Authentication method and device based on trusted device network, equipment, storage medium and program product
By establishing a trusted device network, generating a third identification code using device identification codes and connection information, and verifying it through public and private key pairing, the complex verification problem when users replace devices is solved, achieving secure and reliable intelligent verification and improving the user experience.
Patent Information
- Application Number
- CN202410854684.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-28
- Publication Date
- 2025-12-19
- Estimated Expiration
- 2044-06-28
AI Technical Summary
In existing technologies, users need to perform complex account passwords and SMS verification codes when changing mobile phones or using untrusted devices, resulting in a poor user experience.
By establishing a trusted device network, using the identification codes and connection information of the first and second devices, a third identification code is generated to establish the trusted device network. The user's business operation process is simplified by verifying the operation through public and private key pairing.
It enables intelligent verification directly on the second device, avoiding multiple logins on the first device, providing a secure, reliable, and fast verification solution, and improving the user experience.
Smart Images

Figure CN118449780B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of information security, which can be applied to the financial field, and more particularly to a verification method and device based on a trusted device network, equipment, storage medium and program product. BACKGROUND
[0002] The trusted device is commonly used to determine whether the device currently used by the user is a trusted and low-risk device, and if so, the user is allowed to perform simplified login of the App, such as directly using the FaceID of the device to complete the login of the App.
[0003] However, at present, if the user needs to run the APP to complete the related operation, when there is a change of mobile phone or there is a non-trusted device, the user is required to input the account password and add verification of reserved mobile phone SMS verification code and other complex and inefficient verification processes, which makes the user experience poor. SUMMARY
[0004] In view of the above problems, the present disclosure provides a verification method, device, equipment, storage medium and program product based on a trusted device network. Through the method, the user operation process is not only simplified efficiently, but also the intelligent verification is started, and the user experience is improved.
[0005] According to a first aspect of the present disclosure, a verification method based on a trusted device network is provided, which comprises: installing an application on a second device based on application information of a first device; based on the running of the application, establishing a trusted device network according to a first identification code of the first device, a second identification code of the second device and connection information of the first device and the second device; in response to any business operation, verifying the operation through communication of the trusted device network; and executing the operation through the second device according to the result of the verification.
[0006] According to an embodiment of the present disclosure, the second identification code of the second device is obtained by the following method, comprising: obtaining running information of the second device when running the application; and comprehensively processing the running information and combining features by using a preset algorithm to obtain the second identification code of the second device.
[0007] According to an embodiment of the present disclosure, based on the running of the application, the trusted device network is established according to the first identification code of the first device, the second identification code of the second device and the connection information of the first device and the second device, which comprises: based on the running of the application by the first device and the second device respectively, installing a digital certificate to the first device to match the first device and the second device; based on the matching result, establishing the trusted device network according to the first identification code of the first device, the second identification code of the second device and the connection information of the first device and the second device, and generating a third identification code of the current trusted device network, wherein the third identification code of the current trusted device network is only one.
[0008] According to an embodiment of the present disclosure, based on the running of the application, the trusted device network is established according to the first identification code of the first device, the second identification code of the second device, and the connection information of the first device and the second device, and further comprises: determining the first device as a trusted device according to the first identification code of the first device; and determining the second device as a trusted device according to the second identification code of the second device.
[0009] According to an embodiment of the present disclosure, the third identification code is updated once for each third device added to the trusted device network.
[0010] According to an embodiment of the present disclosure, in response to any business operation, the operation is verified through the communication of the trusted device network, comprising: obtaining the business operation instruction of the user; based on the business operation instruction, the public key of the first device is matched with the preset private key of the second device to generate a key pair, so as to verify the operation.
[0011] According to an embodiment of the present disclosure, according to the result of the verification, the operation is executed through the second device, comprising: when the key pair matches, the operation is executed by running the application in the second device.
[0012] The second aspect of the present disclosure provides a verification device based on a trusted device network, comprising: an application installation module, configured to install an application on a second device based on application information of a first device; a trusted device network establishment module, configured to establish a trusted device network based on the running of the application, according to the first identification code of the first device, the second identification code of the second device, and the connection information of the first device and the second device; an operation verification module, configured to verify the operation through the communication of the trusted device network in response to any business operation; and an operation execution module, configured to execute the operation through the second device according to the result of the verification.
[0013] The third aspect of the present disclosure provides an electronic device, comprising: one or more processors; a storage device configured to store one or more computer programs, and the one or more processors execute the one or more computer programs to implement the steps of the above method.
[0014] The fourth aspect of the present disclosure further provides a computer-readable storage medium having a computer program stored thereon, and the computer program is executed by a processor to implement the steps of the above method.
[0015] The fifth aspect of the present disclosure further provides a computer program product comprising a computer program, and the computer program is executed by a processor to implement the steps of the above method. BRIEF DESCRIPTION OF DRAWINGS
[0016] The above and other objects, features and advantages of the present disclosure will become more apparent from the following description of embodiments of the present disclosure taken in conjunction with the accompanying drawings, in which:
[0017] Figure 1 An application scenario diagram of the verification method based on the trusted device network according to an embodiment of the present disclosure is schematically shown;
[0018] Figure 2 A flowchart of the verification method based on the trusted device network according to an embodiment of the present disclosure is schematically shown;
[0019] Figure 3 A flowchart of obtaining the second identification code of the second device according to an embodiment of the present disclosure is schematically shown;
[0020] Figure 4 A flowchart of establishing the trusted device network according to an embodiment of the present disclosure is schematically shown;
[0021] Figure 5 A flowchart of verifying the business operation according to an embodiment of the present disclosure is schematically shown;
[0022] Figure 6 A structural block diagram of the verification device based on the trusted device network according to an embodiment of the present disclosure is schematically shown; and
[0023] Figure 7 A block diagram of an electronic device suitable for the verification method based on the trusted device network according to an embodiment of the present disclosure is schematically shown. DETAILED DESCRIPTION
[0024] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it is to be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the following detailed description, numerous specific details are set forth in order to provide a thorough understanding of the embodiments of the present disclosure. However, it will be apparent to one skilled in the art that one or more embodiments can be practiced without these specific details. In addition, in the following description, descriptions of well-known structures and techniques are omitted to avoid unnecessarily obscuring the concept of the present disclosure.
[0025] The terms used herein are merely used to describe specific embodiments and are not intended to limit the present disclosure. The terms "include", "comprise", and the like used herein indicate the presence of the features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0026] All terms used herein, including technical and scientific terms, have meanings that are commonly understood by one of ordinary skill in the art unless otherwise defined. It should be noted that the terms used herein should be interpreted as having meanings consistent with the context of the present description, and should not be interpreted in an idealized or overly formal manner.
[0027] In the case of using expressions similar to "at least one of A, B, and C, etc.", it is generally intended to include any of A, B, and C alone, a combination of at least two of A, B, and C, etc.
[0028] Some of the blocks and / or flowcharts in the drawings represent computer program instructions or programs. These program instructions can be implemented by a processor of a general purpose computer, a special purpose computer, or other programmable data processing apparatus. When the program instructions are executed by the processor, the instructions can create means for implementing the functions / operations specified in the block diagrams and / or flowcharts. The technology of the present disclosure can be implemented in the form of hardware and / or software (including firmware, microcode, etc.). In addition, the technology of the present disclosure can take the form of a computer readable storage medium storing instructions executable by a processor, which cause the processor to perform the methods of the present disclosure.
[0029] In the technical solutions of the present disclosure, the user information (including but not limited to user personal information, user image information, user device information such as location information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved are information and data authorized by the user or authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of related data comply with relevant laws, regulations and standards, necessary security measures are taken, public order and good customs are not violated, and appropriate operation portals are provided for users to choose authorization or refusal.
[0030] In the scenario of using personal information for automated decision-making, the methods, devices and systems provided by the embodiments of the present disclosure all provide corresponding operation portals for users to choose to agree or refuse the automated decision-making result; if the user chooses to refuse, the expert decision-making process is entered. The expression "automated decision-making" here refers to the activity of automatically analyzing and evaluating a person's behavior habits, interests and hobbies, or economic, health, credit status, etc. by a computer program, and making decisions. The expression "expert decision-making" here refers to the activity of making decisions by personnel who are engaged in a certain field of work, have specialized experience, knowledge and skills, and have reached a certain professional level.
[0031] Embodiments of the present disclosure provide a trusted device network-based verification method, which comprises: installing an application on a second device based on application information of a first device; establishing a trusted device network according to a first identification code of the first device, a second identification code of the second device and connection information between the first device and the second device based on running of the application; verifying an operation through communication of the trusted device network in response to any service operation; and executing the operation through the second device according to a result of the verification.
[0032] Through embodiments of the present disclosure, by forming a trusted device network of a user with a first device and a second device of the user, smart verification can be directly started on the second device, avoiding the user from logging in to an APP on the first device multiple times in multiple scenarios, thereby providing a safe, reliable and fast verification scheme for the user and improving a better experience for the user. Not only is the user operation process in multiple scenarios such as device replacement simplified efficiently, but also smart verification is started and a better experience for the user is improved.
[0033] Figure 1 An application scenario diagram of the trusted device network-based verification method according to an embodiment of the present disclosure is schematically shown. It should be noted that, Figure 1 The diagram shown is only an example of an application scenario to which embodiments of the present disclosure can be applied, to help those skilled in the art understand the technical content of the present disclosure, but does not mean that embodiments of the present disclosure cannot be used in other devices, systems, environments or scenarios.
[0034] As Figure 1 shown, the application scenario 100 according to this embodiment can include terminal devices 101, 102, 103, a network 104 and a server 105. The network 104 is a medium for providing a communication link between the terminal devices 101, 102, 103 and the server 105. The network 104 can include various connection types, such as wired, wireless communication links or optical fiber cables, etc.
[0035] A user can use the terminal devices 101, 102, 103 to interact with the server 105 through the network 104 to receive or send messages, etc. Various communication client applications can be installed on the terminal devices 101, 102, 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (only as examples).
[0036] The terminal devices 101, 102, 103 can be various electronic devices with display screens and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers and desktop computers, etc.
[0037] The server 105 can be a server that provides various services, such as a background management server that provides support for a website browsed by a user using the terminal device 101, 102, 103 (as an example). The background management server can perform analysis and the like on received user requests and the like, and feed back a processing result (such as a webpage, information, or data obtained or generated according to a user request) to the terminal device.
[0038] It should be noted that the verification method based on the trusted device network provided in the embodiments of the present disclosure can be generally executed by the server 105. Accordingly, the verification apparatus based on the trusted device network provided in the embodiments of the present disclosure can be generally arranged in the server 105. The verification method based on the trusted device network provided in the embodiments of the present disclosure can also be executed by a server or a server cluster different from the server 105 and capable of communicating with the terminal device 101, 102, 103 and / or the server 105. Accordingly, the verification apparatus based on the trusted device network provided in the embodiments of the present disclosure can also be arranged in a server or a server cluster different from the server 105 and capable of communicating with the terminal device 101, 102, 103 and / or the server 105.
[0039] It should be understood that the number of terminal devices, networks, and servers in the system 100 is merely illustrative. Any number of terminal devices, networks, and servers can be provided according to implementation needs. Figure 1
[0040] The following will describe the verification method based on the trusted device network provided in the embodiments of the present disclosure based on the scenario described below. Figure 1 Figures 2-5 The verification method based on the trusted device network provided in the embodiments of the present disclosure will be described in detail.
[0041] Figure 2 A flowchart of the verification method based on the trusted device network according to the embodiments of the present disclosure is schematically shown.
[0042] As shown in Figure 2 , the verification method based on the trusted device network can further include operations S210-S240.
[0043] In operation S210, based on the application information of the first device, an application is installed on the second device.
[0044] In operation S220, based on the running of the application, a trusted device network is established according to the first identification code of the first device, the second identification code of the second device, and the connection information of the first device and the second device.
[0045] In the embodiments of the present disclosure, the first device can be a smart phone or the like, and an APP application has been installed on the smart phone. For example, the second device can be a smart wearable device such as a smart sports bracelet, and the APP can be a mobile banking APP. The APP is pushed from the smart phone to the smart wearable device, and the user installs and runs the APP on the smart wearable device.
[0046] For example, when the user opens the APP on the smart wearable device for the first time, the smart wearable device can collect various running information related to the APP. According to the related running information, the second device can generate a unique identification code, which is described in detail as follows.
[0047] Figure 3 A flowchart for obtaining the second identification code of the second device according to the embodiments of the present disclosure is shown schematically.
[0048] As shown in Figure 3 The second identification code of the second device is obtained by the following method, further comprising operation S310 to operation S320.
[0049] In operation S310, running information of the second device when running the application is obtained.
[0050] Specifically, according to the first opening of the APP by the second device, various running information of the second device when running the application can be obtained. For example, the running information can include device information (memory information, base station information, system information, sensor information, etc.) of the smart wearable device; network information (data flow, wireless connection signal, etc.); wearable sports information (step count, standing time, calorie consumption, etc.).
[0051] In operation S320, the running information is comprehensively processed, and a preset algorithm is used for feature combination to obtain the second identification code of the second device.
[0052] Specifically, according to the obtained running information, the information is comprehensively processed, and a similarity algorithm is used for feature combination of the collected various running information, and finally a second identification code of the second device is generated. The second identification code of the second device is a unique identification code. When the second device starts the APP subsequently, the collection and calculation of the above running information will continue.
[0053] In the embodiments of the present disclosure, the first device and the second device both need to be trusted devices before the trusted device network is established.
[0054] Specifically, the first device is determined to be a trusted device according to the first identification code of the first device.
[0055] For example, the device fingerprint of the first device (i.e., the smart phone) can be used as the first identification code. If the device fingerprint does not match the preset fingerprint, the first device is not trusted and cannot be determined as a trusted device.
[0056] In an embodiment of the present disclosure, the second device is determined as a trusted device according to the second identification code of the second device. When the second device runs the APP, if abnormal behavior occurs, for example, the motion information of the smart wearable device is collected, and the step count is 0 for consecutive N days, and the power is 100% for consecutive N days, etc., the second device is no longer trusted and cannot support security authentication.
[0057] When it is determined that the first device and the second device are both trusted devices, a trusted device network is established based on the identification code of the first device and the identification code of the second device. The details are as follows.
[0058] Figure 4 A flowchart for establishing a trusted device network according to an embodiment of the present disclosure is schematically shown.
[0059] As shown in Figure 4 , based on the running of the application, the trusted device network is established according to the first identification code of the first device, the second identification code of the second device, and the connection information of the first device and the second device, and further includes operation S410~operation S420.
[0060] In operation S410, based on the running of the application by the first device and the second device respectively, a digital certificate is installed to the first device to match the first device and the second device.
[0061] Specifically, when the user starts the second device (i.e., the smart wearable device) to run the APP, the first device (i.e., the smart phone) is matched. For example, in the state that the smart phone starts Bluetooth, the digital certificate is installed to the first device to match the first device and the second device.
[0062] In operation S420, based on the matching result, the trusted device network is established and the third identification code of the current trusted device network is generated according to the first identification code of the first device, the second identification code of the second device, and the connection information of the first device and the second device, wherein the third identification code of the current trusted device network is only one.
[0063] In an embodiment of the present disclosure, when the first device and the second device are matched, the trusted device network is established and the third identification code of the current trusted device network is generated according to the first identification code of the first device, the second identification code of the second device, and the connection information of the first device and the second device.
[0064] For example, in the state that the Bluetooth of the mobile phone is opened, the device fingerprint unique identifier of the smart phone App, the device unique identifier of the smart wearable device App and the current device connection state information are processed to generate the identification code of the unique trusted device network.
[0065] In the embodiments of the present disclosure, the third identification code is updated once for each third device added to the trusted device network. For example, when a smart wearable device is added to the trusted device network, the identification code of the new unique trusted device network is updated.
[0066] It should be noted that, in the process of matching the first device and the second device to establish the trusted device network, it is necessary to continuously monitor whether the first device and the second device are trusted devices.
[0067] By establishing the trusted device network, the security of verification is increased according to the continuous monitoring of whether the first device and the second device are trusted devices. When there is an abnormal login APP or an abnormal transfer through the APP, information can be sent to the devices in the trusted device network for confirmation, thereby ensuring the safety of the user.
[0068] In operation S230, in response to any business operation, the operation is verified through the communication of the trusted device network.
[0069] In operation S240, according to the result of verification, the operation is executed through the second device.
[0070] Figure 5 The flowchart of verifying the business operation according to the embodiments of the present disclosure is schematically shown.
[0071] As shown in Figure 5 In response to any business operation, the process of verifying the operation through the communication of the trusted device network further includes operation S510~operation S520.
[0072] In operation S510, the business operation instruction of the user is obtained.
[0073] In operation S520, based on the business operation instruction, the first device and the second device are paired and a key pair is generated through the public key of the first device and the preset private key of the second device to verify the operation.
[0074] In the embodiments of the present disclosure, after the establishment of the trusted device network is completed, there may be multiple business scene operations required by the user at this time. At this time, the operation of the user in multiple scenarios is verified based on the communication of the established trusted device network, which is described as follows.
[0075] Specifically, in the trusted device network, the first device (i.e., the smart phone) has a public key, and the second device (i.e., the smart wearable device) has a private key with specific attributes. For example, when the second device is connected to the first device, the trusted smart phone is the master device, the smart wearable device is connected through Bluetooth, and the master device and the smart wearable device are verified and matched through the generated secret key pair.
[0076] According to the verification result, when the key pair is matched, the operation is performed by running the application in the second device.
[0077] For example, after the trusted device network is completed, when the user has a business operation such as logging into a mobile bank, the smart wearable device receives a login of the mobile bank; when the user rebinds the terminal on the mobile phone, the smart wearable device will receive a prompt, and the user can confirm on the smart wearable device, simplifying the user login operation steps of the mobile bank (such as eliminating SMS, face recognition, or login password, etc.).
[0078] For example: when the user has a business operation such as making a small amount of transfer, the user can also complete the transfer by only inputting the transfer password on the smart wearable device. With the stable operation of the trusted device, the user's operation verification can be gradually simplified.
[0079] For another example, when the user logs in to the online banking APP on the computer and makes a transfer, when the user makes a large amount of transfer or other risky transactions, when the smart wearable device is a trusted device, the smart wearable device will push a message through the App on the smart wearable device, and the user clicks the message to confirm or refuse. The user's choice will be uploaded to the server through the data service connected to the smart phone, and the next operation will be performed.
[0080] Through the embodiments of the present disclosure, by forming the trusted device network of the user by the first device and the second device of the user, the smart verification can be directly started on the second device, avoiding the user from logging in to the APP on the first device multiple times in multiple scenarios, thereby providing a safe, reliable, and fast verification scheme for the user and improving the user's experience.
[0081] Based on the above verification method based on the trusted device network, the present disclosure also provides a verification device based on the trusted device network. The following will be combined with Figure 6 The device will be described in detail.
[0082] Figure 6 The structure block diagram of the verification device based on the trusted device network according to the embodiments of the present disclosure is schematically shown.
[0083] As Figure 6As shown, the embodiment of the trusted device network based verification apparatus 600 includes an application installation module 610, a trusted device network establishment module 620, an operation verification module 630, and an operation execution module 640.
[0084] The application installation module 610 is configured to install an application on the second device based on the application information of the first device. In an embodiment, the application installation module 610 can be configured to perform operation S210 described above, and details are not repeated here.
[0085] The trusted device network establishment module 620 is configured to establish a trusted device network according to the first identification code of the first device, the second identification code of the second device, and the connection information of the first device and the second device based on the running of the application. In an embodiment, the trusted device network establishment module 620 can be configured to perform operation S220 described above, and details are not repeated here.
[0086] The operation verification module 630 is configured to verify an operation through communication of the trusted device network in response to any business operation. In an embodiment, the operation verification module 630 can be configured to perform operation S230 described above, and details are not repeated here.
[0087] The operation execution module 640 is configured to execute the operation through the second device according to the result of the verification. In an embodiment, the operation execution module 640 can be configured to perform operation S240 described above, and details are not repeated here.
[0088] According to embodiments of the present disclosure, any of the application installation module 610, the trusted device network establishment module 620, the operation verification module 630, and the operation execution module 640 can be combined in one module, or any of them can be split into multiple modules. Alternatively, at least part of the function of one or more of these modules can be combined with at least part of the function of the other modules, and implemented in one module. According to embodiments of the present disclosure, at least one of the application installation module 610, the trusted device network establishment module 620, the operation verification module 630, and the operation execution module 640 can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on substrate, a system on package, an application specific integrated circuit (ASIC), or any other reasonable way of integrating or packaging a circuit, etc. hardware or firmware, or in any one of software, hardware, and firmware or in any appropriate combination of several of them. Alternatively, at least one of the application installation module 610, the trusted device network establishment module 620, the operation verification module 630, and the operation execution module 640 can be at least partially implemented as a computer program module which can perform corresponding functions when the computer program module is run.
[0089] Figure 7 A block diagram of an electronic device suitable for a trusted device web based authentication method according to an embodiment of the present disclosure is schematically shown.
[0090] As shown, an electronic device 700 according to an embodiment of the present disclosure includes a processor 701 that can perform various appropriate actions and processes according to programs stored in a read only memory (ROM) 702 or loaded from a storage section 707 into a random access memory (RAM) 703. The processor 701 can include, for example, a general purpose microprocessor (e.g., a CPU), an instruction set processor, and / or a related chipset, and / or a special purpose microprocessor (e.g., an application specific integrated circuit (ASIC)), and / or the like. The processor 701 can also include on-board memory for cache purposes. The processor 701 can include a single processing unit or multiple processing units to perform the various actions of the method processes according to embodiments of the present disclosure. Figure 7
[0091] In the RAM 703, various programs and data required for the operation of the electronic device 700 are stored. The processor 701, the ROM 702, and the RAM 703 are connected to each other via a bus 704. The processor 701 performs various operations of the method processes according to embodiments of the present disclosure by executing the programs in the ROM 702 and / or the RAM 703. Note that the programs can also be stored in one or more memories other than the ROM 702 and the RAM 703. The processor 701 can also perform various operations of the method processes according to embodiments of the present disclosure by executing the programs stored in the one or more memories.
[0092] According to embodiments of the present disclosure, the electronic device 700 can also include an input / output (I / O) interface 705, which is also connected to the bus 704. The electronic device 700 can also include one or more of the following components connected to the I / O interface 705: an input section 706 including a keyboard, a mouse, etc.; an output section 707 including a display such as a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 707 including a hard disk, etc.; and a communication section 709 including a network interface card such as a LAN card, a modem, etc. The communication section 709 performs communication processing via a network such as the Internet. A drive 710 is also connected to the I / O interface 705 as necessary. A removable medium 711 such as a magnetic disk, a magneto-optical disk, a semiconductor memory, etc. is attached to the drive 710 as necessary, so that a computer program read out therefrom is installed into the storage section 707 as necessary.
[0093] The present disclosure also provides a computer readable storage medium, which can be included in the device / apparatus / system described in the above embodiments, or exist separately without being assembled into the device / apparatus / system. The above computer readable storage medium carries one or more programs, which, when executed, implement the method according to the embodiments of the present disclosure.
[0094] According to an embodiment of the present disclosure, the computer readable storage medium can be a non-volatile computer readable storage medium, which can include, but is not limited to, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any appropriate combination thereof. In the present disclosure, the computer readable storage medium can be any tangible medium that contains or stores a program, which can be used by or in connection with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present disclosure, the computer readable storage medium can include one or more of the ROM 702 and / or the RAM 703 described above, and / or one or more memories other than the ROM 702 and the RAM 703.
[0095] The embodiments of the present disclosure also include a computer program product, which includes a computer program containing program codes for executing the methods shown in the flowcharts. When the computer program product is run in a computer system, the program codes are used to make the computer system implement the methods provided by the embodiments of the present disclosure.
[0096] The above functions defined in the system / apparatus of the embodiments of the present disclosure are performed when the computer program is executed by the processor 701. According to an embodiment of the present disclosure, the above described system, apparatus, module, unit, etc. can be implemented by computer program modules.
[0097] In one embodiment, the computer program can rely on a tangible storage medium such as an optical storage medium, a magnetic storage medium, etc. In another embodiment, the computer program can also be transmitted, distributed, and downloaded in the form of a signal via a network medium, and be downloaded and installed through the communication part 709, and / or installed from the detachable medium 711. The program codes contained in the computer program can be transmitted by any appropriate network medium, including but not limited to wireless, wired, etc., or any appropriate combination thereof.
[0098] In such embodiments, the computer program can be downloaded and installed from the network via the communication section 709, and / or installed from the removable media 711. When the computer program is executed by the processor 701, the above-described functions defined in the system of the embodiments of the present disclosure are executed. According to the embodiments of the present disclosure, the system, device, apparatus, module, unit, and the like described above can be implemented by the computer program modules.
[0099] According to the embodiments of the present disclosure, the program code for executing the computer program provided by the embodiments of the present disclosure can be written in any combination of one or more programming languages, and specifically, these computer programs can be implemented using high-level procedural and / or object-oriented programming language, and / or assembly / machine language. The programming language includes, but is not limited to, such as Java, C++, python, “C” language or similar programming language. The program code can be executed entirely on the user computing device, partially on the user device, partially on a remote computing device, or entirely on a remote computing device or server. In the case involving a remote computing device, the remote computing device can be connected to the user computing device through any kind of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, connected to the Internet through an Internet service provider).
[0100] The flowcharts and block diagrams in the drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowcharts or block diagrams can represent a module, a segment, or a portion of code, which comprises one or more executable instructions for implementing the specified logical functions. It should also be noted that in some alternative implementations, the functions noted in the blocks can occur out of the order noted in the figures. For example, two blocks noted in succession can in fact be executed substantially concurrently or in the reverse order, depending on the functionality involved. It should also be noted that each block in the flowcharts or block diagrams, and combinations of blocks in the flowcharts or block diagrams, can be implemented by dedicated hardware-based systems that perform the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0101] Those skilled in the art can understand that the features described in various embodiments of the present disclosure and / or claims can be combined or / and integrated, even if such combinations or integrations are not explicitly described in the present disclosure. In particular, the features described in various embodiments of the present disclosure and / or claims can be combined and / or integrated in various combinations, without departing from the spirit and teachings of the present disclosure. All these combinations and / or integrations fall within the scope of the present disclosure.
[0102] The above described embodiments of the present disclosure. However, these embodiments are merely for illustrative purposes, and are not intended to limit the scope of the present disclosure. Although each embodiment is described above separately, this does not mean that the measures in each embodiment cannot be advantageously used in combination. The scope of the present disclosure is defined by the appended claims and their equivalents. Those skilled in the art can make various substitutions and modifications without departing from the scope of the present disclosure, and all such substitutions and modifications shall fall within the scope of the present disclosure.
Claims
1. A method for verifying based on a trusted device network, characterized by, The method comprises: installing the application on the second device based on the application information of the first device; based on the running of the application, establishing a trusted device network according to the first identification code of the first device, the second identification code of the second device, and the connection information of the first device and the second device; in response to any business operation, verifying the operation through the communication of the trusted device network; according to the result of the verification, executing the operation through the second device.
2. The method of claim 1, wherein, The second identification code of the second device is obtained by the following method, comprising: obtaining the running information of the second device when running the application; comprehensively processing the running information and combining the features by using a preset algorithm to obtain the second identification code of the second device.
3. The trustlet-based verification method of claim 1 or 2, wherein, Based on the running of the application, the trusted device network is established according to the first identification code of the first device, the second identification code of the second device, and the connection information of the first device and the second device, comprising: based on the running of the application by the first device and the second device respectively, installing a digital certificate to the first device to match the first device and the second device; based on the matching result, establishing a trusted device network according to the first identification code of the first device, the second identification code of the second device, and the connection information of the first device and the second device, and generating a third identification code of the current trusted device network, wherein the third identification code of the current trusted device network is only one.
4. The method of claim 3, wherein, Based on the running of the application, the trusted device network is established according to the first identification code of the first device, the second identification code of the second device, and the connection information of the first device and the second device, further comprising: determining the first device as a trusted device according to the first identification code of the first device; and determining the second device as a trusted device according to the second identification code of the second device.
5. The method of claim 4, wherein, The third identification code will be updated once for each third device added to the trusted device network.
6. The trustlet-based verification method of claim 1, wherein, In response to any business operation, the operation is verified through the communication of the trusted device network, comprising: obtaining the business operation instruction of the user; based on the business operation instruction, pairing the public key of the first device with the preset private key of the second device and generating a key pair to verify the operation.
7. The method of claim 6, wherein, According to the result of the verification, the operation is executed through the second device, comprising: when the key pair matches, the operation is executed by running the application in the second device.
8. A verification device based on a Trusted Device Network, characterized in that, The device comprises: application installation module, for installing the application on the second device based on the application information of the first device; trusted device network establishment module, for establishing a trusted device network according to the first identification code of the first device, the second identification code of the second device, and the connection information of the first device and the second device based on the running of the application; operation verification module, for verifying the operation through the communication of the trusted device network in response to any business operation; operation execution module, for executing the operation through the second device according to the result of the verification.
9. An electronic device, comprising: one or more processors; a storage means for storing one or more computer programs, characterized in that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1-7.
10. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by a processor to implement the steps of the method according to any one of claims 1-7.
11. A computer program product comprising a computer program, characterized in that, The computer program is executed by a processor to implement the steps of the method according to any one of claims 1-7. The computer program is executed by a processor to implement the steps of the method according to any one of claims 1-7.
Citation Information
Patent Citations
Equipment authentication method, device and system, electronic equipment and medium
CN112733113A
Information processing method and device, equipment and storage medium
CN117591407A