Account sharing method and related equipment

By using the device private key and the device public key to decrypt the ciphertext information on the account holding end and obtaining the login private key, the problem of cumbersome and low security in the existing technology is solved, and a simplified account login process and improved account security is achieved.

CN120017351AActive Publication Date: 2025-05-16VIVO MOBILE COMM CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510152038.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-11
Publication Date
2025-05-16
Estimated Expiration
2045-02-11

Smart Images

  • Figure CN120017351A_ABST
    Figure CN120017351A_ABST
Patent Text Reader

Abstract

The invention discloses an account sharing method and related equipment, and belongs to the technical field of data processing, and the method comprises the steps: obtaining first ciphertext information shared by an account holding end and a login private key identifier corresponding to the first ciphertext information under the condition that a login operation for a target account shared by the account holding end is detected; acquiring a first equipment public key in the account holding end and an equipment private key of the account using end, and determining a first common key according to the first equipment public key and the equipment private key; obtaining a first random number from the account holding end according to the login private key identifier, and decrypting the first ciphertext information according to the first common key to obtain a first encrypted login private key of the target account, the first encrypted login private key being obtained by encrypting a login private key by the first random number; and decrypting the first encrypted login private key according to the first random number to obtain a login private key, and logging in the target account at the account using end according to the login private key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of data processing technology, and specifically relates to an account sharing method and related equipment. Background Art

[0002] In daily life, we may encounter scenarios where we need to share account passwords. For example, user A shares his account password with user B, and user B uses the account password to log in to user A's account on his own device. When user B obtains the account password, the security of user A's account may be reduced.

[0003] In the exemplary technology, when user B needs to log in to user A's account, user B enters the mobile phone number associated with user A's account, and logs in to user A's account by requesting a verification code generated by the input mobile phone number from user A.

[0004] Although the above-mentioned shared account login method does not require the account holder's account password, there are many procedures for logging into the shared account, which makes the process of non-account holders logging into the account holder's account complicated. Summary of the invention

[0005] The purpose of the embodiments of the present application is to provide an account sharing method and related devices to solve the problem of cumbersome procedures for non-account holders to log in to the account of the account holder.

[0006] In a first aspect, an embodiment of the present application provides an account sharing method, including:

[0007] When the account user detects a login operation for a target account shared by the account holder, the account user obtains the first ciphertext information shared by the account holder and a login private key identifier corresponding to the first ciphertext information, where the login private key identifier is used to indicate an identifier of a login private key of the target account;

[0008] The account user obtains the first device public key of the account holder and the device private key of the account user, and determines a first common key according to the first device public key and the device private key;

[0009] The account user obtains a first random number according to the login private key identifier, and decrypts the first ciphertext information according to the first common key to obtain a first encrypted login private key of the target account, wherein the first encrypted login private key is obtained by the account holder encrypting the login private key based on the first random number;

[0010] The account user end decrypts the first encrypted login private key according to the random number to obtain the login private key, and logs in the target account at the account user end according to the login private key.

[0011] In a second aspect, the present application provides an account sharing method, including:

[0012] When the account holder detects a sharing operation for a target account in the account holder, the account holder determines the account user designated by the sharing operation and generates a random number;

[0013] The account holder obtains the login private key of the target account in the account holder and the login private key identifier corresponding to the login private key, and encrypts the login private key according to the random number to obtain an encrypted login private key;

[0014] The account holder obtains the device public key of the account user and the device private key of the account holder, and determines the target common key according to the device public key and the device private key;

[0015] The account holder encrypts the encrypted login private key according to the target common key to obtain ciphertext information, and sends the ciphertext information, the target account and the login private key identifier to the account user.

[0016] In a third aspect, an embodiment of the present application provides an account usage terminal, the device comprising:

[0017] A first acquisition module is used to acquire, when a login operation for a target account shared by an account holder is detected, first ciphertext information shared by the account holder and a login private key identifier corresponding to the first ciphertext information, wherein the login private key identifier is used to indicate an identifier of a login private key of the target account;

[0018] A second acquisition module is used to acquire a first device public key of the account holding end and a device private key of the account using end, and determine a first common key according to the first device public key and the device private key;

[0019] A third acquisition module is used to obtain a first random number according to the login private key identifier, and decrypt the first ciphertext information according to the first common key to obtain a first encrypted login private key of the target account, where the first encrypted login private key is obtained by the account holder encrypting the login private key based on the first random number;

[0020] A decryption module is used to decrypt the first encrypted login private key according to the random number to obtain the login private key, and log in to the target account at the account user end according to the login private key.

[0021] In a fourth aspect, an embodiment of the present application provides an account holding terminal, the device comprising:

[0022] A determination module, configured to, when a sharing operation is detected for a target account in the account holding terminal, determine the account using terminal specified by the sharing operation and generate a random number;

[0023] A fourth acquisition module, used to acquire the login private key of the target account in the account holding terminal and the login private key identifier corresponding to the login private key, and encrypt the login private key according to the random number to obtain an encrypted login private key;

[0024] A fifth acquisition module, used to acquire a device public key of the account user and a device private key of the account holder, and determine a target common key according to the device public key and the device private key;

[0025] The encryption module is used to encrypt the encrypted login private key according to the target common key to obtain ciphertext information, and send the ciphertext information, the target account and the login private key identifier to the account user.

[0026] In a fifth aspect, an embodiment of the present application provides an electronic device, comprising a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps of the method described in the first aspect or the second aspect are implemented.

[0027] In a sixth aspect, an embodiment of the present application provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the method described in the first aspect or the second aspect are implemented.

[0028] In the seventh aspect, an embodiment of the present application provides a chip, which includes a processor and a communication interface, the communication interface is coupled to the processor, and the processor is used to run a program or instruction to implement the method described in the first aspect or the second aspect.

[0029] In an eighth aspect, an embodiment of the present application provides a computer program product, which is stored in a storage medium and is executed by at least one processor to implement the method described in the first aspect or the second aspect.

[0030] In an embodiment of the present application, when the account-using end performs a login operation on a target account shared by the account-holding end, the ciphertext information of the account-holding end is decrypted through the device private key of the account-using end, the device public key of the account-holding end, and the random number of the account-holding end, and the login private key of the target account used for login is obtained, thereby realizing the login of the target account on the account-using end through the login private key. The user only needs to perform a login operation once on the account-using end to log in to the target account shared by the account-holding end. Since the user cannot learn the login password of the target account based on the login private key, the process of users logging into the shared account is reduced, and the process of non-account holders logging into the account of the account holder is simplified. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] Figure 1 is a schematic diagram of a scenario of an account sharing method according to an exemplary embodiment;

[0032] Figure 2 This is one of the flowcharts of an account sharing method according to an exemplary embodiment of an account user terminal;

[0033] Figure 3 This is a second flowchart diagram of an account sharing method according to an exemplary embodiment;

[0034] Figure 4 is a schematic diagram of interaction between an account holding end and an account using end according to an exemplary embodiment;

[0035] Figure 5 is a third flow chart of an account sharing method according to an exemplary embodiment of an account user end;

[0036] Figure 6 This is a fourth flow chart of an account sharing method according to an exemplary embodiment of an account user end;

[0037] Figure 7 This is one of the flowcharts of an account sharing method according to an exemplary embodiment of an account holding end;

[0038] Figure 8 is a structural block diagram of an account user terminal according to an exemplary embodiment;

[0039] Fig. 9 is a structural block diagram of an account holding terminal according to an exemplary embodiment;

[0040] Fig.10 is a structural block diagram of an electronic device according to an exemplary embodiment;

[0041] Fig.11A schematic diagram of the hardware structure of an electronic device to implement an embodiment of the present application. DETAILED DESCRIPTION

[0042] The following will be combined with the drawings in the embodiments of the present application to clearly describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments in the present application belong to the scope of protection of this application.

[0043] The terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described here, and the objects distinguished by "first", "second", etc. are generally of one type, and the number of objects is not limited. For example, the first object can be one or more. In addition, "and / or" in the specification and claims represents at least one of the connected objects, and the character " / " generally indicates that the objects associated with each other are in an "or" relationship.

[0044] In daily life, we may encounter scenarios where we need to share account passwords. For example, user A shares his account password with user B, and user B uses the account password to log in to user A's account on his own device. When user B obtains the account password, the security of user A's account may be reduced.

[0045] In the exemplary technology, when user B needs to log in to user A's account, user B enters the mobile phone number associated with user A's account, and logs in to user A's account by requesting a verification code generated by the input mobile phone number from user A.

[0046] Although the above-mentioned shared account login method does not require the account holder's account password, there are many procedures for logging into the shared account, which makes the process of non-account holders logging into the account holder's account complicated.

[0047] In response to the problem of cumbersome procedures for non-account holders to log in to the account of the account holder, the inventor of the present application conceived that, when the account-using end performs the login operation of the target account shared by the account holder, the ciphertext information of the account holder is decrypted by the device private key of the account-using end, the device public key of the account holder and the random number of the account holder to obtain the login private key of the target account used for login, thereby realizing the login of the target account at the account-using end through the login private key. The user only needs to perform one login operation at the account-using end to log in to the target account shared by the account holder. Since the user cannot know the login password of the target account based on the login private key, the process of users logging in to the shared account is reduced and the process of non-account holders logging in to the account of the account holder is simplified.

[0048] Reference Figure 1 , the scenario diagram of the account sharing method provided by this application is explained. Figure 1 As shown, the account holder 100 is the binding terminal of the target account, and the account holder 100 can share the target account. The terminal that accepts the sharing of the target account is the account user 200. The account holder 100 obtains the login private key of the target account, encrypts the login private key to obtain ciphertext information, and sends the login private key identifier, target account and ciphertext information corresponding to the login private key to the account user 200. When the account user 200 needs to log in to the target account, the account user 200 uses the device public key, login private key identifier and its own device private key of the account holder 100 to decrypt the ciphertext information to obtain the login private key. The account user 200 sends signature data to the authentication server 300 based on the login key. After the authentication server 300 passes the authentication based on the signature data, it feeds back the running interface of the target account to the account user 200, that is, the account user 200 successfully logs in to the target account.

[0049] The following combination includes Figure 1 The accompanying drawings describe in detail the account sharing method and related devices provided in the embodiments of the present application through specific embodiments and their application scenarios.

[0050] The account sharing method provided in the embodiment of the present application can be applied to application scenarios of account sharing.

[0051] Combine the following Figure 1 The account sharing method provided in the embodiment of the present application is described in detail.

[0052] Reference Figure 2 , Figure 2 This is one of the flow diagrams of the account sharing method on the account user side provided by this application, such as Figure 2 As shown, the account sharing method includes the following steps:

[0053] Step S201, when a login operation for a target account shared by an account holder is detected, obtain the first ciphertext information shared by the account holder and the login private key identifier corresponding to the first ciphertext information, where the login private key identifier is used to indicate the identifier of the login private key of the target account.

[0054] In this embodiment, the execution subject is the account user terminal. The account user terminal refers to the terminal that logs into the target account shared by the account holder terminal. The account user terminal can be a mobile phone, computer, tablet or other device. The account holder terminal refers to the terminal that the target account is bound to or frequently logged in.

[0055] An account list is set in the account user end, and the account list includes the account bound to the account user end and the target account of the account holder end. The target account is the account bound to the account holder end and the account shared by the account holder end. User B can select the target account shared by the account holder end in the account list to log in. When the account user end detects the login operation for the target account, it can be determined that user B selects the target account shared by the account holder end to log in. The target account can be an account of a video website, a game account, an account of a social software, etc. User A shares the target account of user A with the account user end associated with user B through the account holder end, so that user B can log in to the target account through the account user end.

[0056] When a login operation of the target account is detected, the account user obtains the stored first ciphertext information and the login private key identifier corresponding to the first ciphertext information. The first ciphertext information and the login private key identifier are sent to the account user when the account holder shares the target account. The first ciphertext information contains the login private key required to log in to the target account, and the first ciphertext information contains the encrypted login private key. The first ciphertext information is used by the account user to obtain the encrypted login private key. The login private key identifier refers to the identifier of the login private key. The login private key identifier is used by the account user to decrypt the first ciphertext information. The specific decryption process is referred to below.

[0057] The first ciphertext information and the login private key identifier are stored on the account user end, but the first ciphertext information and the login private key identifier can also be stored on the account service end. Exemplarily, the account user end itself has account B, and the account holder end sends the first ciphertext information, account B, account A (target account) and the login private key identifier to the account service end for associated storage. When the account user end needs to obtain the first ciphertext information, it generates an acquisition request based on account B and sends the acquisition request to the account service end. The account service end parses the acquisition request to obtain account B, and the account service end sends the first ciphertext information and the login private key identifier associated with account B to the account user end.

[0058] Step S202, obtain the first device public key of the account holder and the device private key of the account user, and determine the first common key based on the first device public key and the device private key.

[0059] After obtaining the first ciphertext information, the account user needs to decrypt the first ciphertext information. Exemplarily, the account user obtains the device public key of the account holder, and the device public key is defined as the first device public key. It should be noted that the device public key involved in this application refers to the public key of the device, and other devices can obtain the data of the device where the device public key is located through the device public key. Exemplarily, the first device public key of the account holder is stored in the server, and the account holder generates a public key acquisition request for the account holder based on the device identifier of the account holder, and sends the public key acquisition request to the server. The server parses the public key acquisition request to obtain the device identifier, and the device public key stored in the server is stored in association with the device identifier corresponding to the device public key. The server can obtain the associated first device public key through the device identifier and send the first device public key to the account user.

[0060] A device private key is set in the account user end, and the account user end obtains the stored device private key. It should be noted that the device private key involved in this application is a key that the device is not open to the public, and the function of the device private key is: the device where the device private key is located encrypts the data. The first ciphertext information is encrypted by the account holder based on the device public key of the account user end and the device private key of the account holder end. Therefore, the account user end can decrypt the first ciphertext information based on the first device public key and the device private key of the account holder end. The specific decryption method is that the account holder end generates a common key based on the first device public key and the device private key. The generation method is, for example, splicing the first device public key and the device private key to obtain a common key. The common key is defined as the first common key. The account holder end then uses the first common key to decrypt the first ciphertext information to obtain the encrypted login private key.

[0061] Step S203, obtain a first random number according to the login private key identifier, and decrypt the first ciphertext information according to the first common key to obtain a first encrypted login private key of the target account, the first encrypted login private key is obtained by the account holder encrypting the login private key based on the first random number.

[0062] The account holder can obtain the encrypted login private key by decrypting the first ciphertext information through the first common key, and the encrypted login private key is defined as the first encrypted login private key. The first encrypted login private key is generated by the account holder based on its own first random number and login private key, so the account user needs to decrypt the first encrypted login private key based on the first random number. In one example, the account user stores the first random number sent by the account holder, and the first random number is stored in association with the login private key identifier. The account user obtains the first random number associated with the login private key identifier. In another example, the account user generates a target login request for the target account based on the login private key identifier, and sends the target login request to the account holder. The account holder parses the target login request to obtain the login private key identifier, and sends the first random number associated with the login private key identifier to the account user.

[0063] Step S204: decrypt the first encrypted login private key according to the first random number to obtain a login private key, and log in to the target account at the account user end according to the login private key.

[0064] The first encrypted login private key is obtained by the account holder end encrypting the login private key based on the first random number. Exemplarily, the login private key is passkey_pri_1, and the first random number is rand_1, then the first encrypted login private key sub_passkey_pri_1=passkey_pri_1⊕rand_1, where ⊕ represents the symbol of the XOR operation. After obtaining the first random number, the account user end decrypts the first encrypted login private key based on the first random number, that is, performs the operation of sub_passkey_pri_1⊕rand_1. Since sub_passkey_pri_1=passkey_pri_1⊕rand_1, sub_passkey_pri_1⊕rand_1=passkey_pri_1, that is, the login private key can be obtained.

[0065] After obtaining the login private key, the account user can log in to the target account on the account user based on the login private key. Exemplarily, the account user generates a login request based on the login private key identifier, and sends the login request to the authentication server. The server parses the login request to obtain the login private key identifier, obtains the login public key associated with the login private key identifier, and sends a challenge value challenge to the account user. The authentication server performs a signature operation on the login public key passkey_pub_1 based on the challenge to obtain the first signature data Sign(passkey_pub_1, challenge). After obtaining the challenge, the account user signs the login private key based on the challenge to obtain the second signature data Sign(passkey_pri_1, challenge). The account user sends the second signature data Sign(passkey_pri_1, challenge) to the authentication server. The authentication server compares the second signature data Sign(passkey_pri_1, challenge) with the first signature data Sign(passkey_pub_1, challenge). If the two match, the authentication is successful. The authentication server sends the running interface of the target account to the account user, allowing the account user to log in to the target account.

[0066] It should be noted that after the account user obtains the login private key, the login private key cannot be stored by the account user due to its special structure. For example, the login private key is set with a script code. When the script code detects a storage write operation from a non-account holder, it disrupts the order of the fields in the login private key, making it impossible for the account user to store the login private key, thus preventing the account user from using the stored login private key for long-term login to the target account.

[0067] In this embodiment, when the account-using end performs a login operation on a target account shared by the account-holding end, the ciphertext information of the account-holding end is decrypted through the device private key of the account-using end, the device public key of the account-holding end, and the random number of the account-holding end, and the login private key of the target account used for login is obtained, thereby realizing the login of the target account at the account-using end through the login private key. The user only needs to perform a login operation once at the account-using end to log in to the target account shared by the account-holding end. Since the user cannot learn the login password of the target account based on the login private key, the process of users logging into the shared account is reduced, and the process of non-account holders logging into the account of the account holder is simplified.

[0068] Reference Figure 3 , Figure 3 This is the second flow chart of the account sharing method on the account user side provided by this application, based on Figure 2In the embodiment shown, before step S201, the following steps are further included:

[0069] Step S301, receiving the first ciphertext information, the login private key identifier and the target account sent by the account holder, and constructing a sharing list according to the login private key identifier and the target account.

[0070] Step S302: store the sharing list in association with the first ciphertext information.

[0071] In this embodiment, user A can select a terminal shared by the target account in the account holding terminal, that is, the account holding terminal detects the sharing operation for the target account and obtains the account user terminal specified by the sharing operation. Exemplarily, the user can specify that user B of account B can use the target account. The terminal where account B is located is the account user terminal. In addition, the target account is also provided with multiple login private keys, each of which can be used to log in to the target account. User A can select the login private key identified as passkey_id_1 as the login private key that the account user terminal can use to log in to the target account. The designated account user terminal can be determined by scanning the code or the friends and relatives list. In one example, the account holding terminal scans the shared QR code of other terminals, and after the scanning is completed, the other terminals serve as the account user terminal. In another example, user A clicks on the friends and relatives list in the account holding terminal, and the friends and relatives list contains multiple accounts. User A performs an account selection operation in the friends and relatives list, that is, the account holding terminal displays the friends and relatives list, and after detecting the selection operation, the terminal where the account selected by the selection operation is located is used as the account user terminal. After determining the account user, the account holder obtains the target account's login private key passkey_pri_1 and login private key identifier passkey_id_1, and generates a random number rand_1, which is defined as the first random number, and the first random number has the same length as passkey_pri_1.

[0072] The account holder encrypts the login private key with the first random number to obtain an encrypted login private key. For example, the first encrypted login private key sub_passkey_pri_1=passkey_pri_1⊕rand_1. The account holder stores the target account account_A, the account user's account account_B, the login private key identifier, and the random number rand_1 in the sharing list of account_A. The sharing list is as follows:

[0073] Receiver Login private key source passkey id Random Numbers account_B account_A passkey_id_1 rand_1

[0074] A trusted list is set in the account holder, for example:

[0075]

[0076] When the ID of the account user selected by the account holder needs to be in the trusted list. The account holder obtains the device public key device_B_trust_pub of the account user from the trusted list based on the ID of the account user. The account holder stores the device private key device_A_trust_pri. The account holder generates a common key shared_AB_key=SHARE(device_B_trust_pub,device_A_trust_pri) through the device public key of the account user and the device private key of the account holder, where A refers to the account holder and B refers to the account user.

[0077] The account holder encrypts the first encrypted login private key based on the target common key to obtain the first ciphertext information Enc(shared_AB_key,sub_passkey_pri_1). The account holder then sends the first ciphertext information, the target account and the login private key identifier to the account user, that is, the account user receives the first ciphertext information, the login private key identifier and the target account sent by the account holder. The account user constructs a sharing list based on the login private key identifier and the target account. The sharing list is, for example:

[0078] Target account Login private key ID account_A passkey_id_1

[0079] The account user stores the sharing list in association with the first ciphertext information.

[0080] Step S303, when a login operation for a target account shared by the account holder is detected, a login private key identifier is obtained from the sharing list according to the target account, and the first ciphertext information associated with the sharing list is obtained.

[0081] When the account user detects a login operation for the target account, the account user determines the sharing list where the target account is located, obtains the login private key identifier from the sharing list, and obtains the first ciphertext information associated with the sharing list. By setting the sharing list, the login private key identifier can be quickly obtained, which speeds up the account user to obtain the login private key of the target account, thereby quickly logging in to the target account and improving the user experience.

[0082] Furthermore, the account holder sets the first valid time period information time1 for the first encrypted login private key, and sends the first ciphertext information, the target account, the first valid time period information and the login private key identifier to the account user. By setting the first valid time period information of the first encrypted login private key, the account user can only use the target account during the specified valid time period, which meets the user's need to limit the sharing time of the target account and improves the user experience.

[0083] The account user receives the first ciphertext information, the login private key identifying the target account, and the first valid time period information sent by the account holder, thereby constructing a sharing list with the target account and the first valid time period information. The constructed sharing list is as follows:

[0084]

[0085] The account user first determines the sharing list where the target account is located, and obtains the first valid time period information time1 from the sharing list. If the current time point is in the first valid time period information, it can be determined that the target account can continue to log in to the account user. The account user obtains the login private key identifier from the sharing list for subsequent acquisition of the login private key.

[0086] When the current time point exceeds the first valid time point, the target account cannot log in at the account user end, and the account user end outputs a prompt message indicating that the target account has expired. Specifically, the login private key sets the script code based on the first valid time period information, and the script code calculates the storage time of the first ciphertext information in the account user end. If the storage time reaches the time of the first valid time period information, the script code disrupts the order of the fields in the login private key, so that the account user end cannot obtain the real login private key to log in to the target account.

[0087] Based on this embodiment, refer to Figure 4 , briefly describe the interaction between the account holder and the account user, as follows:

[0088] 401. The account holder obtains the login private key passkey_pri_1 corresponding to the login private key identifier passkey_id_1, and generates a random number rand_1;

[0089] 402. Generate sub_passkey_pri_1=passkey_pri_1⊕rand_1 based on the random number rand_1 and passkey_pri_1, and configure the valid time period time1 of sub_passkey_pri_1;

[0090] 403. The account holder obtains the device public key device_B_trust_pub of the account user from the account user.

[0091] 404. The account holder generates a common key shared_AB_key=SHARE(device_B_trust_pub, device_A_trust_pri) based on its own device private key device_A_trust_pri and device public key device_B_trust_pub.

[0092] 405. The account holder uses the common key shared_AB_key to encrypt sub_passkey_pri_1 to obtain the ciphertext sub_passkey_cipher=Enc(shared_AB_key,sub_passkey_pri_1);

[0093] 406. The account holder sends the ciphertext, the account accouA, the login private key identifier passkey_id_1, and the valid time period time1 to the account user;

[0094] 407. The account user obtains the device public key device_A_trust_pub from the account holder;

[0095] 408. Generate a common key shared_BA_key=SHARE(device_A_trust_pub, device_B_trust_pri) based on device_A_trust_pub and its own device private key device_B_trust_pri.

[0096] 409. The account user uses shared_BA_key to decrypt the ciphertext sub_passkey_cipher to obtain the encrypted login private key sub_passkey_pri_1;

[0097] 410. The account user sends a request {req, passkey_id_1} to the account holder;

[0098] 411. The account holder feeds back a random number rand_1 based on the request;

[0099] 412. The account user decrypts the encrypted login private key based on the random number to obtain a temporary login private key passkey_pri_1 = sub_passkey_pri_1⊕rand_1;

[0100] 413. The account user logs in to account acountA based on passkey_pri_1.

[0101] In this embodiment, the user can safely share the target account with other users through the account holding terminal without worrying about the leakage of the login password of the target account, thereby improving the sharing security of the target account.

[0102] Reference Figure 5 , Figure 5 This is the third flow chart of the account sharing method on the account user side provided by this application, based on Figure 2 or Figure 3In the illustrated embodiment, step S202 includes:

[0103] Step S501, determining the sharing terminal of the target account.

[0104] In this embodiment, the target account can be shared multiple times. For example, the target account belongs to user A. User A shares the target account with user B, and user B can share the target account with user C, thereby forming a long link sharing of the target account. Due to the existence of long link sharing, the account user end can be a secondary sharing terminal of the target account or a multi-level sharing terminal. The secondary sharing terminal refers to the terminal that directly shares the target account with the account holder; the multi-level sharing terminal refers to the terminal that other terminals authorize the target account to log in with the consent of the account holder. The multi-level sharing terminal is, for example, the terminal device associated with the above-mentioned user C.

[0105] The sharing terminal above the account user end uses its device private key to encrypt the encrypted login private key, so the account user end needs to determine the sharing terminal to obtain the accurate device public key. For example, device A shares the target account with device B, device B shares the target account with device C, and device C shares the target account with device D. The sharing link of the target account is device A→device B→device C→device D. Device C needs to log in to the target account, so the upper sharing terminal of device C is device B. In this regard, the account user end determines the terminal that sends the first ciphertext information, and the terminal is defined as the sharing terminal.

[0106] Step S502: When the sharing terminal is the account holder, obtain the first device public key of the account holder and the device private key of the account user.

[0107] When the sharing terminal is the account holder, the account user obtains the first device public key of the account holder and the device private key of the account user, decrypts the first ciphertext information to obtain the first encrypted login private key, and then decrypts the first encrypted login private key based on the first random number to obtain the login private key.

[0108] When the sharing terminal is not the account holding terminal, the account user obtains the device public key of the sharing terminal, which is defined as the second device public key and the device private key of the account user. The second common key is determined based on the second device public key and the device private key, and the first ciphertext information is decrypted by the second common key to obtain the second encrypted login private key of the target account.

[0109] The second encrypted login private key is a login private key encrypted by random numbers of all upstream terminals of the account user. For example, device A shares the target account with device B, device B shares the target account with device C, and device C shares the target account with device D. The target account sharing link is device A→device B→device C→device D. If device C needs to log in to the target account, the upstream terminals include device B and device A, which means that it needs to obtain the random numbers generated by device A and device B. These random numbers are all random numbers used to encrypt the login private key.

[0110] In this regard, the account user obtains the first random number generated by the account holder based on the login private key identifier, and obtains the second random number generated by the sharing terminal based on the login private key identifier. Exemplarily, the upstream terminal includes device B and device A, then the account user sends a random number acquisition request to device B (sharing terminal) based on the login private key identifier, and device B obtains the second random number; and if device B finds that the login private key identifier is sent by device A, then device B sends a random number acquisition request to device A based on the login private key identifier, so that device A feeds back the first random number to device B, and device B feeds back the second random number and the first random number to the account user.

[0111] The account user end decrypts the second encrypted login private key based on the first random number and the second random number to obtain the login private key, so as to log in the target account on the account user end through the login private key. Exemplarily, the second encrypted login secret key is encrypted by the first random number rand_1 of device A and the second random number rand_2 of device B, and the second encrypted login private key is expressed as: passkey_pri_1⊕rand_1⊕rand_2; the account user end uses the first random number rand_1 and the second random number rand_2 to decrypt, and the decryption process is: passkey_pri_1⊕rand_1⊕rand_2⊕rand_1⊕rand_2, so as to obtain the login private key passkey_pri_1.

[0112] In this embodiment, the sharing of the target account can support long link sharing. The account user accurately obtains the device public key based on its own sharing terminal in the long link to ensure that the correct login private key is obtained.

[0113] Reference Figure 6 , Figure 6 This is the fourth flow chart of the account sharing method on the account user side provided by this application, based on Figure 2 , Figure 3 or Figure 5 In the embodiment shown, after step S204, the following steps are further included:

[0114] Step S601, when a sharing operation for a target account is detected, a target terminal specified by the sharing operation is determined, and a third random number is generated.

[0115] In this embodiment, the account user terminal can share the target account for a second time. Specifically, user B can share the target account on the account user terminal, that is, when the account user terminal detects the sharing operation for the target account, it determines the target terminal specified by the sharing operation. Exemplarily, user B long presses the control of the target account on the account user terminal, and the account user terminal pops up a sharing option box. If user B clicks the sharing option box, the account user terminal outputs a list of relatives and friends for user B to select the account shared by the target account in the list of relatives and friends. The terminal where the account is located is defined as the target terminal.

[0116] Furthermore, the account user needs to obtain the consent of the account holder to share the target account. In this regard, after determining the account of the terminal corresponding to the sharing operation, the account user generates a sharing request based on the account and sends the sharing request to the account holder. The account holder displays the account of the above terminal, and the account carries the name of the user associated with the terminal. If user A agrees to share the target account with the user associated with the account, he clicks the button to agree to share on the account holder, and the account holder sends the consent information to the account user, and the account user uses the terminal corresponding to the sharing operation as the target terminal.

[0117] Before sharing the target account, the account user needs to encrypt the first encrypted login private key. In response, the account user generates a random number, which is defined as the third random number.

[0118] Step S602: encrypt the first encrypted login private key according to the third random number to obtain a third encrypted login private key.

[0119] After obtaining the third random number, the account user terminal further encrypts the first encrypted login private key based on the third random number to obtain a third encrypted login private key. For example, if the third random number is rand_3, then the third encrypted login private key is sub_passkey_pri_1⊕rand_3.

[0120] Step S603: Acquire the second device public key of the target terminal, and determine the third common key according to the second device public key and the device private key.

[0121] After obtaining the third encrypted login private key, the account user needs to further encrypt the third encrypted login private key. Exemplarily, a trusted list is stored in the account user, and the device public key of the target terminal is stored in the trusted list. The account user obtains the device public key of the target terminal from the trusted list, and the device public key is defined as the second device public key. The account user then generates a common key based on the second device public key and its own device private key, and the common key is defined as the third common key. Exemplarily, the second device public key is device_C_trust_pub, and the device private key is device_B_trust_pri, then the third common key shared_BC_key = SHARE (device_C_trust_pub, device_B_trust_pri), B represents the account user, and C represents the target terminal.

[0122] Step S604: encrypt the third encrypted login private key according to the third common key to obtain second ciphertext information, and send the second ciphertext information, the target account and the login private key identifier to the target terminal.

[0123] After obtaining the third common key, the account user encrypts the third encrypted login private key based on the third common key to obtain the second ciphertext information sub_sub_passkeys_cipher, and then sends the second secret information, the target account and the login private key identifier to the target terminal.

[0124] Furthermore, the account user can set the effective time period information time2 for the third encrypted login private key, and the effective time period information is defined as the second effective time period information. The account user sends the second ciphertext information, the target account and the second effective time period information to the target terminal, that is, the target terminal can log in to the target account during the second effective time period information.

[0125] When the target terminal needs to log in to the target account, the target terminal generates a fourth common key through the third device public key of the account user end and the device private key of the target terminal, and decrypts the second ciphertext information through the fourth common key to obtain the third encrypted login private key. The target terminal then sends a first login request for the target account to the target user end. The target user end parses the first login request to obtain the login private key identifier, and then obtains the third random number based on the login private key identifier. The target user end generates a second login request for the target terminal to log in to the target account based on the login private key identifier, and then sends the second login request to the account holder end, and the account holder end feeds back the first random number. After receiving the first random number, the account user end sends the first random number and the third random number to the target terminal, so that the target terminal can obtain the login private key based on the first random number and the third random number to log in to the target account. The process of the target account obtaining the login private key based on the first random number and the third random number is the same as the process of the account user end obtaining the login private key based on the first random number and the second random number, and will not be repeated here.

[0126] It should be noted that each time the target account is shared, a sub-link will be generated on the account holder side. The complete sharing link can be obtained by merging the sub-links on the account holder side. For example, if device A shares the account with account B, the corresponding sub-link is device A→device B; if device B shares the account with account C, the corresponding sub-link is device B→device C; the sharing link synthesized by the two sub-links is: A→device B→device C.

[0127] In this embodiment, the account can support long link sharing, that is, other terminals that log in to the target account can share the target account with other people, so that multiple users can share the account, thereby improving the user experience.

[0128] In one embodiment, user A who holds the account can cancel the sharing of the target account.

[0129] Specifically, when the account holder cancels the permission of the account user to log in to the target account, the authentication server sends a login interface to the account user, that is, the authentication server forces the account user to log out of the target account, so that the account user switches from the running interface of the target account to the login interface. It can be understood that the account user displays the login interface sent by the authentication server. Exemplarily, the account holder displays an account user that can log in to the target account. When user A clicks the control represented by the account user on the account holder, a button to cancel sharing pops up; if user A clicks the button, it is deemed that the account holder detects the cancellation operation of the permission of the account user to log in to the target account, and the account holder sends the exit instruction of the target account to the authentication service, so that the authentication server sends the login interface to the account user based on the exit instruction, that is, the authentication server forcibly switches the running interface of the target account of the account user to the login interface, so as to force the target account to log out from the account user.

[0130] In this embodiment, the user at the account holder end can cancel sharing of the target account, and the person being shared cannot continue to use the login private key to log in to the target account, thereby ensuring the target account owner's control over the sharing of the target account.

[0131] Reference Figure 7 , Figure 7 This is one of the flow diagrams of the account sharing method on the account holder side provided by this application. The account sharing method includes:

[0132] Step S701, when a sharing operation is detected for a target account in an account holding end, the account user end specified by the sharing operation is determined and a random number is generated.

[0133] In this embodiment, the execution subject is the account holder.

[0134] In this embodiment, user A can select a terminal shared by the target account in the account holding terminal, that is, the account holding terminal detects the sharing operation for the target account and obtains the account user terminal specified by the sharing operation. Exemplarily, the user can specify that user B of account B can use the target account. The terminal where account B is located is the account user terminal. In addition, the target account is also provided with multiple login private keys, each of which can be used to log in to the target account. User A can select the login private key identified as passkey_id_1 as the login private key that the account user terminal can use to log in to the target account. The designated account user terminal can be determined by scanning the code or the friends and relatives list. In one example, the account holding terminal scans the shared QR code of other terminals, and after the scanning is completed, the other terminals serve as the account user terminal. In another example, user A clicks on the friends and relatives list in the account holding terminal, and the friends and relatives list contains multiple accounts. User A performs an account selection operation in the friends and relatives list, that is, the account holding terminal displays the friends and relatives list, and after detecting the selection operation, the terminal where the account selected by the selection operation is located is used as the account user terminal. After determining the account user, the account holder obtains the target account's login private key passkey_pri_1 and login private key identifier passkey_id_1, and generates a random number rand_1, the length of which is consistent with that of passkey_pri_1.

[0135] Step S702, obtaining the login private key of the target account in the account holder and the login private key identifier corresponding to the login private key, and encrypting the login private key according to a random number to obtain an encrypted login private key.

[0136] Step S703, obtain the device public key of the account user and the device private key of the account holder, and determine the target common key based on the device public key and the device private key.

[0137] The account holder encrypts the login private key with a random number to obtain an encrypted login private key. For example, the encrypted login private key sub_passkey_pri_1 = passkey_pri_1⊕rand_1. The account holder stores the target account account_A, the account user's account account_B, the login private key identifier, and the random number rand_1 in the sharing list of account_A. The sharing list is as follows:

[0138] Receiver Login private key source passkey id Random Numbers account_B account_A passkey_id_1 rand_1

[0139] A trusted list is set in the account holder, for example:

[0140]

[0141] When the ID of the account user selected by the account holder needs to be in the trusted list. The account holder obtains the device public key device_B_trust_pub of the account user from the trusted list based on the ID of the account user. The account holder stores the device private key device_A_trust_pri. The account holder generates a common key shared_AB_key=SHARE(device_B_trust_pub,device_A_trust_pri) through the device public key of the account user and the device private key of the account holder, where A refers to the account holder and B refers to the account user.

[0142] Step S704, encrypt the encrypted login private key according to the target common key to obtain ciphertext information, and send the ciphertext information, the target account and the login private key identifier to the account user.

[0143] The account holder encrypts the encrypted login private key based on the target common key to obtain the ciphertext information Enc(shared_AB_key,sub_passkey_pri_1). The account holder then sends the ciphertext information, the target account and the login private key identifier to the account user, that is, the account user receives the ciphertext information, login private key identifier and target account sent by the account holder. The account user constructs a sharing list based on the login private key identifier and the target account. The sharing list is, for example:

[0144] Target account Login private key ID account_A passkey_id_1

[0145] The account user associates and stores the sharing list with the ciphertext information. The account user uses the ciphertext information to obtain the login private key to log in to the target account. For details, refer to the above embodiment and will not be repeated here.

[0146] Furthermore, the account holder sets the valid time period information time1 for the encrypted login private key, and sends the ciphertext information, the target account, the valid time period information and the login private key identifier to the account user.

[0147] The account user receives the ciphertext information, login private key identification target account and valid time period information sent by the account holder, and then constructs a sharing list with the target account and valid time period information. The constructed sharing list is as follows:

[0148]

[0149] The account user first determines the sharing list where the target account is located, and obtains the valid time period information time1 from the sharing list. If the current time point is in the valid time period information, it can be determined that the target account can continue to log in to the account user. The account user obtains the login private key identifier from the sharing list for subsequent acquisition of the login private key.

[0150] If the current time point exceeds the valid time period information, the target account cannot log in at the account user end, and the account user end outputs a prompt message that the target account has expired. Specifically, the login private key sets the script code based on the valid time period information. The script code calculates the storage duration of the ciphertext information at the account user end. If the storage duration reaches the duration of the valid time period information, the script code disrupts the order of the fields in the login private key, making it impossible for the account user end to obtain the real login private key to log in to the target account.

[0151] In this embodiment, the account holder encrypts the login private key through a random number, a device private key, and a device public key of the account user, so that the account user cannot know the login password of the target account when logging into the target account, thereby improving the login security of the target account. The account user only needs to perform the login operation of the target account once to complete the login of the target account, thereby simplifying the process of a non-account holder logging into the account of the account holder.

[0152] In one embodiment, after the account holder sends the ciphertext information, the target account and the login private key identifier to the account user, if the account user needs to log in to the target account, it needs to obtain a random number used to encrypt the login private key from the account holder. Specifically, the account user generates a target login request for the target account based on the login private key identifier, and sends the target login request to the account holder, receives the target login request for the target account sent by the account user, parses the target login request to obtain the login private key identifier, obtains the login private key identifier according to the target login request, obtains the random number of the login private key corresponding to the encrypted login private key identifier, and sends the random number to the account user.

[0153] In this embodiment, when the account user needs to log in to the target account, the random number used to encrypt the login private key is sent to the account user to ensure that the account user can obtain the correct login private key to log in to the target account.

[0154] In one embodiment, user A who holds the account can cancel the sharing of the target account.

[0155] Specifically, when the account holder cancels the permission of the account user to log in to the target account, the authentication server sends a login interface to the account user, that is, the authentication server forces the account user to log out of the target account, so that the account user switches from the running interface of the target account to the login interface. It can be understood that the account user displays the login interface sent by the authentication server. Exemplarily, the account holder displays an account user that can log in to the target account. When user A clicks the control represented by the account user on the account holder, a button to cancel sharing pops up; if user A clicks the button, it is deemed that the account holder detects the cancellation operation of the permission of the account user to log in to the target account, and the account holder sends the exit instruction of the target account to the authentication service, so that the authentication server sends the login interface to the account user based on the exit instruction, that is, the authentication server forcibly switches the running interface of the target account of the account user to the login interface, so as to force the target account to log out from the account user.

[0156] In this embodiment, the user at the account holder end can cancel sharing of the target account, and the person being shared cannot continue to use the login private key to log in to the target account, thereby ensuring the target account owner's control over the sharing of the target account.

[0157] Based on the same inventive concept, the present application also provides an account usage terminal. Figure 8 The account usage terminal provided in the embodiment of the present application is described in detail.

[0158] Figure 8 It is a structural block diagram of an account holding terminal according to an exemplary embodiment.

[0159] like Figure 8 As shown, 800 may be an electronic device for logging into an account, and the account user terminal 800 may include:

[0160] A first acquisition module 810 is used to acquire, when a login operation for a target account shared by an account holder is detected, the first ciphertext information shared by the account holder and a login private key identifier corresponding to the first ciphertext information, where the login private key identifier is used to indicate an identifier of a login private key of the target account;

[0161] The second acquisition module 820 is used to acquire the first device public key of the account holder and the device private key of the account user, and determine the first common key according to the first device public key and the device private key;

[0162] A third acquisition module 830 is used to obtain a first random number according to the login private key identifier, and decrypt the first ciphertext information according to the first common key to obtain a first encrypted login private key of the target account, where the first encrypted login private key is obtained by encrypting the login private key based on the first random number by the account holder;

[0163] The decryption module 840 is used to decrypt the first encrypted login private key according to the first random number to obtain the login private key, and log in to the target account at the account user end according to the login private key.

[0164] In one embodiment, the account user terminal 800 is specifically used for:

[0165] Receiving the first ciphertext information, the login private key identifier, and the target account sent by the account holder, and constructing a sharing list according to the login private key identifier and the target account;

[0166] storing the sharing list in association with the first ciphertext information;

[0167] Obtaining the first ciphertext information shared by the account holder and the login private key identifier corresponding to the first ciphertext information, including:

[0168] According to the target account, obtain the login private key identifier from the sharing list, and obtain the first ciphertext information associated with the sharing list.

[0169] In one embodiment, the account user terminal 800 is specifically used for:

[0170] Receive the first ciphertext information, the login private key identifier, the target account number, and the first valid time period information of the first ciphertext information sent by the account holder;

[0171] Construct a sharing list based on the login private key identifier, the target account, and the first valid time period information;

[0172] According to the target account, obtain the login private key identifier from the sharing list, including:

[0173] According to the target account, obtain the first valid time period information from the sharing list;

[0174] When the current time point is within the first valid time period, the login private key identifier is obtained from the sharing list.

[0175] In one embodiment, the account user terminal 800 is specifically used for:

[0176] When the current time point exceeds the first valid time period information, a prompt message indicating that the target account has expired is output.

[0177] In one embodiment, the account user terminal 800 is specifically used for:

[0178] Determine the sharing terminal of the target account, where the sharing terminal is used to indicate the device that shares the target account to the account user;

[0179] When the sharing terminal is the account holder, the first device public key of the account holder and the device private key of the account user are obtained.

[0180] In one embodiment, the account user terminal 800 is specifically used for:

[0181] When the sharing terminal is not the account holding terminal, obtain the second device public key of the sharing terminal and the device private key of the account using terminal;

[0182] Determine a second common key according to the second device public key and the device private key, and decrypt the first ciphertext information according to the second common key to obtain a second encrypted login private key of the target account;

[0183] Obtaining a first random number generated by the account holding terminal according to the login private key identifier, and obtaining a second random number generated by the sharing terminal according to the login private key identifier;

[0184] The second encrypted login private key is decrypted according to the first random number and the second random number to obtain the login private key, and the target account is logged in at the account user end according to the login private key.

[0185] In one embodiment, the account user terminal 800 is specifically used for:

[0186] When a sharing operation for a target account is detected, determining a target terminal specified by the sharing operation, and generating a third random number;

[0187] Encrypting the first encrypted login private key according to the third random number to obtain a third encrypted login private key;

[0188] Obtaining a second device public key of the target terminal, and determining a third common key based on the second device public key and the device private key;

[0189] The third encrypted login private key is encrypted according to the third common key to obtain the second ciphertext information, and the second ciphertext information, the target account and the login private key identifier are sent to the target terminal.

[0190] In one embodiment, the account user terminal 800 is specifically used for:

[0191] Setting second valid time period information for the third encrypted login private key;

[0192] The second ciphertext information, the target account number, the second valid time period information and the login private key identifier are sent to the target terminal.

[0193] In one embodiment, the account user terminal 800 is specifically used for:

[0194] Receiving a first login request of a target account sent by a target terminal, and obtaining a login private key identifier according to the first login request;

[0195] Obtaining a third random number according to the login private key identifier, and generating a second login request for the target terminal to log in to the target account according to the login private key identifier;

[0196] Sending a second login request to the account holder, and receiving a first random number fed back by the account holder based on the second login request;

[0197] The first random number and the third random number are sent to the target terminal, so that the target terminal can obtain a login private key to log in to the target account based on the first random number and the third random number.

[0198] In one embodiment, the account user terminal 800 is specifically used for:

[0199] Generate a target login request for the target account according to the login private key identifier, and send the target login request to the account holder;

[0200] A first random number fed back by the account holder based on the target login request is received.

[0201] In one embodiment, the account user terminal 800 is specifically used for:

[0202] The login interface sent by the authentication server is displayed, wherein the account holder cancels the account user's permission to log in to the target account, and the authentication server sends the login interface to the account user to enable the account user to log out of the target account.

[0203] The account user end in the embodiment of the present application may be an electronic device, or a component in the electronic device, such as an integrated circuit or a chip. The electronic device may be a terminal, or may be other devices other than a terminal. Exemplarily, the electronic device may be a mobile phone, a tablet computer, a laptop computer, a PDA, a vehicle-mounted electronic device, a mobile Internet device (Mobile Internet Device, MID), an augmented reality (augmented reality, AR) / virtual reality (virtual reality, VR) device, a robot, a wearable device, an ultra-mobile personal computer (ultra-mobile personal computer, UMPC), a netbook or a personal digital assistant (personal digital assistant, PDA), etc. It may also be a server, a network attached storage (Network Attached Storage, NAS), a personal computer (personal computer, PC), a television (television, TV), a teller machine or a self-service machine, etc., which is not specifically limited in the embodiment of the present application.

[0204] The account user terminal in the embodiment of the present application may be a device having an operating system. The operating system may be an Android operating system, an iOS operating system, or other possible operating systems, which are not specifically limited in the embodiment of the present application.

[0205] The account user terminal provided in the embodiment of the present application can achieve Figure 2-6 The various processes implemented in the method embodiment achieve the same technical effect and will not be described again here to avoid repetition.

[0206] Based on the same inventive concept, the present application also provides an account holding terminal. Figure 8 The account holding end provided in the embodiment of the present application is described in detail.

[0207] Fig. 9 It is a structural block diagram of an account holding terminal according to an exemplary embodiment.

[0208] like Fig. 9 As shown, 900 may be an electronic device for logging into an account, and the account holding terminal 900 may include:

[0209] The determination module 910 is used to determine the account user end specified by the sharing operation and generate a random number when a sharing operation is detected for the target account in the account holding end;

[0210] The fourth acquisition module 920 is used to obtain the login private key of the target account in the account holding terminal and the login private key identifier corresponding to the login private key, and encrypt the login private key according to the random number to obtain an encrypted login private key;

[0211] A fifth acquisition module 930 is used to acquire a device public key of the account user and a device private key of the account holder, and determine a target common key according to the device public key and the device private key;

[0212] The encryption module 940 is used to encrypt the encrypted login private key according to the target common key to obtain ciphertext information, and send the ciphertext information, the target account and the login private key identifier to the account user.

[0213] In one embodiment, the account holder 900 is specifically used for:

[0214] Set the valid time period information for the encrypted login private key;

[0215] The ciphertext information, target account, valid time period information and login private key identifier are sent to the account user.

[0216] In one embodiment, the account holder 900 is specifically used for:

[0217] Receive a target login request from a target account sent by the account user;

[0218] Obtain the login private key identifier according to the target login request, and obtain the random number of the login private key corresponding to the encrypted login private key identifier;

[0219] Send the random number to the account holder.

[0220] In one embodiment, the account holder 900 is specifically used for:

[0221] When a permission cancellation operation is detected for the target account logged in by the account user, a logout instruction of the target account is sent to the authentication server, so that the authentication server can send a login interface to the account user based on the logout instruction. The login interface is used to instruct the account user to log out of the target account.

[0222] The account holder in the embodiment of the present application may be an electronic device or a component in the electronic device, such as an integrated circuit or a chip. The electronic device may be a terminal or other devices other than a terminal. Exemplarily, the electronic device may be a mobile phone, a tablet computer, a laptop computer, a PDA, a vehicle-mounted electronic device, a mobile Internet device (Mobile Internet Device, MID), an augmented reality (augmented reality, AR) / virtual reality (virtual reality, VR) device, a robot, a wearable device, an ultra-mobile personal computer (ultra-mobile personal computer, UMPC), a netbook or a personal digital assistant (personal digital assistant, PDA), etc. It may also be a server, a network attached storage (Network Attached Storage, NAS), a personal computer (personal computer, PC), a television (television, TV), a teller machine or a self-service machine, etc., which is not specifically limited in the embodiment of the present application.

[0223] The account holder in the embodiment of the present application may be a device with an operating system. The operating system may be an Android operating system, an iOS operating system, or other possible operating systems, which are not specifically limited in the embodiment of the present application.

[0224] The account holder provided in the embodiment of the present application can achieve Figure 7 The various processes implemented in the method embodiment achieve the same technical effect and will not be described again here to avoid repetition.

[0225] In some embodiments, Fig.10As shown, an embodiment of the present application further provides an electronic device 1000, including a processor 1001 and a memory 1002, wherein the memory 1002 stores programs or instructions that can be executed on the processor 1001, and when the program or instructions are executed by the processor 1001, the various steps of the above-mentioned account sharing method embodiment are implemented, and the same technical effect can be achieved. To avoid repetition, they are not described here.

[0226] It should be noted that the electronic devices in the embodiments of the present application include the above-mentioned mobile electronic devices and non-mobile electronic devices.

[0227] Fig.11 A schematic diagram of the hardware structure of an electronic device to implement an embodiment of the present application.

[0228] The electronic device 1100 includes but is not limited to: a radio frequency unit 1101, a network module 1102, an audio output unit 1103, an input unit 1104, a sensor 1105, a display unit 1106, a user input unit 1107, an interface unit 1108, a memory 1109, and a processor 1110 and other components.

[0229] Those skilled in the art will appreciate that the electronic device 1100 may also include a power source (such as a battery) for supplying power to each component, and the power source may be logically connected to the processor 1110 through a power management system, thereby implementing functions such as managing charging, discharging, and power consumption management through the power management system. Fig.11 The electronic device structure shown in the figure does not constitute a limitation on the electronic device, and the electronic device may include more or fewer components than shown in the figure, or combine certain components, or arrange components differently, which will not be described in detail here. The processor 1110 is used to implement the steps in any of the above embodiments.

[0230] It should be understood that in the embodiment of the present application, the input unit 1004 may include a graphics processor (Graphics Processing Unit, GPU) 10041 and a microphone 10042, and the graphics processor 10041 processes the image data of the static picture or video obtained by the image capture device (such as a camera) in the video capture mode or the image capture mode. The display unit 1106 may include a display panel 11061, and the display panel 11061 may be configured in the form of a liquid crystal display, an organic light emitting diode, etc. The user input unit 1107 includes a touch panel 11071 and at least one of other input devices 11072. The touch panel 11071 is also called a touch screen. The touch panel 11071 may include two parts: a touch detection device and a touch controller. Other input devices 11072 may include, but are not limited to, a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, and a joystick, which will not be repeated here.

[0231] The memory 1109 can be used to store software programs and various data. The memory 1109 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data, wherein the first storage area may store an operating system, an application program or instructions required for at least one function (such as a sound playback function, an image playback function, etc.), etc. In addition, the memory 1109 may include a volatile memory or a non-volatile memory, or the memory 1109 may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDRSDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a synchronous link dynamic random access memory (SLDRAM) and a direct memory bus random access memory (DRRAM). The memory 808 in the embodiment of the present application includes but is not limited to these and any other suitable types of memory.

[0232] The processor 1110 may include one or more processing units; in some embodiments, the processor 1110 integrates an application processor and a modem processor, wherein the application processor mainly processes operations related to an operating system, a user interface, and application programs, and the modem processor mainly processes wireless communication signals, such as a baseband processor. It is understandable that the modem processor may not be integrated into the processor 1110.

[0233] An embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, each process of the above-mentioned account sharing method embodiment is implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0234] The processor is the processor in the electronic device in the above embodiment. The readable storage medium includes a computer readable storage medium, such as a computer read-only memory, a random access memory, a magnetic disk or an optical disk.

[0235] An embodiment of the present application further provides a chip, which includes a processor and a communication interface, wherein the communication interface and the processor are coupled, and the processor is used to run programs or instructions to implement the various processes of the above-mentioned account sharing method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0236] It should be understood that the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.

[0237] An embodiment of the present application provides a computer program product, which is stored in a storage medium. The program product is executed by at least one processor to implement the various processes of the above-mentioned account sharing method embodiment and can achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0238] It should be noted that, in this article, the terms "comprise", "include" or any other variant thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise one..." do not exclude the presence of other identical elements in the process, method, article or device including the element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in reverse order according to the functions involved, for example, the described method may be performed in an order different from that described, and various steps may also be added, omitted, or combined. In addition, the features described with reference to certain examples may be combined in other examples.

[0239] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a computer software product, which is stored in a storage medium (such as ROM / RAM, a disk, or an optical disk), and includes a number of instructions for a terminal (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods of each embodiment of the present application.

[0240] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of the present application, ordinary technicians in this field can also make many forms without departing from the purpose of the present application and the scope of protection of the claims, all of which are within the protection of the present application.

Claims

1. An account sharing method, characterized in that: include: When the account user detects a login operation for a target account shared by the account holder, the account user obtains the first ciphertext information shared by the account holder and a login private key identifier corresponding to the first ciphertext information, where the login private key identifier is used to indicate an identifier of a login private key of the target account; The account user obtains the first device public key of the account holder and the device private key of the account user, and determines a first common key according to the first device public key and the device private key; The account user obtains a first random number according to the login private key identifier, and decrypts the first ciphertext information according to the first common key to obtain a first encrypted login private key of the target account, wherein the first encrypted login private key is obtained by the account holder encrypting the login private key based on the first random number; The account user decrypts the first encrypted login private key according to the first random number to obtain the login private key, and logs in to the target account according to the login private key.

2. The method according to claim 1, characterized in that: Before the account user obtains the first ciphertext information shared by the account holder, the method further includes: Receiving the first ciphertext information, the login private key identifier and the target account sent by the account holder, and constructing a sharing list according to the login private key identifier and the target account; storing the sharing list in association with the first ciphertext information; The obtaining of the first ciphertext information shared by the account holder and the login private key identifier corresponding to the first ciphertext information includes: According to the target account, the login private key identifier is obtained from the sharing list, and the first ciphertext information associated with the sharing list is obtained.

3. The method according to claim 2, characterized in that The receiving the first ciphertext information, the login private key identifier and the target account sent by the account holder, and constructing a sharing list according to the login private key identifier and the target account, includes: Receiving the first ciphertext information, the login private key identifier, the target account, and the first valid time period information of the first ciphertext information sent by the account holder; Constructing a sharing list according to the login private key identifier, the target account and the first valid time period information; The acquiring the login private key identifier from the sharing list according to the target account includes: According to the target account, obtaining the first valid time period information from the sharing list; When the current time point is within the first valid time period information, the login private key identifier is obtained from the sharing list.

4. The method according to claim 3, characterized in that After acquiring the first valid time period information from the sharing list according to the target account, the method further includes: When the current time point exceeds the first valid time period information, a prompt message indicating that the target account has expired is output.

5. The method according to claim 1, characterized in that The account user obtains the first device public key of the account holder and the device private key of the account user, including: Determine a sharing terminal of the target account, where the sharing terminal is used to indicate a device that shares the target account to a user of the account; In the case that the sharing terminal is the account holding terminal, a first device public key of the account holding terminal and a device private key of the account using terminal are obtained.

6. The method according to claim 5, characterized in that After determining the sharing terminal of the target account, the method further includes: In the case where the sharing terminal is not the account holding terminal, obtaining a second device public key of the sharing terminal and a device private key of the account using terminal; Determine a second common key according to the second device public key and the device private key, and decrypt the first ciphertext information according to the second common key to obtain a second encrypted login private key of the target account; Acquire a first random number generated by the account holding terminal according to the login private key identifier, and acquire a second random number generated by the sharing terminal according to the login private key identifier; The second encrypted login private key is decrypted according to the first random number and the second random number to obtain the login private key, and the target account is logged in at the account user end according to the login private key.

7. The method according to claim 1, characterized in that After the account user end decrypts the first ciphertext information according to the first common key to obtain the first encrypted login private key of the target account, the method further includes: In case a sharing operation for the target account is detected, determining a target terminal specified by the sharing operation, and generating a third random number; Encrypting the first encrypted login private key according to the third random number to obtain a third encrypted login private key; Acquire a second device public key of the target terminal, and determine a third common key according to the second device public key and the device private key; The third encrypted login private key is encrypted according to the third common key to obtain second ciphertext information, and the second ciphertext information, the target account and the login private key identifier are sent to the target terminal.

8. The method according to claim 7, characterized in that The sending the second ciphertext information, the target account, and the login private key identifier to the target terminal includes: Setting second valid time period information for the third encrypted login private key; The second ciphertext information, the target account, the second valid time period information and the login private key identifier are sent to the target terminal.

9. The method according to claim 7, characterized in that: After sending the second ciphertext information, the target account and the login private key identifier to the target terminal, the method further includes: Receiving a first login request of the target account sent by the target terminal, and acquiring the login private key identifier according to the first login request; Acquire a third random number according to the login private key identifier, and generate a second login request for the target terminal to log in to the target account according to the login private key identifier; Sending the second login request to the account holder, and receiving the first random number fed back by the account holder based on the second login request; The first random number and the third random number are sent to the target terminal, so that the target terminal obtains the login private key to log in to the target account based on the first random number and the third random number.

10. The method according to claim 1, characterized in that The obtaining a first random number according to the login private key identifier includes: Generate a target login request for the target account according to the login private key identifier, and send the target login request to the account holder; Receive a first random number fed back by the account holder based on the target login request.

11. The method according to any one of claims 1 to 10, after logging into the target account at the account user end using the login private key, further comprising: The login interface sent by the authentication service end is displayed, wherein the account holder cancels the permission of the account user end to log in to the target account, and the authentication service end sends the login interface to the account user end to make the account user end log out of the target account.

12. An account sharing method, characterized in that: include: When the account holder detects a sharing operation for a target account in the account holder, the account holder determines the account user designated by the sharing operation and generates a random number; The account holder obtains the login private key of the target account in the account holder and the login private key identifier corresponding to the login private key, and encrypts the login private key according to the random number to obtain an encrypted login private key; The account holder obtains the device public key of the account user and the device private key of the account holder, and determines the target common key according to the device public key and the device private key; The account holder encrypts the encrypted login private key according to the target common key to obtain ciphertext information, and sends the ciphertext information, the target account number and the login private key identifier to the account user.

13. The method according to claim 12, characterized in that The sending the ciphertext information, the target account, and the login private key identifier to the account user terminal includes: Setting valid time period information for the encrypted login private key; The ciphertext information, the target account, the valid time period information and the login private key identifier are sent to the account user.

14. The method according to claim 12, characterized in that After sending the ciphertext information, the target account and the login private key identifier to the account user, the method further includes: Receiving a target login request of the target account sent by the account user; Obtaining a login private key identifier according to the target login request, and obtaining a random number for encrypting a login private key corresponding to the login private key identifier; The random number is sent to the account holder.

15. The method according to any one of claims 12 to 14, characterized in that: After sending the ciphertext information, the target account and the login private key identifier to the account user, the method further includes: When a permission cancellation operation for the account user to log in to the target account is detected, a logout instruction of the target account is sent to the authentication server, so that the authentication server sends a login interface to the account user based on the logout instruction, and the login interface is used to instruct the account user to log out of the target account.

16. An account user terminal, characterized in that: include: A first acquisition module is used to acquire, when a login operation for a target account shared by an account holder is detected, first ciphertext information shared by the account holder and a login private key identifier corresponding to the first ciphertext information, wherein the login private key identifier is used to indicate an identifier of a login private key of the target account; A second acquisition module is used to acquire a first device public key of the account holding end and a device private key of the account using end, and determine a first common key according to the first device public key and the device private key; A third acquisition module is used to obtain a first random number according to the login private key identifier, and decrypt the first ciphertext information according to the first common key to obtain a first encrypted login private key of the target account, where the first encrypted login private key is obtained by the account holder encrypting the login private key based on the first random number; A decryption module is used to decrypt the first encrypted login private key according to the random number to obtain the login private key, and log in to the target account at the account user end according to the login private key.

17. An account holding terminal, characterized in that: include: A determination module, configured to, when a sharing operation is detected for a target account in the account holding terminal, determine the account using terminal specified by the sharing operation and generate a random number; A fourth acquisition module, used to acquire the login private key of the target account in the account holding terminal and the login private key identifier corresponding to the login private key, and encrypt the login private key according to the random number to obtain an encrypted login private key; A fifth acquisition module, used to acquire a device public key of the account user and a device private key of the account holder, and determine a target common key according to the device public key and the device private key; The encryption module is used to encrypt the encrypted login private key according to the target common key to obtain ciphertext information, and send the ciphertext information, the target account and the login private key identifier to the account user.

18. An electronic device, characterized in that: It includes a processor and a memory, the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, the steps of the account sharing method according to any one of claims 1 to 15 are implemented.

19. A readable storage medium, characterized in that: The readable storage medium stores a program or instruction, and when the program or instruction is executed by the processor, the steps of the account sharing method according to any one of claims 1 to 15 are implemented.

20. A computer program product, characterized in that The program product is stored in a storage medium, and the program product is executed by at least one processor to implement the steps of the account sharing method according to any one of claims 1 to 15.

Citation Information

Patent Citations

  • Data processing method and device based on blockchain, storage medium and equipment

    CN111476572A

  • Data protection method and electronic equipment

    CN117195276A

  • Image based shared secret proxy for secure password entry

    US20080320310A1