Identity authentication method and device, electronic equipment and storage medium

By exchanging authentication information through near-field communication between devices, the problem of requiring manual configuration by users for IoT device networking and connection is solved, enabling fast and secure identity authentication even in situations with poor external network signal, thus improving the device interconnection experience.

CN121968096APending Publication Date: 2026-05-01BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING XIAOMI MOBILE SOFTWARE CO LTD
Filing Date
2024-10-29
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

In existing technologies, IoT devices require manual configuration by the user when connecting to a network, resulting in a poor interconnection experience between terminal devices and IoT devices in scenarios with poor or no external network signal.

Method used

By conducting near-field communication between devices, identity authentication is performed using the authentication information of the first and second devices, including generating and exchanging certificate credentials or communication information encrypted with shared keys, thereby achieving identity authentication between devices.

Benefits of technology

It supports offline authentication, which improves the user experience of device interconnection and ensures fast and secure identity authentication even when the external network signal is poor or there is no external network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121968096A_ABST
    Figure CN121968096A_ABST
Patent Text Reader

Abstract

The invention relates to an identity authentication method and device, electronic equipment and a storage medium. The identity authentication method comprises the steps that after a first device logs in a first account, first authentication information is acquired, the first authentication information is associated with the first account, and the first authentication information is used for being sent to a device bound with the first account through a cloud service; when the first equipment and the second equipment are networked, second authentication information sent by the second equipment is received in a near field communication mode, the second authentication information is associated with a second account, and the second account is a user account bound with the second equipment; and performing identity authentication with the second equipment based on the first authentication information and the second authentication information. Identity authentication during equipment networking is realized in a near field communication mode, off-line authentication is supported, dependence on an external network is not needed, identity authentication can be carried out even in a scene that an external network signal is poor or the external network is blocked, and compared with a cloud authentication mode and a near field authentication mode, the method is faster and safer, and the equipment interconnection use experience of a user can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Authentication methods, devices, electronic devices and storage media Technical Field

[0001] This disclosure relates to the field of Internet of Things (IoT) technology, and in particular to an identity authentication method, device, electronic device, and storage medium. Background Technology

[0002] As users' demands for smart home experiences continue to increase, the interconnection between terminal devices and Internet of Things (IoT) devices is becoming increasingly important. To ensure the security of connections between devices, authentication is required when terminal devices and IoT devices establish a network connection. In related technologies, because IoT devices lack account capabilities, manual configuration by the user is required during network connection. This allows terminal devices to interconnect with IoT devices via the cloud, and authentication is performed through the cloud during the interconnection process. Therefore, in scenarios with poor or no external network signal, the interconnection experience between terminal devices and IoT devices is poor. Summary of the Invention

[0003] To overcome the problems existing in related technologies, this disclosure provides an identity authentication method, apparatus, electronic device, and storage medium.

[0004] According to a first aspect of the present disclosure, an identity authentication method is provided, the method comprising:

[0005] After logging into the first account on the first device, the first authentication information is obtained. The first authentication information is associated with the first account and is used to send to the device bound to the first account via cloud service.

[0006] When the first device and the second device are networked, the first device receives the second authentication information sent by the second device via near-field communication. The second authentication information is associated with the second account, which is a user account bound to the second device.

[0007] Based on the first authentication information and the second authentication information, identity authentication is performed with the second device.

[0008] In an exemplary embodiment, the step of authenticating the identity with the second device based on the first authentication information and the second authentication information includes:

[0009] If the first authentication information matches the second authentication information, it is determined that the first account and the second device have successfully authenticated their identities.

[0010] If the first authentication information does not match the second authentication information, it is determined that the authentication of the first account and the second device has failed.

[0011] In an exemplary embodiment, the first device includes a preset service, and receiving the second authentication information sent by the second device via near-field communication includes:

[0012] The second authentication information sent by the second device is received through the preset communication protocol in the preset service, and the preset communication protocol is used to implement near-field communication.

[0013] In an exemplary embodiment, the first authentication information is a certificate credential issued based on the identity information associated with the first account; obtaining the first authentication information includes:

[0014] Generate the identity information associated with the first account;

[0015] Send a request to the cloud service for the first authentication information, the request information including the identity information associated with the first account;

[0016] Receive the first authentication information sent by the cloud service.

[0017] In an exemplary embodiment, the first authentication information includes the account identifier of the first account, and the second authentication information includes the account identifier of the second account; the step of authenticating the identity with the second device based on the first authentication information and the second authentication information includes:

[0018] If the account identifier of the second account is the same as the account identifier of the first account, it is determined that the identity authentication between the first account and the second device is successful;

[0019] If the account identifier of the second account is different from that of the first account, it is determined that the authentication between the first account and the second device has failed.

[0020] In one exemplary embodiment, the method further includes: the first authentication information is also associated with the second device; after the first device and the second device successfully authenticate each other,

[0021] The verification information is sent to the second device via near-field communication. The verification information is used to verify whether the second device has third authentication information, and the third authentication information is associated with the third device.

[0022] The signature verification information and the third authentication information sent by the second device are received via near-field communication, wherein the signature verification information is information obtained by signing the verification information.

[0023] The second device is authenticated based on the signature verification information, the first authentication information, and the third authentication information.

[0024] In an exemplary embodiment, the first authentication information includes the device identifier of the second device, and the third authentication information includes the device identifier of the third device; the step of authenticating the device with the second device based on the signature verification information, the first authentication information, and the third authentication information includes:

[0025] If the signature verification information passes the verification and the device identifier of the third device is the same as the device identifier of the second device, the device authentication of the second device is determined to be successful.

[0026] If the signature verification information fails to pass verification, or if the device identifier of the third device is different from the device identifier of the second device, the device authentication of the second device is determined to have failed.

[0027] In an exemplary embodiment, the first authentication information represents the identity code associated with the first account, and the second authentication information represents the identity code associated with the second account; obtaining the first authentication information includes:

[0028] Randomly generate the identity code associated with the first account;

[0029] Based on the identity code associated with the first account, first key information is generated. The first key information is used to encrypt or decrypt near-field communication information between the first device and the device bound to the first account.

[0030] Based on the first key information, the first authentication information is determined;

[0031] The method further includes:

[0032] Send the identity code associated with the first account to the cloud service.

[0033] In one exemplary embodiment, the method further includes: if the first account and the second device successfully authenticate each other, before the first device and the second device form a network,

[0034] After logging into the first account on the first device, in response to receiving the binding instruction between the first account and the second device, the first account is bound to the second device, the binding information of the second device is obtained, and the binding information of the second device is sent to the cloud service;

[0035] or,

[0036] After logging into the first account on the first device, a request for the first account to be bound to the cloud service is sent.

[0037] Receive the binding information of the second device sent by the cloud service;

[0038] The binding information of the second device includes the device information of the second device.

[0039] In an exemplary embodiment, if the first account and the second device successfully authenticate each other, the method further includes:

[0040] After logging into the first account on the first device, in response to receiving the unbinding instruction between the first account and the second device, the first account is unbound from the second device, and the unbinding information of the second device is sent to the cloud service;

[0041] or,

[0042] After logging into the first account on the first device, a request for the first account to be bound to the cloud service is sent.

[0043] Receive the unbinding information of the second device sent by the cloud service;

[0044] The unbinding information of the second device includes the device information of the second device.

[0045] In one exemplary embodiment, the method further includes:

[0046] Receive information from the cloud service regarding changes in the number of devices bound to the first account.

[0047] In one exemplary embodiment, the method further includes:

[0048] The first authentication information is sent to the second device via near-field communication, so that the second device can perform identity authentication with the first device based on the first authentication information and the second authentication information.

[0049] According to a second aspect of the present disclosure, an identity authentication method is provided, the method comprising:

[0050] After confirming that the second device is bound to the second account, the second authentication information is obtained. The second authentication information is associated with the second account and is obtained based on cloud services.

[0051] When the second device and the first device are networked, the second authentication information is sent to the first device via near-field communication, so that the first device can authenticate its identity with the second device based on the first authentication information and the second authentication information. The first authentication information is associated with the first account, which is the user account logged in by the first device.

[0052] In an exemplary embodiment, the second device includes a preset service, and sending the second authentication information to the first device via near-field communication includes:

[0053] The second authentication information is sent to the first device through a preset communication protocol in the preset service, wherein the preset communication protocol is used to implement near-field communication.

[0054] In one exemplary embodiment, the second device further includes a proxy service for transmitting information between the preset service and the cloud service.

[0055] In one exemplary embodiment, the second authentication information is a certificate credential issued based on the identity information associated with the second account; obtaining the second authentication information includes:

[0056] After confirming that the second device is bound to the second account, the application information for the second authentication information is sent to the cloud service. The second authentication information is obtained based on the device logged into the second account.

[0057] Receive the second authentication information sent by the cloud service.

[0058] In one exemplary embodiment, the method further includes:

[0059] The verification information sent by the first device is received via near-field communication. The verification information is used to verify whether the second device has third authentication information, and the third authentication information is associated with the third device.

[0060] The verification information is signed by the second device to obtain signature verification information, and the third authentication information is obtained from the second device.

[0061] The first device sends signature verification information and the third authentication information to the first device via near-field communication, so that the first device can authenticate the second device based on the signature verification information, the first authentication information and the third authentication information, wherein the first authentication information is also associated with the second device.

[0062] In one exemplary embodiment, the second authentication information represents the identity code associated with the second account; obtaining the second authentication information includes:

[0063] Receive the identity code associated with the second account sent by the cloud service. The identity code associated with the second account is generated by the device that logs in to the second account.

[0064] Based on the identity code associated with the second account, a second key information is generated. The second key information is used to encrypt or decrypt near-field communication information between the second device and the device logged into the second account.

[0065] Based on the second key information, the second authentication information is determined.

[0066] In one exemplary embodiment, before obtaining the second authentication information, the method further includes:

[0067] The cloud service receives binding information of the second device, which includes device information of the second device. The binding information of the second device is sent to the cloud service by the device logged into the second account.

[0068] Confirm that the second device is bound to the second account, and save the device information of the second device.

[0069] In one exemplary embodiment, the method further includes:

[0070] Receive unbinding information of the second device sent by the cloud service. The unbinding information of the second device includes the device information of the second device. The unbinding information of the second device is sent to the cloud service by the device logged into the second account.

[0071] Confirm that the second device is unbound from the second account, and delete the saved device information and the second authentication information of the second device.

[0072] In one exemplary embodiment, the method further includes:

[0073] Receive the first authentication information sent by the first device via near-field communication;

[0074] Based on the first authentication information and the second authentication information, identity authentication is performed with the first device.

[0075] According to a third aspect of the present disclosure, an identity authentication method is provided, the method comprising:

[0076] After logging into the first account on the first device and binding the first account to the second device, the first authentication information is obtained and sent to the second device. The first authentication information is obtained based on the first device.

[0077] The first authentication information is associated with the first account, and the first authentication information is used to perform identity authentication through near-field communication when the first device and the second device are networked.

[0078] In one exemplary embodiment, obtaining the first authentication information includes:

[0079] The system receives a request for the first authentication information sent by the first device, the request information including identity information associated with the first account generated by the first device.

[0080] A certificate credential is issued based on the identity information associated with the first account, and the certificate credential is used as the first authentication information.

[0081] The method further includes:

[0082] Send the first authentication information to the first device.

[0083] In an exemplary embodiment, sending the first authentication information to the second device includes:

[0084] Receive the application information for the first authentication information sent by the second device;

[0085] The first account bound to the second device is matched from the bound device mapping relationship, wherein the bound device mapping relationship represents the mapping relationship between a user account and the device bound to it;

[0086] Send the first authentication information associated with the first account to the second device.

[0087] In one exemplary embodiment, obtaining the first authentication information includes:

[0088] Receive the identity code associated with the first account sent by the first device;

[0089] Sending the first authentication information to the second device includes:

[0090] Send the identity code associated with the first account to the second device.

[0091] In one exemplary embodiment, before obtaining the first authentication information, the method further includes:

[0092] In response to receiving the binding information of the second device sent by the first device, the binding information of the second device is sent to the second device, and the mapping relationship between the first account and the second device is added to the binding device mapping relationship;

[0093] or,

[0094] In response to receiving a request from the first device for the binding device of the first account, the second device bound to the first account is obtained from the binding device mapping relationship, and the binding information of the second device is sent to the first device;

[0095] The binding information of the second device includes the device information of the second device, and the binding device mapping relationship represents the mapping relationship between the user account and the device bound to it.

[0096] In one exemplary embodiment, the method further includes:

[0097] In response to receiving the unbinding information of the second device sent by the first device, the system sends the unbinding information of the second device to the second device and deletes the mapping relationship between the first account and the second device in the bound device mapping relationship;

[0098] or,

[0099] In response to receiving the request information from the first device to bind the first account to a device, the device sends the unbinding information of the second device to the first device;

[0100] The device binding mapping relationship represents the mapping relationship between a user account and the device bound to it, and the unbinding information of the second device includes the device information of the second device.

[0101] In one exemplary embodiment, the method further includes:

[0102] Send the number of devices bound to the first account to the first device.

[0103] According to a fourth aspect of the present disclosure, an identity authentication device is provided, the device comprising:

[0104] The processing module is configured to obtain first authentication information after logging into the first account on the first device. The first authentication information is associated with the first account and is used to send the first authentication information to the device bound to the first account via cloud service.

[0105] The transceiver module is configured to receive second authentication information sent by the second device via near-field communication when the first device and the second device are networked. The second authentication information is associated with a second account, which is a user account bound to the second device.

[0106] The authentication module is configured to perform identity authentication with the second device based on the first authentication information and the second authentication information.

[0107] According to a fifth aspect of the present disclosure, an identity authentication device is provided, the device comprising:

[0108] The processing module is configured to obtain second authentication information after determining that the second device is bound to the second account. The second authentication information is associated with the second account and is obtained based on cloud services.

[0109] The transceiver module is configured to send the second authentication information to the first device via near-field communication when the second device and the first device are networked, so that the first device can authenticate its identity with the second device based on the first authentication information and the second authentication information. The first authentication information is associated with a first account, which is the user account logged into the first device.

[0110] According to a sixth aspect of the present disclosure, an identity authentication device is provided, the device comprising:

[0111] The processing module is configured to obtain first authentication information after logging into a first account on a first device and binding the first account to a second device, and send the first authentication information to the second device, wherein the first authentication information is obtained based on the first device;

[0112] The first authentication information is associated with the first account, and the first authentication information is used to perform identity authentication through near-field communication when the first device and the second device are networked.

[0113] According to a seventh aspect of the present disclosure, an electronic device is provided, comprising:

[0114] processor;

[0115] Memory used to store processor-executable instructions;

[0116] The processor is configured to perform the methods described in the first, second, or third aspects of the embodiments of this disclosure.

[0117] According to an eighth aspect of the present disclosure, a non-transitory computer-readable storage medium is provided, wherein instructions in the storage medium, when executed by a processor of an electronic device, enable the electronic device to perform the method described in the first, second, or third aspect of the present disclosure.

[0118] The above-described method of this disclosure has the following advantages: it enables device authentication during networking through near-field communication, supports offline authentication, does not rely on the external network, and can perform authentication even in scenarios where the external network signal is poor or the external network is unavailable. Furthermore, compared with cloud authentication, near-field authentication is faster and more secure, which can improve the user's device interconnection experience.

[0119] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description

[0120] The accompanying drawings, which are incorporated in and form a part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure.

[0121] Figure 1 is a flowchart illustrating an identity authentication method according to an exemplary embodiment;

[0122] Figure 2 is a flowchart illustrating an identity authentication method according to an exemplary embodiment;

[0123] Figure 3 is a flowchart illustrating an identity authentication method according to an exemplary embodiment;

[0124] Figure 4 is a flowchart illustrating an identity authentication method according to an exemplary embodiment;

[0125] Figure 5 is a flowchart illustrating an identity authentication method according to an exemplary embodiment;

[0126] Figure 6 is a flowchart illustrating an identity authentication method according to an exemplary embodiment;

[0127] Figure 7 is a flowchart illustrating an identity authentication method according to an exemplary embodiment;

[0128] Figure 8 is a flowchart illustrating an identity authentication method according to an exemplary embodiment;

[0129] Figure 9 is a flowchart illustrating an identity authentication method according to an exemplary embodiment;

[0130] Figure 10 is an interactive flowchart of an identity authentication method according to an exemplary embodiment;

[0131] Figure 11 is a flowchart of an interaction method for identity authentication according to an exemplary embodiment.

[0132] Figure 12 is an interactive flowchart of an identity authentication method according to an exemplary embodiment;

[0133] Figure 13 is an interactive flowchart of an identity authentication method according to an exemplary embodiment;

[0134] Figure 14 is a flowchart illustrating the interaction between binding a first account to a second device according to an exemplary embodiment.

[0135] Figure 15 is a flowchart illustrating the interaction between a first account and a second device according to an exemplary embodiment.

[0136] Figure 16 is a schematic diagram illustrating an identity authentication method according to an exemplary embodiment;

[0137] Figure 17 is a block diagram of an identity authentication device according to an exemplary embodiment;

[0138] Figure 18 is a block diagram of an identity authentication device according to an exemplary embodiment;

[0139] Figure 19 is a block diagram three illustrating an identity authentication device according to an exemplary embodiment;

[0140] Figure 20 is a block diagram illustrating an electronic device according to an exemplary embodiment. Detailed Implementation

[0141] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numerals in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this disclosure. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this disclosure as detailed in the appended claims.

[0142] In the exemplary embodiments of this disclosure, to overcome the problems existing in related technologies where terminal devices and IoT devices authenticate each other via the cloud, an identity authentication method is provided, comprising: after a first device logs into a first account, obtaining first authentication information, the first authentication information being associated with the first account, and the first authentication information being sent to the device bound to the first account via a cloud service; when the first device and a second device are networked, receiving second authentication information sent by the second device via near-field communication, the second authentication information being associated with a second account, the second account being a user account bound to the second device; and performing identity authentication with the second device based on the first authentication information and the second authentication information. This method achieves identity authentication when devices are networked via near-field communication, supports offline authentication, does not rely on the external network, and can perform identity authentication even in scenarios where the external network signal is poor or unavailable. Furthermore, compared to cloud authentication, near-field authentication is faster and more secure, improving the user's device interconnection experience.

[0143] In an exemplary embodiment of this disclosure, an identity authentication method is provided, applied to a first device. FIG1 is a flowchart of an identity authentication method according to an exemplary embodiment. As shown in FIG1, the identity authentication method includes the following steps S101-S103:

[0144] Step S101: After logging into the first account on the first device, obtain the first authentication information. The first authentication information is associated with the first account and is used to send to the device bound to the first account via cloud service.

[0145] The first device includes electronic devices such as smartphones, tablets, personal computers, smart wearable devices, smart TVs, and smart vehicle systems. In some embodiments, the first device may also be referred to as a core device. The first device includes an account service, which is used to manage accounts on the operating system of the first device. The accounts in the account service may also be referred to as device accounts.

[0146] The first device logs in to a first account via an account service. The first account can be any user account. The first authentication information represents information that can be used for identity authentication, such as certificate credentials or communication information encrypted with a shared key. The shared key is generated based on the identity code. The type of the first authentication information is related to the authentication method; different authentication methods use different types of first authentication information. Different user accounts are associated with different authentication information. The first authentication information is associated with the first account; that is, the first authentication information is the authentication information corresponding to the first account. After logging into the first account on the first device, the first authentication information associated with the first account is obtained. The method of obtaining the first authentication information is determined based on its type. For example, if the first authentication information is a certificate credential, it is obtained from a Certificate Authority (CA). If the first authentication information is communication information encrypted with a shared key, the first device generates a shared key based on the identity code, and then generates the first authentication information based on the shared key. The first authentication information is sent to the device bound to the first account via cloud service, so that the device bound to the first account can obtain the first authentication information, and so that the device bound to the first account can send the first authentication information to the first device when networking with the first device, to ensure that the identity authentication with the first device can be successful.

[0147] Step S102: When the first device and the second device are networking, the first device receives the second authentication information sent by the second device through near-field communication. The second authentication information is associated with the second account, which is a user account bound to the second device.

[0148] When the first device discovers the second device through the networking service and establishes a network with it, it receives the second authentication information sent by the second device via near-field communication (NFC). The NFC method can be any NFC method, such as LAN, Bluetooth, or ZigBee. The second device can be any unknown IoT device, such as a smart lamp, smart speaker, or smart home device. The type of the second authentication information is the same as the type of the first authentication information. The second authentication information is obtained by the second device, and the method by which the second device obtains the second authentication information is determined by its type. For example, if the authentication information is a certificate, it is obtained from the certificate authority; if the authentication information is communication information encrypted with a shared key, the second device generates a shared key based on the identity code, and then generates the second authentication information based on the shared key. The second authentication information is associated with a second account, which is a user account bound to the second device. The second account may be the same user account as the first account, or it may be a different user account.

[0149] In some embodiments, the first device includes a preset service. This preset service is used to obtain first authentication information after the first device logs into a first account. The first authentication information is sent to the device bound to the first account via a cloud service. When the first device and a second device are networked, the preset service receives second authentication information sent by the second device via near-field communication (NFC). Based on the first and second authentication information, the first device performs identity authentication with the second device. The preset service is a custom service capable of implementing the above functions. It receives the second authentication information sent by the second device through a preset communication protocol. This preset communication protocol is used to implement NFC and is a custom communication protocol capable of implementing the above communication functions.

[0150] Step S103: Based on the first authentication information and the second authentication information, perform identity authentication with the second device.

[0151] Identity authentication, also known as account authentication or same-account authentication, is used to verify whether the user account logged in on the first device and the user account bound to the second device are the same user account, i.e., whether the second device is the device bound to the first account. Since the first authentication information is associated with the first account logged in on the first device, and the second authentication information is associated with the second account bound to the second device, based on the first and second authentication information, it is possible to verify whether the second account and the first account are the same user account, i.e., whether the second device is the device bound to the first account. In some embodiments, if the identity authentication between the first account and the second device is successful, a network connection between the first and second devices can be established, and the first device can control the second device via near-field communication.

[0152] In some embodiments, when the first device logs into the first account for the first time to form a network, it needs to perform the above step S101 to obtain the first authentication information and save it in the first device. Therefore, after logging into the first account for the first time or forming a network for the first time, it is not necessary to obtain the first authentication information again. It is only necessary to perform the above steps S102-S103.

[0153] In the exemplary embodiments of this disclosure, the first device obtains first authentication information associated with the first account. When the first device and the second device are networked, the first device receives second authentication information associated with the second account sent by the second device via near-field communication (NFC). Based on the first and second authentication information, it can verify whether the second account and the first account are the same user account, thereby authenticating the identity of the second device. This method achieves identity authentication during device networking via NFC, supports offline authentication, does not rely on the external network, and can perform identity authentication even in scenarios with poor external network signal or no external network access. After successful identity authentication, device interconnection can be achieved without additional user configuration. Furthermore, the device bound to the first account can also be controlled via NFC, achieving offline control and improving the user's device interconnection experience. In addition, compared to cloud authentication, NFC authentication is faster and more secure.

[0154] In some embodiments, step S103 in the above embodiments includes the following two cases:

[0155] The first method is to determine that the first account and the second device have successfully authenticated their identities if the first authentication information matches the second authentication information.

[0156] The second method is to determine that the authentication of the first device and the second device has failed if the first authentication information does not match the second authentication information.

[0157] The first device verifies whether the first authentication information and the second authentication information match. For example, when the authentication information is a certificate credential, if the certificate credential is valid and the user account associated with the certificate credential is the same account, then the first authentication information and the second authentication information match. If the certificate credential is invalid and / or the user account associated with the certificate credential is not the same account, then the first authentication information and the second authentication information do not match. When the authentication information is communication information encrypted with a shared key, if communication can be conducted through the communication information encrypted with the shared key, that is, the receiving end can decrypt the authentication information of the sending end, then the first authentication information and the second authentication information match. If communication cannot be conducted through the communication information encrypted with the shared key, that is, the receiving end cannot decrypt the authentication information of the sending end, then the first authentication information and the second authentication information do not match. The shared key is generated based on the identity code. If the first authentication information matches the second authentication information, it means that the user account logged in on the first device and the user account bound to the second device are the same user account, i.e., the second account and the first account are the same user account. In this case, the second device is determined to be the device bound to the first account, and the identity authentication between the first account and the second device is successful. If the first authentication information does not match the second authentication information, it means that the user account logged in on the first device and the user account bound to the second device are not the same user account, i.e., the second account and the first account are not the same user account. In this case, the second device is determined to be the device bound to the first account, and the identity authentication between the first account and the second device fails.

[0158] In some embodiments, the above embodiments further include: sending first authentication information to a second device via near-field communication, so that the second device can perform identity authentication with the first device based on the first authentication information and the second authentication information.

[0159] The first device sends first authentication information to the second device via near-field communication. Based on the first and second authentication information, the second device verifies whether the user account logged in on the first device and the user account bound to the second device are the same user account, i.e., whether the first device is the device logged into the second account. This two-way authentication between the first and second devices ensures the security of both devices.

[0160] In an exemplary embodiment of this disclosure, an identity authentication method is provided, applied to a first device. FIG2 is a flowchart of an identity authentication method according to an exemplary embodiment. As shown in FIG2, the identity authentication method includes the following steps S201-S205:

[0161] Step S201: After logging into the first account on the first device, generate the identity information associated with the first account.

[0162] After logging into the first account on the first device, the first device randomly generates identity information associated with the first account. The identity information can be any information that can uniquely identify the first account. The identity information is different for different user accounts. For example, the identity information can be the elliptic public-private key pair corresponding to the first account.

[0163] Step S202: Send a request for first authentication information to the cloud service. The request information includes the identity information associated with the first account. The first authentication information is a certificate issued based on the identity information associated with the first account.

[0164] When the type of the first authentication information is a certificate credential, after generating the identity information associated with the first account, the first device, using the cloud service as the certificate issuing authority for the certificate credential, sends a request for the first authentication information to the cloud service. This request carries the identity information associated with the first account, requesting the cloud service to issue a certificate credential based on that identity information. In some implementations, if the identity information is an elliptic public-private key pair corresponding to the first account, the request for the first authentication information carries the public key from that pair. Upon receiving the request for the first authentication information, the cloud service issues a certificate credential based on the identity information associated with the first account, uses this certificate credential as the first authentication information, and sends it to the first device. Simultaneously, the cloud service also sends the first authentication information to the device bound to the first account.

[0165] Step S203: Receive the first authentication information sent by the cloud service.

[0166] After receiving the first authentication information sent by the cloud service, the first authentication information is stored in the first device.

[0167] Step S204: When the first device and the second device are networking, the first device receives the second authentication information sent by the second device through near-field communication. The second authentication information is a certificate credential issued based on the identity information associated with the second account. The second account is a user account bound to the second device.

[0168] When the type of the first authentication information is a certificate credential, the second authentication information received by the first device is obtained by the second device from the cloud service, and is obtained after the second device has determined to be bound to the second account.

[0169] Step S205: Based on the first authentication information and the second authentication information, perform identity authentication with the second device.

[0170] In some implementations, the first authentication information includes an account identifier for a first account, and the second authentication information includes an account identifier for a second account, wherein the account identifier is an identifier that uniquely identifies a user account. Based on the first and second authentication information, identity authentication with the second device is performed, including the following two scenarios:

[0171] The first method is to determine if the account identifier of the second account is the same as that of the first account, thus confirming successful identity authentication between the first account and the second device.

[0172] If the account identifier of the second account is the same as that of the first account, it means that the second account and the first account are the same user account. That is, the second authentication information matches the first authentication information, and the second device is determined to be the device bound to the first account. At this time, the identity authentication of the first account and the second device is successful.

[0173] The second method is to determine if the account identifier of the second account is different from that of the first account, thus confirming that the authentication between the first account and the second device has failed.

[0174] If the account identifier of the second account is different from that of the first account, it means that the second account and the first account are not the same user account. That is, the second authentication information does not match the first authentication information. Therefore, it is determined that the second device is not the device bound to the first account, and the identity authentication between the first account and the second device fails.

[0175] In this embodiment, a certificate issued by a cloud service is used as authentication information, which can ensure the reliability of the authentication information. Authentication information is obtained before network connection, which provides a guarantee for near-field identity authentication. Offline identity authentication is supported, which does not rely on the external network. Identity authentication can be performed even in scenarios where the external network signal is poor or the external network is unavailable.

[0176] In an exemplary embodiment of this disclosure, an identity authentication method is provided, applied to a first device. FIG3 is a flowchart of an identity authentication method according to an exemplary embodiment. As shown in FIG3, the identity authentication method includes the following steps S301-S308:

[0177] Step S301: After logging into the first account on the first device, generate the identity information associated with the first account.

[0178] For a detailed implementation of step S301, please refer to step S201, which will not be repeated here.

[0179] Step S302: Send a request for first authentication information to the cloud service. The request information includes the identity information associated with the first account. The first authentication information is a certificate issued based on the identity information associated with the first account.

[0180] For a detailed implementation of step S302, please refer to step S202, which will not be repeated here.

[0181] Step S303: Receive the first authentication information sent by the cloud service. The first authentication information includes the account identifier of the first account.

[0182] For a detailed implementation of step S303, please refer to step S203, which will not be repeated here.

[0183] Step S304: When the first device and the second device are networking, the first device receives the second authentication information sent by the second device through near-field communication. The second authentication information includes the account identifier of the second account, which is a user account bound to the second device.

[0184] For a detailed implementation of step S304, please refer to step S204, which will not be repeated here.

[0185] Step S305: If the account identifier of the second account is the same as the account identifier of the first account, it is confirmed that the identity authentication between the first account and the second device is successful.

[0186] For a detailed implementation of step S305, please refer to step S205, which will not be repeated here.

[0187] Step S306: Send verification information to the second device via near-field communication. The verification information is used to verify whether the second device has third authentication information, and the third authentication information is associated with the third device.

[0188] After successful authentication between the first account and the second device (i.e., after confirming that the second device is the device bound to the first account), the first device randomly generates verification information. The type and content of this verification information are unrestricted; for example, it can be a random number. This verification information is used to verify whether the second device itself possesses third authentication information, which is a device certificate used to identify the device type. If other devices steal the second authentication information from the second device, they will also successfully authenticate during identity verification, potentially leading to data leakage when connecting to a network with them. Therefore, to avoid this situation, it is necessary to further verify the device type of the second device. When verifying the device type of the second device, to prevent the second device from stealing the third authentication information of other devices, the verification information first checks whether the second device itself possesses third authentication information. This third authentication information is the device certificate of the second device, and it is associated with the third device. The third device and the second device may be the same device or different devices.

[0189] Step S307: Receive signature verification information and third authentication information sent by the second device via near-field communication. The signature verification information is the information obtained by signing the verification information.

[0190] The signature verification information is obtained by the second device signing the verification information sent by the first device after receiving it. The third authentication information is obtained from the second device. Specifically, the third authentication information is a device certificate obtained from the second device, which is a level two certificate.

[0191] Step S308: Based on the signature verification information, the first authentication information, and the third authentication information, perform device authentication on the second device.

[0192] Device authentication verifies whether the second device's device type matches the target type. Based on signature verification information, it can be confirmed whether the second device itself possesses third authentication information, i.e., confirm that the third authentication information was obtained from the second device, preventing the second device from stealing the third authentication information through other means. When the first account successfully authenticates with the second device, it indicates that the second device is bound to the first account. Therefore, the first authentication information is associated not only with the first account but also with the second device. The second device can be understood as the expected device for networking with the first device. The third authentication information is authentication information obtained from the second device and associated with a third device. The third device can be understood as the actual device for networking with the first device. Therefore, after determining that the third authentication information is the device authentication information of the second device based on signature verification information, the first and third authentication information can then be used to confirm whether the second device is the target type device, i.e., whether the actual third device is the same device as the expected second device.

[0193] In some implementations, the first authentication information further includes the device identifier of the second device, and the third authentication information includes the device identifier of the third device. The first device pre-stores a root certificate for the third authentication information. The third authentication information is authenticated using the root certificate to obtain the device identifier of the third device. Device authentication with the second device is performed based on the signature verification information, the first authentication information, and the third authentication information, including the following two cases:

[0194] The first method is to verify the signature information and confirm that the device identifier of the third device is the same as that of the second device. If the signature verification information is verified and the device identifier of the third device is the same as that of the second device, the device authentication of the second device is confirmed to be successful.

[0195] The second method is to determine that the second device's authentication has failed if the signature verification information fails or the device identifier of the third device is different from that of the second device.

[0196] The device identifier is a unique identifier assigned to IoT devices by the developer. If the third authentication information is obtained from the signature verification information and is identical to the verification information generated by the first device, it means the third authentication information was obtained from the second device itself, and the signature verification passes. If the signature verification information is not obtained from the signature verification information and is identical to the verification information generated by the first device, it means the third authentication information was not obtained from the second device itself, and the signature verification fails. If the device identifier of the third device is the same as the device identifier of the second device, it means the second device is the target device type, i.e., the third device and the second device are the same device. If the device identifier of the third device is different from the device identifier of the second device, it means the second device is not the target device type, i.e., the third device and the second device are not the same device. Therefore, if the third authentication information is obtained from the second device itself and it is determined that the second device is the target device type, the second device authentication succeeds; if the third authentication information is not obtained from the second device itself, or it is determined that the second device is not the target device type, the second device authentication fails.

[0197] In some implementations, verification information is sent to the second device through a preset communication protocol in a preset service, and signature verification information and third authentication information sent by the second device are received. The preset service then performs device authentication on the second device based on the signature verification information, the first authentication information, and the third authentication information.

[0198] In this embodiment, in addition to account authentication, strong device type verification is added, that is, device authentication is added. This can avoid data leakage caused by other devices stealing authentication information related to account authentication, and further improve the security of authentication.

[0199] In an exemplary embodiment of this disclosure, an identity authentication method is provided, applied to a first device. FIG4 is a flowchart of an identity authentication method according to an exemplary embodiment. As shown in FIG4, the identity authentication method includes the following steps S401-S407:

[0200] Step S401: After logging into the first account on the first device, a random identity code associated with the first account is generated.

[0201] The identity code associated with the first account can be any byte code, such as a 32-byte random code. In some implementations, the identity code may also be called a PIN code.

[0202] Step S402: Based on the identity code associated with the first account, generate first key information. The first key information is used to encrypt or decrypt near-field communication information between the first device and the device bound to the first account.

[0203] The identity code associated with the first account is input into a preset key generation formula, which outputs first key information. This first key information is used to encrypt or decrypt near-field communication information between the first device and the device bound to the first account. The preset key generation formula is pre-stored in the first device and in devices networked with it; the specific formula content is not limited. In some implementations, the first key information may also be referred to as the shared key corresponding to the identity code associated with the first account.

[0204] Step S403: Determine the first authentication information based on the first key information.

[0205] The communication information generated by encrypting the first key information is identified as the first authentication information. Therefore, the first authentication information represents the identity code associated with the first account.

[0206] Step S404: Send the identity code associated with the first account to the cloud service.

[0207] The first device sends a randomly generated identity code associated with the first account to the cloud service, so that the cloud service can send it to the device bound to the first account and enable the device bound to the first account to obtain the first authentication information. In some implementations, the cloud service authenticates the first account before receiving the identity code associated with the first account to ensure the reliability of the first account.

[0208] Step S405: When the first device and the second device are networking, the first device receives the second authentication information sent by the second device through near-field communication. The second authentication information represents the identity code corresponding to the second account, and the second account is the user account bound to the second device.

[0209] The second authentication information represents the identity code associated with the second account. This identity code is generated by the device logged into the second account and sent to the second device via a cloud service. The second authentication information is communication information encrypted with second key information, which is generated by the second device based on the identity code associated with the second account. The second device receives the identity code associated with the second account from the cloud service, inputs it into a preset key generation formula, and outputs the second key information. Since the second account and the first account may be the same user account or different user accounts, the second key information generated by the first device and the first key information generated by the first device may be the same or different. In some implementations, the first device receives the second authentication information sent by the second device through a preset communication protocol in a preset service.

[0210] Step S406: If the second authentication information matches the first authentication information, it is determined that the first account and the second device have successfully authenticated each other.

[0211] If the second authentication information matches the first authentication information, it means that the first device can decrypt the communication information sent by the second device that is encrypted by the second key information using the first key information. This indicates that the first key information and the second key information are the same. If the identity code used to generate the second authentication information is the same as the identity code used to generate the first authentication information, that is, the second account and the first account are the same user account, then it is determined that the second device is the device bound to the first account. At this time, the identity authentication of the first account and the second device is successful.

[0212] Step S407: If the second authentication information does not match the first authentication information, it is determined that the authentication of the first account and the second device has failed.

[0213] If the second authentication information does not match the first authentication information, it means that the first device cannot decrypt the communication information encrypted by the second device using the first key information. This indicates that the first key information and the second key information are different, and the identity code used to generate the second key information is different from the identity code used to generate the first key information. In other words, the second account and the first account are not the same user account. Therefore, it is determined that the second device is not the device bound to the first account, and the authentication between the first account and the second device fails.

[0214] In this embodiment, the user account assigns an identity code to the bound device through the cloud service. The cloud service authenticates the first account and the device bound to the first account to ensure that only the device logged into the first account and the device bound to the first account know the identity code, which can guarantee the reliability of identity authentication. Furthermore, the identity code is assigned before network connection to provide a guarantee for near-field identity authentication. Offline identity authentication is supported without relying on the external network. Identity authentication can be performed even in scenarios where the external network signal is poor or the external network is unavailable.

[0215] In some embodiments, if the first account and the second device successfully authenticate, it indicates that the second device is the device bound to the first account, meaning that the first account had already bound the second device before authentication. After binding the second device, the first account can either bind the second device on the first device after logging into the first account on the first device and obtaining the binding information of the second device, or it can bind the second device on another device after logging into the first account on another device and obtaining the binding information of the second device after logging into the first account on the first device. The binding information of the second device includes device information, such as at least one of the device identifier, device name, and device type of the second device. Therefore, the first device can obtain the binding information of the second device in the following two ways:

[0216] The first method involves the device logging into the first account on the first device, responding to the binding instruction between the first account and the second device, binding the first account to the second device, obtaining the binding information of the second device, and sending the binding information of the second device to the cloud service.

[0217] A preset application or preset application service in the first device is used to manage bound devices. When the first account is logged into the first device, the first account is also logged into the preset application or preset application service, allowing other devices to be bound through the preset application or preset application service. When the preset application or preset application service receives a binding instruction between the first account and the second device, it executes the binding operation, binding the first account and the second device. The first device then obtains the binding information of the second device and simultaneously sends the binding information of the second device to the cloud service through the preset application or preset application service. This allows the cloud service to send the binding information to the second device, notifying the cloud service and the second device that the first account and the second device have been successfully bound. In some embodiments, after the first account binds the second device, the device information of the second device is initially set to default values. The user can modify and update the device information of the second device through the preset application or preset application service. After receiving the updated device information of the second device, the first device sends the updated device information to the cloud service, allowing the cloud service to send it to the second device.

[0218] The second method involves sending a request to the cloud service to bind the first account to the first device after the first device logs in to the first account; and receiving the binding information of the second device sent by the cloud service.

[0219] After the first device logs into the first account, and the preset application or preset application service also logs into the first account, the first device sends a request for the bound device of the first account to the cloud service through the preset application or preset application service to obtain the binding information of the device already bound to the first account. If, before the first device logs into the first account, another device logged into the first account has already bound the first account to a second device, then after the first device sends the request for the bound device of the first account to the cloud service through the preset application or preset application service, the cloud service will send the binding information of the second device to the first device. After receiving the binding information of the second device, the user can view the device information of the second device in the preset application or preset application service. After the first device obtains the binding information of the second device, when networking with the second device, it can perform identity authentication through near-field communication in this embodiment.

[0220] In one example, after device 1 logs in to account 1 and binds to device 2, both device 1 and device 2 can apply for the first authentication information corresponding to account 1 from the cloud service. Therefore, when device 1 and device 2 are networked, they can perform identity authentication based on the first authentication information of account 1 through near-field communication. After device 3 logs in to account 1, device 3 can also apply for the first authentication information of account 1 from the cloud service and can obtain the bound device of account 1 (i.e., device 3) from the cloud service. Therefore, when device 3 is networked with device 1, it can also perform identity authentication based on the first authentication information of account 1.

[0221] In this embodiment, regardless of whether the first device logs into the first account and binds the second device, or the first account has already bound the second device before the first device logs into the first account, the binding information of the second device can be obtained after logging into the first account on the first device. That is, the bound devices of the first account can be viewed. Based on this, any device that logs into the first account can achieve near-field authentication when networking with the second device, thereby achieving heterogeneous authentication.

[0222] In some embodiments, if the first account and the second device successfully authenticate each other, it means that the second device is the device bound to the first account. In this case, the first account and the second device can be unbound in the following two ways:

[0223] The first method involves the device logging into the first account on the first device, responding to the unbinding instruction received from the first account and the second device, unbinding the first account from the second device, and sending the unbinding information of the second device to the cloud service.

[0224] The unbinding information of the second device includes the device information of the second device, including at least one of the device identifier, device name, and device type of the second device.

[0225] When the first account is logged into on the first device, it is also logged into a preset application or preset application service. The already bound device can then be unbound through the preset application or preset application service. Upon receiving the unbinding command from the first account and the second device, the preset application or preset application service executes the unbinding operation, unbinding the first account from the second device. Simultaneously, the unbinding information of the second device is sent to the cloud service through the preset application or preset application service, so that the cloud service sends the unbinding information to the second device, notifying the cloud service and the second device that the first account and the second device have been unbound. In some implementations, after the first account and the second device are unbound, the device information of the second device stored in the first account is deleted.

[0226] The second method involves sending a request to the cloud service to bind the first account to the first device after the first device logs in to the first account; and receiving the unbinding information for the second device from the cloud service.

[0227] After logging into the first account on the first device, and the preset application or preset application service also logging into the first account, the preset application or preset application service sends a request for the bound device of the first account to the cloud service to obtain the binding information of the device already bound to the first account. If the second device is unbound from another device logged into the first account, after the first device sends the request for the bound device of the first account to the cloud service through the preset application or preset application service, the cloud service will send the unbinding information of the second device to the first device. After receiving the binding information of the second device, the first device can delete the device information of the second device saved in the first account.

[0228] In some implementations, when the number of devices bound to the first account changes, the first device will receive information about the change in the number of devices bound to the first account sent by the cloud service. Even if binding or unbinding operations are performed on other devices logged into the first account, the first device can still be informed of the changes in the number of devices bound to the first account in a timely manner.

[0229] In some implementations, the first device logs into the first account through the account service, binds or unbinds the second device through a preset application or preset application service, and sends the binding or unbinding information to the cloud service. The preset service monitors the login status in the account service and obtains the binding or unbinding information from the cloud service.

[0230] In an exemplary embodiment of this disclosure, an identity authentication method is provided, applied to a second device. FIG5 is a flowchart of an identity authentication method according to an exemplary embodiment. As shown in FIG5, the identity authentication method includes the following steps S501-S502:

[0231] Step S501: After confirming that the second device is bound to the second account, obtain the second authentication information. The second authentication information is associated with the second account and is obtained based on cloud services.

[0232] The second device includes electronic devices such as smart desk lamps, smart speakers, and smart home devices. In some embodiments, the second device may also be called an Internet of Things (IoT) device. The second device does not provide account services and it is impossible to log in to a user account on the second device.

[0233] After a user account binds a device, the user account sends binding information to the device to notify it that the device has been bound. Upon receiving the binding information from the second account, the second device confirms its binding with the second account. At this point, it obtains the second authentication information associated with the second account. This second authentication information is obtained through cloud services. The second authentication information represents information that can be used for identity authentication, such as certificate credentials or communication information encrypted with a shared key. The shared key is generated based on an identity code. The type of authentication information is related to the authentication method; different authentication methods use different types of authentication information. The second authentication information is associated with the second account; that is, the second authentication information is the authentication information corresponding to the second account. The method of obtaining the second authentication information is determined based on its type. For example, if the second authentication information is a certificate credential, it is obtained from a Certificate Authority (CA). If the second authentication information is communication information encrypted with a shared key, the second device generates a shared key corresponding to the identity code and then encrypts the communication information using the shared key. This identity code is generated by the device logged into the second account and then sent to the second device via cloud services.

[0234] In step S502, when the second device and the first device are networking, the second authentication information is sent to the first device via near-field communication so that the first device can authenticate its identity with the second device based on the first authentication information and the second authentication information. The first authentication information is associated with the first account, which is the user account logged in by the first device.

[0235] When the second device discovers the first device through the networking service and forms a network with the first device, it sends second authentication information to the first device via near-field communication (NFC). The NFC method can be any NFC method, such as LAN, Bluetooth, ZigBee, etc. The first device can be any unknown device capable of logging into a user account, such as a smartphone or tablet. The first device contains first authentication information, the type of which is the same as the type of second authentication information. The first authentication information is obtained by the first device, and the method by which the first device obtains the first authentication information is determined by its type. For example, if the authentication information is a certificate credential, the first device obtains the first authentication information from the certificate authority; if the authentication information is communication information encrypted with a shared key, where the shared key is generated based on an identity code, the first device generates the first authentication information. The first authentication information is associated with a first account, which is the user account logged into by the first device. The first account may be the same user account as the second account, or it may not be the same user account as the second account.

[0236] After receiving the second authentication information sent by the second device, the first device performs identity authentication on the second device based on the first and second authentication information. Identity authentication, also known as account authentication or same-account authentication, is used to verify whether the user account bound to the second device is the same user account as the user account logged in on the first device. That is, whether the second account and the first account are the same user account. If the second account and the first account are the same user account, then the second device is the device bound to the first account, and the identity authentication between the first account and the second device is successful. If the second account and the first account are not the same user account, then the second device is not the device bound to the first account, and the identity authentication between the first account and the second device fails.

[0237] In some embodiments, the second device includes a preset service. This preset service is used to acquire second authentication information. When the second device and the first device are networked, the second authentication information is sent to the first device via near-field communication (NFC) so that the first device can authenticate itself with the second device based on the first and second authentication information. The preset service is a custom service capable of implementing the above functions. It sends the second authentication information to the first device through a preset communication protocol and receives the second authentication information sent by the second device through the same preset communication protocol. The preset communication protocol is used to implement NFC, and it is a custom communication protocol capable of implementing the above communication functions.

[0238] In some embodiments, before the second device forms a network for the first time after binding the second account, it needs to perform the above step S501 to obtain the second authentication information and save it in the second device. Therefore, when forming a network for the first time, it is not necessary to obtain the second authentication information again, and only the above step S502 needs to be performed.

[0239] In the exemplary embodiments of this disclosure, the second device obtains second authentication information associated with the second account. When the second device and the first device are networked, the second device sends the second authentication information to the first device via near-field communication (NFC), enabling the first device to authenticate itself with the second device based on the first authentication information associated with the first account and the second authentication information associated with the second account. This method achieves identity authentication during device networking via NFC, supports offline authentication, does not rely on the external network, and can perform identity authentication even in scenarios with poor external network signal or no external network access. Furthermore, compared to cloud authentication, NFC authentication is faster and more secure, improving the user's device interconnection experience.

[0240] In some embodiments, the above embodiments further include: receiving first authentication information sent by the first device via near-field communication; and performing identity authentication with the first device based on the first authentication information and the second authentication information.

[0241] The second device receives the first authentication information sent by the first device via near-field communication. Based on the first and second authentication information, the second device verifies whether the user account logged in on the first device and the user account bound to the second device are the same user account, i.e., whether the first device is the device logged into the second account. This two-way authentication between the first and second devices ensures the security of both devices.

[0242] If the first authentication information matches the second authentication information, the identity authentication of the first account and the second device is confirmed to be successful.

[0243] If the first authentication information does not match the second authentication information, the authentication between the first device and the second device is deemed to have failed.

[0244] If the first authentication information matches the second authentication information, it means that the user account logged in on the first device and the user account bound to the second device are the same user account, i.e., the second account and the first account are the same user account. In this case, it is determined that the first device is the device logged in with the second account, and the identity authentication between the first account and the second device is successful. If the first authentication information does not match the second authentication information, it means that the user account logged in on the first device and the user account bound to the second device are not the same user account, i.e., the second account and the first account are not the same user account. In this case, it is determined that the second device is not the device logged in with the second account, and the identity authentication between the first account and the second device fails. For the specific implementation method of identity authentication, please refer to the above embodiment, specifically steps S205 and S406-S407, which will not be repeated here.

[0245] In an exemplary embodiment of this disclosure, an identity authentication method is provided, applied to a second device. FIG6 is a flowchart of an identity authentication method according to an exemplary embodiment. As shown in FIG6, the identity authentication method includes the following steps S601-S603:

[0246] Step S601: After confirming that the second device is bound to the second account, send the application information for the second authentication information to the cloud service. The second authentication information is a certificate credential issued based on the identity information associated with the second account. The second authentication information is obtained based on the device that logs into the second account.

[0247] If the type of the second authentication information is a certificate credential, the device logged into the second account will generate identity information associated with the second account and designate the cloud service as the certificate issuing authority. The cloud service will issue the corresponding certificate credential based on the identity information associated with the second account and use this certificate credential as the second authentication information. After confirming that the second device is bound to the second account, the second device can send an application for second authentication information to the cloud service to request the second authentication information associated with the second account, i.e., to apply for second authentication information from the cloud service.

[0248] Step S602: Receive the second authentication information sent by the cloud service.

[0249] After receiving the application for second authentication information from the second device, the cloud service will search for the user account bound to the second device in the database. Once it is confirmed that the user account bound to the second device is the second account, the cloud service will send the second authentication information associated with the second account to the second device.

[0250] In some embodiments, the second device further includes a proxy service for transmitting information between the preset service and the cloud service. The preset service sends a request for second authentication information to the cloud service through the proxy service and receives the second authentication information sent by the cloud service through the proxy service. In some embodiments, the proxy service may also be referred to as an OT service or OT channel, used to establish a connection between the preset service in the second device and the cloud service. In some embodiments, the proxy service is also used to authenticate with the cloud service, enabling the cloud service to verify the identity of the second device and ensure that the second device is the device bound to the first account.

[0251] Step S603: When the second device and the first device are networking, the second authentication information is sent to the first device via near-field communication so that the first device can authenticate its identity with the second device based on the first authentication information and the second authentication information. The first authentication information is associated with the first account, which is the user account logged in by the first device.

[0252] In some implementations, the first authentication information includes the account identifier of the first account, and the second authentication information includes the account identifier of the second account. After receiving the second authentication information, if the account identifier of the second account is the same as the account identifier of the first account, the authentication of the first account and the second device is successful; if the account identifier of the second account is different from the account identifier of the first account, the authentication of the first account and the second device fails.

[0253] In this embodiment, a certificate issued by a cloud service is used as authentication information, which can ensure the reliability of the authentication information. Authentication information is obtained before network connection, which provides a guarantee for near-field identity authentication. Offline identity authentication is supported, which does not rely on the external network. Identity authentication can be performed even in scenarios where the external network signal is poor or the external network is unavailable.

[0254] In an exemplary embodiment of this disclosure, an identity authentication method is provided, applied to a second device. FIG7 is a flowchart of an identity authentication method according to an exemplary embodiment. As shown in FIG7, the identity authentication method includes the following steps S701-S706:

[0255] Step S701: After confirming that the second device is bound to the second account, send the application information for the second authentication information to the cloud service. The second authentication information is a certificate credential issued based on the identity information associated with the second account. The second authentication information is obtained based on the device that logs into the second account.

[0256] For a detailed implementation of step S701, please refer to step S601, which will not be repeated here.

[0257] Step S702: Receive the second authentication information sent by the cloud service.

[0258] For a detailed implementation of step S702, please refer to step S602, which will not be repeated here.

[0259] Step S703: When the second device and the first device are networking, the second authentication information is sent to the first device via near-field communication so that the first device can authenticate its identity with the second device based on the first authentication information and the second authentication information. The first authentication information is associated with the first account, which is the user account logged in by the first device.

[0260] For a detailed implementation of step S703, please refer to step S603, which will not be repeated here.

[0261] Step S704: Receive verification information sent by the first device via near-field communication. The verification information is used to verify whether the second device has third authentication information, and the third authentication information is associated with the third device.

[0262] The system receives verification information sent by the first device. This verification information is randomly generated by the first device, and its type and content are not restricted. For example, the verification information may be a random number. This verification information is used to verify whether the second device itself possesses third authentication information. The third authentication information is a device certificate used to characterize the device type. The third authentication information is the device certificate of the second device and is associated with the third device. The third device and the second device may be the same device or they may not be the same device.

[0263] Step S705: Sign the verification information using the second device to obtain signature verification information, and obtain the third authentication information from the second device.

[0264] After receiving the verification information sent by the first device, the second device signs the verification information to obtain signed verification information, and simultaneously obtains third authentication information. Since the third authentication information is a device certificate obtained from the second device, it belongs to the second-level certificate category. In some embodiments, the verification information is signed using a security chip to obtain signed verification information, and the third authentication information is obtained from the security chip. The security chip is a secure element (SE) in the second device, and the type of encryption chip can be any type, such as a MODSEMI chip or a MOD8ID chip.

[0265] Step S706: Send signature verification information and third authentication information to the first device via near-field communication, so that the first device can authenticate the second device based on the signature verification information, the first authentication information and the third authentication information, wherein the first authentication information is also associated with the second device.

[0266] The signature verification information and the third authentication information are sent to the first device. The first device verifies the signature verification information to determine whether the third authentication information was obtained from the second device. After the verification is successful, the root certificate pre-stored in the first device is used to authenticate the third authentication information. If the device identifier of the third device included in the third authentication information is the same as the device identifier of the second device included in the first authentication information, then the second device is the target device type and the device authentication of the second device is successful.

[0267] In some implementations, the second device receives verification information sent by the first device through a preset communication protocol in a preset service. The preset service sends the verification information to the security chip and obtains third authentication information from the security chip. The security chip signs the verification information to obtain signature verification information and returns it to the preset service. The signature verification information and the third authentication information are then sent to the first device through the preset communication protocol in the preset service.

[0268] In this embodiment, in addition to account authentication, strong device type verification is added, that is, device authentication is added. This can avoid data leakage caused by other devices stealing authentication information related to account authentication, and further improve the security of authentication.

[0269] In an exemplary embodiment of this disclosure, an identity authentication method is provided, applied to a second device. FIG8 is a flowchart illustrating an identity authentication method according to an exemplary embodiment. As shown in FIG8, the identity authentication method includes the following steps S801-S804:

[0270] Step S801: After confirming that the second device is bound to the second account, receive the identity code associated with the second account sent by the cloud service. The identity code associated with the second account is generated by the device that logged into the second account.

[0271] The second account may or may not be the same as the first account. The identity code associated with the second account is randomly generated by the device logging into the second account and can be any byte code, such as a 32-byte random code. In some implementations, the identity code may also be called a PIN code. After generating the identity code associated with the second account, the device logging into the second account sends it to the cloud service, which then sends it to the second device.

[0272] In some implementations, an identity code associated with the second account is received through a proxy service. The proxy service is used to establish a connection between the preset service and the cloud service, and to authenticate with the cloud service so that the cloud service can verify the identity of the second device and ensure that the second device is the device bound to the first account.

[0273] Step S802: Based on the identity code associated with the second account, generate second key information. The second key information is used to encrypt or decrypt near-field communication information between the second device and the device logged into the second account.

[0274] The identity code associated with the second account is input into a preset key generation formula, which outputs second key information. This second key information is used to encrypt or decrypt near-field communication information between the second device and the device logged into the second account. The preset key generation formula is pre-stored in the second device and in devices networked with it; the specific formula content is not limited. In some implementations, the second key information may also be referred to as the shared key corresponding to the identity code associated with the second account.

[0275] Step S803: Determine the second authentication information based on the second key information.

[0276] The information generated by encrypting the second key information is identified as the second authentication information. Therefore, the second authentication information represents the identity code associated with the second account.

[0277] Step S804: When the second device and the first device are networking, the second authentication information is sent to the first device via near-field communication, so that the first device can authenticate its identity with the second device based on the first authentication information and the second authentication information.

[0278] The first authentication information represents the identity code associated with the first account. The identity code associated with the first account is generated by the first device, and the first account is the user account logged in by the first device.

[0279] The first device generates first key information based on a randomly generated identity code associated with the first account, and sends the identity code associated with the first account to the device bound to the first account via a cloud service. The method for determining the first authentication information based on the first key information is the same as the method for determining the second authentication information based on the second key information. After the second device sends the second authentication information to the first device through a preset communication protocol in a preset service, the first device verifies whether the second authentication information matches the first authentication information to determine whether the second account and the first account are the same user account, and to determine whether the second device is the device bound to the first device. If the second authentication information matches the first authentication information, that is, the second device can decrypt the communication information encrypted by the first device using the second key information, then the authentication between the first account and the second device is successful; if the second key information does not match the first key information, that is, the second device cannot decrypt the communication information encrypted by the first device using the second key information, then the authentication between the first account and the second device fails.

[0280] In this embodiment, the user account assigns an identity code to the bound device through the cloud service. The cloud service authenticates the user account and the device bound to the user account to ensure that only the device logged into the user account and the device bound to the user account know the identity code, which can guarantee the reliability of identity authentication. Furthermore, the identity code is assigned before network connection to provide a guarantee for near-field identity authentication. Offline identity authentication is supported without relying on the external network. Identity authentication can be performed even in scenarios where the external network signal is poor or the external network is unavailable.

[0281] In some embodiments, before the second device obtains the second authentication information, the above-described embodiments applied to the second device further include the following steps:

[0282] Receive the binding information of the second device sent by the cloud service. The binding information of the second device includes the device information of the second device. The binding information of the second device is sent to the cloud service by the device logged into the second account.

[0283] Confirm that the second device is bound to the second account and save the device information of the second device.

[0284] The binding information of the second device includes the device information of the second device, such as at least one of the device identifier, device name, and device type. After the device logged into the second account binds the second device, it sends the binding information of the second device to the cloud service. The cloud service then sends the binding information of the second device to the second device to notify the cloud service and the second device that the second account and the second device have been successfully bound. Upon receiving the binding information, the second device can confirm that it is bound to the second account and saves the device information. In some implementations, after the second account binds the second device, the device information of the second device is initially set to default values. The user can modify and update the device information of the second device through preset applications or preset application services on the device logged into the second account, and send the updated device information to the second device through the cloud service. Upon receiving the updated device information, the second device saves the updated device information.

[0285] In some embodiments, the above-described implementation of the second device further includes the following steps:

[0286] The unbinding information of the second device received from the cloud service includes the device information of the second device, which is sent to the cloud service by the device logged into the second account.

[0287] Confirm that the second device is unbound from the second account, and delete the saved device information and second authentication information of the second device.

[0288] After a device logged into the second account unbinds itself, it sends the unbinding information to the cloud service. The cloud service then sends the unbinding information back to the second device, notifying both the cloud service and the second device that the second account and the second device are no longer bound. Upon receiving this unbinding information, the second device can confirm that it is unbound from the second account and deletes all saved device information and the second authentication information associated with the second account.

[0289] In this embodiment, after any device logs into the user account bound to the second device, it can obtain the binding information of the second device. Based on this, when the second device is networked with any device that logs into the user account bound to the second device, it can achieve near-field identity authentication, thereby achieving heterogeneous authentication.

[0290] In an exemplary embodiment of this disclosure, an identity authentication method is provided, applied to a cloud service. The identity authentication method includes: after a first device logs into a first account and the first account is bound to a second device, obtaining first authentication information and sending the first authentication information to the second device, wherein the first authentication information is obtained based on the first device.

[0291] The first authentication information is associated with the first account and is used for identity authentication via near-field communication when the first device and the second device are networked.

[0292] After logging into the first account on the first device via the account service, the cloud service learns that the first device has logged into the first account. After the first account is bound to the second device, the first device sends binding information to the cloud service. Upon receiving the binding information, the cloud service learns that the first account is bound to the second device. The first authentication information represents information that can be used for identity authentication, such as certificate credentials or communication information encrypted with a shared key. The shared key is generated based on the identity code, and different user accounts are associated with different authentication information. The first authentication information is associated with the first account; therefore, the first authentication information is obtained from the first device that has logged into the first account. After obtaining the first authentication information, the cloud service sends the first authentication information to the second device bound to the first account. Thus, both the first and second devices possess the first authentication information. When the first and second devices are networked, there is no need to go through the cloud service again; identity authentication between the first and second devices can be achieved directly through near-field communication based on the first authentication information.

[0293] In an exemplary embodiment of this disclosure, an identity authentication method is provided, applied to cloud services. Figure 9 is a flowchart of an identity authentication method according to an exemplary embodiment, including steps S901-S906:

[0294] Step S901: After the first device logs in to the first account and the first account is bound to the second device, the device receives a request for first authentication information sent by the first device. The request information includes the identity information associated with the first account generated by the first device.

[0295] When the type of the first authentication information is a certificate credential, after generating the identity information associated with the first account, the first device sends a request for the first authentication information to the cloud service as the certificate issuing authority of the certificate credential. The request information carries the identity information associated with the first account and is used to request the cloud service to issue a certificate credential based on the identity information associated with the first account.

[0296] Step S902: Issue a certificate credential based on the identity information associated with the first account, and use the certificate credential as the first authentication information.

[0297] In some implementations, the first authentication information includes the account identifier of the first account.

[0298] Step S903: Send the first authentication information to the first device.

[0299] Step S904: Receive the application information for the first authentication information sent by the second device.

[0300] After confirming that it is bound to the first account, the second device sends an application for the first authentication information to the cloud service to request the first authentication information associated with the first account.

[0301] Step S905: Match the first account bound to the second device from the bound device mapping relationship. The bound device mapping relationship represents the mapping relationship between the user account and the device bound to it.

[0302] The cloud service stores a device binding mapping relationship to record the mapping relationship between user accounts and their bound devices. For example, if a first account is mapped to a second device, it means that the first account is bound to the second device. After receiving the first authentication information request information sent by the second device, the cloud service looks up the user account bound to the second device in the device binding mapping relationship table, which is the first account. In some implementations, the device binding mapping relationship is a mapping relationship between the user account's account identifier and the device identifier of the bound device. The first authentication information request information sent by the second device carries the device identifier of the second device. The cloud service matches the corresponding user account's account identifier in the device binding mapping relationship based on the device identifier of the second device, which is the account identifier of the first account.

[0303] Step S906: Send the first authentication information associated with the first account to the second device.

[0304] After determining that the second device is bound to the first account, the cloud service sends the first authentication information associated with the first account to the second device.

[0305] It should be noted that when the cloud service receives the first authentication information application from the first device, it will authenticate the first account to ensure the reliability of the first account. Only after the authentication is successful will the cloud service send the first authentication information to the first device. When the cloud service receives the first authentication information application from the second device, it will authenticate the second device to ensure that the second device is the device bound to the first account. Only after the authentication is successful will the cloud service send the first authentication information to the second device.

[0306] In this embodiment, a certificate issued by a cloud service is used as authentication information, which can ensure the reliability of the authentication information. The authentication information is issued after the first device logs into the first account and the first account is bound to the second device, thus providing a guarantee for near-field identity authentication when devices are networked.

[0307] In an exemplary embodiment of this disclosure, an identity authentication method is provided, applied to a cloud service. The identity authentication method includes: after a first device logs into a first account and the first account is bound to a second device, receiving an identity code associated with the first account sent by the first device, and sending the identity code associated with the first account to the second device.

[0308] The identity code associated with the first account is randomly generated by the first device and can be any byte code, such as a 32-byte random code. In some implementations, the identity code can also be a PIN code. The identity code associated with the first account is used to generate key information, which is used to encrypt or decrypt near-field communication information between the first device and the second device. During identity authentication, the matching of the key information generated by the first device and the key information generated by the second device is used to verify whether the second device is the device bound to the first account.

[0309] It should be noted that when the cloud service receives the identity code associated with the first account from the first device, it will authenticate the first account to ensure its reliability. When the cloud service sends the identity code associated with the first account to the second device, it will authenticate the second device to ensure that the second device is the device bound to the first account.

[0310] In some embodiments, before obtaining the first authentication information, the above-described embodiments applied to cloud services further include the following steps:

[0311] In response to receiving the binding information of the second device sent by the first device, the binding information of the second device is sent to the second device, and the mapping relationship between the first account and the second device is added to the binding device mapping relationship;

[0312] or,

[0313] In response to receiving a request from the first device for the binding device of the first account, the system retrieves the second device bound to the first account from the binding device mapping relationship and sends the binding information of the second device to the first device.

[0314] The binding information of the second device includes device information such as at least one of the device identifier, device name, and device type. The binding device mapping relationship represents the mapping relationship between a user account and the device it is bound to. If the cloud service receives the binding information of the second device from the first device, it indicates that the binding operation was performed after the first device logged into the first account. Simultaneously, the cloud service learns that the first account and the second device are successfully bound, and adds the mapping relationship between the first account and the second device to the binding device mapping relationship table. For example, it records the account identifier of the first account and the device identifier of the second device in the binding device mapping relationship table. At the same time, it sends the binding information of the second device to the second device to notify the second device that the binding with the first account is successful. In some implementations, upon receiving updated device information of the second device from the first device, the cloud service forwards the updated device information to the second device. If the cloud service receives a request from the first device for binding a device to the first account, it indicates that the binding operation was performed after another device logged into the first account. In this case, it searches the binding device mapping relationship to find which devices the first account is bound to, determines that the first account is bound to the second device, and then sends the binding information of the second device to the first device.

[0315] In some embodiments, the above-described implementation of cloud services further includes the following steps:

[0316] In response to receiving the unbinding information of the second device sent by the first device, the system sends the unbinding information of the second device to the second device and deletes the mapping relationship between the first account and the second device in the binding device mapping relationship;

[0317] or,

[0318] In response to receiving a request from the first device to bind the first account to a second device, the device sends a request to the first device to unbind the second device.

[0319] The unbinding information for the second device includes the device information of the second device, such as at least one of the device identifier, device name, and device type. The device binding mapping relationship represents the mapping relationship between a user account and the device bound to it. If the cloud service receives the unbinding information for the second device from the first device, it indicates that the unbinding operation was performed after the first device logged into the first account. Simultaneously, the cloud service learns that the first account and the second device are unbound and deletes the mapping relationship between the first account and the second device from the device binding mapping relationship table, for example, by deleting the device identifier of the second device from the table. At the same time, it sends the unbinding information for the second device to the second device to notify it of the unbinding from the first account. If the cloud service receives a request from the first device for the first account to bind to a device, it indicates that the unbinding operation was performed after another device logged into the first account. In this case, the cloud service sends the unbinding information for the second device received from the other device to the first device.

[0320] In some implementations, after the bound devices of the first account in the bound device mapping relationship change, such as binding a new device or unbinding an existing device, the cloud service will send the first device the information on the change in the number of bound devices of the first account. Even if the binding or unbinding operation is performed on other devices logged into the first account, the first device can be informed of the change in the bound devices of the first account in a timely manner.

[0321] In an exemplary embodiment of this disclosure, an identity authentication method is provided. Figure 10 is an interactive flowchart of an identity authentication method according to an exemplary embodiment. As shown in Figure 10, the method includes the following steps S1001-S1004:

[0322] Step S1001: After logging into the first account on the first device, the first device obtains the first authentication information, which is then associated with the first account.

[0323] In step S1002, after confirming that the second device is bound to the second account, it obtains the second authentication information, which is then associated with the second account.

[0324] Step S1003: When the first device and the second device form a network, the second device sends the second authentication information to the first device via near-field communication.

[0325] In step S1004, the first device performs identity authentication with the second device based on the first authentication information and the second authentication information.

[0326] The specific implementation methods for each step are described in the foregoing embodiments and will not be repeated here.

[0327] In an exemplary embodiment of this disclosure, an identity authentication method is provided. Figure 11 is an interactive flowchart of an identity authentication method according to an exemplary embodiment. As shown in Figure 11, the method includes the following steps S1101-S1110:

[0328] Step S1101: After logging into the first account on the first device, the first device generates the identity information associated with the first account;

[0329] Step S1102: The first device sends a request for first authentication information to the cloud service. The request information includes the identity information associated with the first account.

[0330] Step S1103: The cloud service issues a certificate credential based on the identity information associated with the first account, and uses the certificate credential as the first authentication information, which includes the account identifier of the first account.

[0331] Step S1104: The cloud service sends the first authentication information to the first device;

[0332] In step S1105, after the second device is confirmed to be bound to the second account, the second device sends the application information for the second authentication information to the cloud service. The second authentication information is a certificate credential issued based on the identity information associated with the second account. The second authentication information includes the account identifier of the second account and is obtained based on the device that logs in to the second account.

[0333] Step S1106: The cloud service matches the second account bound to the second device from the bound device mapping relationship. The bound device mapping relationship represents the mapping relationship between the user account and the device bound to it.

[0334] Step S1107: The cloud service sends the second authentication information associated with the second account to the second device;

[0335] In step S1108, when the first device and the second device are networking, the second device sends the second authentication information to the first device through near-field communication, and the first device sends the first authentication information to the second device through near-field communication.

[0336] Step S1109: If the account identifier of the second account is the same as the account identifier of the first account, the first device confirms that the identity authentication between the first account and the second device is successful.

[0337] Step S1110: If the account identifier of the second account is different from the account identifier of the first account, the first device determines that the identity authentication between the first account and the second device has failed.

[0338] Step S1111: If the account identifier of the second account is the same as the account identifier of the first account, the second device is confirmed to have successfully authenticated with the first device.

[0339] In step S1112, if the account identifier of the second account is different from that of the first account, the second device is determined to have failed to authenticate with the first device.

[0340] The specific implementation methods for each step are described in the foregoing embodiments and will not be repeated here.

[0341] In an exemplary embodiment of this disclosure, an identity authentication method is provided. Figure 12 is an interactive flowchart of an identity authentication method according to an exemplary embodiment. If the first device determines that the first account and the second device have successfully authenticated their identities, steps S1201-S1204 as shown in Figure 12 are executed:

[0342] In step S1201, the first device sends verification information to the second device via near-field communication. The verification information is used to verify whether the second device has third authentication information, and the third authentication information is associated with the third device.

[0343] Step S1202: The second device signs the verification information to obtain the signature verification information, and obtains the third authentication information from the second device;

[0344] In step S1203, the second device sends signature verification information and third authentication information to the first device via near-field communication.

[0345] In step S1204, the first device performs device authentication on the second device based on the signature verification information, the first authentication information, and the third authentication information.

[0346] In some implementations, the first authentication information also includes the device identifier of the second device, and the third authentication information includes the device identifier of the third device. If the signature verification information is verified successfully and the device identifier of the third device is the same as the device identifier of the second device, the first device determines that the device authentication of the second device is successful; if the signature verification information is not verified successfully, or the device identifier of the third device is different from the device identifier of the second device, the first device determines that the device authentication of the second device is unsuccessful.

[0347] In an exemplary embodiment of this disclosure, an identity authentication method is provided. Figure 13 is an interactive flowchart of an identity authentication method according to an exemplary embodiment. As shown in Figure 13, the method includes the following steps S1301-S1310:

[0348] Step S1301: After logging into the first account on the first device, the first device randomly generates an identity code associated with the first account;

[0349] Step S1302: The first device sends the identity code associated with the first account to the cloud service;

[0350] Step S1303: The first device generates first key information based on the identity code associated with the first account. The first key information is used to encrypt or decrypt near-field communication information between the first device and the device bound to the first account.

[0351] Step S1304: The first device determines the first authentication information based on the first key information;

[0352] Step S1305: After the second account is bound to the second device, the cloud service sends the identity code associated with the second account to the second device. The identity code associated with the second account is generated by the device that logged in to the second account.

[0353] Step S1306: The second device generates second key information based on the identity code associated with the second account. The second key information is used to encrypt or decrypt near-field communication information between the second device and the device logged into the second account.

[0354] Step S1307: The second device determines the second authentication information based on the second key information;

[0355] In step S1308, when the first device and the second device are networking, the second device sends the second authentication information to the first device through near-field communication, and the first device sends the first authentication information to the second device through near-field communication.

[0356] Step S1309: If the second authentication information matches the first authentication information, the first device determines that the first account and the second device have successfully authenticated their identities.

[0357] Step S1310: If the second authentication information does not match the first authentication information, the first device determines that the authentication between the first account and the second device has failed.

[0358] Step S1311: If the second authentication information matches the first authentication information, the second device is confirmed to have successfully authenticated with the first device.

[0359] In step S1312, if the second authentication information does not match the first authentication information, the second device determines that the authentication with the first device has failed.

[0360] In some embodiments, if the first account and the second device successfully authenticate each other, it means that the second device is the device bound to the first account, that is, the first account was bound to the second device before the authentication. Figure 14 is an interactive flowchart of the first account binding to the second device according to an exemplary embodiment. As shown in Figure 14, it includes the following steps S1401-S1408:

[0361] Step S1401: After logging into the first account on the first device, in response to receiving the binding instruction between the first account and the second device, the first device binds the first account to the second device and obtains the binding information of the second device;

[0362] The binding information of the second device includes the device information of the second device;

[0363] Step S1402: The first device sends the binding information of the second device to the cloud service;

[0364] Step S1403: The cloud service adds a mapping relationship between the first account and the second device in the bound device mapping relationship. The bound device mapping relationship represents the mapping relationship between a user account and the device bound to it.

[0365] Step S1404: The cloud service sends the binding information of the second device to the second device;

[0366] Step S1405: The second device is confirmed to be bound to the first account, and the device information of the second device is saved;

[0367] Step S1406: The first device sends the updated device information of the second device to the cloud service;

[0368] Step S1407: The cloud service sends the updated device information of the second device to the second device;

[0369] Step S1408: The second device saves the updated device information of the second device.

[0370] In some embodiments, FIG15 is a flowchart illustrating the interaction of unbinding a first account from a second device according to an exemplary embodiment, as shown in FIG15, including the following steps S1501-S1505:

[0371] Step S1501: After logging into the first account on the first device, in response to receiving the unbinding instruction between the first account and the second device, the first device unbinds the first account from the second device.

[0372] Step S1502: The first device sends the unbinding information of the second device to the cloud service;

[0373] Step S1503: The cloud service deletes the mapping relationship between the first account and the second device in the bound device mapping relationship;

[0374] Step S1504: The cloud service sends the unbinding information of the second device to the second device;

[0375] In step S1505, the second device is confirmed to be unbound from the first account, and the saved device information and first authentication information of the second device are deleted. The first authentication information is obtained by binding the second device to the first account and saved on the second device.

[0376] In one exemplary embodiment, an identity authentication method is provided. Figure 16 is a schematic diagram of an identity authentication method according to an exemplary embodiment. As shown in Figure 16, a first device logs into a first account through an account service. After a preset service listens to the login information of the first account, it requests the authentication information of the first account from the account cloud. The first device logs into the first account through a preset application and performs the operation of binding a second device. After successful binding, the binding information of the second device is sent to the application cloud corresponding to the preset application. The application cloud synchronizes the binding information to the account cloud and simultaneously sends the binding information to the proxy service of the second device. After receiving the binding information, the proxy service of the second device forwards it to the preset service of the second device. After receiving the binding information, the preset service requests the authentication information of the first account from the application cloud through the proxy service, and then the application cloud requests the authentication information of the first account from the account cloud. Thus, both the preset service of the first device and the preset service of the second device can obtain the authentication information of the first account from the cloud service. When the first device and the second device are networked, the second device can successfully authenticate itself with the first device based on the authentication information. In addition, after the first account binds a new device or unbinds an existing device, the cloud service sends the information on the change in the number of bound devices to the first device logged into the first account. Even if binding or unbinding operations are performed on other devices logged into the first account, the first device can be informed of the changes in the bound devices of the first account in a timely manner.

[0377] In an exemplary embodiment of this disclosure, an identity authentication device is provided. FIG17 is a block diagram of an identity authentication device according to an exemplary embodiment. As shown in FIG17, the identity authentication device includes:

[0378] The processing module 1701 is configured to obtain first authentication information after the first device logs in to the first account. The first authentication information is associated with the first account and is used to send the first authentication information to the device bound to the first account via cloud service.

[0379] The transceiver module 1702 is configured to receive second authentication information sent by the second device via near-field communication when the first device and the second device are networked. The second authentication information is associated with a second account, which is a user account bound to the second device.

[0380] The authentication module 1703 is configured to perform identity authentication with the second device based on the first authentication information and the second authentication information.

[0381] In one exemplary embodiment, the authentication module 1703 is further configured to:

[0382] If the first authentication information matches the second authentication information, the identity authentication of the first account and the second device is confirmed to be successful.

[0383] If the first authentication information does not match the second authentication information, the authentication of the first account and the second device is deemed to have failed.

[0384] In one exemplary embodiment, the first device includes a preset service, and the transceiver module 1702 is further configured to:

[0385] The system receives the second authentication information sent by the second device through the preset communication protocol in the preset service. The preset communication protocol is used to implement near-field communication.

[0386] In an exemplary embodiment, the first authentication information is a certificate credential issued based on the identity information associated with the first account; the processing module 1701 is further configured to:

[0387] Generate the identity information associated with the first account;

[0388] Send a request to the cloud service for the first authentication information, which includes the identity information associated with the first account;

[0389] Receive the first authentication information sent by the cloud service.

[0390] In one exemplary embodiment, the first authentication information includes the account identifier of the first account, and the second authentication information includes the account identifier of the second account; the authentication module 1703 is further configured to:

[0391] If the account identifier of the second account is the same as that of the first account, the identity authentication between the first account and the second device is confirmed to be successful.

[0392] If the account identifier of the second account is different from that of the first account, it is determined that the authentication between the first account and the second device has failed.

[0393] In one exemplary embodiment, the first authentication information is also associated with the second device after the first device and the second device have successfully authenticated each other;

[0394] The transceiver module 1702 is also configured to send verification information to the second device via near-field communication. The verification information is used to verify whether the second device has third authentication information, and the third authentication information is associated with the third device. The transceiver module 1702 is also configured to receive signature verification information and third authentication information sent by the second device via near-field communication. The signature verification information is information obtained by signing the verification information.

[0395] The authentication module 1703 is also configured to authenticate the second device based on signature verification information, first authentication information, and third authentication information.

[0396] In an exemplary embodiment, the first authentication information includes the device identifier of the second device, and the third authentication information includes the device identifier of the third device; the authentication module 1703 is further configured to:

[0397] If the signature verification information passes the verification and the device identifier of the third device is the same as that of the second device, the device authentication of the second device is confirmed to be successful.

[0398] If the signature verification fails, or if the device identifier of the third device is different from that of the second device, the device authentication of the second device is determined to have failed.

[0399] In an exemplary embodiment, the first authentication information represents the identity code associated with the first account, and the second authentication information represents the identity code associated with the second account; the processing module 1701 is further configured to:

[0400] Randomly generate an identity code associated with the first account and send the identity code associated with the first account to the cloud service;

[0401] Based on the identity code associated with the first account, a first key information is generated. The first key information is used to encrypt or decrypt near-field communication information between the first device and the device bound to the first account.

[0402] Based on the first key information, the first authentication information is determined.

[0403] In an exemplary embodiment, if the first account and the second device successfully authenticate each other, before the first device and the second device form a network, the processing module 1701 is further configured to:

[0404] After logging into the first account on the first device, in response to receiving the binding instruction between the first account and the second device, the first account is bound to the second device, the binding information of the second device is obtained, and the binding information of the second device is sent to the cloud service;

[0405] or,

[0406] After logging into the first account on the first device, a request for the first account to be bound to the cloud service is sent.

[0407] Receive binding information for the second device sent by the cloud service;

[0408] The binding information of the second device includes the device information of the second device.

[0409] In an exemplary embodiment, if the first account and the second device successfully authenticate each other, the processing module 1701 is further configured to:

[0410] After logging into the first account on the first device, in response to receiving the unbinding instruction between the first account and the second device, the first account is unbound from the second device, and the unbinding information of the second device is sent to the cloud service;

[0411] or,

[0412] After logging into the first account on the first device, a request for the first account to be bound to the cloud service is sent.

[0413] Receive unbinding information for the second device sent by the cloud service;

[0414] The unbinding information for the second device includes the device information of the second device.

[0415] In one exemplary embodiment, the processing module 1701 is further configured to:

[0416] Receive information from the cloud service regarding changes in the number of devices bound to the first account.

[0417] In one exemplary embodiment, the transceiver module 1702 is further configured to:

[0418] The first authentication information is sent to the second device via near-field communication, so that the second device can authenticate its identity with the first device based on the first authentication information and the second authentication information.

[0419] In an exemplary embodiment of this disclosure, an identity authentication device is provided. FIG18 is a block diagram two of an identity authentication device according to an exemplary embodiment. As shown in FIG18, the identity authentication device includes:

[0420] The processing module 1801 is configured to obtain second authentication information after determining that the second device is bound to the second account. The second authentication information is associated with the second account and is obtained based on cloud services.

[0421] The transceiver module 1802 is configured to send second authentication information to the first device via near-field communication when the second device and the first device are networked, so that the first device can authenticate its identity with the second device based on the first authentication information and the second authentication information. The first authentication information is associated with a first account, which is the user account logged in by the first device.

[0422] In one exemplary embodiment, the second device includes a preset service, and the transceiver module 1802 is further configured to:

[0423] The second authentication information is sent to the first device through the preset communication protocol in the preset service. The preset communication protocol is used to realize near-field communication.

[0424] In one exemplary embodiment, the second device further includes a proxy service for transmitting information between a preset service and a cloud service.

[0425] In an exemplary embodiment, the second authentication information is a certificate credential issued based on the identity information associated with the second account; the processing module 1801 is further configured to:

[0426] After confirming that the second device is bound to the second account, an application for second authentication information is sent to the cloud service. The second authentication information is obtained based on the device logged into the second account.

[0427] Receive the second authentication information sent by the cloud service.

[0428] In one exemplary embodiment,

[0429] The transceiver module 1802 is also configured to receive verification information sent by the first device via near-field communication. The verification information is used to verify whether the second device has third authentication information, and the third authentication information is associated with the third device.

[0430] The processing module 1801 is also configured to sign the verification information through the second device, obtain the signature verification information, and obtain the third authentication information from the second device;

[0431] The transceiver module 1802 is also configured to send signature verification information and third authentication information to the first device via near-field communication, so that the first device can authenticate the second device based on the signature verification information, the first authentication information and the third authentication information, wherein the first authentication information is also associated with the second device.

[0432] In one exemplary embodiment, the second authentication information represents the identity code associated with the second account; the processing module 1801 is further configured to:

[0433] Receive the identity code associated with the second account sent by the cloud service. The identity code associated with the second account is generated by the device that logs in to the second account.

[0434] Based on the identity code associated with the second account, a second key information is generated. The second key information is used to encrypt or decrypt near-field communication information between the second device and the device logged into the second account.

[0435] Based on the second key information, the second authentication information is determined.

[0436] In one exemplary embodiment, before obtaining the second authentication information, the processing module 1801 is further configured to:

[0437] Receive the binding information of the second device sent by the cloud service. The binding information of the second device includes the device information of the second device. The binding information of the second device is sent to the cloud service by the device logged into the second account.

[0438] Confirm that the second device is bound to the second account and save the device information of the second device.

[0439] In one exemplary embodiment, the processing module 1801 is further configured to:

[0440] Receive unbinding information of the second device sent by the cloud service. The unbinding information of the second device includes the device information of the second device. The unbinding information of the second device is sent to the cloud service by the device logged into the second account.

[0441] Confirm that the second device is unbound from the second account, and delete the saved device information and second authentication information of the second device.

[0442] In one exemplary embodiment,

[0443] The transceiver module 1802 is also configured to receive the first authentication information sent by the first device via near-field communication.

[0444] The authentication module 1803 is configured to perform identity authentication with the first device based on the first authentication information and the second authentication information.

[0445] In an exemplary embodiment of this disclosure, an identity authentication device is provided. FIG19 is a block diagram three of an identity authentication device according to an exemplary embodiment. As shown in FIG19, the identity authentication device includes:

[0446] The processing module 1901 is configured to obtain first authentication information and send the first authentication information to the second device after the first device logs in to the first account and the first account is bound to the second device. The first authentication information is obtained based on the first device.

[0447] The first authentication information is associated with the first account and is used for identity authentication via near-field communication when the first device and the second device are networked.

[0448] In one exemplary embodiment, the processing module 1901 is further configured to:

[0449] The request information for receiving first authentication information sent by the first device includes identity information associated with the first account generated by the first device.

[0450] Certificate credentials are issued based on the identity information associated with the first account, and the certificate credentials are used as the first authentication information.

[0451] Send the first authentication information to the first device.

[0452] In one exemplary embodiment, the processing module 1901 is further configured to:

[0453] Receive the application information for the first authentication information sent by the second device;

[0454] Match the first account bound to the second device from the bound device mapping relationship. The bound device mapping relationship represents the mapping relationship between a user account and the device bound to it.

[0455] Send the first authentication information associated with the first account to the second device.

[0456] In one exemplary embodiment, the processing module 1901 is further configured to:

[0457] Receive the identity code associated with the first account sent by the first device;

[0458] Send the identity code associated with the first account to the second device.

[0459] In one exemplary embodiment, before obtaining the first authentication information, the processing module 1901 is further configured to:

[0460] In response to receiving the binding information of the second device sent by the first device, the binding information of the second device is sent to the second device, and the mapping relationship between the first account and the second device is added to the binding device mapping relationship;

[0461] or,

[0462] In response to receiving a request from the first device for the binding device of the first account, the system retrieves the second device bound to the first account from the binding device mapping relationship and sends the binding information of the second device to the first device.

[0463] The binding information of the second device includes the device information of the second device, and the binding device mapping relationship represents the mapping relationship between the user account and the device bound to it.

[0464] In one exemplary embodiment, the processing module 1901 is further configured to:

[0465] In response to receiving the unbinding information of the second device sent by the first device, the system sends the unbinding information of the second device to the second device and deletes the mapping relationship between the first account and the second device in the binding device mapping relationship;

[0466] or,

[0467] In response to receiving a request from the first device to bind the first account to a second device, the device sends the unbinding information of the second device to the first device.

[0468] Among them, the bound device mapping relationship represents the mapping relationship between a user account and the device bound to it, and the unbinding information of the second device includes the device information of the second device.

[0469] In one exemplary embodiment, the processing module 1901 is further configured to:

[0470] Send the number of devices bound to the first account to the first device.

[0471] Regarding the apparatus in the above embodiments, the specific manner in which each module performs its operation has been described in detail in the embodiments related to the method, and will not be elaborated upon here.

[0472] Figure 20 is a block diagram illustrating an electronic device 2000 according to an exemplary embodiment.

[0473] Referring to FIG20, the electronic device 2000 may include one or more of the following components: processing component 2002, memory 2004, power supply component 2006, multimedia component 2008, audio component 2010, input / output (I / O) interface 2012, sensor component 2014, and communication component 2016.

[0474] Processing component 2002 typically controls the overall operation of electronic device 2000, such as operations associated with display, telephone calls, data communication, camera operation, and recording operations. Processing component 2002 may include one or more processors 2020 to execute instructions to complete all or part of the steps of the methods described above. Furthermore, processing component 2002 may include one or more modules to facilitate interaction between processing component 2002 and other components. For example, processing component 2002 may include a multimedia module to facilitate interaction between multimedia component 2008 and processing component 2002.

[0475] Memory 2004 is configured to store various types of data to support the operation of electronic device 2000. Examples of this data include instructions for any application or method operating on electronic device 2000, contact data, phonebook data, messages, pictures, videos, etc. Memory 2004 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.

[0476] Power supply component 2006 provides power to various components of electronic device 2000. Power supply component 2006 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to electronic device 2000.

[0477] Multimedia component 2008 includes a screen that provides an output interface between the electronic device 2000 and the user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen may be implemented as a touchscreen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors may sense not only the boundaries of the touch or swipe action but also the duration and pressure associated with the touch or swipe operation. In some embodiments, multimedia component 2008 includes a front-facing camera and / or a rear-facing camera. When the electronic device 2000 is in an operating mode, such as a shooting mode or a video mode, the front-facing camera and / or the rear-facing camera may receive external multimedia data. Each front-facing camera and rear-facing camera may be a fixed optical lens system or have focal length and optical zoom capabilities.

[0478] Audio component 2010 is configured to output and / or input audio signals. For example, audio component 2010 includes a microphone (MIC) configured to receive external audio signals when electronic device 2000 is in an operating mode, such as call mode, recording mode, and voice recognition mode. The received audio signals may be further stored in memory 2004 or transmitted via communication component 2016. In some embodiments, audio component 2010 also includes a speaker for outputting audio signals.

[0479] I / O interface 2012 provides an interface between processing component 2002 and peripheral interface modules, such as keyboards, click wheels, buttons, etc. These buttons may include, but are not limited to, home buttons, volume buttons, start buttons, and lock buttons.

[0480] Sensor assembly 2014 includes one or more sensors for providing state assessments of various aspects of electronic device 2000. For example, sensor assembly 2014 can detect the on / off state of electronic device 2000, the relative positioning of components such as the display and keypad of electronic device 2000, changes in position of electronic device 2000 or a component of electronic device 2000, the presence or absence of user contact with electronic device 2000, the orientation or acceleration / deceleration of electronic device 2000, and temperature changes of electronic device 2000. Sensor assembly 2014 may include a proximity sensor configured to detect the presence of nearby objects without any physical contact. Sensor assembly 2014 may also include a light sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, sensor assembly 2014 may also include an accelerometer, gyroscope, magnetometer, pressure sensor, or temperature sensor.

[0481] The communication component 2016 is configured to facilitate wired or wireless communication between the electronic device 2000 and other devices. The electronic device 2000 can access wireless networks based on communication standards, such as WiFi, 2G, or 3G, or combinations thereof. In one exemplary embodiment, the communication component 2016 receives broadcast signals or broadcast-related information from an external broadcast management system via a broadcast channel. In one exemplary embodiment, the communication component 2016 also includes a near-field communication (NFC) module to facilitate short-range communication. For example, the NFC module may be implemented based on radio frequency identification (RFID) technology, Infrared Data Association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology, and other technologies.

[0482] In an exemplary embodiment, the electronic device 2000 may be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the methods described above.

[0483] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 2004 including instructions, which can be executed by a processor 2020 of an electronic device 2000 to perform the above-described method. For example, the non-transitory computer-readable storage medium may be a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device, etc.

[0484] A non-transitory computer-readable storage medium, when instructions in the storage medium are executed by a processor of an electronic device, enables the electronic device to perform an authentication method, including any of the methods described above.

[0485] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the following claims.

[0486] It should be understood that this disclosure is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this disclosure is limited only by the appended claims.

Claims

1. An identity authentication method, characterized in that, The method includes: after logging into a first account on a first device, obtaining first authentication information, the first authentication information being associated with the first account and used to send the first authentication information to the device bound to the first account via a cloud service; when the first device and a second device are networked, receiving second authentication information sent by the second device via near-field communication, the second authentication information being associated with a second account, the second account being a user account bound to the second device; and performing identity authentication with the second device based on the first authentication information and the second authentication information.

2. The identity authentication method according to claim 1, characterized in that, The step of authenticating the identity with the second device based on the first authentication information and the second authentication information includes: if the first authentication information matches the second authentication information, determining that the first account and the second device have successfully authenticated; if the first authentication information does not match the second authentication information, determining that the first account and the second device have failed to authenticate.

3. The identity authentication method according to claim 1 or 2, characterized in that, The first device includes a preset service. Receiving the second authentication information sent by the second device via near-field communication includes: receiving the second authentication information sent by the second device via a preset communication protocol in the preset service. The preset communication protocol is used to implement near-field communication.

4. The identity authentication method according to claim 1, characterized in that, The first authentication information is a certificate issued based on the identity information associated with the first account; The step of obtaining the first authentication information includes: generating identity information associated with the first account; sending a request for the first authentication information to a cloud service, the request information including the identity information associated with the first account; and receiving the first authentication information sent by the cloud service.

5. The identity authentication method according to claim 4, characterized in that, The first authentication information includes the account identifier of the first account, and the second authentication information includes the account identifier of the second account; The step of authenticating the identity with the second device based on the first authentication information and the second authentication information includes: if the account identifier of the second account is the same as the account identifier of the first account, it is determined that the identity authentication between the first account and the second device is successful; If the account identifier of the second account is different from that of the first account, it is determined that the authentication between the first account and the second device has failed.

6. The identity authentication method according to claim 4, characterized in that, The method further includes: the first authentication information is also associated with the second device; after the first device and the second device successfully authenticate each other, verification information is sent to the second device via near-field communication, the verification information being used to verify whether the second device has third authentication information, the third authentication information being associated with the third device; receiving signature verification information and the third authentication information sent by the second device via near-field communication, the signature verification information being information obtained by signing the verification information; and performing device authentication on the second device based on the signature verification information, the first authentication information, and the third authentication information.

7. The identity authentication method according to claim 6, characterized in that, The first authentication information includes the device identifier of the second device, and the third authentication information includes the device identifier of the third device; The step of authenticating the second device based on the signature verification information, the first authentication information, and the third authentication information includes: if the signature verification information is verified successfully and the device identifier of the third device is the same as the device identifier of the second device, the second device is determined to be successfully authenticated; if the signature verification information is not verified successfully, or the device identifier of the third device is different from the device identifier of the second device, the second device is determined to be unauthenticated.

8. The identity authentication method according to claim 1 or 2, characterized in that, The first authentication information represents the identity code associated with the first account, and the second authentication information represents the identity code associated with the second account; The step of obtaining the first authentication information includes: randomly generating an identity code associated with the first account; generating first key information based on the identity code associated with the first account, wherein the first key information is used to encrypt or decrypt near-field communication information between the first device and the device bound to the first account; and determining the first authentication information based on the first key information. The method further includes: sending the identity code associated with the first account to a cloud service.

9. The identity authentication method according to claim 1, characterized in that, The method further includes: if the first account and the second device successfully authenticate each other, before the first device and the second device form a network, after the first device logs in to the first account, in response to receiving the binding instruction between the first account and the second device, binding the first account to the second device, obtaining the binding information of the second device, and sending the binding information of the second device to the cloud service; or, after the first device logs in to the first account, sending the request information for binding the first account to the cloud service; receiving the binding information of the second device sent by the cloud service; wherein, the binding information of the second device includes the device information of the second device.

10. The identity authentication method according to claim 1, characterized in that, If the first account and the second device successfully authenticate each other, the method further includes: after the first device logs into the first account, in response to receiving the unbinding instruction between the first account and the second device, unbinding the first account from the second device and sending the unbinding information of the second device to the cloud service; or, after the first device logs into the first account, sending the request information of the bound device of the first account to the cloud service; receiving the unbinding information of the second device sent by the cloud service; wherein the unbinding information of the second device includes the device information of the second device.

11. The identity authentication method according to claim 10, characterized in that, The method further includes: receiving information on changes in the number of devices bound to the first account sent by the cloud service.

12. The identity authentication method according to claim 1, characterized in that, The method further includes: sending the first authentication information to the second device via near-field communication, so that the second device can perform identity authentication with the first device based on the first authentication information and the second authentication information.

13. An identity authentication method, characterized in that, The method includes: after determining that the second device is bound to the second account, obtaining second authentication information, the second authentication information being associated with the second account, and the second authentication information being obtained based on cloud services; when the second device and the first device are networked, sending the second authentication information to the first device via near-field communication, so that the first device can perform identity authentication with the second device based on the first authentication information and the second authentication information, wherein the first authentication information is associated with the first account, and the first account is the user account logged in by the first device.

14. The identity authentication method according to claim 13, characterized in that, The second device includes a preset service. Sending the second authentication information to the first device via near-field communication includes sending the second authentication information to the first device via a preset communication protocol in the preset service. The preset communication protocol is used to implement near-field communication.

15. The identity authentication method according to claim 14, characterized in that, The second device also includes a proxy service, which is used to transmit information between the preset service and the cloud service.

16. The authentication method according to any one of claims 13-15, characterized in that, The second authentication information is a certificate issued based on the identity information associated with the second account; The step of obtaining the second authentication information includes: after determining that the second device is bound to the second account, sending an application for the second authentication information to the cloud service, wherein the second authentication information is obtained based on the device logged into the second account; and receiving the second authentication information sent by the cloud service.

17. The identity authentication method according to claim 16, characterized in that, The method further includes: receiving verification information sent by the first device via near-field communication, the verification information being used to verify whether the second device has third authentication information, the third authentication information being associated with the third device; signing the verification information via the second device to obtain signature verification information, and obtaining the third authentication information from the second device; sending the signature verification information and the third authentication information to the first device via near-field communication, so that the first device performs device authentication on the second device based on the signature verification information, the first authentication information, and the third authentication information, wherein the first authentication information is also associated with the second device.

18. The authentication method according to any one of claims 13-15, characterized in that, The second authentication information represents the identity code and second key information associated with the second account; The step of obtaining the second authentication information includes: receiving an identity code associated with the second account sent by a cloud service, wherein the identity code associated with the second account is generated by the device logging into the second account; generating second key information based on the identity code associated with the second account, wherein the second key information is used to encrypt or decrypt near-field communication information between the second device and the device logging into the second account; and determining the second authentication information based on the second key information.

19. The authentication method according to any one of claims 13-15, characterized in that, Before obtaining the second authentication information, the method further includes: receiving binding information of the second device sent by the cloud service, the binding information of the second device including device information of the second device, the binding information of the second device being sent to the cloud service by a device logged into the second account; determining that the second device is bound to the second account, and saving the device information of the second device.

20. The authentication method according to any one of claims 13-15, characterized in that, The method further includes: receiving unbinding information of the second device sent by the cloud service, the unbinding information of the second device including device information of the second device, the unbinding information of the second device being sent to the cloud service by the device logged in to the second account; determining that the second device is unbound to the second account, and deleting the saved device information of the second device and the second authentication information.

21. The identity authentication method according to claim 13, characterized in that, The method further includes: receiving the first authentication information sent by the first device via near-field communication; and performing identity authentication with the first device based on the first authentication information and the second authentication information.

22. An identity authentication method, characterized in that, The method includes: after a first device logs into a first account and the first account is bound to a second device, obtaining first authentication information and sending the first authentication information to the second device, wherein the first authentication information is obtained based on the first device; wherein the first authentication information is associated with the first account, and the first authentication information is used for identity authentication via near-field communication when the first device and the second device are networked.

23. The identity authentication method according to claim 22, characterized in that, The method of obtaining the first authentication information includes: receiving a request for the first authentication information sent by the first device, the request information including identity information associated with the first account generated by the first device; issuing a certificate credential based on the identity information associated with the first account, and using the certificate credential as the first authentication information; the method further includes: sending the first authentication information to the first device.

24. The identity authentication method according to claim 23, characterized in that, Sending the first authentication information to the second device includes: receiving application information for the first authentication information sent by the second device; matching the first account bound to the second device from the bound device mapping relationship, wherein the bound device mapping relationship represents the mapping relationship between a user account and the device bound to it; and sending the first authentication information associated with the first account to the second device.

25. The identity authentication method according to claim 22, characterized in that, The step of obtaining the first authentication information includes: receiving the identity code associated with the first account sent by the first device; the step of sending the first authentication information to the second device includes: sending the identity code associated with the first account to the second device.

26. The identity authentication method according to claim 22, characterized in that, Before obtaining the first authentication information, the method further includes: in response to receiving the binding information of the second device sent by the first device, sending the binding information of the second device to the second device and adding a mapping relationship between the first account and the second device to the binding device mapping relationship; or, in response to receiving the request information of the binding device of the first account sent by the first device, obtaining the second device bound to the first account from the binding device mapping relationship and sending the binding information of the second device to the first device; wherein, the binding information of the second device includes the device information of the second device, and the binding device mapping relationship represents the mapping relationship between the user account and the device bound to it.

27. The identity authentication method according to claim 26, characterized in that, The method further includes: in response to receiving unbinding information of the second device sent by the first device, sending unbinding information of the second device to the second device and deleting the mapping relationship between the first account and the second device in the binding device mapping relationship; or, in response to receiving a request information of the first account to bind a device sent by the first device, sending unbinding information of the second device to the first device; wherein, the binding device mapping relationship represents the mapping relationship between a user account and the device bound to it, and the unbinding information of the second device includes the device information of the second device.

28. The identity authentication method according to claim 27, characterized in that, The method further includes sending information about the change in the number of devices bound to the first account to the first device.

29. An identity authentication device, characterized in that, The device includes: a processing module configured to obtain first authentication information after logging into a first account on a first device, the first authentication information being associated with the first account and used to send the first authentication information to a device bound to the first account via a cloud service; a transceiver module configured to receive second authentication information sent by the second device via near-field communication when the first device and the second device are networked, the second authentication information being associated with a second account, the second account being a user account bound to the second device; and an authentication module configured to perform identity authentication with the second device based on the first authentication information and the second authentication information.

30. An identity authentication device, characterized in that, The device includes: a processing module configured to obtain second authentication information after determining that the second device is bound to the second account, the second authentication information being associated with the second account and obtained based on a cloud service; and a transceiver module configured to send the second authentication information to the first device via near-field communication when the second device and the first device are networked, so that the first device can perform identity authentication with the second device based on the first authentication information and the second authentication information, wherein the first authentication information is associated with the first account, and the first account is the user account logged in by the first device.

31. An identity authentication device, characterized in that, The device includes a processing module configured to, after a first device logs into a first account and the first account is bound to a second device, obtain first authentication information and send the first authentication information to the second device, wherein the first authentication information is obtained based on the first device; wherein the first authentication information is associated with the first account and is used for identity authentication via near-field communication when the first device and the second device are networked.

32. An electronic device, characterized in that, include: processor; A memory for storing processor-executable instructions; wherein the processor is configured to perform the method as claimed in any one of claims 1-12, 13-21, or 22-28.

33. A non-transitory computer-readable storage medium, characterized in that, When the instructions in the storage medium are executed by the processor of the electronic device, the electronic device is able to perform the method as described in any one of claims 1-12, 13-21, or 22-28.