Account association authentication method and device, equipment and storage medium
By sending messages of random numbers and signature verification codes between different brands of devices, the associated authentication of system accounts is realized, and the problem of low efficiency of account association authentication in the prior art is solved, and efficiency and reliability are improved.
Patent Information
- Application Number
- CN202510186627.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-19
- Publication Date
- 2025-05-27
AI Technical Summary
In the prior art, the system account association authentication between devices of different brands is relatively low, and the respective associated cloud servers are required to conduct cloud-cloud docking.
By sending messages of random numbers and signature verification codes between the first device and the second device, the associated authentication of the system account is realized without the need for docking of each corresponding server.
This improves the efficiency of account association authentication, and since this method is two-way, it increases the reliability of account association authentication.
Smart Images

Figure CN120050033A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of device interconnection technology, and in particular, to an account association authentication method, apparatus, device, and storage medium. Background Art
[0002] In order to achieve reliable cross-device data transmission, it is often necessary to perform association authentication on system accounts logged in on different devices. In related technologies, if different devices belong to different brands, the association authentication of system accounts on different devices usually requires cloud-to-cloud docking by cloud servers associated with the devices respectively, resulting in low efficiency of account association authentication. Summary of the Invention
[0003] This application provides an account association authentication method, apparatus, device, and storage medium, which improves the efficiency of account association authentication.
[0004] In a first aspect of an embodiment of this application, an account association authentication method is provided. The method is applied to a first device, the first device is communicatively connected to a second device, a first system account of the first device is associated with a first user identifier, and a second system account of the second device is associated with a second user identifier. The method includes:
[0005] Sending a first message to the second device, the first message including a first random number and a first message verification code, where the first message verification code is obtained by signing the first user identifier based on the first random number;
[0006] Receiving a second message sent by the second device when the first message verification code and a second message verification code match, where the second message verification code is obtained by signing the second user identifier based on the first random number, and where the second message includes a second random number and a third message verification code, and the third message verification code is obtained by signing the second user identifier based on the second random number;
[0007] Comparing the third message verification code and a fourth message verification code to determine whether the first system account and the second system account are successfully associated and authenticated, where the fourth message verification code is obtained by signing the first user identifier based on the second random number.
[0008] In a second aspect of an embodiment of this application, an account association authentication method is provided. The method is applied to a second device, the second device is communicatively connected to a first device, a first system account of the first device is associated with a first user identifier, and a second system account of the second device is associated with a second user identifier. The method includes:
[0009] Receive a first message sent by the first device, where the first message includes a first random number and a first message verification code, and the first message verification code is obtained by signing the first user identifier based on the first random number;
[0010] When the first message verification code matches the second message verification code, send a second message to the first device, so that the first device compares a fourth message verification code and a third message verification code to determine whether the association authentication between the first system account and the second system account is successful. The second message includes a second random number and the third message verification code. The second message verification code is obtained by signing the second user identifier based on the first random number. The third message verification code is obtained by signing the second user identifier based on the second random number. The fourth message verification code is obtained by signing the first user identifier based on the second random number.
[0011] A third aspect of the embodiments of this application provides an account association authentication device, which is applied to a first device. The first device is communicatively connected to a second device. The first system account of the first device is associated with a first user identifier, and the second system account of the second device is associated with a second user identifier. The device includes:
[0012] A first message sending unit, configured to send a first message to a second device. The first message includes a first random number and a first message verification code, and the first message verification code is obtained by signing the first user identifier based on the first random number;
[0013] A first message receiving unit, configured to receive a second message sent by the second device when the first message verification code and the second message verification code match. The second message verification code is obtained by signing the second user identifier based on the first random number. The second message includes a second random number and a third message verification code, and the third message verification code is obtained by signing the second user identifier based on the second random number;
[0014] An association authentication unit, configured to compare the third message verification code and the fourth message verification code to determine whether the association authentication between the first system account and the second system account is successful. The fourth message verification code is obtained by signing the first user identifier based on the second random number.
[0015] A fourth aspect of the embodiments of this application provides an account association authentication device, which is applied to a second device. The second device is communicatively connected to a first device. The first system account of the first device is associated with a first user identifier, and the second system account of the second device is associated with a second user identifier. The device includes:
[0016] A second message receiving unit, configured to receive a first message sent by the first device, where the first message includes a first random number and a first message verification code, and the first message verification code is obtained by signing the first user identifier based on the first random number;
[0017] A second message sending unit, configured to send a second message to the first device when the first message verification code matches a second message verification code, so that the first device compares a fourth message verification code and a third message verification code to determine whether the first system account and the second system account are successfully associated and authenticated. The second message includes a second random number and the third message verification code. The second message verification code is obtained by signing the second user identifier based on the first random number. The third message verification code is obtained by signing the second user identifier based on the second random number. The fourth message verification code is obtained by signing the first user identifier based on the second random number.
[0018] A fifth aspect of the embodiments of the present application provides an electronic device,
[0019] A memory storing executable program code;
[0020] And a processor coupled to the memory;
[0021] The processor calls the executable program code stored in the memory, and when the executable program code is executed by the processor, the processor is caused to implement the method disclosed in the first aspect or the second aspect of the embodiments of the present application.
[0022] A sixth aspect of the embodiments of the present application provides a computer-readable storage medium, on which executable program code is stored, and when the executable program code is executed by a processor, the method disclosed in the first aspect or the second aspect of the embodiments of the present application is implemented.
[0023] A seventh aspect of the embodiments of the present application discloses a computer program product, and when the computer program product runs on a computer, the computer is caused to execute the method disclosed in the first aspect or the second aspect of the embodiments of the present application.
[0024] An eighth aspect of the embodiments of the present application discloses an application publishing platform, which is used to publish a computer program product, where when the computer program product runs on a computer, the computer is caused to execute the method disclosed in the first aspect or the second aspect of the embodiments of the present application.
[0025] From the above technical solutions, it can be seen that the embodiments of the present application have at least the following advantages:
[0026] Send a first message to a second device, where the first message includes a first random number and a first message authentication code, and the first message authentication code is obtained by signing a first user identifier based on the first random number; and, receive a second message sent by the second device when the first message authentication code and a second message authentication code match, where the second message authentication code is obtained by signing a second user identifier based on the first random number, and the second message includes a second random number and a third message authentication code, and the third message authentication code is obtained by signing the second user identifier based on the second random number; and, compare the third message authentication code and a fourth message authentication code to determine whether the association authentication between a first system account and a second system account is successful, where the fourth message authentication code is obtained by signing the first user identifier based on the second random number.
[0027] By implementing this method, the first device and the second device can achieve the association authentication of system accounts by mutually determining whether the user identifiers associated with their system accounts are consistent, without the need for their respective corresponding servers to be docked, which can effectively improve the efficiency of account association authentication. In addition, since the association authentication of the system accounts shown in this method is two-way, the reliability of account association authentication is higher. Description of the Drawings
[0028] Figure 1 is a scenario diagram of the account association authentication method disclosed in an embodiment of the present application;
[0029] Figure 2 is a flowchart of the account association authentication method disclosed in an embodiment of the present application;
[0030] Figure 3 is a system architecture diagram of the account association authentication method disclosed in an embodiment of the present application;
[0031] Figure 4 is a flowchart of a process for the first device and the second device to construct a session secret key disclosed in an embodiment of the present application;
[0032] Figure 5 is a flowchart of a process for associating and authenticating a target user account and a first system account disclosed in an embodiment of the present application;
[0033] Figure 6 is an architecture diagram of a first device disclosed in an embodiment of the present application;
[0034] Figure 7 is a structural diagram of an account association authentication device disclosed in an embodiment of the present application;
[0035] Figure 8 is another structural diagram of an account association authentication device disclosed in an embodiment of the present application;
[0036] Figure 9 It is a structural diagram of a first device disclosed in an embodiment of the present application;
[0037] Figure 10 It is a structural diagram of a second device disclosed in an embodiment of the present application. Detailed implementation manners
[0038] The present application provides an account association authentication method, device, equipment and storage medium, which can improve the efficiency of account association authentication.
[0039] In order to enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all should belong to the scope protected by the present application.
[0040] It should be noted that in the present application, words such as "exemplarily" or "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as "exemplarily" or "for example" in the present application should not be interpreted as being more preferred or having more advantages than other embodiments or design solutions. Exactly speaking, using words such as "exemplarily" or "for example" is intended to present relevant concepts in a specific manner.
[0041] "At least one" means one or more, and "multiple" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone, where A and B may be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after. "At least one (item)" or its similar expression below refers to any combination of these items, including any combination of single item (item) or plural items (items). For example, at least one (item) of a, b and c may represent: a, or b, or c, or a and b, or a and c, or b and c, or a, b and c, where a, b and c may be single or multiple.
[0042] Please refer to Figure 1 , Figure 1 It is a scenario diagram of the account association authentication method disclosed in the embodiment of the present application. As Figure 1The scene diagram shown includes a first device 10 and a second device 20. A first system account is logged in on the first device 10, and a second system account is logged in on the second device 20. The first device 10 and the second device are communicatively connected, and the communication connection method may include, but is not limited to, a Classic Bluetooth (BT) connection, a Bluetooth Low Energy (BLE) connection, or a Wireless Fidelity (WiFi) connection.
[0043] In order to enable reliable data transmission between the first device 10 and the second device 20, it is usually necessary to perform associated authentication on the first system account and the second system account. In the related art, if the first device 10 and the second device 20 belong to different brands, the associated authentication of the first system account and the second system account often requires cloud-to-cloud docking of the cloud servers associated with the first device 10 and the second device 20 respectively, resulting in low efficiency of account associated authentication.
[0044] To solve this problem, the embodiments of the present application disclose an account associated authentication method, apparatus, device, and storage medium, which can improve the efficiency of account associated authentication.
[0045] The account associated authentication method disclosed in the embodiments of the present application may include: the first device 10 sends a first message including a first random number and a first message verification code to the second device 20. The first message verification code is obtained by signing the first user identifier based on the first random number. When the second device 20 receives the first message, it compares the first message verification code with a second message verification code to determine whether the associated authentication of the first system account and the second system account is successful. When the first message verification code and the second message verification code match, the second device 20 sends a second message including a second random number and a third message verification code to the first device 10. The second message verification code is obtained by signing the second user identifier based on the first random number, and the third message verification code is obtained by signing the second user identifier based on the second random number. The first device 10 compares the third message verification code with a fourth message verification code to determine whether the associated authentication of the first system account and the second system account is successful. The fourth message verification code is obtained by signing the first user identifier based on the second random number. It can be seen that the first device 10 and the second device 20 can achieve the associated authentication of the system account by mutually determining whether the user identifiers associated with the system accounts of each other are consistent, without the need for docking of their respective corresponding servers, which can effectively improve the efficiency of account associated authentication. In addition, since the associated authentication of the system account shown in this method is two-way, the reliability of account associated authentication is higher.
[0046] In the embodiments of the present application, the first device 10 may be a mobile terminal (such as a mobile phone, a smart watch, etc.), and the second device 20 may be a vehicle-mounted computer, a tablet computer, a notebook computer, a television, etc. The embodiments of the present application do not make any limitations in this regard.
[0047] Please refer to Figure 2 , Figure 2 which is a flowchart of an account association authentication method disclosed in the embodiments of the present application. As Figure 2 shown, the account association method may include the following steps:
[0048] 201. The first device signs the first user identifier based on the first random number to obtain a first message authentication code.
[0049] It can be understood that the first random number is a random number generated by a random number generator on the first device. The first user identifier may be information used to identify the user's identity, which may be a mobile phone number or an ID card number, etc. The embodiments of the present application do not make any limitations in this regard. In the following embodiments, the first user identifier is mainly described by taking the mobile phone number as an example, and the first user identifier is denoted as the first mobile phone number in the following embodiments.
[0050] The first device signing the first user identifier based on the first random number may mean that the first device signs the first user identifier based on the first random number according to a preset signature algorithm. Among them, the preset signature algorithm is a signature algorithm for the user identifier negotiated in advance between the first device and the second device. The preset signature algorithm may include, but is not limited to, at least one of the following: ECDSA, Schnorr, HmacSha1, HmacSha256, HmacSha512, SHA256, RS256, RSASSA-PSS, ECDSA, Ed25519, BLS, etc.
[0051] Exemplarily, the preset signature algorithm is a combination of HmacSha256 and SHA256. The process of signing the first mobile phone number may be: first, calculate the hash value of the first random number using SHA256 to obtain a hash value of a fixed length, and then use this hash value as the secret key of the HmacSha256 algorithm to sign the first mobile phone number to obtain the first message authentication code. The signature message of the first message authentication code may be "HmacSha256(SHA256(first random number), first mobile phone number)".
[0052] The first user identifier may be obtained by the first device from the account management server corresponding to the first device, or may be obtained by the first device from the account management application running on the first device. The embodiments of the present application do not make any limitations in this regard.
[0053] 202. The first device sends a first message to the second device, and the first message includes a first random number and a first message verification code.
[0054] When the first device is BT / BLE connected to the second device, the first device can send the first message to the second device through the Bluetooth module.
[0055] When the first device is WiFi connected to the second device, the first device can send the first message to the second device through the WiFi module.
[0056] It can be understood that the message format of the first message is "first random number + first message verification code".
[0057] 203. The second device signs the second user identifier based on the first random number to obtain a second message verification code, and compares the first message verification code with the second message verification code.
[0058] It should be noted that for the introduction of the second user identifier, reference can be made to the above description of the first user identifier, which will not be elaborated here.
[0059] In the following embodiments, the second user identifier can be recorded as the second mobile phone number. When the second device receives the first message, it can sign the second mobile phone number based on the first random number in the first message according to a preset signature algorithm to obtain a second message verification code. Exemplarily, the signature message of the second message verification code can be "HmacSha256(SHA256(first random number), second mobile phone number)".
[0060] The second user identifier can be obtained by the second device from the account management server corresponding to the second device, or can be obtained by the second device from the account management application running on the second device. The embodiments of the present application do not make limitations.
[0061] It should be noted that in the case where the signature method and the random number are the same, if the first mobile phone number is the same as the second mobile phone number, the second message verification code and the second message verification code are the same. Therefore, by comparing whether the second message verification code and the second message verification code are the same, the second device can determine whether the first mobile phone number is the same as the second mobile phone number. If they are the same, the second device considers that the users of the first device and the second device are the same user, and the associated authentication of the first system account and the second system account is successful.
[0062] 204. When the first message verification code and the second message verification code match, the second device signs the second user identifier based on the second random number to obtain a third message verification code.
[0063] Among them, the second random number can be a random number generated by a random number generator on the second device. The second device signs the second user identifier based on the second random number to obtain a third message authentication code. It can be that the second device signs the second mobile phone number based on the second random number according to a preset signature algorithm to obtain the third message authentication code, or the second device signs the second mobile phone number based on the first random number and the second random number according to a preset signature algorithm.
[0064] Exemplarily, the signature message of the third message authentication code can be "HmacSha256(SHA256(second random number), second mobile phone number)", or "HmacSha256(SHA256(first random number || second random number), second mobile phone number)".
[0065] In the embodiment of the present application, when the second device confirms that the first message authentication code and the second message authentication code match, the association authentication between the first system account and the second system account is successful. The signature message of the third message authentication code may further include characters indicating the successful association authentication between the first system account and the second system account, such as "OK", "True", etc.
[0066] Exemplarily, the signature message of the third authentication code can also be "HmacSha256(SHA256(first random number || second random number), second mobile phone number || OK)".
[0067] 205. The second device sends a second message to the first device, and the second message includes the second random number and the third message authentication code.
[0068] Exemplarily, the message format of the second message can be "second random number + third message authentication code", or "second random number + OK + third message authentication code".
[0069] 206. The first device signs the first user identifier based on the second random number to obtain a fourth message authentication code, and compares the third message authentication code and the fourth message authentication code to determine whether the association authentication between the first system account and the second system account is successful.
[0070] It can be understood that when the third message authentication code is obtained by the second device signing the second mobile phone number based on the second random number according to a preset signature algorithm, the first device signs the first mobile phone number based on the second random number according to the preset signature algorithm to obtain the fourth message authentication code. When the third message authentication code is obtained by the second device signing the second mobile phone number based on the first random number and the second random number according to the preset signature algorithm, the first device signs the first mobile phone number based on the second random number and the second random number according to the preset signature algorithm to obtain the fourth message authentication code.
[0071] It should be noted that when the signature method and the random number are the same, if the first mobile phone number is the same as the second mobile phone number, the third message authentication code and the fourth message authentication code are the same. Therefore, by comparing whether the fourth message authentication code and the fourth message authentication code are the same, the first device can determine whether the first mobile phone number and the second mobile phone number are the same. If they are the same, the first device considers that the users of the first device and the second device are the same user, and the association authentication of the first system account and the second system account is successful.
[0072] In the embodiment of the present application, the first device includes a first interconnection management module, and the second device includes a second interconnection management module. The first device transmits service data to the second interconnection management module of the second device through the first interconnection management module, and the second device transmits service data to the first interconnection management module of the first device through the second interconnection management module.
[0073] It should be noted that in the embodiment of the present application, the first device is the initiator of the interconnection, and the second device is the receiver of the interconnection. When the second device determines that both the first device and the second device consider the association authentication of the first system account and the second system account to be successful, the second device interconnects the first interconnection management module and the second interconnection management module. The specific connection process can be: when the third message authentication code and the fourth message authentication code match, the first device sends a third message to the second device to indicate that the third message authentication code and the fourth message authentication code match. When the second device receives this third message, it can know that the authentication on the first device side is successful. At this time, the second device interconnects the first interconnection management module and the second interconnection management module.
[0074] It should be noted that when the communication connection between the first device and the second device is in the BLE mode, based on the connection method of account association authentication, there is no need for manual intervention by the user, realizing a completely seamless connection.
[0075] Since the successful account association authentication means that the users of the first device and the second device are the same user, the connection established by the first interconnection management module and the second interconnection management module based on this can allow the first device and the second device to transmit the first service data to each other. The first service data may include service data with a privacy level higher than the preset level, that is, private data can be transmitted between the first device and the second device. For example, when the first device is a mobile phone and the second device is a car infotainment system, the mobile phone can send data such as schedules, meetings, express deliveries, takeaways, and trips to the car infotainment system, and the car infotainment system can send data such as in-vehicle camera data and in-vehicle voice data to the mobile phone.
[0076] In addition, it should be noted that in the case where the association authentication of the first system account and the second system account fails (the second device determines that the first message verification code and the second message verification code do not match, or the first device determines that the third message verification code and the fourth message verification code do not match), the first interconnection management module and the second interconnection management module can also be interconnected based on the connection code. The interconnection process based on the connection code can be: the first device sends the first connection code input by the user to the second device, and the second device compares the first connection code with the preset connection code in the second device, and when the first connection code and the preset connection code match, interconnects the first interconnection management module and the second interconnection management module.
[0077] It can be understood that when the first device determines that the third message verification code and the fourth message verification code do not match, it can output a connection code input interface for the user to input the connection code. When the second device determines that the first message verification code and the second message verification code do not match, the first device can output a connection code input interface when it receives the fourth message sent by the second device indicating that the first message verification code and the second message verification code do not match.
[0078] Since the connection established based on the connection code cannot guarantee that the users of the first device and the second device are the same person, the connection established by the first interconnection management module and the second interconnection management module based on this can allow the first device and the second device to transmit the second service data to each other. The second service data can be service data with a privacy level lower than the preset level, that is, non-private data is transmitted between the first device and the second device. For example, when the first device is a mobile phone and the second device is a car infotainment system, the mobile phone can send the status information of the mobile phone (such as battery power, system version, etc.), multimedia data, vehicle control-related data, etc. to the car infotainment system, and the car infotainment system can send the driving data of the vehicle (including vehicle speed, driving mileage, fuel consumption, etc.), road condition information, etc. to the mobile phone.
[0079] Exemplarily, the system architecture diagram of the account association authentication method can be referred to as follows Figure 3 . Such as Figure 3The system architecture diagram shown includes a first device and a second device. Among them, the first device includes a first interconnection management module and a first account management application. The first interconnection management module may include a first account association authentication module and a first secure transmission gateway. The first account association authentication module may include an authentication sub-module A and an authentication sub-module B; the second device includes a second interconnection management module and a second account management application. The second interconnection management module includes a second account association authentication module and a second secure transmission gateway. The second account association authentication module may include an authentication sub-module C and an authentication sub-module D.
[0080] The following combines Figure 3 the system architecture diagram shown to describe the process of account association authentication for the first device and the second device:
[0081] The authentication sub-module A obtains the first mobile phone number from the first account management application and sends it to the authentication sub-module B. The authentication sub-module B signs the first mobile phone number based on the first random number to obtain the first message verification code and sends it to the first secure transmission gateway. Then, the first secure transmission gateway sends the first message including the first random number and the first message verification code to the second secure transmission gateway. When the second secure transmission gateway receives the first message, it notifies the authentication sub-module C to obtain the second mobile phone number from the second account management application. After the authentication sub-module C obtains the second mobile phone number, it sends the second mobile phone number to the authentication sub-module D. The authentication sub-module D signs the second mobile phone number using the first random number to obtain the second message verification code and compares the first message verification code and the second message verification code. It can be understood that this part describes the process of account association authentication for the second device.
[0082] When the authentication sub-module D determines that the first message verification code and the second message verification code match, it signs the second mobile phone number based on the second random number to obtain the third message verification code and sends the second random number and the third message verification code to the second secure transmission gateway. The second secure transmission gateway sends the second message including the second random number and the third message verification code to the first secure transmission gateway. When the first secure transmission gateway receives the second message, it sends the second random number and the third message verification code to the authentication sub-module B. The authentication sub-module B signs the first mobile phone number based on the second random number to obtain the fourth message verification code and compares the third message verification code and the fourth message verification code. It can be understood that this part describes the process of account association authentication for the first device.
[0083] By implementing Figure 2In the method shown, the first device and the second device can implement the associated authentication of system accounts by mutually determining whether the user identifiers associated with their respective system accounts are the same, without the need for the corresponding servers of each to be docked, which can effectively improve the efficiency of account associated authentication. In addition, since the associated authentication of the system accounts shown in this method is two-way, the reliability of account associated authentication is higher.
[0084] In some embodiments, the above-mentioned third message may include a first public key. It can be understood that the second device can inform the first device that the account associated authentication on its side has passed by sending the first public key to the first device. In this way, the first device can also directly construct a session secret key based on the first public key. The following embodiments will be combined Figure 4 to introduce the process of the first device and the second device constructing the session secret key.
[0085] 401. When the third message verification code and the fourth message verification code match, the first device sends the first public key to the second device.
[0086] Among them, the first public key may be the ECDH public key of the first interconnection management module.
[0087] In the embodiments of the present application, in order to prevent the ECDH public key of the first interconnection management module from being tampered with or forged, the way for the first device to send the first public key to the second device may be to sign the concatenation of the first public key and the fifth random number based on the ECDSA private key of the first interconnection management module to obtain a first signature, and send the seventh message including the first public key, the fifth random number, and the first signature to the second device.
[0088] Exemplarily, the message corresponding to the first signature may be "ecdsa_sig(r, R'||the fifth random number)", where r is the ECDSA private key of the first interconnection management module, R' is the ECDH public key of the first interconnection management module, and the message format of the corresponding seventh message is "R'+the fifth random number+the first signature".
[0089] The second device receiving the first public key may refer to the second device receiving the seventh message, parsing the first public key and the fifth random number from the seventh message, and verifying the first signature according to the ECDSA public key of the first interconnection management module. If the first signature verification passes, the second device considers that the parsed first public key has not been tampered with and can be directly used to construct the first session secret key on the second device side.
[0090] In the embodiments of the present application, the ECDSA public key of the first interconnection management module may be pre-sent by the first device to the second device, or may be sent to the second device together with the ECDH public key of the first interconnection management module. The embodiments of the present application do not make any limitations.
[0091] When the ECDSA public key of the first interconnection management module is pre - sent to the second device, the ECDSA public key of the first interconnection management module can be carried in the above - mentioned first message. The first message authentication code in the first message can be obtained by signing the concatenation of the first mobile phone number and the ECDH public key of the first interconnection management module using the first random number. Exemplarily, the signature message of the first message authentication code can be "HmacSha256(SHA256(first random number), first mobile phone number||R)", where R is the ECDSA public key of the first interconnection management module. Further, the message format of the first message is "R + first random number + first message authentication code".
[0092] When the ECDSA public key of the first interconnection management module is sent to the second device together with the ECDH public key of the first interconnection management module, the seventh message can further include the ECDSA public key of the first interconnection management module and the message authentication code corresponding to the ECDSA public key of the first interconnection management module.
[0093] Exemplarily, the signature message of the message authentication code corresponding to the ECDSA public key of the first interconnection management module can be "HmacSha256(SHA256(fifth random number), R)", and the corresponding message format of the seventh message can be "R + R' + fifth random number + message authentication code corresponding to the ECDSA public key of the first interconnection management module + first signature".
[0094] 402. The second device interconnects the second interconnection management module with the first interconnection management module.
[0095] 403. The second device constructs a first session key based on the first public key.
[0096] It can be understood that the second device constructs the first session key based on the first public key and the ECDH private key of the second interconnection management module.
[0097] 404. The second device sends the second public key to the first device.
[0098] Among them, the second public key can be the ECDH public key of the second interconnection management module.
[0099] In the embodiments of the present application, in order to prevent the ECDH public key of the second interconnection management module from being tampered with or forged, the way for the second device to send the second public key to the first device can be to sign the concatenation of the second public key, the first public key, the fifth random number, and the sixth random number based on the ECDSA private key of the second interconnection management module to obtain the second signature, and send the eighth message including the second public key, the sixth random number, and the second signature to the first device.
[0100] Exemplarily, the message corresponding to the second signature can also be "ecdsa_sig(t, T'||R'||the sixth random number||the fifth random number)", where t is the ECDSA private key of the second interconnection management module, and T' is the ECDH public key of the second interconnection management module. The message format of the corresponding eighth message can be "T'+the sixth random number+the second signature".
[0101] It can be understood that the first device receiving the second public key means that the first device receives the eighth message, parses the second public key and the sixth random number from the eighth message, and verifies the second signature according to the ECDSA public key of the second interconnection management module. If the second signature verification passes, the first device considers that the parsed second public key has not been tampered with and can be directly used to construct the second session key on the first device side.
[0102] In the embodiments of the present application, the ECDSA public key of the second interconnection management module can be pre-sent by the second device to the first device, or can be sent to the first device together with the ECDH public key of the second interconnection management module. The embodiments of the present application do not make any limitations.
[0103] In the case where the ECDSA public key of the second interconnection management module is pre-sent to the first device, the ECDSA public key of the second interconnection management module can be carried in the above-mentioned second message. Exemplarily, the signature message of the third message verification code in the second message can be "HmacSha256(SHA256(the first random number||the second random number), OK||the second mobile phone number||T||R)", where T is the ECDSA public key of the second interconnection management module, and R is the ECDSA public key of the first interconnection management module. Further, the message format of the second message is "T+the second random number+OK+the third message verification code".
[0104] In the case where the ECDSA public key of the second interconnection management module is sent to the second device together with the ECDH public key of the second interconnection management module, the eighth message can further include the ECDSA public key of the second interconnection management module and the message verification code corresponding to the public key of the ECDSA of the second interconnection management module.
[0105] Exemplarily, the signature message of the message verification code corresponding to the public key of the ECDSA of the second interconnection management module can be "HmacSha256(SHA256(the sixth random number||the fifth random number), T||R)". Correspondingly, the message format of the eighth message can be "T+T'+the sixth random number+the message verification code corresponding to the public key of the ECDSA of the second interconnection management module+the second signature".
[0106] 405. The first device constructs a second session key based on the second public key.
[0107] It is understandable that the second device constructs a first session key based on the first public key and the ECDH private key of the first interconnection management module.
[0108] 406. The first device transmits first service data to the second device based on the second session key.
[0109] It is understandable that the first device encrypts its own service data based on the second session key, sends the encrypted service data to the second device, and decrypts the service data sent by the second device received based on the second session key.
[0110] 407. The second device transmits first service data to the first device based on the first session key.
[0111] It is understandable that the second device encrypts its own service data based on the first session key, sends the encrypted service data to the first device, and decrypts the service data sent by the first device received based on the first session key.
[0112] It should be noted that the exchange of the ECDH public keys of the first device and the second device is also implemented based on the secure transmission gateways of their respective interconnection management modules.
[0113] By implementing Figure 4 the method shown, after the first interconnection management module and the second interconnection management module establish an interconnection, the first device and the second device can also construct a session key to encrypt and decrypt for subsequent secure data transmission, further improving the security of data transmission.
[0114] In some embodiments, the first device may further include a third-party management application for managing the second device. A target user account is logged in to the third-party management application, and the target user account is associated with a third user identifier. Before the first device sends a first message to the second device, it may also perform account association authentication on the target user account and the first system account. The process of the first device performing association authentication on the target user account and the first system account can refer to the following Figure 5 .
[0115] The following combines examples to explain the reason for the first device to perform association authentication on the target user account and the first system account before sending a first message to the second device:
[0116] In the case where the first device is a mobile phone and the second device is a vehicle computer, the third-party management application can be a vehicle management application installed on the mobile phone, which is a comprehensive service platform developed by the vehicle brand, and its main functions include vehicle control, information query, community interaction, service reservation, etc. Usually, the target user account is associated with the mobile phone number of the car owner, but because the target user account can authorize other non-car owners to log in remotely on their devices, the first device can determine whether the target user account is logged in on the non-car owner's device by associating and authenticating the target user account and the first system account. Specifically, if the target user account and the first system account association authentication fail, it means that the target user account is logged in on the non-car owner's device and the first device is the non-car owner's device. If the target user account and the first system account association authentication pass, it means that the target user account is logged in on the car owner's device and the first device is the car owner's device.
[0117] It should be noted that, in the case where the first device is the device of the car owner, the first system account of the first device and the second system account of the second device can most likely be associated and authenticated to achieve a seamless connection between the first interconnection management module and the second interconnection management module, but in the case where the first device is not the device of the car owner, the first system account of the first device and the second system account of the second device must not be able to be associated and authenticated successfully. Based on this, the first device does not need to initiate an operation to associate and authenticate the first system account with the second system account, and the connection between the first interconnection management module and the second interconnection management module is achieved based on the connection code entered by the user on the first device.
[0118] See also Figure 5 , Figure 5 It is a flowchart illustrating that the first device disclosed in the embodiment of the present application performs association authentication on the target user account and the first system account.
[0119] 501. A first interconnection management module signs a first user identifier based on a third random number to obtain a fifth message verification code.
[0120] 502. The first interconnection management module sends a fifth message including a third random number and a fifth message verification code to the third-party management application.
[0121] In an embodiment of the present application, before sending the fifth message to the third-party management application, the first interconnection module can search for the package name of the third-party management application in the corresponding cloud server or preset database based on the target device information of the second device (for example, the vendor identification code and the product identification code), and then send the fifth message to the third-party management application based on the package name.
[0122] Optionally, the way for the first interconnection management module to send a message to the third-party management application may be the Inter-Process Communication (IPC) method, which may include, but is not limited to, pipes, message queues, or sockets, etc.
[0123] 503. The third-party management application signs the third user identifier based on the third random number to obtain the sixth message authentication code.
[0124] 504. The third-party management application compares the fifth message authentication code with the sixth message authentication code.
[0125] 505. When the fifth message authentication code and the sixth message authentication code match, the third-party management application signs the third user identifier based on the fourth random number to obtain the seventh message authentication code.
[0126] It can be understood that when the fifth message authentication code and the sixth message authentication code do not match, the association between the first system account and the target user account fails.
[0127] 506. The third-party management application sends a sixth message including the fourth random number and the seventh message authentication code to the first interconnection management module.
[0128] 507. The first interconnection management module signs the first user identifier based on the fourth random number to obtain the eighth message authentication code.
[0129] 508. The first interconnection management module compares the seventh message authentication code with the eighth message authentication code to determine whether the association authentication between the first system account and the target user account is successful.
[0130] It can be understood that when the seventh message authentication code and the eighth message authentication code match, the association authentication between the first system account and the target user account is successful; otherwise, the association authentication between the first system account and the target user account fails.
[0131] Optionally, when the association authentication between the first system account and the target user account fails, the first device may also output a connection code input interface.
[0132] It should be noted that for the operation of the first interconnection management module and the third-party management application to perform account association authentication, reference can be made to the operation of the first device and the second device to perform account association authentication in the above embodiments, which will not be elaborated here.
[0133] In some embodiments, the first account association authentication module of the first interconnection management module may further include an authentication sub-module E, and the third-party management application includes an authentication sub-module F, as Figure 6 shown in the architecture diagram of the first device.
[0134] The following combines Figure 6 the architecture diagram of the first device shown in the figure to illustrate the process of associating and authenticating a target user account and a first system account: The authentication sub-module E obtains the first mobile phone number from the authentication sub-module A, signs the first mobile phone number based on the third random number to obtain the fifth message verification code, and sends the fifth message including the third random number and the fifth message verification code to the third-party management application. The authentication sub-module F of the third-party management application first signs the third mobile phone number based on the third random number to obtain the sixth message verification code, compares the sixth message verification code and the fifth message verification code, and when the sixth message verification code and the fifth message verification code match, signs the third user identifier based on the fourth random number to obtain the seventh message verification code, and sends the sixth message including the fourth random number and the seventh message verification code to the first interconnection management module. When the first interconnection management module receives the sixth message, it hands it over to the authentication sub-module B for processing. The authentication sub-module B signs the first user identifier based on the fourth random number to obtain the eighth message verification code, and compares the seventh message verification code and the eighth message verification code to determine whether the association authentication between the first system account and the target user account is successful.
[0135] Please refer to Figure 7 , Figure 7 which is a structural diagram of the account association authentication device disclosed in the embodiments of the present application. As Figure 7 shown, the account association authentication device is applied to the first device, the first device is communicatively connected to the second device, the first system account of the first device is associated with the first user identifier, and the second system account of the second device is associated with the second user identifier. As Figure 7 shown, the account association authentication device may include a first message sending unit 701, a first message receiving unit 702, and an association authentication unit 703, where:
[0136] The first message sending unit 701 is configured to send a first message to the second device, the first message includes a first random number and a first message verification code, and the first message verification code is obtained by signing the first user identifier based on the first random number;
[0137] The first message receiving unit 702 is configured to receive a second message sent by the second device when the first message verification code and the second message verification code match, the second message verification code is obtained by signing the second user identifier based on the first random number, where the second message includes a second random number and a third message verification code, and the third message verification code is obtained by signing the second user identifier based on the second random number;
[0138] An association authentication unit 703, configured to compare the third message authentication code and the fourth message authentication code to determine whether the association authentication between the first system account and the second system account is successful, where the fourth message authentication code is obtained by signing the first user identifier based on the second random number.
[0139] In some embodiments, the first device includes a first interconnection management module, and the second device includes a second interconnection management module. The first device transmits service data to the second interconnection management module of the second device through the first interconnection management module. The first message sending unit 701 is further configured to send a third message to the second device when the third message authentication code and the fourth message authentication code match, where the third message is used to indicate that the third message authentication code and the fourth message authentication code match, so that the second device interconnects the second interconnection management module and the first interconnection management module when receiving the third message.
[0140] In some embodiments, the third message includes a first public key, and the first public key is used to construct a session secret key for transmitting service data.
[0141] In some embodiments, as Figure 7 shown, the account association authentication device may further include a data processing unit, configured to transmit first service data to the second device when the second interconnection management module and the first interconnection management module are interconnected, where the first service data includes service data with a privacy level higher than a preset level.
[0142] In some embodiments, the first device includes a first interconnection management module, and the second device includes a second interconnection management module. The first device transmits service data to the second interconnection management module of the second device through the first interconnection management module. As Figure 7 shown, the account association authentication device may further include a display unit, configured to output a connection code input interface when the third message authentication code and the fourth message authentication code do not match, where the connection code input interface is used for a user to input a connection code to interconnect the first interconnection management module and the second interconnection management module;
[0143] Or,
[0144] configured to output a connection code input interface when receiving a fourth message sent by the second device indicating that the first message authentication code and the second message authentication code do not match, where the connection code input interface is used for a user to input a connection code to interconnect the first interconnection management module and the second interconnection management module.
[0145] In some embodiments, the first message receiving unit 702 is further configured to send a first connection code input by the user in the connection code input interface to the second device, so that when the second device determines that the first connection code matches a preset connection code in the second device, the first interconnection management module is interconnected with the second interconnection management module.
[0146] In some embodiments, the data processing unit is further configured to, when the first interconnection management module is interconnected with the second interconnection management module, perform transmission of second service data with the second device, where the second service data is service data with a privacy level lower than a preset level.
[0147] In some embodiments, the first device includes a first interconnection management module and a third-party management application for managing the second device. A target user account is logged in to the third-party management application, and the target user account is associated with a third user identifier. Before sending the first message to the second device, the first message sending unit 701 is further configured to send a fifth message to the third-party management application through the first interconnection management module, where the fifth message includes a third random number and a fifth message verification code, and the fifth message verification code is obtained by signing the first user identifier based on the third random number;
[0148] The association authentication unit 703 is further configured to determine, through the third-party management application, that the fifth message verification code matches the sixth message verification code;
[0149] The first message sending unit 701 is further configured to send a sixth message to the first interconnection management module. The sixth message verification code is obtained by signing the third user identifier based on the third random number. The sixth message includes a fourth random number and a seventh message verification code, and the seventh message verification code is obtained by signing the third user identifier based on the fourth random number;
[0150] The association authentication unit 703 is further configured to compare, through the first interconnection management module, the seventh message verification code with the eighth message verification code to determine whether the association authentication between the first system account and the target user account is successful. The eighth message verification code is obtained by signing the first user identifier based on the fourth random number.
[0151] In some embodiments, the first user identifier includes a first mobile phone number, and the second user identifier includes a second mobile phone number.
[0152] Please refer to Figure 8 , Figure 8 which is another structural diagram of the account association authentication device disclosed in the embodiments of the present application. As Figure 8The described account association authentication device is applied to the second device, which is communicatively connected to the first device. The first system account of the first device is associated with a first user identifier, and the second system account of the second device is associated with a second user identifier. As Figure 8 The described account association authentication device may include: a second message receiving unit 801 and a second message sending unit 802; where
[0153] The second message receiving unit 801 is configured to receive a first message sent by the first device. The first message includes a first random number and a first message verification code, and the first message verification code is obtained by signing the first user identifier based on the first random number.
[0154] The second message sending unit 802 is configured to, when the first message verification code matches the second message verification code, send a second message to the first device, so that the first device compares a fourth message verification code and a third message verification code to determine whether the association authentication between the first system account and the second system account is successful. The second message includes a second random number and the third message verification code. The second message verification code is obtained by signing the second user identifier based on the first random number. The third message verification code is obtained by signing the second user identifier based on the second random number. The fourth message verification code is obtained by signing the first user identifier based on the second random number.
[0155] In some embodiments, the first device includes a first interconnection management module, and the second device includes a second interconnection management module. The second device transmits service data to the interconnection management module of the first device through the second interconnection management module. The second message receiving unit 801 is further configured to receive a third message sent by the first device when the third message verification code and the fourth message verification code match. The third message is used to indicate that the third message verification code and the fourth message verification code match.
[0156] Wherein, as Figure 8 The described account association authentication device may further include an interconnection unit, which is configured to interconnect the second interconnection management module and the first interconnection management module.
[0157] In some embodiments, the third message includes a first public key, and the first public key is used to construct a session secret key for transmitting service data.
[0158] In some embodiments, as Figure 8The described account association authentication device may further include a data processing unit, which is configured to transmit first service data with the first device when the first interconnection management module is interconnected with the second interconnection management module, and the first service data includes service data with a privacy level higher than a preset level.
[0159] In some embodiments, the first device includes a first interconnection management module, the second device includes a second interconnection management module, the first device transmits service data with the second interconnection management module of the second device through the first interconnection management module. The second message sending unit 802 is further configured to send a fourth message indicating that the first message verification code and the second message verification code do not match to the first device when the first message verification code and the second message verification code do not match, so that when the first device receives the fourth message, it outputs a connection code input interface, and the connection code input interface is used for the user to input a connection code to interconnect the first interconnection management module and the second interconnection management module.
[0160] In some embodiments, the second message receiving unit 801 is further configured to receive a first connection code sent by the first device, and the first connection code is a connection code input by the user on the connection code input interface; Figure 8 The described account association authentication device may further include an association authentication unit, which is configured to compare the first connection code with a preset connection code in the second device; the interconnection unit is further configured to interconnect the first interconnection management module and the second interconnection management module when the first connection code matches the preset connection code.
[0161] In some embodiments, when the first interconnection management module is interconnected with the second interconnection management module, the data processing unit is further configured to transmit second service data with the first device, and the second service data is service data with a privacy level lower than the preset level.
[0162] In some embodiments, the first user identifier includes a first mobile phone number, and the second user identifier includes a second mobile phone number.
[0163] Please refer to Figure 9 , Figure 9 which is a structural diagram of the first device disclosed in the embodiments of the present application. As Figure 9 shown, the first device may include components such as a processor 901, a memory 902, a display unit 903, an input unit 904, a sensor 905, and an audio circuit 906.
[0164] Among them, the processor 901 is the control center of the first device, connecting various parts of the entire first device through various interfaces and lines. By running or executing software programs and / or modules stored in the memory 902, and calling the data stored in the memory 902, it executes various functions of the first device and processes data, thereby monitoring the first device as a whole. Optionally, the processor 901 may include one or more processing units; optionally, the processor 901 may integrate an application processor, which mainly processes operating devices, user interfaces, application programs, etc. Of course, other processors may also be included, which will not be listed one by one here.
[0165] The memory 902 can be used to store software programs and modules. The processor 901 executes various functional applications and data processing of the first device by running the software programs and modules stored in the memory 902. The memory 902 may mainly include a program storage area and a data storage area. Among them, the program storage area may store operating devices, application programs required for at least one function (such as sound playback function, image playback function, etc.); the data storage area may store data created according to the use of the first device (such as audio data, phone book, etc.). In addition, the memory 902 may include high-speed random access memory, and may also include non-volatile memory, such as at least one magnetic disk storage device, flash memory device, or other volatile solid-state storage devices.
[0166] The display unit 903 can be used to display information input by the user or information provided to the user, as well as various menus of the first device. The display unit 903 may include a display panel. Optionally, the display panel may be configured in the form of a liquid crystal display (LCD), an organic light-emitting diode (OLED), etc. Further, the touch panel may cover the display panel. When the touch panel detects a touch operation on or near it, it transmits it to the processor 901 to determine the type of touch event. Subsequently, the processor 901 provides a corresponding visual output on the display panel according to the type of touch event. Among them, the touch panel and the display panel are not Figure 9 shown above. The touch panel and the display panel can be implemented as two independent components to realize the input and input functions of the first device, or the touch panel and the display panel can be integrated to realize the input and output functions of the first device.
[0167] The input unit 904 can be used to receive input digital or character information, and generate key signal inputs related to the user settings and function controls of the first device. Specifically, the input unit 904 can include a touch panel and other input devices. The touch panel, also known as a touch screen, can collect touch operations of the user on or near it (such as operations of the user using any suitable object or accessory such as a finger, a stylus, etc. on or near the touch panel), and drive the corresponding connection device according to a pre-set program. In addition, various types such as resistive, capacitive, infrared, and surface acoustic wave can be used to implement the touch panel. In addition to the touch panel, the input unit 904 can also include other input devices. Specifically, the other input devices can include, but are not limited to, one or more of function keys (such as volume control buttons, switch buttons, etc.), trackballs, joysticks, etc.
[0168] The first device may further include at least one sensor 905, such as a magnetometer, a gyroscope sensor, a motion sensor, and other sensors. Specifically, the magnetometer is used to determine the orientation of the first device, and the gyroscope sensor can be used to determine the motion posture of the first device, can be used for anti-shake shooting, and can also be used for navigation and somatosensory game scenarios. As a kind of motion sensor, the acceleration sensor can detect the magnitude of acceleration in all directions, and can detect the magnitude and direction of gravity when stationary, and can be used for applications that identify the posture of the first device, such as horizontal and vertical screen switching, related games, and magnetometer posture calibration, etc.; as for other sensors such as a pressure gauge, a barometer, a hygrometer, a thermometer, an infrared sensor, etc. that the first device can also be configured with, they will not be elaborated here.
[0169] The audio circuit 906 can include a speaker and a microphone, and can provide an audio interface between the user and the first device. The audio circuit 906 can transmit the electrical signal after converting the received audio data to the speaker, and the speaker converts it into a sound signal for output; on the other hand, the microphone converts the collected sound signal into an electrical signal, which is received by the audio circuit 906 and then converted into audio data, and then the audio data is output to the processor 901 for processing, and then sent to another device such as via the video circuit, or the audio data is output to the memory 902 for further processing.
[0170] Although not shown, the first device may further include a power supply and a camera. Optionally, the position of the camera on the first device can be front-facing or rear-facing, and the embodiments of the present application do not limit this.
[0171] It can be understood that the structure schematically shown in the embodiments of the present application does not constitute a specific limitation on the first device. In other embodiments of the present application, the first device may include more or fewer components than shown, or combine certain components, or split certain components, or have different component arrangements. The illustrated components can be implemented in hardware, software, or a combination of software and hardware.
[0172] In an embodiment of the present application, the first device is communicatively connected to the second device. The first system account of the first device is associated with a first user identifier, and the second system account of the second device is associated with a second user identifier. The processor 901 further has the following functions:
[0173] Send a first message to the second device, the first message including a first random number and a first message verification code, where the first message verification code is obtained by signing the first user identifier based on the first random number;
[0174] Receive a second message sent by the second device when the first message verification code and a second message verification code match, where the second message verification code is obtained by signing the second user identifier based on the first random number. Wherein, the second message includes a second random number and a third message verification code, and the third message verification code is obtained by signing the second user identifier based on the second random number;
[0175] Compare the third message verification code and a fourth message verification code to determine whether the association authentication between the first system account and the second system account is successful, where the fourth message verification code is obtained by signing the first user identifier based on the second random number.
[0176] In an embodiment of the present application, the first device includes a first interconnection management module, and the second device includes a second interconnection management module. The first device transmits service data to the second interconnection management module of the second device through the first interconnection management module. The processor 901 further has the following functions:
[0177] When the third message verification code and the fourth message verification code match, send a third message to the second device, where the third message is used to indicate that the third message verification code and the fourth message verification code match, so that when the second device receives the third message, it interconnects the second interconnection management module and the first interconnection management module.
[0178] In an embodiment of the present application, the third message includes a first public key, and the first public key is used to construct a session secret key for transmitting service data.
[0179] In an embodiment of the present application, when the second interconnection management module and the first interconnection management module are interconnected, the processor 901 further has the following functions:
[0180] Transmit first service data with the second device, where the first service data includes service data with a privacy level higher than a preset level.
[0181] In an embodiment of the present application, the first device includes a first interconnection management module, and the second device includes a second interconnection management module. The first device transmits service data to the second interconnection management module of the second device through the first interconnection management module. The processor 901 further has the following functions:
[0182] In the case where the third message authentication code and the fourth message authentication code do not match, output a connection code input interface for a user to input a connection code to interconnect the first interconnection management module and the second interconnection management module;
[0183] Or,
[0184] In the case of receiving a fourth message sent by the second device indicating that the first message authentication code and the second message authentication code do not match, output a connection code input interface for a user to input a connection code to interconnect the first interconnection management module and the second interconnection management module.
[0185] In an embodiment of the present application, the processor 901 further has the following functions:
[0186] Send a first connection code input by the user on the connection code input interface to the second device, so that when the second device determines that the first connection code matches a preset connection code in the second device, interconnect the first interconnection management module and the second interconnection management module.
[0187] In an embodiment of the present application, when the first interconnection management module and the second interconnection management module are interconnected, the processor 901 further has the following functions:
[0188] Transmit second service data with the second device, where the second service data is service data with a privacy level lower than a preset level.
[0189] In an embodiment of the present application, the first device includes a first interconnection management module and a third-party management application for managing the second device. A target user account is logged in to the third-party management application, and the target user account is associated with a third user identifier. Before sending the first message to the second device, the processor 901 further has the following functions:
[0190] Send a fifth message to the third-party management application through the first interconnection management module. The fifth message includes a third random number and a fifth message authentication code, and the fifth message authentication code is obtained by signing the first user identifier based on the third random number;
[0191] The third-party management application determines that the fifth message verification code and the sixth message verification code match, and sends a sixth message to the first interconnection management module. The sixth message verification code is obtained by signing the third user identifier based on the third random number. The sixth message includes a fourth random number and a seventh message verification code. The seventh message verification code is obtained by signing the third user identifier based on the fourth random number.
[0192] The first interconnection management module compares the seventh message verification code with the eighth message verification code to determine whether the association authentication between the first system account and the target user account is successful. The eighth message verification code is obtained by signing the first user identifier based on the fourth random number.
[0193] In the embodiment of the present application, the first user identifier includes a first mobile phone number, and the second user identifier includes a second mobile phone number.
[0194] Please refer to Figure 10 , Figure 10 which is a structural diagram of a second device disclosed in the embodiment of the present application. As Figure 10 shown, the second device may include a processor 1001 and a memory 1002. Among them, for the introduction of the processor 1001 and the memory 1002, reference may be made to the introduction of the processor 901 and the memory 902 of the first device above, which will not be elaborated here.
[0195] In the embodiment of the present application, the second device is communicatively connected to the first device. The first system account of the first device is associated with the first user identifier, and the second system account of the second device is associated with the second user identifier. The processor 1001 further has the following functions:
[0196] Receiving a first message sent by the first device. The first message includes a first random number and a first message verification code. The first message verification code is obtained by signing the first user identifier based on the first random number.
[0197] When the first message verification code matches the second message verification code, sending a second message to the first device, so that the first device compares the fourth message verification code and the third message verification code to determine whether the association authentication between the first system account and the second system account is successful. The second message includes a second random number and the third message verification code. The second message verification code is obtained by signing the second user identifier based on the first random number. The third message verification code is obtained by signing the second user identifier based on the second random number. The fourth message verification code is obtained by signing the first user identifier based on the second random number.
[0198] In an embodiment of the present application, the first device includes a first interconnection management module, the second device includes a second interconnection management module, and the second device transmits service data to the interconnection management module of the first device through the second interconnection management module. The processor 1001 further has the following functions:
[0199] Receive a third message sent by the first device when the third message authentication code and the fourth message authentication code match, where the third message is used to indicate that the third message authentication code and the fourth message authentication code match;
[0200] Interconnect the second interconnection management module and the first interconnection management module.
[0201] In an embodiment of the present application, the third message includes a first public key, and the first public key is used to construct a session secret key for transmitting service data.
[0202] In an embodiment of the present application, when the first interconnection management module is interconnected with the second interconnection management module, the processor 1001 further has the following functions:
[0203] Transmit first service data with the first device, where the first service data includes service data with a privacy level higher than a preset level.
[0204] In an embodiment of the present application, the first device includes a first interconnection management module, the second device includes a second interconnection management module, and the first device transmits service data to the second interconnection management module of the second device through the first interconnection management module. The processor 1001 further has the following functions:
[0205] When the first message authentication code and the second message authentication code do not match, send a fourth message to the first device to indicate that the first message authentication code and the second message authentication code do not match, so that when the first device receives the fourth message, it outputs a connection code input interface, and the connection code input interface is used for a user to input a connection code to interconnect the first interconnection management module and the second interconnection management module.
[0206] In an embodiment of the present application, the processor 1001 further has the following functions:
[0207] Receive a first connection code sent by the first device, where the first connection code is a connection code input by the user in the connection code input interface;
[0208] Compare the first connection code with a preset connection code in the second device;
[0209] When the first connection code matches the preset connection code, the first interconnection management module is interconnected with the second interconnection management module.
[0210] In an embodiment of the present application, when the first interconnection management module is interconnected with the second interconnection management module, the processor 1001 further has the following functions:
[0211] Transmit second service data with the first device, where the second service data is service data with a privacy level lower than a preset level.
[0212] In an embodiment of the present application, the first user identifier includes a first mobile phone number, and the second user identifier includes a second mobile phone number.
[0213] An embodiment of the present application discloses a computer-readable storage medium, on which executable program code is stored. When the executable program code is executed by a processor, the method executed by the first device or the second device in the embodiment of the present application is implemented.
[0214] An embodiment of the present application discloses a computer program product. When the computer program product runs on a computer, the computer is enabled to implement the method executed by the first device or the second device in the embodiment of the present application.
[0215] An embodiment of the present application discloses an application publishing platform, which is used to publish a computer program product. When the computer program product runs on a computer, the computer is enabled to implement the method executed by the first device or the second device in the embodiment of the present application.
[0216] It should be noted here that: the descriptions of the above storage medium and device embodiments are similar to the descriptions of the above method embodiments and have beneficial effects similar to those of the method embodiments. For the technical details not disclosed in the storage medium, storage medium and device embodiments of the present application, please refer to the descriptions of the method embodiments of the present application for understanding.
[0217] It should be understood that the "one embodiment" or "an embodiment" or "some embodiments" mentioned throughout the specification means that the specific features, structures or characteristics related to the embodiment are included in at least one embodiment of the present application. Therefore, the "in one embodiment" or "in an embodiment" or "in some embodiments" that appear throughout the specification do not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics can be combined in one or more embodiments in any suitable manner. It should be understood that in various embodiments of the present application, the magnitudes of the serial numbers of the above processes do not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application. The serial numbers of the embodiments of the present application above are only for description and do not represent the advantages or disadvantages of the embodiments. The descriptions of the above embodiments tend to emphasize the differences between the embodiments, and their similarities or similarities can be referred to each other. For the sake of brevity, they will not be repeated herein.
[0218] The term "and / or" in this article is only a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, object A and / or object B can represent: object A exists alone, object A and object B exist simultaneously, and object B exists alone.
[0219] It should be noted that in this article, the term "comprise", "include" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such a process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of another identical element in the process, method, article or device including the element.
[0220] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The above-described embodiments are only illustrative. For example, the division of the modules is only a logical function division, and there can be other division methods in actual implementation. For example, multiple modules or components can be combined, or can be integrated into another system, or some features can be ignored, or not executed. In addition, the coupling, direct coupling, or communication connection between the components shown or discussed with each other can be through some interfaces, and the indirect coupling or communication connection of the devices or modules can be electrical, mechanical or other forms.
[0221] The modules described above as separate components may or may not be physically separated, and the components shown as modules may or may not be physical modules; they may be located in one place or distributed across multiple network elements; some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0222] In addition, in each embodiment of the present application, all the functional modules may be integrated in one processing unit, or each module may be a separate unit alone, or two or more modules may be integrated in one unit; the above integrated modules may be implemented in the form of hardware, or in the form of a combination of hardware and software functional units.
[0223] Those of ordinary skill in the art can understand that all or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions. The foregoing program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps including the above method embodiments; and the foregoing storage medium includes: removable storage devices, read-only memory (ROM), magnetic disks, or optical disks and other various media that can store program codes.
[0224] Alternatively, if the above integrated unit of the present application is implemented in the form of a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the embodiments of the present application, in essence, or the part that contributes to the related art, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing an electronic device to execute all or part of the methods described in various embodiments of the present application. And the foregoing storage medium includes: removable storage devices, ROM, magnetic disks, or optical disks and other various media that can store program codes.
[0225] The methods disclosed in several method embodiments provided in the present application can be arbitrarily combined without conflict to obtain new method embodiments.
[0226] The features disclosed in several product embodiments provided in the present application can be arbitrarily combined without conflict to obtain new product embodiments.
[0227] The features disclosed in several method or device embodiments provided in the present application can be arbitrarily combined without conflict to obtain new method embodiments or device embodiments.
[0228] As described above, it is only the implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed by this application can easily think of changes or substitutions, which should all be covered within the protection scope of this application. Therefore, the protection scope of this application shall be subject to the protection scope of the said claims.
Claims
1. An account association authentication method, characterized in that: The method is applied to a first device, the first device is in communication connection with a second device, a first system account of the first device is associated with a first user identifier, and a second system account of the second device is associated with a second user identifier. The method includes: Sending a first message to a second device, where the first message includes a first random number and a first message verification code, where the first message verification code is obtained by signing the first user identifier based on the first random number; receiving a second message sent by the second device when the first message authentication code and the second message authentication code match, where the second message authentication code is obtained by signing the second user identifier based on the first random number, wherein the second message includes a second random number and a third message authentication code, where the third message authentication code is obtained by signing the second user identifier based on the second random number; The third message verification code and the fourth message verification code are compared to determine whether the first system account and the second system account are successfully associated and authenticated, wherein the fourth message verification code is obtained by signing the first user identifier based on the second random number.
2. The method according to claim 1, characterized in that: The first device includes a first interconnection management module, the second device includes a second interconnection management module, the first device transmits service data with the second interconnection management module of the second device through the first interconnection management module, and the method further includes: When the third message authentication code matches the fourth message authentication code, a third message is sent to the second device, where the third message is used to indicate that the third message authentication code matches the fourth message authentication code, so that the second device interconnects the second interconnection management module with the first interconnection management module when receiving the third message.
3. The method according to claim 2, characterized in that The third message includes a first public key, where the first public key is used to construct a session key for transmitting business data.
4. The method according to claim 2, characterized in that: In a case where the second interconnection management module is interconnected with the first interconnection management module, the method further includes: The first service data is transmitted to the second device, where the first service data includes service data with a privacy level higher than a preset level.
5. The method according to claim 1, characterized in that The first device includes a first interconnection management module, the second device includes a second interconnection management module, the first device transmits service data with the second interconnection management module of the second device through the first interconnection management module, and the method further includes: In the case where the third message verification code and the fourth message verification code do not match, outputting a connection code input interface, wherein the connection code input interface is used for a user to input a connection code to interconnect the first interconnection management module and the second interconnection management module; or, When a fourth message sent by the second device indicating that the first message verification code and the second message verification code do not match is received, a connection code input interface is output, where the connection code input interface is used for a user to input a connection code to interconnect the first interconnection management module and the second interconnection management module.
6. The method according to claim 5, characterized in that The method further comprises: The first connection code input by the user in the connection code input interface is sent to the second device, so that the second device interconnects the first interconnection management module with the second interconnection management module when it is determined that the first connection code matches a preset connection code in the second device.
7. The method according to claim 6, characterized in that In a case where the first interconnection management module is interconnected with the second interconnection management module, the method further includes: The second service data is transmitted to the second device, where the second service data is service data with a privacy level lower than a preset level.
8. The method according to claim 1, characterized in that: The first device includes a first interconnection management module and a third-party management application for managing the second device, a target user account is logged in to the third-party management application, and the target user account is associated with a third user identifier. Before sending the first message to the second device, the method further includes: Sending a fifth message to the third-party management application through the first interconnection management module, wherein the fifth message includes a third random number and a fifth message verification code, and the fifth message verification code is obtained by signing the first user identifier based on the third random number; Determining, by the third-party management application, that the fifth message verification code matches the sixth message verification code, and sending a sixth message to the first interconnection management module, where the sixth message verification code is obtained by signing the third user identifier based on the third random number, and the sixth message includes a fourth random number and a seventh message verification code, where the seventh message verification code is obtained by signing the third user identifier based on the fourth random number; The first interconnection management module compares the seventh message verification code with the eighth message verification code to determine whether the first system account and the target user account are successfully associated and authenticated, wherein the eighth message verification code is obtained by signing the first user identifier based on the fourth random number.
9. The method according to claim 1, characterized in that: The first user identification includes a first mobile phone number, and the second user identification includes a second mobile phone number.
10. An account association authentication method, characterized in that: The method is applied to a second device, the second device is in communication connection with a first device, a first system account of the first device is associated with a first user identifier, and a second system account of the second device is associated with a second user identifier. The method includes: receiving a first message sent by the first device, where the first message includes a first random number and a first message verification code, where the first message verification code is obtained by signing the first user identifier based on the first random number; When the first message verification code matches the second message verification code, a second message is sent to the first device so that the first device compares the fourth message verification code and the third message verification code to determine whether the association authentication of the first system account and the second system account is successful, the second message includes a second random number and the third message verification code, the second message verification code is obtained by signing the second user identifier based on the first random number, the third message verification code is obtained by signing the second user identifier based on the second random number, and the fourth message verification code is obtained by signing the first user identifier based on the second random number.
11. The method according to claim 10, characterized in that The first device includes a first interconnection management module, the second device includes a second interconnection management module, the second device transmits service data with the interconnection management module of the first device through the second interconnection management module, and the method further includes: receiving a third message sent by the first device when the third message authentication code matches the fourth message authentication code, the third message being used to indicate that the third message authentication code matches the fourth message authentication code; The second interconnection management module is interconnected with the first interconnection management module.
12. The method according to claim 11, characterized in that The third message includes a first public key, where the first public key is used to construct a session key for transmitting business data.
13. The method according to claim 11, characterized in that In a case where the first interconnection management module is interconnected with the second interconnection management module, the method further includes: Transmitting first service data with the first device, where the first service data includes service data with a privacy level higher than a preset level.
14. The method according to claim 10, characterized in that The first device includes a first interconnection management module, the second device includes a second interconnection management module, the first device transmits service data with the second interconnection management module of the second device through the first interconnection management module, and the method further includes: In a case where the first message verification code and the second message verification code do not match, a fourth message is sent to the first device to indicate that the first message verification code and the second message verification code do not match, so that the first device outputs a connection code input interface when receiving the fourth message, and the connection code input interface is used for a user to input a connection code to interconnect the first interconnection management module and the second interconnection management module.
15. The method according to claim 14, characterized in that The method further comprises: receiving a first connection code sent by the first device, where the first connection code is a connection code entered by a user on the connection code input interface; Comparing the first connection code with a preset connection code in the second device; When the first connection code matches the preset connection code, the first interconnection management module is interconnected with the second interconnection management module.
16. The method according to claim 15, characterized in that In a case where the first interconnection management module is interconnected with the second interconnection management module, the method further includes: The second service data is transmitted to the first device, where the second service data is service data with a privacy level lower than a preset level.
17. The method according to claim 10, characterized in that The first user identification includes a first mobile phone number, and the second user identification includes a second mobile phone number.
18. An account association authentication device, characterized in that: The apparatus is applied to a first device, the first device is communicatively connected with a second device, a first system account of the first device is associated with a first user identifier, and a second system account of the second device is associated with a second user identifier, and the apparatus includes: A first message sending unit, configured to send a first message to a second device, where the first message includes a first random number and a first message verification code, where the first message verification code is obtained by signing the first user identifier based on the first random number; A first message receiving unit, configured to receive a second message sent by the second device when the first message authentication code and the second message authentication code match, the second message authentication code being obtained by signing the second user identifier based on the first random number, wherein the second message includes a second random number and a third message authentication code, and the third message authentication code being obtained by signing the second user identifier based on the second random number; An association authentication unit is used to compare the third message authentication code and the fourth message authentication code to determine whether the first system account and the second system account are successfully associated and authenticated, and the fourth message authentication code is obtained by signing the first user identifier based on the second random number.
19. An account association authentication device, characterized in that: The apparatus is applied to a second device, the second device is communicatively connected to a first device, a first system account of the first device is associated with a first user identifier, and a second system account of the second device is associated with a second user identifier, and the apparatus includes: A second message receiving unit is configured to receive a first message sent by the first device, where the first message includes a first random number and a first message verification code, where the first message verification code is obtained by signing the first user identifier based on the first random number; A second message sending unit is used to send a second message to the first device when the first message verification code matches the second message verification code, so that the first device compares the fourth message verification code and the third message verification code to determine whether the association authentication of the first system account and the second system account is successful, the second message includes a second random number and the third message verification code, the second message verification code is obtained by signing the second user identifier based on the first random number, the third message verification code is obtained by signing the second user identifier based on the second random number, and the fourth message verification code is obtained by signing the first user identifier based on the second random number.
20. An electronic device, characterized in that: include: A memory storing executable program code; and a processor coupled to the memory; The processor calls the executable program code stored in the memory, and when the executable program code is executed by the processor, the processor implements the method as described in any one of claims 1-9 or 10-17.
21. A computer-readable storage medium having executable program code stored thereon, characterized in that: When the executable program code is executed by a processor, the method described in any one of claims 1-9 or 10-17 is implemented.