Access control method and related device
By using an access control method based on weak authentication factors, electronic devices create a restricted execution environment based on operation instructions and authentication factors when locked, which solves the problem of cumbersome unlocking and achieves more granular access control and convenient operation.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HUAWEI TECH CO LTD
- Filing Date
- 2021-06-29
- Publication Date
- 2026-04-28
AI Technical Summary
The current unlocking process for electronic devices requires users to input precise identity authentication information, resulting in cumbersome authentication operations that affect convenience and device usage efficiency.
An access control method based on weak authentication factors is adopted. By obtaining operation instructions and weak authentication factors, a restricted execution environment is created according to the risk level of the operation instructions and the security level of the authentication factors, allowing some operations to be performed in a locked state.
It enables finer-grained access control in the locked state, enriches the usage scenarios of electronic devices, and improves the convenience of user operation and the security of devices.
Smart Images

Figure CN121935899A_ABST
Abstract
Description
[0001] This application is a divisional application. The original application has the application number 202110742228.8 and the original application date is June 29, 2021. The entire contents of the original application are incorporated herein by reference. Technical Field
[0002] This application relates to the field of terminal and identity authentication technology, and in particular to access control methods and related devices. Background Technology
[0003] For security and to prevent accidental operation, electronic devices such as computers and mobile phones can be set to a locked state. When an electronic device is in a locked state, the user needs to enter pre-set authentication information, such as a fingerprint, facial recognition, or password, to unlock it and enter the unlocked state. Most functions of the electronic device can only be accessed in the unlocked state.
[0004] Currently, users need to input precise identity verification information, such as a close-up facial image or a fingerprint that perfectly matches a preset fingerprint, to unlock electronic devices. Furthermore, users cannot use less accurate authentication methods, such as voiceprint authentication, to unlock their devices. This results in users having to go through cumbersome authentication processes, sometimes even multiple times, to unlock their devices, thus diminishing the convenience of using electronic devices. Summary of the Invention
[0005] This application provides access control methods and related devices that allow users to freely and conveniently control electronic devices without having to go through cumbersome authentication to unlock them.
[0006] In a first aspect, embodiments of this application provide an access control method based on a weak authentication factor, comprising: when a first device is in a locked state, acquiring a first operation instruction and a first authentication factor; the first operation instruction is used to request access to a first resource of the first device, the first authentication factor includes authentication information that does not meet the unlocking requirements of the first device, and authentication information that meets the unlocking requirements of the first device is used to switch the first device from a locked state to an unlocked state; the first device determines the resources that the first device is allowed to access based on the first operation instruction and the first authentication factor; if the resources that the first device is allowed to access include the first resource, then the first device responds to the first operation instruction and accesses the first resource.
[0007] By implementing the method provided in the first aspect, electronic devices no longer solely determine whether to respond and execute corresponding operations based on whether they are unlocked. Instead, more granular access control can be achieved for various resources based on operation commands and weak authentication factors, enriching the usage scenarios and scope of electronic devices. For users, there is no need to go through cumbersome authentication to unlock electronic devices and trigger them to perform certain operations, allowing users to control electronic devices more freely and conveniently.
[0008] In conjunction with the first aspect, in some implementations, the first device can determine the resources it is allowed to access based on the risk level of accessing the first resource; the higher the risk level of accessing the first resource, the fewer resources the first device is allowed to access. Specifically, the higher the privacy level of the first resource, the higher the risk level of accessing it. This fully considers the risks of resource access and avoids situations such as data leakage.
[0009] In conjunction with the first aspect, in some implementations, the first device can determine the resources it is allowed to access based on the security level of the first authentication factor; the lower the security level of the first authentication factor, the fewer resources the first device is allowed to access. Specifically, the higher the authentication capability level (ACL) of the authentication method corresponding to the first authentication factor, or the higher the matching degree between the first authentication factor and the authentication information that meets the unlocking requirements of the first device, or the higher the security level of the first authentication factor, the better it is acquired. This fully considers the reliability of the current authentication factor and avoids situations such as data leakage.
[0010] In conjunction with the first aspect, in some implementations, the first resource includes: predefined resources that the first device cannot access in a locked state. Here, resources accessible in a locked state are basic or commonly used resources, such as camera applications, flashlights, Bluetooth, etc. Resources inaccessible in a locked state may include resources involving user privacy data, such as photos, browsing history, etc. The resources accessible in a locked state may be predefined by the first device.
[0011] In conjunction with the first aspect, in some implementations, the first operation instruction includes any one of the following: semantics carried by speech, gestures, facial expressions, or body posture.
[0012] In conjunction with the first aspect, in some embodiments, the first device may acquire the first operation command in any of the following ways: The first device collects voice or images and identifies the first operation command carried in the voice or images; The first device receives voice or image sent by the second device and identifies the first operation command carried in the voice or image; or, The first device receives the first operation command sent by the second device.
[0013] In conjunction with the first aspect, in some implementations, the authentication information includes any one or more of the following: password, graphic, or biometric features. Biometric features are divided into two categories: physical features and behavioral features. Physical features include: face, voiceprint, fingerprint, palm print, retina, iris, body odor, face shape, heart rate, and deoxyribonucleic acid (DNA). Behavioral features include: signature, body posture (such as gait), etc.
[0014] In conjunction with the first aspect, in some implementations, the authentication information that fails to meet the unlocking requirements of the first device may include any one or more of the following: 1. Identity authentication information that is below the standard required for the first authentication method.
[0015] The first authentication method is an identity authentication method used to switch the first device from a locked state to an unlocked state.
[0016] In some embodiments, the first authentication method is an authentication method with an authentication capability level (ACL) higher than a third value, or the first authentication method is preset by the first device. For example, the first authentication method may include password authentication, image authentication, fingerprint authentication, and facial authentication, etc.
[0017] Identity authentication information below the standard required for the first authentication method may include: biometric features whose matching degree with a pre-stored first biometric feature is lower than a first value, where the first biometric feature is the identity authentication information corresponding to the first authentication method. The first value can be preset.
[0018] 2. Identity authentication information that meets the standards required for the second authentication method.
[0019] The second authentication method is an identity authentication method other than the first authentication method.
[0020] In some embodiments, the second authentication method is an identity authentication method other than the first authentication method. The second authentication method can be an identity authentication method with a lower authentication capability level (ACL), or the second authentication method can be pre-configured by the first device. For example, the second authentication method may include voiceprint authentication, heart rate authentication, body posture authentication, etc.
[0021] The identity authentication information that meets the standards required for the second authentication method includes: a biometric feature whose matching degree with a pre-stored second biometric feature reaches a second value, where the second biometric feature is the identity authentication information corresponding to the second authentication method. The second value can be preset.
[0022] In conjunction with the first aspect, in some implementations, the first device may obtain the first authentication factor through any one or more of the following: The first device collects voice or images and identifies the first authentication factor carried in the voice or images; The first device receives voice or image sent by the second device and identifies the first authentication factor carried in the voice or image; or, The first device receives the first authentication factor sent by the second device.
[0023] In conjunction with the first aspect, in some embodiments, the first device may also simultaneously acquire a first operation command and a first authentication factor. For example, the first device may acquire speech, identify the semantics of the speech, and determine the semantics as the first operation command; identify the voiceprint carried by the speech, and determine the voiceprint as the first authentication factor. Alternatively, the first device may acquire images, identify gestures, facial expressions, and body postures in the images, and determine the gestures, facial expressions, and body postures in the images as the first operation command; identify the biometric features carried in the images, and determine the biometric features as the first authentication factor.
[0024] In conjunction with the first aspect, in some embodiments, after the first device accesses the first resource in response to the first operation instruction, the first device may also receive a user operation requesting access to a second resource of the first device. If the resources that the first device allows access to include the second resource, the first device responds to the user operation and accesses the second resource; if the resources that the first device allows access to do not include the second resource, the first device refuses to respond to the user operation.
[0025] The above implementation method can limit the operations that the first device can perform to a certain range, thus avoiding the expansion of permissions and protecting the data security of the first device.
[0026] In conjunction with the first aspect, in some implementations, after the first device responds to the first operation command and accesses the first resource, it can also obtain a second authentication factor. The second authentication factor includes identity authentication information that meets the unlocking requirements of the first device, or a predetermined number of first authentication factors. The first device switches from a locked state to an unlocked state based on the second authentication factor. When the second authentication factor is a predetermined number of first authentication factors, the user can complete identity authentication and trigger the unlocking of the electronic device by entering the first authentication factors multiple times.
[0027] In conjunction with the previous implementation, after the first device determines the resources it is allowed to access, but before obtaining the second authentication factor, it can display a first control, detect operations performed on the first control, and respond to these operations by starting to detect identity authentication information. In other words, the user can actively trigger the first device to start detecting identity authentication information, thereby obtaining the second authentication factor and unlocking the device. This allows the user to decide whether to unlock based on their own needs and also saves power consumption for the first device.
[0028] In conjunction with the first aspect, in some embodiments, after the first device determines the resources that it is allowed to access, it can create a restricted execution environment in which the first device is allowed to access the determined resources. The first device can access the first resource in the restricted execution environment in response to a first operation instruction.
[0029] In the previous embodiment, when specifically creating a restricted execution environment, the first device can record the determined operations that are allowed to be executed. That is, the first device records which specific access operations are allowed to be performed on which resources or types of resources.
[0030] Secondly, embodiments of this application provide a cross-device access control method, comprising: when a first device is in a locked state, receiving a second operation instruction sent by a third device; the second operation instruction is used to request access to a third resource of the first device; the first device determines, according to the second operation instruction, the resources that the first device is allowed to access; if the resources that the first device is allowed to access include the third resource, then the first device responds to the second operation instruction and accesses the third resource.
[0031] Implementing the second approach, electronic devices no longer solely rely on unlocking status to determine whether to respond and execute corresponding operations. Instead, they use operational commands to achieve more granular access control over various resources, enriching the usage scenarios and scope of electronic devices. For users, unlocking electronic devices no longer requires cumbersome authentication to trigger operations, allowing for more flexible and convenient control.
[0032] In conjunction with the second aspect, in some implementations, the first device can determine the resources it is allowed to access based on the risk level of accessing the third resource; the higher the risk level of accessing the third resource, the fewer resources the first device is allowed to access. Specifically, the higher the privacy level of the third resource, the higher the risk level of accessing it. This fully considers the risks of resource access and avoids situations such as data leakage.
[0033] In conjunction with the second aspect, in some embodiments, the third resource includes: a predefined resource that the first device cannot access in a locked state. Here, the third resource is the same as the first resource in the first aspect, and reference can be made to the relevant description in the first aspect.
[0034] In conjunction with the second aspect, in some implementations, the third operation instruction includes any one of the following: semantics carried by speech, gestures, facial expressions, or body posture.
[0035] In conjunction with the second aspect, in some implementations, the third operation instruction is a screen casting request. Thus, for data sharing scenarios such as screen casting and multi-screen interaction, when one device shares data to another device, the other device does not need to be unlocked. Compared to solutions that require unlocking the other device every time data is shared, the embodiments of this application reduce the difficulty and complexity of screen casting and multi-screen interaction, providing users with a better user experience.
[0036] In conjunction with the second aspect, in some embodiments, after the first device accesses the third resource in response to the second operation instruction, it may receive a user operation requesting access to a fourth resource of the first device. If the resources that the first device allows access to include the fourth resource, the first device responds to the user operation and accesses the fourth resource; if the resources that the first device allows access to do not include the fourth resource, the first device refuses to respond to the user operation.
[0037] The above implementation method can limit the operations that the first device can perform to a certain range, thus avoiding the expansion of permissions and protecting the data security of the first device.
[0038] In conjunction with the second aspect, in some implementations, after the first device responds to the second operation instruction and accesses the third resource, it can obtain a second authentication factor. The second authentication factor includes identity authentication information that meets the unlocking requirements of the first device, or a predetermined number of first authentication factors. The first device switches from a locked state to an unlocked state based on the second authentication factor. When the second authentication factor is the predetermined number of first authentication factors, the user can complete identity authentication and trigger the unlocking of the electronic device by entering the first authentication factors multiple times.
[0039] In conjunction with the previous implementation, after the first device determines the resources it is allowed to access, but before obtaining the second authentication factor, it can display the first control; detect an operation performed on the first control; and respond to the operation performed on the first control by starting to detect identity authentication information. In other words, the user can actively trigger the first device to start detecting identity authentication information, thereby obtaining the second authentication factor and unlocking the device. This allows the user to decide whether to unlock based on their own needs and also saves power consumption on the first device.
[0040] In conjunction with the second aspect, in some implementations, after the first device determines the resources it is allowed to access, it can create a restricted execution environment in which the first device is allowed to access the determined resources. The first device can then access a third resource within the restricted execution environment in response to a second operational instruction.
[0041] In the previous embodiment, when specifically creating a restricted execution environment, the first device can record the determined operations that are allowed to be executed. That is, the first device records which specific access operations are allowed to be performed on which resources or types of resources.
[0042] Thirdly, embodiments of this application provide an electronic device, including: a memory and one or more processors; the memory is coupled to one or more processors, the memory is used to store computer program code, the computer program code includes computer instructions, and one or more processors call the computer instructions to cause the electronic device to perform the method as described in the first aspect or any embodiment of the first aspect.
[0043] Fourthly, embodiments of this application provide an electronic device, including: a memory and one or more processors; the memory is coupled to one or more processors, the memory is used to store computer program code, the computer program code including computer instructions, and one or more processors call the computer instructions to cause the electronic device to perform the method as described in the second aspect or any embodiment of the second aspect.
[0044] Fifthly, embodiments of this application provide a communication system, including a first device and a second device, wherein the first device is used to perform the method as described in the first aspect or any embodiment of the first aspect.
[0045] In a sixth aspect, embodiments of this application provide a communication system, including a first device and a third device, wherein the first device is used to perform the method as described in the second aspect or any of the embodiments of the second aspect.
[0046] In a seventh aspect, embodiments of this application provide a computer-readable storage medium including instructions that, when executed on an electronic device, cause the electronic device to perform a method as described in the first aspect or any embodiment of the first aspect.
[0047] Eighthly, embodiments of this application provide a computer program product that, when run on a computer, causes the computer to perform the method of the second aspect or any of the embodiments of the second aspect.
[0048] Ninthly, embodiments of this application provide a computer-readable storage medium including instructions that, when executed on an electronic device, cause the electronic device to perform a method as described in the first aspect or any embodiment of the first aspect.
[0049] In a tenth aspect, embodiments of this application provide a computer program product that, when run on a computer, causes the computer to perform the method of the second aspect or any of the embodiments of the second aspect.
[0050] By implementing the technical solution provided in this application, when an electronic device is in a locked state, after obtaining an operation command and authentication information indicating that the unlocking requirements have not been met, it can determine whether access to the resource requested by the operation command is permitted. If so, the device will respond to the operation command and access the corresponding resource. Implementing this method eliminates the need for users to undergo cumbersome authentication to unlock the electronic device, allowing access to corresponding resources while it is locked, thus enabling users to control the electronic device more freely and conveniently. Furthermore, the electronic device no longer determines whether to perform certain operations based on whether it is unlocked, allowing for finer-grained access control and enriching the usage scenarios and scope of the electronic device. Attached Figure Description
[0051] Figure 1 A schematic diagram of the hardware structure of the electronic device provided in the embodiments of this application; Figure 2 A schematic diagram of the software structure of the electronic device provided in the embodiments of this application; Figure 3 The structural diagram of the communication system provided in the embodiments of this application; Figure 4 A flowchart illustrating the access control method based on weak authentication factors provided in this application embodiment; Figure 5A The user interface of the electronic device 100 provided in this application embodiment when it is in a locked state; Figures 5B-5D The scenario in which the electronic device 100 provided in the embodiments of this application is located; Figures 5E-5G The user interface displayed after creating a restricted execution environment for the electronic device 100 provided in this application embodiment; Figure 6 A flowchart illustrating a cross-device access control method provided in an embodiment of this application; Figures 7A-7C A set of user interfaces involved in cross-device access control methods; Figure 8A and Figure 8B A schematic diagram of the software structure of the electronic device 100 provided in the embodiments of this application. Detailed Implementation
[0052] The technical solutions in the embodiments of this application will be clearly and thoroughly described below with reference to the accompanying drawings. In the description of the embodiments of this application, unless otherwise stated, " / " means "or," for example, A / B can mean A or B; the word "and / or" in the text is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Furthermore, in the description of the embodiments of this application, "multiple" refers to two or more than two.
[0053] Hereinafter, the terms "first" and "second" are used for descriptive purposes only and should not be construed as implying or suggesting relative importance or implicitly indicating the number of indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature, and in the description of the embodiments of this application, unless otherwise stated, "multiple" means two or more.
[0054] The term "user interface (UI)" used in the following embodiments of this application refers to the medium interface through which an application or operating system interacts and exchanges information with a user. It realizes the conversion between the internal form of information and the form that the user can accept. The user interface is source code written in a specific computer language such as Java or Extensible Markup Language (XML). The interface source code is parsed and rendered on the electronic device, ultimately presenting content that the user can recognize. A common form of user interface is the graphical user interface (GUI), which refers to a user interface related to computer operation displayed graphically. It can be visible interface elements such as text, icons, buttons, menus, tabs, text boxes, dialog boxes, status bars, navigation bars, and widgets displayed on the screen of an electronic device.
[0055] In this embodiment of the application, the electronic device has two states: a locked state and an unlocked state.
[0056] In the locked state, the electronic device can only perform predefined operations and cannot perform any other operations. The locked state can be used to prevent accidental user operations or to prevent the electronic device from performing operations other than those predefined.
[0057] In the embodiments of this application, the electronic device performing a certain operation specifically refers to the electronic device performing an access operation on a certain resource. This access operation may include operations such as reading, adding, deleting, writing, modifying, and executing.
[0058] In this embodiment of the application, the resources in the electronic device may include one or more of the following: software resources, hardware resources, peripherals or peripheral resources, etc. of the electronic device. Hardware resources and hardware-related configurations of electronic devices, such as cameras, sensors, audio devices, displays, motors, flashlights, etc., that may be included in electronic devices.
[0059] Software resources are related to the software configuration of electronic devices. This includes, for example, applications (apps) or service components installed on the electronic device, its memory resources, computing power (e.g., beautification algorithms, audio and video encoding / decoding capabilities), network capabilities, device connectivity, device discovery capabilities, data transmission capabilities, and so on. Software resources can include system resources as well as third-party resources; there are no specific limitations here.
[0060] Peripherals are devices that connect to electronic devices and are used for transmitting, forwarding, and storing data and information. Examples of peripherals include accessories for electronic devices such as mice, external displays, Bluetooth headsets, keyboards, and smartwatches and smart bracelets managed by the electronic device. The resources of peripherals can include hardware and software resources, which are described in the preceding sections.
[0061] In this embodiment, the predefined operations can be predefined by the manufacturer of the electronic device and cannot be modified. The manufacturer of the electronic device may include the manufacturer, supplier, provider, etc., of the electronic device. A manufacturer can refer to a production company that manufactures electronic devices using self-made or purchased parts and raw materials. A supplier can refer to a company that provides the complete electronic device, raw materials, or parts. For example, the manufacturer of Huawei's "Mate" series mobile phones is Huawei Technologies Co., Ltd.
[0062] These predefined operations do not involve user privacy data and only include some basic or commonly used operations. These predefined operations may include launching or shutting down some basic applications, such as launching the camera application, turning on the flashlight, opening the calculator, scanning a QR code, turning Bluetooth on / off, turning cellular signals on / off, turning Wireless Fidelity (Wi-Fi) signals on / off, etc., and after launching the camera application, the electronic device cannot access the gallery or photo album through the camera application.
[0063] Other operations besides the predefined operations can include operations involving user privacy data, as well as some operations that do not involve user privacy data. User privacy data can include user data stored in various applications, such as user photos, videos, audio, contact information, browsing history, shopping history, etc. Operations involving user privacy data can include, for example, launching or closing the gallery, photo album, contacts, shopping apps, instant messaging apps, memos, sharing user data via background processes, Wi-Fi, USB, Bluetooth, etc. Operations that do not involve user privacy data can include, for example, launching a navigation app without reading user data, launching a browser without reading browsing history, launching a video app without reading browsing history, etc. Navigation apps can also be referred to as map apps or other similar terms.
[0064] In the unlocked state, electronic devices can perform not only the predefined operations of the locked state, but also other operations beyond those predefined operations. For example, in the unlocked state, electronic devices can perform operations involving user privacy data, such as launching the gallery or photo album, launching shopping apps and viewing shopping records, launching instant messaging apps, viewing memos, viewing navigation data, viewing browser browsing history, and so on.
[0065] In this embodiment, the locked state can also be referred to by other terms, such as the screen lock state. Similarly, the unlocked state can also be referred to by other terms, and there is no limitation here. For the sake of simplicity, the terms "locked state" and "unlocked state" will be used uniformly in the following descriptions.
[0066] Electronic devices can preset multiple authentication methods and, in a locked state, can receive authentication information corresponding to the preset authentication methods. After confirming that the input authentication information meets the authentication standards, the device can unlock and enter an unlocked state.
[0067] Identity authentication is a technology used to verify a user's identity. Currently, identity authentication methods include password authentication, image authentication, and biometric authentication. Different users can be distinguished using different authentication information. Specifically, electronic devices can pre-store passwords, images, or biometric features. When a user enters the pre-stored password or image, or when the entered biometric feature matches a pre-stored feature with a certain degree of accuracy, the electronic device can confirm that the user is the one whose identity was previously stored. This degree of accuracy can be preset. The higher the degree of accuracy, the higher the accuracy of the biometric authentication method.
[0068] Passwords can be strings consisting of numbers, letters, and symbols.
[0069] Biometrics are divided into two categories: physical characteristics and behavioral characteristics. Physical characteristics include: face, voiceprint, fingerprint, palm print, retina, iris, body odor, facial shape, blood pressure, blood oxygen, blood sugar, respiratory rate, heart rate, electrocardiogram waveform over a single cycle, and deoxyribonucleic acid (DNA). Behavioral characteristics include: signature, body posture (such as gait), etc.
[0070] Because electronic devices vary in their accuracy in extracting various types of information, such as passwords, images, and biometric features, each of the aforementioned authentication methods has a corresponding authentication capability level (ACL). The higher the ACL, the more reliable the authentication result. The accuracy of information extraction by electronic devices depends on current technological advancements. For example, electronic devices are very accurate at extracting passwords and fingerprints, but less accurate at extracting voiceprints and signatures. Furthermore, for the same type of information, different electronic devices using different algorithms will achieve varying degrees of accuracy in extracting information using that authentication method.
[0071] Objectively speaking, the ACL (Access Control List) of an authentication method can be determined by its false accept rate (FAR), false reject rate (FRR), and spoof accept rate (SAR). The lower the FAR, the lower the FRR, and the lower the SAR, the higher the ACL. For example, the ACLs of password / image authentication, face / fingerprint authentication, voiceprint authentication, and body posture authentication decrease in that order.
[0072] ACLs can be divided into several levels of different granularities, which are not limited here. For example, ACLs can be divided into four levels.
[0073] To ensure data security, electronic devices typically only use authentication methods with higher ACLs to unlock them, rather than using authentication methods with lower ACLs.
[0074] For ease of description, the authentication method used to unlock the electronic device will be referred to as the first authentication method; other authentication methods besides the first authentication method will be referred to as the second authentication method. The first authentication method can be set by the electronic device or its manufacturer, and is not limited here. For example, an electronic device can be set to use password authentication, pattern authentication, fingerprint authentication, and facial recognition to unlock, instead of voiceprint authentication, heart rate authentication, or body posture authentication.
[0075] When an electronic device is locked, it can receive user-input authentication information. After confirming that the input authentication information meets the standards of the first authentication method, it unlocks and enters the unlock state. However, to input compliant authentication information, users need to perform relatively cumbersome operations. For example, users need to strictly enter a preset password or pattern, hold their face close to the front-facing camera of the electronic device at a certain distance, and press and hold a clean finger on the fingerprint sensor, etc. In other words, users need to perform cumbersome authentication operations, sometimes multiple times, to unlock the device, wasting a significant amount of time and the power consumption of the electronic device.
[0076] Furthermore, an increasing number of users are using voice commands and body gestures to control electronic devices, offering significant convenience in scenarios such as driving, cooking, and exercising without the need for physical contact. However, due to the low Access Limits (ACLs) of authentication methods like voiceprint and body gesture authentication, electronic devices cannot be directly unlocked via voice, body gesture, or remote gestures, requiring the use of other authentication methods with higher ACLs. This results in a loss of the convenience of voice commands, body gestures, and remote gestures, hindering users from freely and conveniently controlling electronic devices.
[0077] It can be seen that if a user wants to trigger an electronic device to perform operations other than the predefined operations in the locked state, they need to enter authentication information that conforms to a higher ACL authentication standard in a cumbersome way to unlock the device. This reduces the convenience of electronic devices and creates obstacles for users to use them.
[0078] The following embodiments of this application provide an access control method based on weak authentication factors. In this method, when an electronic device is in a locked state, after obtaining a first operation instruction and a weak authentication factor, a limited execution environment is created based on the risk level of the operation corresponding to the first operation instruction and the security level of the weak authentication factor. The device then responds to the first operation instruction and executes the corresponding operation within this limited execution environment.
[0079] The correspondence between the first operation instruction and its corresponding operation is preset by the electronic device. The first operation instruction can be received directly by the electronic device, or it can be obtained by another device and sent to the electronic device. The specific content of the first operation instruction can be found in the detailed description of the subsequent method embodiments, and will not be repeated here.
[0080] In some embodiments, the first operation instruction is used to request the electronic device to perform operations other than those predefined operations in the locked state. For details regarding the locked state, predefined operations, and operations other than those predefined operations, please refer to the relevant descriptions above.
[0081] A weak authentication factor refers to authentication information that fails to meet the requirements for unlocking an electronic device. Weak authentication factors can include the following two categories: 1. Authentication information that falls below the standards required for the first authentication method. 2. Authentication information that meets the standards required for the second authentication method. Weak authentication factors can be directly collected by the electronic device or collected by other devices and then sent to the electronic device. The specific content of weak authentication factors can be found in the detailed description of the subsequent method embodiments, and will not be repeated here.
[0082] In some embodiments, the electronic device may receive a first operation instruction and a weak authentication factor, respectively.
[0083] In some embodiments, the electronic device may simultaneously receive a first operation instruction and a weak authentication factor.
[0084] A restricted execution environment refers to a limited execution environment. An execution environment can include both hardware and software environments. It can be a sandbox or a function domain containing multiple functions. In a restricted execution environment, an electronic device can only execute a specified subset of operations and cannot execute other operations besides those specified operations. In other words, in a restricted execution environment, an electronic device can only access a subset of its resources and cannot access other resources outside of those specified resources. The restricted execution environment in this application embodiment may also be referred to as a limited execution environment, a restricted runtime environment, a restricted domain, etc., and is not limited thereto.
[0085] The electronic device can create a restricted execution environment based on the risk level of the operation corresponding to the first operation instruction and the security level of the weak authentication factor. The lower the risk level of the operation corresponding to the first operation instruction, or the higher the security level of the weak authentication factor, the more resources can be accessed in the restricted execution environment created by the electronic device. For details regarding the risk level of the operation, the security level of the weak authentication factor, and the method of creating the restricted execution environment, please refer to the relevant descriptions in the subsequent method embodiments.
[0086] Through the aforementioned access control method based on weak authentication factors, electronic devices no longer determine whether to respond and execute corresponding operations solely based on whether they are unlocked. Instead, they decide whether to execute the operation based on the risk level of the operation command and the security level of the weak authentication factor. This enables more granular access control, enriching the usage scenarios and scope of electronic devices. For users, there's no need to go through cumbersome authentication to unlock the electronic device; they can trigger operations beyond predefined ones while the device is locked, allowing for more flexible and convenient operation. Furthermore, electronic devices no longer simply categorize resources into those accessible by predefined operations and those accessible by other operations; they also implement more granular access control for each type of resource.
[0087] This application also provides a cross-device access control method, which is applied to a communication system containing two electronic devices. In this method, one electronic device can send a second operation instruction to another electronic device. The other electronic device can create a limited execution environment based on the risk level of the operation corresponding to the second operation instruction, and respond to the second operation instruction in the limited execution environment to perform the corresponding operation.
[0088] The second operation instruction and its corresponding operation are pre-set by the electronic device. This second operation instruction is an operation instruction sent by other electronic devices, such as a screen mirroring request. The specific content of the second operation instruction can be found in the detailed description of the subsequent method embodiments, and will not be repeated here.
[0089] In some embodiments, the second operation instruction is used to request the electronic device to perform other operations besides the predefined operations in the locked state described above.
[0090] The lower the risk level of the operation corresponding to the second operation instruction, the more resources can be accessed in the restricted execution environment created by the electronic device.
[0091] Through the aforementioned cross-device access control method, electronic devices no longer determine whether to respond to user operations solely based on whether they are unlocked. Instead, they decide based on the risk level of the operation commands received across devices. This enables more granular access control, enriching the usage scenarios and scope of electronic devices. For users, there's no need for cumbersome authentication to unlock the electronic device; they can trigger operations beyond predefined ones while the device is locked, allowing for more flexible and convenient operation. Furthermore, electronic devices no longer simply categorize resources into those accessible by predefined operations and those accessible by other operations; they implement more granular access control for each type of resource.
[0092] In both access control methods described above, after an electronic device creates a restricted execution environment, if the electronic device receives a user operation requesting an operation other than those permitted by the restricted execution environment, the electronic device can prompt the user to unlock. After unlocking at the user's request, the electronic device can respond to the previously received user operation and execute the corresponding operation.
[0093] In both access control methods described above, after the electronic device creates a restricted execution environment, the user can also actively trigger the unlocking of the electronic device. Once unlocked, the electronic device can respond to user actions and perform various operations.
[0094] The electronic device 100 provided in the embodiments of this application will be introduced first.
[0095] The electronic device 100 can be of various types, and this application embodiment does not limit the specific type of the electronic device 100. For example, the electronic device 100 includes a mobile phone, but may also include tablet computers, desktop computers, laptop computers, handheld computers, large-screen TVs, smart screens, wearable devices, augmented reality (AR) devices, virtual reality (VR) devices, artificial intelligence (AI) devices, in-vehicle systems, smart headphones, game consoles, and may also include Internet of Things (IoT) devices or smart home devices such as smart water heaters, smart lights, smart air conditioners, cameras, etc. It is not limited to these; the electronic device 100 may also include non-portable terminal devices such as laptops with touch-sensitive surfaces or touch panels, and desktop computers with touch-sensitive surfaces or touch panels, etc.
[0096] Figure 1 A schematic diagram of the structure of the electronic device 100 is shown.
[0097] Electronic device 100 may include processor 110, external memory interface 120, internal memory 121, universal serial bus (USB) interface 130, charging management module 140, power management module 141, battery 142, antenna 1, antenna 2, mobile communication module 150, wireless communication module 160, audio module 170, speaker 170A, receiver 170B, microphone 170C, headphone jack 170D, sensor module 180, button 190, motor 191, indicator 192, camera 193, display screen 194, and subscriber identification module (SIM) card interface 195, etc. The sensor module 180 may include a pressure sensor 180A, a gyroscope sensor 180B, a barometric pressure sensor 180C, a magnetic sensor 180D, an accelerometer sensor 180E, a distance sensor 180F, a proximity sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, etc.
[0098] It is understood that the structures illustrated in the embodiments of this application do not constitute a specific limitation on the electronic device 100. In other embodiments of this application, the electronic device 100 may include more or fewer components than illustrated, or combine some components, or split some components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.
[0099] Processor 110 may include one or more processing units, such as application processors (APs), modem processors, graphics processing units (GPUs), image signal processors (ISPs), controllers, video codecs, digital signal processors (DSPs), baseband processors, and / or neural network processing units (NPUs). These different processing units may be independent devices or integrated into one or more processors.
[0100] The controller can generate operation control signals based on the instruction opcode and timing signals to complete the control of instruction fetching and execution.
[0101] The processor 110 may also include a memory for storing instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. This memory can store instructions or data that the processor 110 has just used or that are used repeatedly. If the processor 110 needs to use the instruction or data again, it can retrieve it directly from the memory. This avoids repeated accesses, reduces the waiting time of the processor 110, and thus improves the efficiency of the system.
[0102] The wireless communication function of electronic device 100 can be realized through antenna 1, antenna 2, mobile communication module 150, wireless communication module 160, modem processor and baseband processor, etc.
[0103] Antenna 1 and antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in electronic device 100 can be used to cover one or more communication frequency bands. Different antennas can also be multiplexed to improve antenna utilization. For example, antenna 1 can be multiplexed as a diversity antenna for a wireless local area network. In some other embodiments, the antennas can be used in conjunction with a tuning switch.
[0104] The mobile communication module 150 can provide solutions for wireless communication, including 2G / 3G / 4G / 5G, applied to the electronic device 100. The mobile communication module 150 may include at least one filter, switch, power amplifier, low noise amplifier (LNA), etc. The mobile communication module 150 can receive electromagnetic waves via antenna 1, and perform filtering, amplification, and other processing on the received electromagnetic waves before transmitting them to a modem processor for demodulation. The mobile communication module 150 can also amplify the signal modulated by the modem processor and convert it into electromagnetic waves for radiation via antenna 1. In some embodiments, at least some functional modules of the mobile communication module 150 may be housed in the processor 110. In some embodiments, at least some functional modules of the mobile communication module 150 and at least some modules of the processor 110 may be housed in the same device.
[0105] The modem processor may include a modulator and a demodulator. The modulator modulates the low-frequency baseband signal to be transmitted into a mid-to-high frequency signal. The demodulator demodulates the received electromagnetic wave signal into a low-frequency baseband signal. The demodulator then transmits the demodulated low-frequency baseband signal to the baseband processor for processing. After processing by the baseband processor, the low-frequency baseband signal is transmitted to the application processor. The application processor outputs sound signals through an audio device (not limited to speaker 170A, receiver 170B, etc.) or displays images or videos through the display screen 194. In some embodiments, the modem processor may be a separate device. In other embodiments, the modem processor may be independent of the processor 110 and may be housed in the same device as the mobile communication module 150 or other functional modules.
[0106] The wireless communication module 160 can provide solutions for wireless communication applications on the electronic device 100, including wireless local area networks (WLANs) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), and infrared (IR) technologies. The wireless communication module 160 can be one or more devices integrating at least one communication processing module. The wireless communication module 160 receives electromagnetic waves via antenna 2, demodulates and filters the electromagnetic wave signals, and sends the processed signal to processor 110. The wireless communication module 160 can also receive signals to be transmitted from processor 110, frequency modulate and amplify them, and then convert them into electromagnetic waves for radiation via antenna 2.
[0107] In some embodiments, antenna 1 of electronic device 100 is coupled to mobile communication module 150, and antenna 2 is coupled to wireless communication module 160, enabling electronic device 100 to communicate with networks and other devices via wireless communication technology. The wireless communication technology may include Global System for Mobile Communications (GSM), General Packet Radio Service (GPRS), Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), Time Division Code Division Multiple Access (TD-SCDMA), Long Term Evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technologies, etc. The GNSS may include the Global Positioning System (GPS), the Global Navigation Satellite System (GLONASS), the BeiDou Navigation Satellite System (BDS), the Quasi-Zenith Satellite System (QZSS), and / or satellite-based augmentation systems (SBAS).
[0108] Electronic device 100 implements display functions through a GPU, a display screen 194, and an application processor. The GPU is a microprocessor for image processing, connected to the display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations and for graphics rendering. Processor 110 may include one or more GPUs, which execute program instructions to generate or modify display information.
[0109] Display screen 194 is used to display images, videos, etc. Display screen 194 includes a display panel. The display panel may be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a miniature LED, a microLED, a quantum dot light-emitting diode (QLED), etc. In some embodiments, electronic device 100 may include one or N displays 194, where N is a positive integer greater than 1.
[0110] Electronic device 100 can perform shooting functions through ISP, camera 193, video codec, GPU, display 194 and application processor.
[0111] The ISP is used to process data fed back from the camera 193. For example, when taking a picture, the shutter is opened, and light is transmitted through the lens to the camera's photosensitive element. The light signal is converted into an electrical signal, and the camera's photosensitive element transmits the electrical signal to the ISP for processing, converting it into an image visible to the naked eye. The ISP can also perform algorithmic optimization on image noise and brightness. The ISP can also optimize parameters such as exposure and color temperature of the shooting scene. In some embodiments, the ISP can be set in the camera 193.
[0112] Camera 193 is used to capture still images or videos. An object is projected onto a photosensitive element by generating an optical image through the lens. The photosensitive element can be a charge-coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the light signal into an electrical signal, which is then passed to an ISP for conversion into a digital image signal. The ISP outputs the digital image signal to a DSP for processing. The DSP converts the digital image signal into image signals in standard RGB, YUV, or other formats. In some embodiments, the electronic device 100 may include one or N cameras 193, where N is a positive integer greater than 1.
[0113] Digital signal processors (DSPs) are used to process digital signals. Besides digital image signals, they can also process other digital signals. For example, when electronic device 100 selects a frequency, the DSP can perform Fourier transforms on the frequency energy.
[0114] An NPU (Neural Processing Unit) is a computational processor for neural networks (NNs). By borrowing the structure of biological neural networks, such as the transmission patterns between neurons in the human brain, it can rapidly process input information and continuously learn on its own. NPUs can enable intelligent cognitive applications in electronic devices, such as image recognition, facial recognition, speech recognition, and text understanding.
[0115] Internal memory 121 may include one or more random access memory (RAM) and one or more non-volatile memory (NVM).
[0116] The random access memory can be directly read and written by the processor 110. It can be used to store executable programs (such as machine instructions) of the operating system or other running programs, as well as user and application data.
[0117] Non-volatile memory can also store executable programs and user and application data, and can be pre-loaded into random access memory for direct reading and writing by the processor 110.
[0118] The external memory interface 120 can be used to connect to external non-volatile memory to expand the storage capacity of the electronic device 100.
[0119] Electronic device 100 can implement audio functions, such as music playback and recording, through audio module 170, speaker 170A, receiver 170B, microphone 170C, headphone jack 170D, and application processor.
[0120] The audio module 170 is used to convert digital audio information into analog audio signals for output, and also to convert analog audio input into digital audio signals. The audio module 170 can also be used for encoding and decoding audio signals. In some embodiments, the audio module 170 may be located in the processor 110, or some functional modules of the audio module 170 may be located in the processor 110.
[0121] The speaker 170A, also known as a "loudspeaker," is used to convert audio electrical signals into sound signals. The electronic device 100 can listen to music or make hands-free calls through the speaker 170A.
[0122] The receiver 170B, also known as the "earpiece," is used to convert audio electrical signals into sound signals. When the electronic device 100 answers a telephone call or voice message, the receiver 170B can be brought close to the ear to listen to the voice.
[0123] Microphone 170C, also known as a "microphone" or "voice transducer," is used to convert sound signals into electrical signals. When making a phone call or sending a voice message, the user can speak by bringing their mouth close to microphone 170C, inputting the sound signal into microphone 170C. Electronic device 100 may have at least one microphone 170C. In some embodiments, electronic device 100 may have two microphones 170C, which, in addition to collecting sound signals, can also perform noise reduction. In other embodiments, electronic device 100 may also have three, four, or more microphones 170C, which can collect sound signals, reduce noise, identify the sound source, and perform directional recording, etc.
[0124] The 170D headphone jack is used to connect wired headphones. The 170D headphone jack can be a USB 130 interface or a 3.5mm Open Mobile Terminal Platform (OMTP) standard interface, a CTIA (Cellular Telecommunications Industry Association of the USA) standard interface.
[0125] Pressure sensor 180A is used to sense pressure signals and convert them into electrical signals. In some embodiments, pressure sensor 180A can be disposed on display screen 194. There are many types of pressure sensors 180A, such as resistive pressure sensors, inductive pressure sensors, and capacitive pressure sensors. In some embodiments, touch operations applied to the same touch location but with different touch intensity can correspond to different operation commands. For example, when a touch operation with an intensity less than a first pressure threshold is applied to the SMS application icon, a command to view an SMS message is executed. When a touch operation with an intensity greater than or equal to the first pressure threshold is applied to the SMS application icon, a command to create a new SMS message is executed.
[0126] The fingerprint sensor 180H is used to collect fingerprints. The electronic device 100 can utilize the characteristics of the collected fingerprints to achieve fingerprint unlocking, accessing application locks, taking photos with fingerprints, answering calls with fingerprints, etc.
[0127] Touch sensor 180K, also known as a "touch device," can be located on display screen 194. The touch sensor 180K and display screen 194 together form a touchscreen, also known as a "touchscreen." Touch sensor 180K detects touch operations applied to or near it. The touch sensor can transmit the detected touch operation to the application processor to determine the type of touch event. Visual output related to the touch operation can be provided through display screen 194. In other embodiments, touch sensor 180K may also be located on the surface of electronic device 100, in a different position than display screen 194.
[0128] Buttons 190 include a power button, volume buttons, etc. Buttons 190 can be mechanical buttons or touch-sensitive buttons. Electronic device 100 can receive button input and generate key signal inputs related to user settings and function control of electronic device 100.
[0129] Motor 191 can generate vibration alerts.
[0130] Indicator 192 can be an indicator light, used to indicate charging status, power changes, or to indicate messages, missed calls, notifications, etc.
[0131] Internal memory 121 is used to store predefined operations that the electronic device can perform in a locked state. Specifically, internal memory 121 can record the resources that the electronic device can access in a locked state, and the specific access operations (e.g., modification, reading, etc.) that can be performed on those resources. In some embodiments of this application: Internal memory 121 can be used to store standard authentication information for one or more users. This authentication information is used to identify users and may include authentication information corresponding to a first authentication method or a second authentication method. For example, this authentication information may include: password, pattern, face, voiceprint, fingerprint, palm print, retina, iris, body odor, face shape, blood pressure, blood oxygen, blood glucose, respiratory rate, heart rate, one-cycle electrocardiogram waveform, deoxyribonucleic acid (DNA), signature, and body posture (such as walking gait).
[0132] The receiver 170B, microphone 170C, display screen 194, camera 193, button 190, sensor module 180 (e.g., pressure sensor 180A, gyroscope sensor 180B), and headphone jack 170D for connecting external headphones, etc., can be used to receive the first operation command input by the user. Detailed information about the first operation command can be found in the description of the subsequent method embodiments.
[0133] The mobile communication module 150 and the wireless communication module 160 can be used to receive first operation commands sent by other devices, and can also be used to receive weak authentication factors sent by other devices.
[0134] Display screen 194, camera 193, fingerprint sensor 180H, receiver 170B, microphone 170C, optical sensor, electrodes, etc., can be used to collect weak authentication factors input by the user. Specifically, display screen 194 can be used to collect user-inputted passwords, patterns, and signatures. Camera 193 is used to collect user-inputted facial features, iris, retina, face shape, body posture, etc. Fingerprint sensor 180H can be used to collect user-inputted fingerprints. Receiver 170B and microphone 170C can be used to collect user-inputted voice. Optical sensor can be used to collect PPG signals (such as blood pressure, blood oxygen, blood glucose, respiratory rate, heart rate, and one-cycle electrocardiogram waveform) using photoplethysmography (PPG) technology. Electrodes configured in electronic device 100 can be used to collect one-cycle electrocardiogram waveforms using electrocardiogram (ECG) technology.
[0135] The processor 110 can analyze the weak authentication factors obtained by the aforementioned modules to determine the security level of the weak authentication factors. The processor is also used to determine the risk level of the operation corresponding to the first operation instruction. Subsequently, the processor 110 is further used to create a restricted execution environment based on the risk level of the operation corresponding to the first operation instruction and the security level of the weak authentication factors, and in this restricted execution environment, respond to the first operation instruction and schedule the various modules of the electronic device 100 to execute the corresponding operations.
[0136] In some embodiments of this application: The mobile communication module 150 and wireless communication module 160 in the electronic device 100 can be used to receive second operation commands sent by other devices.
[0137] The processor 110 can be used to determine the risk level of the operation corresponding to the second operation instruction. Then, the processor 110 is further used to create a restricted execution environment based on the risk level of the operation corresponding to the second operation instruction, and in response to the second operation instruction within the restricted execution environment, schedule the various modules of the electronic device 100 to perform the corresponding operations.
[0138] For details on the functions of each module of the electronic device 100, please refer to the detailed description in the subsequent method embodiments; they will not be repeated here.
[0139] The software system of electronic device 100 can adopt a layered architecture, event-driven architecture, microkernel architecture, microservice architecture, or cloud architecture. This application embodiment uses the layered architecture Android system as an example to exemplify the software structure of electronic device 100.
[0140] Figure 2 This is a software structure block diagram of the electronic device 100 according to an embodiment of this application.
[0141] A layered architecture divides software into several layers, each with a clear role and function. Layers communicate with each other through software interfaces. In some embodiments, the Android system is divided into four layers, from top to bottom: the application layer, the application framework layer, the Android runtime and system libraries, and the kernel layer.
[0142] The application layer can include a series of application packages.
[0143] like Figure 2 As shown, the application package may include applications such as voice assistant, camera, gallery, calendar, call, map, navigation, WLAN, Bluetooth, music, video, and SMS.
[0144] The application framework layer provides application programming interfaces (APIs) and a programming framework for applications in the application layer. The application framework layer includes some predefined functions.
[0145] like Figure 2 As shown, the application framework layer may include a window manager, content provider, view system, phone manager, resource manager, notification manager, etc.
[0146] The window manager is used to manage windowed applications. It can retrieve screen size, determine the presence of a status bar, lock the screen, and capture screenshots, among other things.
[0147] Content providers store and retrieve data, making that data accessible to applications. This data may include videos, images, audio, made and received phone calls, browsing history and bookmarks, phone books, etc.
[0148] A view system includes visual controls, such as controls for displaying text and controls for displaying images. View systems can be used to build applications. A display interface can consist of one or more views. For example, a display interface including a text notification icon could include views for displaying text and views for displaying images.
[0149] The phone manager is used to provide communication functions for electronic device 100. For example, it manages call status (including connection and disconnection).
[0150] The file explorer provides applications with various resources, such as localized strings, icons, images, layout files, video files, and more.
[0151] The notification manager allows applications to display notifications in the status bar. These notifications can be used to deliver informational messages and can disappear automatically after a short pause, requiring no user interaction. For example, the notification manager can be used to notify users of completed downloads or message alerts. The notification manager can also display notifications as icons or scrolling text in the top status bar, such as notifications from background applications, or as dialog boxes on the screen. Examples include displaying text messages in the status bar, emitting sounds, vibrating electronic devices, and flashing indicator lights.
[0152] The Android Runtime consists of core libraries and a virtual machine. The Android runtime is responsible for the scheduling and management of the Android system.
[0153] The core library consists of two parts: one part is the functionalities that need to be called by the Java language, and the other part is the Android core library.
[0154] The application layer and application framework layer run in a virtual machine. The virtual machine executes the Java files of the application layer and application framework layer as binary files. The virtual machine is used to perform functions such as object lifecycle management, stack management, thread management, security and exception management, and garbage collection.
[0155] System libraries can include multiple functional modules. For example: surface manager, media libraries, 3D graphics processing libraries (e.g., OpenGL ES), 2D graphics engines (e.g., SGL), etc.
[0156] The Surface Manager is used to manage the display subsystem and provides the blending of 2D and 3D layers for multiple applications.
[0157] The media library supports playback and recording of various common audio and video formats, as well as still image files. It supports multiple audio and video encoding formats, such as MPEG4, H.264, MP3, AAC, AMR, JPG, and PNG.
[0158] The 3D graphics processing library is used to implement 3D graphics drawing, image rendering, compositing, and layer processing.
[0159] A 2D graphics engine is a graphics engine for 2D drawing.
[0160] The kernel layer is the layer between hardware and software. The kernel layer contains at least the display driver, camera driver, audio driver, and sensor driver.
[0161] The following describes the communication system 10 provided in the embodiments of this application.
[0162] like Figure 3 As shown, the communication system 10 includes electronic device 100, and may also include electronic device 200, or electronic device 300.
[0163] The number of electronic devices 100, 200, or 300 can be one or more.
[0164] The implementation of electronic device 100 and the various operations performed by electronic device 100 can be referred to the above. Figure 1 or Figure 2 The relevant descriptions will not be repeated here.
[0165] This application does not limit the specific type of electronic device 200 or electronic device 300. The type of electronic device 200 or electronic device 300 can be referred to the above description of the type of electronic device 100. For example, electronic device 100 can be a smartphone, and electronic device 200 can be a smartwatch, smart bracelet, earphones, etc. As another example, electronic device 100 can be a smart screen, large-screen TV, laptop computer, etc., and electronic device 300 can be a smartphone.
[0166] Multiple electronic devices in the communication system 10 can be configured with different operating systems (OS), or they can all be configured with the same operating system. Operating systems include, but are not limited to, Harmony®, Android®, iOS®, Windows®, Linux®, Unix®, MacOS®, etc. Among them, Harmony® refers to Huawei's HarmonyOS system.
[0167] Communication connections are established between electronic devices 100 and 200, or between electronic devices 100 and 300. These communication connections may include, but are not limited to: wired connections, wireless connections such as Bluetooth (BT) connections, wireless local area networks (WLANs) such as Wireless Fidelity point-to-point (Wi-Fi P2P) connections, near field communication (NFC) connections, infrared (IR) connections, and remote connections (such as connections established through a server), etc.
[0168] For example, any two electronic devices in communication system 10 can connect by logging into the same account. For instance, two electronic devices can log into the same Huawei account and remotely connect and communicate through a server. Any two electronic devices can also log into different accounts but connect through a binding method. After logging into an account, an electronic device can bind other electronic devices logged into different accounts or not logged into in the device management application. These electronic devices can then communicate with each other through the device management application. Any two electronic devices can also establish a connection by scanning a QR code, using near field communication (NFC) to tap, searching for Bluetooth devices, etc., without limitation. Furthermore, the electronic devices in communication system 10 can also combine any of the above methods to connect and communicate; this embodiment does not impose any limitations on this.
[0169] In some embodiments of this application, electronic device 200 can be used to receive user operations carrying a first operation instruction, and then send the instruction information of the user operation to electronic device 100. For example, when electronic device 200 is an earphone connected to electronic device 100, it can receive voice commands input by the user and then send the voice commands to electronic device 100.
[0170] In other embodiments of this application, electronic device 200 can be used to receive user operations carrying a first operation instruction, then identify the first operation instruction carried by the user operation, and send it to electronic device 100 according to the first operation instruction. For example, when electronic device 200 is a smartwatch connected to electronic device 100, it can receive the user's voice command "use the phone to play music", then identify that the intent of the voice command is to trigger the phone to play music, and then electronic device 200 can send the first operation instruction for requesting electronic device 100 to play music to electronic device 100.
[0171] In some embodiments of this application, electronic device 200 can be used to receive user operations carrying weak authentication factors, and then send the instruction information of the user operation to electronic device 100. For example, when electronic device 200 is an earphone connected to electronic device 100, it can receive voice commands carrying voiceprints input by the user, and then send the voice commands carrying voiceprints to electronic device 100.
[0172] In other embodiments of this application, electronic device 200 can be used to receive user operations carrying weak authentication factors, then identify the weak authentication factors carried by the user operations, and send them to electronic device 100 according to the weak authentication factors. For example, when electronic device 200 is a smartwatch connected to electronic device 100, it can receive voice commands carrying voiceprints input by the user, then identify the voiceprints carried by the voice commands, and then electronic device 200 can send the voiceprint information to electronic device 100.
[0173] In this embodiment, the electronic device 300 can receive user operations, identify the intent of the user operations, generate a second operation instruction based on the intent of the user operations, and then send the second operation instruction to the electronic device 100. For example, when the electronic device 300 is a smartphone and the electronic device 100 is a smart screen, the electronic device 300 can receive user operations for screen mirroring to the smart screen, and then the electronic device 300 can generate a screen mirroring request (i.e., the second operation instruction) and send the screen mirroring request to the smart screen.
[0174] Figure 3 The communication system 10 shown is merely an example. In a specific implementation, the communication system 10 may include more terminal devices, which is not limited here. The communication system 10 may also be referred to as a distributed system or other terms, which are not limited here.
[0175] The function of each device in the communication system 10 can be described in detail in the following method embodiments.
[0176] refer to Figure 4 , Figure 4 This is a flowchart illustrating the access control method based on weak authentication factors provided in an embodiment of this application.
[0177] like Figure 4 As shown, the method may include the following steps: Step S101: When the electronic device 100 is in a locked state, it acquires a first operation instruction and a weak authentication factor.
[0178] In this embodiment, the electronic device 100 can have two states: a locked state and an unlocked state. For specific definitions of the locked and unlocked states, please refer to the preceding descriptions.
[0179] When the electronic device 100 is in a locked state, the display screen can be either on or off; there is no limitation on this. The electronic device 100 may enter a locked state by default if it has not received user operation for an extended period, or it may enter a locked state in response to user operation (such as pressing the power button). For example, refer to... Figure 5A , Figure 5A The user interface 50 displayed when the electronic device 100 is in a locked state is shown.
[0180] The correspondence between the first operation instruction and the operation requested by the electronic device 100 can be preset by the electronic device 100, and is not limited here. In the embodiments of this application, the resource in the electronic device 100 requested by the first operation instruction can be referred to as the first resource. The classification and specific content of the resources in the electronic device 100 can be referred to in the relevant description above. The first resource may include one or more resources, and is not limited here.
[0181] In some embodiments, the first operation instruction is used to request the electronic device 100 to perform an operation other than a predefined operation in the locked state. That is, the first operation instruction is used to request access to a resource in the electronic device 100, and access to that resource is not possible in the locked state. Specifically, the electronic device 100 pre-stores predefined operations that can be performed in the locked state. That is, the electronic device 100 records the resources that can be accessed in the locked state, and the specific access operations (e.g., read, add, delete, write, modify, etc.) that can be performed on those resources. Detailed definitions of the predefined operations can be found in the preceding descriptions.
[0182] In this application embodiment, the form of the first operation instruction is not limited. The first operation instruction may include, but is not limited to, semantics carried by speech, gestures, facial expressions, signatures, body postures, lip movements, button presses, or shaking operations, etc. Among them, gestures, facial expressions, signatures, body postures, and lip movements can be static information at a point in time, such as gestures at a certain point in time, or dynamic information over a period of time, such as changes in lip movements over a period of time, etc.
[0183] Electronic device 100 can obtain the first operation command in the following ways: 1. Electronic device 100 directly receives a user operation carrying a first operation instruction, and extracts the first operation instruction from the user operation. In the locked state, the electronic device 100 can periodically, or under certain triggering conditions, begin receiving user input and extracting a first operation command from it. These triggering conditions can be varied, such as activating a voice assistant, detecting a wrist raise, or detecting a tap on the display screen. Here, the electronic device 100 can continuously run a wake-word recognition program with low power consumption, activating the voice assistant upon detecting a wake-word. By starting to receive user input and extract the first operation command under the detected triggering conditions, the power consumption of the electronic device 100 can be reduced.
[0184] User operations carrying the first operation instruction can take many forms. For example, they may include speech carrying semantics, one or more images containing gestures / facial expressions / body postures / lip movements, swipe operations containing signatures, button press operations, shaking the electronic device 100, and so on.
[0185] The electronic device 100 can use corresponding modules to receive user operations carrying the first operation command. For example, it can receive speech carrying semantics through the receiver 170B and microphone 170C, receive swipe operations including signatures and gestures through the display screen 194, receive images including gestures / facial expressions / body postures / lip movements through the camera 193, receive button press operations through the button 190, receive shaking operations through the gyroscope sensor 180B, and so on.
[0186] Subsequently, the electronic device 100 can identify or extract the first operation instruction from the received user operation. For example, the electronic device 100 can extract semantics from speech, extract gestures / facial expressions / body postures / lip movements from one or more images, extract signatures or gestures from swipe operations, and so on.
[0187] Electronic device 100 can identify the first operation instruction contained in the user's operation locally or via a network. For example, electronic device 100 can identify semantics in speech and gestures / facial expressions / body postures in images locally via processor 110, or it can upload speech or images to the network and identify semantics in speech and gestures / facial expressions / body postures / lip movements in images via a network server or other devices.
[0188] Voice carries semantics, and different voices can carry different semantics. Users can input different commands by inputting different voices. For example, the voice command "Navigate home" can be used to request an electronic device to launch a navigation app and navigate to the user's home location; the voice command "Open photo album" can be used to request an electronic device to launch a photo gallery app.
[0189] When the first operation command received by the electronic device 100 is voice, the electronic device 100 needs to activate the voice assistant first. The voice assistant is an application installed in the electronic device to support users in controlling the electronic device via voice commands. Normally, the voice assistant is in a dormant state; the user can wake up or activate the voice assistant before using it. Only after the voice assistant is activated can the electronic device receive and recognize the user's voice commands. The voice used to wake up the voice assistant can be called a wake word, such as the voice command "Xiao E Xiao E". In some other embodiments, the voice assistant in the electronic device 100 can remain in a wake-up state for an extended period without needing to be activated by a wake word. "Voice assistant" is just one term used in this application; it can also be called a smart assistant or other terms, which are not limited here.
[0190] Gestures can be physical gestures, such as swiping or tapping on a screen. They can also be non-contact gestures, such as opening a palm or clenching a fist above the screen. Non-contact gestures are also called hovering gestures, air gestures, or remote gestures. Users can input different commands using different gestures. For example, an open palm gesture above the screen can be used to request the device to launch a navigation app and navigate to home; a clenched fist gesture can be used to request the device to launch a gallery app.
[0191] Facial expressions can include, for example, blinking, opening the mouth, etc. Users can input different operation commands by inputting different facial expressions.
[0192] Body gestures can include, for example, nodding, shaking the head, swinging the arm, squatting, etc. Users can input different operation commands by inputting different body gestures. For example, a nodding gesture can be used to request an electronic device to play music; a shaking gesture can be used to request an electronic device to pause music playback.
[0193] There are multiple ways to press buttons or shake an electronic device, allowing users to input different commands. For example, double-clicking the power button can be used to request the device to play music, while shaking the device twice can be used to request it to pause music playback.
[0194] Different lip movements can be used to indicate different operations. For example, lip movements corresponding to the voice command "play music" over a period of time can be used to request an electronic device to play music. Using lip movements to input the first operation command makes it easier for users to control electronic devices through lip reading, enriching the usage scenarios and scope of electronic devices.
[0195] The first operation instruction is not limited to the above-mentioned user operations. It can also be implemented in other forms, such as the sound of snapping fingers, etc. There are no restrictions here.
[0196] 2. Other devices send user operation instruction information to electronic device 100, and electronic device 100 extracts the first operation command from the user operation instruction information. Electronic device 100 can establish a communication connection with other devices, such as electronic device 200. The method by which electronic device 100 establishes a communication connection with other electronic devices can be found in [reference needed]. Figure 3 Related descriptions.
[0197] The user operation received by other devices carries a first operation instruction. The timing and method of other devices receiving the user operation carrying the first operation instruction are the same as those of electronic device 100 receiving the user operation carrying the first operation instruction in the first method described above, and can be referred to the relevant description.
[0198] The user operation instructions sent by other devices can be the user operation itself or other instructions related to the user operation. For example, when electronic device 200 is an earphone connected to electronic device 100, it can receive semantically meaningful voice input from the user and then send the voice input to electronic device 100. As another example, when electronic device 200 is a camera connected to electronic device 100, it can capture images containing gestures, facial expressions, and body postures input by the user and then send the images to electronic device 100. As yet another example, when electronic device 200 is a smart bracelet connected to electronic device 100, it can receive a press operation on the power button and then send the instruction information for that press operation to electronic device 100.
[0199] The way in which the electronic device 100 extracts the first operation instruction from the indication information of the user operation is the same as the way in which the electronic device 100 extracts the first operation instruction from the received user operation in the first form described above, and can be referred to the relevant description.
[0200] In the second case described above, other devices, such as electronic device 200, can be regarded as peripherals or accessories of electronic device 100.
[0201] In the second method described above, electronic device 200 can either select electronic device 100 by default or send user operation instructions to electronic device 100 based on the user's selection of electronic device 100. The method by which the user selects electronic device 100 is not limited; for example, it can be done through voice or selection on the user interface. For instance, if electronic device 200 is a headset, it can send the received voice message to the connected electronic device 100 by default. Or, for example, if electronic device 200 detects the voice command "Play music using the mobile phone," it will send that voice message to the mobile phone (i.e., electronic device 100) mentioned in the voice command.
[0202] 3. Other devices receive a user operation carrying a first operation instruction, extract the first operation instruction from the user operation, and then send the first operation instruction to electronic device 100. Electronic device 100 can establish a communication connection with other devices, such as electronic device 200. The method by which electronic device 100 establishes a communication connection with other electronic devices can be found in [reference needed]. Figure 3 Related descriptions.
[0203] Other devices, such as electronic device 200, can first receive a user operation carrying a first operation instruction, identify the first operation instruction contained in the user operation, and then send the first operation instruction to electronic device 100. Here, the other device receiving the user operation carrying the first operation instruction is similar to the electronic device 100 receiving the user operation carrying the first operation instruction in the first form described above, and can be referred to the relevant description. The method by which the other device identifies the first operation instruction contained in the received user operation is the same as the method by which the electronic device 100 identifies the first operation instruction contained in the user operation in the first form described above, and can be referred to the relevant description.
[0204] For example, electronic device 200 can receive voice input from a user, then recognize the semantics of the voice, and then send the semantic information to electronic device 100. As another example, electronic device 200 can capture an image containing gestures / facial expressions / body postures input by a user, recognize the gestures / facial expressions / body postures in the image, and then send the gesture / facial expression / body posture information to electronic device 100.
[0205] In the third method described above, electronic device 200 can select electronic device 100 by default, or send a first operation command to electronic device 100 based on the electronic device 100 selected by the user.
[0206] Weak authentication factors refer to authentication information that fails to meet the requirements for unlocking electronic devices. This authentication information may include passwords, patterns, and biometrics. For a detailed introduction to authentication information, please refer to the relevant descriptions above.
[0207] In this embodiment of the application, the authentication information that fails to meet the requirements for unlocking the electronic device, i.e., the weak authentication factor, may include the following two types: 1. Identity authentication information that is below the standard required for the first authentication method.
[0208] The primary authentication method is the one with a higher ACL (Access Controller List). The ACL determination method can be found in the previous descriptions. The primary authentication method can be pre-set by the electronic device or its manufacturer, as described in the previous sections. For example, the primary authentication method may include password authentication, image authentication, fingerprint authentication, and facial recognition, etc.
[0209] Electronic devices can pre-store user authentication information for subsequent unlocking using the corresponding primary authentication method. For example, if the primary authentication method includes password authentication, the electronic device can pre-store one or more passwords. If the primary authentication method includes image authentication, the electronic device can pre-store one or more images. If the primary authentication method includes biometric authentication, the electronic device can pre-store one or more biometric features, such as fingerprints, faces, etc.
[0210] The authentication information that meets the standards required for the first authentication method may include, for example, a password or pattern pre-stored on the electronic device, or a biometric feature that matches a pre-stored biometric feature (such as a fingerprint or face) with a matching degree reaching a first value. Upon receiving authentication information that meets the standards required for its first authentication method, the electronic device can switch from a locked state to an unlocked state. The first value can be preset.
[0211] Identity authentication information that falls below the standard required by the first authentication method may include, for example, biometric features that match a pre-stored biometric feature with a lower than a first value, or passwords or patterns that have a certain similarity to passwords or patterns pre-stored in the electronic device.
[0212] Compared to the authentication information required by the first authentication method, users can input authentication information that meets lower standards without cumbersome operations or multiple steps. For example, users can input a shape similar to a preset image, face the electronic device's camera from a distance without remaining still, press a wet finger on the fingerprint sensor, or simply point their finger at the camera. Clearly, this reduces the requirements for users to input authentication information, making it simpler, more convenient, and more comfortable for them to use electronic devices.
[0213] 2. Identity authentication information that meets the standards required for the second authentication method.
[0214] The second authentication method is a lower-level authentication method based on ACL (Access Controller Status). The ACL determination method can be found in the previous descriptions. The second authentication method can be pre-set by the electronic device or its manufacturer, as described in the previous sections. For example, the second authentication method may include voiceprint authentication, heart rate authentication, body posture authentication, etc.
[0215] Identity authentication information that meets the standards required for the second authentication method may include, for example, biometric features that match a second value pre-stored in the electronic device's biometric features (such as voiceprints, body postures, etc.). The second value can be preset.
[0216] By using identity authentication information that meets the standards required for the second authentication method, users can control electronic devices in a more convenient way. For example, users can control electronic devices through voice commands or body gestures, allowing them to operate electronic devices without touching them in scenarios such as driving, cooking, and exercising, bringing great convenience.
[0217] In this embodiment of the application, the electronic device 100 may receive one or more weak authentication factors, and this is not limited. That is, the electronic device 100 may receive multiple different weak authentication factors.
[0218] Similar to the first operation instruction, the electronic device in this application embodiment can obtain the weak authentication factor in the following ways: 1. Electronic device 100 directly receives user operations carrying weak authentication factors and extracts the weak authentication factors from the user operations. In the locked state, the electronic device 100 can periodically, or under certain triggering conditions, begin receiving user input and extracting weak authentication factors from it. These triggering conditions can be varied, such as activating a voice assistant, detecting a wrist raise, or detecting a tap on the display screen. By starting to collect weak authentication factors upon detecting the triggering conditions, the power consumption of the electronic device 100 can be reduced.
[0219] Here, user actions carrying weak authentication factors can be of various types, such as user actions indicating passwords (e.g., click actions), user actions indicating graphics (e.g., swipe actions), images or swipe actions carrying biometric features, etc.
[0220] Electronic device 100 can schedule corresponding modules to receive these user operations carrying weak authentication factors. For example, electronic device 100 can receive user operations indicating passwords (e.g., click operations) and user operations indicating graphics (e.g., swipe operations) through display screen 194, capture images containing biometric features (e.g., face, iris, retina, face shape, body posture) through camera 193, capture user-inputted fingerprints through fingerprint sensor 180H, capture user-inputted voice carrying voiceprints through receiver 170B and microphone 170C, and capture heart rate, etc., through optical sensors.
[0221] Then, the electronic device 100 can identify weak authentication factors contained in the received user operations. For example, it can extract voiceprints from speech, passwords from click operations, graphics or signatures from swipe operations, and faces, irises, retina, facial shapes, body postures, or fingerprints from images, etc. Electronic device 100 can identify weak authentication factors in user operations locally or via a network. For example, electronic device 100 can locally identify voiceprints in speech, body postures or facial features in images through processor 110, directly identify button presses, or identify fingerprints through fingerprint sensor 180H. Alternatively, it can upload voice or images to the network and use a network server or other devices to identify voiceprints in speech or body postures or facial features in images.
[0222] 2. Other devices send user operation instructions to electronic device 100, and electronic device 100 extracts weak authentication factors from the user operation instructions. Electronic device 100 can establish a communication connection with other devices, such as electronic device 200. The method by which electronic device 100 establishes a communication connection with other electronic devices can be found in [reference needed]. Figure 3 Related descriptions.
[0223] The user operation received by other devices carries a weak authentication factor. The timing and method by which other devices receive the user operation carrying the weak authentication factor are the same as those of electronic device 100 in the first method described above, and can be referred to the relevant description.
[0224] The user operation instructions sent by other devices can be the user operation itself or other instructions related to the user operation. For example, other devices can collect user operations indicating passwords (such as click operations), user operations indicating graphics (such as swipe operations), images carrying biometric features, or swipe operations, and then send the instructions for these click or swipe operations, or the images, to electronic device 100, which will then identify the weak authentication factors.
[0225] The method by which electronic device 100 extracts weak authentication factors from the instruction information of the user operation is the same as the method by which electronic device 100 extracts weak authentication factors from the received user operation in the first form described above, and can be referred to the relevant description.
[0226] In the second case described above, other devices, such as electronic device 200, can be regarded as peripherals or accessories of electronic device 100.
[0227] In the second method described above, electronic device 200 can select electronic device 100 by default, or it can send user operation instructions to electronic device 100 based on the electronic device 100 selected by the user.
[0228] 3. When other devices receive a user operation carrying a weak authentication factor, they extract the weak authentication factor from the user operation and then send the weak authentication factor to electronic device 100. Electronic device 100 can establish a communication connection with other devices, such as electronic device 200. The method by which electronic device 100 establishes a communication connection with other electronic devices can be found in [reference needed]. Figure 3 Related descriptions.
[0229] Other devices, such as electronic device 200, can first receive a user operation carrying a weak authentication factor, identify the weak authentication factor contained in the user operation, and then send the weak authentication factor to electronic device 100. Here, the other device receiving the user operation carrying the weak authentication factor is similar to the electronic device 100 receiving the user operation carrying the weak authentication factor in the first form described above, and can be referred to the relevant description. The method by which the other device identifies the weak authentication factor contained in the received user operation is the same as the method by which the electronic device 100 identifies the weak authentication factor contained in the user operation in the first form described above, and can be referred to the relevant description.
[0230] For example, electronic device 200 can receive voice input from a user, then identify the voiceprint of the voice, and then send the voiceprint information to electronic device 100. As another example, electronic device 200 can acquire an image containing biometric features (such as face, fingerprint, palm print, retina, iris, body posture, and face shape) input by a user, identify the biometric features contained in the image, and then send the biometric information to electronic device 100.
[0231] In the third method described above, electronic device 200 can select electronic device 100 by default, or it can send a weak authentication factor to electronic device 100 based on the electronic device 100 selected by the user.
[0232] In some embodiments of this application, the electronic device 100 may receive a first operation command and a weak authentication factor, respectively. For example, the electronic device 100 may first acquire the voice command "play music" through a microphone, and then acquire a facial image through a camera.
[0233] In some embodiments of this application, the electronic device 100 can simultaneously receive a first operation instruction and a weak authentication factor. This simplifies user operation and improves the user experience.
[0234] Figures 5B-5D The scenarios shown are a first operation command received simultaneously by electronic device 100, and a weak authentication factor. Figures 5B-5D In this case, all electronic devices 100 are locked.
[0235] For example, refer to Figure 5B , Figure 5B An example is illustrated where an electronic device 100 (e.g., a mobile phone) simultaneously receives a first instruction and a weak authentication factor. Figure 5B As shown, the electronic device 100 can acquire the voice command "navigate home" via a microphone. This voice command also carries a voiceprint, and the electronic device 100 can also recognize the corresponding semantics through this voice command. The first resources accessed by this semantic request include navigation applications and the address of "home".
[0236] For example, refer to Figure 5C , Figure 5C This example illustrates another scenario where an electronic device 100 (e.g., a mobile phone) simultaneously receives a first instruction and a weak authentication factor. For example... Figure 5C As shown, the electronic device 100 can capture images including an open palm gesture via a camera. The electronic device 100 can recognize the open palm gesture in the gesture image and can also recognize the characteristics of the palm (such as fingerprints, knuckle size, etc.). The open palm gesture can be used to request the electronic device 100 to "navigate home," and the first resources requested to access include navigation applications and the address of "home."
[0237] For example, refer to Figure 5D , Figure 5D This example illustrates another scenario where an electronic device 100 (e.g., a smart bracelet) simultaneously receives a first instruction and a weak authentication factor. For example... Figure 5D As shown, electronic device 200 can capture the voice command "play music on mobile phone" through a microphone. This voice command also carries a voiceprint. Electronic device 200 can recognize the voiceprint corresponding to the voice command, and can also recognize the semantics corresponding to the voice command. Then, it sends the semantic information and voiceprint information to electronic device 100 simultaneously. Here, the first resource accessed by the semantic request includes music applications.
[0238] Not limited to Figures 5B-5D In the scenarios shown, the electronic device 100 may also receive other forms of first operation instructions and weak authentication factors in specific implementations. Please refer to the relevant descriptions above, which will not be listed here.
[0239] In step S102, the electronic device 100 creates a restricted execution environment according to the first operation instruction and the weak authentication factor.
[0240] A restricted execution environment refers to a limited execution environment. An execution environment can include both hardware and software environments. It can be a sandbox or a function domain containing multiple functions. In a restricted execution environment, an electronic device can only execute a specified subset of operations and cannot perform any other operations besides those specified operations. In other words, in a restricted execution environment, an electronic device can only access a portion of its resources and cannot access other resources beyond those specified resources.
[0241] This application embodiment does not limit the strategy by which the electronic device 100 creates a restricted execution environment based on the first operation instruction and the weak authentication factor. For example, the electronic device 100 can create a restricted execution environment based on the type of the first operation instruction, the environment in which the weak authentication factor is collected, etc. For example, when the first operation instruction is respectively semantics carried by voice, gesture, facial expression, signature, and body posture, the number of operations that can be executed in the restricted execution environments created by the electronic device 100 decreases sequentially.
[0242] In some embodiments of this application, the electronic device 100 can create a restricted execution environment based on the risk level of the operation corresponding to the first operation instruction and / or the security level of the weak authentication factor. Step S102 may specifically include the following steps S1021-S1024.
[0243] When electronic device 100 receives multiple authentication factors, these factors can be received sequentially. For example, a user can input five voice messages, and electronic device 100 can extract a voiceprint from each message as a weak authentication factor.
[0244] In step S1021, the electronic device 100 determines the risk level of the operation corresponding to the first operation instruction.
[0245] First, the electronic device 100 can determine the operation corresponding to the first operation instruction.
[0246] The correspondence between the first operation instruction and the operation requested by the electronic device 100 can be preset by the electronic device 100, and is not limited here.
[0247] Specifically, different first operation commands (including semantics, gestures, facial expressions, body postures, etc.) can be pre-set to correspond to different operations. For example, the semantic "navigate home," or a gesture of opening one's palm above the screen, corresponds to launching a navigation application and navigating to home; the semantic "play music on phone," corresponds to launching a music application; the semantic "open photo album," or a gesture of clenching one's fist above the screen, corresponds to launching a photo library application; a nodding body posture corresponds to playing music; and a shaking body posture corresponds to pausing music playback. These pre-set correspondences between different semantics, gestures, facial expressions, body postures, and operations can be stored in the electronic device 100 or in a network server; no limitation is made here.
[0248] The electronic device 100 locates the operation corresponding to the first operation instruction in the local area or network according to the pre-set information.
[0249] The operation corresponding to the first operation instruction includes an access operation performed on a specific resource, which can be one or more resources in an electronic device. This access operation may include one or more of the following: reading, adding, deleting, writing, modifying, and executing. The specific details of the resource and the access operation are described in the preceding text. Resources in an electronic device may include software resources, hardware resources, peripherals or peripheral resources, etc., as described in the preceding text.
[0250] Then, the electronic device 100 can first determine the risk level of the operation corresponding to the first operation instruction.
[0251] In this embodiment of the application, the electronic device 100 may pre-store the risk levels corresponding to performing different operations.
[0252] This application embodiment can classify the various operations that the electronic device 100 can perform into different risk levels according to different granularities. This application does not limit the granularity. For example, the risk level of the operation can be roughly divided into three levels: high, medium, and low. Alternatively, the risk level of the operation can be divided into 1-10 levels, with higher values indicating higher risk levels.
[0253] In this embodiment, the higher the risk of privacy leakage to the user when the electronic device 100 performs an operation, the higher the risk level of the operation. The higher the privacy level of the resource accessed by an operation, the more severe the risk of privacy leakage to the user when performing the operation, and the higher the risk level of the operation. For example, the risk level of viewing photos, viewing shopping records, and viewing browsing history in a browser can decrease sequentially. The higher the privacy level of the access operation requested by an operation, the higher the risk level of the corresponding operation. For example, the risk level of reading photos, deleting photos, and adding photos can decrease sequentially.
[0254] In some embodiments of this application, the electronic device 100 can autonomously set risk levels corresponding to different operations. For example, the electronic device 100 can set risk levels for different operations by considering factors such as the type and location of the resources requested for access. For example, the risk level of an operation requesting access to third-party resources is higher than the risk level of an operation requesting access to system resources; the risk level of an operation performed at home is lower than the risk level of an operation performed elsewhere.
[0255] In other embodiments of this application, the electronic device 100 can also set risk levels corresponding to different operations according to user needs. Specifically, the electronic device 100 can determine or set the risk levels of various operations that the electronic device 100 can perform in response to received user operations. For example, the electronic device 100 provides a user interface in the settings application for users to set the risk levels of various operations.
[0256] In other embodiments of this application, the risk level of the operation corresponding to the first operation instruction can also be determined based on the method of obtaining the first operation instruction. For example, when electronic device 100 obtains the first operation instruction through the first to third methods described above, the security level of the obtained first operation instruction decreases sequentially. That is, the security level of the first operation instruction obtained by electronic device 100 through the first method is higher than that of the first operation instruction obtained through the second or third method. As another example, when electronic device 100 receives a first operation instruction sent by electronic device 200, the risk level of the operation corresponding to the first operation instruction can be determined based on electronic device 200. For example, if the historical communication frequency between electronic device 200 and electronic device 100 is higher, the risk level of the operation corresponding to the first operation instruction is lower.
[0257] In step S1022, electronic device 100 determines the security level of the weak authentication factor.
[0258] This application's embodiments can classify weak authentication factors into different security levels according to different granularities. This application does not limit the granularity. For example, the security levels of weak authentication factors can be roughly divided into three levels: high, medium, and low. Alternatively, the security levels of weak authentication factors can be divided into 1-10 levels, with higher values indicating higher security levels.
[0259] In this embodiment, the security level of a weak authentication factor can be determined based on the ACL of the authentication method to which the weak authentication factor belongs. The higher the ACL of the authentication method to which the weak authentication factor belongs, the higher the security level of the weak authentication factor.
[0260] In other embodiments of this application, the security level of the weak authentication factor may also be determined based on one or more of the following: the degree of matching between the weak authentication factor and the pre-stored identity authentication information, the environmental information when the weak authentication factor is received, the acquisition method of the weak authentication factor, or the intensity of the corresponding voice when the weak authentication factor is a voiceprint.
[0261] The higher the match between the weak authentication factor and the pre-stored identity authentication information, or the quieter the environment when receiving the weak authentication factor, or the stronger the intensity of the corresponding voice when the weak authentication factor is a voiceprint, the higher the security level of the weak authentication factor.
[0262] When electronic device 100 obtains weak authentication factors through the first to third methods described above, the security level of its weak authentication factors decreases sequentially. That is, the security level of the weak authentication factor obtained by electronic device 100 through the first method is higher than that obtained through the second or third method.
[0263] After executing S1022, the electronic device 100 can record the authentication method to which the weak authentication factor belongs, the security level of the weak authentication factor, and the authentication validity period of the weak authentication factor. The authentication validity period of the weak authentication factor can be preset by the electronic device, for example, it can be set to a fixed value, such as expiring after the restricted execution environment is created.
[0264] The order of S1021 and S1022 is not limited in the embodiments of this application.
[0265] In optional step S1023, the electronic device 100 determines whether to allow the execution of the operation corresponding to the first operation instruction based on the risk level of the operation corresponding to the first operation instruction and the security level of the weak authentication factor.
[0266] Specifically, the electronic device 100 is pre-set with different risk levels and security levels of authentication factors, allowing the electronic device 100 to perform various operations. This setting can be pre-configured by the user or the manufacturer of the electronic device 100. This application embodiment does not limit the correspondence between the risk level of the operation, the security level of the authentication factor, and the operations allowed to be performed by the electronic device 100.
[0267] For example, if the risk level of the operation corresponding to the first operation instruction is high and the security level of the weak authentication factor is low, the operation corresponding to the first operation instruction shall not be allowed to be executed. Conversely, if the risk level of the operation corresponding to the first operation instruction is low and the security level of the weak authentication factor is high, the operation corresponding to the first operation instruction shall be allowed to be executed.
[0268] In some embodiments, the electronic device 100 can match the risk level of the operation corresponding to the first operation instruction with the security level of the weak authentication factor to determine whether to allow the execution of the operation corresponding to the first operation instruction. Specifically, the electronic device 100 can pre-set the security level of the weak authentication factor for each operation. The higher the risk level of the operation, the higher the security level of the weak authentication factor required to execute the operation.
[0269] If the result of S1023 is yes, then the electronic device 100 continues to execute the subsequent steps.
[0270] If the result of S1023 is negative, the electronic device 100 will not continue to execute subsequent steps.
[0271] In some embodiments, if the execution result of S1023 is negative, the electronic device 100 may also output a prompt message, which may be used to prompt the user that the operation corresponding to the first operation instruction is not allowed to be performed at present.
[0272] In some embodiments, the prompt message may further inform the user of the reason why the operation corresponding to the first operation instruction is not allowed to be performed at present, such as the risk level of the operation corresponding to the first operation instruction being high, or the security level of the weak authentication factor being low.
[0273] In some embodiments, the prompt message may further suggest solutions to the user. For example, it may prompt the user to enter a weaker authentication factor with a higher security level, or prompt the user to unlock the device, etc., without limitation.
[0274] The implementation of this prompt message is the same as that of the prompt message in subsequent step S105. For details, please refer to the relevant descriptions in subsequent steps.
[0275] In step S1024, the electronic device 100 creates a restricted execution environment based on the risk level of the operation corresponding to the first operation instruction and the security level of the weak authentication factor.
[0276] In some embodiments, the electronic device 100 may execute S1024 after receiving a predetermined value of a weak authentication factor. That is, the electronic device 100 may utilize multiple weak authentication factors to create a restricted execution environment.
[0277] The lower the risk level of the operation corresponding to the first operation instruction, or the higher the security level of the weak authentication factor, the more operations are allowed to be performed by the electronic device 100. Here, the operations allowed to be performed by the electronic device 100 are those that can be performed in the restricted execution environment created by the electronic device 100.
[0278] The electronic device 100 has pre-set permissions for various operations under different risk levels and authentication factor security levels. These permissions can be set by the user or the manufacturer of the electronic device 100. This application embodiment does not limit the correspondence between the risk level of the operation, the security level of the authentication factor, and the operations allowed to be performed by the electronic device 100. When the electronic device receives the same first operation instruction but with different weak authentication factors, it can create different restricted execution environments. Conversely, when the electronic device receives different first operation instructions but with the same weak authentication factor, it can also create different restricted execution environments.
[0279] In some embodiments, regardless of the risk level of the operation corresponding to the first operation instruction or the security level of the weak authentication factor, the predetermined operation in the locked state can be executed in the restricted execution environment created by the electronic device 100.
[0280] For example, referring to Table 1, the various operations that the electronic device 100 is allowed to perform under different risk levels and different security levels of authentication factors are illustrated. The risk level of the operation and the security level of the different authentication factors are both divided into 1-5 levels, with higher values indicating higher risk levels and higher security levels for weaker authentication factors.
[0281]
[0282] Table 1 When creating a restricted execution environment, electronic device 100 can record the operations permitted to be performed by electronic device 100, determined based on the risk level of the operation and the security level of different authentication factors. In other words, electronic device 100 records which specific access operations are permitted to be performed on which resources or types of resources.
[0283] In some embodiments, if the electronic device 100 has already created a restricted execution environment, the electronic device 100 can change the current restricted execution environment according to the risk level of the operation and the security level of different authentication factors, changing it to the restricted execution environment described above. Specifically, the electronic device 100 can change the recorded information, thereby changing the current restricted execution environment, as detailed in the preceding description.
[0284] In some embodiments, the electronic device 100 may also consider the number of weak authentication factors obtained in S101 to create a restricted execution environment. For example, the more weak authentication factors obtained in S101, the more operations are allowed to be executed in the created restricted execution environment.
[0285] In some embodiments, if the electronic device 100 executes S1023, the restricted execution environment created in S1024 necessarily allows the execution of the operation corresponding to the first operation instruction. This creates an effective restricted execution environment and reduces resource waste in the electronic device 100.
[0286] In some embodiments, the electronic device 100 may skip S1023 and directly execute S1024. In this case, the restricted execution environment created in step S1024 may not necessarily allow the operation corresponding to the first operation instruction to be executed.
[0287] S103, the electronic device 100 responds to the first operation instruction and executes the operation corresponding to the first operation instruction in the created restricted execution environment.
[0288] In some embodiments, if the electronic device does not execute S1023, then before S103, the electronic device 100 also needs to determine whether the created restricted execution environment allows the operation corresponding to the first operation to be executed. If the determination result is yes, then S103 is executed. If the determination result is no, then the electronic device 100 may stop executing any step, or the electronic device 100 may try to respond to the first operation instruction and execute other operations that are close to the operation corresponding to the first operation instruction in the restricted execution environment.
[0289] The operation corresponding to the first operation instruction can be referred to in the detailed description of S101 and S1021.
[0290] Figures 5E-5F An example is shown of the user interface displayed when the electronic device 100 performs S103.
[0291] refer to Figure 5E , Figure 5E For electronic device 100 to receive Figure 5BThe voice command "Navigate to home" and the user interface 53 displayed after receiving a weak authentication factor (i.e., the voiceprint carried in the voice command). Figure 5E As shown, the restricted execution environment created by the electronic device 100 based on the voice command and weak authentication factor allows navigation applications to be launched and allows the reading of user data from navigation applications, such as reading the detailed address of the user's "home" as "XX Building". Therefore, Figure 5E In the navigation interface provided, the electronic device 100 automatically fills in the detailed address of "home" at the destination.
[0292] refer to Figure 5F , Figure 5F It can also be used to receive electronic devices 100 Figure 5C The image includes an image of an open palm gesture, and the user interface displayed after receiving a weak authentication factor (i.e., the characteristics of the palm, such as fingerprints, knuckle size, etc.). The open palm gesture and the voice command "navigate home" are the same, both used to request the electronic device 100 to navigate to the location of "home". However, due to... Figure 5C The security level of the weak authentication factor received by the electronic device 100 is lower than that of the electronic device 100. Figure 5B The electronic device 100 receives a weak authentication factor indicating a security level. Therefore, based on the open palm gesture and the weak authentication factor, the electronic device 100 creates a restricted execution environment that allows navigation applications to be launched but does not allow the reading of user data from navigation applications. Figure 5F As shown, because the electronic device 100 cannot read the detailed address of "home", the address is not filled in at the destination. The user can manually enter the address of "home" at the destination to navigate to home.
[0293] In optional step S104, the electronic device 100 receives the user's operation.
[0294] This application embodiment does not limit the form of the user operation received by the electronic device 100 in S104. For example, it can be voice carrying semantics, images containing gestures / facial expressions / body postures, swipe operations containing signatures, button press operations, shaking operations of the electronic device 100, etc. The way in which the electronic device 100 receives the user operation in S104 is the same as the first way in which the electronic device 100 receives the user operation carrying the first operation instruction in S101, and can be referred to the relevant description.
[0295] In optional step S105, if the created restricted execution environment allows the operation requested by the user to be performed by the electronic device 100, the electronic device 100 responds to the user operation; if the operation requested by the user to be performed by the electronic device 100 is not allowed, a prompt message is output to inform the user that the operation corresponding to the user operation is currently not allowed.
[0296] Here, the electronic device 100 determines the operation that the user operation requests the electronic device 100 to perform, which is the same as the operation corresponding to the first operation instruction determined by the electronic device 100 in S1021, as can be referred to in the relevant description.
[0297] In this embodiment of the application, the resource requested for access by the user operation in S104 can be referred to as the second resource. The second resource may include one or more resources, and is not limited here.
[0298] Specifically, if the execution environment restricts the execution of the operation corresponding to the user operation in S104, the electronic device 100 will respond to the user operation and execute the operation requested by the user.
[0299] For example, if the user operation in S104 is to request the electronic device 100 to launch the camera application, and the restricted execution environment allows the electronic device 100 to launch the camera application, then the electronic device 100 can launch the camera application.
[0300] For example, such as Figure 5F As shown, after the electronic device 100 detects a user operation (e.g., a click operation) on the control 501 in the user interface 53, if the restricted execution environment allows the microphone to be invoked, the electronic device 100 can activate the microphone to capture the user's voice input.
[0301] If the execution environment restricts the execution of the operation corresponding to the user's operation, the electronic device 100 will not respond to the user's operation and will output a prompt message.
[0302] For example, if the user operation in S104 (e.g., a swipe up from the bottom of the display screen) is used to request the electronic device 100 to display the desktop, and the restricted execution environment does not allow the electronic device 100 to display the desktop, then the electronic device 100 may output a prompt message.
[0303] In some embodiments, the prompt information output by the electronic device 100 may further inform the user of the reason why the operation corresponding to the user operation is not allowed to be performed at present. For example, it may include that the risk level of the user operation is high, or that the security level of the weak authentication factor currently received by the electronic device 100 is low.
[0304] In some embodiments, the prompts output by the electronic device 100 may further suggest solutions to the user. For example, prompting the user to enter a weaker authentication factor with a higher security level, or prompting the user to unlock, etc., without limitation.
[0305] The notification message can be implemented in the form of visual elements, vibration signals, flashlight signals, audio, etc., and there are no restrictions here.
[0306] For example, refer to Figure 5G , Figure 5G An example is shown of a prompt message 502 output by an electronic device 100.
[0307] By using S105, the operations that electronic device 100 can perform can be limited to the scope of the restricted execution environment, which can prevent the expansion of permissions and protect the data security of electronic device 100.
[0308] In optional step S106, the electronic device 100 obtains a strong authentication factor and switches from a locked state to an unlocked state.
[0309] Specifically, strong authentication factors include identity authentication information that meets the standards required for the first authentication method. For a detailed description of the identity authentication information required for the first authentication method, please refer to section S101; it will not be repeated here.
[0310] In some embodiments, strong authentication factors may also include multiple weak authentication factors acquired over a period of time. The specific number of these multiple weak authentication factors can be preset and is not limited here. These multiple weak authentication factors can be the same authentication information or different authentication information. That is, a user can complete authentication by inputting weak authentication factors multiple times. For example, a user can continuously input multiple voice sentences, so that the electronic device 100 can extract multiple voiceprints (i.e., weak authentication factors) and then unlock the device. As another example, the electronic device 100 can simultaneously extract a voiceprint and a distant face, and then unlock the device.
[0311] The method by which electronic device 100 obtains a strong authentication factor can be referred to in S101 for the method by which electronic device 100 obtains a weak authentication factor, and will not be repeated here.
[0312] In some embodiments, the electronic device 100 may automatically begin detecting the strong authentication factor input by the user after outputting a prompt message in S105. After seeing the prompt message output by the electronic device 100, the user may input the strong authentication factor.
[0313] In other embodiments, the electronic device 100 may, at any point after executing S103, begin detecting a strong authentication factor input by the user in response to a received user operation. The user may input the strong authentication factor after performing the user operation. This application embodiment does not limit the form of the user operation.
[0314] For example, refer to Figure 5E and Figure 5F After creating a restricted execution environment, electronic device 100 can continuously display the unlock control 503 in the access control interface. For example... Figure 5E and Figure 5FAs shown, the electronic device 100 can respond to the operation applied to the unlock control 503 and begin detecting the strong authentication factor input by the user. Furthermore, the unlock control 503 can also be used to indicate to the user that the electronic device 100 is currently in a restricted execution environment and remains locked, thereby preventing user operations outside the restricted execution environment.
[0315] The implementation of the unlock control 503 in this application embodiment is not limited. For example, it can be an icon, text, or other form, and it can be transparent or opaque. The unlock control 503 can be displayed at any position on the display screen, can be displayed in a fixed area, or can be dragged by the user; there are no limitations here.
[0316] In this embodiment of the application, the unlocking control 503 may be referred to as the first control.
[0317] Optional step S107: Electronic device 100 shuts down the restricted execution environment.
[0318] In some embodiments, the electronic device 100 can disable the restricted execution environment after switching to the unlocked state following S106.
[0319] In other embodiments, the electronic device 100 may close the restricted execution environment after receiving an operation to close the application launched corresponding to the first operation instruction. When a user triggers the electronic device 100 to close the application launched corresponding to the first operation instruction, it indicates that the user no longer needs the restricted execution environment. Therefore, closing the restricted execution environment can save device resources.
[0320] In a specific implementation, closing the restricted execution environment means that the electronic device 100 deletes various information recorded in S102, such as the various operations that the restricted execution environment allows the electronic device 100 to perform.
[0321] Through the above Figure 4 The access control method based on weak authentication factors, as shown, no longer determines whether an electronic device should respond to and execute a corresponding operation solely based on whether it is unlocked. Instead, it decides whether to execute the operation based on the risk level of the operation command and the security level of the weak authentication factor. This enables more granular access control, enriching the usage scenarios and scope of electronic devices. For users, there is no need to go through cumbersome authentication to unlock the electronic device; they can trigger operations beyond predefined operations while the device is locked, allowing for more flexible and convenient operation. Furthermore, the electronic device no longer simply categorizes resources into those accessible by predefined operations and those accessible by other operations; it also implements more granular access control for each type of resource.
[0322] refer to Figure 6 , Figure 6 This is a flowchart illustrating the cross-device access control method provided in an embodiment of this application.
[0323] like Figure 6 As shown, the method may include the following steps: In step S201, the electronic device 300 receives a user operation, which requests the electronic device 100 to perform a certain operation.
[0324] This application embodiment does not limit the form of user operation in S201. For example, it can be a click or swipe operation on the display screen, voice, gesture / facial expression / body posture, swipe operation including signature, button pressing operation, shaking operation of electronic device 100, etc.
[0325] The user operation requests the electronic device 100 to perform a specific operation, including an access operation to a resource. This resource can be one or more resources within the electronic device 100. The access operation may include, for example, one or more of the following: reading, adding, deleting, writing, modifying, or executing. The specific details of the resource and the access operation are described above. Resources within the electronic device may include software resources, hardware resources, peripherals or peripheral resources, etc., as detailed in the preceding descriptions.
[0326] In this embodiment of the application, the resources in the electronic device 100 that the user requests to access in S201 can be referred to as third resources. The third resource may include one or more resources, and there is no limitation here.
[0327] In one specific embodiment, the user operation is used to request that some data in electronic device 300 be shared to electronic device 100.
[0328] For example, Figures 7A-7B This illustrates a screen mirroring scenario.
[0329] refer to Figure 7A , Figure 7A An exemplary illustration shows a user interface 71 displayed when an electronic device 100 plays a network video selected by a user. This user interface 71 may be displayed by the electronic device 300 in response to a user switching the electronic device 300 from portrait to landscape mode, or by the user clicking a full-screen playback control displayed in the lower right corner of the electronic device 300 while playing a video.
[0330] like Figure 7A As shown, the user interface 71 may also include a screen casting switch control 701, which is used to detect user operations (such as click operations, touch operations, etc.) to turn the screen casting function of the video application on / off.
[0331] refer to Figure 7A The electronic device 300 can detect user operations (such as click operations, touch operations, etc.) applied to the screen projection control 701, discover nearby electronic devices that support screen projection, and display the identifiers of the discovered electronic devices.
[0332] Figure 7B The image shows the identifiers of nearby screen-projection-enabled electronic devices displayed by electronic device 300. For example, such as... Figure 7B As shown, electronic device 300 can detect user operations performed on the identifier corresponding to electronic device 100.
[0333] exist Figure 7A and Figure 7B In the example, the user operation received by electronic device 300 includes clicking control 701 and then clicking the identifier of electronic device 100. This user operation requests that the video currently playing on electronic device 300 be cast to electronic device 100 for continued playback. This user operation requests access to the display screen, speakers, and casting applications of electronic device 100.
[0334] exist Figure 7A and Figure 7B In the example, electronic device 100 is selected by the user. In other embodiments, electronic device 100 may also be selected by default by electronic device 300. For example, after receiving a user operation to click control 701, electronic device 300 may request by default to cast the currently playing video to the device that was cast last time (i.e., electronic device 100) to continue playing.
[0335] S202, the electronic device 300 generates a second operation instruction based on the user's operation, which is used to request the electronic device 100 to perform a certain operation.
[0336] The second operation instruction is the same as the user operation in S201, and is used to request access to a third resource in electronic device 100.
[0337] The embodiments of this application do not limit the form of the second operation instruction. The second operation instruction may be a message sent through wired connection, wireless connection such as Bluetooth (BT) connection, Wi-Fi P2P connection, NFC connection, remote connection, etc.
[0338] In the above Figure 7A and Figure 7B In the screen mirroring scenario shown, the second operation command generated by the electronic device 300 can be a screen mirroring request, which is used to request that the video currently being played by the electronic device 300 be mirrored to the electronic device 100 for continued playback.
[0339] S203, electronic device 300 sends a second operation command to electronic device 100.
[0340] S204, Electronic device 100 is in a locked state, receives a second operation instruction, and creates a restricted execution environment according to the second operation instruction.
[0341] The definition of the locked state can be found in [reference]. Figure 4 The relevant description in the document.
[0342] The definition and acquisition method of the second operation instruction are similar to those of the first operation instruction, and can be found in [reference needed]. Figure 4 The relevant description in the document.
[0343] This application does not limit the strategy by which the electronic device 100 creates a restricted execution environment based on the second operation instruction. For example, the electronic device 100 can create a restricted execution environment based on the type of the second operation instruction. For example, when the second operation instructions are semantics carried by voice, gesture, facial expression, signature, and body posture, the number of operations that can be executed in the restricted execution environments created by the electronic device 100 decreases sequentially.
[0344] In some embodiments, the electronic device 100 may create a restricted execution environment based on the risk level of the operation corresponding to the second operation instruction. Step S204 may specifically include the following steps S2041-S2043.
[0345] S2041, Determine the risk level of the operation corresponding to the second operation instruction.
[0346] Here, electronic device 100 determines the risk level of the operation corresponding to the second operation instruction, and Figure 4 In S102, the electronic device 100 determines that the risk level of the operation corresponding to the first operation instruction is the same, as can be found in the relevant description.
[0347] In step S2042, the electronic device 100 determines whether to allow the execution of the operation corresponding to the second operation instruction based on the risk level of the operation corresponding to the second operation instruction.
[0348] Specifically, the electronic device 100 has pre-set various operations permitted to be performed by the electronic device 100 under different risk levels. This setting can be pre-set by the user or the manufacturer of the electronic device 100. This application embodiment does not limit the correspondence between the risk level of an operation and the operations permitted to be performed by the electronic device 100.
[0349] If the result of S2042 is yes, then the electronic device 100 continues to execute the subsequent steps.
[0350] If the result of S2042 is negative, the electronic device 100 will not continue to execute subsequent steps.
[0351] In some embodiments, if the execution result of S2042 is negative, the electronic device 100 may also output a prompt message, which may be used to prompt the user that the operation corresponding to the second operation instruction is not allowed to be performed at present.
[0352] In some embodiments, the prompt message may further inform the user of the reason why the operation corresponding to the second operation instruction is not allowed to be performed at present, such as the high risk level of the operation corresponding to the second operation instruction.
[0353] In some embodiments, the prompt message may further suggest solutions to the user. For example, it may prompt the user to unlock the device, etc., which is not limited here.
[0354] The implementation of this prompt message is the same as that of the prompt message in subsequent step S207. For details, please refer to the relevant descriptions in subsequent steps.
[0355] In step S2043, the electronic device 100 creates a restricted execution environment based on the risk level of the operation corresponding to the second operation instruction.
[0356] Electronic device 100 creates a restricted execution environment based on the risk level of the operation corresponding to the second operation instruction. Figure 4 In S1024, the electronic device 100 creates a restricted execution environment in the same way as the risk level of the operation corresponding to the first operation instruction, as described in the relevant description.
[0357] For example, refer to Figure 7C , Figure 7C The user interface 72 displayed after the electronic device 100 creates a restricted execution environment is shown. (Example) Figure 7C As shown, electronic device 100 is playing a video sent by electronic device 300, and an unlock control 702 is displayed. This unlock control 702 and... Figure 5E and Figure 5F The unlocking control 503 serves the same purpose, as described in the relevant description. In this embodiment, the unlocking control 702 can also be referred to as the first control.
[0358] S205, the electronic device 100 responds to the second operation instruction and performs the operation corresponding to the second operation instruction in the created restricted execution environment.
[0359] S205 and Figure 4 Similar to S103, please refer to the relevant description.
[0360] Optional steps S206-S209, see reference Figure 4 Optional steps S104-S107.
[0361] In S206, the resource requested for access by the user operation received by the electronic device 100 is called the fourth resource. The fourth resource may include one or more resources, without limitation here.
[0362] In some embodiments of S209, the electronic device 100 may close the restricted execution environment after receiving an operation for closing the application corresponding to the second operation instruction.
[0363] For example, if electronic device 300 receives a user's command to stop screen mirroring, it can send a stop screen mirroring instruction to electronic device 100, after which electronic device 100 closes the restricted execution environment.
[0364] Through the above Figure 6 The cross-device access control method shown no longer determines whether an electronic device responds to a user operation solely based on whether it is unlocked. Instead, it determines the response based on the risk level of the operation command received across devices. This allows for finer-grained access control, enriching the usage scenarios and scope of electronic devices. For users, unlocking the electronic device eliminates the need for cumbersome authentication, enabling the device to perform operations beyond predefined ones while locked, allowing for more flexible and convenient operation. Furthermore, the electronic device no longer simply categorizes resources into those accessible by predefined operations and those accessible by other operations; it implements more granular access control for each type of resource.
[0365] Specifically, for data sharing scenarios such as screen mirroring and multi-screen interaction, when one device shares data with another device, the other device does not need to be unlocked. Compared to solutions that require unlocking the other device every time data is shared, the embodiments of this application reduce the difficulty and complexity of screen mirroring and multi-screen interaction, providing users with a better user experience.
[0366] In the above Figure 4 as well as Figure 6 In the provided access control method, electronic device 100, electronic device 200, and electronic device 300 can be referred to as the first device, the second device, and the third device.
[0367] Weak authentication factors can also be called primary authentication factors, and strong authentication factors can also be called secondary authentication factors.
[0368] refer to Figure 8A , Figure 8A A software architecture diagram of another electronic device 100 provided in this application embodiment.
[0369] like Figure 8AAs shown, the electronic device 100 may include the following modules: an operation instruction recognition module 801, a weak authentication factor recognition module 802, and an access control and execution environment management module 803. Wherein: The operation instruction recognition module 801 is used to acquire the first operation instruction of the electronic device 100.
[0370] In some embodiments, the operation instruction recognition module 801 can be used to acquire a first operation instruction or a second operation instruction through the first method described above. That is, the operation instruction recognition module 801 can be used to receive a user operation carrying a first / second operation instruction and extract the first / second operation instruction from the user operation. In this case, the operation instruction recognition module 801 may include various modules involved in the electronic device 100 acquiring the first / second operation instruction through the first method described above, such as a voice assistant, microphone, etc.
[0371] In some embodiments, the operation instruction recognition module 801 can be used to obtain the first / second operation instruction through the second method described above. That is, the operation instruction recognition module 801 can be used to receive user operation indication information sent by other devices to the electronic device 100, and extract the first / second operation instruction from the user operation indication information. In this case, the operation instruction recognition module 801 may include various modules involved in the electronic device 100 obtaining the first / second operation instruction through the second method described above, such as a wireless communication module, a wired communication module, a voice assistant, etc.
[0372] The operation instruction recognition module 801 is also used to determine the operation corresponding to the first / second operation instruction.
[0373] The weak authentication factor identification module 802 is used to obtain the weak authentication factors of the electronic device 100.
[0374] In some embodiments, the weak authentication factor identification module 802 can be used to obtain weak authentication factors through the first method described above. That is, the weak authentication factor identification module 802 can be used to receive user operations carrying weak authentication factors and extract the weak authentication factors from the user operations. In this case, the weak authentication factor identification module 802 may include various modules involved in the electronic device 100 obtaining weak authentication factors through the first method described above, such as a voice assistant, microphone, camera, fingerprint sensor, etc.
[0375] In some embodiments, the weak authentication factor identification module 802 can be used to obtain weak authentication factors through the second method described above. That is, the weak authentication factor identification module 802 can be used to receive user operation instruction information sent by other devices to the electronic device 100, and extract weak authentication factors from the user operation instruction information. In this case, the weak authentication factor identification module 802 may include various modules involved in the electronic device 100 obtaining weak authentication factors through the second method described above, such as wireless communication modules, mobile communication modules, voice assistants, etc.
[0376] The weak authentication factor identification module 802 is also used to determine the security level of the weak authentication factor. After obtaining the weak authentication factor of the electronic device 100, the weak authentication factor identification module 802 can also generate an authentication token, which indicates the security level of the weak authentication factor, as well as the authentication method, the validity period of the weak authentication factor, etc.
[0377] Subsequently, the operation instruction recognition module 801 sends the operation corresponding to the first operation instruction, and the weak authentication factor recognition module 802 sends the authentication token, to the access control and execution environment management module 803, respectively. This authentication token can be used by the access control and execution environment management module 803 to verify its legitimacy.
[0378] In some embodiments, the access control and execution environment management module 803 is used to determine whether to allow the execution of the operation corresponding to the first operation instruction based on the security level of the operation corresponding to the first operation instruction and the security level of the weak authentication factor. In some embodiments, the access control and execution environment management module 803 is used to determine whether to allow the execution of the operation corresponding to the second operation instruction based on the security level of the operation corresponding to the second operation instruction. If the determination result is yes, the access control and execution environment management module 803 is used to create a restricted execution environment and execute the operation corresponding to the first / second operation instruction in the restricted execution environment. Here, the specific operation of creating a restricted execution environment can be referred to the relevant description in the preceding method embodiments.
[0379] In some embodiments, the electronic device 100 may further include a distributed scheduling module 804, which is used to obtain the first / second operation instruction through the third method described above, or to obtain the weak authentication factor through the third method described above. In this case, the distributed scheduling module 804 may include a wireless communication module, a mobile communication module, etc.
[0380] refer to Figure 8B , Figure 8B The structure of the electronic device access control and execution environment management module 803 is illustrated by way of example.
[0381] like Figure 8B As shown, the access control and execution environment management module 803 may include: access control module 8031, execution environment management module 8032, policy management module 8033, application lifecycle management module 8034, and resource management module 8035.
[0382] The access control module 8031 is used to transmit the operation corresponding to the first / second operation instruction, that is, the information of the accessed resource, to the execution environment management module 8032.
[0383] The execution environment management module 8032 can be used to determine whether the operation corresponding to the first / second operation instruction is allowed. If so, the identifier of the restricted execution environment is set, and the running policy of the restricted execution environment is configured in the policy management module 8033.
[0384] The policy management module 8033 is used to configure the operating policy of the restricted execution environment, that is, to record the various operations that are allowed to be performed in the restricted execution environment, that is, to record which specific access operations are allowed to be performed on which resources or which type of resources.
[0385] The resource management module 8035 may include: an application information management module, a data management module, and a permission management module.
[0386] The application information management module stores and manages information about all applications, and in particular records information about applications that are allowed to start or be accessed in the current restricted execution environment.
[0387] The data management module can be used to classify and hierarchically manage data in electronic devices, and to set restrictions on the data levels or categories that are allowed to be accessed in the execution environment. For example, electronic devices can classify data according to its characteristics, such as dividing it into data with different security levels.
[0388] The permission management module is used to manage permissions for various operations on electronic devices and set restrictions on the permissions allowed in the execution environment.
[0389] The application lifecycle management module 8034 manages the lifecycle of each application in the electronic device 100, such as startup and destruction. When the application lifecycle management module 8034 responds to a user operation to start an application or access data, it first checks with the application information management module to see if the current restricted execution environment allows the application to start, or with the data management module to see if the current restricted execution environment allows access to the data. If so, the application can be started or the data can be accessed. After starting the application, if the application lifecycle management module 8034 needs to perform certain operations, it needs to check with the permission management module to see if the current restricted execution environment has the corresponding permissions. If so, the operation is executed.
[0390] The above Figure 8A and Figure 8B The modules shown can be located in Figure 2 The software system shown can be any one or more layers; no specific limitation is made here.
[0391] Figure 8A and Figure 8B The modules shown are merely examples. In a specific implementation, the electronic device 100 may include more or fewer modules, which is not limited here.
[0392] The various embodiments of this application can be combined arbitrarily to achieve different technical effects.
[0393] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state disk (SSD)).
[0394] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. This program can be stored in a computer-readable storage medium, and when executed, it can include the processes described in the above method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM or random access memory (RAM), magnetic disks, or optical disks.
[0395] In summary, the above description is merely an embodiment of the technical solution of this application and is not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, improvements, etc., made based on the disclosure of this application should be included within the scope of protection of this application.
Claims
1. An access control method, characterized in that, The method includes: When the first device is in a locked state, it acquires a first operation instruction and a first authentication factor; the first operation instruction is used to request access to the first resource of the first device, and the first authentication factor includes identity authentication information that does not meet the unlocking requirements of the first device, and the identity authentication information that meets the unlocking requirements of the first device is used to switch the first device from the locked state to the unlocked state. The first device responds to the first operation command by accessing the first resource, wherein the first resource belongs to the resources that are allowed to be accessed based on the first authentication factor.
2. The method according to claim 1, characterized in that, The first device determines the resources that it is allowed to access based on the first operation instruction, specifically including: The first device determines the resources that it is allowed to access based on the risk level of accessing the first resource; the higher the risk level of accessing the first resource, the fewer resources the first device is allowed to access. The higher the privacy level of the first resource, the higher the risk level of accessing the first resource.
3. The method according to claim 1 or 2, characterized in that, The first device determines the resources that it is allowed to access based on the first authentication factor, specifically including: The first device determines the resources that it is allowed to access based on the security level of the first authentication factor; the lower the security level of the first authentication factor, the fewer resources the first device is allowed to access. Wherein, the higher the authentication capability level (ACL) of the identity authentication method corresponding to the first authentication factor, or the higher the matching degree between the first authentication factor and the identity authentication information that meets the unlocking requirements of the first device, or the higher the security level of the first authentication factor, the better the first authentication factor is obtained.
4. The method according to any one of claims 1-3, characterized in that, The first resource includes: a predefined resource that the first device cannot access in the locked state.
5. The method according to any one of claims 1-4, characterized in that, The first operation instruction includes any one of the following: semantics carried by speech, gestures, facial expressions, and body posture.
6. The method according to claim 5, characterized in that, The first device acquires a first operation instruction, which specifically includes any one of the following: The first device acquires voice or image and identifies the first operation command carried in the voice or image; The first device receives voice or image sent by the second device and identifies a first operation command carried in the voice or image; or, The first device receives the first operation command sent by the second device.
7. The method according to any one of claims 1-6, characterized in that, The identity authentication information includes any one or more of the following: password, graphic, or biometric features.
8. The method according to any one of claims 1-7, characterized in that, The authentication information that does not meet the unlocking requirements of the first device includes: authentication information that is below the standard required by the first authentication method, or authentication information that meets the standard required by the second authentication method; The first authentication method is an identity authentication method used to switch the first device from the locked state to the unlocked state, and the second authentication method is an identity authentication method other than the first authentication method.
9. The method according to claim 8, characterized in that, The first authentication method is an authentication method with an authentication capability level (ACL) higher than the third value, or the first authentication method is preset by the first device.
10. The method according to claim 8 or 9, characterized in that, The identity authentication information that is below the standard required by the first authentication method includes: biometric features whose matching degree with the pre-stored first biometric feature is lower than a first value, where the first biometric feature is the identity authentication information corresponding to the first authentication method; And / or, The identity authentication information that meets the standards required for the second authentication method includes: a biometric feature whose matching degree with a pre-stored second biometric feature reaches a second value, wherein the second biometric feature is the identity authentication information corresponding to the second authentication method.
11. The method according to any one of claims 1-10, characterized in that, The first device acquires the first authentication factor, specifically including any one of the following: The first device acquires voice or image data and identifies the first authentication factor carried in the voice or image data. The first device receives voice or image sent by the second device and identifies the first authentication factor carried in the voice or image; or, The first device receives the first authentication factor sent by the second device.
12. The method according to any one of claims 1-11, characterized in that, The first device acquires a first operation command and a first authentication factor, specifically including any one of the following: The first device collects speech, recognizes the semantics of the speech, and determines the semantics as the first operation command; it also recognizes the voiceprint carried by the speech and determines the voiceprint as the first authentication factor. or, The first device collects images, identifies gestures, facial expressions, and body postures in the images, and determines the gestures, facial expressions, and body postures in the images as the first operation command; it also identifies biometric features carried in the images and determines the biometric features as the first authentication factor.
13. The method according to any one of claims 1-12, characterized in that, After the first device accesses the first resource in response to the first operation command, the method further includes: The first device receives a user operation, the user operation being used to request access to a second resource of the first device; If the resources that the first device is allowed to access include the second resource, then the first device accesses the second resource in response to the user operation. If the resources that the first device is allowed to access do not include the second resource, then the first device refuses to respond to the user's action.
14. The method according to any one of claims 1-13, characterized in that, After the first device accesses the first resource in response to the first operation command, the method further includes: The first device obtains a second authentication factor, which includes identity authentication information that meets the unlocking requirements of the first device, or a predetermined number of the first authentication factors; The first device switches from the locked state to the unlocked state based on the second authentication factor.
15. The method according to claim 14, characterized in that, After the first device determines the resources it is allowed to access, and before the first device obtains the second authentication factor, the method further includes: The first device displays the first control; The first device detects an operation performed on the first control; The first device responds to the operation applied to the first control and begins to detect identity authentication information.
16. The method according to any one of claims 1-15, characterized in that, After the first device determines the resources that the first device is allowed to access, the method further includes: the first device creating a restricted execution environment, in which the first device is allowed to access the resources that were determined to be allowed to access; The first device responds to the first operation instruction by accessing the first resource, specifically including: the first device responds to the first operation instruction by accessing the first resource in the restricted execution environment.
17. An electronic device, characterized in that, include: A memory, and one or more processors; the memory is coupled to the one or more processors, the memory being used to store computer program code, the computer program code including computer instructions, the one or more processors invoking the computer instructions to cause the electronic device to perform the method as described in any one of claims 1-16.
18. A computer-readable storage medium comprising instructions, characterized in that, When the instructions are executed on an electronic device, the electronic device causes the electronic device to perform the method as described in any one of claims 1-16.
19. A computer program product, characterized in that, When the computer program product is run on a computer, it causes the computer to perform the method as described in claims 1-16.