Knowledge base access method and electronic device

By using access control parameters for authentication in knowledge base access requests, the problem of knowledge base security verification is solved, the legitimacy of access requests is verified, and the security of the knowledge base is improved.

CN122437684APending Publication Date: 2026-07-21LENOVO (BEIJING) LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
LENOVO (BEIJING) LTD
Filing Date
2026-04-15
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

Existing technologies cannot effectively verify the security of knowledge base access requests, which adversely affects the security of knowledge bases.

Method used

Authentication is performed by extracting the information to be authenticated from the access request and the access control parameters. The access control parameters contain trusted parameters of the first electronic device to ensure its uniqueness, and the legitimacy of the access request is confirmed based on the authentication result.

Benefits of technology

It improves the reliability of the source of knowledge base access requests, enhances the security of the knowledge base, and prevents unauthenticated access requests from threatening the knowledge base.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122437684A_ABST
    Figure CN122437684A_ABST
Patent Text Reader

Abstract

The application provides a knowledge base access method and an electronic device. The method comprises the following steps: in response to an access request for a target knowledge base on a target electronic device, extracting to-be-authenticated information in the access request, and authenticating the to-be-authenticated information with an access control parameter; the access control parameter at least contains a trusted parameter of a first electronic device, and the trusted parameter can represent the uniqueness of the first electronic device; based on the authentication result, confirming whether the access request for the target knowledge base can access the target knowledge base.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data access technology, and in particular to a knowledge base access method and electronic device. Background Technology

[0002] Currently, when a knowledge base receives an access request, it cannot confirm whether the request will adversely affect the security of the knowledge base, thus compromising its security. Summary of the Invention

[0003] The purpose of this application is to provide a knowledge base access method and an electronic device.

[0004] The embodiments of this application adopt the following technical solution: a knowledge base access method, comprising: In response to an access request to a target knowledge base on a target electronic device, information to be authenticated in the access request is extracted, and the information to be authenticated is authenticated with access control parameters; the access control parameters include at least a trusted parameter of the first electronic device, which can characterize the uniqueness of the first electronic device; Based on the authentication result, it is confirmed whether the access request to the target knowledge base is valid.

[0005] In some embodiments, The trusted parameters of the first electronic device include the first trusted parameter; The method further includes: Obtain the first trusted parameters of the first hardware of the first electronic device; The target knowledge base is encoded with the first trusted parameter to obtain the access control parameter.

[0006] In some embodiments, The trusted parameters of the first electronic device also include the operator's profile; The method further includes: Obtain the carrier's configuration file; The target knowledge base, the operator configuration file, and the first trusted parameter are encoded to obtain the access control parameters.

[0007] In some embodiments, The first electronic device has second hardware applied to the first electronic device, and the second hardware has a second trusted parameter; The method further includes: Obtain the second trusted parameter; The target knowledge base is encoded with the second trusted parameter and the first trusted parameter to obtain the access control parameter.

[0008] In some embodiments, The trusted parameters of the first electronic device include a third trusted parameter; The method further includes: Obtain the third trusted parameter of the first electronic device; The target knowledge base is encoded with the third trusted parameter and the first trusted parameter to obtain the access control parameter.

[0009] In some embodiments, The method further includes: If the authentication result does not meet the preset authentication conditions, the target knowledge base is disabled.

[0010] In some embodiments, The method further includes: If the first electronic device is disconnected from the target user, the target user issues a second request to disable the target hardware of the first electronic device; In response to the second request, the target hardware is disabled.

[0011] In some embodiments, The step of disabling the target hardware in response to the second request includes: In response to the second request, the first operator profile is updated to the second operator profile.

[0012] In some embodiments, The method includes: In response to the second request, determine whether the first electronic device is connected to the target network operating environment; If the first electronic device is not connected to the target network operating environment, the authentication information is compared with the trusted parameters of the first electronic device.

[0013] This application also provides an electronic device, including a processor and a memory, wherein the processor is used for: In response to an access request to a target knowledge base on a target electronic device, information to be authenticated in the access request is extracted, and the information to be authenticated is authenticated with access control parameters; the access control parameters include at least a trusted parameter of the first electronic device, which can characterize the uniqueness of the first electronic device; Based on the authentication result, it is confirmed whether the access request to the target knowledge base is valid. Attached Figure Description

[0014] To more clearly illustrate the technical solutions in the embodiments or related technologies of this application, the drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0015] Figure 1 This is a flowchart illustrating the knowledge base access method for this application.

[0016] Figure 2 This is a schematic diagram illustrating a scenario where the safety of the primary electronic device is endangered.

[0017] Figure 3 This is a schematic diagram of scenario two, where the safety of the first electronic device is endangered.

[0018] Figure 4 This is a schematic diagram of scenario three, illustrating a situation where the safety of the first electronic device is at risk.

[0019] Figure 5 This is a schematic diagram of scenario four, illustrating a situation where the safety of the first electronic device is at risk.

[0020] Figure 6 This is a flowchart of one embodiment of the knowledge base access method of this application.

[0021] Figure 7 This is a flowchart of another embodiment of the knowledge base access method of this application.

[0022] Figure 8 This is a structural block diagram of the electronic device of this application. Detailed Implementation

[0023] Various embodiments and features of this application are described herein with reference to the accompanying drawings.

[0024] It should be understood that various modifications can be made to the embodiments described herein. Therefore, the above description should not be considered as limiting, but merely as an example of embodiments. Other modifications within the scope and spirit of this application will be apparent to those skilled in the art.

[0025] The accompanying drawings, which are included in and form part of this specification, illustrate embodiments of the present application and, together with the general description of the present application given above and the detailed description of the embodiments given below, serve to explain the principles of the present application.

[0026] These and other features of this application will become apparent from the following description of preferred forms of embodiments given as non-limiting examples, with reference to the accompanying drawings.

[0027] It should also be understood that although this application has been described with reference to some specific examples, those skilled in the art can certainly implement many other equivalent forms of this application.

[0028] The above and other aspects, features and advantages of this application will become more apparent when taken in conjunction with the accompanying drawings and in view of the following detailed description.

[0029] Specific embodiments of this application are described thereafter with reference to the accompanying drawings; however, it should be understood that the claimed embodiments are merely examples of this application, which can be implemented in various ways. Well-known and / or repeated functions and structures are not described in detail to avoid unnecessary or redundant details that could obscure the application. Therefore, the specific structural and functional details claimed herein are not intended to be limiting, but merely serve as the basis and representative basis for the claims to teach those skilled in the art to use this application in a variety of substantially any suitable detailed structures.

[0030] This specification may use the phrases “in one embodiment,” “in another embodiment,” “in yet another embodiment,” or “in other embodiments,” all of which may refer to one or more of the same or different embodiments according to this application.

[0031] This application first introduces its application scenario. Electronic devices typically store various knowledge bases, such as personal knowledge bases (PKBs), which contain sensitive user data, such as passwords, privacy data, and authorization credentials. If this sensitive user data is accessed by unauthenticated requests, it could lead to risks such as data leakage or the injection of malicious data. Access to personal knowledge bases includes direct access as well as access via artificial intelligence (AI) systems or other application systems. With the widespread use of AI applications, knowledge bases injected with malicious data (such as viruses) could also interfere with the normal operation of AI models. For example, a malicious user could implant incorrect data into the PKB of a shared device, causing the AI ​​model to generate misleading results based on incorrect information (such as recommending incorrect permissions or leaking disguised sensitive data).

[0032] For the above problems, some solutions are user authentication based on PIN (Personal Identification Number) or biometric credentials. Once the device has been successfully authenticated (due to spoofing attacks), the device will allow access to the personal knowledge base, and the personal knowledge base still has security risks.

[0033] To solve the above problems, combined with Figure 1 This application provides a knowledge base access method, which may include the following steps: S1, in response to an access request to the target knowledge base on the target electronic device, extract the information to be authenticated from the access request, and authenticate the information to be authenticated with the access control parameters; the access control parameters include at least the trusted parameters of the first electronic device, which can characterize the uniqueness of the first electronic device.

[0034] For example, the electronic device may be, but is not limited to, a mobile phone, a watch, and a laptop computer. This application will use a mobile phone as an example to illustrate this application. The target knowledge base may be, but is not limited to, the aforementioned personal knowledge base. The target knowledge base may be one knowledge base or may include two or more knowledge bases. The target knowledge base may store sensitive user data (passwords, privacy data, authorization credentials, etc.).

[0035] User X is the user of the first electronic device, and the target electronic device is any other electronic device distinct from the first electronic device. When an access request to access the target knowledge base is received on the target electronic device, in response to the access request, the information to be authenticated can be extracted from the access request. The access request carries the information to be authenticated. For example, for a data access request, the format of the data access request can be parsed, the key fields corresponding to the information to be authenticated can be located, and then the corresponding key fields can be extracted as the information to be authenticated. The information to be authenticated can be information that can characterize the uniqueness of the target electronic device. This is merely an example of a method for extracting information to be authenticated and does not constitute a limitation on the scope of protection of the claims.

[0036] Of course, it is understandable that the information to be authenticated can also be extracted through other extraction methods. Depending on the different access requests, the extraction method corresponding to the access request can be used for extraction.

[0037] The authentication information extracted from the access request is compared with the access control parameters to obtain the authentication result. Here, the access control parameters include at least the trusted parameters of the first electronic device. The first electronic device can be understood as a user-approved secure electronic device. The trusted parameters of the first electronic device can guarantee the uniqueness of the first electronic device, that is, the trusted parameters of other electronic devices are different from the trusted parameters of the first electronic device.

[0038] Access control parameters include trusted parameters that uniquely characterize the first electronic device. These trusted parameters can be understood as unchangeable hardware-level parameters, ensuring that the access control parameters cannot be tampered with. After authentication, the authentication result between the information to be authenticated and the access control parameters can be obtained, and the authentication result can include authentication successful or authentication failed.

[0039] S2, based on the authentication result, confirm whether the access request to the target knowledge base can access the target knowledge base.

[0040] For example, through the authentication in step S1, if the authentication result is successful, it can be confirmed that the access request to the target knowledge base can access the target knowledge base, the access request is secure, or is recognized by the first electronic device, and the access to the target knowledge base will not pose a security risk to the target knowledge base. For instance, if user X buys a new mobile phone, with user X's participation (e.g., user X enters the corresponding password or uses biometric authentication), the new mobile phone and user X's old mobile phone have been synchronized, and the data on user X's old mobile phone can be migrated to user X's new mobile phone.

[0041] When user X accesses the target knowledge base on his new mobile phone, if the authentication result is that the authentication fails, it can be confirmed that the access request to the target knowledge base cannot be accessed. The access request may be from an electronic device that is not recognized by the first electronic device (e.g., an old mobile phone). Therefore, the access request to the target knowledge base cannot be accessed.

[0042] One scenario where authentication fails is when, in combination with Figure 2 Other users forge user X's mask / fingerprint by guessing or stealing user X's password or biometric credentials. They then use the stolen password or mask / fingerprint to intrude into user X's first electronic device and transmit / share the target knowledge base across terminals through the thief's electronic device. At this time, the authentication information corresponding to the access request to the target knowledge base on the thief's electronic device cannot be authenticated, and the authentication result is authentication failure.

[0043] Another scenario where authentication fails is when combined with... Figure 3 When the network environment of User X's first electronic device changes from its own Wi-Fi network or mobile data network to a public network environment or a network environment provided by other users (such as a Wi-Fi network provided by a merchant or a network environment shared by others), the target electronic device in the public network environment or the network environment provided by other users may access the target knowledge base of the first electronic device. In this case, the authentication information corresponding to the access request to the target knowledge base on the target electronic device will also fail authentication, and the authentication result will be authentication failure. Or, for example, when the network environment of User X's first electronic device changes from a China Mobile network environment to a China Telecom or China Unicom network environment, the authentication result will be authentication failure.

[0044] Another scenario where authentication fails is when, combined with Figure 4Because a malicious user intrudes into a remote server and obtains the authentication credentials (such as passwords / temporary credentials) of user X's first electronic device, the target knowledge base originally belonging to the first electronic device is copied or accessed on another device (the target electronic device). In this case, the authentication information corresponding to the access request to the target knowledge base on the target electronic device also fails authentication, resulting in authentication failure.

[0045] In this embodiment of the application, since the access control parameters include trusted parameters that can characterize the uniqueness of the first electronic device and are unchangeable hardware-level parameters, it is guaranteed that the access control parameters cannot be tampered with. By authenticating the information to be authenticated extracted from the access request and the access control parameters, the reliability of the source of the access request to the target knowledge base is improved, thereby improving the security of the target knowledge base.

[0046] In some embodiments, the trusted parameters of the first electronic device include a first trusted parameter.

[0047] For example, the first electronic device is a mobile phone being used by the user, and the first hardware used on the first electronic device can be a SIM card (Subscriber Identity Module). The first trusted parameter can be the SIM card's ID (Integrated Circuit Card Identifier) ​​or EID (Embedded SIM Card Identifier). The SIM ID is a unique identifier for each SIM card, which can be a 19- or 20-digit string. Each SIM card corresponds to one ID, which remains unchanged throughout its life. The SIM card's ID can be the SIM card's ICCID (Integrated Circuit Card Identifier) ​​or EID (Embedded SIM Card Identifier), which can be used to identify and verify the SIM card's identity in the network.

[0048] The method further includes: Obtain the first trusted parameters of the first hardware of the first electronic device.

[0049] The target knowledge base is encoded with the first trusted parameter to obtain the access control parameter.

[0050] For example, the SIM card ID can be stored in a specific location on the first electronic device (e.g., "status information"). For instance, the SIM card ID can be obtained through the phone's "Settings" - "About phone" - "Status information".

[0051] Encoding the target knowledge base with the SIM card's ID yields access control parameters. For example, the ID can be used as a key to encrypt the target knowledge base ID, generating a fixed-length, irreversible string entry as the access control parameter. These access control parameters can be stored as entries in the target knowledge base in the database of the first electronic device and on the SIM card. When subsequent access to the target knowledge base is needed, this stored access control parameter can be retrieved to verify the information to be authenticated. Access to the target knowledge base is only granted if all trusted parameters included in the access control parameters are successfully authenticated.

[0052] For example, if the SIM card ID is 8986012345678901234F, and the target knowledge base ID (KB_ID) is used as a unique identifier: private_kb_001; the final access control parameter used for authentication is Control_Param. A set binding algorithm is used to bind the target knowledge base's KB_ID to the ID, resulting in a fixed 64-bit hexadecimal string. The access control parameter can be this string. Only this SIM card bound to this target knowledge base will receive the same access control parameter.

[0053] For example, if a mobile phone (the first electronic device) changes its SIM card, the SIM card before the change is the first SIM card, and the first SIM card ID is the first ID; the SIM card after the change is the second SIM card, and the second SIM card ID is the second ID. The second ID is different from the first ID, and the authentication information corresponding to the access request to the target knowledge base by the second SIM card will not be able to pass the authentication through the access control parameters corresponding to the first SIM card.

[0054] For example, when an AI model needs to access a target knowledge base, the phone needs to check the SIM card status. If the user has deactivated the first SIM card, the access control parameters corresponding to the first SIM card cannot be decoded, and the AI ​​model cannot access the target knowledge base.

[0055] In some embodiments, the trusted parameters of the first electronic device further include a carrier profile. The carrier profile may include network settings, user authorization, service options, etc. The carrier profile is the core parameter set for communication between the electronic device (e.g., a mobile phone) and the carrier network.

[0056] The method further includes: Obtain the carrier's configuration file.

[0057] The target knowledge base, the operator configuration file, and the first trusted parameter are encoded to obtain the access control parameters.

[0058] For example, the storage path and retrieval method of the operator's configuration file may differ for different system platforms (such as Android and iOS).

[0059] For example, for Android systems, the carrier configuration file can be stored in a first storage path on the phone, and the carrier configuration file can be retrieved by following the first storage path. For iOS systems, the carrier configuration file can be stored in a second storage path on the phone, and the carrier configuration file can be retrieved by following the second storage path.

[0060] The target knowledge base, along with the acquired operator configuration file and the first trusted parameter, are encoded together to form access control parameters. Thus, when a SIM card is inserted into an electronic device, the system automatically retrieves and applies the corresponding operator configuration file based on the SIM card's ID, ensuring network compatibility and providing necessary communication services.

[0061] In some embodiments, the first electronic device has second hardware applied to the first electronic device, and the second hardware has a second trusted parameter. The second hardware can be understood as part of the first electronic device. The second hardware of the first electronic device can be a baseband chip / modem of the first electronic device, and the second trusted parameter of the second hardware can be an International Mobile Equipment Identity (IMEI). The IMEI can be a 15-digit number used to identify each mobile electronic device. Operators can use the IMEI to lock or prevent the use of stolen or lost electronic devices. Taking a mobile phone as an example, the IMEI is a unique identification number for the phone hardware itself, independent of the SIM card, phone number, and ICCID. Changing the SIM card and phone number does not change the IMEI of the first electronic device. Each mobile phone has a unique IMEI; for dual-SIM phones, there can be two IMEIs (IMEI1, IMEI2).

[0062] The method further includes: Obtain the second trusted parameter. The second trusted parameter is a trusted parameter that reflects the second hardware applied to the first electronic device. It will not change due to the replacement of structural components (such as SIM cards) installed in the first electronic device. It belongs to the mobile phone hardware manufacturer and the first electronic device and is physically bound to the first electronic device.

[0063] The target knowledge base is encoded with the second trusted parameter and the first trusted parameter to obtain the access control parameter.

[0064] For example, taking a mobile phone as an example, the IMEI can be viewed through the phone's settings - About phone - Status information. Following this path, the second reliable parameter, IMEI, can be obtained. For different operating systems of electronic devices (such as Android and iOS), the specific method for obtaining the IMEI may differ.

[0065] After obtaining the second trusted parameter, the target knowledge base can be encoded with the second trusted parameter and the first trusted parameter to obtain the access control parameter. For example, the second trusted parameter and the first trusted parameter can be used as security factors to securely encode the target knowledge base ID, generating an authentication control parameter that is unforgeable, irreversible, and invalidates when the phone / SIM card is changed.

[0066] For example, IMEI=860123456789012; ICCID=8986022021123456789F; KB_ID=ai_private_knowledge_base_001.

[0067] The KB_ID can be encoded using the IMEI and ICCID according to the set encoding formula to obtain the access control parameters as follows: Control_Param=a1b2c3d4e5f67890abcdef1234567890a1b2c3d4e5f67890abcdef1234567890.

[0068] Save the obtained access control parameters in the location described above, which will not be repeated here.

[0069] For each access request on the target electronic device, the authentication information corresponding to the access request can be used to access the target knowledge base. The current IMEI, the current ICCID, and the target knowledge base ID can be read. The access control parameters can be recalculated and compared with the values ​​of the stored access control parameters. If the two match, access to the target knowledge base is allowed; if they do not match, access to the target knowledge base is denied.

[0070] In some embodiments, the trusted parameters of the first electronic device include a third trusted parameter, which may be a user authentication parameter, such as a PIN, biometric credentials, or the CPU (Central Processing Unit) ID.

[0071] The method further includes: Obtain the third trusted parameter of the first electronic device.

[0072] The target knowledge base is encoded with the third trusted parameter and the first trusted parameter to obtain the access control parameter.

[0073] For example, when the third trusted parameter is a PIN, the user can enter the PIN at the target location to obtain the third trusted parameter of the first electronic device. For instance, the first electronic device can display a PIN input box on the screen, and the user can enter the PIN into the input box.

[0074] When the third trusted parameter is a biometric credential such as a fingerprint or facial recognition, the user can input their fingerprint or facial recognition through the fingerprint acquisition module or facial recognition module to obtain the third trusted parameter of the first electronic device.

[0075] When the third trusted parameter is the CPU ID, the CPU ID can be obtained through corresponding instructions. For example, the CPU ID can be obtained by reading the system file of the first electronic device.

[0076] The acquired target knowledge base is encoded along with the third and first trusted parameters. For example, the third and first trusted parameters can be used as security factors to securely encode the target knowledge base ID, generating irreversible authentication control parameters. The obtained access control parameters are saved in the location described above, and will not be repeated here.

[0077] In some embodiments, the method further includes: If the authentication result does not meet the preset authentication conditions, the target knowledge base is disabled.

[0078] For example, if the authentication result is unsuccessful, the access request to the target knowledge base may pose a security risk. The security of the target knowledge base can be ensured by disabling it. Here, if the authentication information corresponding to the access request to the target knowledge base does not match any one or more trusted parameters in the access control parameters, the authentication result can be considered as not meeting the preset authentication conditions.

[0079] Disabling a target knowledge base can be achieved through the following methods: For example, if authentication fails, the user can have their SIM card's validity revoked by the carrier and the target knowledge base disabled remotely through reconfiguration. Specifically, the user can report the SIM card lost online or offline, and the carrier will mark it as invalid. Taking a mobile phone as an example, when the phone connects to the network, it receives a message: "Network refused" and a carrier configuration update: "carrier_revoked = 1". Applications associated with the target knowledge base will detect the abnormal SIM card status and the revoked carrier configuration. Automatic disabling can be performed, including preventing access to the target knowledge base, locking the phone screen, encrypting local data, and preventing access to any content (including the target knowledge base).

[0080] For example, it can also be remotely disabled via a cloud connection linked to the first electronic device. Alternatively, a disabling program can be set up so that it automatically runs and disables the target knowledge base whenever authentication fails.

[0081] For example, if user X takes the first electronic device out of the company's Wi-Fi range, the enterprise knowledge base will be automatically disabled.

[0082] Of course, it is understandable that the target knowledge base can be disabled in other ways; this is merely an example and does not constitute a limitation on the scope of protection of the claims.

[0083] In some embodiments, the method further includes: If the first electronic device is disconnected from the target user, the target user issues a second request to disable the target hardware of the first electronic device.

[0084] For example, the first electronic device becomes detached from the target user, including but not limited to the first electronic device being stolen or the target user losing the first electronic device. For instance, the target user is user X, and the first electronic device uses a China Telecom SIM card. Combined with... Figure 5 and Figure 6When an electronic device is stolen or lost, malicious users (such as thieves) may remove the SIM card and insert it into a new electronic device. Through the authentication or permission mechanisms associated with the SIM card, they can steal the original user's private data stored in the target's knowledge base, thereby tracking or stealing other sensitive information. When the first electronic device is removed from user X, user X can send a second request through an online telecommunications service hall on a computer or other electronic device, or at a physical telecommunications service hall, to request the SIM card (target hardware) of the first electronic device be disabled. User X can log in to the online telecommunications service hall using a password or facial / fingerprint authentication to confirm their legal possession of the SIM card in the stolen phone. User X can also go to a physical telecommunications service hall and have the SIM card in the first electronic device disabled by the service hall staff. For physical telecommunications service halls, user X can also confirm their legal possession of the SIM card in the stolen phone using identification documents such as an ID card.

[0085] In response to the second request, the target hardware is disabled.

[0086] For example, whether online or offline, upon receiving a second request, the operator will mark the SIM card as invalid and disable it. This way, even if other users gain access to the first electronic device, they cannot use the SIM card on the first device, and removing the SIM card from the first device and inserting it into other electronic devices will also prevent its use. Other users cannot obtain the first trusted parameters of the SIM card, nor can they issue access requests to the target knowledge base through the SIM card.

[0087] In some embodiments, disabling the target hardware in response to the second request includes: In response to the second request, the first operator profile is updated to the second operator profile.

[0088] For example, the target user's first electronic device (taking a mobile phone as an example) defaults to a first carrier profile. In response to a second request, the carrier can update the phone's carrier profile to a second carrier profile. Once the target user requests a change in the profile, the phone will use the new profile (the second carrier profile), and the access control parameters will also change. Because access to the target knowledge base depends on authentication using access control parameters (including the carrier profile), even if other users who have obtained the phone from the target user possess both the phone and the SIM card, the target knowledge base previously used by the phone will no longer be valid or usable due to the change in the carrier profile. Similarly, for electronic devices such as watches and laptops carrying SIM cards, the target knowledge base of the stolen electronic device will also become invalid or unusable. The specific principles behind this are not elaborated here.

[0089] In some embodiments, the method includes: In response to the second request, determine whether the first electronic device is connected to the target network operating environment.

[0090] For example, in combination Figure 7 The target network can be a network trusted by the target user, such as Wi-Fi in the target user's home, the Wi-Fi at a relative's home, or the mobile network corresponding to the SIM card on the first electronic device. In response to the second request, it is determined whether the first electronic device is connected to the operating environment of the aforementioned target network. For example, a pre-set network list can be configured. If the network corresponding to the operating environment of the first electronic device is listed in the pre-set network list, it is determined that the first electronic device is connected to the target network operating environment; otherwise, it is determined that the first electronic device is not connected to the target network operating environment.

[0091] If the first electronic device is not connected to the target network operating environment, the authentication information is compared with the trusted parameters of the first electronic device.

[0092] For example, if the first electronic device's access request to the target knowledge base without access to the target network operating environment may pose a security risk, the authentication information of the access request can be extracted and compared with the trusted parameters of the first electronic device to further confirm the security of the access request, thereby improving the security protection of the target knowledge base. Here, the target network operating environment can be understood as a network operating environment familiar to the user or a network operating environment that has been authenticated and is secure by the user. If the first electronic device accesses the target network operating environment (a network operating environment familiar to the user or a network operating environment that has been authenticated and is secure by the user), then the access request is considered secure, and the above authentication process is not required.

[0093] This application also provides an electronic device, combined with... Figure 8 The electronic device includes a processor and a memory, the processor being used for: In response to an access request to a target knowledge base on a target electronic device, information to be authenticated in the access request is extracted, and the information to be authenticated is authenticated with access control parameters; the access control parameters include at least a trusted parameter of the first electronic device, which can characterize the uniqueness of the first electronic device.

[0094] Electronic devices may include, but are not limited to, mobile phones, watches, and laptops. This application will use a mobile phone as an example to illustrate its application. The target knowledge base may include, but is not limited to, the aforementioned personal knowledge base. The target knowledge base may consist of one knowledge base or may include two or more knowledge bases. The target knowledge base may store sensitive user data (passwords, privacy data, authorization credentials, etc.).

[0095] For example, the user of the first electronic device is user X, and the target electronic device is another electronic device distinct from the first electronic device. When an access request to access the target knowledge base is received on the target electronic device, in response to the access request, the information to be authenticated can be extracted from the access request. The access request carries the information to be authenticated. For example, for a certain data access request, the format of the data access request can be parsed, the key fields corresponding to the information to be authenticated can be located, and then the corresponding key fields can be extracted as the information to be authenticated. The information to be authenticated can be information that can characterize the uniqueness of the target electronic device. This is only an example of a method for extracting information to be authenticated and does not constitute a limitation on the scope of protection of the claims.

[0096] Of course, it is understandable that the information to be authenticated can also be extracted through other extraction methods. Depending on the different access requests, the extraction method corresponding to the access request can be used for extraction.

[0097] The authentication information extracted from the access request is compared with the access control parameters to obtain the authentication result. Here, the access control parameters include at least the trusted parameters of the first electronic device. The first electronic device can be understood as a user-approved secure electronic device. The trusted parameters of the first electronic device can guarantee the uniqueness of the first electronic device, that is, the trusted parameters of other electronic devices are different from the trusted parameters of the first electronic device.

[0098] Access control parameters include trusted parameters that uniquely characterize the first electronic device. These trusted parameters can be understood as unchangeable hardware-level parameters, ensuring that the access control parameters cannot be tampered with. After authentication, the authentication result between the information to be authenticated and the access control parameters can be obtained, and the authentication result can include authentication successful or authentication failed.

[0099] Based on the authentication result, it is confirmed whether the access request to the target knowledge base is valid.

[0100] If the authentication result is successful, it can be confirmed that the access request to the target knowledge base is secure, or that the first electronic device approves it, and that access to the target knowledge base will not pose a security risk to the target knowledge base. For example, if the target electronic device is a new mobile phone purchased by user X, and user X participates (e.g., user X enters the corresponding password or uses biometric authentication), the target electronic device and the first electronic device have synchronized data, and the data on the first electronic device can be migrated to the target electronic device.

[0101] If the authentication result is that the authentication fails, it can be confirmed that the access request to the target knowledge base cannot access the target knowledge base. The access request may be from an electronic device that is not recognized by the first electronic device.

[0102] One scenario where authentication fails is when other users forge user X's mask / fingerprint by guessing or stealing user X's password or biometric credentials. Using the stolen password or mask / fingerprint, they intrude into user X's first electronic device and transmit / share the target knowledge base across terminals through the target electronic device. In this case, the authentication information corresponding to the access request to the target knowledge base on the target electronic device cannot be authenticated, and the authentication result is authentication failure.

[0103] Another scenario where authentication fails is when user X's first electronic device switches from its own Wi-Fi network or mobile data network to a public network or a network provided by other users (such as a Wi-Fi network provided by a merchant or a network shared by others). In this case, the target electronic device in the public network or the network provided by other users may access the target knowledge base of the first electronic device. In this case, the information to be authenticated corresponding to the access request to the target knowledge base on the target electronic device will also fail authentication, and the authentication result will be authentication failure.

[0104] Another scenario where authentication fails is when a malicious user compromises a remote server and obtains the authentication credentials (such as passwords / temporary credentials) of the first electronic device, allowing the target knowledge base originally belonging to the first electronic device to be copied or accessed on another device (the target electronic device). In this case, the authentication information corresponding to the access request to the target knowledge base on the target electronic device also fails authentication, resulting in authentication failure.

[0105] It should be understood that in the embodiments of this application, the processor may be a central processing unit (CPU), or it may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.

[0106] It should also be understood that the memory mentioned in the embodiments of this application can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static RAM (SRAM), Dynamic RAM (DRAM), Synchronous DRAM (SDRAM), Double Data Rate SDRAM (DDR SDRAM), Enhanced Synchronous DRAM (ESDRAM), Synchlink DRAM (SLDRAM), and Direct Rambus RAM (DR RAM).

[0107] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA, or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, the memory (storage module) is integrated into the processor. It should also be understood that the terms "first," "second," "third," and various numerical designations used herein are for descriptive convenience only and are not intended to limit the scope of this application.

[0108] Additionally, the character " / " in this article generally indicates that the objects before and after it are in an "or" relationship.

[0109] In implementation, each step of the above method can be completed by integrated logic circuits in the processor's hardware or by instructions in software. The steps of the method disclosed in the embodiments of this application can be directly implemented by a hardware processor, or by a combination of hardware and software modules in the processor. The software modules can reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method. To avoid repetition, detailed descriptions are omitted here.

[0110] In the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0111] Those skilled in the art will recognize that the various illustrative logical blocks (ILBs) and steps described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this application.

[0112] In the several embodiments provided in this application, it should be understood that the disclosed methods can be implemented in other ways.

[0113] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A knowledge base access method, comprising: In response to an access request to a target knowledge base on a target electronic device, extract the authentication information from the access request and authenticate the authentication information with access control parameters; The access control parameters include at least a trusted parameter of the first electronic device, which can characterize the uniqueness of the first electronic device; Based on the authentication result, it is confirmed whether the access request to the target knowledge base is valid.

2. The knowledge base access method according to claim 1, The trusted parameters of the first electronic device include the first trusted parameter; The method further includes: Obtain the first trusted parameters of the first hardware of the first electronic device; The target knowledge base is encoded with the first trusted parameter to obtain the access control parameter.

3. The knowledge base access method according to claim 2, The trusted parameters of the first electronic device also include the operator's profile; The method further includes: Obtain the carrier's configuration file; The target knowledge base, the operator configuration file, and the first trusted parameter are encoded to obtain the access control parameters.

4. The knowledge base access method according to claim 2, The first electronic device has second hardware applied to the first electronic device, and the second hardware has a second trusted parameter; The method further includes: Obtain the second trusted parameter; The target knowledge base is encoded with the second trusted parameter and the first trusted parameter to obtain the access control parameter.

5. The knowledge base access method according to claim 2, The trusted parameters of the first electronic device include a third trusted parameter; The method further includes: Obtain the third trusted parameter of the first electronic device; The target knowledge base is encoded with the third trusted parameter and the first trusted parameter to obtain the access control parameter.

6. The knowledge base access method according to claim 1, The method further includes: If the authentication result does not meet the preset authentication conditions, the target knowledge base is disabled.

7. The knowledge base access method according to claim 1, The method further includes: If the first electronic device is disconnected from the target user, the target user issues a second request to disable the target hardware of the first electronic device; In response to the second request, the target hardware is disabled.

8. The knowledge base access method according to claim 7, The step of disabling the target hardware in response to the second request includes: In response to the second request, the first operator profile is updated to the second operator profile.

9. The knowledge base access method according to claim 7, The method includes: In response to the second request, determine whether the first electronic device is connected to the target network operating environment; If the first electronic device is not connected to the target network operating environment, the authentication information is compared with the trusted parameters of the first electronic device.

10. An electronic device comprising a processor and a memory, the processor being configured to: In response to an access request to a target knowledge base on a target electronic device, extract the authentication information from the access request and authenticate the authentication information with access control parameters; The access control parameters include at least a trusted parameter of the first electronic device, which can characterize the uniqueness of the first electronic device; Based on the authentication result, it is confirmed whether the access request to the target knowledge base is valid.