorded facial images. If the match is successful, the identity authentication is confirmed. or, When the terminal device is connected to a wearable device, the terminal device matches the biometric information collected in real time by the wearable device with the biometric information collected in advance by the wearable device. If the match is successful, the identity authentication is confirmed to be successful. or, The terminal device collects the user's gait feature information and matches the collected gait feature information with the gait feature information collected in advance by the terminal device. If the match is successful, the identity authentication is confirmed.
8. The method according to any one of claims 1-7, characterized in that, The communication types of the short-range wireless communication connection include Near Field Communication (NFC), Bluetooth, Wi-Fi, and Infrared (IR).
9. The method according to any one of claims 1-8, characterized in that, After the terminal device establishes a short-range wireless communication connection with the smart lock, the method further includes: The terminal device receives a first instruction sent by the smart lock. The first instruction is sent by the smart lock after detecting a voice unlock command issued by the user. The first instruction is used to instruct the terminal device to authenticate the user's identity. or, The terminal device detects a user's command to unlock the smart lock using the terminal device; or, The terminal device receives a second instruction sent by the smart lock. The second instruction is sent by the smart lock after detecting that the user touches the smart lock. The second instruction is used to instruct the terminal device to authenticate the user's identity. or, The terminal device determines that the distance between the terminal device and the smart lock is less than a first distance value based on the signal strength of the short-range wireless communication connection.
10. A terminal device, characterized in that, The terminal device includes: one or more processors and a memory; the memory is coupled to the one or more processors, the memory is used to store computer program code, the computer program code includes computer instructions, and the one or more processors are used to invoke the computer instructions to cause the terminal device to execute: Collect the first authentication information when performing the first business identity authentication; Establish a short-range wireless communication connection with the smart lock; If it is confirmed that an unlocking service needs to be performed, the unlocking service is different from the first service. The user's identity is authenticated based on the first authentication information. If the identity authentication is confirmed to be successful, the smart lock is notified to unlock based on the short-range wireless communication connection. The terminal device is a trusted device of the smart lock; Specifically, the user authentication based on the first authentication information includes: if the terminal device passes the first service authentication within a first time interval before the terminal device establishes the short-range wireless communication connection with the smart lock, the authentication will still be confirmed as successful after the terminal device establishes the short-range wireless communication connection with the smart lock.
11. The terminal device according to claim 10, characterized in that, The first authentication information includes password, fingerprint, facial image, swipe and / or touch screen operation.
12. The terminal device according to claim 10 or 11, characterized in that, The first service includes unlocking the terminal device when it is in a locked state.
13. The terminal device according to any one of claims 10-12, characterized in that, The one or more processors are further configured to invoke the computer instructions to cause the terminal device to execute: If the terminal device fails to authenticate the user's identity based on the first authentication information, it collects the second authentication information and authenticates the user's identity based on the second authentication information.
14. The terminal device according to claim 13, characterized in that, The terminal device failed to authenticate the user's identity based on the first authentication information, specifically including: Outside of the first time interval before the terminal device establishes the short-range wireless communication connection with the smart lock, if the terminal device passes the identity authentication of the first service, then after the terminal device establishes the short-range wireless communication connection with the smart lock, the terminal device confirms that the identity authentication failed.
15. The terminal device according to any one of claims 10-12, characterized in that, The one or more processors are further configured to invoke the computer instructions to cause the terminal device to execute: If the terminal device successfully authenticates the user's identity based on the first authentication information, it collects the second authentication information and then authenticates the user's identity based on the second authentication information.
16. The terminal device according to any one of claims 13-15, wherein the one or more processors are configured to invoke the computer instructions to cause the terminal device to collect second authentication information and perform user authentication based on the second authentication information, specifically including: The terminal device turns on its camera and captures images through the camera. The terminal device then matches the captured images with pre-recorded facial images. If the match is successful, the identity authentication is confirmed. or, When the terminal device is connected to a wearable device, the terminal device matches the biometric information collected in real time by the wearable device with the biometric information collected in advance by the wearable device. If the match is successful, the identity authentication is confirmed to be successful. or, The terminal device collects the user's gait feature information and matches the collected gait feature information with the gait feature information collected in advance by the terminal device. If the match is successful, the identity authentication is confirmed.
17. The terminal device according to any one of claims 10-16, characterized in that, The communication types of the short-range wireless communication connection include Near Field Communication (NFC), Bluetooth, Wi-Fi, and Infrared (IR).
18. The terminal device according to any one of claims 10-17, characterized in that, After the terminal device establishes a short-range wireless communication connection with the smart lock, the one or more processors are further configured to invoke the computer instructions to cause the terminal device to execute: The device receives a first instruction sent by the smart lock, which is sent by the smart lock after detecting a voice unlock command issued by the user. The first instruction is used to instruct the terminal device to authenticate the user's identity. or, Detects user commands to unlock the smart lock using the terminal device; or, The terminal device receives a second instruction sent by the smart lock after detecting that the user has touched the smart lock. The second instruction is used to instruct the terminal device to authenticate the user's identity. or, Based on the signal strength of the short-range wireless communication connection, it is determined that the distance between the terminal device and the smart lock is less than a first distance value.
19. A chip applied to a terminal device, the chip comprising one or more processors, the processors being configured to invoke computer instructions to cause the terminal device to perform the method as described in any one of claims 1-9.
20. A computer storage medium, characterized in that, The computer storage medium stores a computer program, which includes program instructions that, when executed on a terminal device, cause the terminal device to perform the method as described in any one of claims 1-9.
Citation Information
Patent Citations
Control method and device of electronic device, electronic device and system
CN106485127A
Unlocking method of intelligent lock of safe cabinet
CN108876983A