Access control method and related apparatus

By using an access control method based on weak authentication factors, electronic devices create a restricted execution environment based on operation instructions and authentication factors when locked, which solves the problem of users needing cumbersome authentication to unlock, and achieves more granular access control and convenient operation.

CN115544469BActive Publication Date: 2025-12-23HUAWEI TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202110742228.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-06-29
Publication Date
2025-12-23
Estimated Expiration
2041-06-29

AI Technical Summary

Technical Problem

In existing technologies, users need to go through cumbersome and precise identity authentication procedures to unlock electronic devices, which makes the use of electronic devices inconvenient. In particular, low authentication methods such as voice and body gestures cannot be unlocked directly, affecting the user's ability to operate freely.

Method used

The access control method based on weak authentication factors is adopted. By obtaining the operation instructions and weak authentication factors, a restricted execution environment is created according to the risk level of the operation instructions and the security level of the authentication factors. This allows some operations to be performed in a locked state, thus achieving more granular access control.

Benefits of technology

Users can perform certain operations while the device is locked without cumbersome authentication, which improves the convenience and security of electronic devices, enriches usage scenarios, and avoids the risk of data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115544469B_ABST
    Figure CN115544469B_ABST
Patent Text Reader

Abstract

The application provides an access control method and related apparatus. In the method, when the electronic device is in a locked state, after obtaining an operation instruction and identity authentication information that does not meet an unlocking requirement, it is determined whether to allow access to a resource requested to be accessed by the operation instruction, and if so, the corresponding resource is accessed in response to the operation instruction. By implementing the method, the user does not have to unlock the electronic device through cumbersome authentication, but can trigger the electronic device to access the corresponding resource in the locked state, so that the user can more freely and conveniently control the electronic device. In addition, the electronic device no longer determines whether to perform certain operations according to whether to unlock, so that more fine-grained access control can be achieved, and the use scenarios and range of the electronic device are enriched.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of terminals and identity authentication, and in particular to an access control method and related apparatus. BACKGROUND

[0002] Electronic devices such as computers and mobile phones can be set to a locked state for security and to prevent misoperation. When an electronic device is in a locked state, a user needs to input predetermined identity authentication information such as a preset fingerprint, face, or password to unlock the electronic device and enter an unlocked state. Most functions of the electronic device can only be invoked in the unlocked state.

[0003] Currently, a user needs to input accurate identity authentication information such as a face at close range and a fingerprint that is completely identical to a preset fingerprint to trigger unlocking of the electronic device. In addition, the user cannot use some authentication methods with less accuracy such as voiceprint authentication to unlock the electronic device. This results in the user needing to perform tedious authentication operations or even multiple authentication operations to unlock the electronic device, and the use of the electronic device loses convenience. SUMMARY

[0004] The present application provides an access control method and related apparatus, which can allow a user to freely and conveniently manipulate an electronic device without having to perform tedious authentication to unlock the electronic device.

[0005] In a first aspect, an embodiment of the present application provides an access control method based on a weak authentication factor, including: when a first device is in a locked state, obtaining a first operation instruction and a first authentication factor; the first operation instruction is used to request access to a first resource of the first device, and the first authentication factor includes identity authentication information that does not meet unlocking requirements of the first device, and the identity authentication information that meets the unlocking requirements of the first device is used to switch the first device from the locked state to an unlocked state; the first device determines a resource that the first device allows to access according to the first operation instruction and the first authentication factor; and if the resource that the first device allows to access includes the first resource, the first device accesses the first resource in response to the first operation instruction.

[0006] The method provided by the first aspect is implemented, and the electronic device no longer only determines whether to respond to perform a corresponding operation according to whether the electronic device is unlocked. According to the operation instruction and the weak authentication factor, more fine-grained access control can be implemented for various resources, which enriches the use scenarios and use range of the electronic device. For a user, the electronic device can be triggered to perform some operations without having to perform tedious authentication to unlock the electronic device, so that the user can more freely and conveniently manipulate the electronic device.

[0007] In some embodiments of the first aspect, the first device can determine the resources allowed to be accessed by the first device according to a risk level of accessing the first resource; the higher the risk level of accessing the first resource, the fewer the resources allowed to be accessed by the first device. The higher the privacy level of the first resource, the higher the risk level of accessing the first resource. In this way, the risk of resource access can be fully considered, and data leakage and the like can be avoided.

[0008] In some embodiments of the first aspect, the first device can determine the resources allowed to be accessed by the first device according to a security level of the first authentication factor; the lower the security level of the first authentication factor, the fewer the resources allowed to be accessed by the first device. The higher the authentication capability level ACL of the identity authentication mode corresponding to the first authentication factor, or the higher the matching degree of the first authentication factor and the identity authentication information meeting the unlocking requirement of the first device, or the higher the security level of the first authentication factor. In this way, the reliability of the current authentication factor can be fully considered, and data leakage and the like can be avoided.

[0009] In some embodiments of the first aspect, the first resource includes a resource that the first device cannot access in a locked state and is predefined. Here, the resources that can be accessed in the locked state are basic resources or commonly used resources, such as camera applications, flashlights, Bluetooth, and the like. The resources that cannot be accessed in the locked state can include resources related to user privacy data, such as photos, browsing records, and the like. The resources that can be accessed in the locked state can be predefined by the first device.

[0010] In some embodiments of the first aspect, the first operation instruction includes any of the following: a voice-carrying semantic, a gesture, a facial expression, a body posture.

[0011] In some embodiments of the first aspect, the first device can obtain the first operation instruction in any of the following ways:

[0012] The first device collects a voice or an image and identifies the first operation instruction carried in the voice or the image;

[0013] The first device receives a voice or an image sent by the second device and identifies the first operation instruction carried in the voice or the image; or

[0014] The first device receives the first operation instruction sent by the second device.

[0015] In some embodiments of the first aspect, the identity authentication information comprises any one or more of: a password, a figure, or a biometric feature. The biometric feature can be classified into two categories: a physical feature and a behavioral feature. The physical feature includes: a face, a voiceprint, a fingerprint, a palm print, a retina, an iris, a body odor, a face shape, a heart rate, and a deoxyribonucleic acid (DNA). The behavioral feature includes: a signature, a body posture (e.g., a walking gait), and the like.

[0016] In some embodiments of the first aspect, the identity authentication information that does not meet the unlocking requirement of the first device can comprise any one or more of:

[0017] 1. identity authentication information that is below a required standard of a first authentication mode.

[0018] The first authentication mode is an identity authentication mode used to switch the first device from a locked state to an unlocked state.

[0019] In some embodiments, the first authentication mode is an identity authentication mode whose authentication capability level (ACL) is higher than a third value, or the first authentication mode is pre-set by the first device. For example, the first authentication mode can include a password authentication, a figure authentication, a fingerprint authentication, a face authentication, and the like.

[0020] The identity authentication information that is below the required standard of the first authentication mode can include a biometric feature whose matching degree with a pre-stored first biometric feature is below a first value. The first biometric feature is the identity authentication information corresponding to the first authentication mode. The first value can be pre-set.

[0021] 2. identity authentication information that meets a required standard of a second authentication mode.

[0022] The second authentication mode is an identity authentication mode other than the first authentication mode.

[0023] In some embodiments, the second authentication mode is an identity authentication mode other than the first authentication mode. The second authentication mode can be an identity authentication mode whose authentication capability level (ACL) is lower, or the second authentication mode is pre-set by the first device. For example, the second authentication mode can include a voiceprint authentication, a heart rate authentication, a body posture authentication, and the like.

[0024] The identity authentication information that meets the required standard of the second authentication mode includes a biometric feature whose matching degree with a pre-stored second biometric feature reaches a second value. The second biometric feature is the identity authentication information corresponding to the second authentication mode. The second value can be pre-set.

[0025] In some embodiments of the first aspect, the first device can obtain the first authentication factor by any one or more of:

[0026] The first device collects a voice or an image, and identifies a first authentication factor carried in the voice or the image;

[0027] The first device receives a voice or an image sent by the second device, and identifies a first authentication factor carried in the voice or the image; or,

[0028] The first device receives a first authentication factor sent by the second device.

[0029] With reference to the first aspect, in some embodiments, the first device can also simultaneously obtain a first operation instruction and the first authentication factor. For example, the first device can collect a voice, identify a semantic of the voice, determine the semantic as the first operation instruction, and identify a voiceprint carried in the voice, and determine the voiceprint as the first authentication factor. Alternatively, the first device can collect an image, identify a gesture, a facial expression, a body posture in the image, and determine the gesture, the facial expression, and the body posture in the image as the first operation instruction, and identify a biological feature carried in the image, and determine the biological feature as the first authentication factor.

[0030] With reference to the first aspect, in some embodiments, after the first device accesses the first resource in response to the first operation instruction, the first device can also receive a user operation for requesting to access a second resource of the first device. If the resources allowed to be accessed by the first device include the second resource, the first device accesses the second resource in response to the user operation; if the resources allowed to be accessed by the first device do not include the second resource, the first device rejects to respond to the user operation.

[0031] Through the above embodiment, the operations that can be performed by the first device can be limited within a certain range, so that the expansion of the permission can be avoided, and the data security of the first device can be protected.

[0032] With reference to the first aspect, in some embodiments, after the first device accesses the first resource in response to the first operation instruction, the first device can also obtain a second authentication factor, the second authentication factor including identity authentication information meeting an unlocking requirement of the first device, or a predetermined number of first authentication factors, and the first device switches from a locked state to an unlocked state according to the second authentication factor. When the second authentication factor is the predetermined number of first authentication factors, the user can complete the identity authentication by inputting the first authentication factor for multiple times, and trigger the first device to be unlocked.

[0033] In combination with the previous embodiment, after the first device determines the resources that the first device allows to access, before the first device obtains the second authentication factor, the first device can display the first control, detect the operation on the first control, and in response to the operation on the first control, start detecting the identity authentication information. That is, the user can actively trigger the first device to start detecting the identity authentication information, so as to obtain the second authentication factor and unlock. In this way, the user can decide whether to unlock according to the user's own needs, and the power consumption of the first device can be saved.

[0034] In combination with the first aspect, in some embodiments, after the first device determines the resources that the first device allows to access, the first device can create a restricted execution environment, in which the first device allows to access the determined resources that allow to access. The first device can access the first resource in the restricted execution environment in response to the first operation instruction.

[0035] In the previous embodiment, when the restricted execution environment is specifically created, the first device can record the determined operations that allow to execute. That is, the first device records which specific access operations the first device is allowed to perform on which resources or which type of resources.

[0036] In the second aspect, an embodiment of the present application provides a cross-device access control method, including: when the first device is in a locked state, receiving a second operation instruction sent by a third device; the second operation instruction is used to request to access a third resource of the first device; the first device determines resources that the first device allows to access according to the second operation instruction; if the resources that the first device allows to access include the third resource, the first device accesses the third resource in response to the second operation instruction.

[0037] Implementing the method of the second aspect, the electronic device no longer only decides whether to respond to execute the corresponding operation according to whether to unlock, but according to the operation instruction, implements more fine-grained access control on various types of resources, enriches the use scenarios and use range of the electronic device. For the user, the electronic device can be triggered to execute some operations without unlocking the electronic device through cumbersome authentication, so that the user can more freely and conveniently manipulate the electronic device.

[0038] In combination with the second aspect, in some embodiments, the first device can determine the resources that the first device allows to access according to a risk level of accessing the third resource; the higher the risk level of accessing the third resource, the fewer the resources that the first device allows to access. Among them, the higher the privacy degree of the third resource, the higher the risk level of accessing the third resource. In this way, the risk of resource access can be fully considered to avoid data leakage and the like.

[0039] In some embodiments of the second aspect, the third resource comprises a resource that the first device is not allowed to access in the locked state. Here, the third resource is the same as the first resource of the first aspect, and the related description can be referred to the first aspect.

[0040] In some embodiments of the second aspect, the third operation instruction comprises any one of the following: a voice-carrying semantic, a gesture, a facial expression, a body posture.

[0041] In some embodiments of the second aspect, the third operation instruction is a screen projection request. In this way, for a data sharing scenario such as screen projection and multi-screen interaction, the other device does not need to be unlocked when one device shares data to the other device. Compared with the solution that the other device needs to be unlocked every time data is shared, the embodiments of the present application reduce the difficulty and complexity of screen projection and multi-screen interaction, and can bring better user experience.

[0042] In some embodiments of the second aspect, after the first device accesses the third resource in response to the second operation instruction, the first device can receive a user operation for requesting to access a fourth resource of the first device. If the resources allowed to be accessed by the first device include the fourth resource, the first device accesses the fourth resource in response to the user operation; if the resources allowed to be accessed by the first device do not include the fourth resource, the first device refuses to respond to the user operation.

[0043] Through the above embodiment, the operations that the first device can perform can be limited within a certain range, so that the expansion of the permission is avoided, and the data security of the first device is protected.

[0044] In some embodiments of the second aspect, after the first device accesses the third resource in response to the second operation instruction, the first device can obtain a second authentication factor, which comprises identity authentication information meeting the unlocking requirement of the first device, or a predetermined number of first authentication factors; and the first device switches from the locked state to the unlocked state according to the second authentication factor. When the second authentication factor is the predetermined number of first authentication factors, the user can complete the identity authentication by inputting the first authentication factor multiple times to trigger the unlocking of the electronic device.

[0045] In combination with the above embodiment, after the first device determines the resources allowed to be accessed by the first device, and before the first device obtains the second authentication factor, the first device can display a first control; the first device detects an operation acting on the first control; and the first device starts detecting the identity authentication information in response to the operation acting on the first control. That is, the user can actively trigger the first device to start detecting the identity authentication information, so as to obtain the second authentication factor and unlock. In this way, the user can decide whether to unlock according to the user's own needs, and the power consumption of the first device can be saved.

[0046] With reference to the second aspect, in some embodiments, after the first device determines the resources that the first device allows to be accessed, the first device can create a restricted execution environment in which the first device allows access to the determined resources that are allowed to be accessed. The first device can access the third resource in the restricted execution environment in response to the second operation instruction.

[0047] In the above embodiment, when the restricted execution environment is specifically created, the first device can record the determined operations that are allowed to be performed. That is, the first device records which specific access operations are allowed to be performed by the first device on which resources or which type of resources.

[0048] In the third aspect, an embodiment of the present application provides an electronic device, including a memory and one or more processors; the memory is coupled to the one or more processors, and the memory is configured to store computer program codes including computer instructions; the one or more processors are configured to invoke the computer instructions to enable the electronic device to perform the method in the first aspect or any one of the embodiments of the first aspect.

[0049] In the fourth aspect, an embodiment of the present application provides an electronic device, including a memory and one or more processors; the memory is coupled to the one or more processors, and the memory is configured to store computer program codes including computer instructions; the one or more processors are configured to invoke the computer instructions to enable the electronic device to perform the method in the second aspect or any one of the embodiments of the second aspect.

[0050] In the fifth aspect, an embodiment of the present application provides a communication system, including a first device and a second device; the first device is configured to perform the method in the first aspect or any one of the embodiments of the first aspect.

[0051] In the sixth aspect, an embodiment of the present application provides a communication system, including a first device and a third device; the first device is configured to perform the method in the second aspect or any one of the embodiments of the second aspect.

[0052] In the seventh aspect, an embodiment of the present application provides a computer readable storage medium, including instructions; when the instructions are run on an electronic device, the electronic device is enabled to perform the method in the first aspect or any one of the embodiments of the first aspect.

[0053] In the eighth aspect, an embodiment of the present application provides a computer program product; when the computer program product is run on a computer, the computer is enabled to perform the method in the second aspect or any one of the embodiments of the second aspect.

[0054] In the ninth aspect, an embodiment of the present application provides a computer readable storage medium, including instructions; when the instructions are run on an electronic device, the electronic device is enabled to perform the method in the first aspect or any one of the embodiments of the first aspect.

[0055] In a tenth aspect, the embodiments of the present application provide a computer program product, which, when running on a computer, causes the computer to execute the method of the second aspect or any one of the embodiments of the second aspect.

[0056] By implementing the technical solutions provided in the present application, when the electronic device is in a locked state, after obtaining an operation instruction and identity authentication information that does not meet an unlocking requirement, it can be determined whether to allow access to a resource requested to be accessed by the operation instruction, and if so, the corresponding resource is accessed in response to the operation instruction. By implementing the method, the user does not have to unlock the electronic device through cumbersome authentication, but can trigger the electronic device to access the corresponding resource in the locked state, so that the user can more freely and conveniently control the electronic device. In addition, the electronic device no longer determines whether to perform certain operations according to whether it is unlocked, so that more fine-grained access control can be achieved, and the use scenarios and use range of the electronic device are enriched. BRIEF DESCRIPTION OF DRAWINGS

[0057] Figure 1 A hardware structure diagram of an electronic device provided in the embodiments of the present application;

[0058] Figure 2 A software structure diagram of an electronic device provided in the embodiments of the present application;

[0059] Figure 3 A structure diagram of a communication system provided in the embodiments of the present application;

[0060] Figure 4 A flowchart of an access control method based on a weak authentication factor provided in the embodiments of the present application;

[0061] Figure 5A A user interface when the electronic device 100 is in a locked state provided in the embodiments of the present application;

[0062] Figures 5B-5D A scenario in which the electronic device 100 is provided in the embodiments of the present application;

[0063] Figures 5E-5G A user interface displayed after the electronic device 100 creates a restricted execution environment provided in the embodiments of the present application;

[0064] Figure 6 A flowchart of a cross-device access control method provided in the embodiments of the present application;

[0065] Figures 7A-7C A set of user interfaces related to the cross-device access control method;

[0066] Figure 8A and Figure 8BA software structure diagram of the electronic device 100 is provided in the embodiments of the present application. DETAILED DESCRIPTION

[0067] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings. In the description of the embodiments of the present application, unless otherwise specified, " / " represents the meaning of or, for example, A / B can represent A or B; the "and / or" in the text only describes the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B, which means that there are three cases of A alone, A and B together, and B alone. In addition, in the description of the embodiments of the present application, "multiple" means two or more than two.

[0068] Hereinafter, the terms "first" and "second" are only used for description purposes, and cannot be understood as implying or suggesting relative importance or implicitly indicating the number of indicated technical features. Therefore, the features defined with "first" and "second" can explicitly or implicitly include one or more features. In the description of the embodiments of the present application, unless otherwise specified, the meaning of "multiple" is two or more than two.

[0069] In the embodiments of the present application, the term "user interface (UI)" is a medium interface for interaction and information exchange between an application or an operating system and a user, which realizes the conversion between the internal form of information and the form that the user can accept. The user interface is source code written in a specific computer language such as Java, extensible markup language (XML), etc. The interface source code is parsed, rendered, and finally presented as content that can be recognized by the user on the electronic device. The commonly used form of user interface is graphic user interface (GUI), which refers to a user interface that displays information in a graphical manner. It can be a visual interface element such as text, icon, button, menu, tab, text box, dialog box, status bar, navigation bar, Widget, etc. displayed in the display screen of the electronic device.

[0070] In the embodiments of the present application, the electronic device has two states: a locked state and an unlocked state.

[0071] In the locked state, the electronic device can only perform predefined operations and cannot perform other operations other than the predefined operations. The locked state can be used to avoid user misoperation or prevent the electronic device from performing other operations other than the predefined operations.

[0072] In the embodiments of the present application, the electronic device performing an operation specifically refers to the electronic device performing an access operation on a resource, which may, for example, include reading, adding, deleting, writing, modifying, executing, and the like.

[0073] In the embodiments of the present application, the resource in the electronic device may include one or more of the following: a software resource, a hardware resource, a peripheral device, or a resource of the peripheral device, and the like of the electronic device. Among them:

[0074] The hardware resource is related to the hardware configuration of the electronic device, which may, for example, include a camera, a sensor, an audio device, a display screen, a motor, a flash, and the like possessed by the electronic device.

[0075] The software resource is related to the software configuration of the electronic device, which may, for example, include an application (APP) or a service component installed by the electronic device, a possessed memory resource, a computing capability (for example, a beautifying algorithm capability, an audio and video coding and decoding capability), a network capability, a device connection capability, a device discovery capability, a data transmission capability, and the like. The software resource may include a system resource or a third-party resource, which is not limited here.

[0076] The peripheral device refers to a device connected to the electronic device, which is used for transmitting, forwarding, and storing data and information, and the like. The peripheral device may, for example, include a peripheral device of the electronic device, such as a mouse, an external display screen, a Bluetooth headset, a keyboard, and the like, and a smart watch, a smart bracelet, and the like managed by the electronic device. The resource of the peripheral device may include a hardware resource and a software resource, which may refer to the related description in the foregoing.

[0077] In the embodiments of the present application, the predefined operation may be predefined by the manufacturer of the electronic device and cannot be modified. The manufacturer of the electronic device may include a manufacturer, a supplier, a provider, and the like of the electronic device. The manufacturer may refer to a manufacturer that processes and manufactures the electronic device by using self-made or purchased parts and raw materials. The supplier may refer to a manufacturer that provides the whole machine, raw materials, or parts of the electronic device. For example, the manufacturer of the Huawei "Mate" series of mobile phones is Huawei Technologies Co., Ltd.

[0078] The predefined operation does not involve the privacy data of the user, and only includes some basic operations or commonly used operations. The predefined operation may, for example, include starting or closing some basic applications, such as starting a camera application, turning on a flashlight, opening a calculator, scanning a two-dimensional code, closing / opening Bluetooth, closing / opening a cellular signal, opening / closing a wireless fidelity (Wi-Fi) signal, and the like, and the electronic device cannot enter a gallery or an album through the camera application after starting the camera application.

[0079] The other operations in addition to the predefined operation can include operations involving user privacy data, and operations partially not involving user privacy data. The user privacy data can include user data stored in respective applications, such as photos, videos, audios, contact information, browsing records, shopping records, and the like of the user. The operations involving user privacy data can include, for example, starting or closing a gallery, an album, a contact list, a shopping application, an instant messaging application, a memo, sharing user data through a background, Wi-Fi, USB, Bluetooth, and the like. The operations partially not involving user privacy data can include, for example, starting a navigation application without reading user data, starting a browser without reading browsing records, starting a video application without reading browsing records, and the like. The navigation application can also be referred to as a map application or other names.

[0080] In the unlocked state, the electronic device can perform other operations in addition to the predefined operation in the locked state. For example, the electronic device can perform operations involving user privacy data in the unlocked state, such as starting a gallery or an album, starting a shopping application and viewing shopping records, starting an instant messaging application, viewing a memo, viewing navigation data, viewing browsing records of a browser, and the like.

[0081] In embodiments of the present application, the locked state can also be referred to as other names, such as a lock screen state or the like. Similarly, the unlocked state can also be referred to as other names, which are not limited here. For the sake of simplicity of description, the locked state and the unlocked state will be used uniformly for description hereinafter.

[0082] The electronic device can preset a plurality of identity authentication methods, and can receive identity authentication information corresponding to the preset identity authentication methods in the locked state. When it is determined that the input identity authentication information meets an identity authentication standard, the electronic device can be unlocked and enter the unlocked state.

[0083] Identity authentication is a technology for confirming the identity of a user. At present, identity authentication methods can include password authentication, pattern authentication, and biometric authentication. Different users can be distinguished by different identity authentication information. Specifically, the electronic device can prestore a password, a pattern, or a biometric feature. When a user inputs the pre-stored password or pattern, or inputs a biometric feature that matches the pre-stored biometric feature to a certain degree, the electronic device can confirm that the user is the user of the previously pre-stored information. The value of the matching degree can be pre-set. The higher the value of the matching degree, the higher the accuracy of the biometric authentication method.

[0084] The password can be a string composed of numbers, letters, and symbols.

[0085] Biological features are classified into two categories: physical features and behavioral features. Physical features include face, voiceprint, fingerprint, palm print, retina, iris, human odor, face shape, blood pressure, blood oxygen, blood sugar, respiration rate, heart rate, one cycle of electrocardiogram waveform, deoxyribo nucleic acid (DNA), etc. Behavioral features include signature, body posture (e.g., walking gait), etc.

[0086] Since electronic devices extract various types of information such as passwords, patterns, and various biological features with different degrees of accuracy, each of the above identity authentication methods has a corresponding authentication capability level (ACL). The higher the ACL, the higher the reliability of the result of identity authentication using the authentication method. The accuracy of information extracted by an electronic device depends on the current state of technology development. For example, the accuracy of password and fingerprint extraction by an electronic device is very high, but the accuracy of voiceprint and signature extraction is relatively low. For the same type of information, different algorithms used by different electronic devices result in different degrees of accuracy of information extracted by different electronic devices using the identity authentication method.

[0087] Objectively speaking, the ACL of an identity authentication method can be determined according to the false accept rate (FAR), false reject rate (FRR), and spoof accept rate (SAR) when the identity authentication method is used. The lower the FAR, the lower the FRR, and the lower the SAR, the higher the ACL. For example, the ACL of password authentication / pattern authentication, face authentication / fingerprint authentication, voiceprint authentication, and body posture authentication decreases in turn.

[0088] The ACL can be divided into multiple levels of different granularity, which is not limited here. For example, the ACL can be divided into four levels.

[0089] In order to ensure data security, an electronic device usually only uses an identity authentication method with a high ACL to unlock, and does not use an identity authentication method with a low ACL to unlock.

[0090] For ease of description, the identity authentication method used by an electronic device to unlock is referred to as a first authentication method, and other identity authentication methods other than the identity authentication method used by the electronic device to unlock are referred to as a second authentication method. The first authentication method can be set by the electronic device or the manufacturer of the electronic device, which is not limited here. For example, an electronic device can be set to use password authentication, pattern authentication, fingerprint authentication, and face authentication to unlock, and not to use voiceprint authentication, heart rate authentication, and body posture authentication to unlock.

[0091] In the locked state, the electronic device can receive identity authentication information input by a user, and after determining that the input identity authentication information meets the criteria of the first authentication mode, the electronic device is unlocked and enters an unlocked state. In order to input identity authentication information that meets the criteria, the user needs to perform relatively cumbersome operations. For example, the user needs to strictly input a preset password or pattern, align the face to the front camera of the electronic device within a certain distance and keep still, press the fingerprint recognition sensor with a clean finger and keep still, and the like. That is, the user needs to unlock the device through cumbersome authentication operations, even multiple authentication operations, which wastes a lot of time and power consumption of the electronic device.

[0092] In addition, more and more users use voice instructions, body gestures, and the like to control electronic devices, which brings great convenience without touching the electronic device in the scenarios of driving, cooking, exercising, and the like. However, due to the low ACL of voiceprint authentication, body gesture authentication, and the like, the electronic device cannot be directly unlocked by voice, body gesture, or remote gesture, and needs to be unlocked by using other identity authentication modes with higher ACL. This results in the loss of convenience of voice instructions, body gestures, and remote gestures, and brings obstacles to the user's easy and convenient control of the electronic device.

[0093] It can be seen that if the user wants to trigger the electronic device to perform other operations in addition to the predefined operations in the locked state, the user needs to input identity authentication information that meets the criteria of the identity authentication mode with higher ACL through cumbersome methods to unlock the device, which reduces the convenience of the electronic device and brings obstacles to the user's use of the electronic device.

[0094] The following embodiments of the present application provide an access control method based on a weak authentication factor. In this method, when the electronic device is in a locked state, after obtaining a first operation instruction and a weak authentication factor, a limited execution environment can be created according to the risk level of the operation corresponding to the first operation instruction and the security level of the weak authentication factor, and the corresponding operation is performed in the limited execution environment in response to the first operation instruction.

[0095] The correspondence between the first operation instruction and the operation corresponding thereto is pre-set by the electronic device. The first operation instruction can be directly received by the electronic device, or can be obtained by another device and sent to the electronic device. The specific content of the first operation instruction can be referred to the detailed description of the subsequent method embodiments, which is not described here.

[0096] In some embodiments, the first operation instruction is used to request the electronic device to perform other operations in addition to the predefined operations in the locked state. For the locked state, the predefined operation, and the other operation in addition to the predefined operation, please refer to the relevant description in the foregoing.

[0097] The weak authentication factor refers to identity authentication information that does not meet the unlocking requirement of the electronic device. The weak authentication factor can include the following two types: 1. identity authentication information that is lower than the required standard of the first authentication mode. 2. identity authentication information that meets the required standard of the second authentication mode. The weak authentication factor can be directly collected by the electronic device, or can be collected by other devices and sent to the electronic device. The specific content of the weak authentication factor can be referred to the detailed description of the subsequent method embodiments, which will not be described here.

[0098] In some embodiments, the electronic device can receive the first operation instruction and the weak authentication factor respectively.

[0099] In some embodiments, the electronic device can receive the first operation instruction and the weak authentication factor simultaneously.

[0100] The restricted execution environment refers to a restricted execution environment. The execution environment can include a hardware environment and a software environment. The execution environment can be a sandbox or a function domain containing multiple functions. In the restricted execution environment, the electronic device can only perform a specified part of the operation, and cannot perform other operations other than the specified part of the operation. That is, in the restricted execution environment, the electronic device can only access part of the resources of the electronic device, and cannot access other resources other than the part of the resources. The restricted execution environment in the embodiments of the present application can also be referred to as a restricted execution environment, a restricted running environment, a restricted domain, and the like, which are not limited here.

[0101] The electronic device can create a restricted execution environment according to the risk level of the operation corresponding to the first operation instruction and the security level of the weak authentication factor. The lower the risk level of the operation corresponding to the first operation instruction, or the higher the security level of the weak authentication factor, the more resources that can be accessed in the restricted execution environment created by the electronic device. The risk level of the operation, the security level of the weak authentication factor, and the way to create the restricted execution environment can be referred to the related description in the subsequent method embodiments.

[0102] Through the above access control method based on the weak authentication factor, the electronic device no longer decides whether to respond to perform the corresponding operation according to whether to be unlocked, but decides whether to perform the operation according to the risk level of the operation instruction and the security level of the weak authentication factor, so that more fine-grained access control can be implemented, and the use scenarios and use range of the electronic device are enriched. For the user, the electronic device can be triggered to perform other operations in addition to the predefined operation in the locked state without unlocking the electronic device through cumbersome authentication, so that the user can more freely and conveniently manipulate the electronic device. In addition, the electronic device no longer simply divides resources into resources accessible to the predefined operation and resources accessible to other operations, but also implements more fine-grained access control for various resources.

[0103] The embodiments of the present application also provide a cross-device access control method, which is applied to a communication system including two electronic devices. In the method, one electronic device can send a second operation instruction to another electronic device, and the other electronic device can create a limited execution environment according to the risk level of the operation corresponding to the second operation instruction, and respond to the second operation instruction in the limited execution environment to perform the corresponding operation.

[0104] The second operation instruction is an operation instruction sent by the other electronic device, which can be a screen projection request and the like. The specific content of the second operation instruction can be referred to the detailed description of the subsequent method embodiments, which is not described here.

[0105] In some embodiments, the second operation instruction is used to request the electronic device to perform other operations in addition to the predefined operation in the locked state.

[0106] The lower the risk level of the operation corresponding to the second operation instruction, the more resources accessible in the limited execution environment created by the electronic device.

[0107] Through the above cross-device access control method, the electronic device no longer decides whether to respond to the user operation according to whether to be unlocked, but decides whether to respond to the user operation according to the risk level of the operation instruction received by the cross-device, so that more fine-grained access control can be implemented, and the use scenarios and use range of the electronic device are enriched. For the user, the electronic device can be triggered to perform other operations in addition to the predefined operation in the locked state without unlocking the electronic device through cumbersome authentication, so that the user can more freely and conveniently manipulate the electronic device. In addition, the electronic device no longer simply divides resources into resources accessible to the predefined operation and resources accessible to other operations, but also implements more fine-grained access control for various resources.

[0108] In the above two access control methods, after the electronic device creates the restricted execution environment, if the electronic device receives a user operation and the user operation requests to perform an operation other than the operation allowed to be performed by the restricted execution environment, the electronic device can prompt the user to unlock. After the electronic device is unlocked at the user's trigger, the electronic device can perform the corresponding operation in response to the previously received user operation.

[0109] In the above two access control methods, after the electronic device creates the restricted execution environment, the user can also actively trigger the electronic device to unlock. After the electronic device is unlocked, the electronic device can perform various operations in response to user operations.

[0110] Next, first introduce the electronic device 100 provided by the embodiments of the present application.

[0111] The electronic device 100 can be of various types, and the embodiments of the present application do not limit the specific type of the electronic device 100. For example, the electronic device 100 includes a mobile phone, and can also include a tablet computer, a desktop computer, a laptop computer, a handheld computer, a notebook computer, a large-screen television, a smart screen, a wearable device, an augmented reality (AR) device, a virtual reality (VR) device, an artificial intelligence (AI) device, a car machine, a smart earphone, a game machine, and can also include an internet of things (IOT) device or a smart home device such as a smart water heater, a smart lamp, a smart air conditioner, a camera, and the like. Without limitation, the electronic device 100 can also include a laptop with a touch-sensitive surface or a touch panel, a desktop computer with a touch-sensitive surface or a touch panel, and the like. Non-portable terminal devices, and the like.

[0112] Figure 1 A structural schematic diagram of the electronic device 100 is shown.

[0113] The electronic device 100 can include a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, a headset interface 170D, a sensor module 180, a key 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and a subscriber identification module (SIM) card interface 195, etc. The sensor module 180 can include a pressure sensor 180A, a gyro sensor 180B, a barometric pressure sensor 180C, a magnetic sensor 180D, an acceleration sensor 180E, a distance sensor 180F, a proximity light sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, etc.

[0114] It can be understood that the structure illustrated in the embodiments of the present application does not constitute a specific limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 can include more or fewer components than illustrated, or combine certain components, or split certain components, or different arrangement of components. The illustrated components can be implemented in hardware, software, or a combination of software and hardware.

[0115] The processor 110 can include one or more processing units, for example: the processor 110 can include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Different processing units can be independent devices, or can be integrated in one or more processors.

[0116] The controller can generate operation control signals according to instruction operation codes and timing signals, and complete the control of fetching and executing instructions.

[0117] The processor 110 can also include a memory for storing instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. The memory can hold instructions or data that the processor 110 has just used or is using repeatedly. If the processor 110 needs to use the instructions or data again, it can call them directly from the memory. This avoids repeated access and reduces the waiting time of the processor 110, thus improving the efficiency of the system.

[0118] The wireless communication function of the electronic device 100 can be implemented through the antenna 1, the antenna 2, the mobile communication module 150, the wireless communication module 160, the modem processor, and the baseband processor, etc.

[0119] The antenna 1 and the antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in the electronic device 100 can be used to cover a single or multiple communication frequency bands. Different antennas can also be multiplexed to improve the utilization of the antennas. For example, the antenna 1 can be multiplexed as a diversity antenna for a wireless local area network. In some other embodiments, the antennas can be used in combination with a tuning switch.

[0120] The mobile communication module 150 can provide a solution for wireless communication including 2G / 3G / 4G / 5G, etc. applied to the electronic device 100. The mobile communication module 150 can include at least one filter, a switch, a power amplifier, a low noise amplifier (LNA), etc. The mobile communication module 150 can receive electromagnetic waves from the antenna 1, and perform filtering, amplification, etc. on the received electromagnetic waves, and transmit them to the modem processor for demodulation. The mobile communication module 150 can also amplify the signals modulated by the modem processor, and convert them into electromagnetic waves radiated through the antenna 1. In some embodiments, at least part of the functional modules of the mobile communication module 150 can be arranged in the processor 110. In some embodiments, at least part of the functional modules of the mobile communication module 150 and at least part of the modules of the processor 110 can be arranged in the same device.

[0121] The modem processor can include a modulator and a demodulator. The modulator is used to modulate a low-frequency baseband signal to be transmitted into a medium-high frequency signal. The demodulator is used to demodulate the received electromagnetic wave signal into a low-frequency baseband signal. The demodulator then transmits the demodulated low-frequency baseband signal to the baseband processor for processing. The low-frequency baseband signal processed by the baseband processor is transmitted to the application processor. The application processor outputs sound signals through an audio device (not limited to the loudspeaker 170A and the receiver 170B, etc.), or displays images or videos through the display screen 194. In some embodiments, the modem processor can be an independent device. In some other embodiments, the modem processor can be independent of the processor 110, and arranged in the same device as the mobile communication module 150 or other functional modules.

[0122] The wireless communication module 160 can provide a solution for wireless communication including a wireless local area network (WLAN) (e.g., a wireless fidelity (Wi-Fi) network), Bluetooth (BT), a global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared (IR) technology, etc., which is applied to the electronic device 100. The wireless communication module 160 can be one or more devices that integrate at least one communication processing module. The wireless communication module 160 receives an electromagnetic wave via the antenna 2, demodulates and filters the electromagnetic wave signal, and transmits the processed signal to the processor 110. The wireless communication module 160 can also receive a signal to be transmitted from the processor 110, frequency-modulate the signal, amplify it, and radiate it as an electromagnetic wave via the antenna 2.

[0123] In some embodiments, the antenna 1 and the mobile communication module 150 of the electronic device 100 are coupled, and the antenna 2 and the wireless communication module 160 are coupled, so that the electronic device 100 can communicate with a network and other devices through wireless communication technology. The wireless communication technology can include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technology, etc. The GNSS can include a global positioning system (GPS), a global navigation satellite system (GLONASS), a beidu navigation satellite system (BDS), a quasi-zenith satellite system (QZSS), and / or a satellite based augmentation systems (SBAS).

[0124] The electronic device 100 implements a display function through a GPU, a display screen 194, and an application processor, etc. The GPU is a microprocessor for image processing, which is connected to the display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. The processor 110 can include one or more GPUs, which execute program instructions to generate or change display information.

[0125] The display screen 194 is configured to display images, videos, and the like. The display screen 194 includes a display panel. The display panel can be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flex light-emitting diode (FLED), a Miniled, a MicroLed, a Micro-oLed, a quantum dot light emitting diodes (QLED), or the like. In some embodiments, the electronic device 100 can include one or N display screens 194, where N is a positive integer greater than 1.

[0126] The electronic device 100 can implement the photographing function through the ISP, the camera 193, the video codec, the GPU, the display screen 194, and the application processor.

[0127] The ISP is configured to process the data fed back by the camera 193. For example, when taking a photo, the shutter is opened, the light is transmitted to the camera photosensitive element through the lens, the light signal is converted into an electrical signal, and the camera photosensitive element transmits the electrical signal to the ISP for processing to convert it into an image visible to the naked eye. The ISP can also optimize the noise, brightness, and skin color of the image. The ISP can also optimize the exposure, color temperature, and other parameters of the shooting scene. In some embodiments, the ISP can be disposed in the camera 193.

[0128] The camera 193 is configured to capture still images or videos. An object generates an optical image through a lens and projects it onto a photosensitive element. The photosensitive element can be a charge coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the light signal into an electrical signal, which is then transmitted to the ISP to convert it into a digital image signal. The ISP outputs the digital image signal to the DSP for processing. The DSP converts the digital image signal into an image signal in a standard RGB, YUV, or the like format. In some embodiments, the electronic device 100 can include one or N cameras 193, where N is a positive integer greater than 1.

[0129] The digital signal processor is used to process digital signals, which can process not only digital image signals but also other digital signals. For example, when the electronic device 100 selects a frequency point, the digital signal processor is used to perform Fourier transform on the frequency point energy, etc.

[0130] The NPU is a neural-network (NN) calculation processor, which can quickly process input information by referring to the structure of a biological neural network, such as the transmission mode between human brain neurons, and can also constantly self-learn. Through the NPU, the electronic device 100 can realize intelligent cognition and other applications, such as image recognition, face recognition, voice recognition, text understanding, etc.

[0131] The internal memory 121 can include one or more random access memories (RAMs) and one or more non-volatile memories (NVMs).

[0132] The random access memory can be directly read and written by the processor 110, and can be used to store executable programs (such as machine instructions) of an operating system or other programs running in the background, and can also be used to store data of users and application programs, etc.

[0133] The non-volatile memory can also store executable programs and store data of users and application programs, etc., which can be loaded into the random access memory in advance for direct reading and writing by the processor 110.

[0134] The external memory interface 120 can be used to connect an external non-volatile memory, to realize the expansion of the storage capacity of the electronic device 100.

[0135] The electronic device 100 can realize audio functions through the audio module 170, the speaker 170A, the receiver 170B, the microphone 170C, the earphone interface 170D, and the application processor, etc. For example, music playing, recording, etc.

[0136] The audio module 170 is used to convert digital audio information into an analog audio signal output, and is also used to convert an analog audio input into a digital audio signal. The audio module 170 can also be used to encode and decode audio signals. In some embodiments, the audio module 170 can be arranged in the processor 110, or some functional modules of the audio module 170 can be arranged in the processor 110.

[0137] The speaker 170A, also known as a "loudspeaker", is used to convert an audio electrical signal into an acoustic signal. The electronic device 100 can listen to music or listen to a hands-free call through the speaker 170A.

[0138] The receiver 170B, also called "earpiece", is used to convert audio electrical signals into sound signals. When the electronic device 100 answers a phone call or a voice message, the user can answer the voice by placing the receiver 170B close to the ear.

[0139] The microphone 170C, also called "microphone", "sound collector", is used to convert sound signals into electrical signals. When making a phone call or sending a voice message, the user can make a sound by placing the mouth close to the microphone 170C, and input the sound signal into the microphone 170C. The electronic device 100 can be provided with at least one microphone 170C. In some other embodiments, the electronic device 100 can be provided with two microphones 170C, which can realize the noise reduction function in addition to collecting sound signals. In some other embodiments, the electronic device 100 can be provided with three, four or more microphones 170C, which can realize the collection of sound signals, noise reduction, and identification of sound sources, and realize the directional recording function, etc.

[0140] The earphone interface 170D is used to connect a wired earphone. The earphone interface 170D can be a USB interface 130, or a 3.5mm open mobile terminal platform (OMTP) standard interface, or a cellular telecommunications industry association of the USA (CTIA) standard interface.

[0141] The pressure sensor 180A is used to sense pressure signals, and can convert the pressure signals into electrical signals. In some embodiments, the pressure sensor 180A can be provided on the display screen 194. There are many types of pressure sensors 180A, such as resistance type pressure sensors, inductance type pressure sensors, and capacitance type pressure sensors. In some embodiments, touch operations with the same touch position but different touch operation intensities can correspond to different operation instructions. For example, when a touch operation with a touch operation intensity less than a first pressure threshold is applied to a short message application icon, an instruction to view a short message is executed. When a touch operation with a touch operation intensity greater than or equal to the first pressure threshold is applied to the short message application icon, an instruction to create a new short message is executed.

[0142] The fingerprint sensor 180H is used to collect fingerprints. The electronic device 100 can use the collected fingerprint characteristics to realize fingerprint unlocking, access to application lock, fingerprint shooting, fingerprint answering incoming calls, etc.

[0143] Touch sensor 180K, also referred to as a "touch device". Touch sensor 180K can be disposed on display screen 194, and touch sensor 180K and display screen 194 together form a touch screen, also referred to as a "touch panel". Touch sensor 180K is configured to detect a touch operation applied to or near the touch sensor 180K. The touch sensor can transmit the detected touch operation to the application processor to determine the touch event type. Visual output related to the touch operation can be provided through display screen 194. In other embodiments, touch sensor 180K can also be disposed on the surface of electronic device 100, which is different from the position where display screen 194 is located.

[0144] Keys 190 include a power key, a volume key, and the like. Keys 190 can be mechanical keys. Alternatively, keys 190 can be touch keys. Electronic device 100 can receive key input and generate key signal input related to user settings and function control of electronic device 100.

[0145] Motor 191 can generate a vibration prompt.

[0146] Indicator 192 can be an indicator light, which can be used to indicate a charging state, a power change, and can also be used to indicate a message, a missed call, a notification, and the like.

[0147] Internal memory 121 is configured to store predefined operations that can be performed by electronic device 100 in a locked state. Specifically, internal memory 121 can record resources that can be accessed by electronic device 100 in a locked state, and specific access operations (e.g., modification, reading, etc.) that can be performed on the resources. In some embodiments of the present application:

[0148] Internal memory 121 can be used to store standard identity authentication information of one or more users. The identity authentication information is used to identify a user, and can include identity authentication information corresponding to a first authentication method, and can also include identity authentication information corresponding to a second authentication method. For example, the identity authentication information can include a password, a pattern, a face, a voiceprint, a fingerprint, a palm print, a retina, an iris, a human odor, a face shape, blood pressure, blood oxygen, blood sugar, respiratory rate, heart rate, one cycle of electrocardiogram waveform, deoxyribo nucleic acid (DNA), a signature, a body posture (e.g., walking gait), and the like.

[0149] Receiver 170B, microphone 170C, display screen 194, camera 193, keys 190, sensor module 180 (e.g., pressure sensor 180A, gyroscope sensor 180B), earphone 170D, and the like can be used to receive a first operation instruction input by a user. The details of the first operation instruction can be referred to the description of subsequent method embodiments.

[0150] The mobile communication module 150 and the wireless communication module 160 can be configured to receive the first operation instruction sent by another device, and can also be configured to receive the weak authentication factor sent by another device.

[0151] The display screen 194, the camera 193, the fingerprint sensor 180H, the receiver 170B, the microphone 170C, the optical sensor, the electrode, and the like can be configured to collect the weak authentication factor input by the user. Specifically, the display screen 194 can be configured to collect the password, the figure, the signature input by the user. The camera 193 can be configured to collect the face, the iris, the retina, the face shape, the body posture, and the like of the user. The fingerprint sensor 180H can be configured to collect the fingerprint input by the user. The receiver 170B and the microphone 170C can be configured to collect the voice input by the user. The optical sensor can be configured to collect the PPG signal (for example, the blood pressure, the blood oxygen, the blood sugar, the respiratory rate, the heart rate, the electrocardiogram waveform in one cycle, and the like) by using the PPG technology. The electrode configured by the electronic device 100 can be configured to collect the electrocardiogram waveform in one cycle by using the ECG technology.

[0152] The processor 110 can analyze the weak authentication factor collected by each of the above modules, and determine the security level of the weak authentication factor. The processor is further configured to determine the risk level of the operation corresponding to the first operation instruction. Then, the processor 110 is further configured to create a restricted execution environment according to the risk level of the operation corresponding to the first operation instruction and the security level of the weak authentication factor, and respond to the first operation instruction in the restricted execution environment to schedule each module of the electronic device 100 to perform the corresponding operation.

[0153] In some embodiments of the present application:

[0154] The mobile communication module 150 and the wireless communication module 160 in the electronic device 100 can be configured to receive the second operation instruction sent by another device.

[0155] The processor 110 can be configured to determine the risk level of the operation corresponding to the second operation instruction. Then, the processor 110 is further configured to create a restricted execution environment according to the risk level of the operation corresponding to the second operation instruction, and respond to the second operation instruction in the restricted execution environment to schedule each module of the electronic device 100 to perform the corresponding operation.

[0156] For the role of each module of the electronic device 100, please refer to the detailed description of the subsequent method embodiments, which will not be repeated here.

[0157] The software system of the electronic device 100 can employ a layered architecture, an event-driven architecture, a microkernel architecture, a microservices architecture, or a cloud architecture. Embodiments of the present application take an Android system with a layered architecture as an example to illustrate the software structure of the electronic device 100.

[0158] Figure 2 is a software structure block diagram of the electronic device 100 of embodiments of the present application.

[0159] A layered architecture divides software into several layers, each of which has a clear role and division of labor. Layers communicate with each other through software interfaces. In some embodiments, an Android system is divided into four layers, from top to bottom, an application layer, an application framework layer, an Android runtime and system library, and a kernel layer.

[0160] The application layer can include a series of application packages.

[0161] As shown in Figure 2 , the application packages can include voice assistants, cameras, galleries, calendars, calls, maps, navigation, WLAN, Bluetooth, music, videos, short messages, and the like.

[0162] The application framework layer provides application programming interfaces (APIs) and programming frameworks for the applications of the application layer. The application framework layer includes some pre-defined functions.

[0163] As shown in Figure 2 , the application framework layer can include window managers, content providers, view systems, phone managers, resource managers, notification managers, and the like.

[0164] The window manager is used to manage window programs. The window manager can obtain the size of the display screen, determine whether there is a status bar, lock the screen, and take screenshots, etc.

[0165] The content provider is used to store and obtain data, and make the data accessible to applications. The data can include videos, images, audio, dialed and received calls, browsing history and bookmarks, phone books, and the like.

[0166] The view system includes visual controls, such as controls for displaying text, controls for displaying pictures, and the like. The view system can be used to build applications. A display interface can be composed of one or more views. For example, a display interface including a short message notification icon can include a view for displaying text and a view for displaying pictures.

[0167] The telephony manager is used to provide the communication function of the electronic device 100. For example, the management of the call status (including the connection, the hang-up, etc.).

[0168] The resource manager provides various resources for the application program, such as the localized string, the icon, the picture, the layout file, the video file, etc.

[0169] The notification manager enables the application program to display the notification information in the status bar, which can be used to convey the notification type of the message, which can automatically disappear after a short stay without the user interaction. For example, the notification manager is used to notify the download completion, the message reminder, etc. The notification manager can also be the notification in the form of the chart or the scroll bar text appearing in the top status bar of the system, for example, the notification of the application program running in the background, and can also be the notification in the form of the dialogue window appearing on the screen. For example, the text information is prompted in the status bar, the prompt sound is emitted, the electronic device is vibrated, the indicator light is blinked, etc.

[0170] The Android runtime includes the core library and the virtual machine. The Android runtime is responsible for the scheduling and management of the Android system.

[0171] The core library contains two parts: one part is the function function required to be called by the java language, and the other part is the core library of the Android.

[0172] The application program layer and the application program framework layer run in the virtual machine. The virtual machine executes the java file of the application program layer and the application program framework layer into the binary file. The virtual machine is used to execute the management of the object life cycle, the stack management, the thread management, the security and the exception management, and the garbage collection, etc.

[0173] The system library can include multiple function modules. For example: the surface manager, the media library, the three-dimensional graphics processing library (for example: OpenGL ES), the 2D graphics engine (for example: SGL), etc.

[0174] The surface manager is used to manage the display subsystem, and provides the fusion of the 2D and 3D layers for multiple application programs.

[0175] The media library supports the playback and recording of multiple commonly used audio, video formats, and static image files, etc. The media library can support multiple audio and video coding formats, for example: MPEG4, H.264, MP3, AAC, AMR, JPG, PNG, etc.

[0176] The three-dimensional graphics processing library is used to realize the three-dimensional graphics drawing, the image rendering, the synthesis, and the layer processing, etc.

[0177] The 2D graphics engine is the drawing engine of the 2D drawing.

[0178] The kernel layer is the layer between hardware and software. The kernel layer contains at least the display driver, camera driver, audio driver, and sensor driver.

[0179] The following describes the communication system 10 provided in the embodiments of this application.

[0180] like Figure 3 As shown, the communication system 10 includes electronic device 100, and may also include electronic device 200, or electronic device 300.

[0181] The number of electronic devices 100, 200, or 300 can be one or more.

[0182] The implementation of electronic device 100 and the various operations performed by electronic device 100 can be referred to the above. Figure 1 or Figure 2 The relevant descriptions will not be repeated here.

[0183] This application does not limit the specific type of electronic device 200 or electronic device 300. The type of electronic device 200 or electronic device 300 can be referred to the above description of the type of electronic device 100. For example, electronic device 100 can be a smartphone, and electronic device 200 can be a smartwatch, smart bracelet, earphones, etc. As another example, electronic device 100 can be a smart screen, large-screen TV, laptop computer, etc., and electronic device 300 can be a smartphone.

[0184] Multiple electronic devices in communication system 10 can be configured with different software operating systems (OS), or they can all be configured with the same software operating system. Operating systems include, but are not limited to, those mentioned above. And so on. Among them, It refers to Huawei's HarmonyOS operating system.

[0185] Communication connections are established between electronic devices 100 and 200, or between electronic devices 100 and 300. These communication connections may include, but are not limited to: wired connections, wireless connections such as Bluetooth (BT) connections, wireless local area networks (WLANs) such as Wireless Fidelity point-to-point (Wi-Fi P2P) connections, near field communication (NFC) connections, infrared (IR) connections, and remote connections (such as connections established through a server), etc.

[0186] For example, any two electronic devices in the communication system 10 can be connected by logging in the same account. For example, the two electronic devices can log in the same Huawei account and remotely connect and communicate through the server. Any two electronic devices can also log in different accounts, but are connected through binding. After one electronic device logs in an account, it can bind other electronic devices that log in different accounts or are not logged in in the device management application, and then the electronic devices can communicate through the device management application. Any two electronic devices can also establish a connection through scanning a two-dimensional code, near field communication (NFC) touch, searching for a Bluetooth device, and the like, which are not limited herein. In addition, the electronic devices in the communication system 10 can also be connected and communicated in combination with any of the above manners, which are not limited herein.

[0187] In some embodiments of the present application, the electronic device 200 can be configured to receive a user operation carrying a first operation instruction, and then send indication information of the user operation to the electronic device 100. For example, when the electronic device 200 is a headset connected to the electronic device 100, it can receive a voice instruction input by the user, and then send the voice instruction to the electronic device 100.

[0188] In some embodiments of the present application, the electronic device 200 can be configured to receive a user operation carrying a first operation instruction, and then send indication information of the user operation to the electronic device 100. For example, when the electronic device 200 is a headset connected to the electronic device 100, it can receive a voice instruction input by the user, and then send the voice instruction to the electronic device 100.

[0189] In some embodiments of the present application, the electronic device 200 can be configured to receive a user operation carrying a weak authentication factor, and then send indication information of the user operation to the electronic device 100. For example, when the electronic device 200 is a headset connected to the electronic device 100, it can receive a voice instruction input by the user carrying a voiceprint, and then send the voice instruction carrying the voiceprint to the electronic device 100.

[0190] In some embodiments of the present application, the electronic device 200 can be configured to receive a user operation carrying a weak authentication factor, identify the weak authentication factor carried by the user operation, and send the weak authentication factor to the electronic device 100. For example, when the electronic device 200 is a smart watch connected to the electronic device 100, the electronic device 200 can receive a voice instruction input by a user carrying a voiceprint, identify the voiceprint carried by the voice instruction, and then send the voiceprint information to the electronic device 100.

[0191] In some embodiments of the present application, the electronic device 300 can be configured to receive a user operation, identify the intention of the user operation, generate a second operation instruction according to the intention of the user operation, and send the second operation instruction to the electronic device 100. For example, when the electronic device 300 is a smart phone and the electronic device 100 is a smart screen, the electronic device 300 can receive a user operation for screen projection to the smart screen, and then the electronic device 300 can generate a screen projection request (i.e., a second operation instruction) and send the screen projection request to the smart screen.

[0192] Figure 3 The communication system 10 shown is only an example. In actual implementation, the communication system 10 can also include more terminal devices, which are not limited herein. The communication system 10 can also be referred to as a distributed system or other names, which are not limited herein.

[0193] The roles of the devices in the communication system 10 can be referred to the detailed description of the subsequent method embodiments.

[0194] Reference Figure 4 , Figure 4 A flowchart of an access control method based on a weak authentication factor provided in some embodiments of the present application.

[0195] As Figure 4 shown, the method can include the following steps:

[0196] In step S101, when the electronic device 100 is in a locked state, a first operation instruction and a weak authentication factor are obtained.

[0197] In some embodiments of the present application, the electronic device 100 can have two states: a locked state and an unlocked state. The specific definitions of the locked state and the unlocked state can be referred to the related description above.

[0198] When the electronic device 100 is in the locked state, the display screen can be in a bright screen state or an off-screen state, which is not limited herein. The electronic device 100 can enter the locked state by default when no user operation is received for a long time, or can enter the locked state in response to a user operation (e.g., an operation of pressing a power button). For example, Figure 5A , Figure 5AA user interface 50 displayed when the electronic device 100 is in a locked state is shown.

[0199] The correspondence between the first operation instruction and the operation requested to be performed by the electronic device 100 can be pre-set by the electronic device 100, which is not limited herein. In embodiments of the present application, the resource in the electronic device 100 requested to be accessed by the first operation instruction can be referred to as a first resource. The classification and specific content of the resource in the electronic device 100 can be referred to the relevant description above. The first resource can include one or more resources, which is not limited herein.

[0200] In some embodiments, the first operation instruction is used to request the electronic device 100 to perform an operation other than the predefined operation in the locked state. That is, the first operation instruction is used to request to access a certain resource in the electronic device 100, and the access to the resource is not executable by the electronic device in the locked state. Specifically, the electronic device 100 pre-stores predefined operations executable in the locked state. That is, the electronic device 100 records the resources that can be accessed in the locked state and the specific access operations (such as reading, adding, deleting, writing, modifying, etc.) executable on the resources. The detailed definition of the predefined operation can be referred to the relevant description above.

[0201] The form of the first operation instruction is not limited in embodiments of the present application. The first operation instruction can include, but is not limited to, voice-carrying semantics, gestures, facial expressions, signatures, body postures, lip shapes, key pressing operations or shaking operations, etc. Among them, the gestures, facial expressions, signatures, body postures, and lip shapes can be static information at a time point, such as gestures at a time point, or dynamic change information within a period of time, such as lip shape changes within a period of time, etc.

[0202] The electronic device 100 can obtain the first operation instruction in the following ways:

[0203] 1. The electronic device 100 directly receives a user operation carrying the first operation instruction and extracts the first operation instruction from the user operation

[0204] In the locked state, the electronic device 100 can periodically or under certain triggering conditions, start receiving user operations input by the user and extract the first operation instruction therefrom. The triggering conditions can include various conditions, such as starting the voice assistant, detecting the wrist lifting operation by the electronic device 100, detecting the operation of tapping the display screen by the electronic device 100, etc. Here, the electronic device 100 can continuously run the wake-up word recognition program at low power consumption, and start the voice assistant after detecting the wake-up word. In this way, by starting to receive user operations and extracting the first operation instruction therefrom under the triggering conditions, the power consumption of the electronic device 100 can be reduced.

[0205] The user operation carrying the first operation instruction can have various forms. For example, it can include a voice carrying semantics, one or more images containing gestures / facial expressions / postures / oral forms, a sliding operation containing a signature, a key pressing operation, a shaking operation of the electronic device 100, and the like.

[0206] The electronic device 100 can use a corresponding module to receive the user operation carrying the first operation instruction. For example, the voice carrying semantics can be received through the receiver 170B and the microphone 170C, the sliding operation containing a signature can be received through the display screen 194, the sliding operation containing gestures can be received through the camera 193, the image containing gestures / facial expressions / postures / oral forms can be received through the key 190, the key pressing operation can be received through the gyroscope sensor 180B, the shaking operation can be received, and the like.

[0207] Then, the electronic device 100 can identify or extract the first operation instruction from the received user operation. For example, the electronic device 100 can extract semantics from the voice, extract gestures / facial expressions / postures / oral forms from one or more images, extract a signature or gestures from a sliding operation, and the like.

[0208] The electronic device 100 can identify the first operation instruction contained in the user operation locally or through a network. For example, the electronic device 100 can identify semantics in the voice, gestures / facial expressions / postures in the image, and the like through the processor 110 locally, or upload the voice or image to a network server or other device to identify semantics in the voice, gestures / facial expressions / postures / oral forms in the image, and the like through the network server or other device.

[0209] The voice carries semantics, and different voices can carry different semantics. The user can input different operation instructions by inputting different voices. For example, the voice "navigate to home" can be used to request the electronic device to start a navigation application and navigate to the home position; the voice "open the photo album" can be used to request the electronic device to start a gallery application.

[0210] When the first operation instruction received by the electronic device 100 is a voice, the electronic device 100 needs to start a voice assistant first. The voice assistant is an application installed in the electronic device, which is used to support the user to control the electronic device through voice instructions. Generally, the voice assistant is in a dormant state, and the user can wake up or start the voice assistant before using the voice assistant. Only after the voice assistant is woken up, the electronic device can receive and recognize the voice instruction input by the user. The voice used to wake up the voice assistant can be called a wake-up word, for example, the wake-up word can be the voice "Xiao E Xiao E". In other embodiments, the voice assistant in the electronic device 100 can be in a wake-up state for a long time, and does not have to be woken up by a wake-up word. The voice assistant is only a word used in this application, which can also be called an intelligent assistant and other words, which are not limited here.

[0211] The gesture can be a gesture of touching the electronic device, such as a sliding gesture, a clicking gesture, and the like touching the display screen. The gesture can also be a hovering gesture that does not contact the electronic device, such as a gesture of opening a palm above the display screen or a fist gesture, and the like. The hovering gesture can also be called a floating gesture, an air gesture, a remote gesture, and the like. The user can input different operation instructions by inputting different gestures. For example, the gesture of opening a palm above the display screen can be used to request the electronic device to start a navigation application and navigate to the home location; the gesture of clenching a fist above the display screen can be used to request the electronic device to start a gallery application.

[0212] The facial expression can include, for example, a blinking expression, a mouth opening expression, and the like. The user can input different operation instructions by inputting different facial expressions.

[0213] The body posture can include, for example, nodding, shaking, arm swinging, squatting, and the like. The user can input different operation instructions by inputting different body postures. For example, the body posture of nodding can be used to request the electronic device to play music; the body posture of shaking can be used to request the electronic device to pause playing music.

[0214] There can be various ways to press the key or shake the electronic device, and the user can input different operation instructions by pressing the key or shaking the electronic device in different ways. For example, the operation of double-clicking the power key can be used to request the electronic device to play music, and shaking the electronic device twice can be used to request the electronic device to pause playing music.

[0215] Different mouth shapes can be used to indicate different operations. For example, the change of the mouth shape corresponding to the voice "play music" within a period of time can be used to request the electronic device to play music. Using the mouth shape to input the first operation instruction can facilitate the user to control the electronic device through lip language, and enrich the use scenarios and use range of the electronic device.

[0216] Not limited to the above several user operations, the first operation instruction can also be implemented in other forms, such as a sound of snapping fingers, etc., which are not limited here.

[0217] 2. Other devices send the electronic device 100 the indication information of the user operation, and the electronic device 100 extracts the first operation instruction from the indication information of the user operation

[0218] The electronic device 100 can establish a communication connection with other devices, such as the electronic device 200. The way the electronic device 100 establishes a communication connection with other electronic devices can be referred to Figure 3 for relevant description.

[0219] The user operation received by the other device carries the first operation instruction. The timing and manner of the other device receiving the user operation carrying the first operation instruction are the same as the timing and manner of the electronic device 100 receiving the user operation carrying the first operation instruction in the above-mentioned first mode, and can be referred to

[0220] The indication information of the user operation sent by the other device can be the user operation itself, or other indication information of the user operation. For example, when the electronic device 200 is a headset connected to the electronic device 100, it can receive a voice input by the user containing semantics, and then send the voice to the electronic device 100. For another example, when the electronic device 200 is a camera connected to the electronic device 100, it can collect an image input by the user containing a hand gesture / face expression / physical posture, and then send the image to the electronic device 100. For another example, when the electronic device 200 is a smart bracelet connected to the electronic device 100, it can receive a press operation on the power key, and then send the indication information of the press operation to the electronic device 100.

[0221] The way the electronic device 100 extracts the first operation instruction from the indication information of the user operation is the same as the way the electronic device 100 extracts the first operation instruction from the received user operation in the above-mentioned first mode, and can be referred to

[0222] In the above-mentioned second case, the other device, such as the electronic device 200, can be regarded as a peripheral device or a accessory device of the electronic device 100.

[0223] In the above-mentioned second mode, the electronic device 200 can send the indication information of the user operation to the electronic device 100 by default, or send the indication information of the user operation to the electronic device 100 selected by the user. The way in which the user selects the electronic device 100 is not limited, for example, the user can select the electronic device 100 by voice or selection operation on the user interface. For example, when the electronic device 200 is a headset, the received voice can be sent to the connected electronic device 100 by default. For another example, the electronic device 200 can detect the voice instruction "play music using the mobile phone", and send the voice to the mobile phone (i.e. the electronic device 100) mentioned in the voice instruction.

[0224] 3. The other device receives the user operation carrying the first operation instruction, extracts the first operation instruction from the user operation, and sends the first operation instruction to the electronic device 100

[0225] The electronic device 100 can establish a communication connection with the other device, for example, the electronic device 200. The way in which the electronic device 100 establishes a communication connection with the other device can be referred to the related description. Figure 3 Related description.

[0226] The other device, for example, the electronic device 200, can first receive the user operation carrying the first operation instruction, identify the first operation instruction contained in the user operation, and then send the first operation instruction to the electronic device 100. Here, the other device receives the user operation carrying the first operation instruction, which is similar to the way in which the electronic device 100 receives the user operation carrying the first operation instruction in the above-mentioned first mode, and the related description can be referred to. The way in which the other device identifies the first operation instruction contained in the received user operation is the same as the way in which the electronic device 100 identifies the first operation instruction contained in the user operation in the above-mentioned first mode, and the related description can be referred to.

[0227] For example, the electronic device 200 can receive the voice input by the user, then identify the semantic information of the voice, and then send the semantic information to the electronic device 100. For another example, the electronic device 200 can collect the image input by the user, which contains gestures / facial expressions / posture, identify the gestures / facial expressions / posture in the image, and then send the gestures / facial expressions / posture information to the electronic device 100.

[0228] In the above-mentioned third mode, the electronic device 200 can send the first operation instruction to the electronic device 100 by default, or send the first operation instruction to the electronic device 100 selected by the user.

[0229] The weak authentication factor refers to the identity authentication information that does not meet the unlocking requirement of the electronic device. The identity authentication information can include a password, a pattern, and a biological feature. The identity authentication information will be described in detail in the related description. The electronic device 100 can establish a communication connection with the other device, for example, the electronic device 200. The way in which the electronic device 100 establishes a communication connection with the other device can be referred to the related description. Related description. The other device, for example, the electronic device 200, can first receive the user operation carrying the first operation instruction, identify the first operation instruction contained in the user operation, and then send the first operation instruction to the electronic device 100. Here, the other device receives the user operation carrying the first operation instruction, which is similar to the way in which the electronic device 100 receives the user operation carrying the first operation instruction in the above-mentioned first mode, and the related description can be referred to. The way in which the other device identifies the first operation instruction contained in the received user operation is the same as the way in which the electronic device 100 identifies the first operation instruction contained in the user operation in the above-mentioned first mode, and the related description can be referred to. For example, the electronic device 200 can receive the voice input by the user, then identify the semantic information of the voice, and then send the semantic information to the electronic device 100. For another example, the electronic device 200 can collect the image input by the user, which contains gestures / facial expressions / posture, identify the gestures / facial expressions / posture in the image, and then send the gestures / facial expressions / posture information to the electronic device 100. In the above-mentioned third mode, the electronic device 200 can send the first operation instruction to the electronic device 100 by default, or send the first operation instruction to the electronic device 100 selected by the user. The weak authentication factor refers to the identity authentication information that does not meet the unlocking requirement of the electronic device. The identity authentication information can include a password, a pattern, and a biological feature. The identity authentication information will be described in detail in the related description.

[0230] In the embodiments of the present application, the identity authentication information that does not meet the electronic device unlocking requirement, i.e., the weak authentication factor, can include the following two kinds:

[0231] 1. The identity authentication information that is lower than the required standard of the first authentication mode.

[0232] The first authentication mode is an identity authentication mode with a higher ACL. The ACL determination mode can refer to the related description above. The first authentication mode can be pre-set by the electronic device or the manufacturer of the electronic device, which can refer to the related description above. For example, the first authentication mode can include password authentication, pattern authentication, fingerprint authentication, and face authentication, etc.

[0233] The electronic device can pre-store the identity authentication information of the user for subsequent use of the corresponding first authentication mode for unlocking. For example, when the first authentication mode includes password authentication, the electronic device can pre-store one or more passwords. When the first authentication mode includes pattern authentication, the electronic device can pre-store one or more patterns. When the first authentication mode includes biometric authentication, the electronic device can pre-store one or more biometric features, such as fingerprints, faces, etc.

[0234] The identity authentication information that meets the required standard of the first authentication mode can include, for example, a password or a pattern pre-stored by the electronic device, or a biometric feature that matches the pre-stored biometric feature (such as a fingerprint, a face, etc.) to a first value. The electronic device can switch from the locked state to the unlocked state after receiving the identity authentication information that meets the required standard of the first authentication mode of the electronic device. The first value can be pre-set.

[0235] The identity authentication information that is lower than the required standard of the first authentication mode can include, for example, a biometric feature that matches the pre-stored biometric feature to a value lower than the first value, or a password or a pattern that matches the pre-stored password or pattern to a certain value.

[0236] Compared with the identity authentication information that meets the required standard of the first authentication mode, the user does not need to perform tedious operations or multiple operations to input the identity authentication information that is lower than the required standard of the first authentication mode. For example, the user can input a pattern similar to the pre-set pattern, remotely align the face to the camera of the electronic device without having to keep still, press the position of the fingerprint recognition sensor with a water-stained finger, or align the camera with the finger, etc. Obviously, this can reduce the requirements for the user to input the identity authentication information, so that the user can use the electronic device more simply, conveniently, and freely.

[0237] 2. The identity authentication information that meets the required standard of the second authentication mode.

[0238] The second authentication manner is an identity authentication manner with a lower ACL. The ACL can be determined in the manner described above. The second authentication manner can be pre-set by the electronic device or the manufacturer of the electronic device. For example, the second authentication manner can include voiceprint authentication, heart rate authentication, body posture authentication, and the like.

[0239] Identity authentication information meeting the required criteria of the second authentication manner can include, for example, a biological feature with a matching degree of a second value with a biological feature (such as a voiceprint or a body posture) pre-stored by the electronic device. The second value can be pre-set.

[0240] Through the identity authentication information meeting the required criteria of the second authentication manner, the user can use a more convenient manner to control the electronic device. For example, the user can control the electronic device through a voice instruction or a body posture, and can control the electronic device without touching in a driving, cooking, or exercising scenario, thereby bringing great convenience.

[0241] In the embodiments of the present application, the number of weak authentication factors received by the electronic device 100 can be one or multiple, which is not limited herein. That is, the electronic device 100 can receive multiple different weak authentication factors.

[0242] Similar to the first operation instruction, the electronic device can obtain the weak authentication factor in the following manners in the embodiments of the present application:

[0243] 1. The electronic device 100 directly receives a user operation carrying a weak authentication factor and extracts the weak authentication factor from the user operation

[0244] In the locked state, the electronic device 100 can periodically or under certain triggering conditions, start receiving a user operation input by a user and extract a weak authentication factor therefrom. The triggering conditions can include multiple conditions, for example, can include after starting a voice assistant, after the electronic device 100 detects a wrist lifting operation, after the electronic device 100 detects a display screen tapping operation, and the like. In this way, by starting to collect the weak authentication factor under the triggering condition, the power consumption of the electronic device 100 can be reduced.

[0245] Here, the user operation carrying the weak authentication factor can be various, for example, can include a user operation (such as a click operation) indicating a password, a user operation (such as a sliding operation) indicating a figure, an image carrying a biological feature, or a sliding operation, and the like.

[0246] The electronic device 100 can schedule the corresponding module to receive the user operation carrying the weak authentication factor. For example, the electronic device 100 can receive a user operation (e.g., a click operation) indicating a password through the display screen 194, a user operation (e.g., a slide operation) indicating a figure, capture an image containing a biological feature (e.g., a face, an iris, a retina, a face shape, a body posture) through the camera 193, capture a fingerprint input by a user through the fingerprint sensor 180H, capture a voice carrying a voiceprint input by a user through the receiver 170B and the microphone 170C, capture a heart rate through the optical sensor, and the like.

[0247] Subsequently, the electronic device 100 can identify the weak authentication factor contained in the received user operation. For example, the voiceprint is extracted from the voice, the password is extracted from the click operation, the figure or signature is extracted from the slide operation, the face, the iris, the retina, the face shape, the body posture, or the fingerprint is extracted from the image, and the like.

[0248] The electronic device 100 can identify the weak authentication factor contained in the user operation locally or through a network. For example, the electronic device 100 can identify the voiceprint in the voice, the body posture or the face shape in the image, and the like, through the processor 110 locally, identify the operation of pressing the key directly through the key, identify the fingerprint through the fingerprint sensor 180H, and the like, and can upload the voice or the image to the network to identify the voiceprint in the voice, the body posture or the face shape in the image, and the like, through a network server or another device.

[0249] 2. The other device transmits the indication information of the user operation to the electronic device 100, and the electronic device 100 extracts the weak authentication factor from the indication information of the user operation

[0250] The electronic device 100 can establish a communication connection with another device, for example, the electronic device 200. The electronic device 100 and another electronic device can establish a communication connection in the manner described with reference to Figure 3 Related descriptions.

[0251] The user operation received by the other device carries the weak authentication factor. The timing and manner in which the other device receives the user operation carrying the weak authentication factor are the same as the timing and manner in which the electronic device 100 receives the user operation carrying the weak authentication factor in the first manner described above, and can be described with reference to related descriptions.

[0252] The indication information of the user operation sent by the other device can be the user operation itself or other indication information of the user operation. For example, the other device can collect a user operation (e.g., a click operation) indicating a password, a user operation (e.g., a sliding operation) indicating a figure, an image carrying a biological feature, or a sliding operation, and then send the indication information of the click operation or the sliding operation or the image to the electronic device 100, so that the electronic device 100 identifies the weak authentication factor from the indication information.

[0253] The electronic device 100 extracts the weak authentication factor from the indication information of the user operation in the same manner as the electronic device 100 extracts the weak authentication factor from the received user operation in the first form, which can be referred to the related description.

[0254] In the second form, the other device (e.g., the electronic device 200) can be regarded as an external device or an accessory device of the electronic device 100.

[0255] In the second form, the electronic device 200 can send the indication information of the user operation to the electronic device 100 by default or according to the electronic device 100 selected by the user.

[0256] 3. The other device receives the user operation carrying the weak authentication factor, extracts the weak authentication factor from the user operation, and then sends the weak authentication factor to the electronic device 100.

[0257] The electronic device 100 can establish a communication connection with the other device (e.g., the electronic device 200). The electronic device 100 establishes the communication connection with the other device in the same manner as the electronic device 100 establishes the communication connection with the other device in the first form, which can be referred to the related description. Figure 3

[0258] The other device (e.g., the electronic device 200) can first receive the user operation carrying the weak authentication factor, identify the weak authentication factor contained in the user operation, and then send the weak authentication factor to the electronic device 100. Here, the other device receives the user operation carrying the weak authentication factor in the same manner as the electronic device 100 receives the user operation carrying the weak authentication factor in the first form, which can be referred to the related description. The other device identifies the weak authentication factor contained in the received user operation in the same manner as the electronic device 100 identifies the weak authentication factor contained in the received user operation in the first form, which can be referred to the related description.

[0259] ​For example, the electronic device 200 can receive a voice input by a user, and then identify a voiceprint of the voice, and then send the voiceprint information to the electronic device 100. For another example, the electronic device 200 can collect an image input by a user, and the image contains a biological feature (for example, a face, a fingerprint, a palm print, a retina, an iris, a body posture, a face shape), and then identify the biological feature contained in the image, and then send the biological feature information to the electronic device 100.

[0260] In the third mode described above, the electronic device 200 can send the weak authentication factor to the electronic device 100 by default, or according to the electronic device 100 selected by the user.

[0261] In some embodiments of the present application, the electronic device 100 can receive the first operation instruction and the weak authentication factor respectively. For example, the electronic device 100 can first collect a voice instruction "play music" through a microphone, and then collect a face image through a camera.

[0262] In some embodiments of the present application, the electronic device 100 can receive the first operation instruction and the weak authentication factor simultaneously. In this way, the user operation can be simplified, and the user experience is better.

[0263] Figures 5B-5D The scenarios in which the electronic device 100 receives the first operation instruction and the weak authentication factor simultaneously are shown respectively. In Figures 5B-5D , the electronic device 100 is in a locked state.

[0264] Exemplarily, reference is made to Figure 5B , Figure 5B Exemplarily, the scenario in which the electronic device 100 (for example, a mobile phone) receives the first instruction and the weak authentication factor simultaneously is shown. As shown in Figure 5B , the electronic device 100 can collect a voice instruction "navigate to home" through a microphone, and the voice instruction carries a voiceprint, and the electronic device 100 can also identify a corresponding semantic through the voice instruction. The first resource requested to be accessed by the semantic includes a navigation application and the address of "home".

[0265] Exemplarily, reference is made to Figure 5C , Figure 5C Exemplarily, another scenario in which the electronic device 100 (for example, a mobile phone) receives the first instruction and the weak authentication factor simultaneously is shown. As shown in Figure 5CAs shown, the electronic device 100 can capture an image including the open-palm gesture through the camera, the electronic device 100 can recognize the open-palm gesture in the gesture image, and can also recognize the features (e.g., fingerprint, finger joint size, etc.) of the palm. The open-palm gesture can be used to request the electronic device 100 to "navigate to home", and the first resource accessed by the request includes the navigation application and the address of "home".

[0266] Exemplarily, reference is made to Figure 5D , Figure 5D Exemplarily, another scenario is shown in which the electronic device 100 (e.g., a smart bracelet) simultaneously receives a first instruction and a weak authentication factor. As shown, the electronic device 200 can capture the voice instruction "play music with the phone" through the microphone, the voice instruction carries a voiceprint, the electronic device 200 can recognize the voiceprint corresponding to the voice instruction, and can also recognize the semantic information corresponding to the voice instruction, and then send the semantic information and the voiceprint information to the electronic device 100. Here, the semantic information requests to access the first resource including the music application. Figure 5D

[0267] Not limited to Figures 5B-5D In the scenarios shown, in specific implementations, the electronic device 100 can also receive other forms of first operation instructions and weak authentication factors, which can be referred to the related descriptions above, and will not be listed one by one here.

[0268] In step S102, the electronic device 100 creates a restricted execution environment according to the first operation instruction and the weak authentication factor.

[0269] The restricted execution environment refers to a restricted execution environment. The execution environment can include a hardware environment and a software environment. The execution environment can be a sandbox or a function domain including multiple functions. In the restricted execution environment, the electronic device can only perform a specified part of the operation, and cannot perform other operations unexpected to the part of the operation. In other words, in the restricted execution environment, the electronic device can only access part of the resources of the electronic device, and cannot access other resources other than the part of the resources.

[0270] The embodiments of the present application do not limit the strategy of the electronic device 100 to create a restricted execution environment according to the first operation instruction and the weak authentication factor. For example, the electronic device 100 can create a restricted execution environment according to the type of the first operation instruction, the environment when the weak authentication factor is captured, etc. For example, when the first operation instruction is a voice-carrying semantic, a gesture, a facial expression, a signature, and a body posture, respectively, the number of operations that can be performed in the restricted execution environment created by the electronic device 100 decreases in turn.

[0271] ​In some embodiments of the present application, the electronic device 100 can create a restricted execution environment according to the risk level of the operation corresponding to the first operation instruction, and / or the security level of the weak authentication factor. Step S102 can specifically include steps S1021-S1024.

[0272] When the electronic device 100 receives multiple authentication factors, the multiple authentication factors can be received in sequence. For example, the user can input 5 sentences of speech respectively, and the electronic device 100 can extract a voiceprint from each sentence of speech as a weak authentication factor.

[0273] Step S1021, the electronic device 100 determines the risk level of the operation corresponding to the first operation instruction.

[0274] First, the electronic device 100 can first determine the operation corresponding to the first operation instruction.

[0275] The correspondence between the first operation instruction and the operation requested to be executed by the electronic device 100 can be pre-set by the electronic device 100, which is not limited here.

[0276] Specifically, different first operation instructions (including semantics, gestures, facial expressions, body postures, etc.) can be pre-set to correspond to different operations. For example, the semantics "navigate to home" or the gesture of spreading the palm in front of the display screen corresponds to starting a navigation application and navigating to the home position; the semantics "use the phone to play music" corresponds to starting a music application; the semantics "open the photo album" or the gesture of clenching the fist in front of the display screen corresponds to starting a gallery application; the body posture of nodding corresponds to playing music; the body posture of shaking the head corresponds to pausing the music. The pre-set correspondence between different semantics, gestures, facial expressions, body postures and operations can be stored in the electronic device 100 or in a network server, which is not limited here.

[0277] The electronic device 100 finds the operation corresponding to the first operation instruction in the local or network according to the pre-set information.

[0278] The operation corresponding to the first operation instruction includes an access operation on a certain resource, which is one or more resources in the electronic device, and the access operation can include one or more of reading, adding, deleting, writing, modifying, and executing, for example. The specific content of the resource and the access operation is described in the foregoing. The resources in the electronic device can include software resources, hardware resources, peripherals or resources of peripherals, etc., and are specifically described in the foregoing.

[0279] Then, the electronic device 100 can first determine the risk level of the operation corresponding to the first operation instruction.

[0280] In the embodiments of the present application, the electronic device 100 can pre-store risk levels corresponding to different operations respectively.

[0281] The embodiments of the present application can divide the operations executable by the electronic device 100 into different risk levels according to different granularity. The granularity is not limited in the present application. For example, the risk levels of the operations can be roughly divided into three levels: high, medium and low. For another example, the risk levels of the operations can be divided into 1-10 levels, and the higher the value is, the higher the risk level of the operation is.

[0282] In the embodiments of the present application, the higher the risk degree of privacy leakage brought to the user when the electronic device 100 executes an operation is, the higher the risk level of the operation is. The higher the privacy degree of the resource required to be accessed by an operation is, the higher the risk degree of privacy leakage brought to the user when the operation is executed is, and the higher the risk level of the operation is. For example, the risk degrees of viewing photos, viewing shopping records and viewing browsing records in the browser can decrease in turn. The higher the privacy degree of the access operation required by an operation is, the higher the risk level of the operation is. For example, the risk degrees of reading photos, deleting photos and adding photos can decrease in turn.

[0283] In some embodiments of the present application, the electronic device 100 can autonomously set the risk levels corresponding to different operations respectively. For example, the electronic device 100 can consider the categories of the resources required to be accessed by the operations, the locations and other factors to set the risk levels of different operations. For example, the risk level of the operation requiring to access third-party resources is higher than the risk level of the operation requiring to access system resources, and the risk level of the operation executed at home is lower than the risk level of the operation executed at other places.

[0284] In some embodiments of the present application, the electronic device 100 can also set the risk levels corresponding to different operations respectively according to the user demand. Specifically, the electronic device 100 can determine or set the risk levels of the operations executable by the electronic device 100 in response to the received user operation. For example, the electronic device 100 can provide a user interface in a setting application to allow the user to set the risk levels of the operations.

[0285] In some other embodiments of the present application, the risk level of the operation corresponding to the first operation instruction can also be determined according to the acquisition manner of the first operation instruction. For example, the security level of the first operation instruction obtained by the electronic device 100 through the above-mentioned first to third manners is successively lowered. That is, the security level of the first operation instruction obtained by the electronic device 100 through the first manner is higher than that of the first operation instruction obtained through the second or third manner. For another example, when the electronic device 100 receives the first operation instruction sent by the electronic device 200, the risk level of the operation corresponding to the first operation instruction can be determined according to the electronic device 200. For example, the higher the historical communication frequency between the electronic device 200 and the electronic device 100 is, the lower the risk level of the operation corresponding to the first operation instruction is.

[0286] In step S1022, the electronic device 100 determines the security level of the weak authentication factor.

[0287] In the embodiments of the present application, the weak authentication factor can be divided into different security levels according to different granularity. The granularity is not limited in the present application. For example, the security level of the weak authentication factor can be roughly divided into three levels of high, medium and low. For another example, the security level of the weak authentication factor can be divided into 1-10 levels, and the higher the value is, the higher the security level of the weak authentication factor is.

[0288] In the embodiments of the present application, the security level of the weak authentication factor can be determined according to the ACL of the identity authentication manner to which the weak authentication factor belongs. The higher the ACL of the identity authentication manner to which the weak authentication factor belongs is, the higher the security level of the weak authentication factor is.

[0289] In some other embodiments of the present application, the security level of the weak authentication factor can also be determined according to one or more of the following: the matching degree between the weak authentication factor and the pre-stored identity authentication information, the environment information when the weak authentication factor is received, the acquisition manner of the weak authentication factor, or the intensity of the corresponding voice when the weak authentication factor is a voiceprint.

[0290] The higher the matching degree between the weak authentication factor and the pre-stored identity authentication information is, or the quieter the environment when the weak authentication factor is received is, or the stronger the intensity of the corresponding voice when the weak authentication factor is a voiceprint is, the higher the security level of the weak authentication factor is.

[0291] When the electronic device 100 obtains the weak authentication factor through the above-mentioned first to third manners, the security level of the weak authentication factor obtained by the electronic device 100 is successively lowered. That is, the security level of the weak authentication factor obtained by the electronic device 100 through the first manner is higher than that of the weak authentication factor obtained through the second or third manner.

[0292] After performing S1022, the electronic device 100 can record the identity authentication mode to which the weak authentication factor belongs, the security level of the weak authentication factor, and the authentication validity period of the weak authentication factor. The authentication validity period of the weak authentication factor can be pre-set by the electronic device, for example, can be set as a fixed value such as invalidation after the restricted execution environment is created.

[0293] The order of S1021 and S1022 is not limited in the embodiments of the present application.

[0294] Optionally, S1023, the electronic device 100 judges whether to allow the operation corresponding to the first operation instruction according to the risk level of the operation corresponding to the first operation instruction and the security level of the weak authentication factor.

[0295] Specifically, the risk level of different operations and the security level of different authentication factors are pre-set in the electronic device 100, and each operation allowed to be performed by the electronic device 100 is set. The setting can be set in advance by the user or the manufacturer of the electronic device 100. The correspondence between the risk level of the operation and the security level of the authentication factor and the operation allowed to be performed by the electronic device 100 is not limited in the embodiments of the present application.

[0296] For example, when the risk level of the operation corresponding to the first operation instruction is high and the security level of the weak authentication factor is low, the operation corresponding to the first operation instruction is not allowed to be performed. For another example, when the risk level of the operation corresponding to the first operation instruction is low and the security level of the weak authentication factor is high, the operation corresponding to the first operation instruction is allowed to be performed.

[0297] In some embodiments, the electronic device 100 can match the risk level of the operation corresponding to the first operation instruction and the security level of the weak authentication factor to judge whether to allow the operation corresponding to the first operation instruction to be performed. Specifically, the electronic device 100 can pre-set the security level of the weak authentication factor for performing each operation. When the risk level of the operation is higher, the security level of the weak authentication factor required to perform the operation is also higher.

[0298] If the execution result of S1023 is yes, the electronic device 100 continues to perform the subsequent steps.

[0299] If the execution result of S1023 is no, the electronic device 100 no longer continues to perform the subsequent steps.

[0300] In some embodiments, if the execution result of S1023 is no, the electronic device 100 can also output prompt information, which can be used to prompt the user that the operation corresponding to the first operation instruction is not allowed to be performed at present.

[0301] In some embodiments, the prompt information can further prompt the user of the reason why the user is not allowed to perform the operation corresponding to the first operation instruction, for example, can include that the risk level of the operation corresponding to the first operation instruction is high, or the security level of the weak authentication factor is low.

[0302] In some embodiments, the prompt information can further prompt the user of the solution. For example, prompt the user to input a weak authentication factor with a higher security level, or prompt the user to unlock, etc., which is not limited here.

[0303] Regarding the implementation form of the prompt information, it is the same as the implementation form of the prompt information in the subsequent step S105, and specific reference can be made to the related description in the subsequent step.

[0304] In step S1024, the electronic device 100 creates a restricted execution environment according to the risk level of the operation corresponding to the first operation instruction and the security level of the weak authentication factor.

[0305] In some embodiments, the electronic device 100 can perform S1024 after receiving the weak authentication factor of the predetermined value. That is, the electronic device 100 can use multiple weak authentication factors to create a restricted execution environment.

[0306] The lower the risk level of the operation corresponding to the first operation instruction, or the higher the security level of the weak authentication factor, the more operations the electronic device 100 is allowed to perform. Here, the operations allowed to be performed by the electronic device 100, that is, the operations that can be performed in the restricted execution environment created by the electronic device 100.

[0307] The electronic device 100 is pre-set with the risk levels of different operations and the security levels of different authentication factors, and the operations allowed to be performed by the electronic device 100 under different risk levels of operations and different security levels of authentication factors. The setting can be set in advance by the user or the manufacturer of the electronic device 100. The present application does not limit the correspondence between the risk level of the operation and the security level of the authentication factor, and the operation allowed to be performed by the electronic device 100. When the electronic device receives the same first operation instruction and different weak authentication factors, it can create different restricted execution environments. When the electronic device receives different first operation instructions and the same weak authentication factor, it can also create different restricted execution environments.

[0308] In some embodiments, regardless of the risk level of the operation corresponding to the first operation instruction and the security level of the weak authentication factor, the predetermined operation in the locked state can be performed in the restricted execution environment created by the electronic device 100.

[0309] Exemplarily, referring to Table 1, exemplary operations allowed to be executed by the electronic device 100 under different risk levels of operations and different security levels of authentication factors are shown. In the table, the risk level of operations and the security level of authentication factors are both divided into 1-5 levels, and the higher the value is, the higher the risk level of operations is, and the higher the security level of weak authentication factors is.

[0310]

[0311]

[0312] Table 1

[0313] When the restricted execution environment is created, the electronic device 100 can record operations allowed to be executed by the electronic device 100 according to the risk level of operations and the security level of authentication factors. That is, the electronic device 100 records which specific access operations are allowed to be executed by the electronic device 100 on which resources or which type of resources.

[0314] In some embodiments, if the electronic device 100 has already created a restricted execution environment, the electronic device 100 can change the current restricted execution environment to the restricted execution environment described above according to the risk level of operations and the security level of authentication factors. Specifically, the electronic device 100 can change the recorded information to change the current restricted execution environment, which can be referred to the foregoing description.

[0315] In some embodiments, the electronic device 100 can also consider the number of weak authentication factors obtained in S101 when creating the restricted execution environment. For example, the more the number of weak authentication factors obtained in S101 is, the more operations allowed to be executed in the created restricted execution environment are.

[0316] In some embodiments, if the electronic device 100 executes S1023, the restricted execution environment created in S1024 must allow the operation corresponding to the first operation instruction to be executed. In this way, an effective restricted execution environment can be created, and the waste of resources in the electronic device 100 can be reduced.

[0317] In other embodiments, the electronic device 100 can not necessarily execute S1023, but directly execute S1024. At this time, the restricted execution environment created in S1024 does not necessarily allow the operation corresponding to the first operation instruction to be executed.

[0318] S103, the electronic device 100 executes the operation corresponding to the first operation instruction in the created restricted execution environment in response to the first operation instruction.

[0319] In some embodiments, if the electronic device does not perform S1023, before S103, the electronic device 100 further needs to determine whether the created limited execution environment allows the operation corresponding to the first operation instruction, and if the result of the determination is yes, perform S103. If the result of the determination is no, the electronic device 100 can stop performing any step, or the electronic device 100 can try to respond to the first operation instruction and perform other operations close to the operation corresponding to the first operation instruction in the limited execution environment.

[0320] The operation corresponding to the first operation instruction can refer to the detailed description of S101 and S1021.

[0321] Figures 5E-5F An exemplary user interface displayed when the electronic device 100 performs S103 is shown.

[0322] Reference is made to Figure 5E , Figure 5E The user interface 53 displayed when the electronic device 100 receives the voice instruction "navigate to home" in Figure 5B and receives the weak authentication factor (i.e. the voiceprint carried in the voice instruction) is shown. As shown in Figure 5E , the limited execution environment created by the electronic device 100 according to the voice instruction and the weak authentication factor allows starting the navigation application and allows reading the user data of the navigation application, for example, reading the detailed address of the user's "home" as "XX Mansion". Therefore, Figure 5E , in the navigation interface provided in , the electronic device 100 automatically fills in the detailed address of "home" at the destination.

[0323] Reference is made to Figure 5F , Figure 5F The user interface displayed when the electronic device 100 receives the image including the gesture of opening the palm in Figure 5C and receives the weak authentication factor (i.e. the features of the palm, such as the fingerprint, the size of the knuckles, etc.) is also shown. The gesture of opening the palm and the voice instruction "navigate to home" are both used to request the electronic device 100 to navigate to the location of "home". However, since Figure 5C , the security level of the weak authentication factor received by the electronic device 100 is lower than that of Figure 5B , the electronic device 100 creates a limited execution environment according to the gesture of opening the palm and the weak authentication factor, which allows starting the navigation application but does not allow reading the user data of the navigation application. As shown in Figure 5F , since the electronic device 100 cannot read the detailed address of "home", the address is not filled in at the destination. The user can manually input the address of "home" at the destination to navigate to home.

[0324] In optional step S104, the electronic device 100 receives the user's operation.

[0325] This application embodiment does not limit the form of the user operation received by the electronic device 100 in S104. For example, it can be voice carrying semantics, images containing gestures / facial expressions / body postures, swipe operations containing signatures, button press operations, shaking operations of the electronic device 100, etc. The way in which the electronic device 100 receives the user operation in S104 is the same as the first way in which the electronic device 100 receives the user operation carrying the first operation instruction in S101, and can be referred to the relevant description.

[0326] In optional step S105, if the created restricted execution environment allows the operation requested by the user to be performed by the electronic device 100, the electronic device 100 responds to the user operation; if the operation requested by the user to be performed by the electronic device 100 is not allowed, a prompt message is output to inform the user that the operation corresponding to the user operation is currently not allowed.

[0327] Here, the electronic device 100 determines the operation that the user operation requests the electronic device 100 to perform, which is the same as the operation corresponding to the first operation instruction determined by the electronic device 100 in S1021, as can be referred to in the relevant description.

[0328] In this embodiment of the application, the resource requested for access by the user operation in S104 can be referred to as the second resource. The second resource may include one or more resources, and is not limited here.

[0329] Specifically, if the execution environment restricts the execution of the operation corresponding to the user operation in S104, the electronic device 100 will respond to the user operation and execute the operation requested by the user.

[0330] For example, if the user operation in S104 is to request the electronic device 100 to launch the camera application, and the restricted execution environment allows the electronic device 100 to launch the camera application, then the electronic device 100 can launch the camera application.

[0331] For example, such as Figure 5F As shown, after the electronic device 100 detects a user operation (e.g., a click operation) on the control 501 in the user interface 53, if the restricted execution environment allows the microphone to be invoked, the electronic device 100 can activate the microphone to capture the user's voice input.

[0332] If the execution environment restricts the execution of the operation corresponding to the user's operation, the electronic device 100 will not respond to the user's operation and will output a prompt message.

[0333] For example, if the user operation of S104 (e.g., a swipe operation from the bottom of the display screen upward) is used to request the electronic device 100 to display the desktop, and the limited execution environment does not allow the electronic device 100 to display the desktop, the electronic device 100 can output a prompt information.

[0334] In some embodiments, the prompt information output by the electronic device 100 can further prompt the user for the reason why the operation corresponding to the user operation is not allowed to be performed at present, for example, can include that the risk level of the user operation is high, or the security level of the weak authentication factor currently received by the electronic device 100 is low.

[0335] In some embodiments, the prompt information output by the electronic device 100 can further prompt the user for a solution. For example, prompting the user to input a weak authentication factor with a higher security level, or prompting the user to unlock, etc., which are not limited here.

[0336] The implementation form of the prompt information can be a visual element, a vibration signal, a flashlight signal, an audio, etc., which are not limited here.

[0337] Exemplarily, with reference to Figure 5G , Figure 5G Exemplarily, the prompt information 502 output by the electronic device 100 is shown.

[0338] Through S105, the operation that the electronic device 100 can perform can be limited within the range of the limited execution environment, so that the expansion of the authority can be avoided, and the data security of the electronic device 100 can be protected.

[0339] Optionally, S106, the electronic device 100 acquires the strong authentication factor, and switches from the locked state to the unlocked state.

[0340] Specifically, the strong authentication factor includes identity authentication information meeting the required standard of the first authentication mode. The identity authentication information meeting the required standard of the first authentication mode can refer to the detailed description in S101, which is not repeated here.

[0341] In some embodiments, the strong authentication factor can also include a plurality of weak authentication factors acquired within a period of time. Here, the specific number of the plurality of weak authentication factors can be pre-set, which is not limited here. The plurality of weak authentication factors can be the same identity authentication information, or can be different identity authentication information. That is, the user can complete the identity authentication by inputting the weak authentication factor multiple times. For example, the user can continuously input multiple sentences of voice, so that the electronic device 100 can extract a plurality of voice prints (i.e., weak authentication factors) to complete the unlocking. For another example, the electronic device 100 can extract a voice print and a face at a long distance at the same time, and then unlock.

[0342] The electronic device 100 can acquire the strong authentication factor in the same manner as that in S101 for acquiring the weak authentication factor, which will not be repeated here.

[0343] In some embodiments, the electronic device 100 can automatically start detecting the strong authentication factor input by the user after outputting the prompt information in S105. The user can input the strong authentication factor after seeing the prompt information output by the electronic device 100.

[0344] In some other embodiments, the electronic device 100 can start detecting the strong authentication factor input by the user in response to a received user operation at any time point after performing S103. The user can input the strong authentication factor after inputting the user operation. The embodiments of the present application do not limit the form of the user operation.

[0345] For example, referring to Figure 5E and Figure 5F , the electronic device 100 can continuously display the unlock control 503 in the displayed access control interface after creating the restricted execution environment. As shown in Figure 5E and Figure 5F , the electronic device 100 can start detecting the strong authentication factor input by the user in response to an operation on the unlock control 503. In addition, the unlock control 503 can also be used to prompt the user that the electronic device 100 is currently in the restricted execution environment and is still in the locked state, thereby avoiding user operations outside the scope of the restricted execution environment.

[0346] The embodiments of the present application do not limit the implementation of the unlock control 503, which can be an icon, text or other forms, and can be transparent or opaque. The unlock control 503 can be displayed at any position in the display screen, can be displayed in a fixed area, or can be dragged by the user, which will not be repeated here.

[0347] In the embodiments of the present application, the unlock control 503 can be referred to as a first control.

[0348] Optionally, in S107, the electronic device 100 closes the restricted execution environment.

[0349] In some embodiments, the electronic device 100 can close the restricted execution environment after switching to the unlocked state after S106.

[0350] In some other embodiments, the electronic device 100 can close the restricted execution environment after receiving an operation for closing the application started by the first operation instruction. The user triggers the electronic device 100 to close the application started by the first operation instruction, which indicates that the current user no longer needs the restricted execution environment, and therefore the electronic device 100 closes the restricted execution environment, which can save device resources.

[0351] In a specific implementation, the electronic device 100 closing the restricted execution environment refers to the electronic device 100 deleting the information recorded in S102, for example, the recorded operations allowed by the restricted execution environment to be executed by the electronic device 100, and the like.

[0352] Through the above Figure 4 The access control method based on the weak authentication factor shown in the embodiment of the present application can no longer determine whether to respond to the execution of the corresponding operation according to whether the electronic device is unlocked, but can determine whether to execute the operation according to the risk level of the operation instruction and the security level of the weak authentication factor, so that more fine-grained access control can be implemented, and the use scenarios and use range of the electronic device are enriched. For the user, the electronic device can be triggered to execute other operations in addition to the predefined operation in the locked state without unlocking the electronic device through cumbersome authentication, so that the user can more freely and conveniently manipulate the electronic device. In addition, the electronic device no longer simply divides resources into resources accessible by the predefined operation and resources accessible by other operations, but also implements more fine-grained access control for various resources.

[0353] Reference Figure 6 , Figure 6 The flowchart of the cross-device access control method provided by the embodiment of the present application is shown.

[0354] As Figure 6 shown, the method can include the following steps:

[0355] In S201, the electronic device 300 receives a user operation for requesting the electronic device 100 to execute an operation.

[0356] The form of the user operation in S201 is not limited in the embodiment of the present application, for example, it can be a click operation or a sliding operation acting on the display screen, a voice, a gesture / face expression / physical posture, a sliding operation containing a signature, a key pressing operation, a shaking electronic device 100 operation, and the like.

[0357] The operation requested by the user operation to be executed by the electronic device 100 includes an access operation on a resource, the resource being one or more resources in the electronic device 100, and the access operation including one or more of reading, adding, deleting, writing, modifying, and executing, for example. The specific content of the resource and the access operation is determined with reference to the related description hereinbefore. The resources in the electronic device can include software resources, hardware resources, peripheral resources, and the like, and specific reference is made to the related description hereinbefore.

[0358] In the embodiment of the present application, the resource in the electronic device 100 requested to be accessed by the user request in S201 can be referred to as a third resource. The third resource can include one or more resources, which are not limited here.

[0359] In one specific embodiment, the user operation is for requesting to share some data in the electronic device 300 to the electronic device 100.

[0360] Exemplarily, Figures 7A-7B A screen mirroring scenario is shown.

[0361] Referring to Figure 7A , Figure 7A An exemplary user interface 71 is shown when the electronic device 100 plays a network video selected by the user. The user interface 71 can be displayed by the electronic device 300 in response to the user switching the electronic device 300 from a portrait state to a landscape state, or the user clicking a full screen playing control displayed in the lower right corner of the electronic device 300 when the electronic device 300 plays a video.

[0362] As Figure 7A shown, the user interface 71 can further include a screen mirroring switch control 701, which is used to listen to a user operation (such as a click operation, a touch operation, etc.) for starting / stopping the screen mirroring function of the video application.

[0363] Referring to Figure 7A , the electronic device 300 can detect a user operation (such as a click operation, a touch operation, etc.) acting on the screen mirroring control 701, discover a nearby electronic device supporting screen mirroring, and display the identity of the discovered electronic device.

[0364] Figure 7B An exemplary identity of a nearby electronic device supporting screen mirroring displayed by the electronic device 300 is shown. Exemplarily, as Figure 7B shown, the electronic device 300 can detect a user operation acting on the identity corresponding to the electronic device 100.

[0365] In Figure 7A and Figure 7B exemplary cases, the user operation received by the electronic device 300 includes a user operation of first clicking the control 701 and then clicking the identity of the electronic device 100, which is for requesting to cast the video currently played by the electronic device 300 to the electronic device 100 for continuous playing. The user operation requests to access the display screen, the speaker, and the screen mirroring application of the electronic device 100, etc.

[0366] In Figure 7A and Figure 7B exemplary cases, the electronic device 100 is selected by the user, and in some other embodiments, the electronic device 100 can also be selected by the electronic device 300 by default. For example, after the electronic device 300 receives the user operation of clicking the control 701, it can by default request to cast the video currently played to the electronic device 100 for continuous playing, which is the last device for screen mirroring.

[0367] S202, the electronic device 300 generates a second operation instruction according to the user operation, the second operation instruction being used to request the electronic device 100 to perform an operation.

[0368] The second operation instruction is the same as the user operation in S201, and is used to request to access a third resource in the electronic device 100.

[0369] The form of the second operation instruction is not limited in the embodiments of the present application. For example, the second operation instruction can be a message sent through wired connection, wireless connection such as Bluetooth (BT) connection, Wi-Fi P2P connection, NFC connection, remote connection, etc.

[0370] In the screen projection scenario shown in FIG. 1 and FIG. 2, the second operation instruction generated by the electronic device 300 can be a screen projection request, the screen projection request being used to request to project the video currently played by the electronic device 300 to the electronic device 100 for continuous playing. Figure 7A Figure 7B

[0371] S203, the electronic device 300 sends the second operation instruction to the electronic device 100.

[0372] S204, the electronic device 100 is in a locked state, receives the second operation instruction, and creates a limited execution environment according to the second operation instruction.

[0373] The definition of the locked state can refer to the related description in the Figure 4 .

[0374] The definition and acquisition method of the second operation instruction are similar to those of the first operation instruction, and can refer to the related description in the Figure 4 .

[0375] The embodiments of the present application do not limit the strategy of the electronic device 100 to create a limited execution environment according to the second operation instruction. For example, the electronic device 100 can create a limited execution environment according to the category of the second operation instruction. For example, when the second operation instruction is a voice-carrying semantic, a gesture, a facial expression, a signature, and a body posture respectively, the number of operations that can be performed in the limited execution environment created by the electronic device 100 decreases in turn.

[0376] In some embodiments, the electronic device 100 can create a limited execution environment according to the risk level of the operation corresponding to the second operation instruction. Step S204 can specifically include steps S2041-S2043.

[0377] S2041, determining the risk level of the operation corresponding to the second operation instruction.

[0378] ​​Here, the electronic device 100 determines the risk level of the operation corresponding to the second operation instruction, and Figure 4 The electronic device 100 determines the risk level of the operation corresponding to the first operation instruction in S102 of the method 1000, which can refer to the related description.

[0379] In S2042, the electronic device 100 determines whether to allow the operation corresponding to the second operation instruction according to the risk level of the operation corresponding to the second operation instruction.

[0380] Specifically, the electronic device 100 is pre-configured with operations allowed to be executed by the electronic device 100 under different risk levels of the operations. The configuration can be pre-configured by a user or a manufacturer of the electronic device 100. The present application does not limit the correspondence between the risk level of the operation and the operation allowed to be executed by the electronic device 100.

[0381] If the execution result of S2042 is yes, the electronic device 100 continues to execute the subsequent steps.

[0382] If the execution result of S2042 is no, the electronic device 100 does not continue to execute the subsequent steps.

[0383] In some embodiments, if the execution result of S2042 is no, the electronic device 100 can further output prompt information, which can be used to prompt the user that the operation corresponding to the second operation instruction is not allowed to be executed at present.

[0384] In some embodiments, the prompt information can further prompt the user the reason why the operation corresponding to the second operation instruction is not allowed to be executed at present, for example, can include that the risk level of the operation corresponding to the second operation instruction is high.

[0385] In some embodiments, the prompt information can further prompt the user a solution. For example, prompt the user to unlock, etc., which is not limited here.

[0386] The implementation form of the prompt information is the same as that in the subsequent step S207, which can refer to the related description in the subsequent steps.

[0387] In S2043, the electronic device 100 creates a restricted execution environment according to the risk level of the operation corresponding to the second operation instruction.

[0388] The way in which the electronic device 100 creates the restricted execution environment according to the risk level of the operation corresponding to the second operation instruction is the same as that in S1024 of the method 1000, which can refer to the related description. Figure 4

[0389] ​Exemplarily, refer to Figure 7C , Figure 7C The electronic device 100 creates a restricted execution environment, and the displayed user interface 72 is shown. As shown in the figure, the electronic device 100 is playing a video sent by the electronic device 300, and displays an unlock control 702. The unlock control 702 and the unlock control 503 in Figure 7C and Figure 5E have the same function, and refer to the related description. In the embodiments of the present application, the unlock control 702 can also be referred to as a first control. Figure 5F

[0390] S205, the electronic device 100 executes the operation corresponding to the second operation instruction in the created restricted execution environment in response to the second operation instruction.

[0391] S205 and Figure 4 S103 are similar, and refer to the related description.

[0392] Optional steps S206-S209, refer to optional steps S104-S107 in Figure 4 .

[0393] In S206, the resource requested to be accessed by the user operation received by the electronic device 100 is referred to as a fourth resource. The fourth resource can include one or more resources, which are not limited here.

[0394] In some embodiments of S209, the electronic device 100 can close the restricted execution environment after receiving an operation for closing the application started by the second operation instruction.

[0395] For example, if the electronic device 300 receives a user operation to stop the screen projection, it can send an indication information to stop the screen projection to the electronic device 100, and then the electronic device 100 closes the restricted execution environment.

[0396] Through the cross-device access control method shown in the above Figure 6 , the electronic device no longer decides whether to respond to the user operation according to whether it is unlocked, but decides whether to respond to the user operation according to the risk level of the operation instruction received across devices, which can realize more fine-grained access control and enrich the use scenarios and use range of the electronic device. For the user, it is not necessary to unlock the electronic device through cumbersome authentication to trigger the electronic device to perform other operations in addition to the predefined operation in the locked state, so that the user can more freely and conveniently manipulate the electronic device. In addition, the electronic device no longer simply divides the resources into resources accessible by the predefined operation and resources accessible by other operations, but also realizes more fine-grained access control for various resources.

[0397] ​Particularly, for a data sharing scenario such as screen projection and multi-screen interaction, when one device shares data to another device, the other device does not need to be unlocked. Compared with a solution in which the other device needs to be unlocked each time data is shared, the embodiments of the present application reduce the difficulty and complexity of screen projection and multi-screen interaction, and can bring better user experience to users.

[0398] In the above Figure 4 And Figure 6 In the access control method provided, the electronic device 100, the electronic device 200, and the electronic device 300 can be referred to as a first device, a second device, and a third device.

[0399] The weak authentication factor can also be referred to as a first authentication factor, and the strong authentication factor can also be referred to as a second authentication factor.

[0400] Referring to Figure 8A , Figure 8A Another software architecture diagram of the electronic device 100 provided by the embodiments of the present application is provided.

[0401] As shown in Figure 8A , the electronic device 100 can include the following modules: an operation instruction identification module 801, a weak authentication factor identification module 802, and an access control and execution environment management module 803. Among them:

[0402] The operation instruction identification module 801 is configured to obtain a first operation instruction of the electronic device 100.

[0403] In some embodiments, the operation instruction identification module 801 can be configured to obtain the first operation instruction or the second operation instruction by the above-mentioned first method. That is, the operation instruction identification module 801 can be configured to receive a user operation carrying the first / second operation instruction, and extract the first / second operation instruction from the user operation. In this case, the operation instruction identification module 801 can include various modules involved when the electronic device 100 obtains the first / second operation instruction by the above-mentioned first method, such as a voice assistant, a microphone, and the like.

[0404] In some embodiments, the operation instruction identification module 801 can be configured to obtain the first / second operation instruction by the above-mentioned second method. That is, the operation instruction identification module 801 can be configured to receive indication information of a user operation sent by another device to the electronic device 100, and extract the first / second operation instruction from the indication information of the user operation. In this case, the operation instruction identification module 801 can include various modules involved when the electronic device 100 obtains the first / second operation instruction by the above-mentioned second method, such as a wireless communication module, a wired communication module, a voice assistant, and the like.

[0405] The operation instruction recognition module 801 is further configured to determine the operation corresponding to the first / second operation instruction.

[0406] The weak authentication factor recognition module 802 is configured to obtain the weak authentication factor of the electronic device 100.

[0407] In some embodiments, the weak authentication factor recognition module 802 can be configured to obtain the weak authentication factor by the above-mentioned first way. That is, the weak authentication factor recognition module 802 can be configured to receive the user operation carrying the weak authentication factor, and extract the weak authentication factor from the user operation. In this case, the weak authentication factor recognition module 802 can include various modules involved when the electronic device 100 obtains the weak authentication factor by the above-mentioned first way, such as a voice assistant, a microphone, a camera, a fingerprint sensor, and the like.

[0408] In some embodiments, the weak authentication factor recognition module 802 can be configured to obtain the weak authentication factor by the above-mentioned second way. That is, the weak authentication factor recognition module 802 can be configured to receive the indication information of the user operation sent by the other device to the electronic device 100, and extract the weak authentication factor from the indication information of the user operation. In this case, the weak authentication factor recognition module 802 can include various modules involved when the electronic device 100 obtains the weak authentication factor by the above-mentioned second way, such as a wireless communication module, a mobile communication module, a voice assistant, and the like.

[0409] The weak authentication factor recognition module 802 is further configured to determine the security level of the weak authentication factor. After obtaining the weak authentication factor of the electronic device 100, the weak authentication factor recognition module 802 can further generate an authentication token, which indicates the security level of the weak authentication factor, and can also indicate the authentication mode, the valid time of the weak authentication factor, and the like.

[0410] Subsequently, the operation instruction recognition module 801 sends the operation corresponding to the first operation instruction, and the weak authentication factor recognition module 802 sends the authentication token to the access control and execution environment management module 803, respectively. The authentication token can be used by the access control and execution environment management module 803 to verify the legitimacy.

[0411] In some embodiments, the access control and execution environment management module 803 is used to determine whether to allow the execution of the operation corresponding to the first operation instruction based on the security level of the operation corresponding to the first operation instruction and the security level of the weak authentication factor. In some embodiments, the access control and execution environment management module 803 is used to determine whether to allow the execution of the operation corresponding to the second operation instruction based on the security level of the operation corresponding to the second operation instruction. If the determination result is yes, the access control and execution environment management module 803 is used to create a restricted execution environment and execute the operation corresponding to the first / second operation instruction in the restricted execution environment. Here, the specific operation of creating a restricted execution environment can be referred to the relevant description in the preceding method embodiments.

[0412] In some embodiments, the electronic device 100 may further include a distributed scheduling module 804, which is used to obtain the first / second operation instruction through the third method described above, or to obtain the weak authentication factor through the third method described above. In this case, the distributed scheduling module 804 may include a wireless communication module, a mobile communication module, etc.

[0413] refer to Figure 8B , Figure 8B The structure of the electronic device access control and execution environment management module 803 is illustrated by way of example.

[0414] like Figure 8B As shown, the access control and execution environment management module 803 may include: access control module 8031, execution environment management module 8032, policy management module 8033, application lifecycle management module 8034, and resource management module 8035.

[0415] The access control module 8031 ​​is used to transmit the operation corresponding to the first / second operation instruction, that is, the information of the accessed resource, to the execution environment management module 8032.

[0416] The execution environment management module 8032 can be used to determine whether the operation corresponding to the first / second operation instruction is allowed. If so, the identifier of the restricted execution environment is set, and the running policy of the restricted execution environment is configured in the policy management module 8033.

[0417] The policy management module 8033 is used to configure the operating policy of the restricted execution environment, that is, to record the various operations that are allowed to be performed in the restricted execution environment, that is, to record which specific access operations are allowed to be performed on which resources or which type of resources.

[0418] The resource management module 8035 may include: an application information management module, a data management module, and a permission management module.

[0419] The application information management module stores and manages information of all applications, and records information of applications allowed to be started or accessed in the current restricted execution environment.

[0420] The data management module can be used to classify and manage data in the electronic device, and set data levels or categories allowed to be accessed in the restricted execution environment. For example, the electronic device can classify data according to characteristics of the data, for example, data of different security levels.

[0421] The permission management module is used to manage permissions of operations in the electronic device, and set permissions allowed in the restricted execution environment.

[0422] The application lifecycle management module 8034 is used to manage lifecycles of applications in the electronic device 100, for example, starting or destroying, etc. When the application lifecycle management module 8034 is about to start an application or access data in response to a user operation, it first confirms whether the current restricted execution environment allows to start the application from the application information management module, or whether the current restricted execution environment allows to access the data from the data management module, and if yes, the application can be started or the data can be accessed. After the application lifecycle management module 8034 starts the application, if it is about to perform an operation, it needs to confirm whether the current restricted execution environment has the corresponding permission from the permission management module, and if yes, the operation is performed.

[0423] The modules shown in the above Figure 8A and Figure 8B may be located in any one or more layers of the software system shown in Figure 2 , which is not limited here.

[0424] Figure 8A and Figure 8B The modules shown in the above

[0425] The embodiments of the present application can be combined in any way to achieve different technical effects.

[0426] In the above embodiments, all or part of the processes can be implemented by software, hardware, firmware, or any combination thereof. When implemented by software, all or part of the processes can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes described in the present application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions can be transferred from one website, computer, server or data center to another website, computer, server or data center through wired (such as coaxial cable, optical fiber, digital subscriber line) or wireless (such as infrared, wireless, microwave, etc.) manner. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. that includes one or more available media sets. The available media can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid state disk (SSD)), etc.

[0427] Those of ordinary skill in the art can understand that all or part of the processes in the above embodiments can be implemented by a computer program to instruct the relevant hardware, and the program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the above embodiments. The storage medium includes ROM or random access memory (RAM), magnetic disk or optical disk, and various media that can store program codes.

[0428] In summary, the above only describes the embodiments of the technical scheme of the present application, and is not used to limit the protection scope of the present application. Any modification, equivalent replacement, improvement, etc. made according to the disclosure of the present application shall be included in the protection scope of the present application.

Claims

1. An access control method based on weak authentication factors, characterized in that, The method includes: When the first device is in a locked state, it acquires a first operation instruction and a first authentication factor; the first operation instruction is used to request access to a first resource of the first device, and the first authentication factor includes: identity authentication information that is lower than the standard required by the first authentication method, or identity authentication information that meets the standard required by the second authentication method, wherein the first authentication method is an identity authentication method used to unlock the first device, the second authentication method is an identity authentication method other than the identity authentication method used to unlock the first device, and the identity authentication information that meets the standard required by the first authentication method is used to switch the first device from the locked state to the unlocked state; The first device determines the resources that the first device is allowed to access based on the first operation instruction and the first authentication factor; If the resources that the first device is allowed to access include the first resource, then the first device responds to the first operation instruction and accesses the first resource.

2. The method according to claim 1, characterized in that, The first device determines the resources that it is allowed to access based on the first operation instruction, specifically including: The first device determines the resources that it is allowed to access based on the risk level of accessing the first resource; the higher the risk level of accessing the first resource, the fewer resources the first device is allowed to access. The higher the privacy level of the first resource, the higher the risk level of accessing the first resource.

3. The method according to claim 1, characterized in that, The first device determines the resources that it is allowed to access based on the first authentication factor, specifically including: The first device determines the resources that the first device is allowed to access based on the security level of the first authentication factor; the lower the security level of the first authentication factor, the fewer resources the first device is allowed to access. Wherein, the higher the authentication capability level (ACL) of the identity authentication method corresponding to the first authentication factor, or the higher the matching degree between the first authentication factor and the identity authentication information that meets the unlocking requirements of the first device, or the higher the security level of the first authentication factor, the better the first authentication factor is obtained.

4. The method according to claim 1, characterized in that, The first resource includes: a predefined resource that the first device cannot access in the locked state.

5. The method according to any one of claims 1-4, characterized in that, The first operation instruction includes any one of the following: semantics carried by speech, gestures, facial expressions, and body posture.

6. The method according to claim 5, characterized in that, The first device acquires a first operation instruction, which specifically includes any one of the following: The first device acquires voice or image and identifies the first operation command carried in the voice or image; The first device receives voice or image sent by the second device and identifies a first operation command carried in the voice or image; or, The first device receives the first operation command sent by the second device.

7. The method according to any one of claims 1-4, characterized in that, The identity authentication information includes any one or more of the following: password, graphic, or biometric features.

8. The method according to any one of claims 1-4, characterized in that, The authentication information that does not meet the unlocking requirements of the first device includes: authentication information that is below the standard required by the first authentication method, or authentication information that meets the standard required by the second authentication method; The first authentication method is an identity authentication method used to switch the first device from the locked state to the unlocked state, and the second authentication method is an identity authentication method other than the first authentication method.

9. The method according to claim 8, characterized in that, The first authentication method is an authentication method with an authentication capability level (ACL) higher than the third value, or the first authentication method is preset by the first device.

10. The method according to claim 8, characterized in that, The identity authentication information that is below the standard required by the first authentication method includes: biometric features whose matching degree with the pre-stored first biometric feature is lower than a first value, where the first biometric feature is the identity authentication information corresponding to the first authentication method; And / or, The identity authentication information that meets the standards required for the second authentication method includes: a biometric feature whose matching degree with a pre-stored second biometric feature reaches a second value, wherein the second biometric feature is the identity authentication information corresponding to the second authentication method.

11. The method according to any one of claims 1-4, characterized in that, The first device acquires the first authentication factor, specifically including any one of the following: The first device acquires voice or image data and identifies the first authentication factor carried in the voice or image data. The first device receives voice or image sent by the second device and identifies the first authentication factor carried in the voice or image; or, The first device receives the first authentication factor sent by the second device.

12. The method according to any one of claims 1-4, characterized in that, The first device acquires a first operation command and a first authentication factor, specifically including any one of the following: The first device collects speech, recognizes the semantics of the speech, and determines the semantics as the first operation command; it also recognizes the voiceprint carried by the speech and determines the voiceprint as the first authentication factor. or, The first device collects images, identifies gestures, facial expressions, and body postures in the images, and determines the gestures, facial expressions, and body postures in the images as the first operation command; it also identifies biometric features carried in the images and determines the biometric features as the first authentication factor.

13. The method according to any one of claims 1-4, characterized in that, After the first device accesses the first resource in response to the first operation command, the method further includes: The first device receives a user operation, the user operation being used to request access to a second resource of the first device; If the resources that the first device is allowed to access include the second resource, then the first device accesses the second resource in response to the user operation. If the resources that the first device is allowed to access do not include the second resource, then the first device refuses to respond to the user's action.

14. The method according to any one of claims 1-4, characterized in that, After the first device accesses the first resource in response to the first operation command, the method further includes: The first device obtains a second authentication factor, which includes identity authentication information that meets the unlocking requirements of the first device, or a predetermined number of the first authentication factors; The first device switches from the locked state to the unlocked state based on the second authentication factor.

15. The method according to claim 14, characterized in that, After the first device determines the resources it is allowed to access, and before the first device obtains the second authentication factor, the method further includes: The first device displays the first control; The first device detects an operation performed on the first control; The first device responds to the operation applied to the first control and begins to detect identity authentication information.

16. The method according to any one of claims 1-4, characterized in that, After the first device determines the resources that the first device is allowed to access, the method further includes: the first device creating a restricted execution environment, in which the first device is allowed to access the resources that were determined to be allowed to access; The first device responds to the first operation instruction by accessing the first resource, specifically including: the first device responds to the first operation instruction by accessing the first resource in the restricted execution environment.

17. A cross-device access control method, characterized in that, The method includes: When the first device is in a locked state, it receives a second operation instruction sent by the third device; the second operation instruction is used to request access to the third resource of the first device. The first device determines the resources that the first device is allowed to access based on the second operation instruction; If the resources that the first device is allowed to access include the third resource, then the first device, in response to the second operation instruction, accesses the third resource; The first device obtains a second authentication factor, which includes a predetermined number of first authentication factors. The first authentication factors include: identity authentication information that is lower than the standard required by the first authentication method, or identity authentication information that meets the standard required by the second authentication method. The first authentication method is an identity authentication method used to unlock the first device, and the second authentication method is an identity authentication method other than the identity authentication method used to unlock the first device. The identity authentication information that meets the standard required by the first authentication method is used to switch the first device from the locked state to the unlocked state. The first device switches from the locked state to the unlocked state based on the second authentication factor.

18. The method according to claim 17, characterized in that, The first device determines the resources that it is allowed to access based on the second operation instruction, specifically including: The first device determines the resources that the first device is allowed to access based on the risk level of accessing the third resource; the higher the risk level of accessing the third resource, the fewer resources the first device is allowed to access. The higher the privacy level of the third resource, the higher the risk level of accessing the third resource.

19. The method according to claim 17, characterized in that, The third resource includes: predefined resources that the first device cannot access in the locked state.

20. The method according to any one of claims 17-19, characterized in that, The second operation instruction includes any one of the following: semantics carried by speech, gestures, facial expressions, and body posture.

21. The method according to any one of claims 17-19, characterized in that, The second operation command is a screen mirroring request.

22. The method according to any one of claims 17-19, characterized in that, After the first device accesses the third resource in response to the second operation command, the method further includes: The first device receives a user operation, the user operation being used to request access to the fourth resource of the first device; If the resources that the first device is allowed to access include the fourth resource, then the first device accesses the fourth resource in response to the user operation. If the resources that the first device is allowed to access do not include the fourth resource, then the first device refuses to respond to the user's action.

23. The method according to any one of claims 17-19, characterized in that, After the first device determines the resources it is allowed to access, and before the first device obtains the second authentication factor, the method further includes: The first device displays the first control; The first device detects an operation performed on the first control; The first device responds to the operation applied to the first control and begins to detect identity authentication information.

24. The method according to any one of claims 17-19, characterized in that, After the first device determines the resources that the first device is allowed to access, the method further includes: the first device creating a restricted execution environment, in which the first device is allowed to access the resources that were determined to be allowed to access; The first device responds to the second operation instruction by accessing the third resource, specifically including: the first device responds to the second operation instruction by accessing the third resource in the restricted execution environment.

25. An electronic device, characterized in that, include: A memory, and one or more processors; the memory is coupled to the one or more processors, the memory being used to store computer program code, the computer program code including computer instructions, the one or more processors invoking the computer instructions to cause the electronic device to perform the method as described in any one of claims 1-16 or 17-24.

26. A computer-readable storage medium comprising instructions, characterized in that, When the instructions are executed on an electronic device, the electronic device causes the electronic device to perform the method as described in any one of claims 1-16 or 17-24.

27. A computer program product, characterized in that, When the computer program product is run on a computer, it causes the computer to perform the method as described in any one of claims 1-16 or 17-24.

28. A communication system, characterized in that, The communication system includes: a first device and a third device, wherein the third device is used to perform the method as described in any one of claims 17-24.

Citation Information

Patent Citations

  • Touch screen terminal and unlocking method thereof

    CN102087585A

  • Device, method, and graphical user interface for accessing an application in a locked device

    CN104169857A

  • Method and device for remotely controlling mobile terminal

    CN105100281A

  • Phone information safety managing method based on multi-password unlocking

    CN106231073A