Identity authentication method, storage medium and electronic equipment
By deploying a method that utilizes TEE devices to assist identity authentication on non-TEE smart devices, the problem that non-TEE devices cannot obtain security protection is solved, and the security protection of secure SSO services and authentication process is achieved.
Patent Information
- Application Number
- CN202510207018.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2020-05-08
- Publication Date
- 2025-06-20
AI Technical Summary
Non-TEE devices in existing smart devices cannot obtain security protection, resulting in data and accounts being easily tampered with or counterfeit, which in turn causes problems such as user account information leakage and account malicious control.
By deploying an identity authentication method on a non-TEE device, the method assists the user device in identity authentication using a TEE device with a TEE unit. The method includes the IDP determining the TEE device associated with the user device, the user device establishes a communication connection with the TEE device, sending an identity authentication parameter to the IDP, and IDP uses the TEE device to perform identity authentication.
It realizes that non-TEE devices can provide secure SSO services with the help of TEE devices, solves the problem that non-TEE devices cannot obtain security protection, and protects the security of the entire authentication process through the TEE mechanism.
Smart Images

Figure CN120180403A_ABST
Abstract
Description
[0001] This application is a divisional application. The application number of the original application is 202010383065.4, the original application date is May 8, 2020, and the entire content of the original application is incorporated herein by reference. Technical Field
[0002] One or more embodiments of this application generally relate to the field of identity authentication in information security technology, and more particularly to an identity authentication method, a storage medium, and an electronic device. Background Art
[0003] A Trusted Execution Environment (TEE) is a secure area within the main processor. It can run in a relatively independent environment and run in parallel with the main operating system. The confidentiality and integrity of the code and data loaded in the TEE can be protected. By using both hardware and software to protect data and code, this parallel system is more secure than traditional systems (i.e., Rich Execution Environment). Trusted applications running in the TEE can access all the functions of the device's main processor and memory, while protecting these components in the TEE from being affected by user-installed applications running in the main operating system through hardware isolation.
[0004] Currently, the full-scenario services of smart devices have been widely applied globally. In full-scenario services, in order to provide the convenience of user operations, each smart device needs to support users to log in with user accounts and perform corresponding application security authentication, data synchronization, web browsing, message application operations, etc. This requires all smart devices to use TEE chips. Otherwise, problems such as data and accounts being tampered with or counterfeited will occur, leading to the leakage of user account information and the malicious control of user accounts.
[0005] It can be understood that if all smart devices use TEE chips, this will significantly increase the chip complexity and process / R & D costs. In addition, smart devices purchased by users without TEE chips configured before will also pose security risks in the increasingly popular full-scenario services. Summary of the Invention
[0006] Some embodiments of this application provide an identity authentication method, a storage medium, and an electronic device. The following introduces this application from multiple aspects, and the implementation manners and beneficial effects of the following multiple aspects can be referred to each other.
[0007] To address the above scenarios, in a first aspect, an embodiment of the present application provides an identity authentication method for an identity authentication system. The identity authentication system includes a user device without a Trusted Execution Environment (TEE) unit, a TEE device with a TEE unit, and an Identity Provider (IDP). The TEE device will assist the user device in performing identity authentication. The method includes: The IDP determines a TEE device associated with the user device according to an authentication request sent by the user device; after determining the associated TEE device of the user device, the user device establishes a communication connection with the associated TEE device and sends the identity authentication parameters of the user device to the TEE device, and these identity authentication parameters will be used for the identity authentication performed by the IDP; the TEE device sends the identity authentication parameters of the user device to the IDP; the IDP receives the identity authentication parameters of the user device sent by the TEE device and performs the authentication steps of the authentication protocol with the TEE device according to the identity authentication parameters, so as to authenticate the user of the user device.
[0008] As can be seen from the embodiment of the first aspect above, the embodiment of the present application can be deployed on non-TEE electronic devices, enabling non-TEE devices to provide secure Single Sign-On (SSO) services for users with the help of TEE devices such as smartphones, solving the problem that non-TEE devices cannot obtain security protection. And by utilizing the TEE mechanism, the security of the entire authentication process of the user device is protected by the TEE.
[0009] In combination with the first aspect, in some embodiments, the user device is further configured to: send a flag indicating that the user device does not have a TEE unit to the IDP.
[0010] In combination with the first aspect, in some embodiments, determining a TEE device associated with the user device includes: the IDP receives an identity authentication account from the user device and an identity authentication account from the TEE device; the IDP determines that the user device has an associated TEE device when the identity authentication account of the user device is the same as or associated with the identity authentication account from the TEE device.
[0011] In combination with the first aspect, in some embodiments, the identity authentication system further includes an associated device, and the method further includes: the associated device receives an identity authentication account from the user device and a flag at least partially indicating that the user device does not have a TEE unit; the associated device receives an identity authentication account from the TEE device and a flag at least partially indicating that the TEE device has a TEE unit; and the associated device associates the user device with the TEE device for the identity authentication account when it determines that the identity authentication account of the user device is the same as that of the TEE device.
[0012] In connection with the first aspect, in some embodiments, determining a TEE device associated with a user device includes: the IDP sending a request to an associated device to inquire whether the user device has an associated TEE device; and the IDP determining the TEE device associated with the user device according to the response of the associated device.
[0013] In a second aspect, embodiments of the present application provide an identity authentication method for a user device, where the user device does not have a Trusted Execution Environment (TEE) unit. The method includes: establishing a communication connection with a TEE device having a TEE unit, where the TEE device is associated with the user device; and sending identity authentication parameters of the user device to the TEE device, so that after the TEE device sends the identity authentication parameters to an Identity Provider (IDP), the IDP authenticates the user of the user device according to the identity authentication parameters and by using the TEE device.
[0014] As can be seen from the embodiments of the second aspect above, the embodiments of the present application can be deployed on non-TEE electronic devices, enabling non-TEE devices to provide secure SSO services for users with the help of TEE devices such as smart phones, solving the problem that non-TEE devices cannot obtain security protection. Moreover, by using the TEE mechanism, the security of the entire authentication process of the user device is protected by the TEE. And as long as the user device is associated with at least one TEE device, the TEE device can provide a trusted execution environment for various user devices without a trusted execution environment, realizing secure authentication and login of the user device.
[0015] In connection with the second aspect, in some embodiments, it further includes: sending a flag to the IDP that at least partially indicates that the user device does not have a TEE unit; receiving a request from the IDP to confirm whether to use the TEE device for identity authentication; and sending information determining to use the TEE device to authenticate the user of the user device to the IDP.
[0016] In connection with the second aspect, in some embodiments, it further includes: sending an identity authentication account of the user device to the IDP.
[0017] In connection with the second aspect, in some embodiments, it further includes: sending an identity authentication account of the user device and a flag that at least partially indicates that the user device does not have a TEE unit to an associated device.
[0018] In connection with the second aspect, in some embodiments, when the identity authentication account of the user device is the same as or associated with the identity authentication account from the TEE device, the TEE device is associated with the user device.
[0019] In an embodiment of the present application, as long as at least one TEE device is registered under the user's identity authentication account, the TEE device can provide a trusted execution environment for various user devices that do not have a trusted execution environment under the user's identity authentication account, realizing secure login of the user devices.
[0020] In combination with the second aspect, in some embodiments, the identity authentication parameter includes at least one of the device serial number and the device identification number of the user device.
[0021] In combination with the second aspect, in some embodiments, the user device has another identity authentication account, where the other identity authentication account of the user device is the same as the identity authentication account of another TEE device, and the other TEE device has a TEE unit.
[0022] In a third aspect, an embodiment of the present application provides an identity authentication method for a trusted execution environment (TEE) device, where the TEE device has a TEE unit; characterized by including: establishing a communication connection with a user device, where the user device does not have a TEE unit, and where the TEE device is associated with the user device; receiving identity authentication parameters from the user device, where the identity authentication parameters are used for authenticating the user of the user device; and sending the identity authentication parameters to an identity provider (IDP) for the IDP to authenticate the user of the user device based on the identity authentication parameters and using the TEE device.
[0023] It can be seen from the embodiments of the above third aspect that in the embodiments of the present application, as long as the user device is associated with at least one TEE device, the TEE device can provide a trusted execution environment for various user devices that do not have a trusted execution environment, realizing secure authentication and login of the user devices.
[0024] In combination with the third aspect, in some embodiments, establishing a communication connection with the user device includes: receiving a request from the IDP to determine whether the TEE device is online; in response to the request, establishing a communication connection with the user device; and sending information that the TEE device is online to the IDP.
[0025] In combination with the third aspect, in some embodiments, it further includes: sending the identity authentication account of the TEE device, and a mark at least partially indicating that the TEE device has a TEE unit, to an associated device.
[0026] In combination with the third aspect, in some embodiments, it further includes: sending the identity authentication account of the TEE device, and a mark at least partially indicating that the TEE device has a TEE unit, to the IDP.
[0027] In combination with the third aspect, in some embodiments, when the authentication account of the user equipment is the same as or associated with the authentication account from the TEE device, the TEE device is associated with the user equipment.
[0028] In combination with the third aspect, in some embodiments, the authentication parameter includes at least one of the device serial number and the device identification number of the user equipment.
[0029] Fourth aspect, embodiments of the present application provide an identity authentication method for an identity provider (IDP), characterized by including: receiving an authentication request from a user equipment, where the user equipment does not have a trusted execution environment (TEE) unit; in response to the authentication request, determining whether the user equipment has an associated TEE device, where the TEE device has a TEE unit; and at least partially based on the case that the user equipment has an associated TEE device, receiving the identity authentication parameter of the user equipment sent by the TEE device, and authenticating the user of the user equipment according to the identity authentication parameter and using the TEE device.
[0030] It can be seen from the embodiments of the fourth aspect above that in the embodiments of the present application, as long as at least one TEE device is registered under the identity authentication account of the user, this TEE device can provide a trusted execution environment for various other user equipments that do not have a trusted execution environment under the identity authentication account of the user, and realize the secure login of the user equipment.
[0031] In combination with the fourth aspect, in some embodiments, it further includes: receiving information from the user equipment indicating that the user equipment does not have a trusted execution environment (TEE) unit.
[0032] In combination with the fourth aspect, in some embodiments, when determining whether the user equipment has an associated TEE device, it further includes: sending a request to the associated device to inquire whether the user equipment has an associated TEE device.
[0033] In combination with the fourth aspect, in some embodiments, when determining whether the user equipment has an associated TEE device, it further includes: receiving the identity authentication account from the user equipment and the identity authentication account from the TEE device; when the identity authentication account of the user equipment is the same as or associated with the identity authentication account from the TEE device, determining that the user equipment has an associated TEE device; and when the identity authentication account of the user equipment is different from or not associated with the identity authentication account from the TEE device, determining that the user equipment does not have an associated TEE device.
[0034] In combination with the fourth aspect, in some embodiments, it further includes: when the user device has an associated TEE device, sending a request to the TEE device to confirm that the TEE device is online; receiving information from the TEE device confirming that the TEE device is online; and receiving the identity authentication parameters of the user device sent by the TEE device, and authenticating the user of the user device according to the identity authentication parameters.
[0035] In combination with the fourth aspect, in some embodiments, authenticating the user of the user device according to the identity authentication parameters and using the TEE device includes: using the identity authentication parameters to authenticate the user of the user device by interacting with the TEE device based on the encrypted data of the identity authentication parameters.
[0036] In combination with the fourth aspect, in some embodiments, the encrypted data includes: a challenge value encrypted with an encryption key and a credential value encrypted with a verification key, where the encryption key and the verification key are generated based on the identity authentication parameters.
[0037] In combination with the fourth aspect, in some embodiments, the identity authentication parameters include at least one of the device serial number and the device identification number of the user device.
[0038] Fifth aspect, an embodiment of the present application provides an identity authentication method for associated devices, which is characterized by including: receiving identity authentication accounts sent by the user device and the TEE device, where the user device does not have a trusted execution environment (TEE) unit and the TEE device has a TEE unit; establishing an association between the user device and the TEE device according to the received identity authentication account; in response to a request from an identity provider (IDP), determining the TEE device associated with the user device requesting identity authentication, so that the TEE device sends the identity authentication parameters of the user device to the IDP, and the IDP authenticates the user of the user device according to the identity authentication parameters and uses the TEE device.
[0039] It can be seen from the above embodiments of the fifth aspect that in the embodiments of the present application, as long as at least one TEE device is registered under the identity authentication account of the user, the TEE device can provide a trusted execution environment for other various user devices without a trusted execution environment under the identity authentication account of the user, realizing the secure login of the user device.
[0040] In combination with the fifth aspect, in some embodiments, establishing an association between the user device and the TEE device according to the received identity authentication account includes: when it is determined that the identity authentication account of the user device is the same as or associated with the identity authentication account of the TEE device, associating the user device with the TEE device.
[0041] In combination with the fifth aspect, in some embodiments, determining a TEE device associated with a user device requesting identity authentication in response to a request from an Identity Provider (IDP) includes: receiving a request from the Identity Provider (IDP) to query whether the user device is associated with a TEE device; querying that the user device is associated with the TEE device; and returning information indicating the association between the user device and the TEE device to the IDP.
[0042] In a sixth aspect, the present application provides a computer-readable storage medium, which may be non-volatile. The storage medium contains instructions that, when executed, implement the methods described in any of the foregoing aspects or embodiments.
[0043] In a seventh aspect, the present application provides an electronic device, including: a memory for storing instructions executed by one or more processors of the electronic device, and a processor for executing the instructions in the memory to perform the methods described in any of the foregoing aspects or embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Figure 1 A schematic diagram showing an identity authentication system according to an example of an embodiment of the present application.
[0045] Figure 2 An interaction schematic diagram showing an example identity authentication method according to an embodiment of the present application.
[0046] Figure 3 A flowchart showing an identity authentication method according to an embodiment of the present application.
[0047] Figure 4 A flowchart showing another identity authentication method according to an embodiment of the present application.
[0048] Figure 5 A flowchart showing another identity authentication method according to an embodiment of the present application.
[0049] Figure 6 A flowchart showing another identity authentication method according to an embodiment of the present application.
[0050] Figure 7 An interaction schematic diagram showing user device registration according to an embodiment of the present application.
[0051] Figure 8 An interaction schematic diagram showing user device authentication according to an embodiment of the present application.
[0052] Figure 9 A flowchart showing the process of an identity provider providing registration according to an embodiment of the present application.
[0053] Figure 10 Shows a schematic flow diagram of TEE device-assisted registration according to an embodiment of the present application.
[0054] Figure 11 Shows a schematic flow diagram of identity provider-provided authentication according to an embodiment of the present application.
[0055] Figure 12 Shows a schematic flow diagram of TEE device-assisted authentication according to an embodiment of the present application.
[0056] Figure 13 Shows a schematic diagram of an electronic device according to an embodiment of the present application. Detailed implementation manners
[0057] The following specific embodiments illustrate the implementation manners of the present application. Those skilled in the art can easily understand other advantages and effects of the present application from the content disclosed in this specification. Although the description of the present application will be introduced in conjunction with preferred embodiments, this does not mean that the features of this invention are limited to this embodiment. On the contrary, the purpose of introducing the invention in conjunction with the embodiment is to cover other alternatives or modifications that may be extended based on the claims of the present application. In order to provide a deep understanding of the present application, many specific details will be included in the following description. The present application can also be implemented without these details. In addition, in order to avoid confusing or obscuring the key points of the present application, some specific details will be omitted in the description. It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other.
[0058] In addition, various operations will be described as multiple discrete operations in the most helpful way for understanding the illustrative embodiments; however, the described order should not be construed as implying that these operations must depend on the order. In particular, these operations do not need to be performed in the presented order.
[0059] Unless otherwise specified in the context, the terms "comprising", "having", and "including" are synonyms. The phrase "A / B" means "A or B". The phrase "A and / or B" means "(A and B) or (A or B)".
[0060] It should be noted that in this specification, similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.
[0061] As used herein, the term "module or unit" may refer to or include an application specific integrated circuit (ASIC), an electronic circuit, a processor (shared, dedicated, or group) that executes one or more software or firmware programs and / or a memory (shared, dedicated, or group), combinational logic circuitry, and / or other suitable components that provide the described functionality, or may be a part of an application specific integrated circuit (ASIC), an electronic circuit, a processor (shared, dedicated, or group) that executes one or more software or firmware programs and / or a memory (shared, dedicated, or group), combinational logic circuitry, and / or other suitable components that provide the described functionality.
[0062] The currently popular user login method is single sign-on (SSO). The so-called SSO is the user's one-time authentication login. In short, after a user logs in to the identity authentication server once, they can obtain the permission to access other associated systems and application software in the single sign-on system. At the same time, this implementation does not require the administrator to modify the user's login status or other information. This means that in multiple application systems, the user only needs to log in once to access all mutually trusted application systems. This method reduces the time consumption caused by logging in. However, the security of the central authentication service of this method only depends on SSL (Secure Sockets Layer), making it have certain security risks.
[0063] The technical solution of this application hopes to provide an identity authentication method based on a trusted execution environment (TEE) such as the ARM company's Trustzone and the Intel company's SGX architecture. This method is compatible with all existing SSO protocols and greatly enhances the security of single sign-on by utilizing the TEE mechanism. In addition, the identity authentication method of this application can be deployed on non-TEE electronic devices, enabling non-TEE devices to provide secure SSO services for users with the help of TEE devices such as smartphones.
[0064] Figure 1 A schematic diagram showing an example of an identity authentication system according to an embodiment of the present application.
[0065] The identity authentication system 10 may include a user device 110, a network 120, one or more electronic devices having a Trusted Execution Environment (TEE) such as the ARM company's Trustzone or the Intel company's SGX architecture. Hereinafter, for simplicity, it is simply referred to as the TEE device 130 and the Identity Provider (IDP) 140. The user device 110 further includes a control unit 111 and a transceiver unit 112. The TEE device 130 may include a TEE unit 132 and a transceiver unit 133. Optionally or additionally, the TEE device 130 may further include a control unit 131. The identity provider 140 may include a control unit 141, a TEE unit 142, and a transceiver unit 143. Among them, in Figure 1 and the remaining drawings, the letter after the reference number, such as "130a", indicates a reference to an element having that specific reference number. A reference number without a subsequent letter in the text, such as "130", indicates an overall reference to an embodiment of the element with that reference number. It can be understood that the structures illustrated in the embodiments of the present invention do not constitute specific limitations on the user device 110, the TEE device 130, and the identity provider 140. In other embodiments of the present application, the user device 110, the TEE device 130, and the identity provider 140 may include more or fewer components than shown, or combine certain components, or split certain components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.
[0066] The user device 110 may include, but is not limited to, smart speakers, smart refrigerators, home robots, wearable devices (e.g., display glasses or goggles, watches, bracelets, earphones, armbands, jewelry, etc.), IoT devices, and various other electronic devices that generally do not have a trusted execution environment.
[0067] Network 120 may include various transmission media for enabling data communication among user device 110, TEE device 130, and identity provider 140. For example, network 120 may be a local area network or a wide area network relayed through a Relay device. For example, the local area network may include short-range communication networks such as a WiFi hotspot network, a WiFi P2P network, a Bluetooth network, a Zigbee network, or a Near Field Communication (NFC) network. The wide area network may include a 3rd-generation mobile communication technology (3G) network, a 4th-generation mobile communication technology (4G) network, a 5th-generation mobile communication technology (5G) network, and / or a future evolved Public Land Mobile Network (PLMN) or the Internet, etc.
[0068] TEE device 130 may include smartphones, tablets, personal computers, smart TVs, and in-vehicle infotainment devices (e.g., in-vehicle smart screens), as well as various other electronic devices that typically have a trusted execution environment.
[0069] Identity provider 140 is typically an authentication server responsible for user identity authentication. User device 110 and / or TEE device 130 may be registered with identity provider 140, thereby associating the registered device with the user's identity authentication account. After that, when the user uses user device 110 and / or TEE device 130 to log in to the user's identity authentication account, identity provider 140 provides the user's identity authentication service.
[0070] Optionally or additionally, the identity authentication system 10 of the present application may further include an associated device (not shown). The associated device can be used to provide user identity authentication accounts and device registration and management services, and to associate multiple devices under the same account, such as establishing an association relationship table between the user's identity authentication account and the device. As another example, the associated device can also obtain the user identity authentication account and the device association relationship table from the service provider. In the case where the identity authentication system 10 includes an associated device, the identity provider 140 can provide security authentication services for the service provider of the associated device. For example, after the user 150 registers the user device 110 on the associated device, or after the service provider of the user 150 sends the user identity authentication account and the device association relationship table of the user 150 to the associated device, the associated device can send the identity authentication account information of the user 150 and the device information of the user device 110 to the identity provider 140, so that the identity provider 140 can provide corresponding security authentication services.
[0071] In one or more other embodiments, the associated device can be used only to provide user identity authentication account and device registration services, and to associate multiple devices under the same identity authentication account. In this case, the identity provider 140 can provide identity authentication services, and the service provider of the service requested by the user can be other devices not shown. Optionally, the identity provider 140 can also be the service provider of the service requested by the user, and the identity provider 140 can also provide identity authentication services.
[0072] In one or more other embodiments, the associated device can also be a part of the identity provider 140, that is to say, the associated device can be included in the identity provider 140 as a component or unit, and the identity provider 140 can implement all the functions of the associated device. In this case, as Figure 1 shown, the identity authentication system 10 does not need to have an associated device independent of the identity provider 140.
[0073] According to an embodiment of the present application, the control units (111, 131, and 141) of the user device 110, the TEE device 130, and the identity provider 140 can be implemented in hardware, software, or a combination of software and hardware, where the hardware includes, but is not limited to, processing circuits such as a central processing unit (CPU), an application processor, or a micro-programmed control unit (MCU). Among them, different processing units can be independent devices or integrated in one or more processors. In the embodiments herein, the control units (111, 131, and 141) can be configured to execute some or all of the one or more interaction processes and method flows described below.
[0074] In some embodiments, the TEE units (132 and 142) of the TEE device 130 and the identity provider 140 can include control units with a trusted execution environment. For example, the TEE units (132 and 142) can be processing circuits such as a central processing unit (CPU), an application processor, or a micro-programmed control unit (MCU) with a trusted execution environment. In this case, as Figure 1 shown, the TEE device 130 and the identity provider 140 may not include the control unit 131 and the control unit 141. The TEE unit 132 of the TEE device 130 can implement all the functions of the control unit 131, and the TEE unit 142 of the identity provider 140 can implement all the functions of the control unit 141.
[0075] In other embodiments, the TEE units (132 and 142) of the TEE device 130 and the identity provider 140 can be security chips that provide a trusted execution environment. For example, TEE security chips based on the ARM company's Trustzone and the Intel company's SGX architectures provide a TEE security framework and full life cycle management of security applications for the TEE device 130 and the identity provider 140. In this case, the TEE units (132 and 142) of the TEE device 130 and the identity provider 140 can, for example, jointly implement one or more embodiments of the present application as coprocessors of the control unit 131 of the TEE device 130 and the control unit 141 of the identity provider 140, respectively.
[0076] The user device 110 can use its transceiver unit 112 to communicate data with the TEE device 130 and the identity provider 140 via the network 120. Similarly, the TEE device 130 can use its transceiver unit 133 to communicate data with the user device 110 and the identity provider 140 via the network 120, and the identity provider 140 can use its transceiver unit 143 to communicate data with the user device 110 and the TEE device 130 via the network 120.
[0077] In some possible scenarios of the identity authentication system 10, the user device 110 or the TEE device 130 can be communicatively connected to the identity provider 140 based on the fifth-generation mobile communication technology (5G) network. As an example, with the deployment of the 5G network, it can provide users with extremely large access bandwidth, and its data transmission rate is much higher than that of previous cellular networks, up to 10 Gbit / s at most, faster than the current wired Internet transmission speed and 100 times faster than the current 4G LTE cellular network. Another advantage of the 5G network is lower network latency (faster response time), generally less than 1 millisecond.
[0078] In some other possible scenarios of the identity authentication system 10, the user device 110 can securely communicate data with the TEE device 130 based on a WiFi hotspot network, a WiFi P2P network, a Bluetooth network, a Zigbee network, or a Near Field Communication (NFC) network.
[0079] The following briefly describes the security authentication process between the TEE device 130 and the identity provider 140. In the identity authentication system 10, when the user 150 uses the TEE device 130 to register a user identity authentication account with the identity provider 140 via the network 120, the TEE unit 132 of the TEE device 130 generates a pair of asymmetric key pairs, which includes a private key and a public key, and associates them with the user's local identity information, such as biometric features such as fingerprints, faces, and iris patterns. The private key is retained in the TEE unit 132 of the TEE device 130 and cannot be read by hackers. The public key is transmitted to the TEE unit 142 of the identity provider 140, and the identity provider 140 associates this public key with the user's corresponding user identity authentication account.
[0080] Subsequently, when the user 150 logs in to the identity provider 140 for authentication, the private key in the TEE unit 132 of the TEE device 130 signs the challenge data (Challenge) of the identity provider 140, and the identity provider 140 uses the corresponding public key for verification. The private key in the TEE unit 132 of the TEE device 130 must be identified by the local user 150, such as pressing a key, pressing a fingerprint, or scanning a face, before it can be used for signing operations.
[0081] The following introduces some exemplary scenarios of the identity authentication system 10. For example, in a scenario where the user 150 needs to make a mobile payment through the user device 110, the user device 110 may be a smart watch or bracelet with a mobile payment function, the TEE device may be the smart phone of the user 150, and the identity provider 140 may be a payment platform selected by the user, such as Alipay, WeChat, Google Pay, Apple Pay, etc. The identity provider 140 may also be a third-party service provider that provides security authentication for the payment platform, which is not specifically limited here.
[0082] As an example, when the user 150 checks out at a store, restaurant, supermarket or other business place, the user 150 wants to use the user device 110 worn on the wrist, such as a smart bracelet or smart watch, to make a quick and convenient payment without having to take out the TEE device 130, such as a smartphone, from a pocket, a handbag or a backpack to make a mobile payment. In this case, if the user device 110 is such as Figure 1 For devices that do not support TEE as shown in , when the user device 110 needs to log in to the user identity authentication account to complete the payment, it can use the TEE device 130 under the same user identity authentication account to complete the security authentication with the identity provider 140 and complete the corresponding payment operation on the user device 110.
[0083] In another possible scenario of the identity authentication system 10, for example, in a home where the user 150 has various smart home products. The user device 110 may be a smart home accessory or a low-end home gateway that does not usually have a trusted execution environment but supports the installation of applications or triggering smart payments, such as a smart refrigerator, a home robot, a smart speaker, etc. The TEE device 130 may be a smart TV, a tablet computer, a high-end home gateway, and a smartphone of the user 150 and / or other family members at home. The identity provider 140 may be an application installation platform such as an app store, or a payment platform selected by the user, such as Alipay, WeChat, Google Pay, Apple Pay, etc. When user 150 needs to install an application for user device 110, for example, user 150 installs a music playback application for user device 110 such as a smart speaker, or user 150 installs a cooking application for user device 110 such as a smart steam oven, or user 150 installs a food monitoring application or a recipe application for user device 110 such as a smart refrigerator, user 150 needs to log in to the application installation platform through user device 110 to purchase, download and install the application. In this case, when user device 110 needs to log in to the user identity authentication account of the application installation platform, it can use the TEE device 130 under the same user identity authentication account, such as a smart TV, to complete the security authentication with the identity provider 140 and complete the corresponding application installation on the user device 110, wherein the identity provider 140 can be an application installation platform or a third-party service provider that provides security authentication for the application installation platform, and there is no specific limitation here.
[0084] In the above scenario, as long as at least one TEE device 130 is registered under the user's identity authentication account, the TEE device 130 can provide a trusted execution environment for various other user devices under the user's identity authentication account that do not have a trusted execution environment, thereby achieving secure login of the user device.
[0085] As another example, in some cases, the user 150 may have multiple family members at home, and some or all of the multiple family members may control various smart home devices at home through the TEE device 130 such as a smartphone. Figure 1As shown, assuming that the TEE device 130 is a smart phone, family member A (user 150) can use the TEE device 130a to control various smart home devices at home, family member B can use the TEE device 130b to control various smart home devices at home, and family member C can use the TEE device 130c to control various smart home devices at home. Generally, a family account or family circle can be established by a family member, enabling each family member to share the use of various smart home devices. The family member who establishes the family account or family circle is generally referred to as the family master member, and the family master member has the main control authority over each smart home device. For example, the authority to configure smart home devices, set up accounts, update systems, share devices, etc. Taking user 150 as the family master member as an example, user 150 uses the TEE device 130a to establish a family circle. After family members B and C join the family circle, the TEE device 130a, the TEE device 130b, and the TEE device 130c are interconnected based on the family circle. User 150 can share some or all of the smart home devices at home with each member in the family circle. When family member B or family member C needs to use a smart home device, they log in to the shared smart home device, such as the user device 110, through the user accounts of their respective TEE devices 130b and TEE devices 130c. Thus, low-end electronic devices such as the user device 110 can be controlled by multiple TEE-supported devices. In this scenario, when the user device 110 needs to perform the aforementioned application download and installation or trigger a smart payment, the user device 110 can complete the security authentication by means of the user account of any family member. Optionally or additionally, in the case where the permissions of the user account used by the user device 110 are insufficient, the user device 110 can also complete the security authentication through the family circle with the help of other TEE devices 130 (e.g., the TEE device 130a) whose permissions meet the requirements. For example, if the user device 110 performs security authentication by means of the TEE device 130b of family member B or the TEE device 130c of family member C, but the TEE device 130b and the TEE device 130c do not have the main control authority over the user device 110 and cannot assist the user device 110 in performing security authentication, then through the family circle, the user device 110 can request the TEE device 130a with the main control authority to assist the user device 110 in performing security authentication.
[0086] In the above scenario, when other family members who are not the family master member log in to the user device without TEE using their respective accounts, they can complete the security authentication with the help of the family master member's account and TEE device. This can not only achieve the security authentication of the user device without TEE, but also control the authorized login of some TEE devices of family members, thus realizing the cross-account authorization of the identity authentication technology of the present application.
[0087] The identity authentication method provided by the embodiments of the present application will be described exemplarily below in combination with the accompanying drawings and the above application scenarios. Figure 2 The interaction process of the identity authentication method of the present application is shown. As Figure 2 shown, Figure 2 Some prior arts in the art are not shown in the figure, for example, including the process of user 150 registering an identity authentication account with the identity provider 140; how user 150 operates the user device 110 and the TEE device 130 to register devices in the associated device 160, and how the associated device 160 correlates and stores the information of the identity authentication account of user 150, the device information of the user device 110, and the device information of the TEE device 130; and the process of user 150 operating the TEE device 130a to establish a home circle, adding other TEE devices 130b and 130c to the established home circle, and the mutual correlation of the three TEE devices 130a, 130b, and 130c in the home circle. The following takes the scenario where user 150 uses a smart watch (user device 110) to log in to a third-party application as an example to illustrate the interaction process between devices. In this scenario, for example, the user device 110 may be a smart watch without a TEE, the TEE device 130 may be the smart phone of user 150, the associated device 160 may be a device for storing the identity authentication account information and device information registered by the user, and the identity provider 140 may be a device for securely authenticating the identity of user 150. Optionally, the identity provider 140 may also be an application service provider and may authenticate the identity of the user.
[0088] As Figure 2 shown, in 201a: Send the information of the user's identity authentication account and the device information of the TEE device. When user 150 registers a TEE device 130 such as a smart phone with the associated device 160, the TEE device 130 may send the information of the identity authentication account of user 150 and the device information of the TEE device 130 to the associated device 160. The information of the identity authentication account may include the name of the identity authentication account registered by user 150, etc., where the identity authentication account may be, for example, a Google account, an Apple account, or a Huawei account registered by the user. The device information may include the ID number and serial number that uniquely identify the TEE device 130, and a mark indicating that the TEE device 130 has a TEE unit 132, etc.
[0089] In other embodiments, in Figure 1In the scenario of the family circle described in , after user 150 uses the TEE device 130a to establish a family circle and family members B and C join the family circle, the TEE device 130a, the TEE device 130b, and the TEE device 130c are associated with each other based on the family circle. The association information of each device in this family circle, as well as the permission information that the TEE device 130a is the main family member device and the TEE device 130b and the TEE device 130c are non-main family member devices, can be stored in the associated device 160.
[0090] In 201b: Send the information of the user's identity authentication account and the device information of the user device. Similar to the above block 201a, when user 150 registers a user device 110 such as a smart watch with the associated device 160, the user device 110 can send the information of the user 150's identity authentication account and the device information of the user device 110 to the associated device 160. The information of the identity authentication account may include the name of the identity authentication account registered by user 150, etc. The device information may include the ID number and serial number that uniquely identify the user device 110, and a mark indicating that the user device 110 does not have a TEE unit, etc.
[0091] In an alternative embodiment, during the respective processes of the user registering the TEE device 130 and the user device 110, the information of the user's identity authentication account and the device information of the TEE device 130 and the user device 110 may also be sent to the identity provider 140, and this application does not make specific restrictions on this.
[0092] It can be understood that the associated device 160 can associate the user device 110 and the TEE device 130 of user 150 based on the information of the user 150's identity authentication account. For example, establish an association relationship table among the identity authentication account of user 150, the user device 110, and the TEE device 130.
[0093] After the registration of the user device 110 and the TEE device 130 is completed, when the user 150 uses the user device 110 to log in to a third-party application based on SSO, for example, when the user 150 needs to use the registered identity authentication account to log in to a third-party application installed on the smart watch (user device 110), at 202: the user device 110 sends an SSO-based application login request and information indicating that the user device 110 does not have a TEE unit to the identity provider 140. Here, the identity provider 140 can be the operating agency of the third-party application or an agency designated by the third-party application to provide identity authentication services. In the case where the identity provider 140 is an agency designated by the third-party application to provide identity authentication services, the login request initiated by the user device 110 can also be directed to the identity provider 140 through the third-party application. In various scenarios described in this application, since there is no specific limitation on the third-party application that the user device 110 needs to log in to, for the sake of easy understanding, the embodiments of this application are described exemplarily with the user device 110 directly sending a login request to the identity provider 140 as an example. Optionally or additionally, the device ID of the user device can be included in the login request, so that the identity provider 140 can determine that the sender of the login request is the user device 110.
[0094] After the identity provider 140 determines, based on the information sent by the user device 110, that the user device 110 does not have a TEE unit, that is, the user device 110 does not have a trusted execution environment, at 203: the identity provider 140 sends a query request to the associated device 160 to query whether the user device 110 has an associated TEE device. The query request may include the device ID of the user device 110, information about the user's identity authentication account, or may include the device ID of the user device 110 and information about the user's identity authentication account.
[0095] In some other embodiments, when the user device 110 logs in using the account of a device that does not have login permission in the home circle, for example, using the account of the TEE device 130b or the TEE device 130c, when the identity provider 140 determines that the user device 110 does not have a trusted execution environment and the accounts of the TEE device 130b or the TEE device 130c do not have primary control authority over the user device 110, the identity provider 140 may query the associated device 160 for the home circle master device associated with the user device 110.
[0096] After receiving the query request from the identity provider 140, the associated device 160 can query, for example, the association relationship table or the home circle to retrieve whether there is a TEE device or a home master device (TEE device 130a) associated with the user device 110, and at 204: send the query result for the user device 110 to the identity provider 140.
[0097] In an alternative other embodiment, at 202, the user equipment 110 may also not send information indicating that the user equipment 110 does not have a TEE unit. Since the user equipment 110 has provided information that it does not have a TEE unit when registering with the associated device 160, in this case, after receiving the login request, the identity provider 140 may directly send a query request to the associated device 160. The associated device 160 may, based on the device ID of the user equipment 110 provided by the identity provider 140 in the query request, query that the user equipment 110 is a device without a TEE unit, and then further query whether there is an associated TEE device for the user equipment 110 and send the query result to the identity provider 140.
[0098] After the identity provider 140 receives the query result from the associated device 160, if the query result includes information about the TEE device 130 associated with the user equipment 110, then at 205, the identity provider 140: sends a request to confirm that the TEE device 130 is online. In some embodiments, the request to confirm that the TEE device 130 is online may be a simple handshake request based on a communication protocol. For example, the identity provider 140 sends a request message such as an ACK packet to the TEE device 130. If the TEE device 130 responds to the request message and the two devices complete the handshake, then the identity provider 140 may determine that the TEE device 130 is in an online state on the network.
[0099] In some other embodiments, the request to confirm that the TEE device 130 is online may be made by triggering the TEE device 130 to perform the following exemplary operations and then sending the relevant operation results to the identity provider 140, so that the identity provider 140 can confirm that the TEE device 130 is in an online state on the network.
[0100] Exemplarily, after the TEE device 130 receives a request from the identity provider 140 to confirm that the TEE device 130 is online, the TEE device 130 sends a request to establish a communication connection with the user device 110 and a device authentication request at 206. For example, the TEE device 130 can communicate with the user device 110 through short-range communication protocols such as USB, Bluetooth, and WiFi, and these communication protocols support existing Secure Remote Password (SRP) authentication protocols and Password-Authenticated Key Exchange (PAKE) protocols. By adopting the SRP protocol or PAKE protocol in the short-range communication protocol, the TEE device 130 and the user device 110 can authenticate each other's devices and establish a secure communication between the TEE device 130 and the user device 110. The device authentication here is to ensure that the devices at both ends of the communication connection are not impersonated by other devices by possible attackers. For example, the device authentication can enable the user device 110 to ensure that the device connected to it is the TEE device 130 associated with the user device 110, rather than other devices used by the attacker to impersonate the TEE device 130. At the same time, the device authentication can enable the TEE device 130 to ensure that the device connected to it is the user device 110 associated with the TEE device 130, rather than other devices used to impersonate the user device 110.
[0101] After the device authentication between the TEE device 130 and the user device 110 is successful, the user device 110 sends information indicating that the device authentication is passed and the identity authentication parameters of the user device 110 to the TEE device 130 at 207. The identity authentication parameters of the user device 110 include parameters such as the device ID and the device serial number. The TEE device 130 can save the identity authentication parameters of the user device 110 and use these parameters for subsequent authentication processes.
[0102] Subsequently, the TEE device 130 sends information indicating that the device authentication is passed and the identity authentication parameters of the user device 110 to the identity provider 140 at 208. The TEE device 130 represents to the identity provider 140 that the local TEE device 130 and the user device 110 have completed mutual device authentication, and indicates that the TEE device 130 is online and available for subsequent authentication processes. The identity provider 140 can save the identity authentication parameters of the user device 110 for subsequent identity authentication processes.
[0103] After the identity provider 140 receives a good authentication result from the TEE device 130, it sends a request to confirm the use of the TEE device 130 to authenticate the user of the user device 110 to the user device 110 at 209.
[0104] User 150 confirms the request from the identity provider on user device 110 and, at 210, sends information to identity provider 140 determining to use TEE device 130 to authenticate the user of user device 110.
[0105] After receiving the confirmation information from user device 110, identity provider 140, at 211, interacts with TEE device 103 to encrypt data based on the authentication parameters to authenticate the user of user device 110. Specific processes for authenticating the user of user device 110 will be further described in one or more subsequent embodiments of this application.
[0106] After the authentication between user device 110 and identity provider 140 assisted by TEE device 130 is completed, TEE device 130, at 212, sends information indicating successful authentication to identity provider 140. After receiving the information indicating successful authentication from TEE device 130, identity provider 140, at 213, sends information indicating successful authentication of the user identity of user device 100 to user device 110 to notify user device 110 that the login is successful.
[0107] According to the above interaction process of this application, as long as at least one TEE device 130 is registered under the user's authentication account, this TEE device 130 can provide a trusted execution environment for various other user devices without a trusted execution environment under the user's authentication account, realizing secure login of user devices.
[0108] According to the embodiments of this application, by utilizing the TEE mechanism, the security of the entire authentication process of user devices is protected by TEE. In addition, the authentication method of this application can be deployed on non-TEE electronic devices, enabling non-TEE devices to provide secure SSO services for users with the help of TEE devices such as smartphones, solving the problem that non-TEE devices cannot obtain security protection.
[0109] The following further illustrates in conjunction with the accompanying drawings Figure 2 The authentication method performed by each of the devices shown.
[0110] Figure 3 A flowchart showing the authentication method 300 of user device 110 according to an exemplary embodiment.
[0111] Among them, in some embodiments, part or all of method 300 can be implemented on user device 110 as shown in Figure 1 In some other embodiments, different components of user device 110 as shown in Figure 1 can implement different parts or all of method 300.
[0112] For content not described in the implementation manners of the above methods and example scenarios, reference may be made to the following method implementation manners; similarly, for content not described in the following method implementation manners, reference may be made to the implementation manners of the above methods and example scenarios. For example, Figure 3 The identity authentication method 300 shown is a further illustration of Figure 2 the implementation manners shown. For content already described in the foregoing implementation manners, it will be briefly described below or will not be repeated.
[0113] As Figure 3 shown, at 301: Send the identity authentication account of the user equipment and a flag indicating that the user equipment does not have a TEE unit to the associated device. When the user 150 registers the user equipment 110 such as a smart watch with the associated device 160, the user equipment 110 may send the information of the identity authentication account of the user 150 and the device information of the user equipment 110 to the associated device 160. The device information may include a flag indicating that the user equipment 110 does not have a TEE unit.
[0114] In other implementation manners, for example, in the scenario where the above-mentioned multiple household users form a household circle, the user equipment 110 may have multiple identity authentication accounts, and each identity authentication account corresponds to a family member. In the case where there is more than one primary member among the family members, the user equipment 110 may have another identity authentication account corresponding to the household primary member, and this identity authentication account may be the same as the identity authentication account of the TEE device 130 of another household primary member.
[0115] At 302: Send an SSO-based application login request and a flag indicating that the user equipment does not have a TEE unit to the identity provider. After the registration of the user equipment 110 is completed, when the user 150 uses the user equipment 110 to log in to a third-party application based on SSO, the user equipment 110 sends an SSO-based application login request and information indicating that the user equipment 110 does not have a TEE unit to the identity provider 140.
[0116] At 303: Establish communication with a TEE device having a TEE unit. After the TEE device 130 sends a request for establishing a communication connection and a device authentication request to the user equipment 110, the user equipment 110 may establish a communication connection with the TEE device 130 through a short-range communication protocol such as USB, Bluetooth, WiFi, etc.
[0117] At 304: Provide the identity authentication parameters of the user device to the TEE device. After the direct communication connection between the user device 110 and the TEE device 130 is established and the device authentication between both parties is successful, the user device 110 can send identity authentication parameters such as the device ID and device serial number of the user device 110 to the TEE device 130. Optionally or additionally, the user device 110 can further confirm whether the identity authentication account logged in by the user device 110 is the same as the identity authentication account of the TEE device 130. If the accounts are the same, the user device 110 sends the identity authentication parameters to the TEE device 130.
[0118] After that, the user device 110 will receive a confirmation request from the identity provider 140, which requests the user device 110 to confirm whether to use the TEE device for identity authentication at 305. The user 150 can operate the user device 110 to confirm the request from the identity provider 140. If the user agrees to use the TEE device 130 for identity authentication, then at 306: the user device 110 sends information indicating that the TEE device is used to authenticate the user of the user device to the identity provider 140.
[0119] Figure 4 The flowchart shows the authentication method 400 of the TEE device 130 according to an exemplary embodiment.
[0120] Among them, in some embodiments, part or all of the method 400 can be implemented on the TEE device 130 as shown in Figure 1 . In other embodiments, different components of the TEE device 130 as shown in Figure 1 can implement different parts or all of the method 400.
[0121] For the content not described in the embodiments of the above methods and example scenarios, reference can be made to the following method embodiments; similarly, for the content not described in the following method embodiments, reference can be made to the embodiments of the above methods and example scenarios. For example, Figure 4 The authentication method 400 shown is a further illustration of the embodiments of Figure 2 and Figure 3 . The content already described in the foregoing embodiments will be briefly described below or will not be repeated.
[0122] As shown in Figure 4 , the TEE device 130 at 401: sends the identity authentication account of the TEE device to the associated device and a mark indicating that the TEE device has a TEE unit. When the user 150 registers the TEE device 130 such as a smart phone with the associated device 160, the TEE device 130 can send the information of the identity authentication account of the user 150 and the device information of the TEE device 130 to the associated device 160.
[0123] At 402: Receive a request from the identity provider to determine whether the TEE device is online. After the TEE device 130 receives the request from the identity provider 140, it can perform operations of communicating with the user device 110 according to the requirements of the request. For example, at 403: In response to the request, the TEE device 130 establishes communication with the user device. The TEE device 130 can communicate and connect with the user device 110 through short-distance communication protocols such as USB, Bluetooth, and WiFi.
[0124] After the TEE device 130 and the user device 110 are successfully authenticated through security protocols such as the SRP protocol and the PAKE protocol, at 404: The TEE device 130 receives identity authentication parameters from the user device. The TEE device 130 can save the identity authentication parameters of the user device 110 and use these parameters for subsequent authentication processes.
[0125] In some embodiments, the TEE device 130 can, at 405: Send information that the TEE device is online and the identity authentication parameters to the identity provider.
[0126] When the user device 110 agrees to use the TEE device 130 for identity authentication, the identity provider 140 will interact with the TEE device 130 with encrypted identity authentication parameters, etc. For example, at 406: The TEE device 130 helps the identity provider authenticate the user of the user device through the TEE unit 132. This part of the interaction content between the TEE device 130 and the identity provider 140 will be described in detail below.
[0127] Figure 5 The flowchart shows an identity authentication method 500 for an associated device 160 according to an exemplary embodiment.
[0128] Among them, in some embodiments, part or all of the method 500 can be implemented on the associated device 160 as shown in Figure 1 . In other embodiments, different components of the associated device 160 as shown in Figure 1 can implement different parts or all of the method 500.
[0129] For the content not described in the embodiments of the above methods and example scenarios, reference can be made to the following method embodiments; similarly, for the content not described in the following method embodiments, reference can be made to the above methods and example scenarios. For example, Figure 5 The identity authentication method 500 shown is a further illustration of the Figures 2 - 4 embodiments. The content already described in the foregoing embodiments will be briefly described below or will not be repeated.
[0130] As shown inFigure 5 As shown, when user 150 operates user device 110 and the TEE device 130 registers the device with the associated device 160, the associated device 160 can, at 501: receive the authentication account from the TEE device, and a mark that at least partially indicates that the user TEE device has a TEE unit. For example, the TEE device 130 can send the information of the authentication account of user 150 and the device information of the TEE device 130 to the associated device 160. The information of the authentication account can include the name of the authentication account registered by user 150, etc., where the authentication account can be, for example, a Google account, an Apple account, or a Huawei account registered by the user. The device information can include the ID number and serial number that uniquely identify the TEE device 130, and a mark that identifies that the TEE device 130 has a TEE unit 132, etc.
[0131] Similarly, when the user device 110 is registered, the associated device 160 can, at 502: receive the authentication account from the user device 110, and a mark that at least partially indicates that the user device does not have a TEE unit.
[0132] The associated device 160 can, at 503: associate the user device 110 with the TEE device 130 when it determines that the authentication account of the user device 110 is the same as the authentication account of the TEE device 130 through the authentication accounts during the registration of the TEE device 130 and the user device 110. For example, an association relationship table of the authentication account of user 150, the user device 110, and the TEE device 130 is established in the associated device 160, etc.
[0133] Subsequently, after the user device 110 initiates an SSO application login, the associated device 160 can, at 504: receive a request from the identity provider 140 to query whether the user device 110 is associated with a device that supports a TEE unit. The associated device 160 can query, for example, the association relationship table to retrieve whether there is a TEE device associated with the user device 110.
[0134] At 505: When it is confirmed according to the mark of the user device that the user device does not support a TEE unit, it is queried that the user device is associated with a TEE device that supports a TEE unit. The associated device 160 can, according to the device ID of the user device 110 provided by the identity provider 140 in the query request, query that the user device 110 is a device without a TEE unit, and then further query that the user device 110 is associated with the TEE device 130.
[0135] After that, at 506, the associated device 160 sends the query result of the user device 110 to the identity provider 140. The associated device may send the device information of the TEE device 130 associated with the user device 110 to the identity provider 140 so that the identity provider 140 can communicate with the TEE device 130.
[0136] Figure 6 FIG. shows a flowchart of an identity authentication method 600 of the identity provider 140 according to an exemplary embodiment. Among them, in some embodiments, part or all of the method 600 may be implemented on the identity provider 140 as shown in Figure 1 . In other embodiments, different components of the identity provider 140 as shown in Figure 1 may implement different parts or all of the method 600.
[0137] For the content not described in the embodiments of the above methods and example scenarios, reference may be made to the following method embodiments; similarly, for the content not described in the following method embodiments, reference may be made to the embodiments of the above methods and example scenarios. For example, Figure 6 the identity authentication method 600 shown is a further illustration of the Figures 2 - 5 embodiments. The content already described in the foregoing embodiments will be briefly described or not repeated hereinafter.
[0138] As shown in Figure 6 , when the user 150 uses the user device 110 to log in to a third-party application based on SSO, at 601, the identity provider 140 receives information from the user device 110 indicating that the user device 110 does not have a TEE unit. In this case, the identity provider 140 needs to determine at 602 whether the user device 110 has an associated TEE device.
[0139] As an example, the identity provider 140 may send a request to the associated device 160 asking whether the user device 110 has an associated TEE device. The identity provider 140 may determine that the user device has an associated TEE device 130 based on the query result of the associated device 160.
[0140] As another example, during the respective processes of the user 150 registering the TEE device 130 and the user device 110, when the user device 110 and the TEE device 130 have sent the information of the identity authentication account of the user 150 and the device information of the TEE device 130 and the user device 110 to the identity provider 140, the identity provider 140 can determine that the user device 110 has an associated TEE device 130 by judging that the identity authentication account logged in by the user device 110 is the same as the registered identity authentication account from the TEE device 130. Conversely, when the identity authentication account logged in by the user device 110 is different from the registered identity authentication account from the TEE device 130, the identity provider 140 can determine that the user device 110 does not have an associated TEE device 130.
[0141] After the identity provider 140 determines that the user device has an associated TEE device 130, at 603, the identity provider 140 sends a request to the TEE device 130 to confirm that the TEE device is online. In some embodiments, the request to confirm that the TEE device 130 is online can be a simple handshake request based on a communication protocol. In other embodiments, the request to confirm that the TEE device 130 is online can trigger the TEE device 130 to execute Figure 2 and Figure 4 one or more parts of the identity authentication method shown.
[0142] After the identity provider 140 sends a request to the TEE device 130 to confirm whether it is online, if the TEE device 130 is online, at 604, the identity provider 140 can receive information from the TEE device 130 confirming its online status.
[0143] In some embodiments, when receiving information from the TEE device 130 confirming its online status, the identity provider 140 can also, at 605, receive the identity authentication parameters of the user device 110 from the TEE device 130. The identity provider 140 can save the identity authentication parameters of the user device 110 for subsequent authentication of the identity of the user logging in to the application on the user device 110.
[0144] After that, at 606, the identity provider 140, through the TEE unit 142, uses the identity authentication parameters to authenticate the user of the user device 110 by interacting with the TEE device 130 with encrypted data based on the identity authentication parameters. As an example, the encrypted data can include a challenge value encrypted with an encryption key and a credential value encrypted with a verification key, where the identity provider 140 can generate the encryption key and the verification key using the identity authentication parameters of the user device 110. The above content will be described in detail below with reference to the accompanying drawings.
[0145] Figure 7The figure shows an interactive schematic diagram of a user device according to an embodiment of the present application using a TEE device to perform exemplary user identity authentication account registration at an identity provider. Figure 7 The shown interactive process is an improvement to the prior art implementation part not shown in Figure 2 the figure.
[0146] In some possible scenarios where a user 150 registers an identity authentication account at an identity provider 140, the user can initiate the registration of the user's identity authentication account with the identity provider 140 and bind the user device 110 to the identity authentication account by operating the user device 110. In this scenario, in order to protect the security of the registration information of the user's identity authentication account, the user device 110 can use the TEE device 130 to assist in the registration process. Compared with the prior art, by using the TEE mechanism, the security of the registration process of the user device 110 is protected by the TEE, thereby achieving the purpose of protecting the registration information of the user's identity authentication account.
[0147] Figure 7 The figure shows the data interaction between each device. As Figure 7 shown, when the user 150 first binds or registers the user device 110 to the identity provider 140, the transceiver unit 112 of the user device 110 sends the information for user device registration to the identity provider 140 at 701. The information for user device registration may include the name and password of the identity authentication account of the user 150, and the device information of the user device 110, such as the device ID and serial number of the user device 110, etc.
[0148] After the transceiver unit 143 of the identity provider 140 receives the information from the user device 110, it uses this information to generate the corresponding key and signature value of the user device in the TEE unit 142 of the identity provider 140. The transceiver unit 143 of the identity provider 140 then sends the signature value and the registration information of the user device 110 to the TEE device 130 at 702.
[0149] After the transceiver unit 133 of the TEE device 130 receives the signature value and the registration information of the user device 110 from the identity provider 140, the TEE device 130 verifies the signature value in the TEE unit 132. If the signature value verification passes, the TEE device 130 generates challenge data and a message authentication code in the TEE unit 132. Then, the transceiver unit 133 of the TEE device 130 sends the challenge data and the message authentication code to the identity provider 140 at 703.
[0150] Subsequently, the identity provider 140 decrypts and verifies the message authentication code in the TEE unit 143. After the message authentication code is verified successfully, the transceiver unit 143 sends the information of successful registration to the user device 110 at 704. The registration of the user device 110 is completed.
[0151] Figure 8 The interactive schematic diagram shows how the user device in the embodiment of the present application uses the TEE device to perform identity authentication at the identity provider. Figure 8 The shown interactive process is a further description of Figure 2 the shown interactive process, especially a further description of Figure 2 the parts of blocks 211, 212 and 213 shown. The content described in the foregoing embodiments will be briefly described or not repeated hereinafter.
[0152] As Figure 8 shown, the transceiver unit 133 of the TEE device 130 sends the identity authentication parameters of the user device 110 to the identity provider 140 at 801. Among them, the scenarios where the TEE device 130 sends the identity authentication parameters can refer to the foregoing various embodiments, for example, refer to Figure 2 the description of block 208 in Figure 8 , which will not be repeated here. In an alternative embodiment, the identity authentication parameters may include the device information of the user device, such as the device ID, etc. The following describes block 211 shown with reference to Figure 2 the subsequent process of Figure 2 The parts of blocks 209 - 210 in
[0153] After the transceiver unit 143 of the identity provider 140 receives the identity authentication parameters of the user device 110 from the TEE device 130, it generates the corresponding key and signature value of the user device 110 in the TEE unit 142 of the identity provider 140. Then, the transceiver unit 143 of the identity provider 140 sends the signature value to the TEE device 130 at 802.
[0154] After the transceiver unit 133 of the TEE device 130 receives the signature value from the identity provider 140, the TEE device 130 verifies the signature value in the TEE unit 132. When the signature value is verified successfully, the TEE device 130 generates the first challenge data and the first message authentication code in the TEE unit 132. Then, the transceiver unit 133 of the TEE device 130 sends the first challenge data and the first message authentication code to the identity provider 140 at 803.
[0155] Subsequently, the identity provider 140 decrypts and verifies the first message authentication code in the TEE unit 143. After the verification of the first message authentication code passes, the identity provider 140 generates the second challenge data and the second message authentication code in the TEE unit 142, and sends the second challenge data and the second message authentication code to the TEE device 130 through the transceiver unit 143 at 804.
[0156] After the TEE device 130 receives the second challenge data and the second message authentication code from the identity provider 140, the identity provider 140 decrypts and verifies the second message authentication code in the TEE unit 143. After the verification of the second message authentication code passes, the TEE device 130 notifies the identity provider 140 through the transceiver unit 133 at 805 that the identity authentication has passed.
[0157] After the identity provider 140 receives the reply that the identity authentication of the TEE device 130 has passed, at 806: it agrees that the user device 110 passes the identity authentication to the user device 110. This information can be sent to the user device 110 through the transceiver unit 143, and the identity authentication is completed.
[0158] The above will be specifically described below in conjunction with the accompanying drawings Figure 7 and Figure 8 the processes of the TEE units of the TEE device and the identity provider respectively performing registration and authentication in the above
[0159] Figure 9 shows the process of the TEE unit 142 of the identity provider 140 performing the registration operation in the embodiment of the present application.
[0160] As Figure 9 shown, at 901: according to the registered information, the corresponding key and signature value of the user device 110 are generated. As an example, in the TEE unit 142, the signature value Sign(RND1, RND2) corresponding to the private key of the identity provider 140 is calculated Ski , where RND1 and RND2 are two random numbers generated by the identity provider 140, and Ski is the certificate private key of the identity provider 140.
[0161] At the same time, the TEE unit 142 uses the password of the registered identity authentication account to generate the key of the user device 110, where the key includes the symmetric encryption key (Encrypt Key, EK) for encrypting data and the symmetric verification key (Authentication Key, AK) for authentication, where:
[0162] EK = KDF1(Hash(PWD), RND1);
[0163] AK = KDF2(Hash(PWD), RND2)
[0164] Hash(PWD) is the hash of the user password PWD, and KDF1 and KDF2 are key derivation algorithms (Key Derivation Function, KDF) respectively.
[0165] After that, the transceiver unit 143 sends the signature value and the registered information of the user device to the TEE device 130 at 902. Among them, the signature value is Sign(RND1, RND2) Ski , and the registered information of the user device 110 may include the user password PWD and the device ID.
[0166] At 903: decrypt and verify the message authentication code. After the identity provider 140 receives the challenge data C and the value (Tag) of the message authentication code (Message Authentication Code, MAC) from the TEE device 130, where C = E(RND2, K p , ID p_dev , MF) EK ; Tag = MAC(RND2, K p , ID p_dev , MF) AK . The TEE unit 142 decrypts the challenge data C and the message authentication code through EK and AK, and obtains RND2, K p , ID p_dev and MF, where K p is the shared symmetric key between the user and the authentication center, ID p_dev is the device ID of the user device 110, and MF is the multi-factor authentication data (Multi-factor, MF) required for authentication. Subsequently, the TEE unit 142 verifies the MAC.
[0167] If the MAC verification passes, then the TEE unit 142 stores the multi-factor authentication data MF and the shared symmetric key K p .
[0168] Figure 10 shows the process of the TEE unit 132 of the TEE device 130 performing the auxiliary registration operation according to the embodiments of the present application.
[0169] As Figure 10 shown, the TEE device 130 receives the signature value Sign(RND1, RND2) from the identity provider 140 SkiAfter obtaining the device ID of the user device 110, the TEE unit 132 verifies the signature value at 1001. The TEE device 130 verifies the signature value Sign(RND1, RND2) through the public key of the certificate of the identity provider 140 pre-stored by itself Ski for verification
[0170] At 1002: When the signature value verification is passed, challenge data and a message authentication code are generated. After the TEE unit 132 verifies the signature value Sign(RND1, RND2) Ski and passes the verification, the TEE unit 132 generates EK = KDF1(Hash(PWD), RND1) and AK = KDF2(Hash(PWD), RND2), and generates the shared symmetric key K p .
[0171] Subsequently, the TEE unit 132 uses the above parameters and the ID of the user device 110 p_dev and K p to calculate the challenge data C and the value of MAC, where
[0172] C = E(RND2, K p , ID p_dev , MF) EK ;
[0173] Tag = MAC(RND2, K p , ID p_dev , MF) AK
[0174] where, RND2, K p , ID p_dev , MF These data use EK for symmetric encryption to generate C, and use AK for symmetric encryption to generate the value of MAC (Tag). Then the TEE device 130 sends the challenge data and the message authentication code to the identity provider 140
[0175] Figure 11 shows the process of the TEE unit 142 of the identity provider 140 performing the authentication operation in the embodiment of the present application. For Figure 9 the content already described, it will be briefly described or not described again below
[0176] At 1101: According to the registered information, the corresponding key and signature value of the user device 110 are generated. The process executed by the TEE unit 142 is similar to the process of block 901 in Figure 9 and will not be described again here
[0177] At 1102: Decrypt and verify the first message authentication code. After the identity provider 140 receives the first challenge data C1 and the value Tag1 of the first message authentication code MAC from the TEE device 130, the TEE unit 142 decrypts the challenge data C1 and Tag1 using the EK and AK. Subsequently, the TEE unit 142 verifies the MAC.
[0178] If the MAC verification passes, then, at 1103: When the first message authentication code passes the verification, generate the second challenge data and the second message authentication code. As an example, the TEE unit 142 generates new keys EK' and AK' based on the key K between the user device 110 and the service provider (which can be, for example, the identity provider 140 or the operator of the application) where the user device 110 logs in to the application ps , and the key K between the identity provider 140 and the service provider sp , as follows:
[0179] EK' = KDF1(K sp , RND3),
[0180] AK' = KDF2(K sp , RND3),
[0181] where RND3 is a random number generated by the identity provider 140. After that, the TEE unit 142 calculates the credential value T using the keys EK' and AK' as follows:
[0182] T = E(K ps , ID p_dev ) EK' , RND3, MAC(K PS , RND3, ID p_dev ) AK'
[0183] The TEE unit 142 calculates the second challenge data and the second message authentication code based on the credential value T and the key K ps where the second challenge data is C2 = E(K ps , T) EK , and the second message authentication code is Tag2 = MAC(K ps , T) AK . After that, the identity provider 140 sends the second challenge data and the second message authentication code to the TEE device 130.
[0184] Figure 12 Illustrates the process of the TEE unit 132 of the TEE device 130 performing the auxiliary authentication operation in the embodiments of the present application. For Figure 10 the content that has been described, it will be briefly described below or will not be repeated.
[0185] As Figure 12 shown, after the TEE device 130 receives the signature value Sign(RND1, RND2)Ski from the identity provider 140, the TEE unit 132 verifies the signature value at 1201. Here, reference can be made to Figure 10 the description of block 1001, which will not be elaborated here.
[0186] At 1202: When the signature value verification passes, the first challenge data and the first message authentication code are generated. After the TEE unit 132 verifies the signature value Sign(RND1, RND2) Ski and passes, the TEE unit 132 generates EK = KDF1(Hash(PWD), RND1, RND2, K p , MF) and AK = KDF2(Hash(PWD), RND1, RND2, K p , MF). Subsequently, the TEE unit 132 calculates the first challenge data C1 and the value of the first message authentication code Tag1 using the above parameters, where C1 = E(RND2) EK , Tag1 = MAC(RND2) AK . After that, the TEE device 130 sends the first challenge data C1 and the value of the first message authentication code Tag1 to the identity provider 140.
[0187] After the TEE device 130 receives the second challenge data and the second message authentication code from the identity provider 140, the TEE unit 132 decrypts and verifies the second message authentication code at 1203. The TEE unit 132 uses EK and AK to decrypt the second challenge data C2 = E(K ps , T) EK , the value of the second message authentication code Tag2 = MAC(K ps , T) AK and verifies Tag2.
[0188] If the verification passes, the TEE unit 132 stores the key K ps and the credential T at 1204 when the second message authentication code passes the verification.
[0189] According to the embodiments of the present application, by utilizing the TEE mechanism, the security of the entire authentication process of the user device is protected by the TEE. In addition, the identity authentication method of the present application can be deployed on non-TEE electronic devices, enabling non-TEE devices to provide secure SSO services for users with the help of TEE devices such as smartphones, solving the problem that non-TEE devices cannot obtain security protection.
[0190] Now refer toFigure 13 , which shows a block diagram of an electronic device 1300 according to an embodiment of the present application. The electronic device 1300 can be any one of the user device 110, the TEE device 130, the associated device 160, and the identity provider 140. The device 1300 may include one or more processors 1302, system control logic 1308 connected to at least one of the processors 1302, system memory 1304 connected to the system control logic 1308, non-volatile memory (NVM) 1306 connected to the system control logic 1308, and a network interface 1310 connected to the system control logic 1308.
[0191] The processor 1302 may include one or more single-core or multi-core processors. The processor 1302 may include any combination of general-purpose processors and dedicated processors (e.g., microprocessors, application processors, etc.). In the embodiments herein, the processor 1302 may be configured to implement Figure 1 the respective functions of the control units (111, 131, and 141) shown and execute one or more embodiments according to the various embodiments shown in Figures 2 - 12 . In some other embodiments, the processor 1302 may be configured to implement Figure 1 the respective functions of the TEE units (132 and 142) shown and execute one or more embodiments according to the various embodiments shown in Figures 2 - 12 .
[0192] In a possible implementation, the processor 1302 may run an operating system, e.g., Android, iOS, Windows OS, Linux, and HarmonyOS, etc. In some other possible implementations, the processor 1302 may run a specific application.
[0193] A memory may also be provided in the processor 1302 for storing instructions and data. In some embodiments, the memory in the processor 1302 is a cache memory. This memory may save the instructions or data that the processor 1302 has just used or recycled. If the processor 1302 needs to use the instruction or data again, it can be directly called from the memory. This avoids repeated accesses, reduces the waiting time of the processor 1302, and thus improves the efficiency of the system.
[0194] In some embodiments, the system control logic 1308 may include any suitable interface controller to provide any suitable interface to at least one of the processors 1302 and / or any suitable device or component communicating with the system control logic 1308.
[0195] In some embodiments, the system control logic 1308 may include one or more memory controllers to provide an interface to the system memory 1304. The system memory 1304 may be used to load and store data and / or instructions. In some embodiments, the memory 1304 of the device 1300 may include any suitable volatile memory, such as a suitable dynamic random access memory (DRAM).
[0196] The NVM / memory 1306 may include one or more tangible, non-transitory computer-readable media for storing data and / or instructions. In some embodiments, the NVM / memory 1306 may include any suitable non-volatile memory such as flash memory and / or any suitable non-volatile storage device, such as at least one of a hard disk drive (HDD), a compact disc (CD) drive, and a digital versatile disc (DVD) drive.
[0197] The NVM / memory 1306 may include a portion of the storage resources mounted on the device 1300, or it may be accessible by the device but not necessarily part of the device. For example, the NVM / storage 1306 may be accessed via the network interface 1310 over a network.
[0198] Specifically, the system memory 1304 and the NVM / memory 1306 may respectively include: a temporary copy and a permanent copy of the instructions 1320. The instructions 1320 may include: instructions that, when executed by at least one of the processors 1302, cause the device 1300 to implement the methods as shown in Figures 3 - 6 and Figures 9 - 12 In some embodiments, the instructions 1320, hardware, firmware, and / or its software components may alternatively be located in the system control logic 1308, the network interface 1310, and / or the processor 1302.
[0199] The network interface 1310 may include a transceiver for providing a radio interface for the device 1300 to communicate with any other suitable device (such as a front-end module, an antenna, etc.) over one or more networks, thereby implementing the functions of the respective transceiver units (112, 133, and 143) as shown in Figure 1 In some embodiments, the network interface 1310 may be integrated with other components of the device 1300. For example, the network interface 1310 may be integrated with at least one of the processor 1302, the system memory 1304, the NVM / memory 1306, and a firmware device (not shown) having instructions. When at least one of the processors 1302 executes the instructions, the device 1300 implements one or more of the various embodiments as shown in Figures 2 - 12 the various embodiments shown.
[0200] The network interface 1310 may further include any suitable hardware and / or firmware to provide a multiple-input multiple-output radio interface. For example, the network interface 1310 may be a network adapter, a wireless network adapter, a telephone modem, and / or a wireless modem.
[0201] In one embodiment, at least one of the processors 1302 may be logically encapsulated with one or more controllers for the system control logic 1308 to form a system-in-package (SiP). In one embodiment, at least one of the processors 1302 may be integrated with the logic of one or more controllers for the system control logic 1308 on the same die to form a system-on-chip (SoC).
[0202] The device 1300 may further include: an input / output (I / O) device 1312. The I / O device 1312 may include a user interface that enables a user to interact with the device 1300; the design of the peripheral component interface enables peripheral components to also interact with the device 1300. In some embodiments, the device 1300 further includes sensors for determining at least one of environmental conditions and location information related to the device 1300.
[0203] In some embodiments, the user interface may include, but is not limited to, a display (e.g., a liquid crystal display, a touch screen display, etc.), a speaker, a microphone, one or more cameras (e.g., a still image camera and / or a video camera), a flashlight (e.g., a light-emitting diode flash), and a keyboard.
[0204] In some embodiments, the peripheral component interface may include, but is not limited to, a non-volatile memory port, an audio jack, and a power interface.
[0205] In some embodiments, the sensors may include, but are not limited to, a gyroscope sensor, an accelerometer, a proximity sensor, an ambient light sensor, and a positioning unit. The positioning unit may also be part of or interact with the network interface 1310 to communicate with components of a positioning network (e.g., Global Positioning System (GPS) satellites).
[0206] Each method embodiment of the present application may be implemented in software, magnetic, firmware, etc.
[0207] Program code may be applied to input instructions to perform the various functions described herein and generate output information. The output information may be applied to one or more output devices in a known manner. For the purposes of the present application, a processing system includes any system having a processor such as, for example, a digital signal processor (DSP), a microcontroller, an application specific integrated circuit (ASIC), or a microprocessor.
[0208] The program code can be implemented in a high-level procedural language or an object-oriented programming language to communicate with the processing system. When needed, the program code can also be implemented in an assembly language or a machine language. In fact, the mechanisms described in this article are not limited to the scope of any specific programming language. In any case, the language can be a compiled language or an interpreted language.
[0209] One or more aspects of at least one embodiment can be implemented by representative instructions stored on a computer-readable storage medium, where the instructions represent various logics in a processor, and when read by a machine, cause the machine to fabricate the logics for performing the techniques described herein. These representations, referred to as "IP cores", can be stored on a tangible computer-readable storage medium and provided to multiple customers or production facilities to be loaded into a manufacturing machine that actually fabricates the logic or the processor.
[0210] In some cases, an instruction converter can be used to convert instructions from a source instruction set to a target instruction set. For example, the instruction converter can transform (e.g., using static binary translation, dynamic binary translation including dynamic compilation), morph, emulate, or otherwise convert the instructions into one or more other instructions to be processed by the core. The instruction converter can be implemented in software, hardware, firmware, or a combination thereof. The instruction converter can be on the processor, outside the processor, or partially on the processor and partially outside the processor.
[0211] In some cases, the disclosed embodiments can be implemented in hardware, firmware, software, or any combination thereof. The disclosed embodiments can also be implemented as instructions carried or stored on one or more transient or non-transient machine-readable (e.g., computer-readable) storage media, which can be read and executed by one or more processors. For example, the instructions can be distributed via a network or via other computer-readable media. Thus, the machine-readable medium can include any mechanism for storing or transmitting information in a form readable by a machine (e.g., a computer), but not limited to, floppy disks, optical disks, compact discs read-only memory (CD-ROMs), magneto-optical discs, read-only memory (ROMs), random access memory (RAMs), erasable programmable read-only memory (EPROMs), electrically erasable programmable read-only memory (EEPROMs), magnetic or optical cards, flash memory, or a tangible machine-readable memory for transmitting information via electrical, optical, acoustic, or other forms of propagated signals (e.g., carrier waves, infrared signals, digital signals, etc.) over the Internet. Thus, the machine-readable medium includes any type of machine-readable medium suitable for storing or transmitting electronic instructions or information in a form readable by a machine (e.g., a computer).
[0212] In the accompanying drawings, some structural or method features are shown in a particular arrangement and / or order. However, it should be understood that such a particular arrangement and / or ordering may not be required. In some embodiments, these features may be arranged in a manner and / or order different from that shown in the illustrative drawings. Additionally, the inclusion of a structural or method feature in a particular figure does not imply that such a feature is required in all embodiments, and in some embodiments, these features may not be included or may be combined with other features.
[0213] It should be understood that although the terms "first", "second", etc. may be used herein to describe various elements or data, these elements or data should not be limited by these terms. These terms are only used to distinguish one feature from another. For example, without departing from the scope of the exemplary embodiments, a first feature may be referred to as a second feature, and similarly, a second feature may be referred to as a first feature.
[0214] As described above, the above is only the specific implementation manner of the embodiments of the present application, but the protection scope of the embodiments of the present application is not limited thereto. Any changes or substitutions within the technical scope disclosed in the embodiments of the present application should be covered by the protection scope of the embodiments of the present application. Therefore, the protection scope of the embodiments of the present application should be subject to the protection scope of the claims.
Claims
1. An authentication method for an identity authentication system, wherein the identity authentication system includes a user device without a trusted execution environment (TEE) unit, a TEE device with a TEE unit, and an identity provider (IDP), characterized in that, The method includes: The IDP is used for: determining a TEE device associated with the user device according to the authentication request of the user device; The user device is used for: establishing a communication connection with the TEE device and sending the identity authentication parameters of the user device to the TEE device; The TEE device is used for: sending the identity authentication parameters of the user device to the IDP; The IDP is further used for: receiving the identity authentication parameters of the user device sent by the TEE device, and performing the identity authentication on the user of the user device according to the identity authentication parameters and by using the TEE device.
2. The method according to claim 1, characterized in that, The user device is further used for: sending a mark indicating that the user device does not have the TEE unit to the IDP.
3. The method according to claim 1, characterized in that, Determining a TEE device associated with the user device includes: The IDP receives the identity authentication account from the user device and the identity authentication account from the TEE device; When the identity authentication account of the user device is the same as or associated with the identity authentication account from the TEE device, the IDP determines that the user device has an associated TEE device.
4. The method according to claim 1, characterized in that, The identity authentication system further includes an associated device, and the method further includes: The associated device receives the identity authentication account from the user device and at least partially a mark indicating that the user device does not have the TEE unit; The associated device receives the identity authentication account from the TEE device and at least partially a mark indicating that the TEE device has the TEE unit; and When the associated device determines that the identity authentication account of the user device is the same as the identity authentication account of the TEE device, the associated device associates the user device with the TEE device for the identity authentication account.
5. The method according to claim 4, characterized in that, Determining a TEE device associated with the user device includes: The IDP sends a request to the associated device asking whether the user device has an associated TEE device; the IDP determines the TEE device associated with the user device according to the response of the associated device.
6. An authentication method for a user device, wherein the user device does not have a trusted execution environment (TEE) unit, characterized in that, Includes: Establishing a communication connection with a TEE device having the TEE unit, where the TEE device is associated with the user device; and Sending the identity authentication parameters of the user device to the TEE device, so that after the TEE device sends the identity authentication parameters to the identity provider (IDP), the IDP performs identity authentication on the user of the user device according to the identity authentication parameters and by using the TEE device.
7. The method according to claim 6, characterized in that, Further includes: Sending at least partially a mark indicating that the user device does not have the TEE unit to the IDP; Receiving a request from the IDP to confirm whether to use the TEE device for the identity authentication; and Sending information to the IDP to determine to use the TEE device to perform the identity authentication on the user of the user device.
8. The method according to any one of claims 6-7, characterized in that, Further includes: Sending the identity authentication account of the user device to the IDP.
9. The method according to any one of claims 6-7, characterized in that, Further includes: Send the authentication account of the user equipment and a mark indicating at least partially that the user equipment does not have the TEE unit to an associated device.
10. The method according to any one of claims 6-7, characterized in that, When the authentication account of the user equipment is the same as or associated with the authentication account from the TEE device, the TEE device is associated with the user equipment.
11. The method according to any one of claims 6-7, characterized in that, The authentication parameter includes at least one of the device serial number and the device identification number of the user equipment.
12. The method according to any one of claims 6-11, characterized in that, The user equipment has another authentication account, where the another authentication account of the user equipment is the same as the authentication account of another TEE device, and the another TEE device has the TEE unit.
13. An authentication method for a trusted execution environment (TEE) device, wherein the TEE device has a TEE unit; characterized in that, Comprising: Establish a communication connection with a user equipment, where the user equipment does not have the TEE unit, and the TEE device is associated with the user equipment; Receive authentication parameters from the user equipment, where the authentication parameters are used for authenticating the user of the user equipment; and Send the authentication parameters to an identity provider (IDP) for the IDP to authenticate the user of the user equipment according to the authentication parameters and by using the TEE device.
14. The method according to claim 13, characterized in that, The establishing a communication connection with the user equipment includes: Receive a request from the IDP to determine whether the TEE device is online; In response to the request, establish a communication connection with the user equipment; and Send information that the TEE device is online to the IDP.
15. The method according to any one of claims 13-14, characterized in that, Further comprising: Send the authentication account of the TEE device and a mark indicating at least partially that the TEE device has the TEE unit to an associated device.
16. The method according to any one of claims 13-14, characterized in that, Further comprising: Send the authentication account of the TEE device and a mark indicating at least partially that the TEE device has the TEE unit to the IDP.
17. The method according to any one of claims 13-14, characterized in that, When the authentication account of the user equipment is the same as or associated with the authentication account from the TEE device, the TEE device is associated with the user equipment.
18. The method according to any one of claims 13-16, characterized in that, The authentication parameter includes at least one of the device serial number and the device identification number of the user equipment.
19. An authentication method for an identity provider (IDP), characterized in that, Comprising: Receive an authentication request of a user equipment, where the user equipment does not have a trusted execution environment (TEE) unit; In response to the authentication request, determine whether the user equipment has an associated TEE device, where the TEE device has the TEE unit; and At least partially based on the case that the user equipment has an associated TEE device, receive the authentication parameters of the user equipment sent by the TEE device, and authenticate the user of the user equipment according to the authentication parameters and by using the TEE device.
20. The method according to claim 19, characterized in that, Further comprising: Receive information from the user equipment indicating that the user equipment does not have a trusted execution environment (TEE) unit.
21. The method according to claim 19, characterized in that, The determining whether the user equipment has an associated TEE device further includes: Send a request to an associated device to inquire whether the user equipment has an associated TEE device.
22. The method according to claim 19, characterized in that, Determining whether the user equipment has an associated TEE device further includes: Receiving an authentication account from the user equipment and an authentication account from the TEE device; Determining that the user equipment has the associated TEE device when the authentication account of the user equipment is the same as or associated with the authentication account from the TEE device; and Determining that the user equipment does not have the associated TEE device when the authentication account of the user equipment is different from or not associated with the authentication account from the TEE device.
23. The method according to any one of claims 19-22, characterized in that, It further includes: When the user equipment has the associated TEE device, sending a request to the TEE device to confirm that the TEE device is online; Receiving information from the TEE device confirming that the TEE device is online; And Receiving the authentication parameters of the user equipment sent by the TEE device and performing authentication on the user of the user equipment according to the authentication parameters.
24. The method according to any one of claims 19-23, characterized in that, Performing the authentication on the user of the user equipment according to the authentication parameters and using the TEE device includes: Using the authentication parameters to perform authentication on the user of the user equipment by interacting with the TEE device based on encrypted data of the authentication parameters.
25. The method according to claim 24, characterized in that, The encrypted data includes a challenge value encrypted with an encryption key and a credential value encrypted with a verification key, where the encryption key and the verification key are generated based on the authentication parameters.
26. The method according to claims 19-25, characterized in that, The authentication parameters include at least one of the device serial number and the device identification number of the user equipment.
27. An identity authentication method for associated devices, characterized in that, It includes: Receiving authentication accounts sent by the user equipment and the TEE device, where the user equipment does not have a trusted execution environment (TEE) unit and the TEE device has a TEE unit; Establishing an association between the user equipment and the TEE device according to the received authentication accounts; Responding to a request from an identity provider (IDP), determining the TEE device associated with the user equipment requesting authentication, so that the TEE device sends the authentication parameters of the user equipment to the IDP, and the IDP performs authentication on the user of the user equipment according to the authentication parameters and using the TEE device.
28. The identity authentication method according to claim 27, characterized in that, Establishing an association between the user equipment and the TEE device according to the received authentication accounts includes: when it is determined that the authentication account of the user equipment is the same as or associated with the authentication account of the TEE device, associating the user equipment with the TEE device.
29. The identity authentication method according to claim 27, characterized in that, Responding to a request from an identity provider (IDP), determining the TEE device associated with the user equipment requesting authentication includes: Receiving a request from the identity provider (IDP) to query whether the user equipment is associated with the TEE device; Querying that the user equipment is associated with the TEE device; and Returning information that the user equipment is associated with the TEE device to the IDP.
30. A computer-readable storage medium, characterized in that, Instructions are stored on the computer-readable storage medium, and when executed on a computer, cause the computer to perform the method according to any one of claims 1-29.
31. An electronic device, characterized in that, Comprising: a memory for storing instructions to be executed by one or more processors of the electronic device, and a processor for executing the instructions in the memory to perform the method according to any one of claims 1-29.