Authentication method and electronic equipment

By using a cross-device authentication method and a second electronic device for identity authentication, the problem of smart devices failing to successfully collect user identity information is solved, improving the convenience and reliability of authentication and enhancing the user experience.

CN121765709APending Publication Date: 2026-03-31HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2021-03-24
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

When using smart devices, authentication failures due to the device's inability to successfully collect identity information negatively impact the user experience.

Method used

By using a cross-device authentication method, a second electronic device is used for identity authentication, which solves the problem that the first electronic device cannot successfully collect user identity information. This includes sending a request message to obtain the authentication result and matching preset information to determine whether the authentication is successful or not.

Benefits of technology

It improves the convenience of cross-device authentication, enhances the user experience, and ensures the reliability and security of authentication results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121765709A_ABST
    Figure CN121765709A_ABST
Patent Text Reader

Abstract

The invention provides an authentication method and electronic equipment, the authentication method is executed by first electronic equipment, the method comprises the following steps: the first electronic equipment receives an authentication request, and the authentication request is used for requesting to authenticate a first service; the first electronic equipment determines a risk security level corresponding to the first service; then, the first electronic equipment determines an authentication mode meeting the security risk level according to the risk security level; and finally, the first electronic equipment schedules M pieces of electronic equipment to authenticate the first service according to the authentication mode, and M is a positive integer. According to the method, the authentication mode of the first service meets the corresponding risk security level, so that the security of the authentication result can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application. The original application has the application number 202110313313.2 and the original application date is March 24, 2021. The entire contents of the original application are incorporated herein by reference.

[0002] Cross-references to related applications

[0003] This application claims priority to Chinese Patent Application No. 202110162842.7, filed on February 5, 2021, entitled "An Authentication Method and Electronic Device"; this application also claims priority to Chinese Patent Application No. 202010393895.5, filed on May 11, 2020, entitled "An Authentication Method, Device, and Readable Storage Medium"; this application also claims priority to Chinese Patent Application No. 202110155795.3, filed on February 4, 2021, entitled "A Cross-Device Authentication Method and Electronic Device"; this application... Please also claim priority to Chinese Patent Application No. 202110185361.8, filed on February 10, 2021, entitled "A Data Association Method and Electronic Device"; this application also claims priority to Chinese Patent Application No. 202011063402.8, filed on September 30, 2020, entitled "A Cross-Device Authentication Method and Related Apparatus"; this application also claims priority to Chinese Patent Application No. 202011070212.9, filed on September 30, 2020, entitled "A Multi-Device Collaborative Authentication Method, Apparatus, and System". All of the above are incorporated herein by reference. Technical Field

[0004] This application relates to the field of terminal technology, and in particular to an authentication method and electronic device. Background Technology

[0005] With the development of biometric and image recognition technologies, in addition to the traditional method of authenticating users based on usernames and passwords, users can also be authenticated using their biometric information (such as faces, fingerprints, voiceprints, etc.).

[0006] In practical applications, when a user uses the currently operating smart device to perform local authentication for the service being accessed, the authentication may fail because the smart device cannot successfully collect the user's identity information locally. When the identity authentication fails, the smart device will refuse to execute the service, which will prevent the user from accessing the service normally and affect the user experience. Summary of the Invention

[0007] This application provides an authentication method and electronic device for cross-device authentication, which can improve the convenience of cross-device authentication and effectively enhance the user experience.

[0008] In a first aspect, the method is applicable to a communication system consisting of at least two electronic devices. The method can be executed by a first electronic device in the communication system, wherein the first electronic device and the second electronic device are connected. The method includes: the first electronic device receiving a first operation; in response to the first operation, the first electronic device performing local authentication on the first operation; in response to detecting that the local authentication result of the first electronic device is authentication failure, the first electronic device initiating cross-device authentication, wherein the cross-device authentication is used for the first electronic device to authenticate through the second electronic device; the first electronic device obtaining the cross-device authentication result; and then, if the first electronic device determines that the cross-device authentication result is authentication success, it executes the instruction corresponding to the first operation; otherwise, it does not execute the instruction corresponding to the first operation.

[0009] In this embodiment of the application, the above method can achieve cross-device authentication, improve the convenience of cross-device authentication, and effectively enhance the user experience.

[0010] In one possible design, the first electronic device initiates cross-device authentication, including: the first electronic device sending a first request message to a second electronic device, the first request message being used to request the local authentication result of the second electronic device. The first electronic device obtaining the cross-device authentication result includes: the first electronic device receiving a first response message from the second electronic device, the first response message including the cross-device authentication result, which is the local authentication result of the second electronic device.

[0011] In this embodiment of the application, the first electronic device can obtain the authentication result of the second electronic device for the first operation from the second electronic device through the above method, thereby solving the problem that the first electronic device cannot successfully collect the user's identity information, resulting in authentication failure.

[0012] In one possible design, the first electronic device initiates cross-device authentication, including: the first electronic device sending a second request message to a second electronic device, the second request message being used to request the identity authentication information of the second electronic device; then the first electronic device receiving a second response message from the second electronic device, the second response message including the identity authentication information of the second electronic device. The first electronic device obtaining the cross-device authentication result includes: the first electronic device authenticating the first operation based on the identity authentication information of the second electronic device, generating a cross-device authentication result.

[0013] In this embodiment of the application, the first electronic device can obtain identity authentication information, such as facial information, from the second electronic device through the above method. The first electronic device then uses this identity authentication information to authenticate the first operation, thereby solving the problem that the first electronic device cannot successfully collect the user's identity information, resulting in authentication failure.

[0014] In one possible design, the first electronic device stores preset information; the first electronic device can match the authentication information sent by the second electronic device with the preset information to generate a matching result; when the matching result is greater than a first preset threshold, the local authentication result of the second electronic device is determined to be successful; otherwise, the first electronic device determines that the local authentication result of the second electronic device is unsuccessful.

[0015] In this embodiment, since the first electronic device can obtain identity authentication information from the second electronic device, the problem of the first electronic device being unable to successfully collect the user's identity information can be solved. Furthermore, the first electronic device uses local preset information to match the obtained identity information, and then uses the matching result for authentication. The authentication result can indicate whether the first electronic device has successfully authenticated the user's identity.

[0016] In one possible design, the first electronic device performs local authentication for the first operation in the following manner: the first electronic device stores preset information; in response to the first operation, the first electronic device obtains the authentication information of the user who input the first operation; then the first electronic device matches the user's authentication information with the preset information; and the first electronic device determines whether its local authentication result is successful based on the matching result. For example, if the first electronic device does not obtain complete authentication information of the user who input the first operation, the local authentication result of the first electronic device may fail.

[0017] In one possible design, the first electronic device determines whether its local authentication result is successful based on the matching result, including: the first electronic device comparing the matching degree in the matching result with a second preset threshold; when the matching degree is greater than the second preset threshold, the first electronic device determines that its local authentication result is successful; otherwise, the first electronic device determines that its local authentication result is unsuccessful. For example, if the first electronic device does not obtain complete authentication information from the user who input the first operation, the matching result may be less than the second preset threshold, resulting in the first electronic device's local authentication result failing.

[0018] In one possible design, the authentication information includes any one or more of facial information, fingerprint information, voiceprint information, iris information, and touch screen behavior information; the preset information includes any one or more of facial information, fingerprint information, voiceprint information, iris information, and touch screen behavior information.

[0019] In one possible design, the first operation is any one of the following: screen unlocking, application unlocking, or operation on a functional control within the application.

[0020] In one possible design, the first electronic device and the second electronic device log in to the same user account, which can be one of the following: an instant messaging account, an email account, or a mobile phone number.

[0021] In one possible design, the method further includes: a first electronic device detecting the distance between the first electronic device and a second electronic device; the first electronic device determining that the cross-device authentication result is successful, and in response to detecting that the distance between the first electronic device and the second electronic device is less than a first preset distance, the first electronic device executing the instruction corresponding to the first operation.

[0022] In one possible design, the first electronic device detects the distance between itself and the second electronic device using Bluetooth positioning technology, UWB positioning technology, or Wi-Fi positioning technology.

[0023] In one possible design, the first electronic device and the second electronic device are connected, including: the first device establishing a connection with the second device via a near-field communication protocol; wherein the near-field communication protocol includes one or more of WiFi, UWB, Bluetooth, Zigbee, or NFC protocols.

[0024] In one possible design, before the first electronic device initiates cross-device authentication, the following steps are also included: the first electronic device further receives a second operation, the second operation being used to trigger the activation of the cross-device authentication function; in response to the second operation, and in response to detecting that the local authentication result of the first electronic device is authentication failure, the first electronic device initiates cross-device authentication.

[0025] In one possible design, the method further includes: a first electronic device acquiring security status information of a second electronic device; the first electronic device determining that the cross-device authentication result is successful, and determining that the security status information of the second electronic device indicates that the second electronic device is in a secure state; and the first electronic device executing the instruction corresponding to the first operation. For example, the first electronic device acquires the detection result of a security application on the second electronic device, thereby determining, based on the detection result, that the second electronic device does not have Trojans or other viruses, and also has a secure execution chip; therefore, it can be determined that the second electronic device is a secure device, and the information obtained from the second electronic device is also secure.

[0026] Secondly, embodiments of this application provide an authentication method applicable to a communication system consisting of at least two electronic devices. The method can be executed by a first electronic device in the communication system. The method includes: the first electronic device receiving an authentication request for authenticating a first service; the first electronic device determining an authentication method corresponding to the first service; and scheduling M electronic devices to authenticate the first service according to the authentication method, where M is a positive integer.

[0027] This method improves the security of authentication results by having at least two electronic devices collaboratively authenticate the same service using one or more authentication factors.

[0028] In one possible design, the first electronic device determines the authentication method corresponding to the first service, including: the first electronic device determines the risk security level corresponding to the first service, and then the first electronic device determines the authentication method that meets the security risk level based on the risk security level.

[0029] In this method, the authentication of the first service meets the corresponding risk and security level, thus improving the security of the authentication result. It allows for the use of authentication factors provided by at least two electronic devices to jointly authenticate the same service, thereby ensuring the reliability of the authentication result and enhancing the device's authentication security level. For example, for a high-security door opening service, the camera and door lock can be used in conjunction to perform facial recognition and fingerprint authentication, ensuring the reliability of the authentication result and improving the device's authentication security level.

[0030] In one possible design, the first electronic device determines an authentication method that meets the security risk level based on the risk level, including: the first electronic device determining available authentication factors and available data acquisition capabilities associated with the available authentication factors, and then determining an authentication method that meets the security risk level based on the risk level, the available authentication factors, and the available data acquisition capabilities associated with the available authentication factors.

[0031] In this method, during the process of determining the authentication method, a selection is made from available authentication factors and available data collection capabilities associated with those factors to avoid the problem of data collection failure caused by the unavailability of the selected authentication factor's data collection method.

[0032] In one possible design, when the authentication request includes biometrics, the biometrics are identified to determine the user corresponding to the biometrics. Then, it is determined whether the user has the authority to execute the first service. If the user has the authority to execute the first service, the first electronic device schedules M electronic devices to authenticate the first service according to the authentication method. Otherwise, no more M electronic devices are scheduled to authenticate the first service.

[0033] This method can further determine the permissions of the user performing the operation, preventing users without the necessary permissions from accessing the primary service and ensuring the security of access to the primary service.

[0034] In one possible design, the first electronic device determines an authentication method that meets the risk security level based on the risk security level, including: the first electronic device determining available authentication factors associated with the user, as well as authentication capabilities and available data collection capabilities associated with the available authentication factors; and the first electronic device determining an authentication method that meets the risk security level based on the risk security level, the available authentication factors, the available authentication capabilities, and the available data collection capabilities.

[0035] In this method, during the process of determining the authentication method, a selection is made from available authentication factors and the available collection and authentication capabilities associated with the available authentication factors. This avoids the problem of collection failure due to the unavailability of the collection method of the selected authentication factor, or the problem of authentication failure due to the unavailability of the authentication method of the selected authentication factor.

[0036] In one possible design, the first electronic device determines the authentication method based on the risk and security level, including: the first electronic device uses a decision strategy to determine the authentication method that meets the security risk level, wherein the decision strategy includes, but is not limited to, at least one of the following: prioritizing the use of collected authentication factors for authentication; prioritizing the use of collection capabilities with user-insensible features to collect authentication factors; prioritizing the use of collection capabilities on the user's near-end device to collect authentication factors, wherein the near-end device is at least one of M electronic devices.

[0037] In this method, the authentication method determined by the first electronic device according to the above decision strategy is more suitable for the current authentication scenario, which can effectively improve authentication efficiency and enhance user experience.

[0038] In one possible design, after the first electronic device schedules M electronic devices to authenticate the first service, the process further includes: the first electronic device obtaining the authentication results of the M electronic devices; and then the first electronic device aggregating the authentication results of the M electronic devices to generate the final authentication result.

[0039] In this method, when the first electronic device uses at least two authentication factors to perform superimposed authentication for the same service, the final authentication result can be obtained by aggregating the at least two authentication results. This method can improve the reliability of the authentication result.

[0040] In one possible design, after the first electronic device schedules M electronic devices to authenticate the first service, the process further includes: if the authentication is successful, the first electronic device instructs an operating device to execute the first service, wherein the operating device is at least one of the first electronic device and the M electronic devices.

[0041] In this method, the first electronic device can only instruct the operating device to perform the first service after it has been authenticated according to the above method, which can ensure the security of access to the first service.

[0042] In one possible design, the first electronic device also synchronizes the resources in the M electronic devices to obtain a synchronized resource pool, wherein the resource pool includes the authentication factor, acquisition capability and authentication capability in the M electronic devices; The first electronic device determines an authentication method that meets the security risk level based on the aforementioned risk level, specifically including: The first electronic device determines the authentication method that meets the security risk level based on the risk level and the resource pool.

[0043] In this method, the first electronic device can obtain the authentication factors, collection capabilities and authentication capabilities of each electronic device in the device network by maintaining the resource pool. Therefore, it can determine the authentication method that meets the security risk level, which can enrich the authentication methods to a certain extent and make it easier for the first electronic device to use a more suitable authentication method to authenticate the first service.

[0044] In one possible design, the first electronic device is any one of the M electronic devices, or the first electronic device does not belong to the M electronic devices.

[0045] In one possible design, all M electronic devices are connected to the same local area network, and / or all M electronic devices are pre-bound to the same user account.

[0046] In one possible design, the first service is a door opening service, and the risk and security level corresponding to the door opening service is a high-risk security level. Alternatively, the operation that triggers access to the first service is a first operation on a smart home device, the first operation does not involve personal privacy data, and the risk security level corresponding to the first service is a low-risk security level. Alternatively, the operation that triggers access to the first service is a second operation on the smart home device. The second operation involves personal privacy data but the risk is moderate. The first service corresponds to a medium-risk security level. Alternatively, the operation that triggers access to the first service is a third operation on the smart home device. This third operation involves personal privacy data but carries a high risk, and the first service corresponds to a high-risk security level.

[0047] In one possible design, a first electronic device receives an authentication request, including: the first electronic device receives a target operation, the target operation being used to trigger the generation of the authentication request; the first electronic device determines an authentication method corresponding to a first service, including: the first electronic device determines a target security value required to execute the target operation, the target operation being used to trigger the execution of the first service; the first electronic device determines M1 authentication devices, M1 being a positive integer, the M1 authentication devices being devices capable of authenticating user information, the M1 authentication devices being included in the M electronic devices. The first electronic device schedules the M electronic devices to authenticate the first service according to the authentication method, including: the first electronic device obtains the authentication result of at least one of the M1 authentication devices; the first electronic device determines a total authentication security value based on the correspondence between the authentication method and authentication security value of the at least one authentication device, and the authentication result; if the total authentication security value is not less than the target security value, authentication is successful. When authentication is successful, the method further includes: triggering an operation device to execute the target operation.

[0048] In one possible implementation, the operating device is configured to receive a target operation request, which requests the execution of the target operation. It can be seen that, since a total authentication security value is determined based on the authentication result of at least one of the M1 authentication devices, and the correspondence between the authentication method and authentication security value of the at least one authentication device, and the operating device is triggered to execute the target operation if the total authentication security value is not less than the target security value required to execute the target operation, thereby providing the required authentication level for the target operation.

[0049] In one possible implementation, when M1 equals 1, the device receives a first authentication request, determines a target security value required to perform the target operation, identifies an authentication device, and determines the authentication result of at least one of the authentication devices. Based on the correspondence between the authentication method and authentication security value of the at least one authentication device, and the authentication result, the device determines the authentication security value corresponding to the authentication device. If the authentication security value corresponding to the authentication device is not less than the target security value, the device triggers the operation device to perform the target operation. When M1 equals 1, the authentication security value corresponding to the authentication device determined by the device is the total authentication security value mentioned in the method embodiment of the first aspect above.

[0050] In one possible implementation, the device determines the M1 authentication devices by: determining a set of authentication policy groups, which includes one or more authentication policies, wherein the total authentication security value corresponding to all authentication policies in the authentication policy group is not less than the target security value; and determining the authentication device corresponding to each authentication policy in the authentication policy group as one of the M1 authentication devices; wherein the M1 authentication devices include a first authentication device, or can be understood as referring to one of the M1 authentication devices as the first authentication device. The authentication policy group includes a first authentication policy, the first authentication policy includes a first authentication device, and a first authentication method corresponding to the first authentication device, and the first authentication policy corresponds to a first authentication security value. Thus, the device can authenticate user information by determining one authentication policy, or determine a combination of multiple authentication policies for collaborative authentication of user information, thereby providing the required level of identity authentication for the target operation.

[0051] In one possible implementation, during the process of determining M1 authentication devices, if the device identifies one authentication device among those currently in a communicably reachable state, and this authentication device uses an authentication method with an authentication security value greater than the target security value, then this authentication device can also be identified as one of the aforementioned M1 authentication devices. In this implementation, M1 is 1. Alternatively, in this implementation, the authentication policy group determined by the device includes only one authentication policy.

[0052] In one possible implementation, the authentication policy group also satisfies that each authentication policy in the group corresponds to a biometric authentication method. In this way, users can complete authentication solely through biometric authentication, eliminating the cumbersome process of entering a password.

[0053] In one possible implementation, at least one authentication policy in the authentication policy group has an authentication security value lower than the target security value, and / or the authentication policy group also satisfies that each authentication policy in the authentication policy group corresponds to a biometric authentication method. When a user completes authentication solely through biometric authentication, the cumbersome process of entering a password can be eliminated. Since at least one authentication policy has an authentication security value lower than the target security value, this implementation can combine authentication devices with lower authentication capabilities to complete an authentication requiring a higher level of security. Thus, when a user needs to perform an operation with high identity authentication requirements, several authentication devices with lower authentication capabilities can be used for collaborative authentication, thereby improving the security of identity authentication.

[0054] In one possible implementation, the authentication security value corresponding to each authentication policy in the authentication policy group is lower than the target security value, and / or the authentication policy group also satisfies that the authentication method corresponding to each authentication policy in the authentication policy group is biometric authentication. When a user completes authentication solely through biometric authentication, the cumbersome process of entering a password can be eliminated. Since the authentication security value corresponding to each authentication policy is lower than the target security value, it can be seen that in this implementation, an authentication requiring a high level of authentication can be completed using only authentication devices with relatively low authentication capabilities. Thus, when a user needs to perform an operation with high identity authentication requirements, several authentication devices with relatively low authentication capabilities can be used for collaborative authentication, thereby improving the security of identity authentication.

[0055] In one possible implementation, there is a preset correspondence between the target operation and the authentication policy group, and / or the authentication policy group also satisfies that each authentication policy in the authentication policy group corresponds to a biometric authentication method. When the user completes authentication solely through biometric authentication, the cumbersome process of entering a password can be eliminated. Since there is a preset correspondence between the target operation and the authentication policy group, it can be seen that in this implementation, the user can customize authentication policies for some operations, thus improving the flexibility of the solution.

[0056] In one possible implementation, at least one authentication policy in the authentication policy group has an authentication security value that is not lower than the target security value, and / or the authentication policy group also satisfies that each authentication policy in the authentication policy group uses biometric authentication. When a user completes authentication solely through biometric authentication, the cumbersome process of entering a password can be eliminated. Since at least one authentication policy in the authentication policy group has an authentication security value that is not lower than the target security value, the probability that the total authentication security value is not less than the target security value can be increased.

[0057] To improve the flexibility of the solution, in another possible implementation, the device determines the M1 authentication devices by identifying authentication devices that meet a preset condition as the M1 authentication devices. The preset condition is that the device and the first authentication device are in a communicative reachable state. This solution simplifies the process of determining the M1 authentication devices. In one possible implementation, if the device determines that only one authentication device is currently in a communicative reachable state during the process of determining the M1 authentication devices, then the device determines that communicative reachable authentication device as one of the aforementioned M1 authentication devices. In this implementation, M1 is 1.

[0058] In one possible implementation, the device is the operating device, or the device is a router, or the device is one of the M1 authentication devices, or the operating device is one of the M1 authentication devices, the device is an authentication device other than the operating device among the M1 authentication devices, or the device is located on a server.

[0059] In one possible implementation, when the device is one of M1 authentication devices, determining the authentication result of at least one of the M1 authentication devices includes: the device authenticating user information and determining the authentication result corresponding to the device; the device receiving a second authentication response from each of the M1 authentication devices other than itself, and determining the authentication result of at least one of the M1 authentication devices based on the second authentication response. The second authentication response is sent to the device by the at least one authentication device after completing the authentication of the user information; in this case, the authentication result may be authentication success or authentication failure. Alternatively, the second authentication response is sent to the device by the at least one authentication device after failing to complete the authentication of the user information within a predetermined time; in this case, the authentication device also sends a second authentication response to the device even if it fails to complete the authentication of the user information within the predetermined time, i.e., the authentication result is authentication failure. For example, the predetermined time may be a period of time starting from the receipt of the second authentication request, such as 10 seconds or 2 minutes after receiving the second authentication request. The second authentication response returned by the first authentication device is used to indicate the authentication result of the first authentication device. In other words, the device used to perform the authentication method may be one of M1 authentication devices, and in this case, the device may also perform authentication of user information.

[0060] In one possible implementation, when the device is not one of the M1 authentication devices—for example, if the device is a server, router, or operating device without authentication capabilities—the device receives a second authentication response from each of the M1 authentication devices and determines the authentication result of at least one of the M1 authentication devices based on the second authentication response. The second authentication response is sent to the device by the at least one authentication device after it has completed authenticating the user information; in this case, the authentication result may be successful or unsuccessful. Alternatively, the second authentication response is sent to the device by the at least one authentication device after it has failed to complete authenticating the user information within a predetermined time; in this case, the authentication result is unsuccessful. The second authentication response returned by the first authentication device is used to indicate the authentication result of the first authentication device.

[0061] In one possible implementation, when a first condition is met, i.e., the device is the operating device, the device triggers the operating device to perform the target operation, including: the device performing the target operation.

[0062] In another possible implementation, if the first condition is not met, and the device is not the operating device (e.g., the device is a router, or the device is one of the M1 authentication devices, or the operating device is one of the M1 authentication devices other than the operating device, or the device is a server), then the device triggers the operating device to execute the target operation, including: the device sending a first authentication success response to the operating device; wherein the first authentication success response is used to indicate that the device has successfully authenticated the target operation. Subsequently, after receiving the first authentication success response, the operating device can execute the aforementioned target operation.

[0063] In one possible implementation, after determining the target security value required to perform the target operation, and before determining the M1 authentication devices, the method further includes: if the operating device has authentication capabilities, the method determines that the authentication security value of the operating device is less than the target security value. Thus, when the authentication capabilities of the operating device are insufficient, assistance from other authentication devices is sought, thereby improving the rationality of the solution.

[0064] In another possible implementation, after the device determines the target security value required to perform the target operation, the method further includes: if the operating device has authentication capabilities, the device determines that the authentication security value of the operating device is not less than the target security value; if a first condition is met, the method further includes: the device authenticating the user information; if the device successfully authenticates the user information, the target operation is performed. If the first condition is not met, the method further includes: the device sending a third authentication request to the operating device, wherein the third authentication request requests the operating device to authenticate the user information, and if the authentication of the user information is successful, the target operation is performed. Thus, when the operating device has sufficient authentication capabilities, the authentication is performed by the operating device, thereby improving the rationality of the solution.

[0065] In one possible implementation, the device determines the target security value required to perform the target operation, including: the device using the determined security value corresponding to the target operation as the target security value according to a preset correspondence between operations and security values. In this way, the correspondence between operations and security values ​​can be preset, thereby providing the operation with a corresponding level of security level authentication capability.

[0066] In one possible implementation, the authentication security value of an authentication device is related to the root key storage environment of the authentication device and the authentication method used by the authentication device. Thus, the authentication security value of an authentication device's authentication method can be determined based on the root key storage environment and the authentication method, and this authentication security value can more comprehensively reflect the authentication capability of the authentication device.

[0067] In one possible implementation, before determining the total authentication security value based on the correspondence between the authentication methods and authentication security values ​​of the at least one authentication device, and the authentication result, the device further includes: determining the root key storage environment score corresponding to the first authentication device based on a preset correspondence between the root key storage environment and the root key storage environment score, and the root key storage environment of the first authentication device; determining the authentication method score corresponding to the authentication method of the first authentication device based on a preset correspondence between the authentication method and the authentication method score, and the authentication method of the first authentication device; and calculating the authentication security value of the authentication method of the first authentication device based on a first calculation rule, the root key storage environment score of the first authentication device, and the authentication method score corresponding to the authentication method. Thus, the authentication security value of an authentication method of an authentication device can be determined based on the root key storage environment and the authentication method, and this authentication security value can more comprehensively reflect the authentication capability of the authentication device.

[0068] In one possible implementation, the device determines the total authentication security value based on the correspondence between the authentication methods and authentication security values ​​of the at least one authentication device, and the authentication result. This includes: if the authentication result for the first authentication device is successful, determining the authentication security value of the first authentication device's authentication method based on the correspondence between the authentication methods and authentication security values ​​of the first authentication device; if the authentication result for the first authentication device is unsuccessful, determining the authentication security value of the first authentication device's authentication method to be 0; and calculating the total authentication security value based on the authentication security value of the authentication method of each of the M1 authentication devices and a second calculation rule. Thus, the total authentication security value reflects the total authentication capability of the M1 authentication devices currently performing authentication, thereby determining whether the target operation is permitted based on the total authentication capability.

[0069] In one possible implementation, after the device identifies M1 authentication devices and before determining the authentication result of at least one of the M1 authentication devices, the method further includes: when the device is not an authentication device, for example, when the device is an operating device, server, or router without authentication capabilities, the device sends a second authentication request to each of the M1 authentication devices, the second authentication request being used to request the authentication device to authenticate user information. Alternatively, when the device is one of the M1 authentication devices, the device sends a second authentication request to each of the M1 authentication devices other than itself.

[0070] In one possible implementation, the M1 authentication devices include a first authentication device. The device sends a second authentication request to each of the M1 authentication devices, including sending the second authentication request to the first authentication device. The second authentication request carries indication information for indicating a first authentication method of the first authentication device. Thus, the first authentication device can authenticate user information using the first authentication method indicated in the second authentication request.

[0071] In one possible implementation, before sending the second authentication request to the first authentication device, the device determines the first authentication method of the first authentication device by the following method: All or some of the authentication methods supported by the first authentication device are identified as the first authentication method of the first authentication device; All or some of the biometric authentication methods supported by the first authentication device are identified as the first authentication method of the first authentication device, thus eliminating the tedious process of entering a password; The authentication method with the highest security value among all authentication methods supported by the first authentication device is determined as the first authentication method of the first authentication device. In this way, the authentication security level for authenticating user information can be improved. The authentication method with the highest security value among all biometric authentication methods supported by the first authentication device is determined as the first authentication method of the first authentication device. In this way, the cumbersome process of entering a password can be eliminated, and the authentication security level of user information can be improved.

[0072] In one possible implementation, to improve the flexibility of the scheme, before determining the authentication result of at least one of the M1 authentication devices, the method further includes: the device receiving a first message sent by the first authentication device, the first message carrying indication information for indicating the authentication methods supported by the first authentication device. Alternatively, the device sends a query request to the first authentication device to query the authentication methods supported by the first authentication device, and the device receives a query response returned by the first authentication device, the query response carrying indication information for indicating the authentication methods supported by the first authentication device.

[0073] In one possible implementation, the device is a router, an operating device, one of the M1 authentication devices, or the device is located on a server. When the device is a router, the router, the operating device, and the M1 authentication devices are in the same local area network (LAN). This allows data to be transmitted between the device, the operating device, and the authentication devices via the same LAN, thereby improving data transmission speed.

[0074] In one possible design, the first electronic device receiving the authentication request includes: the first electronic device receiving a first operation, the first operation being used to trigger the generation of the authentication request; the step of determining the authentication method corresponding to the first service includes: determining the first authentication method corresponding to the first service; The method further includes: in response to receiving the first operation, the first electronic device detects whether the local authentication result of the first electronic device passes; in response to detecting that the local authentication result of the first electronic device fails, the first electronic device determines the authentication method corresponding to the first service, and further includes: determining the second authentication method corresponding to the first service.

[0075] The method further includes: a first electronic device sending a request to a second electronic device to obtain the local authentication result of the second electronic device according to a second authentication method; the first electronic device receiving the local authentication result of the second electronic device sent by the second electronic device; in response to receiving the local authentication result of the second electronic device, detecting whether the local authentication result of the second electronic device is passed; in response to detecting that the local authentication result of the second electronic device is passed, the first electronic device executing the instruction corresponding to the first operation.

[0076] In this way, the identity of the first electronic device can be authenticated through the local authentication result of the second electronic device, which effectively improves the convenience of cross-device authentication and creates a better user experience.

[0077] In one possible implementation, after the first electronic device receives the first operation, the method further includes: the first electronic device detecting whether the first operation triggers a locked, low-risk application; and in response to detecting that the first operation triggers a locked, low-risk application, the first electronic device detecting whether its local authentication result is successful. In this way, for locked, low-risk applications, the identity of the first electronic device can be authenticated through the local authentication result of the second electronic device, effectively improving the convenience of controlling locked, low-risk applications.

[0078] In one possible implementation, when the first operation is a first voice command, before the first electronic device checks whether its local authentication result is successful, the method further includes: the first electronic device checking whether the voiceprint features in the first voice command match the voiceprint features of a preset user; and in response to detecting that the voiceprint features in the first voice command match the voiceprint features of the preset user, the first electronic device checks whether its local authentication result is successful. In this way, the first electronic device can achieve voice control based on the local authentication result of the second electronic device, improving the convenience of voice control.

[0079] In one possible implementation, the first electronic device performs local continuous authentication and generates a local authentication result simultaneously with or after receiving the first operation. The local continuous authentication method of the first electronic device includes at least one of the following: facial recognition authentication, iris recognition authentication, and touch screen behavior recognition authentication. The local authentication result of the first electronic device can characterize whether the first electronic device has successfully authenticated the user's identity.

[0080] In one possible implementation, the second electronic device performs local continuous authentication and generates a local authentication result simultaneously with or before the first electronic device receives the first operation; wherein the method of local continuous authentication performed by the second electronic device includes at least one of the following: facial recognition authentication, iris recognition authentication, or touch screen behavior recognition authentication; the local authentication result of the second electronic device can characterize whether the second electronic device has successfully authenticated the user's identity.

[0081] In one possible implementation, before the first electronic device executes the instruction corresponding to the first operation, the method further includes: the first electronic device detecting the distance between itself and the second electronic device; and, in response to detecting that the distance between the first electronic device and the second electronic device is less than a first preset distance, the first electronic device executes the instruction corresponding to the first operation. In this way, while improving the convenience of identity authentication through cross-device authentication, the security of cross-device authentication is ensured by limiting the distance between the first and second electronic devices.

[0082] In one possible implementation, before the first electronic device executes the instruction corresponding to the first operation, the method further includes: the first electronic device detecting whether it is in a secure state; and in response to detecting that the first electronic device is in a secure state, the first electronic device executing the instruction corresponding to the first operation. In this way, while improving the convenience of identity authentication through cross-device authentication, the security of cross-device authentication is ensured by confirming the security state of the second electronic device.

[0083] In one possible implementation, before the first electronic device executes the instruction corresponding to the first operation, the method further includes: the first electronic device detecting whether the priority of the local continuous authentication of the second electronic device is lower than the priority of the local continuous authentication of the first electronic device; and in response to detecting that the priority of the local continuous authentication of the second electronic device is not lower than the priority of the local continuous authentication of the first electronic device, the first electronic device executes the instruction corresponding to the first operation. In this way, while improving the convenience of identity authentication through cross-device authentication, the security of cross-device authentication is ensured by confirming that the priority of the local continuous authentication of the second electronic device is not lower than the priority of the local continuous authentication of the first electronic device.

[0084] In one possible design, the first electronic device receives the authentication request, including: A first electronic device receives a target operation applied to a first interface of the first electronic device, the target operation being used to trigger access to the first service, the first service being associated with a second electronic device; the first electronic device determines an authentication method corresponding to the first service, including: the first electronic device acquiring a target authentication method corresponding to the first service; the first electronic device scheduling M electronic devices to authenticate the first service according to the authentication method, including: the first electronic device collecting authentication information according to the target authentication method.

[0085] A first electronic device sends an authentication request to a second electronic device. The authentication request includes authentication information and is used to request the second electronic device to authenticate the first service. The second electronic device is included among the M electronic devices.

[0086] The first service being associated with the second electronic device could be a service within the second electronic device, or a service related to sensitive data of the second electronic device, or a service of the second electronic device.

[0087] In the above method, the first electronic device can collect authentication information, and the second electronic device can authenticate the authentication information, enabling cross-device collection of authentication information to improve the convenience of authentication operations, avoid users operating on multiple electronic devices, and enhance user experience. Furthermore, the collaborative authentication of the first and second electronic devices for the first service can improve the security of the authentication results, avoiding the problem of low security in authentication results due to hardware limitations or insufficient authentication and collection capabilities of a single electronic device.

[0088] In one possible design, the method further includes: a first electronic device receiving an authentication result from a second electronic device; and then the first electronic device responding to the target operation based on the authentication result. For example, in a non-multi-screen collaboration scenario, the first electronic device can respond to a payment operation as either successful or unsuccessful based on the authentication result from the second electronic device.

[0089] In one possible design, the method further includes: a first electronic device receiving an authentication result sent from a second electronic device; in response to the authentication result, the first electronic device switching from displaying the first interface to displaying a second interface, the second interface including the result of triggering the first service. For example, in a multi-screen collaboration scenario, after the second electronic device authenticates the payment operation, an interface switch occurs, and the interface is synchronized to the first electronic device; therefore, the first electronic device also sends an interface switch notification.

[0090] The multi-screen collaboration scenario refers to the following: the first electronic device and the second electronic device perform multi-screen collaboration, the target operation is a first object acting on the first window in the first interface, the first window is the display window of the second electronic device, and the first service is the service of the second electronic device.

[0091] In one possible design, the first electronic device acquires the target authentication method corresponding to the first service, including: The first electronic device obtains the target authentication method corresponding to the first service locally from its own device. It should be understood that prior to this, the first electronic device needs to synchronize resources with the second electronic device; that is, the first and second electronic devices need to synchronize the authentication methods corresponding to different services or different operations, so that the first electronic device can decide on the target authentication method corresponding to the first service. If the first electronic device has a secure execution environment, this method can improve the security of the authentication result to some extent.

[0092] In one possible design, the first electronic device can obtain the target authentication method corresponding to the first service from the second electronic device. Alternatively, the first electronic device can send a request message to the second electronic device, and then the second electronic device sends the authentication method to the first electronic device. In this method, the first electronic device decides the target authentication method corresponding to the first service. Optionally, the first electronic device can also synchronize resources with the second electronic device; that is, the first and second electronic devices can synchronize the authentication methods corresponding to different services or different operations, so that the first electronic device can decide the target authentication method corresponding to the first service. For example, if the first electronic device has data collection capabilities, it can be prioritized for data collection.

[0093] Additionally, this application provides an authentication method that can be applied to a second electronic device. The first electronic device and the second electronic device can be connected via wired or wireless means. The method includes: The second electronic device receives a request message from the first electronic device, the request message being used to request a target authentication method corresponding to a first service, the first service being associated with the second electronic device; the second electronic device sends the target authentication method corresponding to the first electronic device to the first electronic device. The second electronic device can also receive an authentication request from the first electronic device, the authentication request including authentication information; then, based on the authentication information, it authenticates the first service and generates an authentication result.

[0094] In this method, the second electronic device decides the target authentication method corresponding to the first service, and the second electronic device performs authentication using the authentication information obtained from the first electronic device. This can complete the collaborative authentication between the first and second electronic devices, thereby improving the security and reliability of the authentication results and avoiding the problem of low security of authentication results due to hardware limitations or insufficient authentication and data collection capabilities of a single device.

[0095] In one possible design, the method further includes: a second electronic device sending an authentication result to a first electronic device, the authentication result being used to trigger the first electronic device to respond to a target operation that triggers the first service.

[0096] In one possible design, the second electronic device can respond to the target operation that triggers the first service based on the authentication result, switch from the first interface to the second interface, the second interface including the result of triggering the first service; and then synchronize the second interface to the first electronic device.

[0097] In one possible design, the first service is associated with the second electronic device, including: The first service is a service in the second electronic device, or the first service is associated with sensitive data of the second electronic device, or the first service is a service of the second electronic device.

[0098] In one possible design, the first electronic device and the second electronic device perform multi-screen collaboration. The target operation that triggers access to the first service is a first object acting on the first window, which is the display window of the second electronic device, and the first service is the service of the second electronic device.

[0099] In one possible design, embodiments of this application provide a cross-device authentication method, which can be applied to a first electronic device connected to a second electronic device, and the method includes: The first electronic device receives a target operation performed by a user, which triggers access to a first service. The first service is associated with a second electronic device. The first electronic device determines an authentication method corresponding to the first service based on a resource pool, which includes the authentication method corresponding to the operation of the second electronic device and a template of authentication information. The first electronic device collects authentication information based on the authentication method and then uses the authentication information to authenticate the first service, generating an authentication result.

[0100] Optionally, the first electronic device may also send the authentication result to the second electronic device so that the second electronic device can respond.

[0101] In this method, the first electronic device uses the authentication method obtained from the second electronic device to collect authentication information and perform authentication, thereby improving the convenience of the authentication operation, avoiding the need for users to operate on multiple electronic devices, and enhancing the user experience. Furthermore, the collaborative authentication of the first and second electronic devices for the first service can improve the security of the authentication result, avoiding the problem of low security in authentication results due to hardware limitations or insufficient authentication and data collection capabilities of a single electronic device.

[0102] In one possible design, the first electronic device further includes, before receiving a target operation performed by the user on the first electronic device: The first electronic device can also synchronize resources from the second electronic device to generate a resource pool. The resource pool also includes the authentication method corresponding to the operation of the first electronic device, as well as a template for authentication information. In this way, the first electronic device can use the resource pool to determine the authentication method and use the template for authentication information to authenticate the collected authentication information.

[0103] In one possible design, before the first electronic device receives the authentication request, the method further includes: A first electronic device receives a user's operation, which includes user-input feature information associated with the user's identifier. The first electronic device then matches the feature information using a first feature template to generate a first matching result. The first electronic device then sends the feature information to a second electronic device. The second electronic device matches the feature information using a second feature template to obtain a second matching result, and the first electronic device retrieves the second matching result from the second electronic device. When both the first and second matching results are successful, the first electronic device establishes an association between the first feature template, the second feature template, and the user identifier.

[0104] This method can associate feature templates of the same user across multiple electronic devices. In the event of switching between old and new devices, the user can obtain feature templates from each device belonging to the same user based on this association, and then distribute the feature templates from the old devices to the new electronic devices to achieve one-click migration of feature templates between the old and new devices.

[0105] In one possible design, the method further includes: a first electronic device acquiring usage constraints of a first feature template and a second feature template; and the first electronic device establishing an association between the first feature template, the second feature template, and the usage constraints. The usage constraints may include at least one of the following: 1. Constraints on usage permissions for the feature template; 2. Constraints on the device environment to which the feature template applies; 3. Constraints on the services to which the feature template applies; and 4. Constraints on the security level of the feature template. For example, a user configures usage constraints for the first and second feature templates on the first electronic device, such as configuring applicable services. In this case, the first electronic device can acquire the usage constraints of the first and second feature templates based on the user's configuration information. Alternatively, the first electronic device can acquire the usage constraints of the first and second feature templates from a cloud server or other devices. In this method, by associating feature templates with usage constraints, the usage scenarios of the feature templates can be constrained, preventing the misuse of feature templates.

[0106] In one possible design, the method further includes: a first electronic device can share first recorded information and / or second recorded information to a second electronic device; wherein the first recorded information includes the association between a first feature template, a second feature template, and a user identifier; and the second recorded information includes the association between the first feature template, the second feature template, and usage constraints. In this way, other electronic devices can provide personalized services to users based on this recorded information, such as providing cross-device authentication or device collaborative authentication services.

[0107] In one possible design, the feature information includes user secret data and / or biometric data, the first feature template includes a template of user secret data and / or a template of biometric data, and the second feature template includes a template of the user secret data and / or a template of the biometric data.

[0108] In one possible design, the second electronic device and the first electronic device are connected to the same local area network, and / or the second electronic device and the first electronic device are pre-bound to the same user account.

[0109] In addition, this application provides a data association method that can be applied to a first electronic device. The method includes: the first electronic device receiving a first operation from a user, the first operation being used to request the input of a first feature template; in response to the first operation, the electronic device using an existing second feature template to authenticate the user's identity, wherein the second feature template is associated with the user's user identifier; after authentication is successful, receiving the first feature template input by the user; and establishing an association between the first feature template and the user identifier.

[0110] In this method, because the second feature template is bound to the user identifier, the user's identity can be authenticated using the second feature template. Upon successful authentication, an association can be established between the first feature template and the user identifier. This allows features belonging to the same user within an electronic device to be linked together. This association can be shared with other electronic devices, enabling them to provide personalized services to the user based on this recorded information, such as cross-device authentication or device-based collaborative authentication.

[0111] In one possible design, the electronic device receives a second operation from the user; this second operation triggers the association of a previously entered third feature template with the user identifier; in response to the second operation, the electronic device establishes an association between the third feature template and the user identifier. According to this method, the user can manually associate previously entered feature templates in the electronic device.

[0112] In one possible design, before the electronic device receives the user's second operation, if the user cannot distinguish which feature templates belong to the same user simply by relying on the naming information of the feature templates, then the method may also include a feature template identification process. Specifically, the electronic device may also receive feature information input by the user; match the feature information input by the user with at least one feature template in the first electronic device, and determine the third feature template that matches the feature input by the user.

[0113] In one possible design, the method further includes: the electronic device acquiring usage constraints corresponding to the third feature template; and the electronic device establishing an association between the third feature template and the usage constraints. The usage constraints may include at least one of the following: 1. Constraints on usage permissions for the feature template; 2. Constraints on the device environment to which the feature template applies; 3. Constraints on the services to which the feature template applies; and 4. Constraints on the security level of the feature template.

[0114] In this method, once the feature template is associated with the usage constraints, the user can share the record information, including the usage constraints, with other trusted devices, such as other electronic devices or central devices within the device network. In this way, other electronic devices can provide personalized services to the user based on this record information, such as providing cross-device authentication or device collaborative authentication services.

[0115] In one possible design, after the first electronic device receives the first feature template entered by the user, the method further includes: the first electronic device sending the first feature template to a second electronic device, wherein the second electronic device is connected to the first electronic device. The second electronic device uses a fourth feature template in the second electronic device to match the feature information to obtain a matching result, and the first electronic device obtains the matching result from the second electronic device; when all matching results are successful, an association relationship is established between the fourth feature template, the first feature template, and the user identifier.

[0116] This method can associate feature templates of the same user across multiple electronic devices. In the event of switching between old and new devices, the user can obtain feature templates from each device belonging to the same user based on this association, and then distribute the feature templates from the old devices to the new electronic devices to achieve one-click migration of feature templates between the old and new devices.

[0117] In one possible design, the method further includes: the electronic device sharing the recorded information with the second electronic device; the recorded information includes a fourth feature template, the association between the first feature template and the user identifier. In this way, other electronic devices can provide personalized services to the user based on this recorded information, such as cross-device authentication or device collaborative authentication.

[0118] In one possible design, the feature information includes user secret data and / or biometric data, the first feature template includes a template of user secret data and / or a template of biometric data, and the second feature template includes a template of the user secret data and / or a template of the biometric data.

[0119] In one possible design, the second electronic device and the first electronic device are connected to the same local area network, and / or the second electronic device and the first electronic device are pre-bound to the same user account.

[0120] Thirdly, embodiments of this application provide a first electronic device, including a processor and a memory, wherein the memory is used to store one or more computer programs; when the one or more computer programs stored in the memory are executed by the processor, the first electronic device is able to implement any of the possible design methods executed by the first electronic device in the first aspect described above.

[0121] Fourthly, embodiments of this application provide a second electronic device, including a processor and a memory, wherein the memory is used to store one or more computer programs; when the one or more computer programs stored in the memory are executed by the processor, the second electronic device is able to implement any of the possible design methods executed by the second electronic device in the first aspect described above.

[0122] Fifthly, a communication apparatus is provided, including a receiving device and a processor, to perform any embodiment of any of the methods described in the first aspect.

[0123] The processor can be used to retrieve and run the computer program or instructions from memory, and when the processor executes the computer program or instructions in memory, the communication device can perform any implementation of any of the methods described in the first aspect above.

[0124] Optionally, there can be one or more processors.

[0125] A receiving device is used to perform functions related to receiving. The receiving device can be a receiving unit. In one design, the communication device can be a communication chip, and the receiving device can be the input circuitry or port of the communication chip. In another design, the receiving device can also be a receiver or a receiver-like device.

[0126] In one possible implementation, the communication device may further include a transmitting device for performing transmission-related functions. The transmitting device may be a transmitting unit. In one design, the communication device may be a communication chip, and the transmitting device may be the output circuitry or port of the communication chip. In another design, the transmitting device may also be a transmitter or a transmitter.

[0127] In a sixth aspect, a communication device is provided, which can be the aforementioned device for performing the authentication method. It includes a processor and a memory. Optionally, it further includes a communication interface. The memory is used to store computer programs or instructions, and the processor is used to retrieve and execute the computer programs or instructions from the memory. When the processor executes the computer programs or instructions in the memory, the communication device can execute any implementation of any of the methods described in the first aspect via the communication interface.

[0128] Optionally, there can be one or more processors and one or more memories.

[0129] Optionally, the memory can be integrated with the processor, or the memory can be set up separately from the processor.

[0130] Optionally, the communication interface can be an input / output circuit or a port, or it can be a transmitter and receiver, or a transmitter and receiver.

[0131] A seventh aspect provides a communication device including a processor. The processor is coupled to a memory and can be used to execute any aspect of the first aspect and any possible implementation thereof. Optionally, the communication device further includes a memory. Optionally, the communication device further includes a communication interface, to which the processor is coupled.

[0132] In another implementation, the communication device can be an apparatus for performing any of the methods described in the first aspect above. The communication interface can be a transceiver or an input / output interface. Optionally, the transceiver can be a transceiver circuit. Optionally, the input / output interface can be an input / output circuit.

[0133] In another implementation, the communication device can also be a chip or a chip system. When the communication device is a chip or a chip system, the communication interface can be an input / output interface, interface circuit, output circuit, input circuit, pin, or related circuit on the chip or chip system. The processor can also be manifested as a processing circuit or logic circuit.

[0134] Eighthly, embodiments of this application provide an authentication system, which includes multiple electronic devices interconnected with each other, the multiple electronic devices including: a data acquisition device, an authentication device, and a decision-making device; The decision-making device is used to receive an authentication request, the authentication request being used to request authentication of a first service; and to determine the authentication method corresponding to the first service; The decision-making device is also used to schedule the collection device to collect authentication factors and to schedule the authentication device to perform authentication according to the authentication method. The acquisition device is used to acquire at least one authentication factor and send the at least one authentication factor to the authentication device. The authentication device is used to authenticate the at least one authentication factor to obtain at least one authentication result, and send the at least one authentication result to the decision device; The decision-making device is used to process the at least one authentication result to obtain the authentication result of the first service.

[0135] In one possible design, when determining the authentication method corresponding to the first service, the decision-making device is specifically used for: Determine the risk and security level corresponding to the first business; Based on the risk and security level, determine the authentication method that meets the security risk level.

[0136] In one possible design, the system also includes service equipment; The service device is used to receive a target operation, the target operation is used to trigger the generation of the authentication request, and send the authentication request to the decision device; When the decision-making device receives an authentication request, it is specifically used to: receive the authentication request from the service device; When the decision-making device determines the authentication method corresponding to the first service, it is specifically used to: determine the target security value required to execute the target operation, the target operation being used to trigger the execution of the first service; determine M1 authentication devices, where M1 is a positive integer, the M1 authentication devices being devices capable of authenticating user information, and the M1 authentication devices being included in the M electronic devices; The decision-making device processes the at least one authentication result to obtain the authentication result of the first service, specifically for: Obtain the authentication result of at least one of the M1 authentication devices; The total authentication security value is determined based on the correspondence between the authentication method and the authentication security value of the at least one authentication device, and the authentication result. If the total authentication security value is not less than the target security value, then the authentication is successful; The decision-making device is also used to trigger the operating device to perform the target operation.

[0137] In one possible design, when the decision-making device receives an authentication request, it is specifically used to: receive a first operation, the first operation being used to trigger the generation of the authentication request; The decision-making device determines the authentication method corresponding to the first service, specifically for: Determine the first authentication method corresponding to the first service; The decision-making device is further configured to: in response to receiving the first operation, according to the first authentication method, detect whether the local authentication result of the decision-making device is passed; In response to the detection that the local authentication result of the decision-making device fails, a second authentication method corresponding to the first service is determined; a request to obtain the local authentication result of the authentication device is sent to the authentication device. The authentication result is sent to the decision-making device, along with the local authentication result of the authentication device. The decision-making device is further configured to, in response to receiving the local authentication result from the authentication device, detect whether the local authentication result of the authentication device is passed; and in response to detecting that the local authentication result of the authentication device is passed, the authentication device executes the instruction corresponding to the first operation.

[0138] In one possible design, the system also includes service equipment; The service device is configured to receive a target operation applied to a first interface of a first electronic device, the target operation being used to trigger access to the first service, the first service being associated with the second electronic device; When the decision-making device receives an authentication request, it is specifically used to: receive the authentication request from the service device; When the decision-making device determines the authentication method corresponding to the first service, it is specifically used to: obtain the target authentication method corresponding to the first service; The decision-making device is also used to: collect authentication information according to the target authentication method; and send an authentication request to the authentication device, the authentication request including authentication information; The authentication device is used to authenticate the first service according to the authentication request.

[0139] In one possible design, the plurality of electronic devices includes a first device and a second device, wherein the first device and the second device are any two of the plurality of electronic devices; In one possible implementation, the plurality of electronic devices includes a first device and a second device, wherein the first device and the second device are any two of the plurality of electronic devices; the first device is configured to send first information to the second device before the acquisition device acquires at least one authentication factor, wherein the first information includes at least one of the following: the acquisition capability of the first device, the authentication capability of the first device, and the decision capability of the first device; the acquisition capability of the first device includes the types of authentication factors that the first device can acquire, the authentication capability of the first device includes the types of authentication factors that the first device can authenticate, and the decision capability of the first device is whether the first device can obtain the at least one aggregation result based on at least one of the authentication results.

[0140] In one possible implementation, at least two of the plurality of electronic devices are configured to negotiate and determine the type of the at least one authentication factor before the acquisition device acquires the at least one authentication factor; or, at least one of the plurality of electronic devices is configured to determine the type of the at least one authentication factor in response to a user input operation before the acquisition device acquires the at least one authentication factor.

[0141] In this embodiment, multiple electronic devices can synchronize resource information, which includes at least one of the following: acquisition capability, authentication capability, and decision-making capability. After the resource information is synchronized, any one electronic device can obtain the resource information of the other electronic devices among the multiple electronic devices. Therefore, the multiple electronic devices can coordinate and confirm the type of at least one authentication factor used in the user authentication process based on the acquired resource information, thereby achieving a secure, reliable authentication process with minimal power consumption impact through the acquisition device, authentication device, and decision-making device.

[0142] In one possible implementation, the plurality of electronic devices are further configured to: receive a first aggregation result and a second aggregation result sent by the decision device, wherein the first aggregation result and the second aggregation result are aggregation results obtained by the decision device at different times.

[0143] In this embodiment, the aggregation results obtained by multiple electronic devices may include aggregation results obtained at different times. Any electronic device can perform continuous authentication of the user's identity based on the aggregation results obtained at the aforementioned different times, resulting in higher security and reliability.

[0144] In one possible implementation, the interconnection of the multiple electronic devices specifically includes: the multiple electronic devices connecting to the same local area network and / or the multiple electronic devices logging into the same user account.

[0145] In this embodiment of the application, the interconnection of multiple electronic devices can be a relatively secure and reliable method. By using such multiple electronic devices to perform the user identity authentication process, the security and reliability of the authentication process can be further improved.

[0146] In one possible implementation, when the authentication device authenticates the at least one authentication factor to obtain at least one authentication result, it is specifically configured to: compare the at least one authentication factor with at least one pre-stored template authentication factor to obtain the similarity between the at least one authentication factor and the at least one template authentication factor, wherein the at least one authentication result is the similarity between the at least one authentication factor and the at least one template authentication factor; when the similarity between the at least one authentication factor and the at least one template authentication factor is greater than a first threshold, the at least one authentication result indicates that the user is legitimate.

[0147] In one possible implementation, the plurality of electronic devices further includes a user device, wherein the user device is configured to: perform a first operation when the user device receives the at least one aggregation result and the at least one aggregation result indicates that the user is legitimate.

[0148] In this embodiment of the application, the device can perform corresponding user operations based on at least one aggregation result obtained from multiple electronic devices, thereby achieving a safe and reliable authentication process with minimal impact on power consumption without the user's awareness, and without affecting the user's normal use of the device.

[0149] In one possible implementation, the at least one aggregation result indicating that the user is legitimate includes at least one of the following: when any one of the at least one authentication result indicates that the user is legitimate, the at least one aggregation result indicates that the user is legitimate; when the number of authentication results indicating that the user is legitimate in the at least one authentication result is greater than a second threshold, the at least one aggregation result indicates that the user is legitimate.

[0150] In this application embodiment, there are multiple ways to determine whether at least one aggregation result indicates that the user is legitimate. Different methods can be used for different application scenarios, which is more flexible and has a wider range of application scenarios.

[0151] In one possible implementation, the device is further configured to: detect a second operation acting on the device after the device receives the at least one aggregation result and before the device performs the first operation; and run the first application in response to detecting the second operation.

[0152] In one possible implementation, the plurality of electronic devices includes a third device, a fourth device, a fifth device, and a sixth device, wherein the acquisition device is the third device, the authentication device is the fourth device, the decision-making device is the fifth device, and the user device is the sixth device; or, the plurality of electronic devices includes a seventh device and an eighth device, wherein the acquisition device, the authentication device, and the user device are the seventh device, and the decision-making device is the eighth device.

[0153] In this embodiment, the data acquisition device, authentication device, decision-making device, and user device can be four different devices, or fewer than four. Any one of the multiple electronic devices can be at least one of the following: data acquisition device, authentication device, decision-making device, and user device. That is, any electronic device can include multiple roles, making the implementation more flexible and the application scenarios more extensive. Even systems with a small number of devices can achieve a secure, reliable authentication process with minimal power consumption impact.

[0154] In one possible implementation, the aforementioned plurality of electronic devices include a ninth device, a tenth device, an eleventh device, a twelfth device, a thirteenth device, a fourteenth device, a fifteenth device, and a sixteenth device; the aforementioned acquisition device includes the ninth and tenth devices; the aforementioned authentication device includes the eleventh and twelfth devices; the aforementioned decision-making device includes the thirteenth and fourteenth devices; and the aforementioned usage device includes the fifteenth and sixteenth devices.

[0155] In this embodiment, any one of the acquisition device, authentication device, decision-making device, and usage device is not limited to a single device. This realizes the resource integration and comprehensive scheduling of acquisition capabilities, authentication capabilities, and decision-making capabilities in multiple electronic devices, reducing the processing pressure of a single device and the impact on power consumption, resulting in higher availability.

[0156] Ninthly, a computer program product is provided, comprising: a computer program (also referred to as code or instructions) that, when executed, causes a computer to perform a method in any possible implementation of the first or second aspect above, or causes a computer to perform a method in any of the above implementations.

[0157] In a tenth aspect, a computer-readable storage medium is provided, which stores a computer program (also referred to as code or instructions) that, when run on a computer, causes the computer to perform the method in any possible implementation of the first or second aspect described above, or causes the computer to perform the method in any of the above implementations.

[0158] Eleventhly, a processing apparatus is provided, comprising: an input circuit, an output circuit, and a processing circuit. The processing circuit is configured to receive signals through the input circuit and transmit signals through the output circuit, such that any aspect of the first aspect, and any possible implementation thereof, is implemented, or that any aspect of the second aspect, and any possible implementation thereof, is implemented.

[0159] In specific implementation, the aforementioned processing device can be a chip, the input circuit can be an input pin, the output circuit can be an output pin, and the processing circuit can be a transistor, gate circuit, flip-flop, and various logic circuits, etc. The input signal received by the input circuit can be received and input by a receiver, and the signal output by the output circuit can be output to a transmitter and transmitted by the transmitter. Furthermore, the input circuit and the output circuit can be the same circuit, which is used as the input circuit and output circuit at different times. This application does not limit the specific implementation of the processor and various circuits.

[0160] For the technical effects that can be achieved by the various designs in any of the second to eleventh aspects above, please refer to the description of the technical effects that can be achieved by each design in the first aspect above, which will not be repeated here. Attached Figure Description

[0161] Figure 1A A schematic diagram of a communication system provided in an embodiment of this application; Figure 1B A schematic diagram of a smart home communication system provided in an embodiment of this application; Figure 2 A schematic diagram of a mobile phone structure provided in an embodiment of this application; Figure 3 This is a schematic diagram of an authentication method provided in an embodiment of this application; Figure 4 This is a schematic diagram of another authentication method provided in an embodiment of this application; Figure 5 A schematic diagram of a device structure provided in an embodiment of this application; Figure 6A This is a schematic diagram illustrating a resource synchronization method provided in an embodiment of this application; Figure 6B This is a schematic diagram illustrating another resource synchronization method provided in an embodiment of this application; Figure 7A This application provides a schematic diagram of a door opening scenario. Figure 7B This application provides a schematic diagram of an authentication method in a door-opening scenario. Figure 7CThis is a schematic diagram of another door opening scenario provided in an embodiment of this application; Figure 7D This is a schematic diagram of another door opening scenario provided in an embodiment of this application; Figure 8 A set of interface schematic diagrams provided for embodiments of this application; Figure 9A A schematic diagram illustrating a scenario of voice-operated smart TV provided in an embodiment of this application; Figure 9B This application provides a schematic diagram of an authentication method for a voice-operated smart TV scenario. Figure 10A A schematic diagram illustrating another scenario of voice-operated smart TV provided in an embodiment of this application; Figure 10B This is a schematic diagram of another authentication method for a smart TV with voice operation provided in an embodiment of this application; Figure 11A A schematic diagram illustrating another scenario of voice-operated smart TV provided in an embodiment of this application; Figure 11B This is a schematic diagram of another authentication method for a smart TV with voice operation provided in an embodiment of this application; Figure 12A This is a schematic diagram illustrating a scenario of voice-operated microwave oven, provided as an embodiment of this application. Figure 12B This is a schematic diagram of another authentication method for a microwave oven with voice operation provided in an embodiment of this application; Figure 13 This is a schematic diagram of an authentication method provided in an embodiment of this application; Figure 14 This is a schematic diagram of another authentication method provided in an embodiment of this application; Figure 15A A schematic diagram illustrating a possible application scenario provided by an embodiment of this application; Figure 15B A schematic diagram illustrating an application scenario provided in an embodiment of this application; Figure 15C A schematic diagram illustrating an application scenario provided in an embodiment of this application; Figure 16 A flowchart illustrating an authentication method provided in an embodiment of this application; Figure 17 A flowchart illustrating an authentication method provided in an embodiment of this application; Figure 18 A schematic diagram of the structure of an apparatus provided in an embodiment of this application; Figure 19 A schematic diagram of another device provided in an embodiment of this application; Figure 20 A flowchart illustrating a cross-device authentication method provided in an embodiment of this application; Figure 21 This is a schematic diagram of the system architecture of a communication system provided in the third implementation of the present application; Figure 22 A schematic diagram of an interface for enabling cross-device authentication provided in an embodiment of this application; Figures 23A to 23D A schematic diagram of a voice control scenario provided in an embodiment of this application; Figures 24A to 24G A schematic diagram of the application locking interface provided in the embodiments of this application; Figures 24H to 24M A schematic diagram of the interface for locking application functions provided in the embodiments of this application; Figures 25A to 25J A schematic diagram of a voice control scenario provided in an embodiment of this application; Figures 26A to 26C A schematic diagram of the interface for setting up low-risk applications provided in an embodiment of this application; Figures 27A to 27D A schematic diagram of a voice control scenario provided in an embodiment of this application; Figures 28A to 28H A schematic diagram of the interface for triggering screen projection provided in an embodiment of this application; Figures 28I to 28J A schematic diagram of the screen projection control interface provided in an embodiment of this application; Figures 29A to 29I A schematic diagram of the screen projection control interface provided in an embodiment of this application; Figures 30A to 30C A schematic diagram of the screen projection control interface provided in an embodiment of this application; Figures 31A to 31B A schematic diagram of the screen projection control interface provided in an embodiment of this application; Figures 32A to 32E This is a schematic diagram of the interface for adding authorized users provided in an embodiment of this application; Figures 33A to 33C A schematic diagram of the screen projection control interface provided in an embodiment of this application; Figures 34A to 34C A schematic diagram of a cross-device authentication system provided in an embodiment of this application; Figure 35 A flowchart illustrating the cross-device authentication method in a voice control scenario provided in this application embodiment; Figure 36 A flowchart illustrating the cross-device authentication method in a screen projection control scenario provided in this application embodiment; Figure 37 This is a schematic diagram of a cross-device authentication method provided in an embodiment of this application; Figure 38A and Figure 38B This is a schematic diagram illustrating a device authentication method provided in an embodiment of this application; Figure 39A A schematic diagram of a PC interface provided for an embodiment of this application; Figure 39B A schematic diagram illustrating a PC and mobile phone collaboratively performing face authentication, provided as an embodiment of this application; Figure 39C A schematic diagram of another PC interface provided for an embodiment of this application; Figure 39D A schematic diagram of another PC interface provided for an embodiment of this application; Figure 40 This is a schematic diagram of another cross-device authentication method provided in an embodiment of this application; Figure 41 This is a schematic diagram of another cross-device authentication method provided in an embodiment of this application; Figure 42 A schematic diagram of a payment scenario for a smart TV provided in an embodiment of this application; Figure 43 A schematic diagram of a driving scenario provided in an embodiment of this application; Figure 44 A schematic diagram of a device structure provided in an embodiment of this application; Figure 45 A schematic diagram of the software structure of an electronic device provided in an embodiment of this application; Figure 46A and Figure 46B A set of interface schematic diagrams provided for embodiments of this application; Figure 47 Another set of interface schematic diagrams provided for embodiments of this application; Figure 48A and Figure 48B Another set of interface schematic diagrams provided for embodiments of this application; Figure 49A and Figure 49B Another set of interface schematic diagrams provided for embodiments of this application; Figure 50 Another set of interface schematic diagrams provided for embodiments of this application; Figure 51A This is a schematic diagram illustrating a fingerprint distribution method provided in an embodiment of this application; Figure 51B This is a schematic diagram of a face distribution method provided in an embodiment of this application; Figure 51C This is a schematic diagram illustrating a data association method provided in an embodiment of this application; Figure 52 This application provides a schematic diagram of an associated scenario. Figure 53 Another set of interface schematic diagrams provided for embodiments of this application; Figure 54 This is a schematic diagram of a data association method provided in an embodiment of this application; Figure 55 A schematic diagram illustrating another data association method provided in an embodiment of this application; Figures 56A to 56D Schematic diagrams of the structures of some other electronic devices provided in the embodiments of this application; Figure 57 This is a flowchart illustrating a resource synchronization process provided in an embodiment of this application; Figure 58 This is a flowchart illustrating a multi-device collaborative authentication method provided in an embodiment of this application; Figures 59-60 This is a flowchart illustrating some decision-making processes provided in the embodiments of this application; Figures 61-77 This is a flowchart illustrating some of the multi-device collaborative authentication methods provided in the embodiments of this application; Figure 78 This is a schematic diagram of the software structure of an electronic device provided in an embodiment of this application.

[0162] Figure 79 This is a schematic diagram of an electronic device structure provided in an embodiment of this application. Detailed Implementation

[0163] The technical solutions of the embodiments of this application are described below with reference to the accompanying drawings. In the description of the embodiments of this application, the terminology used in the following embodiments is for the purpose of describing specific embodiments only and is not intended to limit the application. As used in the specification and appended claims of this application, “a,” “an,” “the,” “the,” “the,” and “this” include expressions such as “one or more,” unless the context clearly indicates otherwise. It should also be understood that in the following embodiments of this application, “at least one” and “one or more” refer to one or more (including two). The term “and / or” is used to describe the relationship between related objects, indicating that three relationships can exist; for example, A and / or B can represent: A alone, A and B simultaneously, or B alone, where A and B can be singular or plural. The character “ / ” generally indicates that the preceding and following related objects have an “and” or “or” relationship.

[0164] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of this application include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, phrases such as "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but may also refer to other embodiments. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized. The term "connection" includes direct connections and indirect connections, unless otherwise stated. "First" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated.

[0165] In the embodiments of this application, the words "exemplarily" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as "exemplarily" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design solutions. Specifically, the use of the words "exemplarily" or "for example" is intended to present the relevant concepts in a specific manner.

[0166] Before introducing the technical solutions of the embodiments of this application, some terms used in this application will be explained to facilitate understanding by those skilled in the art.

[0167] The following describes some concepts involved in the embodiments of this application: (1) Certification equipment and operating equipment In this application, a terminal device with authentication capabilities is referred to as an authentication device. For example, a smart speaker has the ability to authenticate a user's voiceprint, so a smart speaker is an authentication device.

[0168] In this application, the device performing the service is referred to as the operating device. For example, if the device performing the door opening service is a door lock, then the operating device is the door lock; similarly, if the device performing the microwave heating service for five minutes is a microwave oven, then the operating device is the microwave oven.

[0169] (2) The correspondence between authentication methods and the scores of authentication methods

[0170] Authentication methods include using biometrics (e.g., fingerprints, voiceprints, iris scans) to authenticate users, and using usernames and passwords to authenticate users. In one scenario, if the security level of the service the user requests is low, the electronic device may use authentication based on a single authentication factor, such as fingerprint authentication. In another scenario, if the security level of the service the user requests is high, the electronic device may use authentication based on multiple authentication factors, such as fingerprint authentication and facial recognition.

[0171] In particular, the proper use of biometrics for user authentication can simplify user operations. For example, in the application scenario of payment, if a user wants to make a mobile payment, they need to enter a password. However, a mobile phone that uses biometric authentication can authenticate the user by fingerprint or facial information, avoiding the hassle of entering a password.

[0172] False acceptance rate (FAR) and false rejection rate (FRR) are evaluation metrics used to assess the performance of algorithms that authenticate users using biometrics.

[0173] The false acceptance rate, simply put, is the proportion of matches that shouldn't be matched. The false rejection rate, simply put, is the proportion of matches that should be successful being incorrectly matched.

[0174] The following explanation uses fingerprint recognition as an example to illustrate the false recognition rate and the rejection rate.

[0175] In fingerprint recognition, the false recognition rate (FCR) refers to the proportion of fingerprints that are considered the same when different fingerprints are matched with a given threshold when the fingerprint recognition algorithm is tested on a standard fingerprint database. Simply put, it is the proportion of fingerprints that should not be matched that are considered to be matched.

[0176] The rejection rate (RR) refers to the proportion of fingerprints that are considered different when the matching rate of the same fingerprint is below a given threshold when testing fingerprint recognition algorithms on a standard fingerprint database. Simply put, it is the proportion of fingerprints that should match each other but are not.

[0177] For example: Assuming there are 110 people, and each person has 8 fingerprint images of their thumb, totaling 110... The fingerprint database contains 880 images (8 images in total), representing 110 categories, with 8 images per category. Ideally, any two images within a category should match successfully, while any images between categories should not match. Each image in the database is matched against all other images except itself, and the false acceptance rate and false rejection rate are calculated for each match.

[0178] False recognition rate: Assuming that due to the performance limitations of the fingerprint recognition algorithm, some fingerprints that should have failed are correctly identified as successful, and assuming this error occurs 1000 times. Theoretically, if all images from the same fingerprint are successfully matched, the error rate would be 7. 8 110 = 6160 times. The total number of matches is 880 × (880 - 1) = 773520 times. The number of failed matches should be 773520 - 6160 = 767360 times. Therefore, the false acceptance rate (FAR) is 1000 / 767360. 100% = 0.13%.

[0179] Refusal rate: Assuming that due to the performance limitations of the fingerprint recognition algorithm, a match that should have been successful is marked as a failure, and if this error occurs 160 times, then the refusal rate is 160 / 6160 = 2.6%.

[0180] In this embodiment, the score of an authentication method can be determined based on its rejection rate and false acceptance rate. Generally, the lower the rejection rate and false acceptance rate of an authentication method, the higher its score. Conversely, the higher the rejection rate and false acceptance rate, the lower its score.

[0181] Table 1 illustrates the correspondence between several authentication methods and their scores.

[0182] Table 1

[0183] (3) The security environment of an authentication device may include: the inside secure element (inSE) level, the trusted execution environment (TEE) level, white box and key segmentation.

[0184] In this embodiment, the hardware security unit can refer to an independent security unit built into the main chip, providing functions such as secure storage of private information and secure execution of important programs. Using inSE-level protection for the root key offers a high level of security and can achieve hardware-based tamper-proofing.

[0185] In this embodiment, the TEE can refer to a trusted execution environment, which is a hardware-secured isolated area of ​​the main processor, providing functions such as confidentiality and integrity protection for code and data, and secure access to external devices. Using a TEE to protect the root key provides a high level of security, reaching the hardware security level.

[0186] (4) A distributed storage system distributes data across multiple independent devices. Traditional network storage systems use a centralized storage server to store all data, making the storage server a bottleneck for system performance and a focal point for reliability and security, thus failing to meet the needs of large-scale storage applications. Distributed network storage systems employ a scalable system architecture, utilizing multiple storage servers to share the storage load and location servers to locate stored information. This not only improves the system's reliability, availability, and access efficiency but also facilitates expansion.

[0187] (5) Authentication factors may include: user secret data, biometric data, etc. User secret data may include the user's lock screen password, user protection password, etc. Biometric data may include one or more of the following: physical biometrics, behavioral biometrics, and soft biometrics. Physical biometrics may include: face, fingerprint, iris, retina, deoxyribonucleic acid (DNA), skin, hand shape, and veins. Behavioral biometrics may include: voiceprint, signature, and gait. Soft biometrics may include: gender, age, height, weight, etc.

[0188] (6) Business: The transaction performed by a device to perform its functions or services. For example, a business can be an unlocking business, a payment business, a door opening business, an artificial intelligence (AI) computing business, various application businesses, distribution businesses, etc.

[0189] Currently, device authentication is primarily based on a single-device authentication process. For example, when a user opens a secure vault app on their phone, the interface prompts them to perform fingerprint authentication. The user then enters their fingerprint on their phone, which performs the authentication and generates a result. There are currently no collaborative authentication solutions for multiple devices.

[0190] To achieve collaborative authentication between devices, this application provides an authentication method. One possible approach involves using at least two electronic devices to jointly authenticate the same service. For example, a PC collects a face image, sends the image to a mobile phone, and the mobile phone uses the face image collected by the PC to authenticate a user-triggered payment transaction. This allows for cross-device collection of authentication factors and collaborative authentication of the same service, improving the convenience of the authentication method. Another possible approach involves using at least two electronic devices with at least two authentication factors to jointly authenticate the same service. For instance, a door lock collects a fingerprint, a camera on the door collects a face image, and a smart speaker uses both the fingerprint and face image from the door lock and the camera image to authenticate the door opening service. This method ensures the reliability of the authentication result and improves the security level of the device authentication.

[0191] The authentication method provided in this application embodiment can be applied to... Figure 1A The diagram shown is a schematic of the communication system architecture. Figure 1A As shown, the communication system architecture may include at least: electronic device 100 and electronic device 200.

[0192] In this embodiment, electronic devices 100 and 200 can establish a connection via wired or wireless means. When electronic devices 100 and 200 establish a wireless connection, the wireless communication protocol used can be Wi-Fi, Bluetooth, ZigBee, Near Field Communication (NFC), various cellular network protocols, etc., without specific limitations.

[0193] In specific implementations, the aforementioned electronic devices 100 and 200 can be mobile phones, tablets, handheld computers, personal computers (PCs), cellular phones, personal digital assistants (PDAs), wearable devices (such as smartwatches), smart home devices (such as televisions), in-vehicle computers, game consoles, and augmented reality (AR) / virtual reality (VR) devices, etc. This embodiment does not impose special limitations on the specific device forms of electronic devices 100 and 200. In this embodiment, electronic devices 100 and 200 can have the same device form. For example, both electronic devices 100 and 200 can be mobile phones. Electronic devices 100 and 200 can also have different device forms. For example, electronic device 100 can be a PC, and electronic device 200 can be a mobile phone.

[0194] The aforementioned electronic devices 100 and 200 can be touchscreen devices or non-touchscreen devices. In this embodiment, both electronic devices 100 and 200 are terminals that can run an operating system, install applications, and have a display (or screen).

[0195] In one possible embodiment of this application, the system architecture may further include a server 300, through which the electronic device 100 can establish a wired or wireless connection with the electronic device 200.

[0196] like Figure 1B As shown, the communication system can be a smart home system. Smart home devices within this system can include: mobile phone 11, smart camera 12, smart TV 13, smart speaker 14, smart bracelet 15, and smart door lock 16, etc. In specific implementations, the number of devices can be more or less. Multiple devices can connect and communicate via a network. These devices can connect and communicate with each other via wired (e.g., USB, twisted pair, coaxial cable, and / or fiber optic) or wireless (e.g., wireless fidelity, Wi-Fi, Bluetooth, and / or mobile network) methods. That is, the network can include, but is not limited to, at least one of the following: wired lines, wireless lines, and other communication lines; routers, access points (APs), and other gateway devices; and cloud servers, etc. For example, multiple devices can access the same local area network (LAN) through communication lines and gateway devices, and communicate through that LAN.

[0197] In some embodiments, multiple devices connected via a network are trusted devices to each other. For example, user terminal devices such as smartphones and tablets may have applications installed to enable communication (e.g., but not limited to Huawei Smart Home). These applications can log in to accounts, and are referred to as account applications. User terminal devices among the multiple devices can log in to the same or associated accounts through this account application, thereby communicating through the account application server. Other devices besides the user terminal devices can connect to the account application server via wireless methods such as Bluetooth and Wi-Fi, or wired methods such as USB (e.g., users can manually add smart home devices via Bluetooth on Huawei Smart Home). Thus, the multiple devices can identify the identity of the communication object through the account application server (e.g., devices logged in or registered on Huawei Smart Home are trusted devices, otherwise they are untrusted devices), thereby enabling highly secure communication through the account application server. These other devices may include, but are not limited to, smart home devices such as smart TVs and smart cameras, and wearable devices such as smart bracelets, smartwatches, and smart glasses.

[0198] Not limited to the situations listed above, in specific implementations, any one of multiple devices may need to be authenticated before connecting to the same Wi-Fi network. This allows multiple devices to identify the identity of the communication partner through the Wi-Fi network (e.g., a device that passes password verification is a trusted device, otherwise it is an untrusted device), thus enabling highly secure communication through the Wi-Fi network. This application's embodiments do not limit this approach.

[0199] The authentication method provided in this application can be applied to electronic devices. In some embodiments, the electronic device may be a portable terminal including functions such as a personal digital assistant and / or a music player, such as a mobile phone, tablet computer, wearable device with wireless communication capabilities (such as a smartwatch), in-vehicle device, etc. Exemplary embodiments of the portable terminal include, but are not limited to, portable terminals running Harmony OS®, iOS®, Android®, Microsoft®, or other operating systems. The aforementioned portable terminal may also be a laptop computer with a touch-sensitive surface (e.g., a touch panel). It should also be understood that in some other embodiments, the aforementioned terminal may also be a desktop computer with a touch-sensitive surface (e.g., a touch panel).

[0200] Figure 2 A schematic diagram of the structure of the electronic device 200 is shown.

[0201] Electronic device 200 may include processor 210, external memory interface 220, internal memory 221, universal serial bus (USB) interface 230, charging management module 240, power management module 241, battery 242, antenna 1, antenna 2, mobile communication module 250, wireless communication module 260, audio module 270, speaker 270A, receiver 270B, microphone 270C, headphone jack 270D, sensor module 280, button 290, motor 291, indicator 292, camera 293, display screen 294, and subscriber identification module (SIM) card interface 295, etc. The sensor module 280 may include a pressure sensor 280A, a gyroscope sensor 280B, a barometric pressure sensor 280C, a magnetic sensor 280D, an accelerometer sensor 280E, a distance sensor 280F, a proximity sensor 280G, a fingerprint sensor 280H, a temperature sensor 280J, a touch sensor 280K, an ambient light sensor 280L, a bone conduction sensor 280M, a pulse sensor 280N, and a heart rate sensor 280P, etc.

[0202] The working principle of the sensors will be illustrated below using the pulse sensor 280N and the heart rate sensor 280P as examples.

[0203] The pulse sensor 280N can detect pulse signals. In some embodiments, the pulse sensor 280N can detect pressure changes generated during arterial pulsation and convert them into electrical signals. There are many types of pulse sensors 280N, such as piezoelectric pulse sensors, piezoresistive pulse sensors, and photoelectric pulse sensors. Piezoelectric and piezoresistive pulse sensors can convert the pressure process of a pulse beat into a signal output using micro-pressure materials (such as piezoelectric elements, bridges, etc.). Photoelectric pulse sensors can convert changes in the transmittance of blood vessels during a pulse beat into a signal output through reflection or transmission, for example, by acquiring pulse signals using photoplethysmography (PPG).

[0204] The heart rate sensor 280P can detect heart rate signals. In some embodiments, the heart rate sensor 280P can acquire heart rate signals via PPG. The heart rate sensor 280P can convert changes in vascular dynamics, such as changes in pulse rate (heart rate) or blood volume (cardiac output), into signal outputs through methods such as reflection or transmission. In some embodiments, the heart rate sensor 280P can measure signals of electrical activity induced in cardiac tissue via electrodes attached to the skin, i.e., acquire heart rate signals via electrocardiography (ECG).

[0205] In some embodiments, the pulse sensor 280N and the heart rate sensor 280P can be packaged in a single pulse / heart rate sensor. This pulse / heart rate sensor can acquire pulse and heart rate signals via PPG.

[0206] Processor 210 may include one or more processing units, such as application processors (APs), modem processors, graphics processing units (GPUs), image signal processors (ISPs), controllers, video codecs, digital signal processors (DSPs), baseband processors, and / or neural network processing units (NPUs). These different processing units may be independent devices or integrated into one or more processors.

[0207] Electronic device 200 implements display functions through a GPU, a display screen 294, and an application processor. The GPU is a microprocessor for image processing, connected to the display screen 294 and the application processor. The GPU is used to perform mathematical and geometric calculations and for graphics rendering. Processor 210 may include one or more GPUs, which execute program instructions to generate or modify display information.

[0208] Electronic device 200 can perform shooting functions through ISP, camera 293, video codec, GPU, display screen 294 and application processor.

[0209] The SIM card interface 295 is used to connect a SIM card. The SIM card can be inserted into or removed from the SIM card interface 295 to make contact with and separate from the electronic device 200. The electronic device 200 can support one or N SIM card interfaces, where N is a positive integer greater than 1. The SIM card interface 295 can support Nano SIM cards, Micro SIM cards, SIM cards, etc. Multiple cards can be inserted into the same SIM card interface 295 simultaneously. The multiple cards can be of the same or different types. The SIM card interface 295 is also compatible with different types of SIM cards. The SIM card interface 295 is also compatible with external memory cards. The electronic device 200 interacts with the network through the SIM card to realize functions such as calls and data communication. In some embodiments, the electronic device 200 uses an eSIM, such as an embedded SIM card.

[0210] The wireless communication function of electronic device 200 can be implemented through antenna 1, antenna 2, mobile communication module 250, wireless communication module 260, modem processor, and baseband processor. Antenna 1 and antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in electronic device 200 can be used to cover one or more communication frequency bands. Different antennas can also be multiplexed to improve antenna utilization. For example, antenna 1 can be multiplexed as a diversity antenna for a wireless local area network. In some other embodiments, the antennas can be used in conjunction with tuning switches.

[0211] The mobile communication module 250 can provide solutions for wireless communication, including 2G / 3G / 4G / 5G, applied to the electronic device 200. The mobile communication module 250 may include at least one filter, switch, power amplifier, low noise amplifier (LNA), etc. The mobile communication module 250 can receive electromagnetic waves via antenna 1, and perform filtering, amplification, and other processing on the received electromagnetic waves before transmitting them to a modem processor for demodulation. The mobile communication module 250 can also amplify the signal modulated by the modem processor and convert it into electromagnetic waves for radiation via antenna 1. In some embodiments, at least some functional modules of the mobile communication module 250 may be housed in the processor 210. In some embodiments, at least some functional modules of the mobile communication module 250 and at least some modules of the processor 210 may be housed in the same device.

[0212] The wireless communication module 260 can provide solutions for wireless communication applications on the electronic device 200, including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), and infrared radiation (IR) technologies. The wireless communication module 260 can be one or more devices integrating at least one communication processing module. The wireless communication module 260 receives electromagnetic waves via antenna 2, performs frequency modulation and filtering of the electromagnetic wave signals, and sends the processed signal to processor 210. The wireless communication module 260 can also receive signals to be transmitted from processor 210, perform frequency modulation and amplification, and convert them into electromagnetic waves for radiation via antenna 2.

[0213] In some embodiments, antenna 1 of electronic device 200 is coupled to mobile communication module 150, and antenna 2 is coupled to wireless communication module 260, enabling electronic device 200 to communicate with networks and other devices via wireless communication technology. The wireless communication technology may include Global System for Mobile Communications (GSM), General Packet Radio Service (GPRS), Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), Time-Division Code Division Multiple Access (TD-SCDMA), Long Term Evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technologies, etc. In this embodiment, electronic device 200 can synchronize authentication factors, data acquisition capabilities, and authentication capabilities with other electronic devices in the device network via mobile communication module 250 and / or wireless communication module 260, so that multiple devices in the subsequent device network can perform their respective functions and collaboratively authenticate user identities. Here, data acquisition capability refers to the electronic device's ability to acquire authentication factors used to identify user identities. Authentication capability refers to the ability of an electronic device to authenticate collected authentication factors to obtain an authentication result. Different authentication factors can correspond to different collection capabilities, and different authentication factors can correspond to different authentication capabilities. After the above-mentioned resource synchronization is performed between multiple devices, the synchronized resource information can be stored in the memory 221, uploaded to the connected cloud server, stored in the device used for resource integration in the multi-device group (hereinafter referred to as the central device), or stored in an external storage device connected to the device. This application embodiment does not limit this.

[0214] Understandable, Figure 2 The components shown do not constitute a specific limitation on the electronic device 200. The electronic device 200 may also include more or fewer components than shown, or combine some components, or separate some components, or have different component arrangements. Furthermore, Figure 2 The combination / connection relationships between the components can also be adjusted and modified.

[0215] The software system of electronic devices can adopt a layered architecture, event-driven architecture, microkernel architecture, microservice architecture, or cloud architecture. This application embodiment uses a layered architecture as an example, where the layered architecture can include Harmony® operating system, iOS®, Android®, Microsoft®, or other operating systems. The authentication method provided in this application embodiment can be applied to terminals integrating the above-mentioned operating systems.

[0216] Understandably, electronic device 200 can be of different types of devices, such as a smartphone, tablet, or other user terminal device. For example, electronic device 200 can be a smart camera or other smart home device. Or, electronic device 200 can be a smart bracelet or other wearable device.

[0217] This application provides an authentication method, which can be executed by a first electronic device. The first electronic device can be any electronic device in the aforementioned communication system, such as an electronic device with authentication capabilities, an electronic device with data collection capabilities, an electronic device with both data collection and authentication capabilities, or a central device with scheduling capabilities, such as... Figure 3 As shown, the method includes the following steps: S301, the first electronic device receives an authentication request, which is used to request authentication of the first service.

[0218] In this step, the first electronic device may receive an operation from the user and, in response to the operation, generate an authentication request; or, the user performs an operation on the second electronic device, and, in response to the operation, the second electronic device generates an authentication request and sends it to the first electronic device, and then the first electronic device receives the authentication request from the second electronic device.

[0219] S302, The first electronic device determines the authentication method corresponding to the first service.

[0220] One possible approach is that, in this step, if the first service is a low-security-level service, the authentication method corresponding to the first service can be authentication using a single authentication factor; if the first service is a high-security-level service, the authentication method corresponding to the first service can be authentication using at least two authentication factors.

[0221] In this step, the first electronic device can independently decide on the authentication method corresponding to the first service; or, the first electronic device can determine the authentication method corresponding to the first service based on its own decision on the authentication method corresponding to the first service, and then combine this with the authentication methods corresponding to the first service decided by other electronic devices obtained from other electronic devices.

[0222] S303, the first electronic device schedules M electronic devices to authenticate the first service according to the authentication method, where M is a positive integer.

[0223] In this step, for example, the first electronic device can, according to the authentication method, schedule electronic device A (electronic device A can be the first electronic device or one of the M electronic devices) to collect authentication factors, and schedule electronic device B to authenticate the authentication factors collected by electronic device A, generating an authentication result, thereby realizing cross-device collection of authentication factors and multi-device collaborative authentication of the same service; in another example, the first electronic device can, according to the authentication method, schedule electronic device A to collect a first authentication factor, and schedule electronic device B to collect a second authentication factor, schedule electronic device C to authenticate the first authentication factor and generate a first authentication result, and schedule electronic device D to authenticate the second authentication factor and generate a second authentication result, thereby combining the two authentication results to complete the authentication of the first service.

[0224] Specifically Figure 3 The authentication method may have several different implementations, which will be further described in detail below in the embodiments of this application.

[0225] Implementation Method 1

[0226] Based on the above Figure 3 As shown in the steps, in S302 above, the specific way in which the first electronic device determines the authentication method corresponding to the first service can be: the first electronic device first determines the risk security level corresponding to the first service; then the first electronic device determines the authentication method that meets the security risk level based on the risk security level.

[0227] In traditional technologies, users typically possess multiple devices, such as mobile phones and smartwatches, each with varying authentication capabilities. If users rely solely on the authentication methods provided by their current device (e.g., voiceprint, 2D face recognition), security risks may arise. For instance, current smart locks generally authenticate users using their fingerprints, unlocking the door upon successful authentication. However, this can be compromised if an unauthorized user steals the homeowner's fingerprint, leading to unauthorized access. This demonstrates the inherent security limitations of traditional authentication methods. In contrast, the authentication method provided in the first implementation of this application improves the security of the authentication result because the authentication method for the first service meets the corresponding risk level. This method allows for the use of multiple authentication factors on multiple electronic devices to authenticate the same service, ensuring the reliability of the authentication result and enhancing the device's authentication security level. For example, for high-security door-opening services, the camera and lock can collaboratively perform face and fingerprint authentication.

[0228] like Figure 4 As shown, the specific process of the authentication method corresponding to this implementation method includes the following steps.

[0229] S401, the first electronic device receives an authentication request, which is used to request authentication of the first service.

[0230] The first electronic device can receive operations performed by the user on the first electronic device and generate an authentication request, or the first electronic device can receive authentication requests from other electronic devices.

[0231] For example, if a user issues a voice wake-up call to open the gallery app, the first electronic device is a smart speaker. The smart speaker receives the wake-up voice from the user, which is the authentication request. The first service can refer to opening the gallery app. In another example, the first electronic device receives an authentication request forwarded from another electronic device. For instance, if a user performs a door-opening operation, the door lock forwards an authentication request related to the door-opening operation to the smart speaker. In this example, the first service can refer to the door-opening service.

[0232] S402, the first electronic device determines the risk and security level corresponding to the execution of the first service.

[0233] For example, as shown in Table 8 below, different wake-up voice commands / operations correspond to different risk and security levels. For instance, if the first service is "open the weather app," since this service or operation does not involve personal data and therefore poses no risk, the corresponding risk and security level is determined to be Level 1. If the first service is "open the gallery app," since this service or operation involves personal data and has a medium risk, the corresponding risk and security level is determined to be Level 3. If the service or operation is "open the safe app," which involves sensitive personal data and has a high risk, the corresponding risk and security level is determined to be Level 4.

[0234] S403, the first electronic device determines the authentication method that meets the security risk level based on the risk level.

[0235] In this step, the authentication method that meets the security risk level can be the authentication of one authentication factor, or the authentication of two or more authentication factors. When the authentication method is the authentication of two or more authentication factors, it is also called the authentication combination method.

[0236] One possible implementation involves a first electronic device using a decision strategy to determine at least one authentication method that meets a security risk level; wherein the decision strategy includes, but is not limited to, at least one of the following: Prioritize the use of previously collected authentication factors; prioritize the use of collection capabilities that are imperceptible to the user; prioritize the use of collection capabilities on the user's local device. See the embodiments shown above for specific examples.

[0237] One possible implementation involves pre-determining available authentication factors and associated data collection capabilities from each of the first electronic device and the M electronic devices. Based on the risk level, the available authentication factors, and the associated data collection capabilities, an authentication method that meets the security risk level is determined. For example, if neither the first electronic device nor the M electronic devices support voiceprint authentication, and the first electronic device has fingerprint collection and authentication capabilities (i.e., voiceprint collection is unavailable), then fingerprint authentication is used instead of voiceprint authentication.

[0238] Another possible implementation involves identifying biometrics when the authentication request includes them, determining the user corresponding to the biometrics, and then determining the available authentication factors associated with the user, as well as the available authentication capabilities and data acquisition capabilities associated with those factors. Based on the risk level, and the available authentication factors, capabilities, and data acquisition capabilities, an authentication method that meets the security risk level is determined. For example, in conjunction with Embodiment 1, the smart speaker obtains an authentication request from a door lock. If the authentication request includes the user's fingerprint, the smart speaker first determines that the user corresponding to the fingerprint is the homeowner, Alisa. Then, it obtains available authentication factors associated with Alisa, such as face recognition and touchscreen behavior. The smart speaker's processor, based on the determined 3D face authentication method, determines the 3D face acquisition capability and 3D face authentication capability from the available authentication units and data acquisition units associated with the available authentication factors. For example, the 3D face acquisition capability belongs to the camera, and the 3D face authentication capability belongs to the smart speaker. In other words, the smart speaker schedules the camera to acquire face images, and the smart speaker's 3D face authentication unit authenticates the acquired face images.

[0239] Another possible implementation involves pre-synchronizing the resources of the first electronic device and the M electronic devices to obtain a synchronized resource pool. This resource pool includes authentication factors, data acquisition capabilities, and authentication capabilities from the M electronic devices. Based on the risk level and the resource pool, at least one authentication method that meets the risk level is determined. In other words, the first electronic device can obtain currently available authentication factors, data acquisition capabilities, and authentication capabilities, and select data acquisition and authentication capabilities that meet the security level. Based on the selected data acquisition and authentication capabilities, at least one authentication method is determined.

[0240] For example, when the first service has a low security risk level, a weaker authentication method can be used, such as voiceprint authentication or password authentication; when the first service has a medium security risk level, a moderately reliable authentication method can be used, such as face authentication, or voiceprint authentication and touch screen behavior authentication; when the first service has a high security risk level, a more reliable authentication method can be used, such as fingerprint authentication and voiceprint authentication, or 3D face authentication and fingerprint authentication.

[0241] It should be noted that, under certain circumstances, the first electronic device may also determine at least one authentication method corresponding to the first service according to a preset configuration table.

[0242] S404, The first electronic device, according to this authentication method, schedules M electronic devices to authenticate the first service.

[0243] In this embodiment, the first electronic device may or may not belong to the M electronic devices. For example, the first electronic device schedules the second electronic device to authenticate the first service according to the at least one authentication method; or, the first electronic device schedules both the first and second electronic devices to authenticate the first service according to the at least one authentication method. If the final authentication result is successful, the operating device is triggered to execute the first service; otherwise, it is not executed.

[0244] One possible implementation involves the first electronic device identifying the biometrics when the authentication request includes biometric features. The device then determines whether the user has permission to perform a first service. If the user has permission, M electronic devices are further dispatched to authenticate the first service. For example, in embodiment one, the smart speaker obtains an authentication request from a door lock. If the authentication request includes the user's fingerprint, the smart speaker first identifies the user corresponding to the fingerprint as the homeowner Alisa. Then, it determines whether the homeowner Alisa has permission to open the door. If the homeowner Alisa has permission, the camera is further dispatched to capture the user's face, and 3D face authentication is performed using the face image. It should be noted that in another possible approach, the first electronic device can also adjust the authentication method based on available authentication factors associated with the user, and the available authentication capabilities and acquisition capabilities associated with those available authentication factors. For example, if the decision-making unit of a smart speaker decides that at least one authentication method is 3D face authentication based on the security risk level of the first business, but the 3D face collection capability associated with the homeowner Alisa is unavailable, the decision method can be adjusted to use voiceprint authentication and pulse authentication.

[0245] Furthermore, in other possible implementations, the processor of the first electronic device can determine at least one authentication method based on the security risk level of the first service, the authentication factor associated with the user, and the available authentication capabilities and data collection capabilities associated with that authentication factor. For example, as shown in Embodiment 1, the door opening service is a high-security operation, and the available authentication factors associated with the homeowner Alisa include 3D face recognition, touchscreen behavior, and fingerprint recognition. Assuming that the available 3D face recognition capability associated with the homeowner Alisa is unavailable, the processor of the smart speaker can determine to use voiceprint authentication and pulse authentication.

[0246] In one possible embodiment, the first electronic device may also filter electronic devices that are far from the user's location based on the user's location, and / or the first electronic device may also filter electronic devices that are not applicable to the current business based on the business scenario.

[0247] In another possible embodiment, the first electronic device can also filter out electronic devices whose security environment does not meet the requirements based on the device's security level and current security status. For example, it can filter out electronic devices containing Trojan viruses.

[0248] In one possible embodiment, the first electronic device can also determine the authentication method for the first service according to a preset configuration table. That is, the preset configuration table contains pre-defined constraints set by the developers; different authentication combinations corresponding to the first service are manually configured in the preset configuration table, such as fingerprint authentication and facial recognition for door opening. Because the preset configuration table takes security risk levels into account during configuration, the first electronic device does not need to determine the security risk level based on the first service.

[0249] It should be noted that, in the first implementation of this application embodiment, the electronic device 200 can synchronize authentication factors, collection capabilities, and authentication capabilities with other electronic devices in the device network through the mobile communication module 250 and / or the wireless communication module 260, so that multiple devices in the device network can perform their respective functions and cooperate to authenticate user identities. Here, collection capability refers to the electronic device's ability to collect authentication factors used to identify user identities. Authentication capability refers to the electronic device's ability to authenticate the collected authentication factors to obtain authentication results. Different authentication factors can correspond to different collection capabilities, and different authentication factors can correspond to different authentication capabilities. After the above resource synchronization is performed between multiple devices, the synchronized resource information can be stored in the internal memory 221, uploaded to a connected cloud server, stored in a device (hereinafter referred to as the central device) used for resource integration in a multi-device group, or possibly stored in an external storage device connected to the device. This application embodiment does not limit this.

[0250] See Figure 5 , Figure 5 A schematic diagram of a communication device 500 is shown. The communication device 500 may include a data acquisition unit 501, an authentication unit 502, a resource management unit 503, a decision-making unit 504, and a scheduling unit 505. Wherein: The data collection unit 501 is used to collect authentication factors.

[0251] Specifically, the communication device 500 may include at least one acquisition unit 501, wherein an acquisition unit 501 can be used to acquire at least one type of authentication factor (hereinafter referred to as an authentication factor). This application embodiment illustrates the use of one acquisition unit acquiring one authentication factor as an example. Authentication factors may be fingerprints, faces, heart rates, pulses, behavioral habits, or device connection status, etc. For example, a face acquisition unit can be used to acquire faces, and the face acquisition unit may refer to... Figure 2 The camera 293 shown; the gait acquisition unit can be used to acquire gait data, and the gait acquisition unit can refer to... Figure 2 The camera 293 shown; the pulse acquisition unit can be used to acquire pulse, and the pulse acquisition unit can be... Figure 2 The pulse sensor shown is 280N; the heart rate acquisition unit can be used to acquire heart rate data. The heart rate acquisition unit can refer to... Figure 2 The heart rate sensor shown is 280P; the touch screen behavior acquisition unit can be used to collect touch screen behavior, and the touch screen behavior acquisition unit can refer to... Figure 2 The display screen 294 shown; the acquisition unit of the trusted device can be used to acquire the connection status and / or wearing status of the wearable device.

[0252] The authentication unit 502 is used to perform authentication based on the authentication factor and generate an authentication result. In software implementation, the authentication unit 502 is generally an authentication service integrated into the operating system. The authentication service can be a process running on the computer, and the computer program corresponding to the authentication service can be stored in the internal memory 221.

[0253] The communication device 500 may include at least one authentication unit 502, wherein an authentication unit 502 can be used to authenticate at least one authentication factor to obtain an authentication result. This application embodiment illustrates an example of one authentication unit authenticating one authentication factor. For example, a face authentication unit can be used to authenticate a face to obtain a face authentication result; a gait authentication unit can be used to authenticate gait information to obtain a gait authentication result; a pulse authentication unit can be used to authenticate a collected pulse to obtain a pulse authentication result; a heart rate authentication unit can be used to authenticate a collected heart rate to obtain a heart rate authentication result; a touchscreen behavior authentication unit can be used to authenticate collected touchscreen behavior information to obtain a touchscreen behavior authentication result; and a trusted device authentication unit can be used to authenticate the collected connection status and / or wearing status of a wearable device to obtain a trusted device authentication result.

[0254] Resource management unit 503 is used to invoke the synchronization service mechanism to synchronize resources with other devices in the device network, generate a resource pool, or maintain or manage the resource pool. Resource management unit 503 includes a resource pool, where resources can be authentication factors (or authentication factor information), device acquisition capabilities, device authentication capabilities, etc. Figure 2 The resource pool in the processor 210 shown in the resource management unit 503 can refer to the resource pool stored in the internal memory 221.

[0255] Specifically, the acquisition unit 501 can proactively report (this operation can be referred to as registration) the acquired authentication factors (or report the information of the acquired authentication factors) and the acquisition capabilities of the device to the resource management unit 503. In addition, the resource management unit 503 can also proactively obtain the acquired authentication factors (or report the information of the acquired authentication factors) and acquisition capabilities from the acquisition unit 501.

[0256] The authentication unit 502 can proactively report authentication capabilities to the resource management unit 503 (this operation can be referred to as registration). Alternatively, the resource management unit 503 can also proactively obtain authentication capabilities from the device where the authentication unit 502 is located.

[0257] For example, the resource pool maintained by the resource management unit 503 can be as shown in Table 2.

[0258] Table 2

[0259] In one possible implementation, consider that devices in a device network may belong to different users, and different devices may store authentication factors for different users. Alternatively, the same device in a device network may be used by different users, and the same device may store templates of authentication factors for different users. Therefore, the resource management unit 503 also manages information about the templates of authentication factors associated with each user. It should be understood that it is necessary to pre-associate the authentication factor templates stored by each device within the device network for each user. Specifically, one possible association method is: the user selects the authentication factor template belonging to their user from the device, and then establishes a correspondence between the selected authentication factor template and the user identifier; another possible association method is: when the device receives a newly entered authentication factor template (such as a secret template or the user's biometric template), it establishes a correspondence between the user's already entered biometric templates (such as fingerprint templates) and the newly entered authentication factor template. Since there is a one-to-one correspondence between the already entered biometric templates (such as fingerprint templates) and the user identifier, and there is also a correspondence between the user's newly entered feature template and the user's already entered biometric templates, the user's newly entered feature template also has a correspondence with the user identifier. In this way, the resource management unit 503 can obtain the authentication factor template corresponding to the user identifier by querying the user identifier, thereby generating authentication factor template information associated with each user.

[0260] For example, the template for the authentication factor of each user managed by the resource management unit 503 can be as shown in Table 3.

[0261] Table 3

[0262] It should be noted that the resource pool and authentication factor association maintained by resource management unit 503 can change dynamically. For example, when a device in the device network is powered off or offline, the authentication and data collection capabilities associated with that device will become unavailable. Another example is that when a device's software version is upgraded, the device may add a new authentication capability. Furthermore, when the set of devices in the device network changes (such as deleting a third electronic device), the authentication resource pool will no longer include the authentication factor, authentication capability, and data collection capability of that third electronic device.

[0263] Decision unit 504 is used to determine, based on the resources in the resource pool maintained by resource management unit 503, an authentication combination method that meets the security risk level using a decision strategy. Decision unit 504 may refer to... Figure 2 The processor 210 shown means that the actions executed by the decision-making unit are run and processed by the processor 210.

[0264] The decision-making strategy of the decision-making unit 504 may include, but is not limited to, at least one of the following: Decision-making strategy 1, prioritizing the use of authentication factors already stored in the device, for example, if the resource pool maintained by the device's resource management unit 503 includes templates for touch screen behavior, and the device has collected user touch screen behavior during historical usage, then the touch screen behavior is prioritized as an authentication factor for authentication; Decision-making strategy 2, prioritizing the use of collection units that are user-unnoticed (or have non-interruption operation characteristics) to collect authentication factors, for example, if the resource pool maintained by the device's resource management unit 503 includes templates for user faces, then the face collection unit is prioritized to collect the user's face; Decision-making strategy 3, prioritizing the use of authentication units that are user-unnoticed (or have non-interruption operation characteristics) for authentication, for example, if the resource pool maintained by the device's resource management unit 503 includes templates for user faces and the device has collected user faces, then the face authentication unit is prioritized to authenticate the user's face; Decision-making strategy 4, prioritizing the collection of authentication factors on the user's near-end device; Decision-making strategy 5, prioritizing authentication on the user's near-end device. For example, when a user is in the living room, devices in the living room (such as smart speakers) are used first to collect the user's voice or perform voiceprint authentication, rather than devices in the bedroom.

[0265] For example, in one possible scenario: the decision-making strategy can be a pre-established mapping table, which includes one or more authentication combinations. Since each authentication combination identifies a corresponding security risk level, the decision-making unit 504 can select the authentication combination corresponding to the risk level of the current business from the mapping table. In another possible scenario: the decision-making strategy can be a pre-established mapping table, which includes one or more authentication methods and their scores. The decision-making strategy also pre-configures indicator scores corresponding to various risk levels. Based on the indicator scores corresponding to the risk level of the current business, the decision-making unit 504 selects an authentication combination from the mapping table whose total score satisfies the indicator scores.

[0266] The scheduling unit 505 is used to determine the target authentication factor to be acquired based on the authentication combination method determined by the decision unit 504, as well as the target acquisition unit and the target authentication unit corresponding to the target authentication factor. The scheduling unit 505 schedules the target acquisition unit to acquire the target authentication factor, and the scheduling unit 505 schedules the target authentication unit to authenticate the acquired target authentication factor, generating an authentication result. Here, the target acquisition unit is the acquisition unit used to acquire the target authentication factor, and the target authentication unit is the authentication unit used to authenticate the target authentication factor. In software implementation, the scheduling unit 505 schedules specific open interfaces, such as scheduling the function interface exposed by the camera to acquire a face image, or scheduling the function interface of the face authentication service to acquire the face authentication result. The scheduling unit 505 can refer to... Figure 2 The processor 210 shown.

[0267] Decision unit 504 is also used to generate a final aggregated authentication result based on the authentication result obtained from at least one target authentication unit.

[0268] It should be noted that the embodiments of this application do not limit the integration method of the above-mentioned units in the electronic device. All of the above-mentioned units can be integrated into one electronic device, or some units can be integrated into one electronic device. For different types of electronic devices, some electronic devices may not have a secure execution environment, that is, no authentication capability, so they integrate a data acquisition unit but not an authentication unit; some electronic devices may be constrained by hardware components, such as smart speakers without cameras or fingerprint sensors, so they integrate an authentication unit but not a data acquisition unit; some electronic devices have both hardware and a secure execution environment, so they integrate both a data acquisition unit and an authentication unit.

[0269] In one possible scenario, the aforementioned acquisition unit 501, authentication unit 502, resource management unit 503, decision-making unit 504, and scheduling unit 505 can all be integrated into various electronic devices in the device network.

[0270] In another possible scenario, the resource management unit 503 and at least one authentication unit 502 are integrated into a third electronic device in the device network, the resource management unit 503 and at least one acquisition unit 501 are integrated into a second electronic device in the device network, and the resource management unit 503, decision-making unit 504 and scheduling unit 505 are integrated into a first electronic device in the device network.

[0271] For example, such as Figure 6AAs shown, the first electronic device is a central device with decision-making capabilities. Generally, central devices have a secure execution environment and / or are normally open devices. The first electronic device includes a resource management unit 503, a decision-making unit 504, and a scheduling unit 505. The second electronic device is an electronic device with data acquisition capabilities, including at least one acquisition unit 501 and a resource management unit 503. The third electronic device is an electronic device with authentication capabilities, including at least one authentication unit 502 and a resource management unit 503. Specifically, if the operating system of the electronic device does not have a unified data synchronization service, a synchronization service function can be added to the resource management unit. The resource synchronization process between devices can include the following steps: S601a, at least one acquisition unit on the second electronic device sends registration information to the resource management unit of the second electronic device.

[0272] For example, the acquisition unit can correspond to devices such as camera 293, sensor module 280, and microphone 270C. The resource management unit can correspond to the aforementioned... Figure 2 The processor 210 is shown. During the power-on process of the second electronic device, the acquisition units such as cameras and sensors notify the processor of the status of each acquisition unit so that the processor 210 can determine the acquisition units that are in an available state, and then save the status information of the acquisition units in an available state to the internal memory 221.

[0273] For example, the registration information may be the acquisition capability of the second electronic device, the acquired authentication factor, or information about the acquired authentication factor, etc. For instance, the registration information may include status information and a heart rate index, whereby the status information indicates that the second electronic device has a heart rate acquisition capability.

[0274] S602a, the resource management unit of the second electronic device stores the authentication factors and acquisition capabilities of the local device.

[0275] For example, the resource management unit of the second electronic device saves the authentication factor and acquisition capability of the local device to a storage unit, such as internal memory 221. In this embodiment, internal memory 221 can be volatile memory or non-volatile memory, or may include both. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM). It should be noted that the memory used in the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0276] S603a, the resource management unit of the second electronic device calls the synchronization service to synchronize data with the resource management unit of the first electronic device.

[0277] In other words, the resource management unit of the second electronic device sends the currently maintained information to the first electronic device, so that the information on the second electronic device is synchronized with the resource management unit of the first electronic device. For example, the status information and heart rate index of the second electronic device are sent to the resource management unit of the first electronic device, so that the resource management units on both the second and first electronic devices store the same status information and heart rate index.

[0278] S604a, at least one authentication unit on the third electronic device sends registration information to the resource management unit of the third electronic device.

[0279] For example, the registration information may be the authentication capability of a third electronic device, such as status information indicating that the third electronic device has heart rate authentication capability.

[0280] S605a, the resource management unit of the third electronic device maintains local authentication capabilities.

[0281] S606a, the resource management unit of the third electronic device reports authentication capability, and the resource management unit of the third electronic device calls the synchronization service to synchronize data with the resource management unit of the first electronic device.

[0282] In other words, the resource management unit of the third electronic device synchronizes the currently maintained information to the resource management unit of the first electronic device. For example, it synchronizes the status information of the third electronic device to the resource management unit of the first electronic device.

[0283] S607a, the resource management unit of the first electronic device maintains a resource pool including authentication factors, acquisition capabilities, and authentication capabilities.

[0284] S608a, the resource management unit of the first electronic device calls the synchronization service to synchronize the resource pool to the resource management unit of the second electronic device.

[0285] S609a, the resource management unit of the first electronic device calls the synchronization service to synchronize the resource pool to the resource management unit of the third electronic device.

[0286] In other words, the resource management unit of the first electronic device manages the authentication factors, acquisition unit capabilities, and authentication unit capabilities of multiple electronic devices in the device network. For example, the resource management unit of the first electronic device performs resource aggregation among devices. After resource aggregation, any device in the device network can obtain information about the acquisition unit or authentication unit deployed by any other device in the device network from the resource management unit of the first electronic device.

[0287] It should be noted that S601a to S603a may also occur after S604a to S606a, or S601a to S603a may be executed in parallel with S604a to S606a. This embodiment does not impose any restrictions on this.

[0288] Optionally, devices can synchronize resources through a connected network (such as a cloud server). The synchronization mechanism of the synchronization service may be, but is not limited to, at least one of the following: timed synchronization (e.g., synchronization every minute), triggered synchronization (e.g., synchronization in response to user operation), and update synchronization (e.g., synchronization when the information of the acquisition unit or authentication unit changes).

[0289] Alternatively, if the operating systems of various electronic devices have a unified data synchronization service, the resource management unit does not need to add a new synchronization service function; resource synchronization can be achieved using the existing data synchronization service. For details, please refer to [link to relevant documentation]. Figure 6A The example mentioned above.

[0290] like Figure 6B As shown, the first electronic device is a central device with decision-making capabilities, including a resource management unit 503, a decision-making unit 504, and a scheduling unit 505. The second electronic device is an electronic device with data acquisition capabilities, including at least one data acquisition unit 501. The third electronic device is an electronic device with authentication capabilities, including at least one authentication unit 502. The resource synchronization process between devices may include the following steps: S601b, at least one acquisition unit on the second electronic device sends first registration information to the resource management unit of the first electronic device.

[0291] For example, the first registration information may be the acquisition capability of the second electronic device, the acquired authentication factor, or information about the acquired authentication factor, etc. For instance, the first registration information may include status information and a heart rate index, whereby the status information indicates that the second electronic device has a heart rate acquisition capability.

[0292] S602b, at least one authentication unit of the third electronic device sends second registration information to the resource management unit of the first electronic device.

[0293] For example, the second registration information may be the acquisition capability of the second electronic device, the acquired authentication factor, or information about the acquired authentication factor, etc. For instance, the second registration information may include status information and a heart rate index, whereby the status information indicates that the second electronic device has a heart rate acquisition capability.

[0294] S603b, the first electronic device locally maintains a resource pool including authentication factors, acquisition capabilities, and authentication capabilities.

[0295] In other words, the resource management unit of the first electronic device manages the authentication factors, acquisition capabilities of the acquisition units, and authentication capabilities of the authentication units of multiple electronic devices in the device network. Essentially, the resource management unit of the first electronic device performs resource aggregation among the devices. After resource aggregation, any device in the device network can obtain information about the acquisition units or authentication units deployed by any other device in the device network from the resource management unit of the first electronic device.

[0296] For example, combining Figure 1B In other words, Figure 1BIn the device network shown, camera 12 actively reports the collected facial biometric templates to smart TV 13, along with information about the face acquisition unit, confirming that the acquisition unit is in an available state. Alternatively, Figure 1B In the illustrated device network, camera 12 actively reports indication information to smart TV 13. This indication information indicates that camera 12 has stored a facial biometric template and that the face acquisition unit of camera 12 is in an available state. After receiving the reported information, resource management unit 503 of smart TV 13 maintains or updates the resource pool, which includes the facial biometric template of camera 12 (or includes the indication information indicating that camera 12 has stored a facial biometric template) and that the face acquisition unit of camera 12 is in an available state.

[0297] The methods provided in the embodiments of this application are described below by way of example. Each embodiment is based on... Figure 1B The following explanation uses a smart home system as an example.

[0298] Example 1

[0299] Example 1 involves Figures 7A to 8 .like Figure 7A In the scenario shown, the smart lock, camera, and smart speaker are wirelessly connected. When a user returns from outside, they open the door. Upon receiving the user's opening action, the smart lock, camera, and smart speaker work together to authenticate the user's identity.

[0300] See Figure 7B As shown, the specific process of the authentication method in this scenario includes the following steps.

[0301] The S701 smart door lock receives user input and collects the user's fingerprint.

[0302] For example, such as Figure 7A As shown, when a user returns from outside, they open the door by touching the fingerprint sensor on the door lock with their finger. The fingerprint acquisition unit on the door lock (such as the fingerprint sensor) collects the user's fingerprint and triggers the generation of an authentication request. This authentication request is used to request identity authentication, and it includes the collected fingerprint. It should be noted that the following steps are explained using the door opening operation as an example of fingerprint unlocking and the authentication request including the user's fingerprint.

[0303] S702, the smart door lock sends an authentication request to the smart speaker, which includes the user's fingerprint.

[0304] In other words, in this scenario, the smart speaker acts as a central device, used to coordinate the network devices in the smart home system to collaboratively authenticate the user's identity.

[0305] The S703 smart speaker authenticates fingerprints and generates authentication results.

[0306] Specifically, the smart speaker includes a fingerprint authentication unit. This unit acquires a fingerprint template and uses it to authenticate the fingerprint. If authentication is successful, the generated fingerprint authentication result includes information indicating successful fingerprint authentication. Optionally, the authentication result may also include the identifier of the target user corresponding to the successfully authenticated fingerprint. If authentication fails, the result includes information indicating that the fingerprint authentication failed. For example, the smart speaker acts as a central device. The fingerprint authentication unit in the smart speaker can first perform fingerprint authentication using an existing fingerprint template. If authentication is successful, the generated fingerprint authentication result includes information indicating successful authentication, and the target user matching the fingerprint in the authentication request is the homeowner, Alisa.

[0307] S704: The smart speaker determines whether the fingerprint authentication result is successful. If the authentication result is unsuccessful, then S714 is executed; if the authentication result is successful, then S705 is executed.

[0308] S705: When the fingerprint authentication result is successful, the smart speaker can also identify the target user corresponding to the fingerprint and determine whether the target user has the authority to perform the door opening function. If the result is yes, the unlocking function is executed, or in other words, S706 is executed; otherwise, S714 is executed.

[0309] For example, the smart speaker can determine whether the homeowner Alisa has the authority to perform the door opening function by querying the resource pool, such as by querying Table 4 below.

[0310] Table 4

[0311] S706, the smart speaker uses a pre-set decision strategy to determine the target authentication factor associated with the target user as 3D face, the target authentication capability associated with the target authentication factor as the 3D face authentication capability on the smart speaker, and the target acquisition capability as the 3D face acquisition capability on the camera.

[0312] The specific details of the decision-making strategy can be found in the text above. Figure 5 The corresponding decision-making unit 504 has decision-making strategies 1 to 4.

[0313] In detail, the decision-making unit of the smart speaker can query the resource management unit and use decision-making strategies to determine the target authentication factor associated with the target user as 3D face, the authentication unit associated with the target authentication factor as 3D face, and the acquisition unit associated with the target acquisition unit as 3D face.

[0314] In one implementation, the resource management unit of the smart speaker can be pre-configured according to the above... Figure 4 The method steps shown synchronize the data acquisition and authentication capabilities of the smart lock and camera. For example, after synchronization, the resource pool maintained by the smart speaker's resource management unit includes the smart lock with fingerprint acquisition capability, the camera with 3D face acquisition capability, and the smart speaker with 3D face authentication and fingerprint authentication units.

[0315] For example, the smart speaker queries the resource management unit for the authentication factors associated with the homeowner Alisa, and the query results are shown in Table 5.

[0316] Table 5

[0317] Furthermore, as a central device, the smart speaker can first be classified as a high-risk level based on Table 6 for the door opening operation.

[0318] Table 6

[0319] Subsequently, based on the authentication factors associated with the homeowner Alisa, and given that the S701 fingerprint door lock has already collected the user's fingerprint, the smart speaker uses a decision-making strategy to prioritize the existing fingerprint authentication method. It then overlays the user-unnoticed 3D face capture method and 3D face authentication method, ultimately determining to use the 3D face + fingerprint authentication combination method corresponding to the high security level to authenticate the user's identity. In other words, the smart speaker's decision-making unit uses a decision-making strategy to determine that the target authentication factor associated with the target user is 3D face, the target authentication unit associated with the target authentication factor is the 3D face authentication unit, and the target capture unit is the 3D face capture unit.

[0320] For example, the decision-making strategy for a smart speaker to determine the authentication combination method corresponding to the risk level requirements may include: Decision Strategy 1: A mapping table is pre-established to determine the appropriate authentication combination based on the risk level requirements. This mapping table can be created by developers exhaustively listing all possible authentication combinations, assigning a corresponding risk level and operation to each combination. The mapping table is defined and allocated based on: a) empirical values; b) experimental test results, such as testing each combination with large datasets. The mapping table can be pre-installed in the device during the early stages of development or downloaded from a server.

[0321] Decision Strategy 2: Preconditions can be set. First, assign minimum scores for FAR and FRR to different risk levels (high, medium, and low). Then, calculate the sum of scores for all available authentication methods using a formula that sums the scores of various authentication methods. Select an authentication combination that is greater than or equal to the minimum score. For example: Currently available authentication methods include 2D face authentication, voiceprint authentication, and fingerprint authentication. Each authentication method has a quantified score describing the credibility of the authentication: voiceprint scores 60; fingerprint scores 80; and 3D face scores 95. The authentication combinations that can meet the minimum score are: Authentication Combination 1) Face + Voiceprint; Authentication Combination 2) Face + Fingerprint; Authentication Combination 3) Voiceprint + Fingerprint. Assuming a high-risk operation requires a minimum score of 160, the decision strategy decides to use Authentication Combination 2) for high-risk business authentication.

[0322] The smart speaker then queries Table 7 in the resource management unit to determine that there are available authentication and acquisition units for 3D faces, and available authentication units for fingerprints. Finally, using a decision-making strategy, it determines the target authentication factors as fingerprints and 3D faces, the target acquisition units as fingerprint acquisition units and 3D face acquisition units, and the target authentication units as fingerprint authentication units and 3D face authentication units. Figure 7A The example shown ultimately determined to use a combination of fingerprint and 3D face authentication. The fingerprint acquisition unit of the smart door lock is used to acquire fingerprints, the 3D face acquisition unit of the camera is used to acquire 3D faces, the fingerprint authentication unit of the smart speaker is used to authenticate fingerprints, and the 3D face authentication unit of the smart speaker is used to authenticate 3D faces.

[0323] Table 7

[0324] Optionally, when multiple fingerprint (or 3D face) acquisition units or multiple authentication units are available, the smart speaker can filter out unsuitable acquisition and / or authentication units based on the business scenario and / or user location. For example, if the current business is door opening, the speaker might prioritize using the fingerprint acquisition unit on the door or the camera acquisition unit on the door to collect the user's 3D face, rather than using smart home devices inside the user's house to collect both fingerprints and 3D faces.

[0325] In the S707, the smart speaker sends a capture command to the camera, which instructs the capture of a 3D face.

[0326] S708, the camera captures facial images.

[0327] S709: The camera sends captured facial images to the smart speaker.

[0328] It should be noted that in this embodiment of the method, the smart speaker can also obtain the 3D face from the camera, that is, the camera can actively report it, or the smart speaker can actively obtain it from the camera.

[0329] The S710 smart speaker authenticates facial images and generates 3D facial authentication results.

[0330] In other words, the 3D face authentication unit of the smart speaker uses the stored 3D face template to authenticate the 3D face captured by the camera and generate the 3D face authentication result.

[0331] S711: The smart speaker determines whether the face authentication result is successful. If the authentication is successful, proceed to S712; otherwise, proceed to S714.

[0332] When facial recognition is successful, the smart speaker sends an unlocking command to the smart door lock.

[0333] For example, when the final authentication result is successful, the smart speaker's processor sends an open command to the smart door lock; when the final authentication result is unsuccessful, the smart speaker's processor sends a refuse-to-open command to the smart door lock.

[0334] The S713 smart lock controls the door to open based on the received unlocking command.

[0335] S714: When fingerprint authentication fails, the target user does not have the authority to perform the door opening operation, or facial authentication fails, the smart lock sends a command to the smart lock to refuse to unlock.

[0336] The S715 smart lock prevents the door from opening based on the received command to refuse unlocking.

[0337] As can be seen from the above embodiments, since the security level of the door opening service is high, the smart door lock, smart speaker and camera work together to authenticate the user's fingerprint and 3D face. Since the fingerprint authentication result and the 3D face authentication result are highly reliable, the security problems caused by simply using the user's fingerprint for identity authentication can be improved, and the reliability of the authentication result is improved.

[0338] In one possible embodiment, in S701 above, when the smart lock has fingerprint authentication capability, the smart lock can first authenticate the user's fingerprint and generate a fingerprint authentication result. If the authentication is successful, subsequent steps are executed; otherwise, subsequent steps are not executed.

[0339] In one possible implementation, if the fingerprint sensor of the smart lock is damaged, preventing the user from collecting the user's fingerprint, the smart speaker can authenticate the user's identity based on 3D facial recognition. If the authentication is successful, the lock will be unlocked.

[0340] In one possible implementation, if the smart lock's battery runs out, preventing the user from properly collecting their fingerprint, the user can choose to issue a voice wake-up command such as "Hey Celia, open the door." Figure 7C As shown, the microphone on the door can send the user's wake-up voice to the smart speaker, which then performs voiceprint authentication. It should be noted that the microphone and the smart lock are powered independently. Alternatively, the indoor smart speaker can collect the user's wake-up voice and perform voiceprint authentication. Furthermore, after successful voiceprint authentication, the user's 3D face can be collected using the same method for 3D face authentication. Finally, based on the 3D face authentication result and the voiceprint authentication result, the smart lock can be instructed to open or refuse to open the door.

[0341] In one possible embodiment, such as Figure 7D As shown, if the camera on the door lock captures the faces of users within a designated area outside the door, and the capture result includes the faces of multiple users, with some faces passing authentication but others failing, one possibility is that the smart speaker can instruct the smart door lock to unlock directly. Another possibility, to improve security, is that the smart speaker can further send the captured facial images to the user's mobile phone for confirmation, or the smart speaker can instruct the camera on the door lock to send the captured facial images to the user's mobile phone. For example, as shown... Figure 8 As shown, the phone displays as follows Figure 8 The interface 800 shown in (a) displays notifications related to smart living applications, including a request to open the door and asks the user to confirm. When the user taps to open the notification, the phone displays the following... Figure 8 The interface 810 shown in (b) displays an image 811 and a prompt box 812, as shown in the figure. The prompt box includes an open control 813 and a reject control 814. When the user determines that the current user is a trusted user based on the image 811, they can click to operate the open control 813; otherwise, they can click to operate the reject control 814. This method can further improve the reliability and security of the authentication results.

[0342] Example 2

[0343] Example 2 involves Figure 9A and Figure 9B .like Figure 9AIn the scenario shown, a wireless connection is established between the smart TV and the smart speaker. When the user operates the smart TV and issues the voice wake-up command "Hey Hey Hey, open the weather app", it triggers the user's identity authentication.

[0344] See Figure 9B As shown, the specific process of the authentication method in this scenario includes the following steps.

[0345] The S901 smart speaker collects the user's wake-up voice, such as "Xiaoyi Xiaoyi, open the weather app".

[0346] For example, the smart speaker collects sounds from the surrounding environment in real time and processes the sounds in real time to obtain the user's wake-up voice.

[0347] S902, the smart speaker determines that opening the weather app is a low-security-risk operation, and then uses a decision-making strategy to determine that the authentication method corresponding to this operation can be voiceprint authentication.

[0348] The specific details of the decision-making strategy can be found in the text above. Figure 5 The corresponding decision-making unit 504 has decision-making strategies 1 to 4.

[0349] Specifically, in one possible scenario, the smart speaker's decision-making unit maintains a preset mapping table. This mapping table can be an exhaustive list of all possible authentication methods by the developers, and each operation is configured with a corresponding risk and security level. For example, as shown in Table 8 below, the mapping table is configured with the risk and security levels corresponding to different wake-up voice commands or operations, as well as the authentication trust level requirements.

[0350] Table 8

[0351] As shown in Table 8 above, when a user issues the wake-up voice command "Open the weather app", the risk security level corresponding to this service is Level 1. The authentication method for this operation needs to meet the authentication trust level requirements of Level 1. Specifically, the authentication method can be voiceprint authentication.

[0352] The S903 smart speaker performs voiceprint authentication on the user's wake-up voice and generates the voiceprint authentication result.

[0353] For example, the scheduling unit of the smart speaker schedules the voiceprint authentication unit of the smart speaker to perform voiceprint authentication on the user's wake-up command according to the authentication method determined by the decision unit, and generates an authentication result.

[0354] S904: The smart speaker determines whether the voiceprint authentication result is successful. If the authentication is successful, proceed to S905; otherwise, proceed to S906.

[0355] S905: When the authentication result is authentication failure, the smart speaker will determine not to instruct the smart TV to open the weather app.

[0356] For example, a smart speaker can also respond via voice if a user's authentication fails.

[0357] S906: When the authentication result is successful, the smart speaker instructs the smart TV to open the weather app.

[0358] As can be seen, in this embodiment, when the user's operation is a low-security-risk operation, the electronic device can use a voiceprint authentication method corresponding to the security-risk level of the operation for authentication.

[0359] Example 3

[0360] Example 3 involves Figure 10A and Figure 10B .like Figure 10A In the scenario shown, a wireless connection is established between the smart TV, smart speaker, and smart band. When the user operates the smart TV and issues the wake-up voice command "Hey Celia, open the gallery app," the user's identity is authenticated.

[0361] See Figure 10B As shown, the specific process of the authentication method in this scenario includes the following steps.

[0362] S1001, the smart speaker collects the user's wake-up voice, where the user's wake-up voice is "Xiaoyi Xiaoyi, open the gallery application".

[0363] S1002, the smart speaker determines that opening the gallery app is a medium-security-risk operation. Then, the smart speaker uses a decision-making strategy to determine that the authentication method corresponding to this operation can be a combination of voiceprint authentication and pulse authentication.

[0364] The specific details of the decision-making strategy can be found in the text above. Figure 5 The corresponding decision-making unit 504 has decision-making strategies 1 to 4.

[0365] Specifically, in one possible scenario, the decision-making unit of the smart speaker can determine, based on a pre-maintained mapping table, that when the wake-up voice command is "open the gallery app," the risk security level corresponding to that operation is determined to be Level 3. The authentication method for that operation needs to meet the authentication trust level requirements of Level 3. Specifically, the authentication method can be voiceprint authentication + pulse authentication.

[0366] The S1003 smart speaker performs voiceprint authentication on the user's wake-up voice and generates the voiceprint authentication result.

[0367] For example, the scheduling unit of the smart speaker instructs the voiceprint authentication unit of the smart speaker to perform voiceprint authentication on the user's wake-up command according to the authentication method determined by the decision unit.

[0368] S1004, the smart speaker uses pre-collected pulse information obtained from the smart bracelet to authenticate the user's pulse and generate a pulse authentication result.

[0369] For example, the scheduling unit of the smart speaker obtains the collected pulse information from the resource management unit and uses the pulse authentication unit in the smart speaker to authenticate the user's pulse.

[0370] S1005, the smart speaker aggregates the authentication results of voiceprint and pulse to generate the final authentication result.

[0371] For example, the decision unit of the smart speaker obtains the voiceprint authentication result from the voiceprint authentication unit and the pulse authentication result from the pulse authentication unit, and aggregates the two authentication results to generate the final authentication result. Specifically, the aggregation method can be that if any one or more authentication results fail, the authentication result fails; if all authentication results are successful, the authentication result is successful.

[0372] S1006, the smart speaker determines whether the final authentication result is successful. If the authentication is successful, proceed to S1007; otherwise, proceed to S1008.

[0373] S1007: If the authentication result is authentication failure, then determine not to instruct the smart TV to open the weather app.

[0374] For example, a smart speaker can also respond via voice if a user's authentication fails.

[0375] S1008: When the authentication result is successful, the smart speaker instructs the smart TV to open the Gallery app.

[0376] Optionally, when the smart TV receives an instruction to open the gallery app, it can open and display pictures stored on local or external storage.

[0377] As can be seen, in this embodiment, when the user's operation is of medium security risk level, the electronic device can use a combination of voiceprint authentication and pulse authentication corresponding to the security risk level of the operation for authentication.

[0378] Example 4

[0379] Example 4 involves Figure 11A and Figure 11B .like Figure 11A In the scenario shown, a smart TV is connected to an external storage drive containing sensitive user data. The smart TV, mobile phone, and smart speaker establish a wireless connection. When the user operates the smart TV and issues a voice wake-up command, "Hey Celia, open the safe app," user authentication is triggered.

[0380] See Figure 11B As shown, the specific process of the authentication method in this scenario includes the following steps.

[0381] S1101, the smart speaker collects the user's wake-up voice, where the user's wake-up voice is "Xiaoyi Xiaoyi, open the safe app".

[0382] In the safe application, the data may come from a storage disk, which may contain sensitive user data such as financial statements and medical examination results.

[0383] S1102, the smart speaker determines that the operation of opening the safe application is a high-security-risk operation. Then, the smart speaker uses a decision-making strategy to determine that the authentication method corresponding to this operation can be a combination of 3D face authentication and voiceprint authentication.

[0384] The specific details of the decision-making strategy can be found in the text above. Figure 5 The corresponding decision-making unit 504 has decision-making strategies 1 to 4.

[0385] Specifically, in one possible scenario, the decision-making unit of the smart speaker can determine, based on a pre-maintained mapping table, that the risk security level corresponding to the wake-up voice command "Open the safe application" is Level 4. The authentication method for this operation needs to meet the authentication trust level requirements of Level 4. Specifically, the authentication method can be 3D face authentication + voiceprint authentication.

[0386] S1103, the smart speaker performs voiceprint authentication on the user's wake-up voice and generates the voiceprint authentication result.

[0387] For example, the scheduling unit of the smart speaker instructs the voiceprint authentication unit of the smart speaker to perform voiceprint authentication on the user's wake-up command according to the authentication method determined by the decision unit. The voiceprint authentication unit of the smart speaker generates the voiceprint authentication result, and then the smart decision unit obtains the voiceprint authentication result from the voiceprint authentication unit.

[0388] S1104, the smart speaker instructs the smart TV to capture facial images.

[0389] For example, the scheduling unit of the smart speaker instructs the camera of the smart TV to capture facial images based on the authentication method determined by the decision-making unit.

[0390] S1105, the camera of a smart TV captures facial images.

[0391] For example, in one possible scenario, the smart TV's camera captures the user's facial image without the user's awareness; in another possible scenario, the smart TV can display a prompt message on the screen, which prompts the user to stand within the camera's field of view, such as facing the smart TV and standing in front of it, so that the camera can accurately capture the user's facial image.

[0392] S1106, the smart TV sends the collected facial images to the smart speaker.

[0393] The S1107 smart speaker obtains facial images from the smart TV, authenticates the user's face, and generates the facial authentication result.

[0394] For example, the smart speaker's face authentication unit authenticates the face image and generates a 3D face authentication result.

[0395] The S1108 smart speaker aggregates the authentication results of voiceprint and 3D face to generate the final authentication result.

[0396] For example, the decision unit of the smart speaker obtains the voiceprint authentication result from the voiceprint authentication unit and the 3D face authentication result from the face authentication unit, and aggregates the two authentication results to generate the final authentication result. Specifically, the aggregation method can be that if any one or more authentication results fail, the authentication result fails; if all authentication results are successful, the authentication result is successful.

[0397] S1109, the smart speaker determines whether the final authentication result is successful. If the authentication is successful, proceed to S1110; otherwise, proceed to S1111.

[0398] S1110, when the authentication result is authentication failure, the smart speaker determines not to instruct the smart TV to open the safe app.

[0399] For example, the smart speaker can also respond that the user authentication failed and instruct the smart TV to refuse to open the safe app.

[0400] S1111: When the authentication result is successful, the smart speaker instructs the smart TV to open the safe app.

[0401] As can be seen, in this embodiment, when the user's operation is a high-security-risk operation, the electronic device can use a combination of voiceprint authentication and 3D face authentication corresponding to the security-risk level of the operation for authentication.

[0402] Example 5

[0403] Example 5 involves Figure 12A and Figure 12B .like Figure 12A In the scenario shown, the microwave oven, smart speaker, and mobile phone establish a wireless connection. The user operates the microwave oven, and when the user issues a voice wake-up command, "Hey Celia, microwave on high for five minutes," it triggers the user's identity authentication.

[0404] See Figure 12B As shown, the specific process of the authentication method in this scenario includes the following steps.

[0405] S1201, the smart speaker collects the user's wake-up voice, where the user's wake-up voice is "Xiaoyi Xiaoyi, microwave on high for five minutes".

[0406] S1202, the smart speaker determines that heating the microwave oven on high for five minutes is a high-risk operation. Then, the smart speaker uses a decision-making strategy to determine that the authentication method corresponding to this operation can be a combination of fingerprint authentication and voiceprint authentication.

[0407] The specific details of the decision-making strategy can be found in the text above. Figure 5 The corresponding decision-making unit 504 has decision-making strategies 1 to 4.

[0408] Specifically, in one possible scenario, the decision-making unit of the smart speaker can determine the risk and security level of the operation involving the microwave oven as Level 4 based on a pre-maintained mapping table. The authentication method for this operation needs to meet the authentication trust level requirements of Level 4. Specifically, the authentication method can be fingerprint authentication + voiceprint authentication.

[0409] S1203, the smart speaker performs voiceprint authentication on the user's wake-up voice and generates the voiceprint authentication result.

[0410] For example, the scheduling unit of the smart speaker instructs the voiceprint authentication unit of the smart speaker to perform voiceprint authentication on the user's wake-up command according to the authentication method determined by the decision unit. The voiceprint authentication unit of the smart speaker generates the voiceprint authentication result, and then the smart decision unit obtains the voiceprint authentication result from the voiceprint authentication unit.

[0411] S1204, the smart speaker instructs the mobile phone to collect the user's fingerprint.

[0412] S1205, the mobile phone receives fingerprint input from the user.

[0413] For example, a smart living application on a mobile phone displays a prompt message asking the user to enter their fingerprint. After receiving the prompt, the user actively touches the fingerprint sensor, and the fingerprint sensor in the mobile phone collects the user's fingerprint.

[0414] Optionally, the above-mentioned S1205 can also be executed by a smart speaker and a mobile phone. For example, the smart speaker issues a voice prompt to prompt the user to enter their fingerprint on the mobile phone, and then the user operates on the fingerprint sensor of the mobile phone, and the fingerprint acquisition unit in the mobile phone acquires the user's fingerprint.

[0415] S1206, the mobile phone sends the collected fingerprint to the smart speaker.

[0416] S1207: The mobile phone authenticates the fingerprint entered by the user and generates the fingerprint authentication result.

[0417] For example, the fingerprint authentication unit in the mobile phone authenticates the received fingerprint and generates the fingerprint authentication result.

[0418] The S1208 smart speaker combines voiceprint and fingerprint authentication results to generate the final authentication result.

[0419] S1209, the smart speaker determines whether the final authentication result is successful. If the authentication is successful, proceed to S1210; otherwise, proceed to S1211.

[0420] S1210, when the authentication result is authentication failure, the smart speaker determines not to instruct the microwave oven to start microwave heating.

[0421] For example, the smart speaker can also respond with a voice message if the user authentication fails, without giving any instructions to the microwave oven.

[0422] S1211, when the authentication result is successful, the smart speaker instructs the microwave oven to start heating for five minutes.

[0423] As can be seen, in this embodiment, when the user's operation is a high-security-risk operation, the electronic device can use a combination of voiceprint authentication and fingerprint authentication corresponding to the security-risk level of the operation for authentication.

[0424] In one possible embodiment, before executing S1203 above, it can be further determined whether the user corresponding to the authenticated voiceprint has permission to operate the microwave oven. If the user has permission, the subsequent steps are executed; otherwise, the subsequent steps are not executed. For example, if the user corresponding to the authenticated voiceprint is the homeowner Alisa, the subsequent steps can be executed; if the user corresponding to the authenticated voiceprint is a child, the subsequent steps are not executed, and the microwave oven is instructed to refuse to start heating or to prompt the user that authentication has failed.

[0425] In one possible embodiment, the device's security level and current security status can be further considered to filter out data collection / authentication capabilities on insecure devices. Assuming that in the scenario shown in Embodiment 5, the data collection capabilities, authentication capabilities, and current device status of the smart speaker and smartphone are as shown in Table 9.

[0426] Table 9

[0427] As shown in Table 9, the smart speaker's security status fails to meet authentication requirements due to the presence of Trojan horse threats. Therefore, the voiceprint authentication unit on the smart speaker is filtered out, and the mobile phone is used for voiceprint and fingerprint authentication. Thus, S1203 could be: the mobile phone acquires the wake-up voice from the smart speaker, the mobile phone's voiceprint authentication unit performs voiceprint authentication on the wake-up voice, and generates a voiceprint authentication result. Optionally, S1207 could be: the mobile phone acquires the fingerprint authentication result from the fingerprint authentication unit and the voiceprint authentication result from the voiceprint authentication unit, aggregating the voiceprint and fingerprint authentication results to generate the final authentication result.

[0428] In one possible embodiment, inappropriate data collection / authentication capabilities can be further filtered based on the business scenario or the user's current location. Assuming that in the scenario shown in Embodiment 5, the data collection capabilities, authentication capabilities, and current device location of the smart speaker and smartphone are as shown in Table 10.

[0429] Table 10

[0430] As shown in Table 10, if the user is currently in the bedroom, the smart speaker is relatively far away from the user. The user can choose to use their mobile phone to collect their voiceprint and fingerprint, and finally complete the fingerprint authentication and voiceprint authentication on their mobile phone.

[0431] It should be understood that this embodiment requires the device location and the user location to be determined in advance. One possible way to determine the device location is that the user can actively mark the location of a fixed device, such as a smart TV, smart speaker, or camera. When the user starts using the device, the user can mark the device location in the application.

[0432] In addition, there are several ways to determine a user's location. One possible implementation is that the image acquisition device has a user location detection module, which updates the user's current location based on the real-time captured images. For example, if there is a surveillance camera in the nursery, the bedroom can capture images in real time. When the nursery camera captures the user's image, the user's current location is updated to the nursery. If there is a camera on the smart screen in the living room, and the smart screen captures the user's image, the user's current location is updated to the living room. In other possible cases, since there may not be a camera in the bedroom, if the smart screen does not detect the user, the user can be prompted to come to the living room for authentication when authentication is initiated.

[0433] Alternatively, another way to determine the user's location is: the user location detection module in the electronic device can continuously sense user signals or periodically sense user information, and when a user is sensed, determine the device's current location as the user's current location. In addition, devices in the device network can also synchronize the sensed user location to other devices so that other devices can determine the user's current location.

[0434] As can be seen from the above embodiments, the authentication method provided in this application can enable the authentication of the same service by using authentication factors provided by at least two electronic devices. That is, multiple authentication factors are used on multiple electronic devices to authenticate the same service. For example, for the high-security door opening service, the camera and door lock are called to perform face authentication and fingerprint authentication in collaboration to ensure the reliability of the authentication result and improve the authentication security level of the device.

[0435] Implementation Method Two

[0436] Based on the above Figure 3The steps shown, in S301 above, the first electronic device receiving an authentication request includes: the first electronic device receiving a target operation, which is used to trigger the generation of an authentication request. In S302 above, the specific method by which the first electronic device determines the authentication method corresponding to the first service may be: the first electronic device first queries the correspondence between the target operation and the target security value, determines the target security value required to execute the target operation, and the target operation is used to trigger the execution of the first service; the first electronic device determines M1 authentication devices, where M1 is a positive integer, and the M1 authentication devices are devices capable of authenticating user information, and the M1 authentication devices are included in the M electronic devices. In S303 above, the first electronic device schedules the M electronic devices to authenticate the first service according to the authentication method, including: the first electronic device obtaining the authentication result of at least one of the M1 authentication devices; determining the total authentication security value according to the correspondence between the authentication method and the authentication security value of the at least one authentication device, and the authentication result; if the total authentication security value is not less than the target security value, then the authentication is successful; otherwise, it fails. Optionally, if the authentication is successful, the method further includes: the first electronic device triggering the operation device to execute the target operation.

[0437] Considering that traditional technologies involve users performing relatively sensitive operations (such as unlocking and payment), these operations typically require strict authentication. If users can only perform facial recognition using weak authentication methods provided by the device itself (such as 2D face recognition), the authentication results are likely to be insecure. In contrast to existing technologies, this second implementation method can trigger the device to perform the target operation only when the total authentication security value is not less than the target security value required to execute the target operation. This provides the necessary level of authentication for the first service, thereby improving the security of identity authentication.

[0438] It should be noted that, for ease of understanding the following text, some concepts involved in this second implementation method will be introduced first: (a) Correspondence between the root key storage environment of the authentication device and the score of the root key storage environment The root key can refer to the key used to encrypt and store authentication credentials. The higher the security level of the root key storage environment, the higher the score of the root key storage environment for that authentication device.

[0439] The root key storage environment of an authentication device may include: the inside Secure Element (inSE) level, the trusted execution environment (TEE) level, white-box, and key segmentation.

[0440] In this application embodiment, white-box refers to white-box cryptography, the main design idea of ​​which is to obfuscate the cryptographic algorithm so that attackers cannot know the specific algorithm operation process. In this way, the root key can be hidden in the software that implements white-box cryptography. The entire algorithm execution process is represented by a lookup table, so that attackers cannot obtain any information about the root key from the software or cryptographic operation process, thus effectively protecting the root key.

[0441] In the key segmentation technique of this application, the key components that make up the root key are stored separately in the system. The root key is dynamically generated by the key components only when needed. Generating the root key requires all key components, and each key component is independently stored in a logical entity. These components need to be stored separately. This method can solve the problem of "hard-coding" the root key and can ensure the security of the root key to a certain extent.

[0442] Table 11 Correspondence between the root key storage environment of the terminal device and the score of the root key storage environment

[0443] (b) Correspondence between certification equipment, certification method and certification security value

[0444] In this embodiment, based on the scores of the root key storage environment of the authentication device and the authentication method, a correspondence between the authentication device, authentication method, and authentication security value can be established. Table 12 exemplarily illustrates an example of the correspondence between the authentication device, authentication method, and authentication security value. In this correspondence, the authentication security value can be calculated according to a first calculation rule. In one possible implementation, the first calculation rule includes: a weighted sum of the scores of the root key storage environment and the authentication method. In Table 12, the weight corresponding to the score of the root key storage environment is set to 0.3, and the weight corresponding to the score of the authentication method is set to 0.7.

[0445] Table 12 Correspondence between certification equipment, certification methods, and certification security values

[0446] In this application embodiment, the authentication security value can be understood as the authentication security level of the authentication device. The higher the authentication security value corresponding to the authentication device and authentication method, the higher the authentication security level of the authentication device using that authentication method; conversely, the lower the authentication security level of the authentication device using that authentication method.

[0447] (c) Operating equipment

[0448] In this embodiment of the application, the terminal device that receives user requests is referred to as the operating device.

[0449] The operating device may or may not have the ability to authenticate user information.

[0450] For example, if a user requests to make a payment on a smart TV, the device provided in this embodiment can invoke the smart TV to perform facial recognition on the user. This example shows that the smart TV is an operating device, and since it needs to perform 2D facial recognition on the user, it is also an authentication device.

[0451] (d) Correspondence between operation and safety value

[0452] The correspondence between operations and security values ​​indicates the security value required for an operation. An operation is considered successfully authenticated and can only be executed if an obtained authentication security value is not less than the security value required for the operation, or if a total authentication security value calculated from multiple obtained authentication security values ​​is not less than the security value required for the operation. Otherwise, the operation is considered unsuccessful to authenticate and cannot be executed.

[0453] In one possible implementation, the correspondence between operations and security values ​​can be preset. Specifically, when the device provided in this embodiment is a server deployed in the cloud, the correspondence between operations and security values ​​can be stored on the cloud server; when the device provided in this embodiment is a router, the correspondence between operations and security values ​​can be stored on the router; and when the device provided in this embodiment is a terminal device, the correspondence between operations and security values ​​can be stored on the terminal device. In another possible implementation, the correspondence between operations and security values ​​can also be set by the user.

[0454] A security value can be a score or a level. Table 13 of this application's embodiments illustrates the correspondence between several operations and security values, using a security value as a score as an example. As shown in Table 13, highly sensitive operations such as payment and unlocking can be set with higher security values ​​(e.g., 95, 90, 85, etc.). Moderately sensitive operations such as unlocking the screen and logging into an account can be set with relatively moderate security values ​​(e.g., 75). Operations involving user type identification can be set with lower security values ​​(e.g., 20).

[0455] Taking the first row of Table 13 as an example, in one application scenario, before a user watches a smart TV, the smart TV needs to perform a "user type identification" operation (this operation can be initiated by the user or automatically triggered after the smart TV is turned on). The purpose of this operation is to allow the smart TV to play TV programs according to the user type. For example, if the user is a parent, a TV program guide corresponding to the parent is provided, and there is no time limit for playback; if the user is a child, a TV program guide corresponding to the child is provided, and the program automatically turns off after 20 minutes. Compared to operations such as payment and unlocking, this operation does not require a very high security level, so a lower security value can be set, such as 20 points in Table 13. As shown in Table 13, small-amount payment operations can be defined as payments of less than 300 yuan, and large-amount payment operations can be defined as payments of not less than 300 yuan.

[0456] Table 13 Correspondence between Operation and Safety Values

[0457] The authentication method provided in the embodiments of this application will be described below in conjunction with practical application scenarios.

[0458] Based on the above, Figure 13 An exemplary flowchart of an authentication method provided in an embodiment of this application is shown below. The following section will illustrate this method in the context of a user requesting a small-amount payment on a smart TV. Figure 13 Let me introduce it. Figure 13 The authentication scheme shown is illustrated using the device provided in the embodiment of this application as the server, and the operating device has authentication capabilities as an example. Figure 13 Because the operating equipment has authentication capabilities, therefore in Figure 13 The equipment operated by the lieutenant general is also identified as certified equipment b2.

[0459] It should be noted that, Figure 13 The authentication scheme shown uses the device provided in the embodiment of this application as an example to illustrate the server. The following... Figure 13 The execution entity "server" in the text can also be replaced with the "device" provided in this application embodiment. When the device provided in this application embodiment is a router, the relevant scheme executed by the device is similar to the scheme executed when the device is a server, and it may be necessary to... Figure 13 The execution entity involved in this process, "server," has been replaced with "router," and will not be elaborated upon further here.

[0460] like Figure 13 As shown, the method includes: S1300, the operating device receives a request from the user to perform a target operation on the operating device.

[0461] In the scenario of a user requesting a small payment on a smart TV, in the S1300, the operating device is a smart TV, such as... Figure 15A As shown, a user wants to watch a show on a smart TV. The video app on the smart TV is in children's mode. The smart TV displays, "This show requires payment to watch. You can purchase the entire series for 10 yuan. Do you want to buy?" If the user clicks "Buy Now," the smart TV receives a request to perform a "10 yuan payment operation." In other words, in this scenario, the target operation is: "a 10 yuan payment operation."

[0462] S1301, the operating device generates a first authentication request and sends it to the server. The first authentication request is used to request the server to authenticate the target operation. The first authentication request may include first indication information, which is used to indicate the target operation.

[0463] Correspondingly, the server receives the first authentication request.

[0464] In the scenario of a user requesting a small payment on a smart TV, in step S1301, the smart TV sends a first authentication request to the server. This first authentication request is used to request authentication for the "payment operation of 10 yuan".

[0465] S1302, the server determines the security value corresponding to the target operation based on the preset correspondence between operations and security values. For ease of description in this embodiment, the security value corresponding to the target operation is referred to as the target security value. The preset correspondence between operations and security values ​​can be as shown in Table 14 above.

[0466] Taking the scenario of a user requesting a small payment operation on a smart TV as an example, the target operation is a "payment operation of 10 yuan". In Table 13 above, if the security value corresponding to a small payment operation of less than 300 yuan is defined as 85 points, then the server can determine the security value corresponding to the "payment operation of 10 yuan" as 85 points by querying the preset correspondence between the operation and the security value (the "payment operation of 10 yuan" belongs to the "small payment operation" of less than 300 yuan in Table 13 above).

[0467] S1303, when the operating device can support the authentication of user information, the server determines one or more authentication security values ​​corresponding to the operating device based on the correspondence between the authentication device, authentication method and authentication security value.

[0468] Optionally, the operating device may send its supported authentication methods and its root key storage environment to the server before S1303, so that the server can establish a correspondence between the operating device, authentication methods, and authentication security values. In one possible implementation, the operating device sends its supported authentication methods and its root key storage environment to the server upon initial network access, so that the server can store them. In another possible implementation, after S1302 and before S1303, after receiving the first authentication request, the server queries the operating device to see if the operating device has authentication capabilities. If the operating device has authentication capabilities, it sends its supported authentication methods and root key storage environment to the server. For example, the operating device (smart TV) has 2D face recognition capabilities and has already reported its capabilities to the server before S1303.

[0469] It should be noted that an operating device may have one or more authentication capabilities. Accordingly, the server can obtain all the authentication methods supported by the operating device and determine the authentication security value corresponding to each authentication method.

[0470] In the scenario of a user requesting a small payment on a smart TV, the smart TV sends its supported authentication methods and root key storage environment to the server before step S1303. Therefore, in step S1303, it can be determined that when the smart TV uses 2D face recognition as the authentication method and the root key storage environment is TEE, the corresponding authentication security score is 76.

[0471] S1304, the server determines whether the authentication security value corresponding to the operating device is less than the target security value.

[0472] S1304 is divided into the following cases.

[0473] In the first scenario, the operating device supports one authentication method.

[0474] In this case, if the authentication security value corresponding to the operating device is found to be less than the target security value, then execute S1305. If it is not less than the target security value, then execute the following... Figure 14 S1416 in the text (this part will be introduced later and will not be repeated here).

[0475] In the second scenario, the operating device supports multiple authentication methods.

[0476] In a scenario where the operating device supports multiple authentication methods, in the first possible implementation, if the maximum value among all authentication security values ​​corresponding to the operating device is less than the target security value, it can be determined that the authentication security value corresponding to the operating device is less than the target security value, and step S1305 is executed. If it is not less than the target security value, meaning that at least one of the multiple authentication methods supported by the operating device can satisfy the authentication of the target operation, then the following can be executed. Figure 14 S1416 in the middle.

[0477] In a second possible implementation where the operating device supports multiple authentication methods, the server can comprehensively calculate multiple authentication security values ​​corresponding to the operating device based on the multiple authentication methods supported by the operating device. If the result is less than the target security value, it can be determined that the authentication security value corresponding to the operating device is less than the target security value, and step S1305 is executed. If it is not less than the target security value, the following can be executed. Figure 14 S1416 in the document. The calculation of multiple authentication security values ​​can be found in the discussion of S1310 below, and will not be described here.

[0478] In a third possible implementation where the operating device supports multiple authentication methods, if the operating device supports both password authentication and biometric authentication, then in one possible implementation, multiple authentication security values ​​corresponding to the biometric authentication method of the operating device can be calculated. If the result is less than the target security value, it can be determined that the authentication security value of the operating device is less than the target security value, and step S1305 is executed. If it is not less than the target security value, then the following can be executed. Figure 14 S1416. In this way, users can authenticate solely through biometric authentication, avoiding the need to enter a password and improving the convenience of user authentication. The calculation of multiple authentication security values ​​can be found in the discussion of S1310 below, and will not be described here. Furthermore, in this case, in subsequent S1306, if the operating device is determined to be one of the M1 authentication devices, the second authentication request sent to the operating device can carry indication information for the biometric authentication method of that operating device. Thus, the operating device can authenticate user information using only the biometric authentication method indicated in the second authentication request.

[0479] In one possible implementation, the server may also skip S1303 to S1304, that is, after receiving the first authentication request in S1301, the server directly executes S1305.

[0480] Taking the first scenario above as an example, considering the scenario where a user requests a small payment operation on a smart TV, in S1304, the smart TV only supports one authentication method, namely 2D face recognition. The smart TV's authentication security value of 76 points is less than the target security value of 85 points, so S1305 is executed.

[0481] S1305, the server determines M1 authentication devices, where M1 is a positive integer, and these M1 authentication devices can be the aforementioned... Figure 3 All or some of the M authentication devices in the method embodiment shown.

[0482] Optionally, each authentication device may send its supported authentication methods and its own root key storage environment to the server before S1305, so that the server can establish the correspondence between the authentication devices, authentication methods, and authentication security values ​​(as shown in Table 12 above). In one possible implementation, each authentication device may send a first message to the server. Each authentication device reports a first message, and the first message reported by the first authentication device carries indication information for indicating the authentication methods supported by the first authentication device. The M1 authentication devices include the first authentication device, or it can be understood that one of the M1 authentication devices is referred to as the first authentication device. For example, each authentication device may send its supported authentication methods to the server when it first accesses the network (e.g., by sending its supported authentication methods through the first message reported by each authentication device). Optionally, each authentication device may also report its own root key storage environment to the server (e.g., the root key storage environment of the first device may also be carried through the first message reported by the first device), so that the server can store it. In another possible implementation, after S1302 and before S1305, the device sends a query request to the first authentication device to query the authentication methods supported by the first authentication device. The device receives a query response from the first authentication device, which carries indication information indicating the authentication methods supported by the first authentication device. Optionally, after receiving the first authentication request, the server queries each authentication device for the authentication methods supported by each authentication device (e.g., through a query request). Optionally, it can also query the root key storage environment of each authentication device (e.g., by sending a query request to each authentication device; in this example, the query request is also used to query the root key storage environment of the authentication devices). For example, the authentication device (smart speaker) has voiceprint recognition capabilities and has already reported its capabilities to the server before S1305.

[0483] In S1305, one possible implementation is that the M1 authentication devices can be all authentication devices that the current server can search for and that are in a communicably reachable state. For example, if there are K authentication devices pre-registered on the server, where K is an integer not less than M1, then the M1 authentication devices are some or all of the K authentication devices. There are multiple ways to select the M1 authentication devices from the K authentication devices, which will be described in detail later and will not be described here.

[0484] In the scenario of a user requesting a small payment on a smart TV, prior to S1305, the server has already obtained the authentication method and root key storage environment of both the smart TV and the smart speaker. In S1305, the server can currently find the smart speaker and smart TV as the only authentication devices in a communicably reachable state (other devices may be powered off, damaged, etc.). In this case, the server can identify the smart TV and smart speaker as M1 authentication devices and execute S1306. Figure 13 Certified device b1 is a smart speaker. Certified device b2 is a smart TV.

[0485] S1306, the server sends a second authentication request to each of the M1 authentication devices. The second authentication request is used to request the authentication device to authenticate the user information.

[0486] Correspondingly, each of the M1 authentication devices receives a second authentication request sent by the server.

[0487] In response to a second authentication request received by an authentication device, when the authentication device supports multiple authentication methods, in one possible implementation, the server can determine the authentication method used by the authentication device and include indication information for the authentication method in the second authentication request, so that the authentication device can perform authentication using the authentication method indicated in the second authentication request. The method by which the server determines the authentication method used by the authentication device will be described later and will not be repeated here.

[0488] In another possible implementation, the second authentication request does not carry indication information for specifying the authentication method. The authentication device decides independently which authentication method to use, or it uses all the authentication methods it supports. The authentication device deciding independently is similar to the method described above where the server determines which authentication method the device uses. In this case, the authentication security value corresponding to the authentication method needs to be stored on the authentication device. Optionally, the calculation rules for the authentication security value can also be stored. Thus, the authentication device can calculate the corresponding authentication security value based on these rules, its own authentication method, and the root key storage environment. In this embodiment, after the hardware and / or software of the authentication device is updated, the authentication security value or the calculation rules for the authentication security value stored by the authentication device can be updated accordingly.

[0489] Taking a scenario where a user requests a small payment on a smart TV as an example, the server sends a second authentication request to both the smart speaker and the smart TV, and this second authentication request does not carry any indication information to specify the authentication method.

[0490] S1307, the authentication device that receives the second authentication request sent by the server authenticates the user information and generates a second authentication response.

[0491] In S1307, an authentication device must first obtain user information before authenticating that information. Specifically, there are several ways for an authentication device to obtain user information. It can collect the information itself, such as by using a smart TV's camera to capture the user's facial information. Alternatively, other devices can collect the information and transmit it to the authentication device via a network. For example, a server can schedule cameras in the room to capture the user's facial information and send it to the smart TV.

[0492] Taking the scenario of a user requesting a small payment on a smart TV as an example, such as Figure 15BAs shown, the smart TV receives a second authentication request from the server. Since this request does not include information indicating the authentication method, the smart TV decides which method to use. Because the smart TV only supports 2D face recognition, it chooses to use this method. When authenticating the user using 2D face recognition, the screen displays a prompt saying "Please look at the camera." When the user looks at the smart TV's camera, the screen displays the user's face information captured by the camera. The smart TV can pre-store the user's face information used for authentication. It compares the captured face information with the stored information. If the comparison is successful, authentication is confirmed; otherwise, it fails. After authentication, the smart TV generates a second authentication response, indicating whether the authentication was successful or failed.

[0493] On the other hand, the smart speaker receives a second authentication request from the server. Since this second request does not carry any information indicating the authentication method, the smart speaker decides which method to use. Because the smart speaker only supports one authentication method—voiceprint recognition—it chooses to authenticate the user. When authenticating the user using voiceprint recognition, the smart speaker will emit a voice prompt asking, "Please confirm whether you agree to the payment? Please answer 'agree' or 'disagree'." The user can answer "agree," and the smart speaker will then authenticate the collected voiceprint information as "agree." This verifies that the user answered "agree" and not "disagree," and also checks if the user's voiceprint matches the voiceprint information previously stored on the smart speaker for authentication. If the smart speaker determines that the user's voiceprint matches the previously stored voiceprint and performs semantic analysis to confirm that the user entered "agree," then authentication is successful; otherwise, authentication fails. After authentication is completed, the smart speaker generates a second authentication response, indicating whether the authentication was successful or failed.

[0494] S1308, for one of the M1 authentication devices, the authentication device returns a second authentication response to the server. The second authentication response may carry an identifier indicating the authentication device, the authentication method used by the authentication device, and an indication of whether the authentication was successful. Optionally, when the authentication device supports only one authentication method, the indication of the authentication method used by the authentication device may not be included in the second authentication response. Optionally, when the second authentication request carries authentication information indicating the authentication method, the second authentication response returned by the authentication device may not include the indication of the authentication method used by the authentication device.

[0495] Among the M1 authentication devices, each authentication device may return one or more second authentication responses (for example, if an authentication device uses two authentication methods, it can return a second authentication response, which carries the authentication results of the two authentication methods; or it may return two second authentication responses, with each second authentication response carrying the authentication result corresponding to one authentication method). It is also possible that some of the M1 authentication devices return second authentication responses, for example, some authentication devices may not return second authentication responses due to their own link failures or other reasons.

[0496] In one possible implementation, the second authentication response returned by at least one authentication device is sent to the device after the at least one authentication device has completed authenticating the user information. After the authentication device completes the authentication of the user information, the second authentication response returned by the authentication device may indicate either successful or failed authentication.

[0497] In another possible implementation, the second authentication response is sent to the device after the at least one authentication device has failed to complete the authentication of the user information within a predetermined time. In this case, the second authentication response returned by the authentication device indicates that the authentication result is authentication failure. For example, the predetermined time may be a period of time starting from the receipt of the second authentication request, such as 10 seconds or 2 minutes after receiving the second authentication request. If the authentication device fails to complete the authentication of the user information within 10 seconds or 2 minutes from the date of receiving the second authentication request, it determines that the authentication result is authentication failure and sends a second authentication response to the device, which indicates that the authentication result is authentication failure.

[0498] In one possible scenario, the authentication device receives a second authentication request, but the user has not completed identity authentication on the authentication device, or the authentication device has not completed the authentication of the user information within a preset time. In this case, the authentication device will not return a second authentication response or will return a second authentication response indicating that the authentication result is authentication failure.

[0499] In a scenario where a user requests a small-amount payment on a smart TV, in step S1307 above, assuming both the smart TV and the smart speaker have successfully authenticated, the second authentication response returned by the smart speaker may include: indication information indicating successful authentication, and the smart speaker's identifier. Optionally, the second authentication response returned by the smart speaker may further include: indication information indicating that the smart speaker uses voiceprint recognition authentication. The second authentication response returned by the smart TV may include: indication information indicating successful authentication, and the smart TV's identifier. Optionally, the second authentication response returned by the smart TV may further include: indication information indicating that the smart TV uses 2D face recognition authentication.

[0500] For example, if the authentication method used by each authentication device has already been specified in the second authentication request, then the second authentication response may not carry indication information indicating the authentication method used by the authentication device. That is, the second authentication response returned by the smart speaker includes: indication information indicating successful authentication, and the smart speaker's identifier. The second authentication response returned by the smart TV includes: indication information indicating successful authentication, and the smart TV's identifier.

[0501] In one possible implementation, in S1308 above, for an authentication device, the second authentication response returned by the authentication device may carry the authentication security value corresponding to the authentication device. In this case, the correspondence between the authentication method and the authentication security value of the authentication device, or the calculation rules for the authentication method and the authentication security value, need to be stored on the authentication device, and the server does not need to execute S1309 below, but directly executes step 210. For example, the second authentication response returned by a smart speaker is: authentication successful, smart speaker identifier, authentication security value of 20 points; the second authentication response returned by a smart TV is: authentication successful, smart TV identifier, authentication security value of 76 points. In this embodiment, the format of the message in the second authentication response is not limited.

[0502] If the second authentication response does not include an authentication security value, the server executes S1309.

[0503] S1309, the server determines the authentication security value corresponding to M1 authentication devices based on the preset correspondence between authentication devices, authentication methods and authentication security values, and the second authentication response.

[0504] For a second authentication response returned by an authentication device, if the second authentication response indicates successful authentication, an authentication security value is determined for that authentication device based on the preset correspondence between authentication devices, authentication methods, and authentication security values. If the second authentication response indicates authentication failure, the authentication security value for that authentication device is determined to be 0 points. If an authentication device does not return a second authentication response, the authentication security value for that authentication device is 0 points.

[0505] Taking a scenario where a user requests a small-amount payment on a smart TV as an example, in S1309, the server, based on the second authentication response returned by the smart speaker, learns that the smart speaker has successfully performed voiceprint authentication. Therefore, according to Table 12 above, the authentication security value for the smart speaker is 20 points. The server, based on the second authentication response returned by the smart TV, learns that the smart speaker has successfully performed 2D face recognition. Therefore, according to Table 12 above, the authentication security value for the smart TV is 76 points.

[0506] In one possible approach, if the second authentication response returned by any of the M1 devices in S1308 already carries the authentication security value corresponding to the authentication method used by the authentication device, then the server can obtain the authentication security value of the M1 electronic devices and execute step 210 without having to query based on the preset correspondence between authentication devices, authentication methods and authentication security values.

[0507] S1310, the server calculates the total authentication security value based on the authentication security values ​​corresponding to M1 authentication devices.

[0508] In S1310, the server can calculate the total authentication security value according to the second calculation rule. There are several methods for calculating the total authentication security value, which are illustrated below.

[0509] Example 1: For instance, with two authentication security values, the total authentication security value can be calculated using formula (1): ...Formula (1) In formula (1), x is one authentication security value, y is another authentication security value, and z is the total authentication security value. In this example, formula (1) can also be described as an example of a second calculation rule.

[0510] In the scenario of a user requesting a small payment on a smart TV, in S1310, the two authentication security values ​​are 76 points and 20 points respectively. Substituting these values ​​into formula (1), the total authentication security value can be calculated as follows:

[0511] This application also provides other methods for calculating the total authentication security value, such as: Example 2: If there are more than two authentication security values, one possible calculation scheme, or an example of a possible second calculation rule, is that the total authentication security value can be calculated by repeatedly using the above formula (1). For example, if there are three authentication security values, two of them are calculated according to formula (1). Furthermore, the results and the third authentication security value are substituted into the above formula (1) for calculation, and the resulting value is the total authentication security value.

[0512] For example, if there are three authentication security values, namely 76 points, 20 points, and 20 points, and 76 points and 20 points are used as the values ​​of parameters x and y in the above formula (1), the result is 86. Substituting 86 and 20 back into formula (1), the value obtained is the total authentication security value:

[0513] The above examples illustrate how to calculate the total authentication security value when there are two authentication security values ​​and three authentication security values. If there are four or more authentication security values, the above examples for the three authentication security values ​​will not be repeated.

[0514] Example 3: For instance, if there are multiple authentication security values, the total authentication security value can be calculated using formula (2): ...Formula (2) In formula (2), i is a variable that takes values ​​sequentially, Fi is the i-th authentication security value, j is the total number of authentication security values, and a1, a2, n, c, and M1 are constants. Among them, a1 and a2 can be the same or different, and their specific values ​​can be chosen according to the actual situation. For multiplication, z is the total authentication security value. In this example, formula (2) can also be described as an example of a second calculation rule.

[0515] Example 4: Besides the solutions provided in Examples 1 and 2, there are several other ways to determine the total authentication security value. For example, multiple authentication security values ​​can be added together and then multiplied by a preset value. For instance, if two authentication security values ​​are 76 and 20, the total authentication security value is (76 + 20). 0.95 = 91.2.

[0516] The methods for calculating the total authentication security value based on multiple authentication security values ​​shown in Examples 1 to 5 above are merely examples and are not intended to be limiting.

[0517] Taking the scenario of a user requesting a small payment on a smart TV as an example, the server calculates the total authentication security value to be 86 points using formula (1).

[0518] S1311, the server determines whether the total authentication security value is less than the target security value required for the target operation.

[0519] If the total authentication security value is not less than the target security value required for the target operation, then execute S1312; if the total authentication security value is less than the target security value required for the target operation, then execute S1314.

[0520] In the scenario where a user requests a small payment on a smart TV, in S1311, the total authentication security value of 86 points calculated using the above formula (1) is greater than the target security value of 85 points, so S1312 is executed.

[0521] S1312, the server returns a first authentication success response to the operating device.

[0522] Correspondingly, the operating device receives a first authentication success response, which carries indication information to indicate successful authentication.

[0523] In the scenario where a user requests a small payment on a smart TV, in S1312, the server returns a first authentication success response to the smart TV.

[0524] S1313, When the operating device receives the first successful authentication response, it executes the target operation.

[0525] Taking a scenario where a user requests a small payment on a smart TV as an example, in S1313, when the smart TV receives the first successful authentication response, it executes the user's requested "payment operation of 10 yuan". For example... Figure 15C As shown, the smart TV displays the message "Purchase successful, you can watch now," and users can select the show they want to watch using the remote control.

[0526] S1314, The server returns a first authentication failure response to the operating device.

[0527] Correspondingly, the operating device receives a first authentication failure response, which carries indication information indicating authentication failure.

[0528] S1315, When the operating device receives the first authentication failure response, it refuses to execute the target operation.

[0529] The scenario of a user requesting a small-amount payment on a smart TV reveals that if only 2D facial recognition is used, the authentication security score is only 76 points, lower than the 85 points required for the target operation. This indicates that the smart TV's authentication capability is insufficient for small-amount payments, resulting in poor security. Furthermore, users may refuse to use the smart TV for payment due to security concerns, leading to payment failure. Figure 13The provided solution combines multiple devices with weak authentication capabilities (lower authentication security values) for collaborative authentication, and then comprehensively judges whether authentication is successful based on multiple authentication results. Thus, when no authentication device with strong authentication capabilities is available, this application can also combine multiple authentication devices with weaker capabilities for collaborative authentication, thereby meeting the user's higher security level requirements (higher security values). Furthermore, since user information can be authenticated through one or more authentication devices using one or more authentication methods in this application embodiment, the requirements for the authentication capabilities of the operating device itself can be reduced, thereby reducing the requirements for individual terminal devices and thus reducing the manufacturing cost of the operating device. On the other hand, when the device provided in this application embodiment is a router, and the router, operating device, and authentication device belong to the same local area network, the signaling interaction between the router and the operating device, and between the router and the authentication device, can be transmitted through the local area network, which can greatly improve the transmission speed and thus accelerate the data processing flow.

[0530] Figure 14 An example is shown Figure 13 One possible implementation method is to determine in step 1304 above that the authentication security value corresponding to the operating device is not less than the target security value.

[0531] It should be noted that, Figure 14 The authentication scheme shown uses the device provided in the embodiment of this application as an example to illustrate the server. The following... Figure 14 The execution entity "server" in the text can also be replaced with the "device" provided in the embodiments of this application. When the device provided in the embodiments of this application is a router, the relevant scheme executed by the device is similar to the scheme executed when the device is a server, and it is necessary to... Figure 14 The execution entity "server" mentioned in the text can be replaced with "router", which will not be elaborated further here.

[0532] like Figure 14 As shown, the authentication method includes the following steps: S1400 to S1404 are the same as S1300 to S1304 mentioned above.

[0533] If, in step 1404 above, it is determined that the authentication security value corresponding to the operating device is not less than the target security value, then step 1416 is executed.

[0534] Step 1416: The server sends a third-party authentication request to the operating device.

[0535] Correspondingly, the operating device receives a third authentication request sent by the server.

[0536] In the first scenario, the operating device supports one authentication method.

[0537] In this case, the third authentication request is used to request the operating device to authenticate the user. It may or may not carry indication information indicating the authentication method used.

[0538] In the second scenario, the operating device supports multiple authentication methods.

[0539] In a scenario where the operating device supports multiple authentication methods, one possible implementation is that the third authentication request may carry indication information indicating all authentication methods supported by the operating device, or it may not carry indication information indicating the authentication method. The operating device then performs authentication using all authentication methods it supports.

[0540] In another possible implementation where the operating device supports multiple authentication methods, the server determines that the operating device uses some of the authentication methods it supports, and the third authentication request carries indication information indicating the authentication method used by the operating device.

[0541] The server determines which authentication method(s) the operating device should use, and there are several possible solutions: Option 1: If the authentication security value corresponding to an authentication method supported by the operating device is greater than the target security value, then that authentication method shall be determined as the authentication method required by the operating device.

[0542] Option 2: The server determines the multiple authentication methods to be used by the operating device, and these multiple authentication methods meet the condition that "the total authentication security value corresponding to the multiple authentication methods is greater than the target security value". The total authentication security value corresponding to the multiple authentication methods can be calculated using the above formula (2).

[0543] Optionally, in Scheme 2, if the operating device supports multiple authentication methods including both password authentication and multiple biometric authentication methods, then multiple biometric authentication methods can be used for authentication. This can avoid the user entering a password, simplify the user's operation, and improve user convenience.

[0544] In cases where the operating device supports multiple authentication methods, the third authentication request sent by the server may not carry indication information for indicating the authentication method. The operating device can determine the authentication method itself, and the determination process can be similar to the above-mentioned scheme where the server determines the authentication method used by the device. In this case, the authentication security value corresponding to the authentication method of the operating device needs to be stored on the operating device, or the rules for calculating the authentication security value need to be stored on the operating device.

[0545] Step 1417: The device is operated to authenticate the user information and determine whether the authentication is successful; if it fails, proceed to step 1418; if it succeeds, proceed to step 1419.

[0546] Step 1418: The operating device refuses to execute the target operation.

[0547] Step 1419: Operate the equipment to perform the target operation.

[0548] pass Figure 14 As can be seen from the scheme shown, if the operating device has authentication capabilities and the authentication capabilities can meet the needs of the target operation, then the operating device can perform authentication. This simplifies the authentication process and improves the convenience of operation.

[0549] As another possible embodiment, the apparatus provided in this application embodiment can also be an authentication device. Figure 16 An exemplary illustration shows a schematic diagram of an authentication method flow for an authentication device provided in an embodiment of this application, such as... Figure 16 As shown in the embodiment of this application, the device provided is on authentication device b1, and the method includes: S1600 to S1605 can be referred to the above. Figure 13 The parts from steps 1300 to 1305 require replacing the execution subject "server" with "authentication device b1" or "the device". Other details will not be repeated here.

[0550] Since the device provided in this embodiment is one of the M1 authentication devices, it does not need to send a second authentication request to the authentication devices. Therefore, in S1606, the device sends a second authentication request to each of the M1 authentication devices except for authentication device b1. The second authentication request is used to request the authentication devices to authenticate the user information.

[0551] S1607, the authentication device (authentication device b2) that received the second authentication request sent by authentication device b1 authenticates the user information and generates a second authentication response.

[0552] S1608, when authentication device b1 is one of the M1 authentication devices, authentication device b1 authenticates the user information and generates a second authentication response.

[0553] It should be noted that in S1608, since the device provided in this embodiment is authentication device b1, the device does not need to send a second authentication request to authentication device b1. Authentication device b1 authenticates the user information and generates a second authentication response. Furthermore, authentication device b1 does not need to return the second authentication response to the device. Therefore, in S1609, the device receives a second authentication response from an authentication device other than authentication device b1.

[0554] S1610 to S1616 can be referred to the above. Figure 13 The parts from steps 1309 to 1315 require replacing the execution subject "server" with "authentication device b1" or "the device". Other details will not be repeated here.

[0555] It is important to note that Figure 16 This illustration merely demonstrates a flowchart of the authentication method when the apparatus provided in this application is authentication device b1. All possible implementations of each step in this diagram can be found in the foregoing. Figure 13 The relevant content will not be repeated here.

[0556] The above-mentioned steps can be found in the foregoing. Figure 13 The relevant content will not be repeated here. From Figure 16 As can be seen from this, when the device provided in the embodiments of this application is an authentication device, compared to the above... Figure 13 The difference in the illustrated scheme is that when the device identifies the authentication device as one of the M1 authentication devices, it is not necessary to send a second authentication request to the authentication device through step 1606. Furthermore, after authenticating the user information, the authentication device is not required to return a second authentication response to the device; instead, the authentication device obtains its own authentication result. Thus, since the device provided in this embodiment is an authentication device, the signaling interaction between the authentication device and the device can be reduced, thereby saving resources and accelerating the execution process.

[0557] As one possible embodiment, the device provided in this application can be a server or a router, or it can be an operating device. Figure 17 An exemplary illustration shows a schematic diagram of an authentication method for an operating device provided in an embodiment of this application, such as... Figure 17 As shown, when the apparatus provided in this application embodiment is an operating device, and the operating device has authentication capabilities, the method includes: S1720 can be referenced from the above. Figure 13 In step 1300, the execution subject "server" needs to be replaced with "operating device" or "the device". Other details will not be repeated here.

[0558] Since the device provided in this embodiment is an operating device, the operating device does not need to send a first authentication request to the server. After S1720, S1721 to S1723 executed by the device can be referred to the foregoing. Figure 13 In steps 1302 to 1304, the executing entity "server" is replaced with "operating device" or "the device". Other details will not be repeated here.

[0559] If it is determined in S1723 that the authentication security value corresponding to the operating device is not less than the target security value, then since the device provided in this embodiment is an operating device, the device does not need to return a third authentication request to the operating device, but instead directly executes S1732. S1732 can be referred to the foregoing. Figure 13 In step 1317, the executing entity "server" is replaced with "operating device" or "the device". Other details will not be repeated here.

[0560] S1724 can be referenced from the above. Figure 13 The details of step 1305 will not be repeated here.

[0561] Since the device provided in this application embodiment is an operating device, and in Figure 17 In this context, the operating device is also one of the M1 authentication devices. Therefore, there is no need to send a second authentication request to the operating device. Based on this, in S1725, the device sends a second authentication request to each of the M1 authentication devices other than the operating device. The second authentication request is used to request the authentication device to authenticate the user information.

[0562] like Figure 17 As shown, the operating device sends a second authentication request to the authentication device b1.

[0563] S1726, the authentication device (authentication device b1) that receives the second authentication request sent by the operating device authenticates the user information and generates a second authentication response.

[0564] S1727, When the operating device is one of the M1 authentication devices, the operating device authenticates the user information and generates a second authentication response.

[0565] It should be noted that in S1727, since the device provided in this embodiment is an operating device, the operating device does not need to send a second authentication request to the operating device. The operating device authenticates the user information and generates a second authentication response. Furthermore, the operating device does not need to perform the step of returning the second authentication response to the operating device. In S1728, the operating device receives the second authentication responses returned by the authentication devices other than the operating device among the M1 authentication devices.

[0566] S1729 to S1731 can be referred to the above. Figure 13 In steps 1309 to 1311, the executing entity "server" is replaced with "operating device" or "the device". Other details will not be repeated here.

[0567] Since the device provided in this application embodiment is an operating device, after determining whether the total authentication security value is less than the target security value in S1731, it is not necessary to execute the step of returning a first authentication response (the first authentication response refers to a first authentication success response or a second authentication failure response) to the operating device. Instead, if in S1731 the device determines that the total authentication security value is not less than the target security value required for the target operation, then S1734 is executed; if the total authentication security value is less than the target security value required for the target operation, then S1733 is executed.

[0568] S1733, The operating device refuses to perform the target operation.

[0569] S1734, Operate the equipment to perform the target operation.

[0570] It is important to note that Figure 17 This is merely a schematic flowchart illustrating the authentication method when the device provided in this application is an operating device. All possible implementations of each step in this flowchart can be found in the foregoing. Figure 13 The relevant content should be replaced with "operating device" or "the device" instead of "server" as the executing entity. Other content will not be repeated here.

[0571] As can be seen from the above process, when the device provided in the embodiments of this application is an operating device, in this case, relative to the above... Figure 13 The difference in the illustrated scheme is that the operating device does not need to send a first authentication request to the server. Instead, the operating device can determine the target security value required to perform the target operation after executing step 1700. Furthermore, when the device identifies M1 authentication devices, if the operating device is confirmed as one of the M1 authentication devices, there is no need to send a second authentication request to the operating device. Moreover, after authenticating the user information, the operating device does not need to return a second authentication response to the device; instead, the operating device obtains the authentication result of the operating device. Thirdly, after the device confirms the relationship between the total authentication security value and the target security value, there is no need to report whether the authentication was successful to the operating device. Instead, the operating device determines whether the authentication was successful based on the total authentication security value and the target security value, and then decides whether to execute the target operation. Thus, since the device provided in this embodiment is an operating device, the signaling interaction between the operating device and the device can be reduced, thereby saving resources and accelerating the execution process.

[0572] In step 205 above, the device provided in this application embodiment can first determine M1 authentication devices. The following describes the specific method of determining M1 authentication devices using the device provided in this application embodiment as a server as an example. When the device is a router or a terminal device, the method of determining M1 authentication devices is similar to the following content, except that the execution subject "server" is replaced with "the device", and other content will not be repeated.

[0573] The device identifies M1 certified devices in the following ways.

[0574] In Method 1, a second authentication request is sent to all authentication devices registered on the server in step 206 above. For example, if K authentication devices are pre-registered on the server, where K is a positive integer not less than M1, then in Method 1, the aforementioned M1 authentication devices are equivalent to the K authentication devices. Some of these K authentication devices may be in a non-communication reachable state, such as a smart TV that is not powered on. Therefore, the offline authentication devices among the K authentication devices may not respond to the second authentication request.

[0575] Method 2: The server sends a first message to K authentication devices or to any of the K authentication devices that are online (e.g., can be found through a network search). The first message is used to query whether the authentication device is in a communicable reachable state. The first message may carry the server's identifier.

[0576] Upon receiving the first message response, the authentication device corresponding to sending the first message response is identified as one of the M1 authentication devices. The first message response may carry the identifier of the authentication device that sent the first response. That is, in Method 2, the first message is sent to query the M1 authentication devices that are in a communication reachable state, and then a second authentication request is sent to the M1 authentication devices.

[0577] Optionally, besides method two, there are several other ways to query the status of the M1 authentication devices that are in a communicable reachable state among the K authentication devices. For example, the device provided in this embodiment is a terminal device, which can query authentication devices that are on the same local area network as itself, and the queried authentication devices are the M1 authentication devices mentioned above. As another example, if the device provided in this embodiment is a terminal device, it can query authentication devices that are on the same local area network as itself, send a first message to the queried authentication devices, and determine the authentication devices that receive the first message response as the M1 authentication devices mentioned above.

[0578] Method 3: The K authentication devices can be prioritized, for example, based on user preferences, or sorted by their authentication security values ​​(e.g., the higher the highest authentication security value of an authentication device, the higher its priority). The server sends the first message to each of the K authentication devices in turn, according to their priorities.

[0579] Upon receiving the first message response, the authentication device corresponding to the sending of the first message response is identified as one of the M1 authentication devices, until: M1 authentication devices have been identified or all authentication devices have been polled. In all three methods, the value of M1 can be preset.

[0580] Option 4: Before step 205, the server has already obtained the authentication methods and root key storage environment supported by each authentication device and established the correspondence between the aforementioned authentication devices, authentication methods, and authentication security values. Then, based on the preset correspondence between authentication devices, authentication methods, and authentication security values, the server determines the authentication devices corresponding to authentication security values ​​not less than the target security value as M1 authentication devices. In this way, a higher authentication level can be provided for operations with higher security requirements.

[0581] Method 5: The server determines M1 authentication devices from a preset pool of K devices that meet preset conditions; K is a positive integer not less than M1. Preset conditions include: the server and the authentication device are in a communicable reachable state, and / or the location of the authentication device is within a preset distance of the user's current location. In this embodiment, communicable reachable state means that the server and the authentication device can communicate, for example, using technologies such as NFC, Wi-Fi, Bluetooth, and 5G mentioned above. The preset distance can be set short, such as 0.3 meters. If the location of the authentication device is within the preset distance of the user's current location, the authentication device can collect the user's information. For example, if the user unlocks the door from outside using a fingerprint, the distance between the smart speaker inside and the user may be outside the preset distance range, meaning the smart speaker inside will not be selected as an authentication device. This approach is more realistic; if the user unlocks the door from outside using a fingerprint, the smart speaker inside cannot collect the user's voiceprint. Not using the smart speaker as the authentication device is more in line with actual application scenarios. In this scenario, the server can infer the user's location based on the target operation the user needs to perform. For example, when the user performs the target operation of unlocking the door, it can be inferred that the user should currently be outside the door. In this case, it can be inferred that some smart devices indoors, such as smart speakers and smart TVs, are at a preset distance from the user. In this case, these authentication devices will no longer be used to authenticate the user.

[0582] For methods 1, 2, 3, 4, and 5 above, if the server needs to determine the authentication method used by one of the K authentication devices, it can confirm one of the following as the authentication method to be used by that device: The authentication device supports all or some of the authentication methods. This authentication device supports all or some of the biometric authentication methods. The authentication method with the highest security value among all authentication methods supported by this authentication device; This authentication device supports the highest security level among all biometric authentication methods.

[0583] Method Six: For K authentication devices, an authentication policy is defined as using one authentication method for each device. That is, an authentication policy includes one authentication device and the authentication method used by that device. For example, if one authentication device corresponds to two authentication methods, then that device corresponds to two authentication policies. The authentication device included in both policies is the same, but the authentication methods included in the two policies are two different authentication methods. In this embodiment, one authentication policy corresponds to one authentication security value.

[0584] In Method Six, all authentication policies can be prioritized based on their authentication security values, with higher security values ​​indicating higher priority. (Note that Method Three prioritized K authentication devices, while Method Six prioritizes authentication policies.) The server, based on the priority of all authentication policies, sequentially sends a first message to the corresponding authentication devices for each policy. The first message is used to check if the authentication device is reachable. Upon receiving the first message response, the authentication device that sent the response is identified as one of M1 authentication devices, continuing until: M1 authentication devices are identified or all authentication policies have been polled. The authentication method corresponding to the authentication policy is then determined as the authentication method used by the corresponding authentication device.

[0585] Option 7: The server combines the authentication policies corresponding to the currently reachable authentication devices to obtain one or more authentication policy groups. (For the definition and introduction of authentication policies, please refer to Option 6 above). Calculate the total authentication security value in each authentication policy group, select an authentication policy group whose total authentication security value is higher than the target security value, and determine the authentication devices in this authentication policy group as M1 authentication devices. The authentication method included in one authentication policy in this authentication policy group is the authentication method used by the authentication devices included in that authentication policy.

[0586] For example, a user may need to perform a target operation that requires a high target security value, but the authentication capabilities of the available devices are low. If a single authentication device performs authentication, the resulting individual authentication security value will be lower than the target security value. In this case, multiple authentication strategies with lower security values ​​can be combined. Authentication can be performed using these multiple devices with lower authentication capabilities, resulting in multiple authentication security values. The total authentication security value calculated based on these multiple authentication security values ​​may be greater than the required target security value, thus enabling the operation to be performed. The total authentication security value can be calculated using formula (1) or formula (2) above. It can be seen that even when there are no authentication devices with strong authentication capabilities, this embodiment can also combine multiple authentication devices with weaker authentication capabilities for collaborative authentication, thereby satisfying the user's high security level requirements (high security value) for the operation.

[0587] In Solution Seven, the server combines authentication policies corresponding to authentication devices that are currently in a communicably reachable state, including those corresponding to biometric authentication methods. This eliminates the need for users to enter passwords, thereby improving user convenience.

[0588] Method 8: Based on the preset correspondence between operations and authentication policies, the server determines M1 authentication devices included in the authentication policy corresponding to the target operation. Furthermore, for each authentication policy corresponding to the target operation, the authentication method included in that policy is determined as: the authentication method used by the authentication devices included in that policy.

[0589] In this approach, authentication devices and their respective authentication methods can be preset for certain operations. For example, the authentication devices for fingerprint unlocking can be preset to 2D face recognition on the user's mobile phone (A1) and fingerprint recognition on the smart lock. This allows users to set one or more authentication devices for operations based on their personal preferences and habits, increasing the flexibility of the solution.

[0590] According to the aforementioned method, Figure 18This is a schematic diagram of a system architecture provided in an embodiment of this application. The system architecture includes an operating device 5100, an authentication device 6100, and a device 7100. Figure 18 The device 7100 in the figure is a structural schematic diagram of the device for performing the above-described authentication method provided in the embodiments of this application, as shown in the figure. Figure 18 As shown, the device can be a server, a router, a terminal device, a chip, or a circuit, such as a chip or circuit that can be installed in a server, router, or terminal device.

[0591] Figure 18 The illustration is based on the premise that device 7100 is independent of operating device 5100 and authentication device 6100. If device 7100 and operating device 5100 are the same device, then the operating device must include not only the two modules in operating device 5100 but also all the modules in device 7100. Similarly, if device 7100 and authentication device 6100 are the same device, then the authentication device must include not only the two modules in authentication device 6100 but also all the modules in device 7100. Likewise, if operating device 5100 also has authentication capabilities and can be used as an authentication device to perform authentication operations, then the operating device, in addition to including… Figure 18 In addition to the two modules in the operating device 5100 shown, the two modules in the authentication device 6100 also need to be included.

[0592] like Figure 18 As shown, the operating device 5100 may include an operation interception and execution module 5101 and a device connection module 5102. The device connection module 5102 can be used to transmit data between or within devices, and the operation interception and execution module 5101 can be used to execute target operations, generate a first authentication request, etc.

[0593] like Figure 18 As shown, the authentication device 6100 may include an authenticator 6101 and a device connection module 6102. The device connection module 6102 can be used to transmit data between or within devices, and the authenticator 6101 can be used to authenticate user information.

[0594] like Figure 18As shown, the device 7100 may include an authentication security level assessment module 7101, an authentication capability discovery module 7102, an authentication scheme decision module 7103, an authenticator scheduling module 7104, and a device connection module 7105. The authentication security level assessment module 7101 can be used to determine the target security value required for the target operation and to calculate the total authentication security value. The authentication capability discovery module 7102 can be used to obtain the authentication capabilities of each authentication device. The authentication scheme decision module 7103 can be used to determine a group of authentication strategies or to determine the M1 authentication devices mentioned in step 1305. The authenticator scheduling module 7104 can be used to send a second authentication request to each authentication device. The device connection module 7105 can be used to transmit data between or within devices.

[0595] The following is based on Figure 18 Using this as an example, we will further introduce the solutions provided in the embodiments of this application. Figure 19 exist Figure 18 Based on this, a schematic diagram of one possible implementation scheme is illustrated below. Figure 19 To introduce, such as Figure 19 As shown, it includes: In step 1900, the operating device 5100 receives the target operation through the operation interception and execution module 5101. For details regarding this step, please refer to the preceding text. Figure 13 Step 1300 will not be repeated here.

[0596] In step 1901, the operation interception and execution module 5101 generates a first authentication request and transmits it to the device connection module 7105 of the device 7100 via the device connection module 5102. Step 1901 can be found in the foregoing. Figure 13 The relevant content of step 1301.

[0597] After receiving the first authentication request through the device connection module 7105, the device 7100 can transmit the first authentication request to the authentication security level assessment module 7101 within the device 7100.

[0598] Step 1902: The authentication security level assessment module 7101 determines the target security value required for the target operation. Step 1902 can be found in the preceding description. Figure 13 The relevant content of step 1302.

[0599] Step 1903, the authentication security level assessment module 7101 can be used to send the target security value to the authentication scheme decision 7103.

[0600] The following steps 1905 to 1908 are provided as an example to illustrate the aforementioned scheme. Figure 13The implementation method for determining the M1 authentication devices in step 1305 is as follows. Other implementation methods for determining the M1 authentication devices involved in the aforementioned method embodiments can also be executed by the device 7100, and will not be described in detail here.

[0601] Step 1904, the authentication scheme decision 7103 sends a signaling message to the authentication capability discovery module 7102 to query available authentication devices.

[0602] In step 1905, the authentication capability discovery module 7102 sends a signaling message to the authentication device 6100 to query the authentication capability of the authentication device 6100. For example, the signaling message can be transmitted between the device connection module 7105 of the device 7100 and the device connection module 6102 of the authentication device 6100.

[0603] In step 1906, the authentication device 6100 can report its authentication capabilities to the authentication capability discovery module 7102 of the device 7100. In this example, the authentication capabilities may include the authentication methods and key storage environment supported by the authentication device 6100.

[0604] Steps 1905 and 1906 described above can be referred to as the capability discovery process. This capability discovery process can be performed after or before step 1904, for example, it can be performed when the authentication device 6100 accesses the network. For a description of how an authentication device reports its own authentication capabilities, please refer to the aforementioned method embodiment section, which will not be repeated here.

[0605] In step 1907, the authentication capability discovery module 7102 identifies the available authentication devices and the authentication capabilities of each authentication device, and returns the identifiers of the available authentication devices and the authentication capabilities of each authentication device to the authentication scheme decision 7103.

[0606] Step 1908, Authentication Scheme Decision 7103, is used to decide on an authentication scheme based on the target security value and the authentication capabilities of each authentication device among the available authentication devices. The decided authentication scheme can be a group of authentication policies. The decided authentication scheme includes M1 authentication devices. The details of deciding on the M1 authentication devices in step 1908 can be found in the relevant content of step 1305 above, and will not be repeated here.

[0607] Step 1909, the authentication scheme decision 7103 sends the authentication scheme to the authenticator scheduling module 7104. The authentication scheme includes the identifiers of M1 authentication devices. Figure 19 The example uses M1 authentication devices as one authentication device, and the authentication device is authentication device 6100 as an example.

[0608] In step 1910, the authenticator scheduling module 7104 performs coordinated scheduling. Specifically, it can send a second authentication request to the authentication device 6100 through the device connection module 7105. The details of the second authentication request can be found in step 1306 above, and will not be repeated here.

[0609] Step 1911: After receiving the second authentication request through the device connection module 6102, the authentication device 6100 can perform user authentication through the authenticator 6101 and return the authentication result to the device 7100 through the device connection module 6102.

[0610] In step 1912, after receiving the authentication result returned by the authentication device 6100 through the device connection module 7105, the device 7100 transmits the authentication result to the authentication security level assessment module 7101.

[0611] In step 1913, the authentication security level assessment module 7101 calculates the total authentication security value based on the authentication result and the authentication security value corresponding to the authentication method of the authentication device. It then generates a first authentication response based on the relationship between the total authentication security value and the target security value. When the authentication security level assessment module 7101 of device 7100 determines that the total authentication security value is not less than the target security value, it can send a first authentication success response; when it determines that the total authentication security value is less than the target security value, it can s...

Claims

1. An authentication method characterized by, The authentication method is executed by a first electronic device, and the method comprises: receiving an authentication request, the authentication request being used to request authentication of a first service; determining a risk security level corresponding to the first service; determining an authentication mode meeting the security risk level according to the risk security level; scheduling M electronic devices to perform authentication on the first service according to the authentication mode, wherein M is a positive integer, the M electronic devices are connected to a same local area network, and / or when M>1, the M electronic devices are bound to a same user account.

2. The method of claim 1, wherein, The determining of the authentication mode meeting the security risk level according to the risk security level comprises: determining available authentication factors and available collection capabilities associated with the available authentication factors; determining the authentication mode meeting the security risk level according to the risk security level, the available authentication factors and the available collection capabilities associated with the available authentication factors.

3. The method according to claim 1 or 2, characterized in that, Further comprising: when the authentication request comprises a biological feature, identifying the biological feature to determine a user corresponding to the biological feature; determining that the user has a permission to perform the first service.

4. The method of claim 3, wherein, The determining of the authentication mode meeting the security risk level according to the risk security level comprises: determining available authentication factors associated with the user, and available authentication capabilities and available collection capabilities associated with the available authentication factors; determining the authentication mode meeting the security risk level according to the risk security level, the available authentication factors, the available authentication capabilities and the available collection capabilities.

5. The method of claim 1, wherein the first electronic device determines the authentication mode meeting the security risk level according to the risk security level by using a decision strategy, wherein the decision strategy comprises at least one of the following: preferentially using an already collected authentication factor for authentication; preferentially using a collection capability with a user-unaware feature to collect an authentication factor; and preferentially using a collection capability on a near-end device of the user to collect an authentication factor, wherein the near-end device is at least one of the M electronic devices.

6. The method according to any one of claims 1 to 5, characterized in that, After the first electronic device schedules the M electronic devices to perform authentication on the first service, the method further comprises: the first electronic device acquires authentication results of the M electronic devices from the M electronic devices, and then aggregates the authentication results of the M electronic devices to generate a final authentication result.

7. The method according to any one of claims 1 to 6, characterized in that, After the first electronic device schedules the M electronic devices to perform authentication on the first service, the method further comprises: if the authentication is passed, the first electronic device instructs an operation device to perform the first service, wherein the operation device is at least one of the first electronic device and the M electronic devices.

8. An electronic device, comprising: The electronic device comprises a processor and a memory; the memory stores program instructions; and the processor is configured to execute the program instructions stored in the memory, so that the electronic device performs the method according to any one of claims 1-7.

9. A computer-readable storage medium, characterized in that, The computer readable storage medium comprises program instructions which, when run on an electronic device, cause the electronic device to perform the method of any one of claims 1-7.