Collaborative identity verification method and device and electronic equipment

By using a collaborative authentication method, authorization authentication is performed collaboratively using the SIM cards of the first and second devices, generating joint assertions and encrypted user credentials. This solves the problem of centralized storage of encryption keys for the Super SIM card, achieving higher security and privacy, and supporting offline verification for multiple roles and cross-domain delegation.

CN121793009APending Publication Date: 2026-04-03CHINA MOBILE INTERNET CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-05
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

The centralized storage of encryption keys in existing technologies for Super SIM cards leads to high security risks, poor privacy and flexibility, and difficulty in supporting multi-role or cross-domain delegation and offline verification.

Method used

The user credentials are authorized and authenticated by the first SIM card in the first device to determine the reachable second device, and the second SIM card in the second device is used for auxiliary authorization and authentication to generate a joint assertion and encrypted user credentials, and authentication is performed by combining multiple security mechanisms.

Benefits of technology

It reduces security risks associated with identity verification, improves reliability and privacy, supports multiple roles and cross-domain delegation, and enhances offline verification capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121793009A_ABST
    Figure CN121793009A_ABST
Patent Text Reader

Abstract

The invention relates to a collaborative identity verification method and device and electronic equipment, and belongs to the technical field of security certification, and the method comprises the steps: responding to a target operation of a target application in first equipment, and carrying out the authorization authentication of a user certificate corresponding to the target application based on a first SIM card in the first equipment; in response to the fact that the user credential passes authorization authentication, determining a second device which the first device can achieve communication; carrying out auxiliary authorization authentication on the user certificate through a second SIM card in the second equipment; and determining whether to authorize the target operation or not according to an authentication result of the second equipment. Therefore, identity authentication is carried out based on cooperation of the first SIM card of the first device and the second SIM card in the second device, the security risk in the identity authentication process is reduced, the reliability and security of identity authentication are improved, and the privacy and flexibility of identity authentication are ensured by carrying out authorization authentication on the user credential.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of security authentication technology, and more particularly to a collaborative authentication method, apparatus, and electronic device. Background Technology

[0002] In related technologies, for Subscriber Identity Module (SIM) cards, encryption keys, digital certificates, and user identity credentials are often securely stored in a secure chip inside the SIM card. This creates an identity verification system managed by a centralized authentication server. When a user or device attempts to access resources, the security functions inside the SIM card perform encryption operations or digital signature operations to generate a secure message containing identity verification and request information. The secure message is then transmitted to the centralized server, which receives it and verifies the security information sent by the SIM card according to preset trust policies and algorithms. After confirming the legitimacy of the user or device's identity, the server centrally authorizes or denies access to specific resources based on the user's or device's permission level, thus completing an integrated identity verification and access management process.

[0003] However, the above-mentioned solutions, based on a single-point information mechanism, have high security risks. The master key, authorization decisions, and auditing are centrally stored in a "super SIM card" or a single backend. When needed, encryption keys are used. If the encryption key is compromised or malfunctions, the authentication and permission management process will be affected and the cost of revocation / recovery will be high. Furthermore, privacy and flexibility are poor, meaning that too much user information is usually exposed, selective disclosure is difficult, and there is insufficient support for multiple roles or cross-domain delegation and offline verification capabilities. Summary of the Invention

[0004] This disclosure provides a collaborative authentication method, apparatus, electronic device, medium, and computer program product.

[0005] The technical solution disclosed herein is as follows: According to a first aspect of the present disclosure, a collaborative authentication method is provided, comprising: in response to a target operation of a target application within a first device, authorizing and authenticating a user credential corresponding to the target application based on a first SIM card within the first device; in response to the user credential passing the authorization authentication, determining a second device that the first device can communicate with; performing auxiliary authorization authentication on the user credential using a second SIM card within the second device; and determining whether to authorize the target operation based on the authentication result of the second device.

[0006] According to a first aspect of the present disclosure, the step of performing auxiliary authorization authentication on the user credential via a second SIM card in the second device further includes: determining a target assertion from an assertion list, and updating the target assertion based on the device description metadata of the first device, the user description metadata of the user, and a measurement digest to generate a joint assertion for the first device; sending the joint assertion to the second device, and receiving an assertion set fed back by the second device based on the joint assertion; encrypting the user credential based on the assertion set to obtain an encrypted user credential; and performing auxiliary authorization authentication on the encrypted user credential via the second SIM card to obtain an authentication result for the second device.

[0007] According to a second aspect of the present disclosure, a collaborative authentication method is provided, comprising: receiving a user credential corresponding to a target application sent by a first device, wherein the target application is an application within the first device; performing auxiliary authorization authentication on the user credential based on a second SIM card within a second device to obtain an authentication result; and sending the authentication result to the first device, wherein the authentication result is used by the first device to determine whether to authorize a target operation of the target application.

[0008] According to a third aspect of the present disclosure, a collaborative authentication device is provided, comprising: a first authentication module, configured to, in response to a target operation of a target application within a first device, authorize and authenticate a user credential corresponding to the target application based on a first SIM card within the first device; a first determination module, configured to, in response to the user credential passing the authorization authentication, determine a second device that the first device can communicate with; a second authentication module, configured to, through a second SIM card within the second device, perform auxiliary authorization authentication on the user credential; and a second determination module, configured to, based on the authentication result of the second device, determine whether to authorize the target operation.

[0009] According to a fourth aspect of the present disclosure, a collaborative authentication device is provided, comprising: a receiving module for receiving a user credential corresponding to a target application sent by a first device, wherein the target application is an application within the first device; an authentication module for performing auxiliary authorization authentication on the user credential based on a second SIM card within a second device to obtain an authentication result; and a sending module for sending the authentication result to the first device, wherein the authentication result is used by the first device to determine whether to authorize a target operation of the target application.

[0010] According to a fifth aspect of the present disclosure, an electronic device is provided, comprising: a processor; a memory for storing executable instructions of the processor; wherein the processor is configured to execute the instructions to implement a cooperative authentication method as described in the first or second aspect of the present disclosure.

[0011] According to a sixth aspect of the present disclosure, a computer-readable storage medium is provided that, when instructions in the computer-readable storage medium are executed by a processor of an electronic device, enables the electronic device to perform a cooperative authentication method as described in the first or second aspect of the present disclosure.

[0012] According to a seventh aspect of the present disclosure, a computer program product is provided, including a computer program that, when executed by a processor, implements the cooperative authentication method according to a first or second aspect of the present disclosure.

[0013] The technical solutions provided by the embodiments of this disclosure have at least the following beneficial effects: In this embodiment, in response to a target operation of a target application within a first device, authorization authentication is performed on the user credentials corresponding to the target application based on a first SIM card within the first device. Upon successful authorization authentication of the user credentials, a second device reachable by communication from the first device is determined. Then, auxiliary authorization authentication is performed on the user credentials using a second SIM card within the second device. Based on the authentication result of the second device, it is determined whether to authorize the target operation. Therefore, this disclosure utilizes the first SIM card of the first device and the second SIM card within the second device to collaboratively perform identity verification, reducing security risks during the identity verification process and improving the reliability and security of identity verification. By authorizing authentication of user credentials, the privacy and flexibility of identity verification are guaranteed.

[0014] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description

[0015] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure, and are not intended to unduly limit this disclosure.

[0016] Figure 1 This is a flowchart illustrating a collaborative authentication method according to an exemplary embodiment.

[0017] Figure 2 This is a flowchart illustrating a collaborative authentication method according to an exemplary embodiment.

[0018] Figure 3This is a flowchart illustrating a collaborative authentication method according to an exemplary embodiment.

[0019] Figure 4 This is a flowchart illustrating a collaborative authentication method according to an exemplary embodiment.

[0020] Figure 5 This is a flowchart illustrating a collaborative authentication method according to an exemplary embodiment.

[0021] Figure 6 This is a block diagram illustrating a collaborative authentication device according to another exemplary embodiment.

[0022] Figure 7 This is a block diagram illustrating a collaborative authentication device according to another exemplary embodiment.

[0023] Figure 8 This is a block diagram illustrating an electronic device according to an exemplary embodiment. Detailed Implementation

[0024] To enable those skilled in the art to better understand the technical solutions of this disclosure, the technical solutions in the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings.

[0025] It should be noted that the terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this disclosure are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this disclosure described herein can be implemented in orders other than those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this disclosure. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this disclosure as detailed in the appended claims.

[0026] The following examples illustrate the collaborative authentication method, apparatus, and electronic device proposed in this disclosure.

[0027] Figure 1 This is a flowchart illustrating a collaborative authentication method provided in an embodiment of this application.

[0028] like Figure 1 As shown, the collaborative authentication method proposed in this embodiment includes the following steps: S101, in response to the target operation of the target application within the first device, authorize and authenticate the user credentials corresponding to the target application based on the first SIM card within the first device.

[0029] It should be noted that this disclosure does not limit the type of target application, such as: the target application is a financial application, a third-party payment platform application, etc.

[0030] For example, if the target application is a financial application, the target operation could be an offline card payment operation, a transfer operation, etc.

[0031] The first SIM card can be a Super SIM card.

[0032] In this embodiment of the disclosure, the user credentials can be checked for consistency based on the first SIM card assist authentication application within the first SIM card, so as to authorize and authenticate the user credentials corresponding to the target application and obtain the authorization and authentication result.

[0033] S102, in response to the user credentials being authenticated through authorization, determine the second device that the first device can communicate with.

[0034] In this embodiment of the disclosure, based on the authorization and authentication result, if the user credentials are determined to be authorized and authenticated, the reachable network range around the first device can be obtained, and the device in the reachable network range around the first device can be identified as the second device.

[0035] The number of second devices can be single or multiple.

[0036] S103 performs auxiliary authorization authentication of user credentials through the second SIM card in the second device.

[0037] In this embodiment of the disclosure, a target assertion is determined from the assertion list, and the target assertion is updated based on the device description metadata of the first device, the user description metadata of the user, and the measurement digest to generate a joint assertion for the first device. The joint assertion is sent to the second device, and an assertion set fed back by the second device based on the joint assertion is received. Based on the assertion set, the user credential is encrypted to obtain an encrypted user credential. The encrypted user credential is then used for auxiliary authorization authentication through a second SIM card to obtain the authentication result of the second device.

[0038] S104, Based on the authentication result of the second device, determine whether to authorize the target operation.

[0039] In this embodiment of the disclosure, after obtaining the authentication result of the second device, the authentication results of the second device are summarized to obtain the final authentication result of the second device, and the authentication result is fed back to the target application to determine whether to authorize the target operation.

[0040] In summary, the collaborative authentication method provided in this disclosure, in response to a target operation of a target application within a first device, authorizes and authenticates the user credentials corresponding to the target application based on a first SIM card within the first device. Upon successful authorization authentication of the user credentials, a second device reachable by communication from the first device is determined. Then, a second SIM card within the second device is used for auxiliary authorization authentication of the user credentials. Based on the authentication result of the second device, it is determined whether to authorize the target operation. Therefore, this disclosure, by collaboratively performing authentication based on the first SIM card of the first device and the second SIM card within the second device, reduces security risks during the authentication process, improves the reliability and security of authentication, and ensures privacy and flexibility in authentication by authorizing and authenticating user credentials.

[0041] Figure 2 This is a flowchart illustrating a collaborative authentication method provided in an embodiment of this application.

[0042] like Figure 2 As shown, the collaborative authentication method proposed in this embodiment includes the following steps: S201, in response to the target operation of the target application within the first device, authorize and authenticate the user credentials corresponding to the target application based on the first SIM card within the first device.

[0043] S202, in response to the user credentials being authenticated through authorization, determines a second device that is communicatively reachable by the first device.

[0044] S203, from the assertion list, determine the target assertion, and based on the device description metadata of the first device, the user description metadata of the user, and the measurement summary, update the target assertion to generate the joint assertion of the first device.

[0045] In this embodiment of the disclosure, an assertion security level threshold is determined based on the target application and target operation, the assertion security level of the assertions in the assertion list is determined, and assertions with an assertion security level greater than the assertion security level threshold are selected as target assertions.

[0046] In this embodiment of the disclosure, the target information carried by the target operation can be determined, and the verification security level of the target application and the target verification security level can be determined. Based on the target information, the verification security level of the target application and the target verification security level, the assertion security level threshold can be determined.

[0047] For example, if the target operation is an offline card swipe, the target information can be the payment amount.

[0048] For example, the assertion security level threshold can be determined using the following formula based on the target information, the verification security level of the target application, and the target verification security level:

[0049] in, To assert security level thresholds, Verification of security level for target application, Verify the security level of the target. For target information.

[0050] For example, regarding the assertion list assertions in ,Right now ,assertion assertion security level The following formula can be used to obtain it:

[0051] in, For assertion Availability (1 indicates available, 0 indicates unavailable) For the ratio of historical access duration to environmental data, For fixed equipment (2 for fixed equipment, 1 for non-fixed equipment), Duration of stay The number of fraudulent activities in the history of the node. The average number of fraudulent nodes surrounding a given node. It is a symbolic function.

[0052] The assertion is a logical rule used by the first device to execute, and the result returns either true or false.

[0053] For example, when the result returns true, it indicates that the assertion is available, and when the result returns false, it indicates that the assertion is not available.

[0054] For example, examples of assertions are shown in Table 1: Table 1

[0055] In this embodiment of the disclosure, after determining the assertion security level and the assertion security level threshold of the assertion list, assertions with an assertion security level greater than the assertion security level threshold are selected, and the target assertion is determined by combining this with the target assertion quantity threshold. The target assertion quantity threshold is determined based on the joint assertion security cost upper limit.

[0056] For example, the target assertion can be determined according to the following formula:

[0057] in, Assertions for the goal The function is derived from the assertion list. Determine that the assertion security level is greater than the assertion security level threshold. The number of assertions, The function selects assertions with a security level greater than the assertion security level threshold that have a number of values ​​less than or equal to a threshold. The goal assertion.

[0058] In this embodiment of the disclosure, multi-point measurements can be performed on the kernel of the first device to generate a measurement digest. Based on the root key pair in the first SIM card, the measurement digest is signed to obtain the proof information of the measurement digest. The root key pair is stored in the certificate of the first SIM card. Based on the device description metadata of the device, the user description metadata of the user, and the proof information of the measurement digest, the target assertion is updated to generate a joint assertion of the first device.

[0059] For example, in response to an offline card payment operation of a financial application within the first device, to ensure security, the assistive authentication provided within the Super SIM card is invoked to authenticate the user credentials. The data provided during the invocation includes device description metadata and user description metadata. After receiving the device description metadata and user description metadata, the Super SIM card checks whether the user description metadata matches the user bound to the Super SIM card. When the user description metadata matches the user bound to the Super SIM card, the Super SIM card assistive authentication application within the Super SIM card is initiated and used to generate a joint assertion containing device description metadata, user description metadata, and proof information.

[0060] It should be noted that, in response to the startup of the first device, a measurement task is initiated to periodically perform multi-point measurements on the kernel of the first device. By executing the measurement task, the original information of the first device, such as device identifier (ID), firmware information, kernel information, driver, security certification authority, security certification authority verification result status, and compatibility protocol information, is collected. The original information of the first device is vectorized and encoded to generate a measurement digest.

[0061] For example, a measurement summary can be represented as:

[0062] in, For equipment identification, For firmware information, For kernel information, For driving, For safety certification bodies, For security certification bodies to verify the status of results, For compatibility protocol information, This is to perform vectorization encoding on the original information.

[0063] In this embodiment of the disclosure, the measurement digest is signed based on the root key pair in the first SIM card to obtain proof information of the measurement digest. The proof information can be used to establish a trusted connection and perform offline authentication, providing hierarchical master / sub identity and verifiable credentials.

[0064] The root key pair is an asymmetric key pair, consisting of the public key KRP and the private key KRR.

[0065] It should be noted that when the first SIM card is activated for the first time, the authorized server corresponding to the first SIM card uses the national cryptographic SM2 algorithm to generate a random root key pair KR. The root key pair is then packaged into a certificate using the X.509 certificate wrapping method, and the root key pair is stored in the certificate of the first SIM card and written into the certificate storage area of ​​the first SIM card.

[0066] In this embodiment of the disclosure, after obtaining the measurement digest, the root key pair in the certificate of the first SIM card is read, the measurement digest is signed, and the proof information of the measurement digest is obtained.

[0067] For example, the proof information for the measurement summary can be obtained according to the following formula. :

[0068] in, To obfuscate random numbers, For measurement summary, For the private key in the root key pair, For multiplication on the multiplication curve in the SM2 algorithm, OR operation This is a circular right shift.

[0069] It should be noted that the purpose of performing multi-point measurements on the kernel of the first device can be understood as: obtaining the characteristic fingerprint of the first device, which is used to trace the identity of the verifier during the verification process. The proof information of the measurement digest is the compressed recognition result of the characteristic fingerprint of the first device.

[0070] In this embodiment of the disclosure, after generating the joint assertion of the first device, the measurement summary and the corresponding proof information, as well as the confused random number corresponding to the proof information, can be stored in the storage area of ​​the first SIM card, and the measurement summary and the corresponding proof information, as well as the confused random number corresponding to the proof information, can be reported to the authorization server corresponding to the first SIM card.

[0071] For example, the first SIM card stores a measurement summary and corresponding proof information, as well as a confused random number corresponding to the proof information, in its storage area. The measurement summary and corresponding proof information, as well as the confused random number, are then reported to the authorization server corresponding to the first SIM card. Accordingly, the authorization server corresponding to the first SIM card can register the proof information by processing the measurement summary, proof information, and the confused random number corresponding to the proof information.

[0072] S204, send a joint assertion to the second device and receive a set of assertions fed back by the second device based on the joint assertion.

[0073] In this embodiment of the disclosure, after obtaining the joint assertion, the joint assertion is sent to the second device. Accordingly, the second device receives the joint assertion sent by the first device, determines the first candidate assertion that the second device itself can support, compares the first candidate assertion and the joint assertion to obtain the difference assertion, determines the assertion set based on the difference assertion, and feeds back the assertion set to the first device. Accordingly, the first device receives the assertion set.

[0074] S205, based on the assertion set, encrypt the user credentials to obtain encrypted user credentials.

[0075] In this embodiment of the disclosure, the session level can be determined based on the assertion set to determine the session level between the first device and the second device. A corresponding session key can be generated based on the session level and the proof information. The user credential can be encrypted based on the session key to obtain an encrypted user credential.

[0076] It should be noted that during the handshake phase or application layer key negotiation phase of data transmission, the Super SIM card determines the session level based on the access control policy isolation instruction to obtain the session level. Based on the session level and the proof information, a session key of the corresponding session level (with different strengths) is generated. The user credentials are then encrypted using the session key to protect the root key pair.

[0077] In this embodiment of the disclosure, the type indicator value of the assertion set is determined, the number of elements in the joint assertion is obtained, and the session level is determined based on the type indicator value, the number of elements, and the maximum number of session levels.

[0078] Specifically, when the assertion set belongs to a joint assertion, the type indicator value is 1; when the assertion library of the second device is the same as the assertion logic of the assertion set, the type indicator value is 2; when the assertion set is obtained by transcoding through the authorization server associated with the second SIM card, the type indicator value is 3.

[0079] Optionally, the completion ratio of the assertion set is determined based on the type indicator value and the number of elements, and the session hierarchy is determined based on the completion ratio and the maximum number of session levels.

[0080] For example, the completion rate of the assertion set can be determined using the following formula:

[0081] in, For completion percentage, For type indicator value, The function is represented by the number of elements in a joint assertion.

[0082] For example, the conversation hierarchy can be determined using the following formula:

[0083] in, For conversation hierarchy, Maximum number of session levels This represents the percentage of completion.

[0084] In this embodiment of the disclosure, after obtaining the session level, a corresponding session key can be generated based on the session level and the proof information.

[0085] For example, the corresponding session key can be generated according to the following formula:

[0086] in, For session key, The function is to generate SL keys of the same length as the proof information for the session hierarchy (the generated keys are concatenated to obtain the session key). The function is a random number generator and is a binary OR operation.

[0087] In this embodiment of the disclosure, the target range of the completion ratio is determined, and based on the target range, it is determined whether to enhance the completion ratio. In response to the need to enhance the completion ratio, the completion ratio is enhanced based on the target enhancement strategy corresponding to the target range to obtain the enhanced completion ratio. The session level is determined based on the enhanced completion ratio and the maximum number of session levels.

[0088] Optionally, in response to the second device sending a completion indication for identity authentication aggregation, when the completion percentage is determined to be less than When determining the completion ratio to be enhanced, the target enhancement strategy of biometric identification and authentication can be invoked to enhance the completion ratio, thus obtaining the enhanced completion ratio.

[0089] For example, the enhancement completion ratio can be determined using the following formula:

[0090] in, To increase the completion rate, The authentication strength of biometric identification, This refers to the reliability parameters of the hardware itself (if there is no biometric authentication function). and All are 0).

[0091] Optionally, in response to the second device sending a completion indication for identity authentication aggregation, when the completion percentage is determined to be greater than or equal to... and less than When determining the completion ratio to be enhanced, the target enhancement policy of the terminal's authorized certificate can be invoked to enhance the completion ratio, thus obtaining the enhanced completion ratio.

[0092] For example, the enhancement completion ratio can be determined using the following formula:

[0093] in, To increase the completion rate, For completion percentage, For the authorization certificate level (if the terminal's authorization certificate cannot be accessed, or the authorization certificate has expired, or the authorization certificate authority is untrusted, (0).

[0094] Optionally, in response to the second device sending a completion indication for identity authentication aggregation, when the completion percentage is determined to be greater than or equal to... and less than When determining the completion rate ratio to be enhanced, the target enhancement strategy for terminal abnormal operation detection can be invoked to enhance the completion rate ratio, thus obtaining the enhanced completion rate ratio.

[0095] For example, the enhancement completion ratio can be determined using the following formula:

[0096] in, To increase the completion rate, For completion percentage, The percentage of terminal fraud authentication.

[0097] Optionally, in response to the second device sending a completion indication for identity authentication aggregation, when the completion percentage is determined to be greater than or equal to... At that time, it was determined not to enhance the completion rate ratio.

[0098] In this embodiment of the disclosure, after obtaining the session key, the user credentials can be encrypted according to the session key to obtain encrypted user credentials, so as to protect the original data by encrypting the user credentials.

[0099] For example, user credentials can be encrypted using the following formula to obtain encrypted user credentials:

[0100] in, For encrypting user credentials, h represents the message digest algorithm. For the authorized user in the user credentials, For session key, The target of authorization in the user credentials.

[0101] In this embodiment of the disclosure, before performing auxiliary authorization authentication of the encrypted user credential through the second SIM card, the method further includes: receiving a completion instruction for identity authentication aggregation sent by the second device; responding to the completion instruction; engaging in chain establishment interaction with the second device to establish a trusted chain between the first device and the second device; and sending the encrypted user credential to the second device through the trusted chain.

[0102] For example, when the completion rate is determined to be greater than or equal to At that time, a chain-building interaction is performed with the second device to establish a trusted chain between the first and second devices, and encrypted user credentials are sent to the second device through the trusted chain.

[0103] S206, the second SIM card is used to perform auxiliary authorization authentication of the encrypted user credentials to obtain the authentication result of the second device.

[0104] S207, determine the completion ratio of the assertion set associated with the second device, and sum the completion ratios to obtain the first sum value.

[0105] S208: Calculate the product of the certification result and the corresponding completion rate, and sum the products to obtain the second sum.

[0106] S209, based on the first sum and the second sum, obtain the target authorization instruction information.

[0107] In this embodiment of the disclosure, after obtaining the first sum and the second sum, an auxiliary authorization result can be obtained based on the first sum and the second sum:

[0108] in, To assist in authorization results, For the first sum, For the second sum, , This is the collection of authentication results from the second device. For the set of One authentication result, The function is to determine the union of the authentication results of the second device. For completion percentage, For the set of One authentication result.

[0109] In this embodiment of the disclosure, after obtaining the auxiliary authorization result, the target authorization instruction information can be obtained based on the auxiliary authorization result and the authorization instruction threshold.

[0110] Optionally, in response to the auxiliary authorization result being greater than or equal to the authorization indication value, the target authorization indication information indicates that the target operation authorization has been passed; in response to the auxiliary authorization result being less than the authorization indication value, the target authorization indication information indicates that the target operation authorization has not been passed.

[0111] S2010, based on the target authorization instruction information, determine whether to authorize the target operation.

[0112] In this embodiment of the disclosure, if the target authorization indication information indicates that the target operation authorization is successful, it is determined that the target operation will be authorized; if the target authorization indication information indicates that the target operation authorization is unsuccessful, it is determined that the target operation will not be authorized.

[0113] In summary, the collaborative authentication method provided in this disclosure, in response to a target operation of a target application within a first device, authorizes and authenticates the user credentials corresponding to the target application based on a first SIM card within the first device. In response to the user credentials passing the authorization authentication, it determines a second device that the first device can communicate with. From an assertion list, it determines a target assertion and updates it based on the device description metadata of the first device, the user description metadata of the user, and a measurement digest, generating a joint assertion for the first device. This joint assertion is then sent to the second device, and the method receives an assertion set from the second device based on the joint assertion. The user credentials are then encrypted according to the assertion set to obtain an encrypted user credential. The encrypted user credential is then used for auxiliary authorization authentication via the second SIM card to obtain the authentication result of the second device. The process involves determining the completion ratio of the assertion set associated with the second device, summing the completion ratios to obtain a first sum, multiplying the authentication result by the corresponding completion ratio, summing the products to obtain a second sum, and obtaining target authorization indication information based on the first and second sums. Based on this target authorization indication information, it is determined whether to authorize the target operation. Thus, this disclosure avoids the high availability and security risks associated with single-point trust mechanisms through multiple security mechanisms such as initializing root key pairs, kernel measurement, joint assertion generation, and assertion sets. It also avoids the problems of excessive user information exposure and poor offline authentication capabilities caused by centralized authentication and authorization, thereby improving the security and privacy of the authentication process and enhancing the reliability of authorizing the target operation.

[0114] Figure 3 This is a flowchart illustrating a collaborative authentication method provided in an embodiment of this application.

[0115] like Figure 3 As shown, the collaborative authentication method proposed in this embodiment includes the following steps: S301, Receive the user credentials corresponding to the target application sent by the first device, wherein the target application is an application within the first device.

[0116] In this embodiment of the disclosure, based on the first SIM card in the first device, the user credentials corresponding to the target application are authorized and authenticated. In response to the user credentials being authorized and authenticated, a second device that can be communicated with the first device is determined, and the first device sends the user credentials corresponding to the target application to the second device.

[0117] S302, based on the second SIM card in the second device, performs auxiliary authorization authentication on the user credentials and obtains the authentication result.

[0118] In this embodiment of the disclosure, in response to receiving an auxiliary authorization authentication request sent by the first device, auxiliary authorization authentication is performed on the user credentials based on the second SIM card in the second device to obtain an authentication result.

[0119] Optionally, the encrypted user credentials can be verified based on the session key of the second device to obtain the authorization target information. Based on the execution assertion set of the second device, the hash value of the user identifier in the encrypted user credentials and the authorization target information can be executed to obtain the authentication result.

[0120] S303, send the authentication result to the first device. The authentication result is used by the first device to determine whether to authorize the target operation of the target application.

[0121] In this disclosed embodiment, after obtaining the authentication result, the authentication result is sent to the first device to complete the auxiliary authorization.

[0122] In summary, the collaborative authentication method provided in this disclosure receives user credentials corresponding to a target application sent by a first device (the target application is an application within the first device), performs auxiliary authorization authentication on the user credentials based on a second SIM card within a second device, obtains an authentication result, and sends the authentication result to the first device. The authentication result is used by the first device to determine whether to authorize a target operation of the target application. Thus, this disclosure uses the second SIM card within the second device to collaboratively perform auxiliary authorization authentication. The authentication result can determine whether to authorize a target operation of the target application, improving the security and privacy of authorization, reducing the risk of fraud, and enhancing the credibility of the target operation.

[0123] Figure 4 This is a flowchart illustrating a collaborative authentication method provided in an embodiment of this application.

[0124] like Figure 4 As shown, the collaborative authentication method proposed in this embodiment includes the following steps: S401, Obtain the joint assertion sent by the first device, wherein the joint assertion is related to the device description metadata of the first device and the user description metadata of the user, as well as the measurement summary and the target assertion.

[0125] S402, based on the joint assertion, obtain the assertion set and feed the assertion set back to the first device. The assertion set is used to encrypt the user credentials to obtain encrypted user credentials.

[0126] In this embodiment of the disclosure, a first candidate assertion that the second device itself can support is determined, the first candidate assertion and the joint assertion are compared to obtain the difference assertion, and the assertion set is determined based on the difference assertion.

[0127] Optionally, the policy engine can be invoked to compare user attributes using rules to determine the first candidate assertion that the second device itself can support. By comparing the first candidate assertion with the joint assertion, the differential assertion can be obtained. ,in, For the difference assertion, For joint assertion, Assertion as the first candidate.

[0128] In this embodiment of the disclosure, after obtaining the differential assertions, the differential assertions can be converted into instructions to obtain an assertion set.

[0129] The assertion set can represent the second device's own support for joint assertions.

[0130] Optionally, in response to the assertion logic of the differential assertion being executable, the set of assertions is determined to be differential assertions.

[0131] For example, the second device checks whether the assertion logic of the difference assertion can be executed in the second device itself. In response that the assertion logic of the difference assertion can be executed in the second device itself, the set of assertions is the difference assertion itself.

[0132] Optionally, in response to the assertion logic of the differential assertion being unexecutable, a second candidate assertion is matched from the assertion library of the second device based on the assertion logic, and the assertion set is determined as the first candidate assertion; in response to the second candidate assertion not being matched in the assertion library, a third candidate assertion is obtained based on the instruction execution environment of the second device and the differential assertion, and the assertion set is determined as the third candidate assertion.

[0133] For example, in response to the assertion logic of the difference assertion, which cannot be executed in the second device itself, the second candidate assertion is matched from the assertion library of the second device according to the assertion logic of the difference assertion, and the assertion set is determined as the first candidate assertion. The assertion logic of the second candidate assertion is the same as that of the first candidate assertion. In response to the second candidate assertion not being matched in the assertion library, the instruction execution environment and the difference assertion are sent to the authorization server associated with the second SIM card. The authorization server transcodes the assertion difference according to the instruction execution environment. If the transcoding is successful, a third candidate assertion is obtained. The authorization server sends the third candidate assertion to the second device. The second terminal receives the third candidate assertion sent by the authorization server and determines the assertion set as the third candidate assertion.

[0134] S403 receives an authorization and authentication request sent by the first device, the authorization and authentication request carrying encrypted user credentials.

[0135] In this embodiment of the disclosure, multi-factor authentication aggregation can be completed according to the completion ratio of the assertion set associated with the second device. In response to the completion of the multi-factor authentication aggregation of the second device, an authentication aggregation completion indication is sent to the first device, and a chain-building interaction is performed with the first device to establish a trusted chain between the first device and the second device. The authorization authentication request sent by the first device is received through the trusted link.

[0136] Optionally, the completion ratio of the assertion set associated with the second device is determined, multi-factor authentication aggregation is performed based on the completion ratio, and in response to the completion of multi-factor authentication aggregation of the second device, an authentication aggregation completion indication is sent to the first device.

[0137] S404: Based on the session key of the second device, the encrypted user credentials are verified to obtain the authorized target information.

[0138] For example, reading encrypted user credentials through a super SIM card in a second device. and According to the session key of the second device ,right and Confirmation is required. To determine the authorized target information.

[0139] The generation process of the session key for the second device is the same as that for the session key for the first device, and will not be repeated here.

[0140] For example, user credentials can be encrypted using the following formula to obtain encrypted user credentials:

[0141] in, For encrypting user credentials, h represents the message digest algorithm. For the authorized user in the user credentials, For session key, This refers to the authorization target information in the user credentials.

[0142] S405, based on the assertion set executed by the second device, executes the hash value of the user identifier and the authorization target information in the encrypted user credentials to obtain the authentication result.

[0143] In this embodiment of the disclosure, the hash value of the user identifier in the encrypted user credential is determined based on the assertion set executed by the second device. and authorized target information The process is executed, and the authentication result is obtained.

[0144] S406, send the authentication result to the first device. The authentication result is used by the first device to determine whether to authorize the target operation of the target application.

[0145] In summary, the collaborative authentication method provided in this disclosure obtains a joint assertion sent by a first device, wherein the joint assertion is related to the device description metadata of the first device, the user description metadata of the user, as well as the measurement digest and the target assertion. Based on the joint assertion, an assertion set is obtained and fed back to the first device. The assertion set is used to encrypt the user credentials to obtain encrypted user credentials. An authorization authentication request sent by the first device is received, which carries the encrypted user credentials. Based on the session key of the second device, the encrypted user credentials are confirmed to obtain authorization target information. Based on the assertion set executed by the second device, the hash value of the user identifier in the encrypted user credentials and the authorization target information are executed to obtain an authentication result. The authentication result is sent to the first device, and the authentication result is used by the first device to determine whether to authorize the target operation of the target application. Thus, this disclosure achieves more secure distributed auxiliary authorization by executing the assertion set based on the second device, executing the hash value of the user identifier in the encrypted user credentials and the authorization target information to obtain an authentication result, which is beneficial to improving the security and trustworthiness of the target operation.

[0146] The specific process of the collaborative authentication method provided in the embodiments of this disclosure will be explained below.

[0147] For example, such as Figure 5As shown, for the first SIM card and the super SIM card, (1) initialize the root key pair in the super SIM card in the first device and store the root key pair in the certificate of the super SIM card; (2) after the first terminal device starts, perform kernel multi-point measurement, generate measurement digest, sign the measurement digest based on the root key pair in the first SIM card, and obtain the proof information of the measurement digest; (3) in response to the target operation of the target application in the first device, perform consistency check on the user credentials corresponding to the target application based on the super SIM card in the first device to determine whether the authorization authentication is passed, and generate the joint assertion of the first device in response to the user credentials being authorized authentication; (4) determine the second device that the first device can communicate with, send the joint assertion to the second device, and the second device obtains the assertion set based on the joint assertion; (5) perform session level judgment in the data transmission or application layer key negotiation stage. (6) Generate a session key according to the session hierarchy; (7) Encrypt the user credentials in the authorization authentication request sent by the first device using the session key to obtain encrypted user credentials; (8) In response to the completion of the multi-factor authentication aggregation of the second device, construct a trusted chain between the first device and the second device, and send the encrypted user credentials in the authorization authentication request to the second device through the trusted chain; (9) After receiving the authorization authentication request, confirm the encrypted user credentials based on the session key to obtain the authorization target information, execute the hash value of the user identifier and the authorization target information in the encrypted user credentials based on the assertion set of the second device, and obtain the authentication result; (10) Receive the authentication results fed back by each second device and summarize them to obtain the final authentication result, feed back the authentication result to the first device, and determine whether to authorize the target operation of the target application in the first device according to the authentication result.

[0148] In summary, the multi-layered digital identity aggregation authentication method based on the Super SIM card constructs multi-layered distributed trust and short-term sub-credentials to reduce the impact of single-point failures and breaches. A hierarchical master / sub-identity and verifiable credential mechanism is designed to achieve minimal disclosure, contextualized identity, and offline / edge authentication. By making the Super SIM card a "multi-layered root of trust" for terminal devices, and leveraging the built-in hardware security module of the Super SIM card, multiple authentication enhancement methods are aggregated to provide trusted chain management throughout the entire lifecycle from device startup to data transmission. Local authentication is supported, and multi-layered session key encryption is used to transmit user credentials. Multi-factor authentication aggregation ensures that the aggregated authentication results meet the authentication requirements of the user credentials. After meeting the authentication requirements, a trusted chain is constructed to transmit encrypted user credentials for data transmission. With the assistance of the Super SIM card in a second device within a nearby reachable network, higher-security distributed collaborative authorization is achieved offline, supporting local authentication and realizing high-security authorization, thus improving the credibility and security of the target operation.

[0149] Figure 6 This is a block diagram illustrating a collaborative authentication device according to an exemplary embodiment.

[0150] like Figure 6 As shown, the collaborative authentication device 600 of this disclosure embodiment may specifically include: a first authentication module 601, a first determination module 602, a second authentication module 603, and a second determination module 604.

[0151] The first authentication module 601 is used to respond to the target operation of the target application in the first device and to perform authorization authentication on the user credentials corresponding to the target application based on the first SIM card in the first device. The first determining module 602 is configured to determine a second device that can be communicated with the first device in response to the user credentials being authenticated through authorization. The second authentication module 603 is used to perform auxiliary authorization authentication of the user credentials through the second SIM card in the second device; The second determining module 604 is used to determine whether to authorize the target operation based on the authentication result of the second device.

[0152] In one embodiment of this disclosure, the second authentication module 603 is further configured to: determine a target assertion from an assertion list, and update the target assertion based on the device description metadata of the first device, the user description metadata of the user, and the measurement digest to generate a joint assertion for the first device; send the joint assertion to the second device, and receive an assertion set fed back by the second device based on the joint assertion; encrypt the user credential based on the assertion set to obtain an encrypted user credential; and perform auxiliary authorization authentication on the encrypted user credential through the second SIM card to obtain the authentication result of the second device.

[0153] In one embodiment of this disclosure, the second authentication module 603 is further configured to: perform multi-point measurements on the kernel of the first device to generate the measurement digest; sign the measurement digest based on the root key pair in the first SIM card to obtain proof information of the measurement digest, wherein the root key pair is stored in the certificate of the first SIM card; and update the target assertion based on the device description metadata, the user description metadata and the proof information of the measurement digest to generate a joint assertion of the first device.

[0154] In one embodiment of this disclosure, the apparatus 600 is further configured to: store the measurement summary and corresponding proof information, as well as the obfuscated random number corresponding to the proof information, in the storage area of ​​the first SIM card; and report the measurement summary and corresponding proof information, as well as the obfuscated random number corresponding to the proof information, to the authorization server corresponding to the first SIM card.

[0155] In one embodiment of this disclosure, before the auxiliary authorization authentication of the encrypted user credential via the second SIM card, the device 600 is further configured to: receive a completion indication of identity authentication aggregation sent by the second device; in response to the completion indication, perform chain establishment interaction with the second device to establish a trusted chain between the first device and the second device; and send the encrypted user credential to the second device through the trusted chain.

[0156] In one embodiment of this disclosure, the second authentication module 603 is further configured to: determine the session level between the first device and the second device by performing a session level determination based on the assertion set; generate a corresponding session key based on the session level and the proof information; and encrypt the user credential based on the session key to obtain the encrypted user credential.

[0157] In one embodiment of this disclosure, the second authentication module 603 is further configured to: determine the type indicator value of the assertion set; obtain the number of elements in the joint assertion; and determine the session level based on the type indicator value, the number of elements, and the maximum number of session levels.

[0158] In one embodiment of this disclosure, the second authentication module 603 is further configured to: determine the completion ratio of the assertion set based on the type indication value and the number of elements; and determine the session level based on the completion ratio and the maximum number of session levels.

[0159] In one embodiment of this disclosure, the second authentication module 603 is further configured to: determine the target range in which the completion ratio is located; determine whether to enhance the completion ratio based on the target range; in response to the need to enhance the completion ratio, enhance the completion ratio based on the target enhancement strategy corresponding to the target range to obtain an enhanced completion ratio; and determine the session level based on the enhanced completion ratio and the maximum number of session levels.

[0160] In one embodiment of this disclosure, the second authentication module 603 is further configured to: determine an assertion security level threshold based on the target application and the target operation; determine the assertion security level of assertions in the assertion list; and select an assertion whose assertion security level is greater than the assertion security level threshold as the target assertion.

[0161] In one embodiment of this disclosure, the second authentication module 603 is further configured to: determine the target information carried by the target operation, and determine the verification security level of the target application and the target verification security level; and determine an assertion security level threshold based on the target information, the verification security level of the target application, and the target verification security level.

[0162] In one embodiment of this disclosure, the second determining module 604 is further configured to: determine the completion ratio of the assertion set associated with the second device, and sum the completion ratio to obtain a first sum; calculate the product of the authentication result and the corresponding completion ratio, and sum the products to obtain a second sum; obtain target authorization indication information based on the first sum and the second sum; and determine whether to authorize the target operation based on the target authorization indication information.

[0163] In the embodiments of this disclosure, the specific manner in which each structure in the collaborative authentication device of the above embodiments performs operations has been described in detail in the embodiments relating to the collaborative authentication method, and will not be repeated here.

[0164] The collaborative authentication device provided in this disclosure, in response to a target operation of a target application within a first device, authorizes and authenticates the user credentials corresponding to the target application based on a first SIM card within the first device. Upon successful authorization authentication of the user credentials, a second device reachable from the first device is determined, and auxiliary authorization authentication is performed on the user credentials using a second SIM card within the second device. Based on the authentication result of the second device, it is determined whether to authorize the target operation. Therefore, this disclosure, based on the collaborative authentication of the first SIM card of the first device and the second SIM card within the second device, reduces security risks during the authentication process, improves the reliability and security of authentication, and ensures privacy and flexibility in authentication by authorizing and authenticating user credentials.

[0165] Figure 7 This is a block diagram illustrating a collaborative authentication device according to an exemplary embodiment.

[0166] like Figure 7 As shown, the collaborative authentication device 700 of this disclosure embodiment may specifically include: a receiving module 701, an authentication module 702, and a sending module 703.

[0167] The receiving module 701 is used to receive the user credentials corresponding to the target application sent by the first device, wherein the target application is an application within the first device; Authentication module 702 is used to perform auxiliary authorization authentication on the user credentials based on the second SIM card in the second device, and obtain authentication results; The sending module 703 is used to send the authentication result to the first device, and the authentication result is used by the first device to determine whether to authorize the target operation of the target application.

[0168] In one embodiment of this disclosure, the receiving module 701 is further configured to: acquire a joint assertion sent by the first device, wherein the joint assertion is related to the device description metadata of the first device and the user description metadata of the user, as well as the measurement digest and the target assertion; acquire an assertion set based on the joint assertion, and feed back the assertion set to the first device, wherein the assertion set is used to encrypt the user credential to obtain an encrypted user credential; and receive an authorization authentication request sent by the first device, wherein the authorization authentication request carries the encrypted user credential.

[0169] In one embodiment of this disclosure, the receiving module 701 is further configured to: determine a first candidate assertion that the second device itself can support; compare the first candidate assertion and the joint assertion to obtain a difference assertion; and determine the assertion set based on the difference assertion.

[0170] In one embodiment of this disclosure, the apparatus 700 is further configured to: determine the assertion set as the differential assertion in response to the assertion logic of the differential assertion being executable; match a second candidate assertion from the assertion library of the second device based on the assertion logic in response to the differential assertion being unexecutable, and determine the assertion set as the first candidate assertion; and obtain the third candidate assertion based on the instruction execution environment of the second device and the differential assertion in response to the second candidate assertion not being matched in the assertion library, and determine the assertion set as the third candidate assertion.

[0171] In one embodiment of this disclosure, the apparatus 700 is further configured to: send the instruction execution environment and differential assertion to the authorization server associated with the second SIM card; and receive the third candidate assertion obtained by the authorization server based on the instruction execution environment and differential assertion transcoding.

[0172] In one embodiment of this disclosure, the receiving module 701 is further configured to: send a completion indication of identity authentication aggregation to the first device in response to the completion of multi-factor authentication aggregation of the second device; perform chain establishment interaction with the first device to establish a trusted chain between the first device and the second device; and receive the authorization authentication request sent by the first device through the trusted chain.

[0173] In one embodiment of this disclosure, the authentication module 702 is further configured to: confirm the encrypted user credential based on the session key of the second device to obtain authorization target information; and execute the hash value of the user identifier in the encrypted user credential and the authorization target information based on the assertion set of the second device to obtain the authentication result.

[0174] In the embodiments of this disclosure, the specific manner in which each structure in the collaborative authentication device of the above embodiments performs operations has been described in detail in the embodiments relating to the collaborative authentication method, and will not be repeated here.

[0175] The collaborative authentication device provided in this embodiment receives a user credential corresponding to a target application sent by a first device (the target application is an application within the first device). Based on a second SIM card within a second device, it performs auxiliary authorization authentication on the user credential, obtains an authentication result, and sends the authentication result back to the first device. The authentication result is used by the first device to determine whether to authorize a target operation of the target application. Thus, the second SIM card within the second device of this disclosure collaboratively performs auxiliary authorization authentication. The authentication result can determine whether to authorize a target operation of the target application, improving the security and privacy of authorization, reducing the risk of fraud, and enhancing the credibility of the target operation.

[0176] Figure 8 This is a block diagram illustrating an electronic device 800 according to an exemplary embodiment.

[0177] like Figure 8 As shown, the above-mentioned electronic device 800 includes: The memory 801 and processor 802 are connected by a bus 803, which connects the different components (including the memory 801 and the processor 802). The memory 801 stores a computer program, which implements the collaborative authentication method of the present disclosure embodiment when the processor 802 executes the program.

[0178] Bus 803 represents one or more of several bus architectures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any of the various bus architectures. For example, these architectures include, but are not limited to, the Industry Standard Architecture (ISA) bus, the Micro Channel Architecture (MAC) bus, the Enhanced ISA bus, the Video Electronics Standards Association (VESA) local bus, and the Peripheral Component Interconnect (PCI) bus.

[0179] Electronic device 800 typically includes a variety of electronic device readable media. These media can be any available media that can be accessed by electronic device 800, including volatile and non-volatile media, removable and non-removable media.

[0180] Memory 801 may also include computer system readable media in the form of volatile memory, such as random access memory (RAM) 804 and / or cache memory 805. Electronic device 800 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, storage system 806 may be used to read and write non-removable, non-volatile magnetic media (… Figure 8 Not shown; usually referred to as a "hard drive"). Although Figure 8 As not shown, a disk drive for reading and writing to a removable non-volatile disk (e.g., a "floppy disk") and an optical disk drive for reading and writing to a removable non-volatile optical disk (e.g., a CD-ROM, DVD-ROM, or other optical media) may be provided. In these cases, each drive may be connected to bus 803 via one or more data media interfaces. Memory 801 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of the embodiments of this disclosure.

[0181] A program / utility 808 having a set (at least one) of program modules 807 may be stored, for example, in memory 801. Such program modules 807 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment. Program modules 807 typically perform the functions and / or methods described in the embodiments of this disclosure.

[0182] Electronic device 800 can also communicate with one or more external devices 809 (e.g., keyboard, pointing device, display 811, etc.), and with one or more devices that enable a user to interact with the electronic device 800, and / or with any device that enables the electronic device 800 to communicate with one or more other computing devices (e.g., network card, modem, etc.). This communication can be performed through input / output (I / O) interface 812. Furthermore, electronic device 800 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 813. Figure 8 As shown, network adapter 813 communicates with other modules of electronic device 800 via bus 803. It should be understood that, although not shown in the figure, other hardware and / or software modules can be used in conjunction with electronic device 800, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0183] The processor 802 executes various functional applications and data processing by running programs stored in the memory 801.

[0184] It should be noted that the implementation process and technical principles of the electronic device in this embodiment are explained in the foregoing description of the collaborative authentication method of the present disclosure embodiment, and will not be repeated here.

[0185] To implement the above embodiments, this disclosure also proposes a computer-readable storage medium.

[0186] When the instructions in the computer-readable storage medium are executed by the processor of the electronic device, the electronic device is able to perform the aforementioned cooperative authentication method. Optionally, the computer-readable storage medium may be a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, or optical data storage device, etc.

[0187] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the following claims.

[0188] It should be understood that this disclosure is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this disclosure is limited only by the appended claims.

Claims

1. A collaborative authentication method, characterized in that, The method includes: In response to a target operation of a target application within the first device, the user credentials corresponding to the target application are authorized and authenticated based on the first SIM card within the first device. In response to the user credentials being authenticated, a second device that can be communicated with the first device is determined; The user credentials are further authorized and authenticated using the second SIM card within the second device; Based on the authentication result of the second device, determine whether to authorize the target operation.

2. The method according to claim 1, characterized in that, The auxiliary authorization authentication of the user credential via the second SIM card within the second device further includes: From the assertion list, the target assertion is determined, and the target assertion is updated based on the device description metadata of the first device, the user description metadata of the user, and the measurement summary to generate a joint assertion of the first device; Send the joint assertion to the second device and receive the set of assertions fed back by the second device based on the joint assertion; The user credentials are encrypted based on the set of assertions to obtain encrypted user credentials; The second SIM card is used to perform auxiliary authorization authentication on the encrypted user credentials to obtain the authentication result of the second device.

3. The method according to claim 2, characterized in that, The step of updating the target assertion based on the device description metadata of the first device, the user description metadata of the user, and the measurement summary to generate a joint assertion for the first device further includes: Perform multi-point measurements on the kernel of the first device to generate the measurement summary; Based on the root key pair in the first SIM card, the measurement digest is signed to obtain the proof information of the measurement digest, and the root key pair is stored in the certificate of the first SIM card; Based on the device description metadata, the user description metadata, and the proof information of the measurement summary, the target assertion is updated to generate a joint assertion for the first device.

4. The method according to claim 3, characterized in that, After generating the joint assertion of the first device, at least one of the following operations is also included: The measurement summary and corresponding proof information, as well as the obfuscated random number corresponding to the proof information, are stored in the storage area of ​​the first SIM card. The measurement summary and corresponding proof information, as well as the obfuscated random number corresponding to the proof information, are reported to the authorization server corresponding to the first SIM card.

5. The method according to claim 2, characterized in that, Before performing auxiliary authorization authentication of the encrypted user credential via the second SIM card, the method further includes: Receive a completion indication of identity authentication aggregation sent by the second device; In response to the completion instruction, a chain-building interaction is performed with the second device to establish a trusted chain between the first device and the second device; The encrypted user credentials are sent to the second device via the trusted chain.

6. The method according to any one of claims 2-5, characterized in that, The step of encrypting the user credential based on the assertion set to obtain an encrypted user credential includes: Based on the assertion set, a session hierarchy determination is performed to determine the session hierarchy between the first device and the second device; Generate a corresponding session key based on the session hierarchy and the proof information; The user credentials are encrypted using the session key to obtain the encrypted user credentials.

7. The method according to claim 6, characterized in that, The step of determining the session level between the first device and the second device based on the assertion set includes: Determine the type indicator value of the assertion set; Obtain the number of elements in the joint assertion; The session hierarchy is determined based on the type indicator value, the number of elements, and the maximum number of session levels.

8. The method according to claim 7, characterized in that, Determining the session hierarchy based on the type indicator value, the number of elements, and the maximum number of session levels includes: Determine the completion rate of the assertion set based on the type indicator value and the number of elements; The session hierarchy is determined based on the completion rate ratio and the maximum number of session levels.

9. The method according to claim 8, characterized in that, Determining the session hierarchy based on the completion rate ratio and the maximum number of session levels includes: Determine the target range within which the completion percentage falls; Based on the target range, determine whether to enhance the completion rate ratio; In response to the need to enhance the completion ratio, the completion ratio is enhanced based on the target enhancement strategy corresponding to the target interval range, resulting in an enhanced completion ratio. The session hierarchy is determined based on the enhancement completion ratio and the maximum number of session levels.

10. The method according to any one of claims 2-5, characterized in that, The step of determining the target assertion from the assertion list includes: Determine the assertion security level threshold based on the target application and the target operation; Determine the assertion security level of the assertions in the assertion list; Assertions whose security level is greater than the assertion security level threshold are selected as the target assertions.

11. The method according to claim 10, characterized in that, The step of determining the assertion security level threshold based on the target application and the target operation includes: Determine the target information carried by the target operation, and determine the verification security level of the target application and the target verification security level; Based on the target information, the verification security level of the target application, and the target verification security level, determine the assertion security level threshold.

12. The method according to claim 8, characterized in that, The step of determining whether to authorize the target operation based on the authentication result of the second device includes: Determine the completion ratio of the assertion set associated with the second device, and sum the completion ratios to obtain a first sum value; The product of the authentication result and the corresponding completion rate is calculated, and the product is summed to obtain the second sum value; Based on the first sum and the second sum, the target authorization instruction information is obtained; Based on the target authorization instruction information, determine whether to authorize the target operation.

13. A collaborative authentication method, characterized in that, The method includes: Receive user credentials for a target application sent by a first device, wherein the target application is an application within the first device; Based on the second SIM card in the second device, auxiliary authorization authentication is performed on the user credentials to obtain the authentication result; The authentication result is sent to the first device, and the authentication result is used by the first device to determine whether to authorize the target operation of the target application.

14. The method according to claim 13, characterized in that, The receipt of the user credentials corresponding to the target application sent by the first device includes: Obtain the joint assertion sent by the first device, wherein the joint assertion is related to the device description metadata of the first device and the user description metadata of the user, as well as the measurement summary and the target assertion; Based on the joint assertion, an assertion set is obtained and fed back to the first device. The assertion set is used to encrypt the user credential to obtain an encrypted user credential. The system receives an authorization and authentication request sent by the first device, the authorization and authentication request carrying the encrypted user credential.

15. The method according to claim 14, characterized in that, The step of obtaining the assertion set based on the joint assertion includes: Determine the first candidate assertion that the second device itself can support; The first candidate assertion and the joint assertion are compared to obtain the difference assertion; The set of assertions is determined based on the difference assertions.

16. The method according to claim 15, characterized in that, Determining the assertion set based on the difference assertions includes at least one of the following operations: In response to the assertion logic being executable for the differential assertion, the set of assertions is determined to be the differential assertion; In response to the assertion logic of the differential assertion being unexecutable, based on the assertion logic, a second candidate assertion is matched from the assertion library of the second device, and the assertion set is determined as the first candidate assertion; In response to the fact that no second candidate assertion is matched in the assertion library, the third candidate assertion is obtained based on the instruction execution environment and differential assertions of the second device, and the assertion set is determined as the third candidate assertion.

17. The method according to claim 16, characterized in that, The process of obtaining the third candidate assertion based on the instruction execution environment and differential assertion of the second device includes: Send the instruction execution environment and difference assertion to the authorization server associated with the second SIM card; Receive the third candidate assertion obtained by the authorization server based on the instruction execution environment and differential assertion transcoding.

18. The method according to any one of claims 14-17, characterized in that, The step of receiving the authorization and authentication request sent by the first device includes: In response to the completion of multi-factor authentication aggregation by the second device, a completion indication for authentication aggregation is sent to the first device; Establish a trust chain between the first device and the second device by interacting with the first device; The authorization and authentication request sent by the first device is received through the trusted link.

19. The method according to any one of claims 14-17, characterized in that, The auxiliary authorization authentication of the user credentials based on the second SIM card within the second device, to obtain the authentication result, includes: Based on the session key of the second device, the encrypted user credentials are confirmed to obtain the authorized target information; Based on the assertion set executed by the second device, the hash value of the user identifier in the encrypted user credential and the authorization target information are executed to obtain the authentication result.

20. A collaborative authentication device, characterized in that, The device includes: The first authentication module is used to respond to the target operation of the target application in the first device and to perform authorization authentication on the user credentials corresponding to the target application based on the first SIM card in the first device. The first determining module is configured to determine a second device that can be communicated with the first device in response to the user credentials being authenticated through authorization; The second authentication module is used to perform auxiliary authorization authentication of the user credentials through the second SIM card in the second device; The second determining module is used to determine whether to authorize the target operation based on the authentication result of the second device.

21. A collaborative authentication device, characterized in that, The device includes: A receiving module is used to receive a user credential corresponding to a target application sent by a first device, wherein the target application is an application within the first device. The authentication module is used to perform auxiliary authorization authentication on the user credentials based on the second SIM card in the second device, and obtain the authentication result; The sending module is used to send the authentication result to the first device, and the authentication result is used by the first device to determine whether to authorize the target operation of the target application.

22. An electronic device, characterized in that, include: processor; Memory for storing the executable instructions of the processor; The processor is configured to execute the instructions to implement the collaborative authentication method as described in any one of claims 1-12 or 13-19.

23. A computer-readable storage medium, characterized in that, When the instructions in the computer-readable storage medium are executed by the processor of the electronic device, the electronic device is enabled to perform the cooperative authentication method as described in any one of claims 1-12 or 13-19.

24. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements a collaborative authentication method according to any one of claims 1-12 or 13-19.