Cross-device authentication method and related equipment

The cross-device authentication method addresses the inconvenience of single-device authentication by using a second device for verification, improving user experience and device responsiveness.

JP7835740B2Active Publication Date: 2026-03-25HUAWEI TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-03-25
Publication Date
2026-03-25

AI Technical Summary

Technical Problem

Current single-device identity authentication methods in mobile phones result in low convenience and poor user experience, especially when biometric feature information cannot be collected, leading to unresponsive devices.

Method used

A cross-device authentication method where a first electronic device initiates cross-device authentication upon local authentication failure, using a second electronic device for identity verification, and executes commands based on the authentication result.

Benefits of technology

Enhances convenience and user experience by allowing seamless identity authentication across devices, ensuring device responsiveness even when local biometric data collection fails.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007835740000001
    Figure 0007835740000001
  • Figure 0007835740000002
    Figure 0007835740000002
  • Figure 0007835740000003
    Figure 0007835740000003
Patent Text Reader

Abstract

This application provides a cross-device authentication method and electronic device applied to a first electronic device. The first electronic device is connected to a second electronic device. When local authentication fails, the first electronic device performs cross-device authentication using the second electronic device. The method is used to implement cross-device authentication information collection to improve the convenience of authentication operations.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0005] , , , ,

[0006] ,

[0001] This application was filed with the China National Intellectual Property Administration on September 30, 2020, and claims priority to Chinese Patent Application No. 202011063402.8 entitled "CROSS-DEVICE AUTHENTICATION METHOD AND RELATED APPARATUS", the entire content of which is incorporated herein by reference.

[0002] This application relates to the field of communication technologies, and in particular, to cross-device authentication methods and related apparatuses.

Background Art

[0003] When a user uses a mobile phone, the mobile phone may continuously perform identity authentication for the user based on the collected biometric feature information of the user (for example, face images, fingerprints, touch inputs on the touch screen) by using technical means such as face recognition, fingerprint recognition, and touch screen behavior recognition. When the identity authentication fails, the mobile phone may not respond to the current user's input operation. When the user attempts to use the mobile phone but the mobile phone cannot collect the user's biometric feature information, the mobile phone may also not be able to respond to the input operations performed by the user.

[0004] In conclusion, the current single-device identity authentication solution has low convenience and poor user experience.

Summary of the Invention

[0005] Embodiments of this application provide a cross-device authentication method and related apparatus that improve the convenience of cross-device authentication and effectively improve the user experience.

[0006] According to a first aspect, the application provides a cross-device authentication method applicable to a first electronic device and a second electronic device. The first electronic device is connected to the second electronic device, and the method includes: the first electronic device receiving a first operation; the first electronic device performing local authentication in response to the first operation; the first electronic device initiating cross-device authentication in response to the first electronic device detecting that the local authentication result of the first electronic device is authentication failure, wherein the cross-device authentication is used by the first electronic device to perform authentication using the second electronic device; the first electronic device obtaining a cross-device authentication result; and the first electronic device executing an instruction corresponding to the first operation if the first electronic device determines that the cross-device authentication result is authentication success.

[0007] In this way, identity authentication of the first electronic device is implemented using the second electronic device, effectively improving the convenience of cross-device authentication and creating a better user experience.

[0008] In a possible implementation, the initiation of cross-device authentication by a first electronic device includes the first electronic device sending a first request message to a second electronic device, the first request message being used to request the acquisition of a local authentication result from the second electronic device, and the acquisition of a cross-device authentication result by the first electronic device includes the first electronic device receiving a first response message from the second electronic device, the first response message containing a cross-device authentication result, the cross-device authentication result being the local authentication result from the second electronic device.

[0009] In a possible implementation, the first electronic device initiating cross-device authentication includes the first electronic device sending a second request message to the second electronic device, the second request message being used to request the acquisition of identity authentication information from the second electronic device, and the first electronic device receiving a second response message from the second electronic device, the second response message containing identity authentication information from the second electronic device, and the first electronic device obtaining a cross-device authentication result includes the first electronic device authenticating a first operation based on the identity authentication information of the second electronic device and generating a cross-device authentication result.

[0010] In a possible implementation, the first electronic device stores preset information, and the first electronic device authenticates a first operation based on the identity authentication information of the second electronic device and generates a cross-device authentication result, which includes the first electronic device matching the identity authentication information transmitted by the second electronic device with the preset information to generate a matching result, and the first electronic device determining that the local authentication result of the second electronic device is successful if the matching result is greater than a first preset threshold, or determining that the local authentication result of the second electronic device is unsuccessful if the matching result is not greater than a first preset threshold.

[0011] In a possible implementation, the first electronic device stores preset information, and the first electronic device performing local authentication for a first action in response to the first action includes, in response to the first action, the first electronic device obtaining the identity authentication information of the user inputting the first action, the first electronic device matching the user's identity authentication information with the preset information, and the first electronic device determining, based on the matching result, whether the local authentication result of the first electronic device is successful.

[0012] In a possible implementation, the first electronic device's determination of whether its local authentication result is successful based on the matching result includes the first electronic device comparing the degree of matching of the matching result with a preset threshold, and determining that the first electronic device's local authentication result is successful if the degree of matching is greater than a second preset threshold, or determining that the first electronic device's local authentication result is unsuccessful if the degree of matching is not greater than a second preset threshold.

[0013] In possible implementations, identity authentication information includes one or more of the following: facial information, fingerprint information, voiceprint information, iris information, and screen touch behavior information, while preset information includes one or more of the following: facial information, fingerprint information, voiceprint information, iris information, and screen touch behavior information.

[0014] In possible implementations, the first action is one of the following: a screen unlock action, an application unlock action, or an action performed on the application's functionality control.

[0015] In a possible implementation, the first and second electronic devices log in to the same user account, which is one of the following: an instant messaging account, an email account, or a mobile phone number.

[0016] In possible implementations, the method further includes the first electronic device detecting the distance between the first electronic device and the second electronic device, and the first electronic device executing a command corresponding to the first operation if the first electronic device determines that the cross-device authentication result is successful, and the first electronic device executing a command corresponding to the first operation if the first electronic device determines that the cross-device authentication result is successful and the distance between the first electronic device and the second electronic device is less than a first preset distance. Whether to execute a command corresponding to the first operation is determined based on the distance.

[0017] In possible implementations, the detection of the distance between the first electronic device and the second electronic device by the first electronic device includes the detection of the distance between the first electronic device and the second electronic device by the first electronic device using Bluetooth positioning technology, ultra-wideband (UWB) positioning technology, or wireless fidelity Wi-Fi positioning technology.

[0018] In possible implementations, the connection of a first electronic device to a second electronic device includes the first device establishing a connection to the second device using a near-field communication protocol, the near-field communication protocol including the connection to the second electronic device by using one or more of the following: Wireless Fidelity Wi-Fi communication protocol, UWB communication protocol, Bluetooth communication protocol, Zigbee communication protocol, or near-field communication NFC protocol.

[0019] In a possible implementation, the first electronic device receives a second action before initiating cross-device authentication, the second action being used to trigger the initiation of a cross-device authentication function, and the first electronic device initiating cross-device authentication in response to detecting that the local authentication result of the first electronic device is an authentication failure includes the first electronic device initiating cross-device authentication in response to the second action and in response to detecting that the local authentication result of the first electronic device is an authentication failure.

[0020] In a possible implementation, the first electronic device further includes obtaining security status information of the second electronic device, and if the first electronic device determines that the cross-device authentication result is successful, executing a command corresponding to the first operation includes the first electronic device executing a command corresponding to the first operation if the first electronic device determines that the cross-device authentication result is successful and that the security status information of the second electronic device indicates that the second electronic device is in a secure state.

[0021] In a possible implementation, after the first electronic device receives the first action, the method further includes detecting whether the first action triggers a locked low-risk application, and in response to detecting that the first action triggers a locked low-risk application, the first electronic device detecting whether the local authentication result of the first electronic device is successful. In this way, identity authentication of the first electronic device for a locked low-risk application is implemented based on the local authentication result of the second electronic device, effectively improving the convenience of controlling the locked low-risk application.

[0022] In possible implementations, when the first action is a first voice command, the method further includes the first electronic device detecting whether the voiceprint features of the first voice command match the voiceprint features of a preset user, and in response to detecting that the voiceprint features of the first voice command match the voiceprint features of a preset user, the first electronic device detecting whether the local authentication result of the first electronic device is successful. In this way, the first electronic device can improve the convenience of voice control by implementing voice control of the first electronic device based on the local authentication result of the second electronic device.

[0023] In possible implementations, the first electronic device performs local sequential authentication and generates a local authentication result for the first electronic device when it receives a first action or after it has received a first action. The method by which the first electronic device performs local sequential authentication includes at least one of facial recognition authentication, iris recognition authentication, and screen touch behavior recognition authentication. The local authentication result for the first electronic device may indicate whether the identity authentication performed by the first electronic device on the user was successful.

[0024] In possible implementations, the second electronic device performs local sequential authentication and generates a local authentication result for the second electronic device when the first electronic device receives a first action, or after the first electronic device receives a first action. The method by which the second electronic device performs local sequential authentication includes at least one of facial recognition authentication, iris recognition authentication, and screen touch behavior recognition authentication. The local authentication result for the second electronic device may indicate whether the identity authentication performed by the second electronic device on the user was successful.

[0025] In a possible implementation, before the first electronic device executes an instruction corresponding to a first operation, the method further includes the first electronic device detecting whether the priority of local continuous authentication of the second electronic device is lower than the priority of local continuous authentication of the first electronic device, and in response to detecting that the priority of local continuous authentication of the second electronic device is not lower than the priority of local continuous authentication of the first electronic device, the first electronic device executing an instruction corresponding to the first operation. Thus, when the convenience of identity authentication is improved through cross-device authentication, it is determined that the priority of local continuous authentication of the second electronic device is not lower than the priority of local continuous authentication of the first electronic device, ensuring the security of cross-device authentication.

[0026] According to a second aspect, this application provides a cross-device authentication method applied to a first electronic device. The first electronic device performs the method of the first electronic device in the first aspect.

[0027] According to a third aspect, this application provides a cross-device authentication method applied to a second electronic device. The second electronic device performs the method of the second electronic device in the first aspect.

[0028] According to a fourth aspect, the present invention provides a first electronic device. The first electronic device is connected to a second electronic device, and the first electronic device includes a memory and one or more processors. The memory is coupled to the one or more processors and is configured to store computer program code, the computer program code includes computer instructions, and the one or more processors call the computer instructions to cause the electronic device to perform the method performed by the first electronic device in the second aspect.

[0029] According to a fourth aspect, the present invention provides a second electronic device. The second electronic device is connected to a first electronic device, and the first electronic device includes a memory and one or more processors. The memory is coupled to the one or more processors, and the memory is configured to store computer program code, the computer program code includes computer instructions, and the one or more processors call the computer instructions to cause the electronic device to perform the method performed by the second electronic device in the third aspect.

[0030] According to a sixth aspect, the present invention provides a computer-readable storage medium including instructions. When the instructions are executed on an electronic device, the electronic device is capable of performing the method in the second or third aspect.

[0031] According to a seventh aspect, the present invention provides a computer program product. When the computer program product is executed on a computer, the computer is capable of performing the method in the second or third aspect.

[0032] According to an eighth aspect, the present invention provides a communication system including a first electronic device and a second electronic device. The first electronic device is configured to perform the method in the second aspect, and the second electronic device is configured to perform the method in the third aspect.

Brief Description of the Drawings

[0033] [Figure 1] It is a schematic diagram of the system architecture of a communication system according to an embodiment of this application.

[0034] [Figure 2] It is a schematic diagram of the structure of an electronic device according to an embodiment of this application.

[0035] [Figure 3A]This is a schematic diagram of the interface through which cross-device authentication is initiated according to one embodiment of this application. [Figure 3B] This is a schematic diagram of the interface through which cross-device authentication is initiated according to one embodiment of this application. [Figure 3C] This is a schematic diagram of the interface through which cross-device authentication is initiated according to one embodiment of this application.

[0036] [Figure 4A] This is a schematic diagram of a voice control scenario according to one embodiment of this application. [Figure 4B] This is a schematic diagram of a voice control scenario according to one embodiment of this application. [Figure 4C] This is a schematic diagram of a voice control scenario according to one embodiment of this application. [Figure 4D] This is a schematic diagram of a voice control scenario according to one embodiment of this application.

[0037] [Figure 5A] This is a schematic diagram of an interface to which an application according to one embodiment of this application is locked. [Figure 5B] This is a schematic diagram of an interface to which an application according to one embodiment of this application is locked. [Figure 5C] This is a schematic diagram of an interface to which an application according to one embodiment of this application is locked. [Figure 5D] This is a schematic diagram of an interface to which an application according to one embodiment of this application is locked. [Figure 5E] This is a schematic diagram of an interface to which an application according to one embodiment of this application is locked. [Figure 5F] This is a schematic diagram of an interface to which an application according to one embodiment of this application is locked. [Figure 5G] This is a schematic diagram of an interface to which an application according to one embodiment of this application is locked.

[0038] [Figure 5H] This is a schematic diagram of an interface in which an application function is locked according to one embodiment of this application. [Figure 5I] This is a schematic diagram of an interface in which an application function is locked according to one embodiment of this application. [Figure 5J] This is a schematic diagram of an interface in which an application function is locked according to one embodiment of this application. [Figure 5K] This is a schematic diagram of an interface in which an application function is locked according to one embodiment of this application. [Figure 5L] This is a schematic diagram of an interface in which an application function is locked according to one embodiment of this application. [Figure 5M] This is a schematic diagram of an interface in which an application function is locked according to one embodiment of this application.

[0039] [Figure 6A] This is a schematic diagram of a voice control scenario according to one embodiment of this application. [Figure 6B] This is a schematic diagram of a voice control scenario according to one embodiment of this application. [Figure 6C] This is a schematic diagram of a voice control scenario according to one embodiment of this application. [Figure 6D] This is a schematic diagram of a voice control scenario according to one embodiment of this application. [Figure 6E] This is a schematic diagram of a voice control scenario according to one embodiment of this application. [Figure 6F] This is a schematic diagram of a voice control scenario according to one embodiment of this application. [Figure 6G] This is a schematic diagram of a voice control scenario according to one embodiment of this application. [Figure 6H] This is a schematic diagram of a voice control scenario according to one embodiment of this application. [Figure 6I] This is a schematic diagram of a voice control scenario according to one embodiment of this application. [Figure 6J]This is a schematic diagram of a voice control scenario according to one embodiment of this application.

[0040] [Figure 7A] This is a schematic diagram of an interface in which a low-risk application according to one embodiment of this application is configured. [Figure 7B] This is a schematic diagram of an interface in which a low-risk application according to one embodiment of this application is configured. [Figure 7C] This is a schematic diagram of an interface in which a low-risk application according to one embodiment of this application is configured.

[0041] [Figure 8A] This is a schematic diagram of a voice control scenario according to one embodiment of this application. [Figure 8B] This is a schematic diagram of a voice control scenario according to one embodiment of this application. [Figure 8C] This is a schematic diagram of a voice control scenario according to one embodiment of this application. [Figure 8D] This is a schematic diagram of a voice control scenario according to one embodiment of this application.

[0042] [Figure 9A] This is a schematic diagram of an interface that triggers a cast according to one embodiment of this application. [Figure 9B] This is a schematic diagram of an interface that triggers a cast according to one embodiment of this application. [Figure 9C] This is a schematic diagram of an interface that triggers a cast according to one embodiment of this application. [Figure 9D] This is a schematic diagram of an interface that triggers a cast according to one embodiment of this application. [Figure 9E] This is a schematic diagram of an interface that triggers a cast according to one embodiment of this application. [Figure 9F] This is a schematic diagram of an interface that triggers a cast according to one embodiment of this application. [Figure 9G] This is a schematic diagram of an interface that triggers a cast according to one embodiment of this application. [Figure 9H] This is a schematic diagram of an interface that triggers a cast according to one embodiment of this application.

[0043] [Figure 9I] This is a schematic diagram of an interface in which casting is controlled according to one embodiment of this application. [Figure 9J] This is a schematic diagram of an interface in which casting is controlled according to one embodiment of this application.

[0044] [Figure 10A] This is a schematic diagram of an interface in which casting is controlled according to one embodiment of this application. [Figure 10B] This is a schematic diagram of an interface in which casting is controlled according to one embodiment of this application. [Figure 10C] This is a schematic diagram of an interface in which casting is controlled according to one embodiment of this application. [Figure 10D] This is a schematic diagram of an interface in which casting is controlled according to one embodiment of this application. [Figure 10E] This is a schematic diagram of an interface in which casting is controlled according to one embodiment of this application. [Figure 10F] This is a schematic diagram of an interface in which casting is controlled according to one embodiment of this application. [Figure 10G] This is a schematic diagram of an interface in which casting is controlled according to one embodiment of this application. [Figure 10H] This is a schematic diagram of an interface in which casting is controlled according to one embodiment of this application. [Figure 10I] This is a schematic diagram of an interface in which casting is controlled according to one embodiment of this application.

[0045] [Figure 11A]This is a schematic diagram of an interface in which casting is controlled according to one embodiment of this application. [Figure 11B] This is a schematic diagram of an interface in which casting is controlled according to one embodiment of this application. [Figure 11C] This is a schematic diagram of an interface in which casting is controlled according to one embodiment of this application.

[0046] [Figure 12A] This is a schematic diagram of an interface in which casting is controlled according to one embodiment of this application. [Figure 12B] This is a schematic diagram of an interface in which casting is controlled according to one embodiment of this application.

[0047] [Figure 13A] This is a schematic diagram of an interface to which an authorized user is added according to one embodiment of this application. [Figure 13B] This is a schematic diagram of an interface to which an authorized user is added according to one embodiment of this application. [Figure 13C] This is a schematic diagram of an interface to which an authorized user is added according to one embodiment of this application. [Figure 13D] This is a schematic diagram of an interface to which an authorized user is added according to one embodiment of this application. [Figure 13E] This is a schematic diagram of an interface to which an authorized user is added according to one embodiment of this application.

[0048] [Figure 14A] This is a schematic diagram of an interface in which casting is controlled according to one embodiment of this application. [Figure 14B] This is a schematic diagram of an interface in which casting is controlled according to one embodiment of this application. [Figure 14C] This is a schematic diagram of an interface in which casting is controlled according to one embodiment of this application.

[0049] [Figure 15A] This is a schematic diagram of a cross-device authentication system according to one embodiment of this application. [Figure 15B] This is a schematic diagram of a cross-device authentication system according to one embodiment of this application. [Figure 15C] This is a schematic diagram of a cross-device authentication system according to one embodiment of this application.

[0050] [Figure 16A] This is a schematic flowchart of the cross-device authentication method in a voice control scenario according to an embodiment of this application. [Figure 16B] This is a schematic flowchart of the cross-device authentication method in a voice control scenario according to an embodiment of this application.

[0051] [Figure 17A] This is a schematic flowchart of a cross-device authentication method in a cast control scenario according to one embodiment of this application. [Figure 17B] This is a schematic flowchart of a cross-device authentication method in a cast control scenario according to one embodiment of this application.

[0052] [Figure 18] This is a schematic flowchart of a cross-device authentication method according to one embodiment of this application.

[0053] [Figure 19] This is a schematic diagram of the structure of a software system according to one embodiment of this application. [Modes for carrying out the invention]

[0054] The technical solutions in the embodiments of this application will be described briefly and completely below with reference to the accompanying drawings. In the description of the embodiments of this application, unless otherwise specified, " / " means "or". For example, A / B may mean A or B. The terms "and / or" in this specification merely describe an relating relationship for describing related subjects, and indicate that there may be three such relationships. For example, A and / or B may represent three cases: A only exists, both A and B exist, and B only exists. In addition, in the description of the embodiments of this application, "multiple" means two or more.

[0055] The terms “First” and “Second” as used herein are intended solely for illustrative purposes and should not be understood as indicators or implications of relative importance, or as implicit indicators of the number of technical features shown. Thus, features limited by “First” and “Second” may explicitly or implicitly include one or more features. In the description of the implementations of this application, unless otherwise specified, “multiple” means two or more. The method procedures provided in the embodiments of this application may include more or less steps and are not limited to a particular sequence of steps. The method procedures provided in the embodiments of this application are examples and should not be construed as limiting this embodiment of this application.

[0056] Based on the background technology, embodiments of this application provide a cross-device authentication method to solve existing technical problems. A cross-device authentication method that improves the convenience of cross-device authentication and effectively improves the user experience can be used.

[0057] The relational concepts in the cross-device authentication method provided in this embodiment of this application will be described first.

[0058] In this embodiment of the application, in addition to screen locking of the electronic device, there may also be application locking of the electronic device, and there may also be application function locking of applications within the electronic device.

[0059] Screen Lock: Screen lock is sometimes also called a lock screen. Screen lock may be used to protect the privacy of an electronic device, prevent accidental touches on the touch screen, and save power without closing the system software. Users may choose a password type for the screen lock. Password types may include, but are not limited to, facial images, fingerprints, and digital passwords. Once a user sets a screen lock and the electronic device enters a screen lock state, it can be understood that the user can only use the electronic device by unlocking the screen using a password, typically.

[0060] Application Lock and Application Feature Lock: Application lock is the locking of a specific application (e.g., payment software or email). Application feature lock is the locking of a specific application feature within a specific application (e.g., payment features in payment software, Me in instant messaging software). Users may select the password type for application lock and application feature lock. Password types may include, but are not limited to, facial images, fingerprints, and digital passwords. The screen lock password or a customized password may be used for application lock and / or application feature lock.

[0061] In this embodiment of the application, the application lock or application function lock may be set by the user, set by default by the electronic device, or adaptively determined by the electronic device based on the usage scenario. This is not specifically limited herein.

[0062] Local Sequential Authentication: Local sequential authentication means that an electronic device may perform sequential identity authentication on a user within its detection range using technical means such as facial recognition, iris recognition, or screen touch behavior recognition. In addition to authentication methods such as facial recognition, fingerprint recognition, and screen touch behavior recognition, in this embodiment of the application, identity authentication may be performed sequentially on a user using another authentication method, such as fingerprint recognition, gait recognition, and heart rate recognition. In this embodiment of the application, a single identity authentication may also be called local authentication. The local authentication result may be an authentication result obtained after an electronic device has performed identity authentication using one or more authentication methods such as facial recognition, fingerprint recognition, and screen touch behavior recognition, and is used to indicate whether identity authentication was successful or not. In this embodiment of the application, identity authentication information may include the local authentication result, or it may include biometric feature information collected by the electronic device using one or more authentication methods such as facial recognition, fingerprint recognition, and screen touch behavior recognition. In some embodiments, the electronic device may perform local sequential authentication periodically, and the result of a single local authentication may include whether local authentication was successful or it may include a timestamp of the local authentication.

[0063] For example, the electronic device 100 pre-stores biometric feature information 1 of user 1, and the biometric feature information 1 is used to verify user 1's identity. During local sequential authentication, the electronic device 100 may determine that user 1's local authentication is successful when the degree of matching between the biometric feature information 1 and the biometric feature information collected by the electronic device 100 using technical means such as facial recognition, fingerprint recognition, or screen touch behavior recognition reaches a preset threshold 1. For example, the preset threshold 1 is equal to 90%.

[0064] It should be noted that in some embodiments, the electronic device may perform local sequential authentication after the user has unlocked the screen. If the user enters a locked application or application function and the identity authentication in the electronic device's local sequential authentication is successful, the electronic device can enter the application or application function without needing to receive the user's unlock action at the application or application function's unlock interface.

[0065] The following describes the communication system 10 provided in the embodiments of this application. Figure 1 is a schematic diagram of an example of the communication system 10 according to one embodiment of this application. As shown in Figure 1, the communication system 10 includes electronic devices 100 and 200. The electronic devices in the communication system 10 may establish wired or wireless connections using one or more connection methods.

[0066] In this embodiment of the application, electronic device 100 may be directly connected to electronic device 200 via a near-field communication connection or a local wired connection. For example, electronic device 100 and electronic device 200 may each include one or more short-range communication modules in a wireless fidelity (Wi-Fi) communication module, an ultra-wideband (UWB) communication module, a Bluetooth communication module, a near-field communication (NFC) communication module, and a ZigBee communication module. Electronic device 100 is used as an example. Electronic device 100 may detect and scan for nearby electronic devices (e.g., electronic device 200) by transmitting signals using a short-range communication module (e.g., a Bluetooth communication module), so that as a result, electronic device 100 can detect nearby electronic devices using a near-field communication protocol (e.g., a Bluetooth wireless communication protocol), establish a wireless communication connection to nearby electronic devices, and transmit data to nearby electronic devices. For example, the electronic device 100 may also be directly connected based on the Wi-Fi peer-to-peer (Wi-Fi P2P) communication protocol.

[0067] In some embodiments, in short-range communication scenarios, the electronic device 100 may further measure the distance to the electronic device 200 using positioning techniques such as Bluetooth positioning techniques, UWB positioning techniques, or Wi-Fi positioning techniques.

[0068] In this embodiment of the application, electronic devices 100 and 200 may be connected to a local area network (LAN) using electronic device 300 via a wired connection or a wireless fidelity (Wi-Fi) connection. Electronic devices 100 and 200 are indirectly connected using electronic device 300. For example, electronic device 300 may be a third-party device such as a router, gateway, or smart device controller. For example, electronic device 300 may transmit data to electronic devices 100 and / or 200 via the network, or receive data transmitted by electronic devices 100 and / or 200 via the network.

[0069] In this embodiment of the application, electronic devices 100 and 200 may, alternatively, be indirectly connected using at least one network device in a wide-area network. For example, electronic devices 100 and 200 establish an indirect connection using electronic device 400. Electronic device 400 may be a hardware server or a cloud server embedded in a virtualization environment. For example, the cloud server may include a virtual machine running on a hardware server of at least another virtual machine. For example, electronic device 400 may transmit data to electronic devices 100 and / or electronic devices 200 over the network, and may receive data transmitted by electronic devices 100 and / or electronic devices 200 over the network. In some embodiments, electronic devices 100 and 200 may be electronic devices that log in to the same account using electronic device 400, or electronic devices 100 and 200 may be electronic devices that log in to different accounts using electronic device 400. For example, electronic device 100 logs into a first account using electronic device 400, and electronic device 200 logs into a second account using electronic device 400. Electronic device 100, which logs into the first account, may use electronic device 400 to initiate a connection request to electronic device 200, which logs into the second account, thereby establishing a connection relationship between the first and second accounts. The first and second accounts may be instant messaging accounts, email accounts, mobile phone numbers, etc. The first and second accounts may belong to different carrier networks or to the same carrier network. This is not specifically limited herein.

[0070] In some implementations of this application, an electronic device 100 is used as an example. After the electronic device 100 has established a connection to the electronic device 200 (the methods of establishing a connection in this application include several types described above, details of which are not described again herein), the electronic device 100 may grant authorization to the electronic device 200 to authorize the electronic device 200 to control the electronic device 100. In some embodiments, authorization of the electronic device 200 includes the possibility that the electronic device 200 may obtain identity authentication information of the electronic device 100. In some embodiments, authorization of the electronic device 200 further includes the possibility that the electronic device 200 may transmit (e.g., cast) interface content of the user interface of the electronic device 200 to the electronic device 100, and conversely control the user interface of the electronic device 200 on the electronic device 100. In some embodiments, the authorization of electronic device 200 further includes the possibility that electronic device 200 may actively obtain the interface content of the user interface of electronic device 100, and conversely, control the user interface of electronic device 100 on electronic device 200. Similarly, after electronic device 100 has established a connection to electronic device 200, electronic device 200 may grant authorization to electronic device 100, specifying authorization for electronic device 100 to control electronic device 200 (for example, authorization to obtain the identity authentication information of electronic device 100). Further details are not described again here.

[0071] In this embodiment of the application, at least one of the electronic device 100 and electronic device 200 may have local sequential authentication capability. The fact that an electronic device has local sequential authentication capability means that the electronic device may perform local sequential authentication using at least one authentication method.

[0072] It can be understood that the system structure shown in Figure 1 does not constitute a particular limitation on the electronic device 10. In some other embodiments of this application, the communication system 10 may further include more electronic devices. For the connection relationships between any two devices in the communication system 10, see electronic device 100 and electronic device 200. Further details are not described again here.

[0073] It should be noted that in this embodiment of the application, neither the type of electronic device 100 nor the type of electronic device 200 is specifically limited. In some embodiments, the electronic device in this embodiment of the application may be a portable device such as a mobile phone, a wearable device (e.g., a smart band or smartwatch), a tablet computer, a laptop computer, a handheld computer, a notebook computer, an ultra-mobile personal computer (UMPC), a mobile phone, a personal digital assistant (PDA), or an augmented reality (AR) / virtual reality (VR) device. Exemplary embodiments of the electronic device include, but are not limited to, electronic devices provided with iOS®, Android®, Microsoft®, or another operating system.

[0074] To facilitate understanding of the solutions in the embodiments of this application, the electronic devices in the embodiments of this application will be described below.

[0075] For example, electronic device 100 is used as an example. Figure 2 is a schematic diagram of the structure of electronic device 100 according to one embodiment of this application.

[0076] As shown in Figure 2, the electronic device may include a processor 110, an external memory interface 120, internal memory 121, a universal serial bus (USB) interface 130, a charge management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, a headset jack 170D, a sensor module 180, a button 190, a motor 191, an indicator 192, a camera 193, a display 194, a subscriber identification module (SIM) card interface 195, and the like. The sensor module 180 may include a pressure sensor 180A, a gyroscope sensor 180B, a barometric pressure sensor 180C, a magnetic sensor 180D, an acceleration sensor 180E, a distance sensor 180F, an optical proximity sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, and the like.

[0077] It can be understood that the structure shown in this embodiment of this application does not constitute a particular limitation on the electronic device 100. In some other embodiments of this application, the electronic device 100 may include more or fewer components than those shown in the figure, some components may be combined, some components may be separated, and may have different component arrangements. The components shown in the figure may be implemented using hardware, software, or a combination of software and hardware.

[0078] The processor 110 may include at least one processing unit. For example, the processor 110 may include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural network processing unit (NPU). Different processing units may be independent components or may be integrated into at least one processor. The processor 110 may execute multiple tasks (e.g., applications) simultaneously to provide multiple services and functions to the user.

[0079] The controller may be the neural center and command center of the electronic device 100. The controller may generate operation control signals based on instruction operation codes and time sequence signals, and complete control over instruction fetching and instruction execution.

[0080] Memory may be located within the processor 110 and is configured to store instructions and data. In some embodiments, the memory within the processor 110 is a cache. The memory may store instructions or data that are used just as needed or periodically by the processor 110. If the processor 110 needs to use the instructions or data again, it may retrieve the instructions or data directly from memory. In this case, repeated access is avoided, the latency of the processor 110 is reduced, and the efficiency of the system is improved.

[0081] In some embodiments, the processor 110 may include at least one interface. This interface may include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM), a universal serial bus (USB) interface, and the like.

[0082] The I2C interface is a bidirectional synchronous serial bus and includes one serial data line (SDA) and one serial clock line (SCL). In some embodiments, the processor 110 may include a group of multiple I2C buses. The processor 110 may be coupled separately to the touch sensor 180K, charger, flashlight, camera 193, etc., via different I2C bus interfaces. For example, the processor 110 may be coupled to the touch sensor 180K via the I2C interface, so that the processor 110 communicates with the touch sensor 180K via the I2C bus interface to implement the touch functionality of the electronic device 100.

[0083] The I2S interface may be used for audio communication. In some embodiments, the processor 110 may include a group of multiple I2S buses. The processor 110 may be coupled to an audio module 170 via the I2S bus to implement communication between the processor 110 and the audio module 170. In some embodiments, the audio module 170 may implement the function of transferring audio signals via the I2S interface to a wireless communication module 160 to receive calls via a Bluetooth headset.

[0084] The PCM interface may also be used for audio communication, analog signal sampling, quantization, and coding. In some embodiments, the audio module 170 may be coupled to the wireless communication module 160 via the PCM bus interface. In some embodiments, the audio module 170 may alternatively implement the function of transmitting audio signals to the wireless communication module 160 via the PCM interface to receive calls via a Bluetooth headset. Both the I2S interface and the PCM interface may be used for audio communication.

[0085] The UART interface is a universal serial data bus configured for asynchronous communication. The bus may be a bidirectional communication bus. The bus converts the data to be transmitted between serial and parallel communication. In some embodiments, the UART interface is typically configured to connect a processor 110 to a wireless communication module 160. For example, the processor 110 communicates with a Bluetooth module in the wireless communication module 160 via the UART interface to implement Bluetooth functionality. In some embodiments, an audio module 170 may transmit audio signals to the wireless communication module 160 via the UART interface to implement the functionality of playing music using a Bluetooth headset.

[0086] The MIPI interface may be configured to connect the processor 110 to peripheral components such as a display 194 or a camera 193. MIPI interfaces include camera serial interfaces (CSI), display serial interfaces (DSI), and the like. In some embodiments, the processor 110 communicates with the camera 193 via the CSI to implement the photographic capabilities of the mobile device 100. The processor 110 communicates with the display 194 via the DSI to implement the display capabilities of the electronic device 100.

[0087] The GPIO interface may be configured using software. The GPIO interface may be configured as a control signal or as a data signal. In some embodiments, the GPIO interface may be configured to connect the processor 110 to a camera 193, a display 194, a wireless communication module 160, an audio module 170, a sensor module 180, and the like. The GPIO interface may be configured as an I2C interface, an I2S interface, a UART interface, a MIPI interface, and the like.

[0088] The USB interface 130 is an interface that conforms to the USB standard specification, and may specifically be a mini USB interface, a micro USB interface, a USB Type-C interface, etc. The USB interface 130 may be configured to connect to a charger to charge the electronic device 100, or to transmit data between the electronic device 100 and peripheral devices, or to connect to a headset to play audio using the headset. The interface may be further configured to connect to another electronic device, for example, an AR device.

[0089] The intermodal interface connection relationships shown in this embodiment of this application are merely illustrative examples and should be understood as not constituting any limitation on the structure of the electronic device 100. In some other embodiments of this application, different interface connection methods, or combinations of multiple interface connection methods, in the above-described embodiments may be used as alternatives for the electronic device 100.

[0090] The charging management module 140 is configured to receive a charging input from the charger. The charger may be a wireless charger or a wired charger.

[0091] The power management module 141 is configured to connect to the battery 142, the charge management module 140, and the processor 110. The power management module 141 receives input from the battery 142 and / or the charge management module 140 and supplies power to the processor 110, internal memory 121, external memory, display 194, camera 193, wireless communication module 160, etc.

[0092] The wireless communication function of the electronic device 100 may be implemented using antenna 1, antenna 2, mobile communication module 150, wireless communication module 160, modem processor, baseband processor, etc.

[0093] Antennas 1 and 2 are configured to transmit and receive electromagnetic wave signals. Each antenna in the electronic device 100 may be configured to cover one or more communication frequency bands. Different antennas may be further multiplexed to improve antenna utilization. For example, antenna 1 may be multiplexed as a diversity antenna in a wireless local area network. In some other embodiments, the antennas may be used in combination with tuning switches.

[0094] The mobile communication module 150 is applied to the electronic device 100 and may provide a wireless communication solution including 2G / 3G / 4G / 5G. The mobile communication module 150 may include at least one filter, switch, power amplifier, low noise amplifier (LNA), etc. The mobile communication module 150 may receive electromagnetic waves via antenna 1, perform processing such as filtering and amplification on the received electromagnetic waves, and transmit the electromagnetic waves to a modem processor for demodulation. The mobile communication module 150 may further amplify the signal modulated by the modem processor and convert the signal into electromagnetic waves for radiation via antenna 1. In some embodiments, at least some functional modules of the mobile communication module 150 may be located in the processor 110. In some embodiments, at least some functional modules of the mobile communication module 150 may be located in the same device as at least some modules of the processor 110.

[0095] The modem processor may include a modulator and a demodulator. The modulator is configured to modulate the low-frequency baseband signal to be transmitted into a medium-frequency signal. The demodulator is configured to demodulate the received electromagnetic signal into a low-frequency baseband signal. The demodulator then transmits the low-frequency baseband signal obtained via demodulation to a baseband processor for processing. The baseband processor processes the low-frequency baseband signal and transfers the obtained signal to an application processor. The application processor outputs an audio signal using an audio device (not limited to speaker 170A, receiver 170B, etc.) or displays an image or video on display 194. In some embodiments, the modem processor may be a separate component. In some other embodiments, the modem processor may be independent of processor 110 and be located in the same device as the mobile communication module 150 or another functional module.

[0096] The wireless communication module 160 is applied to the electronic device 100 and may provide wireless communication solutions including wireless local area networks (WLAN) (e.g., wireless fidelity (Wi-Fi) network), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near-field communication (NFC) technology, infrared (IR) technology, etc. The wireless communication module 160 may be one or more components integrating at least one communication processing module. The wireless communication module 160 receives electromagnetic waves via antenna 2, performs frequency modulation and filtering on the electromagnetic wave signal, and transmits the processed signal to processor 110. The wireless communication module 160 may further receive a signal to be transmitted from processor 110, perform frequency modulation and amplification on that signal, and convert the signal into an electromagnetic wave for radiation via antenna 2.

[0097] In some embodiments, antenna 1 and mobile communication module 150 within electronic device 100 are coupled, and antenna 2 and wireless communication module 160 within electronic device 100 are coupled, so that electronic device 100 can communicate with networks and other devices using wireless communication technology. Wireless communication technology may include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long-term evolution (LTE), BT, GNSS, WLAN, NFC, FM, IR technology, and the like. GNSS may include the Global Positioning System (GPS), Global Navigation Satellite System (GLONASS), BeiDou Navigation Satellite System (BDS), Quasi-Zenith Satellite System (QZSS), and / or Satellite-Based Augmentation System (SBAS).

[0098] The electronic device 100 may implement display functions via a GPU, a display 194, an application processor, etc. The GPU is a microprocessor for image processing and is connected to the display 194 and the application processor. The GPU is configured to perform mathematical and geometric computation and graphics rendering. The processor 110 includes at least one GPU and may execute program instructions to generate or modify display information.

[0099] The display 194 is configured to display images, videos, etc. The display 194 includes a display panel. The display panel may be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a mini-LED, a micro-LED, a micro-OLED, a quantum dot light-emitting diode (QLED), etc. In some embodiments, the electronic device 100 may include one or N displays 194, where N is a positive integer greater than 1.

[0100] The electronic device may implement the shooting function using an ISP, camera 193, video codec, GPU, display 194, application processor, etc.

[0101] The ISP is configured to process data fed back by the camera 193. For example, when the shutter is pressed during shooting, light is transmitted to the camera's photoreceptor through the lens. The light signal is converted into an electrical signal, and the camera's photoreceptor transmits the electrical signal to the ISP for processing, converting the electrical signal into a visible image. The ISP may further perform algorithmic optimization with respect to image noise, brightness, and skin tone. The ISP may further optimize parameters such as exposure and color temperature of the shooting scenario. In some embodiments, the ISP may be located within the camera 193.

[0102] The camera 193 is configured to capture still images or video. An optical image of an object is generated through a lens and cast onto a photoreceptor. The photoreceptor may be a charge-coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photoreceptor converts the optical signal into an electrical signal and then transmits the electrical signal to an ISP to convert the electrical signal into a digital image signal. The ISP outputs the digital image signal to a DSP for processing. The DSP converts the digital image signal into a standard image signal in a format such as RGB or YUV. In some embodiments, the electronic device 100 may include one or more camera modules 193, where N is a positive integer greater than 1.

[0103] In this embodiment of the application, camera 193 includes a camera for collecting images necessary for face recognition, such as an infrared camera or another camera with low power consumption. The camera is typically located on the front of the electronic device 100, for example, above the touch screen, or may be located elsewhere. This is not limited to this embodiment of the application. In some embodiments, the electronic device 100 may further include another camera, and the electronic device 100 may further include a dot matrix transmitter (not shown) configured to emit light. The camera collects light reflected by the face to obtain a face image. The processor processes and analyzes the face image and compares the face image with pre-stored face images to implement identity authentication.

[0104] A digital signal processor is configured to process digital signals and may process other digital signals in addition to digital image signals. For example, when electronic device 100 selects a frequency, the digital signal processor is configured to perform a Fourier transform or the like on the energy of the frequency.

[0105] A video codec is configured to compress or decompress digital video. The electronic device 100 may support one or more video codecs. Therefore, the electronic device 100 may play or record video in multiple encoding formats, such as moving picture experts group (MPEG)-1, MPEG-2, MPEG-3, and MPEG-4.

[0106] An NPU is a neural network (NN) computing processor. The NPU can rapidly process input information by referencing the structure of a biological neural network, for example, the transfer mode between neurons in the human brain, and may also continuously perform self-learning. Intelligent cognition applications of electronic devices 100, such as image recognition, face recognition, speech recognition, and text comprehension, may be implemented via the NPU.

[0107] The external memory interface 120 may be configured to connect to an external storage card, such as a microSD card, in order to expand the storage capacity of the electronic device 100. The external storage card communicates with the processor 110 via the external memory interface 120 and implements data storage functions. For example, files such as music and videos are stored on the external storage card.

[0108] The internal memory 121 may be configured to store computer-executable program code. Executable program code includes instructions. The processor 110 executes the instructions stored in the internal memory 121 to perform various functional applications and data processing of the electronic device 100. The internal memory 121 may include a program storage area and a data storage area.

[0109] The electronic device 100 may implement music playback and recording via audio functions, such as an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, a headset jack 170D, an application processor, etc.

[0110] The audio module 170 is configured to convert digital audio information into analog audio signals for output, and is further configured to convert analog audio input into digital audio signals. The audio module 170 may be further configured to encode and decode audio signals. In some embodiments, the audio module 170 may be located on the processor 110, or some functional modules of the audio module 170 may be located on the processor 110.

[0111] Speaker 170A, also called a "loudspeaker," is configured to convert electrical audio signals into voice signals. The electronic device 100 may be configured to listen to music through speaker 170A or to make calls in hands-free mode.

[0112] Receiver 170B, also known as the "earpiece," is configured to convert electrical audio signals into sound signals. When an electronic device is used to receive a call or to listen to audio information, receiver 170B may be placed near a person's ear to listen to the voice.

[0113] The microphone 170C, also called "mike" or "mic," is configured to convert sound signals into electrical signals. The user may input sound signals into the microphone 170C by emitting sound near the microphone 170C through the user's mouth when making a call or sending audio information. The electronic device 100 may be provided with at least one microphone 170C, which may collect the user's voiceprint characteristics to authenticate the user's identity.

[0114] The headset jack 170D is configured to connect to a wired headset. The headset jack 170D may be a USB interface 130, a 3.5mm open mobile terminal platform (OMTP) standard interface, or a cellular telecommunications industry association of the USA (CTIA) standard interface.

[0115] The pressure sensor 180A is configured to sense a pressure signal and may convert the pressure signal into an electrical signal. In some embodiments, the pressure sensor 180A may be located on the display 194. There are several types of pressure sensors 180A, such as resistive pressure sensors, inductive pressure sensors, and capacitive pressure sensors. A capacitive pressure sensor may include at least two parallel plates made of a conductive material. When force is applied to the pressure sensor 180A, the capacitance between the electrodes changes. The electronic device 100 determines the pressure intensity based on the change in capacitance. When a touch operation is performed on the display 194, the electronic device detects the intensity of the touch operation by using the pressure sensor 180A. The electronic device 100 may also calculate the touch position based on the detection signal of the pressure sensor 180A. In some embodiments, touch operations performed at the same touch position but with different touch operation intensities may correspond to different operation commands. For example, when a touch operation with an intensity less than a first pressure threshold is performed on a messaging application icon, an operation to view SMS messages is executed. When a touch operation with an intensity equal to or greater than a first pressure threshold is performed on a messaging application icon, a command to create an SMS message is executed.

[0116] The gyro sensor 180B may be configured to determine the motion orientation of the electronic device 100. In some embodiments, the angular velocity of the electronic device 100 around three axes (i.e., axes x, y, and z) may be determined using the gyro sensor 180B.

[0117] The barometric pressure sensor 180C is configured to measure atmospheric pressure. In some embodiments, the electronic device 100 uses the barometric pressure value measured by the barometric pressure sensor 180C to calculate altitude and assist in positioning and navigation.

[0118] The magnetic sensor 180D includes a Hall sensor. The electronic device 100 may use the magnetic sensor 180D to detect the opening and closing of the flip leather case. In some embodiments, when the electronic device 100 is a clamshell phone, the electronic device 100 may detect the opening and closing of the flip leather case based on the magnetic sensor 180D. Furthermore, features such as automatic unlocking when the flip leather case is opened are set based on the detected open / closed state of the flip leather case.

[0119] The accelerometer 180E may detect acceleration in various directions (typically three axes) of the electronic device 100. The magnitude and direction of gravity may also be detected when the electronic device 100 is stationary. The accelerometer 180E may be further configured to identify the orientation of the electronic device, which can be applied to applications such as switching between landscape and portrait modes, and pedometers.

[0120] The distance sensor 180F is configured to measure distance. The electronic device 100 may measure distance using an infrared or laser method. In some embodiments, in a shooting scenario, the electronic device may use the distance sensor 180F to measure distance and implement high-speed focusing.

[0121] The optical proximity sensor 180G may include, for example, a light-emitting diode (LED) and an optical detector, such as a photodiode. The light-emitting diode may be an infrared light-emitting diode. The electronic device 100 emits infrared light using the light-emitting diode. The electronic device 100 detects the infrared reflected light from a nearby object using the photodiode.

[0122] The ambient light sensor 180L is configured to sense the brightness of the ambient light. The electronic device 100 may adaptively adjust the brightness of the display 194 based on the sensed ambient light brightness. The ambient light sensor 180L may also be configured to automatically adjust the white balance during shooting. Furthermore, the ambient light sensor 180L may work in cooperation with the optical proximity sensor 180G to detect whether the electronic device 100 is in a pocket.

[0123] The fingerprint sensor 180H is configured to collect fingerprints. The electronic device 100 may use the characteristics of the collected fingerprint to implement fingerprint-based unlocking, application lock access, fingerprint-based photography, fingerprint-based call answering, etc. The fingerprint sensor 180H may be located below the touch screen. The electronic device 100 may receive user touch gestures in an area of ​​the touch screen corresponding to the fingerprint sensor. In response to the touch gesture, the electronic device 100 may collect fingerprint information of the user's finger, and as a result, after successful fingerprint recognition in this embodiment of the application, the electronic device may be unlocked, a locked application may be entered, a locked application function may be entered, etc. In other words, the data collected by the fingerprint sensor 180H may be configured to perform identity identification for the user.

[0124] The temperature sensor 180J is configured to detect temperature. In some embodiments, the electronic device 100 executes a temperature processing policy based on the temperature detected by the temperature sensor 180J.

[0125] The touch sensor 180K is also called a “touch panel.” The touch sensor 180K may be disposed on the display 194, and the touch sensor 180K and the display 194 constitute a touch screen, also called a “touch screen.” The touch sensor 180K is configured to detect touch actions performed on or near the touch sensor. The touch sensor may transmit the detected touch actions to an application processor to determine the type of touch event. Visual outputs related to touch actions may be provided via the display 194. In some other embodiments, the touch sensor 180K may also be disposed on the surface of the electronic device 100, at a location different from the display 194.

[0126] In this embodiment of the application, the electronic device 100 may use a touch sensor 180K to detect touch operations entered by a user on a touch screen and collect one or more touch parameters of the touch operation on the touch screen, such as touch location, touch area, touch force, touch direction, and touch time. The touch force is the pressure of the user's finger on the touch screen and is collected by the electronic device 100 when the user enters a touch operation on the touch screen. In some embodiments, the electronic device 100 may determine the touch force of a touch operation based on a change in a sensing parameter (e.g., capacitance value) on the touch sensor 180K, or it may collect the touch force of a touch operation using a pressure sensor 180A. In some embodiments, the electronic device 100 may perform identity identification of the user based on one or more collected touch parameters of the touch operation. After successful identity identification, the electronic device 100 may respond to touch operations, and further, after successful identity identification in this embodiment of the application, a locked application may be entered, a locked application function may be entered, and so on.

[0127] The bone conduction sensor 180M may acquire vibration signals. In some embodiments, the bone conduction sensor 180M may acquire vibration signals from the vibrating bones of the human vocal cords. The bone conduction sensor 180M may also communicate with the pulse of a human body in order to receive blood pressure pulsation signals.

[0128] Button 190 includes power buttons, volume buttons, etc. Button 190 may be a mechanical button or a touch button. Electronic device 100 may receive button inputs and generate button signal inputs related to user settings and function control of electronic device 100.

[0129] Motor 191 may generate vibration prompts. Motor 191 may be configured to provide call vibration prompts and touch vibration feedback.

[0130] Indicator 192 may be an indicator light and may be configured to show the charging status and power changes, or it may be configured to show messages, missed calls, notifications, etc.

[0131] The SIM card interface 195 is configured to connect to a SIM card. The SIM card may be inserted into or removed from the SIM card interface 195 to implement contact with or separation from the electronic device 100.

[0132] In this embodiment of the application, the structure of the electronic device 200 is described in the relevant description of the embodiment in Figure 1. Further details are not described again here.

[0133] Based on the hardware structure, system, and related concepts described, the cross-device authentication method provided in the embodiments of this application will be described below with reference to the attached drawings for different usage scenarios.

[0134] In the cross-device authentication method, electronic device 100 may establish a connection to at least one electronic device. After the connection is established, electronic device 100 may obtain identity authentication information from at least one electronic device. The at least one electronic device includes electronic device 200. In this embodiment of the application, when local authentication of electronic device 100 fails, electronic device 100 may initiate cross-device authentication, specifically determining whether the identity authentication information of at least one electronic device (e.g., electronic device 200) matches preset information. If the identity authentication information matches preset information, electronic device 100 determines that cross-device identity authentication is successful; otherwise, if the identity authentication information does not match preset information, electronic device 100 determines that cross-device identity authentication is failed. In this way, identity authentication of electronic device 100 is implemented based on local authentication results or biometric feature information of other reliable devices, effectively improving the convenience of identity authentication and creating a better user experience.

[0135] In some embodiments, the identity authentication information may include biometric feature information collected by the electronic device 200 using one or more authentication methods such as facial recognition, fingerprint recognition, and screen touch behavior recognition, and the preset information is the same type of biometric feature information of a preset user of the electronic device 100. For example, the biometric feature information transmitted to the electronic device 100 by the electronic device 200 is a facial image 1 collected by the electronic device 200, and the preset information is a facial image 2 of a preset user, which is pre-stored in the electronic device. When the degree of matching between the facial features of facial image 1 and the facial features of facial image 2 is greater than a preset threshold 1, the electronic device 100 may determine that the facial features of facial image 1 match the facial features of facial image 2 and that cross-device identity authentication is successful. When the degree of matching between the facial features of facial image 1 and the facial features of facial image 2 is less than or equal to the preset threshold 1, the electronic device 100 may determine that the facial features of facial image 1 do not match the facial features of facial image 2 and that cross-device identity authentication is failed. For example, the preset threshold 1 is equal to 90%.

[0136] In some embodiments, electronic devices 100 and 200 include the same preset user (e.g., user 1), and each electronic device 100 and 200 pre-stores the preset user's biometric feature information 1. The identity authentication information may include local authentication results obtained after electronic device 200 has performed identity authentication for users within detection range using one or more authentication methods such as facial recognition, fingerprint recognition, and screen touch behavior recognition. The preset information may be a local authentication result indicating successful identity authentication. The current local authentication result may be understood as successful authentication when electronic device 200 determines that the degree of matching between the biometric feature information collected by electronic device 200 and the preset user's biometric feature information 1 is greater than a preset threshold 1. For example, preset information 1 is equal to 1. When the local authentication result of electronic device 200 is equal to 1, it indicates successful identity authentication, and when the local authentication result is equal to 0, it indicates a failure of identity authentication. When the local authentication result transmitted by the electronic device 200 is equal to the preset information, or when the degree of matching with the facial features of face image 2 is equal to 100%, the electronic device 100 determines that the identity authentication information of the electronic device 200 does not match the preset information and that cross-device identity authentication is successful. Alternatively, when the local authentication result transmitted by the electronic device 200 is not equal to the preset information and the degree of matching with the facial features of face image 2 is not equal to 100%, the electronic device 100 determines that the identity authentication information of the electronic device 200 does not match the preset information and that cross-device identity authentication is unsuccessful.

[0137] The following describes the cross-device authentication method provided in this embodiment of this application for a voice control scenario.

[0138] In some embodiments of this application, user 1 is not within the detection range of electronic device 100 performing local authentication. When electronic device 100 receives voice command 1, electronic device 100 may obtain identity authentication information of at least one electronic device that establishes a connection with electronic device 100, and when it determines that the identity authentication information of electronic device 200 in at least one electronic device matches preset information, electronic device 100 determines cross-device identity authentication success, and then electronic device 100 may, in response to voice command 1, initiate function 1 triggered by voice command 1, in other words, perform the corresponding response action triggered by voice command 1. In this embodiment of this application, it can be understood that electronic device 100 may improve the convenience of voice control by implementing voice control of electronic device 100 based on the identity authentication information of electronic device 200.

[0139] In some embodiments of this application, the user must manually initiate the cross-device authentication function before the electronic device 100 can use cross-device authentication. In some embodiments of this application, the electronic device 100 may initiate the cross-device authentication function by default, and the user does not need to initiate the cross-device authentication function.

[0140] For example, Figure 3A shows an electronic device 100 and a user interface 11 used to display applications installed on the electronic device 100. The user interface 11 may include a status bar 101, a calendar indicator 102, a weather indicator 103, a tray 104 with commonly used application icons, and other application icons 105.

[0141] A tray 104 containing commonly used application icons may display a phone icon, a contact icon, a message icon, and a camera icon. Another application icon 105 may display an icon for application 1, a gallery icon, a music icon, a smart home icon, an email icon, a cloud sharing icon, a note icon, and a settings 105A icon. The user interface 10 may further include a page indicator 106. Another application icon may be distributed across multiple pages, and the page indicator 106 may be configured to indicate the specific page on which the application is currently viewed by the user. The user may flick left or right within the area of ​​another application icon to view application icons on a different page.

[0142] It should be understood that Figure 3A merely shows an example of a user interface for the electronic device 100 and does not constitute a limitation of this application to this embodiment.

[0143] As shown in Figure 3B, when a slide input gesture is detected on the status bar 101, the electronic device 100 may display a notification bar interface 12 in response to such a slide input. The notification bar interface 12 includes a window 107, which is used to control the on / off status of several shortcut functions. As shown in Figure 3B, the window 107 may display a "cross-device" on / off control 107A, or it may display an on / off control for another shortcut function (e.g., Wi-Fi, Bluetooth, flashlight, ringtone, auto-rotate, airplane mode, mobile data, location, or cast).

[0144] When the electronic device 100 can receive an input operation (e.g., a touch operation) performed on the on / off control 107, the electronic device 100 may initiate cross-device authentication in response to the input operation. As shown in Figure 3C, the electronic device 100 may indicate that cross-device authentication has been initiated by changing the display effect of the on / off control 107A.

[0145] In addition to initiating cross-device authentication in Windows 107, the user may, alternatively, initiate cross-device authentication in another manner, which is not specifically limited herein. For example, the user may, alternatively, initiate cross-device authentication in the system settings.

[0146] Based on the characteristics of the functions triggered by voice command 1, different voice control scenarios will be described separately below.

[0147] Voice Control Scenario 1: In this scenario, the electronic device 100 cannot identify the identity of user 1 based on voice command 1. Regardless of whether voice command 1 triggers a locked function or an unlocked function, the electronic device 100 initiates cross-device authentication and initiates the function triggered by the voice command only after successful identity authentication in cross-device authentication. In this embodiment of the application, the locked function may be an input of a locked application, or an input of a locked application function, or an input of a locked file (e.g., a picture, document, or video). This is not specifically limited herein.

[0148] Specifically, in a scenario where the electronic device 100 cannot identify user 1's identity based on voice command 1, one implementation has the ability to identify user identity based on voice, but does not have user 1's voiceprint features pre-stored. Another implementation does not have the ability to identify user identity based on voice.

[0149] In some embodiments, in voice control scenario 1, the electronic device 100 may be in a locked screen state when it receives voice command 1. In some embodiments, in voice control scenario 1, the electronic device 100 may be in an unlocked screen state when it receives voice command 1. This is not limited to the foregoing.

[0150] For example, as shown in Figures 4A to 4D, User 1 is not within the detection range of the electronic device 100's local continuous authentication, the electronic device 100 is unable to collect User 1's biometric characteristic information, and the local authentication result of the electronic device 100 is local authentication failure.

[0151] As shown in Figure 4A, User 1 is not within the detection range of Electronic Device 100 for local authentication, User 1 is using Electronic Device 200, and sends voice command 1, "Hey Celia, play song 1." Voice command 1 includes the wake-up keyword for Electronic Device 100, "Hey Celia." After receiving and recognizing the voice command, Electronic Device 100 initiates cross-device authentication to obtain the identity authentication information of Electronic Device 200. After determining that the identity authentication information of Electronic Device 200 matches the preset information, Electronic Device 100 may respond to voice command 1 by playing song 1 and sending the voice response "Okay, playing song 1" as shown in Figure 4B. In this case, Electronic Device 100 may display the playback interface for song 1 or it may be in a locked screen state. This is not specifically limited herein.

[0152] As shown in Figure 4C, User 1 is not within the detection range of the local authentication of electronic devices 100 and 200, and User 1 sends voice command 1, "Hey Celia, play song 1." Voice command 1 includes the wake-up keyword "Hey Celia" for electronic device 100. After receiving and recognizing the voice command, electronic device 100 initiates cross-device authentication to obtain the identity authentication information of electronic device 200. Since electronic device 200 does not detect User 1's biometric feature information, the identity authentication information of electronic device 200 does not match the preset information. Therefore, electronic device 100 may not play song 1 and instead send the voice response "Please unlock" as shown in Figure 4D. In this case, electronic device 100 may be in a locked screen state. In some embodiments, electronic device 100 in Figure 4D may alternatively display a screen unlock interface.

[0153] Voice Control Scenario 2: In this scenario, the electronic device 100 may identify the user's identity based on the user's voice. In some embodiments, after the electronic device 100 receives the user's voice command 1, and determines through voice recognition that the user is preset user 1 and that voice command 1 triggers an unlock function, the electronic device 100 responds to voice command 1 by directly initiating the function triggered by voice command 1. In some embodiments, after the electronic device 100 receives voice command 1, and determines through voice recognition that the user is preset user 1 and that voice command 1 triggers a locked function, the electronic device 100 initiates cross-device authentication. Only after determining that identity authentication has been successful in cross-device authentication does the electronic device 100 respond to voice command 1 by initiating the function triggered by voice command 1.

[0154] For example, Figures 5A to 5G each show the user interface in which application 1 is locked.

[0155] As shown in Figure 5A, another application icon 105 within the user interface 11 includes a system settings icon 105A. The electronic device 100 may receive an input action (e.g., a touch action) performed on the settings icon 105A and, in response to the input action, may display the settings user interface 13 shown in Figure 5B.

[0156] As shown in Figure 5B, the user interface 13 may include security and privacy settings 201, and may further include settings for XX accounts, wireless and network settings, device connection settings, application and notification settings, battery settings, display settings, sound settings, storage settings, user and account settings, etc. The security and privacy settings 201 may be used to set facial unlocking, fingerprint, lock screen password, application lock, etc. The electronic device 100 may receive input actions (e.g., touch actions) performed on the security and privacy settings 201, and in response to the input action, the electronic device 100 may display the user interface 14 for setting security and privacy as shown in Figure 5C.

[0157] As shown in Figure 5C, the user interface 14 may include an application lock setting item 202, and may further include settings for emergency help, positioning services, biometric recognition and passwords, private space, and security detection. The application lock setting item 202 may be used to lock private applications to effectively prevent unauthorized access by others. The electronic device 100 may receive input actions (e.g., touch actions) performed on the application lock setting item 202, and in response to the input action, the electronic device may display the application lock user interface 15 shown in Figure 5D.

[0158] As shown in Figure 5D, the user interface 15 may include an application search box and a settings bar for at least one application. The settings bar for at least one application may include a settings bar 203 for application 1, a settings bar 204 for application 2, a music settings bar, a payment settings bar, a gallery settings bar, a memo settings bar, and so on. An on / off control may be displayed on each settings bar, and the on / off control may be configured to enable / disable protective locking of application access items. For example, an on / off control 203A may be displayed on the settings bar 203 for application 1, and an on / off control 204A may be displayed on the settings bar 204 for application 2. When the on / off control is in the ON state and the user accesses the application, the user must authenticate their identity, i.e., unlock the application. When the on / off control is in the OFF state and the user accesses the application, the user can access the application directly without authenticating their identity.

[0159] For example, as shown in Figure 5D, the on / off control 203A is in the off state. The electronic device 100 may receive an input operation (e.g., a touch operation) performed on the on / off control 203A of the application, and in response to the input operation, the electronic device may switch the state of the on / off control 203A to the on state shown in Figure 5E.

[0160] As shown in Figure 5E, the user interface 15 may further include an application lock setting control 205. The electronic device 100 may receive an input action (e.g., a touch action) performed on the setting control 205, and in response to the input action, the electronic device 100 may display the application lock setting interface 16 shown in Figure 5F. The setting interface 16 may include multiple password type setting bars for the application lock, such as a lock screen password setting bar, a customizable password setting bar, a face recognition setting bar 206, and a fingerprint setting bar. In some embodiments of this application, the password types may further include voiceprint recognition, screen touch behavior feature recognition, etc. (not shown in Figure 5F). An on / off control may be displayed on each setting bar, and the on / off control may be configured to enable / disable the password type. For example, as shown in Figure 5F, the on / off control 206A is in the off state. The electronic device 100 may receive an input operation (e.g., a touch operation) performed on the application's on / off control 206A, and in response to the input operation, the electronic device 100 may switch the state of the on / off control 206A to the on state shown in Figure 5G.

[0161] In addition to the application locking methods shown in Figures 5A to 5G, users may lock applications using other methods, which are not specifically limited herein. For example, application 1 is locked in its configuration interface.

[0162] For example, Figures 5H to 5M show the user interface in which the application functions of Application 2 are locked, respectively.

[0163] As shown in Figure 5H, another application icon 105 within the user interface 11 includes icon 105A of application 2. See Figure 5E. Application 2 is an unlocked application. The electronic device 100 may receive an input action (e.g., a touch action) performed on icon 105B of application 2, and in response to the input action, the electronic device may display the user interface 17 of application 2 as shown in Figure 5I.

[0164] As shown in Figure 5I, the user interface 17 may include a menu tray 207, which may include multiple menu options such as Records option 207A, Friends option, Group option, and Me option 207B. The content displayed in the user interface 17 is related to the option currently selected in the menu tray 207. As shown in Figure 5I, the Records option 207A is currently selected in the menu tray 207, and the user interface 17 is configured to display multiple "chat records" items. The electronic device 100 may receive an input action (e.g., a touch action) performed on Me option 207B, and in response to the input action, the electronic device may display the Me interface 18 of application 2 as shown in Figure 5J.

[0165] As shown in Figure 5J, the Me interface 18 includes a setting item 208 for application 2, and may further include other setting items, such as a favorites setting item, a My Gallery setting item, and a My Wallet setting item. The electronic device 100 may receive an input action (e.g., a touch action) performed on the setting item 208, and in response to the input action, the electronic device may display the application 2 setting interface 19 shown in Figure 5K.

[0166] As shown in Figure 5K, the configuration interface 19 may include application function security configuration items 209 for application 2, and may further include other configuration items, such as message reminder configuration items, do not disturb mode configuration items, general configuration items, account switching configuration items, and logout configuration items. The electronic device 100 may receive input actions (e.g., touch actions) performed on configuration item 209, and in response to the input action, the electronic device may display the application function security configuration interface 20 shown in Figure 5L.

[0167] As shown in Figure 5L, the settings interface 20 may include a settings bar that may include at least one application function of application 2, and a password type settings bar 211 for the application function of application 2. As shown in Figure 5L, valid password types for the application function of application 2 may include facial recognition and fingerprint. For example, the settings bar for at least one application function may include the settings bar for messages 210, the settings bar for Me, the settings bar for favorites, the settings bar for My Gallery, and the settings items for My Wallet. An on / off control may be displayed on each settings bar, and the on / off control may be configured to enable / disable the protective lock for application access items. For example, the on / off control 210A is displayed on the settings bar 210. As shown in Figure 5L, the on / off control 210A is in the off state. The electronic device 100 may receive an input action (e.g., a touch action) performed on the application's on / off control 210A, and in response to the input action, the electronic device may switch the state of the on / off control 210A to the on state shown in Figure 5M. As shown in Figure 5M, the user may set Me of application 2 as a locked application function.

[0168] In addition to the application function locking methods shown in Figures 5H to 5M, users may lock applications using other methods, which are not specifically limited herein.

[0169] For example, as shown in Figures 6A to 6J, User 1 is not within the detection range where the electronic device 100 performs local authentication, and therefore the electronic device 100 cannot collect biometric characteristic information of User 1.

[0170] As shown in Figure 6A, User 1 is not within the detection range of the local authentication of electronic devices 100 and 200, and User 1 sends voice command 1, "Hey Celia, play song 1." Voice command 1 includes the wake-up keyword "Hey Celia" for electronic device 100. After receiving and recognizing voice command 1, when electronic device 100 recognizes that the voiceprint features of voice command 1 match the voiceprint features of User 1 and determines that Music is the unlocked application shown in Figure 5E, electronic device 100 responds to User 1's voice command by directly playing song 1 and sending the voice response "Okay, playing song 1" as shown in Figure 6B. In this case, the electronic device may display the playback interface for song 1 or may be in a locked screen state. This is not specifically limited herein.

[0171] As shown in Figure 6C, User 1 is not within the detection range of the local authentication of electronic devices 100 and 200, and User 1 sends voice command 1, "Hey Celia, use application 1 to send 'Should I go home to Anna?'" Voice command 1 includes the wake-up keyword for electronic device 100, "Hey Celia". After receiving and recognizing voice command 1, electronic device 100 recognizes that the voiceprint features of voice command 1 match the voiceprint features of User 1, and determines that application 1 is the locked application shown in Figure 5E, at which point electronic device 100 initiates cross-device authentication to obtain the identity authentication information of electronic device 200. Since User 1 is not within the detection range of electronic device 200, the identity authentication information of electronic device 200 does not match the preset information. Therefore, electronic device 100 may not execute the voice command and instead send the voice response "Please unlock me" as shown in Figure 6D. In some embodiments, the electronic device 100 may display the unlock interface 21 for application 1 shown in Figure 6D. From Figure 5G, it can be seen that the password types for application 1 include facial recognition, fingerprint, and lock screen password. Correspondingly, the unlock interface 21 shown in Figure 6D may include facial recognition controls 212, fingerprint controls 213, and lock screen password controls 214. In some embodiments, the electronic device 100 may alternatively be in a screen-off state. This is not specifically limited herein.

[0172] As shown in Figure 6E, User 1 is not within the detection range where Electronic Device 100 performs local authentication, User 1 is using Electronic Device 200, and sends voice command 1, "Hey, Celia, use Application 1 to send 'Are you going home?' to Anna." Voice command 1 includes the wake-up keyword for Electronic Device 100, "Hey, Celia." After receiving and recognizing voice command 1, Electronic Device 100 recognizes that the voiceprint features of voice command 1 match the voiceprint features of User 1, and determines that Application 1 is the locked application shown in Figure 5E, then Electronic Device 100 initiates cross-device authentication to obtain the identity authentication information of Electronic Device 200. When the identity authentication information of Electronic Device 200 matches the preset information, Electronic Device 100 may respond to voice command 1 by using Application 1 to send the message "Are you going home?" to "Anna," and send the voice response "Are you going home? sent to Anna" as shown in Figure 6F.

[0173] As shown in Figure 6G, User 1 is not within the detection range of the local authentication of electronic devices 100 and 200, and User 1 sends voice command 1, "Hey Celia, use application 2 to send 'I'm going to work' to Anna." Voice command 1 includes the wake-up keyword "Hey Celia" for electronic device 100. After receiving and recognizing voice command 1, electronic device 100 recognizes that the voiceprint features of the voice command match the voiceprint features of User 1, and determines that the "Messages" application function of application 2 is the locked application shown in Figure 5M, then electronic device 100 initiates cross-device authentication to obtain the identity authentication information of electronic device 200. Since User 1 is not within the detection range of electronic device 200, the identity authentication information of electronic device 200 does not match the preset information. Therefore, electronic device 100 may not execute the voice command and instead send the voice response "Please unlock me" as shown in Figure 6H. In some embodiments, the electronic device 100 may display an unlock interface 22 for the "Messages" application function of application 2, as shown in Figure 6H. From Figure 5M, it can be seen that the password types for the application function of application 2 include facial recognition and fingerprint. Correspondingly, the unlock interface 22 shown in Figure 6H includes facial recognition controls 215 and fingerprint controls 216.

[0174] As shown in Figure 6I, User 1 is not within the detection range where Electronic Device 100 performs local authentication, and User 1 is using Electronic Device 200 and sends voice command 1, "Hey Celia, use Application 2 to send 'I'm going to work' to Anna." Voice command 1 includes the wake-up keyword for Electronic Device 100, "Hey Celia." After Electronic Device 100 receives and recognizes voice command 1, and when it recognizes that the voiceprint features of the voice command match the voiceprint features of User 1 and determines that the "Messages" application function of Application 2 is the locked application shown in Figure 5M, Electronic Device 100 initiates cross-device authentication to obtain the identity authentication information of Electronic Device 200. When electronic device 100 determines that the identity authentication information of electronic device 200 matches the preset information, electronic device 100 may respond to voice command 1 by using application 2 to send "I'm going to work" to Lisa, and may send the voice response "I sent 'I'm going to work' to Lisa using application 2" as shown in Figure 6J. In some embodiments, electronic device 100 may display the message interface 23 for application 2 to Lisa, or it may maintain the lock screen state. This is not specifically limited herein.

[0175] In this embodiment of the application, a locked application may include a locked low-risk application and a locked high-risk application, and a locked application function may also include a locked low-risk application function and a locked high-risk application function. A locked low-risk function may include inputting a locked low-risk application and inputting a locked low-risk application function. A locked low-risk function may also include inputting a locked high-risk application and inputting a locked high-risk application function.

[0176] Voice Control Scenario 3: In this scenario, electronic device 100 may identify the user's identity based on the user's voice. After receiving voice command 1, if electronic device 100 determines, based on the voice, that the user is preset user 1 and that voice command 1 triggers a locked low-risk function 1, electronic device 100 initiates cross-device authentication. Electronic device 100 initiates the function triggered by voice command 1 in response to voice command 1 only when it determines that the identity authentication information of electronic device 200 matches the preset information. After receiving voice command 1, if electronic device 100 determines that voice command 1 triggers a locked high-risk function, electronic device 100 does not initiate the function triggered by voice command 1.

[0177] In voice control scenario 3, the locked high-risk function does not support cross-device authentication, and it can be understood that the electronic device 100 can only initiate the locked high-risk function after it has received a local unlock operation performed by the user on the electronic device 100.

[0178] In voice control scenario 3, when voice command 1 triggers the unlock function, the electronic device 100 may, after receiving voice command 1, initiate cross-device authentication and, only when it determines that identity authentication is successful, respond to voice command 1 and initiate the function triggered by voice command 1, or the electronic device 100 may, without needing to initiate cross-device authentication, respond to voice command 1 and initiate the function triggered by voice command 1. This is not specifically limited herein.

[0179] In this embodiment of the application, locked low-risk (high-risk) applications may be configured by the user or may be configured by default by the electronic device. Locked high-risk (low-risk) application functions may be configured by the user or may be configured by default by the electronic device. This is not specifically limited herein. For example, by default, the electronic device may consider all application functions such as money transfer, settlement, and red packets to be high-risk application functions.

[0180] For example, Figures 7A to 7C each show a user interface for configuring a low-risk application within a locked application. In embodiments of this application, applications other than low-risk applications within a locked application are high-risk applications, and high-risk applications do not support cross-device authentication.

[0181] As shown in Figure 7A, the user interface 16 may further include a low-risk setting bar 301 and a setting bar for added low-risk applications. For example, the setting bar for added low-risk applications includes a gallery setting bar 302, which is provided with a removal control 302A, configured to remove the gallery from the added low-risk applications. The low-risk setting bar 301 is provided with an add control 301A. The electronic device 100 may receive an input action (e.g., a touch action) performed on the add control 301A, and in response to the input action, the electronic device may display the window 303 shown in Figure 7B on the user interface 16. The window 303 includes setting bars for multiple locked applications, such as a setting bar 304 for application 1, a payment setting bar, a gallery setting bar, a memo setting bar, and an email setting bar. Each locked application setting bar displays an on / off control, which may be configured to set the application as a low-risk application. For example, the settings bar 304 for application 1 displays an on / off control 304A. The electronic device 100 may receive an input action (e.g., a touch action) performed on the on / off control 304A, and in response to the input action, the electronic device may display the settings bar 305 for application 1 shown in Figure 7C on the user interface 16. The settings bar 305 for application 1 is provided with a removal control 305A, which is configured to remove application 1 from the list of added low-risk applications.

[0182] Refer to Figures 6E to 6F. User 1 is using electronic device 200 and intends to control electronic device 100 based on voice command 1 to send a message to "Anna" using application 1. When electronic device 100 receives and recognizes user 1's voice command 1 and determines that application 1 is a locked, low-risk application as shown in Figure 7C, electronic device 100 initiates cross-device authentication to obtain the identity authentication information of electronic device 200. When electronic device 100 determines that the identity authentication information of electronic device 200 matches the preset information, electronic device 100 responds to voice command 1 and sends a message to "Anna" using application 1.

[0183] For example, as shown in Figures 8A to 8D, User 1 is not within the detection range where the electronic device 100 performs local authentication, and therefore the electronic device 100 cannot collect biometric characteristic information of User 1.

[0184] As shown in Figure 8A, User 1 is using electronic device 200 and sends voice command 1, "Hey, Celia, open the payment application." Voice command 1 includes the wake-up keyword "Hey, Celia" for electronic device 100. After receiving and recognizing voice command 1, if electronic device 100 recognizes that the voiceprint features of the voice command match the voiceprint features of User 1 and determines that the payment application is a high-risk application (i.e., not a low-risk application as shown in Figure 7C), electronic device 100 may not execute voice command 1 and instead send the voice response "Please unlock" as shown in Figure 8B.

[0185] In some embodiments, the electronic device 100 assumes by default that the money transfer function in all applications is a high-risk application function. As shown in Figure 8C, user 1 is using the electronic device 200 and sends voice command 1, "Hey Celia, send 10 yuan to Anna using application 1." Voice command 1 includes the wake-up keyword for the electronic device 100, "Hey Celia." After receiving and recognizing voice command 1, if the electronic device 100 recognizes that the voiceprint features of the voice command match the voiceprint features of user 1 and determines that the money transfer is a high-risk application function, the electronic device 100 may not execute the voice command and instead send the voice response "Please unlock" as shown in Figure 8D. Whether the application function is a locked low-risk application function or an unlocked application function, high-risk applications may be understood not to support cross-device authentication.

[0186] In some embodiments of this application, in three voice control scenarios, when electronic device 100 receives voice command 1 and initiates cross-device authentication, electronic device 100 obtains identity authentication information for electronic device 200. Only when electronic device 100 determines that the identity authentication information for electronic device 200 matches preset information and that the distance between electronic device 200 and electronic device 100 is less than the preset distance, does device 100 initiate function 1 triggered by voice command 1. It can be understood that only when the distance between electronic device 200 and electronic device 100 is less than the preset distance does electronic device 100 determine that the identity authentication information for electronic device 200 is a secure and reliable authentication result.

[0187] In some embodiments of this application, in three voice control scenarios, when electronic device 100 receives voice command 1 and initiates cross-device authentication, electronic device 100 obtains identity authentication information for electronic device 200. Electronic device 100 initiates function 1 corresponding to voice command 1 only when it determines that the identity authentication information for electronic device 200 matches preset information and that electronic device 200 is in a secure state. In some embodiments, electronic device 200 being in a secure state may mean that electronic device 200 is not rooted, free of Trojan viruses, and that traffic monitoring is normal. It may be understood that electronic device 100 determines that the identity authentication information for electronic device 200 is a secure and reliable authentication result only when electronic device 200 is in a secure state.

[0188] In some embodiments of this application, in three voice control scenarios, when electronic device 100 receives voice command 1 and initiates cross-device authentication, electronic device 100 obtains identity authentication information of electronic device 200. Electronic device 100 initiates function 1 corresponding to voice command 1 only when it determines that the identity authentication information of electronic device 200 matches preset information and that the priority of the authentication method of electronic device 200's local sequential authentication is not lower than that of electronic device 100. It can be understood that electronic device 100 determines that the identity authentication information of electronic device 200 is a secure and reliable authentication result only when the priority of the authentication method of electronic device 200's local sequential authentication is not lower than that of electronic device 100. For example, the priority of the authentication methods of local sequential authentication may be sorted in descending order, such as face recognition (iris recognition), heart rate detection, gait recognition, and screen touch behavior recognition.

[0189] In some embodiments of this application, in three voice control scenarios, when electronic device 100 receives voice command 1 and initiates cross-device authentication, electronic device 100 obtains identity authentication information for electronic device 200. Electronic device 100 initiates the function triggered by voice command 1 only when it determines that the identity authentication information for electronic device 200 matches preset information and that electronic device 200 satisfies at least two of the following three conditions: "the distance between electronic device 200 and electronic device 100 is less than the preset distance," "electronic device 200 is in a secure state," and "the priority of the authentication method for local sequential authentication of electronic device 200 is not lower than that of electronic device 100." It can be understood that electronic device 100 determines that the identity authentication information for electronic device 200 is a secure and reliable authentication result only when electronic device 200 satisfies at least two of the three conditions.

[0190] Additionally, in the three voice control scenarios, in some embodiments, when electronic device 100 detects biometric feature information of a non-preset user, electronic device 100 maintains the lock screen state regardless of whether the identity authentication information transmitted by electronic device 200 matches the preset information. In some embodiments, when electronic device 200 detects the user's non-preset biometric feature information, the identity authentication information transmitted by electronic device 200 to electronic device 100 may indicate that electronic device 200 has detected biometric feature information of a non-preset user. After receiving the identity authentication information, electronic device 100 remains in the lock screen state.

[0191] The following describes the cross-device authentication method provided in this embodiment of this application for a cast control scenario.

[0192] For example, Figures 9A to 9 show a casting method in which electronic device 100 actively performs a cast on electronic device 200.

[0193] As shown in Figure 9A, the notification bar interface 12 further includes cast control 107B. When the electronic device 100 can receive an input action (e.g., a touch action) performed on the cast control 107B, the electronic device 100 may display the window 401 shown in Figure 9B in response to the input action.

[0194] As shown in Figure 9B, window 401 includes at least one cast device option, for example, a notebook computer XXX option, an electronic device 200 option 401A, and a smart television XXX option. When electronic device 100 can receive an input operation (e.g., a touch operation) performed on option 401A of electronic device 200, electronic device 100 may send a cast request to electronic device 200 in response to the input operation.

[0195] As shown in Figure 9C, the electronic device 200 displays a window 402 on the user interface 31 based on a cast request sent by the electronic device 100. The window 402 includes an OK control 402A and a rejection control 402B. The electronic device 200 may receive an input action (e.g., a touch action) made in response to the rejection control 402B. In response to the input action, the electronic device 200 may close the window 402 and further send a rejection response to the cast request to the electronic device 100. When the electronic device 200 can receive an input action (e.g., a touch action) made in response to the OK control 402A, the electronic device 200 may display a cast window 403 on the user interface 31 as shown in Figure 9D in response to the input action. The cast window 403 displays the cast content sent by the electronic device 100, i.e., the user interface 32.

[0196] In some embodiments, after receiving a cast request sent by electronic device 100, electronic device 200 may directly display the cast window 403 based on the cast content of electronic device 100 without needing to receive input actions performed by the user to confirm the cast.

[0197] In some embodiments, the user interface 32 transmitted by the electronic device 100 includes some or all of the current display interface (user interface 11) of the electronic device 100. As shown in Figure 9D, the user interface 32 includes interface content other than the status bar in the user interface 11 of the electronic device 100, and includes icons 404 for other applications. For example, the icons 404 for other applications include icon 404A for application 1, icon 404B for gallery, icon 404C for music, icon 404D for application 2, icon 404E for email, icon 404E for cloud sharing, icon for notes, and icon for settings.

[0198] In some embodiments, the user interface 31 may be the home screen of the electronic device 200. It should be understood that Figures 9C and 9D merely show examples of user interfaces for the electronic device 200, respectively, and do not constitute a limitation of this application to this embodiment.

[0199] For example, Figures 9E to 9H show a casting method in which electronic device 200 actively acquires the cast content of electronic device 100.

[0200] Figure 9E shows a user interface 31 of an electronic device 200, which is used to display applications installed on the electronic device 200. As shown in Figure 9E, the user interface 31 includes icons 405 for several applications, such as a cloud sharing icon, a stock icon, a settings icon, a screen sharing icon 405A, an email icon, a music icon, a video icon, a browser icon, and a gallery icon. If the electronic device 200 can receive an input action (e.g., a touch action) performed on the screen sharing icon 405A, in response to the input action, the electronic device 200 may display the screen sharing user interface 33 shown in Figure 9F.

[0201] As shown in Figure 9F, the user interface 33 includes an account login control group 406 and a back control 407. The account login control group 406 includes an account input box 406A, a password input box 406B, and a login control 406C, and may further include an account registration control and a password retrieval control. The account registration control is configured to register a new account, and the password retrieval control is configured to retrieve the password for a registered account. When the electronic device 200 receives an input action (e.g., a touch action) performed on the back control 407, the electronic device 200 may display the previous page of the current page.

[0202] As shown in Figure 9F, after the user enters an account in the account input box 406A and the corresponding password in the password input box 406B, the electronic device 200 may display the account user interface 34 shown in Figure 9G when it can receive an input action (e.g., a touch action) performed on the login control 406C.

[0203] As shown in Figure 9G, the user interface 33 may include a profile picture, a user account 408, a return control 409, and options 410 for at least one device logged into the same account, such as the option for Notebook Computer XXX and option 410A for Electronic Device 100. The return control 409 is configured to return to the previous page of the current page. When Electronic Device 200 can receive an input action (e.g., a touch action) performed on option 410A of Electronic Device 200, in response to the input action, Electronic Device 200 may retrieve cast content (i.e., user interface 32) from Electronic Device 100 and display the cast window 411 shown in Figure 9H on the user interface 34. The content displayed in the cast window 410 is the user interface 32. The content displayed in the cast window 411 may be part or all of the home screen 11 of Electronic Device 100, or part or all of the current display interface of Electronic Device 100. This is not specifically limited herein.

[0204] In this embodiment of the application, the electronic device 100 or the electronic device 200 may, alternatively, select an application user interface from an application running on the electronic device 100 for casting. This is not specifically limited herein.

[0205] In addition to the casting method, in this embodiment of this application, the cast content of electronic device 100 may be displayed on electronic device 200 using another casting method. This is not specifically limited herein.

[0206] In the following cast scenarios, it should be noted that in some embodiments, the electronic device 100 pre-stores the biometric feature information 1 of user 1, but does not pre-store the biometric feature information of user 2. In some embodiments, electronic devices 100 and 200 have the same preset user, and both pre-store the biometric feature information 1 of user 1, but do not pre-store the biometric feature information of user 2. Local authentication may be successful when performed by electronic device 200 for user 1.

[0207] Cast Control Scenario 1: Electronic device 200 receives and displays cast content 1 transmitted by electronic device 100. Electronic device 100 obtains the identity authentication information of electronic device 200's local serial authentication in real time. When electronic device 100 determines that the identity authentication information of electronic device 200 does not match the preset information, electronic device 100 stops transmitting the cast content to electronic device 200. In this way, electronic device 100 controls the cast based on the identity authentication information of electronic device 200, preventing unauthorized persons from viewing the cast content of electronic device 100 and improving cast security.

[0208] For example, as shown in Figure 9I, user 1 is using electronic device 200, and the cast window 403 of electronic device 200 displays the user interface 32. As shown in Figures 9I and 9J, after the user of electronic device 200 changes from user 1 to user 2, electronic device 200 may stop displaying the cast content of electronic device 100 and display an exit control 412 and prompt information "Cast interrupted" in the cast window 403. The user may tap the exit control 412, and in response to the detected tap, electronic device 200 may stop displaying the cast window 403.

[0209] In some embodiments, when the user of electronic device 200 changes from user 1 to user 2, electronic device 100 may determine that the identity authentication information of electronic device 200 does not match the preset information, and electronic device 100 may further cast the screen unlock interface of electronic device 100 onto electronic device 200 for display. Note that the cast can only continue after the user has unlocked the screen of electronic device 100. For example, the user enters the password for electronic device 100 into the screen unlock interface of electronic device 100 displayed by electronic device 200, and electronic device 200 transmits that password to electronic device 100. When it determines that the password is correct, electronic device 100 may continue transmitting the cast content.

[0210] In some embodiments, when the user of the electronic device 200 changes from user 1 to user 2, and user 2 is not a preset user of the electronic device 200, the electronic device 200 may further display its screen unlock interface in full screen. Only after unlocking the screen of the electronic device 200 can the user continue to use the electronic device 200 and view the cast content of the electronic device 100.

[0211] In some embodiments of this application, electronic device 200 receives and displays cast content 1 from electronic device 100. Electronic device 200 may receive a touch action 1 performed on cast content 1 and transmit the touch parameters of touch action 1 to electronic device 100. After receiving the touch parameters of touch action 1, electronic device 100 may initiate cross-device authentication to obtain identity authentication information for electronic device 200. When electronic device 100 determines that authentication is successful based on the identity authentication information for electronic device 200, electronic device 100 may initiate a function 2 triggered by touch action 1 in response to touch action 1 and draw cast content 2 corresponding to that function 2. Electronic device 100 transmits cast content 2 to electronic device 200, which receives cast content 2 and displays it in the cast window. When electronic device 100 determines that the identity authentication information for electronic device 200 does not match preset information, electronic device 100 may stop transmitting cast content to electronic device 200. In this embodiment of the application, it can be understood that the electronic device 100 may improve cast safety by implementing cast control of the electronic device 100 based on the identity authentication information of the electronic device 200.

[0212] Based on the different characteristics of function 2 triggered by touch action 1, the cast control scenarios will be described separately below.

[0213] Cast Control Scenario 2: In this scenario, when the function 2 triggered by the touch action 1 is a lock function or an unlock function, the electronic device 100 must perform cross-device authentication. Only after successful authentication does it initiate the function 2 triggered by the touch action, draw the corresponding cast content, and send the cast content to the electronic device 200.

[0214] Unlike Cast Scenario 2, in Cast Control Scenario 1, it can be understood that electronic device 100 obtains the identity authentication information of electronic device 200 in real time. Regardless of whether a touch operation is received on the cast content, if electronic device 100 determines that the identity authentication information of electronic device 200 does not match the preset information, electronic device 100 stops sending the cast content to electronic device 200.

[0215] For example, as shown in Figures 10A to 10D, User 1 is not within the detection range where the electronic device 100 performs local authentication, and therefore the electronic device 100 cannot collect biometric characteristic information of User 1.

[0216] As shown in Figure 10A, user 1 is using electronic device 200. The cast window 403 displayed by electronic device 200 includes the Music icon 404C. See Figure 5E. Music is an unlocked application. Electronic device 200 may receive a touch action 1 (e.g., a tap) performed on the Music icon 404C and notify electronic device 100 of such touch input. After receiving notification from electronic device 200, electronic device 100 may retrieve the identity authentication information of electronic device 200 and, when it determines that the identity authentication information of electronic device 200 matches the preset information, draw the home page interface 35 of the Music application in response to the touch action 1. Electronic device 100 sends the home page interface 35 to electronic device 200, and electronic device 200 receives the home page interface 35 shown in Figure 10B and displays it in the cast window 403.

[0217] It should be noted that when electronic device 200 displays cast content transmitted by electronic device 100, electronic device 100 may be in a locked screen state, display the cast content, or display another application interface. This is not specifically limited herein.

[0218] As shown in Figure 10C, user 2 is using electronic device 200, and the identity authentication performed by electronic device 200 on user 2 fails. Electronic device 200 may receive a touch action 1 (e.g., a tap) performed on the music icon 404C and notify electronic device 100 of the touch action. After receiving the notification from electronic device 200, electronic device 100 initiates cross-device authentication. When electronic device 100 determines that the identity authentication information of electronic device 200 does not match the preset information, it stops sending the cast content to electronic device 200, and electronic device 200 may display the prompt information "Cast interrupted" shown in Figure 10D in the cast window 403.

[0219] As shown in Figure 10E, user 1 is using electronic device 200. The cast window displayed by electronic device 200 further includes the gallery icon 404. See Figure 5E. The gallery is a locked application. Electronic device 200 may receive a touch action 1 (e.g., a tap) performed on the gallery icon 404B and notify electronic device 100 of the touch action. After receiving the notification from electronic device 200, electronic device 100 initiates cross-device authentication. When electronic device 200 determines that its identity authentication information matches the preset information, electronic device 100 may, in response to touch action 1, draw the gallery user interface 36. Electronic device 100 sends the user interface 36 to electronic device 200, which receives the user interface 36 shown in Figure 10F and displays it in the cast window 403.

[0220] In some embodiments of this application, when electronic device 200 displays the user interface of a locked application in the cast window 403, electronic device 100 obtains the identity authentication information of electronic device 200 in real time. When it is determined that the identity authentication information of electronic device 200 does not match the preset information, electronic device 100 stops transmitting cast content, and the cast window 403 of electronic device 200 stops displaying the cast content. For example, as shown in Figures 10F and 10G, electronic device 200 displays the user interface 36 of the gallery in the cast window 403. After the user of electronic device 200 switches from user 1 to user 2, the cast window 403 of electronic device 200 stops displaying the cast content.

[0221] As shown in Figure 10H, user 2 is using electronic device 200. Electronic device 200 may receive a touch action 1 (e.g., a tap) performed on the gallery icon 404B and notify electronic device 100 of the touch action. After receiving the notification from electronic device 200, electronic device 100 initiates cross-device authentication and determines that the identity authentication information of electronic device 200 does not match the preset information. Electronic device 100 stops sending cast content to electronic device 200, and electronic device 200 displays the prompt information "Cast interrupted" shown in Figure 10I in the cast window 403.

[0222] Cast Control Scenario 3: In this scenario, after receiving touch operation 1 using electronic device 200, when it is determined that touch operation 1 triggers unlocked function 2, electronic device 100 responds to touch operation 1 by directly drawing cast content corresponding to function 2 and sending the cast content to electronic device 200. After receiving touch operation 1 using electronic device 200, when it is determined that touch operation 1 triggers locked function 2, electronic device 100 initiates cross-device authentication, and only after determining that cross-device authentication is successful does it respond to touch operation 1 by drawing cast content corresponding to function 2 and sending the cast content to electronic device 200.

[0223] Figures 5A to 5G each show the relevant interfaces to which an application according to one embodiment of this application is locked. Figures 5H to 5M each show the relevant interfaces to which an application function according to one embodiment of this application is locked.

[0224] In some embodiments of this application, during the casting process, electronic device 100 obtains identity authentication information of electronic device 200 in real time. When the cast window of electronic device 200 displays the user interface of a locked application or the user interface of a locked application function, if it determines that the identity authentication information of electronic device 200 does not match the preset information, electronic device 100 stops sending cast content to electronic device 200.

[0225] Refer to Figure 5E. Application 2 is an unlocked application. Refer to Figure 5M. Me of Application 2 is a locked application function. As shown in Figure 11A, User 2 is using electronic device 200. The user interface 32 displayed in the cast window 403 includes the icon 404D of Application 2. Electronic device 200 may receive a touch action 1 (e.g., a tap) performed on the icon 404D of Application 2 and notify electronic device 100 of the touch action. After receiving the notification from electronic device 200, electronic device 100 draws the user interface 37 of Application 2 in response to the touch action 1. Electronic device 100 sends the user interface 37 to electronic device 200, which receives the user interface 37 shown in Figure 11B and displays it in the cast window 403. As shown in Figure 11B, the user interface 37 includes option 413 of Me. Electronic device 200 may receive a touch operation performed on option 413 of Me and notify electronic device 100 of the touch operation. After receiving notification from electronic device 200, electronic device 100 initiates cross-device authentication and, when it determines that the identity authentication information of electronic device 200 does not match the preset information, electronic device 100 stops sending cast content to electronic device 200. As shown in Figure 11C, electronic device 200 stops displaying the cast content of electronic device 100 in the cast window 403.

[0226] Refer to Figure 5E. The gallery is a locked application. Refer to Figures 10E to 10I. In the case of a locked application gallery, electronic device 100 may implement gallery cast control based on the identity authentication information of electronic device 200. As shown in Figures 10E and 10F, user 1 uses electronic device 200. When electronic device 100 determines that the gallery on which a touch operation is performed is a locked application, it initiates cross-device authentication. When it determines that cross-device authentication is successful, electronic device 200 may display the cast content of electronic device 100, i.e., the gallery's user interface 36. As shown in Figures 10H and 10I, user 2 uses electronic device 200. When electronic device 100 determines that the gallery on which a touch operation is performed is a locked application, it initiates cross-device authentication, determines that cross-device authentication has failed, electronic device 100 stops sending the cast content to electronic device 200, and electronic device 200 stops displaying the cast content of electronic device 100. As shown in Figures 10F and 10G, when the cast window 403 of electronic device 200 displays the gallery user interface 36, after the user of electronic device 200 switches from user 1 to user 2, the identity authentication information of electronic device 200 does not match the preset information, and electronic device 200 stops displaying the cast content of electronic device 100.

[0227] Cast Control Scenario 4: In this scenario, after electronic device 100 receives touch action 1, when it determines that touch action 1 triggers the low-risk function 2 of lock, electronic device 100 initiates cross-device authentication, determines that cross-device authentication is successful, and responds to touch action 1 by drawing the user interface of function 2 triggered by touch action 1. After electronic device 100 receives touch action 1, when it determines that touch action 1 triggers the high-risk function 2 of lock, electronic device 100 stops sending cast content to electronic device 200, and electronic device 200 stops displaying the cast content of electronic device 100.

[0228] In cast control scenario 4, for the unlock function 1, after electronic device 100 receives touch operation 1 using electronic device 200, electronic device 100 may initiate cross-device authentication, and only when it determines that cross-device authentication is successful, in response to touch operation 1, it may draw the user interface of function 2 triggered by touch operation 1 and cast the user interface onto electronic device 200, or electronic device 100 may directly draw the user interface of function 2 triggered by touch operation 1 in response to touch operation 1 and cast the user interface onto electronic device 200 without the need to initiate cross-device authentication. This is not specifically limited herein.

[0229] Figures 7A to 7C each show the relevant interfaces in which a locked, low-risk application is configured according to one embodiment of this application.

[0230] Refer to Figure 7C. The gallery is a locked, low-risk application that supports cross-device authentication. Refer to Figures 10E to 10I. In the case of a locked, low-risk application gallery, electronic device 100 may implement gallery cast control based on the identity authentication information of electronic device 200. As shown in Figures 10E and 10F, user 1 uses electronic device 200. When triggered by a touch action, electronic device 100 determines that the gallery is a locked, low-risk application, it initiates cross-device authentication, determines that cross-device authentication is successful, and electronic device 200 may display the cast content of electronic device 100, i.e., the gallery's user interface 36. As shown in Figures 10H and 10I, user 2 uses electronic device 200. When electronic device 100 determines that the gallery triggered by a touch operation is a locked, low-risk application, electronic device 100 initiates cross-device authentication, determines that cross-device authentication has failed, stops sending cast content to electronic device 200, and electronic device 200 stops displaying the cast content of electronic device 100. As shown in Figures 10F and 10G, when the cast window 403 of electronic device 200 displays the gallery's user interface 36 and the user of electronic device 200 switches from user 1 to user 2, electronic device 200 stops displaying the cast content of electronic device 100.

[0231] Refer to Figure 12A. The email is a locked, high-risk application. For example, as shown in Figure 12A, user 1 is using electronic device 200. The user interface 32 displayed in the cast window 403 includes an email icon 404E. Electronic device 200 may receive a touch action 1 (e.g., a tap) performed on the email icon 404E and notify electronic device 100 of the touch action. When electronic device 100 determines that the email on which the touch action was performed is a locked, high-risk application, it stops sending cast content to electronic device 200. As shown in Figure 12B, electronic device 200 may stop displaying the cast content on electronic device 100 and display the prompt information "High-risk operation. Please unlock on electronic device 100."

[0232] In some embodiments of this application, User 1 is the owner of electronic device 100 and electronic device 200. In addition to User 1, other authorized users may be added to electronic device 200, which stores the biometric feature information of other authorized users. Another authorized user may have permission to unlock the screen, unlock locked applications, and unlock locked application functions. The identity authentication information of another authorized user also supports cross-device authentication. When electronic device 200 collects the biometric feature information of another authorized user, the local authentication result of electronic device 200 may also be authentication successful.

[0233] For example, Figures 13A to 13E each show the relevant interfaces on which an electronic device adds biometric authentication feature information (e.g., facial features) of an authorized user.

[0234] As shown in Figure 13A, the user interface 14 includes biometric recognition and password setting items 501. The electronic device 100 may receive an input action (e.g., a touch action) performed on the setting item 501, and in response to the input action, the electronic device may display the biometric recognition and password setting interface 38 shown in Figure 13B. As shown in Figure 13B, the setting interface 38 includes a face recognition setting item 502, a fingerprint setting item, a lock screen password change setting item, and a lock screen password disable setting bar. The electronic device 100 may receive an input action (e.g., a touch action) performed on the face recognition setting item 502, and in response to the input action, the electronic device may display the face recognition user interface 39 shown in Figure 13C. As shown in Figure 13C, the setting interface 39 may include a control 503 for deleting face data 1, a control 504 for adding an alternate appearance, and a face recognition permission setting bar. Face data 1 is the face data of user 1, and the control 503 for deleting face data 1 may be configured to delete the face data entered by user 1. The electronic device 100 may also receive input actions (e.g., touch actions) performed on control 504, and in response to the input action, the electronic device 100 may display the appearance input interface 40 shown in Figure 13D. The window 505 in the appearance input interface 40 is configured to display the face image collected by the camera. After the appearance of user 3 has been entered, the electronic device 100 may display the control 506 for deleting face data 2 on the configuration interface 39, as shown in Figure 13E. The control 506 for deleting face data 2 may be configured to delete the face data entered by user 3. Face data 2 is the face data of user 3, and after user 3's face data has been added, user 3 may be understood to be an authorized user for face recognition.

[0235] In addition to the method of adding authorized users as shown in Figure 13A and Figure 13E, authorized users may be added in other ways in this embodiment of the application, which are not specifically limited herein. Additionally, the electronic device 200 may further collect other biometric feature information of user 3, such as iris, screen touch behavior features, or heart rate features. The steps and procedures are the same as those in Figures 13A to 13E, which are not specifically limited herein.

[0236] In some embodiments, for four cast control scenarios, after the user adds the facial data of authorized user 3, electronic device 100 may transmit user 3's facial data to electronic device 200, and as a result, user 3 also becomes an authorized user of electronic device 200. If user 3 is also an authorized user of electronic device 200, local authentication of electronic device 200 is successful when the facial image of user 1 or authorized user 3 is collected during the process in which electronic device 200 performs local sequential authentication by facial recognition. If user 3 is not an authorized user of electronic device 200, electronic device 100 may retrieve the facial image that belongs to user 1 or authorized user 3 and has been collected by electronic device 200, and electronic device 100 performs identity authentication.

[0237] For example, in cast control scenario 1, as shown in Figure 14A, user 1 is using electronic device 200, and the cast window 403 of electronic device 200 displays the user interface 32. As shown in Figures 14A and 14B, after the user of electronic device 200 changes from user 1 to authorized user 3, electronic device 100 determines that cross-device authentication of electronic device 200 is successful, and electronic device 100 continues to send cast content to electronic device 200, and electronic device 200 continues to display the cast content of electronic device 100. As shown in Figures 14B and 14C, after the user of electronic device 200 changes from authorized user 3 to unauthorized user 2, electronic device 100 determines that cross-device authentication of electronic device 200 has failed, and electronic device 100 stops sending cast content to electronic device 200, and electronic device 200 stops displaying the cast content of electronic device 100.

[0238] In a cast control scenario, it should be noted that electronic device 100 initiates cross-device authentication. When electronic device 100 determines that the identity authentication information of electronic device 200 does not match the preset information, electronic device 100 stops sending cast content to electronic device 200, and electronic device 200 may close the cast window, display the screen unlock interface of electronic device 200 in full screen, display the screen unlock interface of electronic device 100 in the cast window, or display the prompt information "Cast interrupted" in the cast window. This is not limited to what is described herein.

[0239] Optionally, in some embodiments of this application, in four cast control scenarios, when electronic device 100 initiates cross-device authentication, electronic device 100 obtains identity authentication information for electronic device 200. Electronic device 100 continues to transmit cast content to electronic device 200 only when it determines that the identity authentication information for electronic device 200 matches preset information and the distance between electronic device 200 and electronic device 100 is less than the preset distance.

[0240] In some embodiments of this application, in four cast control scenarios, when electronic device 100 initiates cross-device authentication, electronic device 100 obtains identity authentication information for electronic device 200. Electronic device 100 continues to transmit cast content to electronic device 200 only when it determines that the identity authentication information for electronic device 200 matches preset information and that electronic device 200 is in a secure state.

[0241] In some embodiments of this application, in four cast control scenarios, when electronic device 100 initiates cross-device authentication, electronic device 100 obtains identity authentication information for electronic device 200. Electronic device 100 continues to transmit cast content to electronic device 200 only when it determines that the identity authentication information for electronic device 200 matches preset information and that the priority of the authentication method of electronic device 200's local sequential authentication is not lower than that of electronic device 100.

[0242] In some embodiments of this application, in four cast control scenarios, when the electronic device 100 starts cross-device authentication, the electronic device 100 obtains the identity authentication information of the electronic device 200. Only when the electronic device 100 determines that the identity authentication information of the electronic device 200 matches the preset information, and the electronic device 200 determines that at least two of the three conditions of "the distance between the electronic device 200 and the electronic device 100 is smaller than the preset distance", "the electronic device 200 is in a secure state", and "the priority of the authentication method of the local continuous authentication of the electronic device 200 is not lower than that of the electronic device 100" are satisfied, will the electronic device 100 continue to send the cast content to the electronic device 200. Only when the electronic device 200 satisfies at least two of the three conditions, will the electronic device 100 determine that the identity authentication information of the electronic device 200 is secure and reliable.

[0243] In addition to the voice control scenario and the cast scenario, the cross-device authentication method provided in this embodiment of this application may be further applied to cross-device authentication in other scenarios. This is not specifically limited in this specification.

[0244] The foregoing content is the scenario in which the cross-device authentication method in this application is implemented. Hereinafter, the cross-device authentication system related to the cross-device authentication method provided in the embodiments of this application will be described.

[0245] For example, as shown in FIG. 15A, the system includes an electronic device 100 and an electronic device 200 (hereinafter collectively referred to as electronic devices). The continuous authentication modes of each of the electronic device 100 and the electronic device 200 may include a local continuous authentication mode and a cross-device continuous authentication mode. The electronic device 100 and the electronic device 200 each include a continuous feature collection module, a continuous feature authentication module, a local authentication result management module, an authentication mode management module, and a cross-device authentication information acquisition module.

[0246] The continuous feature collection module is configured to continuously collect biometric feature information of the user in the detection range, such as face features, iris features, or screen touch behavior features. The biometric feature information is used for authentication methods such as face recognition, iris recognition, and screen touch behavior recognition.

[0247] The continuous feature authentication module is configured to match the biometric feature information collected by the continuous feature collection module with the biometric feature information pre-stored in the electronic device. When the matching degree reaches a preset threshold 1, the electronic device may determine that the current local authentication result is a successful authentication.

[0248] For example, the electronic device 100 performs local continuous authentication by face recognition. The electronic device 100 uses the continuous feature collection module to obtain face feature information collected by the electronic device 100, and uses the continuous feature authentication module to identify the matching degree between the collected face feature information and the face feature information of the preset user. When the matching degree between the collected face feature information and the face feature information of the preset user reaches the preset threshold 1, the current local authentication result is a successful authentication. For example, the preset threshold 1 is equal to 90%.

[0249] Please note that there are two cases of local authentication failure. In one case, feature collection is interrupted. Specifically, the continuous feature collection module does not collect biometric feature information. For example, if the authentication method for local continuous authentication is facial recognition, and there is no user within the detection range of the electronic device, the continuous feature collection module does not collect facial feature information. In the other case, feature collection is not interrupted, but the matching degree does not reach the preset threshold of 1. For example, if the authentication method for local continuous authentication is facial recognition, and the detection range of the electronic device includes an unauthorized user, the matching degree between the facial feature information collected by the continuous feature collection module and the facial feature information of the preset user does not reach the preset threshold of 1.

[0250] The local authentication result management module is configured to manage the local authentication results generated by the sequential feature authentication module. When the local authentication result changes from "authentication successful" to "authentication failed" (i.e., local sequential authentication is interrupted), the local authentication result management module may notify the authentication mode management module to switch the sequential authentication mode to cross-device sequential authentication mode. When the local authentication result changes from "authentication failed" to "authentication successful", the local authentication result management module may notify the authentication mode management module to switch the sequential authentication mode to local sequential authentication mode.

[0251] In some embodiments of this application, the local authentication result of the continuous feature authentication module may also be used to unlock the screen of an electronic device, unlock an application, and unlock an application function.

[0252] The cross-device authentication information acquisition module is configured to acquire identity authentication information for another connected electronic device when the continuous authentication mode switches to cross-device continuous authentication mode. In some embodiments, the module is configured to acquire local authentication results from a local authentication result management module of another connected electronic device. In some embodiments, the module is configured to acquire biometric feature information collected by a continuous feature acquisition module of another connected electronic device. The electronic device may implement voice control, cast control, or similar based on the identity authentication information of other electronic devices. When the electronic device is operating in cross-device continuous authentication mode, the continuous feature acquisition module, continuous feature authentication module, and local authentication result management module remain operational. In this way, when the local authentication result management module determines that the local authentication result of the electronic device is successful, the authentication mode management module may be notified to switch back to local continuous authentication mode.

[0253] For example, as shown in Figure 15A, User 1 is using electronic device 100, and User 1 is within the detection range of electronic device 100's local continuous authentication, but outside the detection range of electronic device 200's local continuous authentication. In this case, the local authentication result of electronic device 100 is authentication success, and the continuous authentication mode of electronic device 100 is local continuous authentication mode. As shown in Figure 15B, User 1 switches the device being used to electronic device 200, and User 1 is within the detection range of electronic device 200's local continuous authentication, but outside the detection range of electronic device 100's local continuous authentication. In this case, the local authentication result of electronic device 100 is authentication failure, and the local authentication result management module of electronic device 100 notifies the authentication mode management module to switch the continuous authentication mode to cross-device continuous authentication mode. Electronic device 100 may also use the cross-device authentication information management module to obtain the identity authentication information of electronic device 200.

[0254] In some embodiments of this application, as shown in Figure 15C, the electronic device 100 may alternatively not have local sequential authentication capabilities, and the electronic device 100 includes a feature collection module, a feature authentication module, and a cross-device authentication information acquisition module. The feature collection module and the feature authentication module may be configured to implement screen unlocking, application unlocking, and application function unlocking of the electronic device 100. The electronic device 100 may use the cross-device authentication information acquisition module to acquire the identity authentication information of the electronic device 200, and the electronic device 200 may not acquire the identity authentication information of the electronic device 100. The electronic device 100 may still implement voice control and cast control of the electronic device 100 based on the identity authentication information of the electronic device 200.

[0255] In some embodiments of this application, neither the electronic device 100 nor the electronic device 200 may have local sequential authentication capabilities. For example, when initiating cross-device authentication, the electronic device 100 sends a request to the electronic device 200 to obtain identity authentication information from the electronic device 200. After receiving the request, the electronic device 200 collects biometric feature information and sends it to the electronic device 100, or after receiving the request, the electronic device 200 collects biometric feature information, determines a local authentication result, and then sends the local authentication result to the electronic device 100.

[0256] In this embodiment of the application, at least one of the following implementations may be used for communication between different modules.

[0257] Implementation 1: Inter-system broadcast notification For example, the local authentication result management module sends a broadcast to another module of the electronic device to notify that local continuous authentication has been interrupted.

[0258] Implementation 2: Call an interface between modules for notification. For example, interface 1 exists between the local authentication result management module and the authentication mode management module, and the local authentication result management module may notify the authentication mode management module that local continuous authentication has been interrupted by calling interface 1.

[0259] Implementation 3: Information is written to a storage module (e.g., a configuration file or database), and a receiving module actively reads the information from the storage module. For example, the local authentication result management module writes the state in which local continuous authentication is interrupted to a preset configuration file, and by periodically reading the preset configuration file, the authentication mode management module determines that local continuous authentication of the electronic device is interrupted.

[0260] In this embodiment of the application, the identity authentication information of electronic device 100 and electronic device 200 may be obtained by at least one of the following implementations. The following explanation is provided using an example in which electronic device 100 obtains the local authentication result of electronic device 200.

[0261] Implementation 4: Electronic device 200 writes the local authentication result to the distributed database, and one or more electronic devices connected to electronic device 200 (e.g., electronic device 100) may read the local authentication result of electronic device 200 from the distributed database. Note that one or more electronic devices connected to electronic device 200 may perform write and read operations on the distributed database.

[0262] Implementation 5: Electronic device 200 continuously broadcasts its local authentication result to another device and continuously listens to the authentication result broadcast from the other device. Electronic device 100 may continuously listen to the authentication result broadcast by the other device and obtain the local authentication result of electronic device 200.

[0263] Implementation 6: The sequential authentication query interface of electronic device 200 is opened, and one or more electronic devices connected to electronic device 200 (e.g., electronic device 100) may query the local authentication results of electronic device 200 through the query interface.

[0264] Based on the cross-device systems shown in Figures 15A to 15C, the cross-device authentication method provided in the embodiments of this application will be described below.

[0265] For example, Figures 16A and 16B illustrate a cross-device authentication method in a voice control scenario according to one embodiment of this application. The cross-device authentication method includes, but is not limited to, steps S101 to S111.

[0266] S101: The electronic device 200 performs local continuous authentication to obtain identity authentication information.

[0267] In this embodiment of this application, the electronic device 200 may perform local continuous authentication by one or more authentication methods such as face recognition, iris recognition, and screen touch behavior recognition. For example, the authentication method of the local continuous authentication of the electronic device 200 is face recognition. The electronic device 200 may use a low-power camera to collect an image and perform face recognition on the image. When it is determined by face recognition that the image contains the face of the preset user, the local authentication is successful. The preset user may be the user 1 in the foregoing embodiment, or may be the authorized user 3 in the foregoing embodiment. In some embodiments, the electronic device 200 may periodically collect images in real time using a low-power camera. In some embodiments, when receiving a specific touch operation of the user (for example, a touch operation performed on the icon of the locked application), the electronic device 200 may alternatively use a low-power camera to collect an image. In some embodiments, when receiving a cross-device authentication request of the electronic device 100, the electronic device 200 may alternatively use a low-power camera to collect an image. This is not specifically limited in this specification.

[0268] In this embodiment of this application, the electronic device 100 may or may not have the local continuous authentication ability. This is not specifically limited in this specification.

[0269] S102: The electronic device 100 receives the user's voice command 1.

[0270] When a user attempts to control the electronic device 100 based on voice, the user may be understood to utter a voice command 1. See, for example, Figures 4A, 4C, and 6A. When a user attempts to control the electronic device 100 to play song 1, the user may specifically send the voice command 1 "Hey Celia, play song 1." See Figures 6C-6E. When a user attempts to control the electronic device 100 to send a message to Anna using application 1, the user may specifically send the voice command 1 "Hey Celia, use application 1 to send Anna 'Are you coming home?'" In some embodiments, the voice command 1 may, alternatively, not include a wake-up keyword. This is not specifically limited herein.

[0271] In this embodiment of the application, the electronic device 100 may receive and recognize a voice command 1. Note that the electronic device 100 may be an electronic device capable of voice interaction. The electronic device 100 has a microphone and a loudspeaker. Typically, the microphone remains powered on to receive user voice commands at any time. The electronic device 100 further has voice recognition capabilities to enable voice recognition of collected ambient sounds. In some embodiments, the application processor (AP) of the electronic device 100 remains powered on, and the microphone may transmit collected voice information (e.g., voice command 1) to the AP. The AP may recognize the voice information and initiate a function corresponding to the voice information. In some embodiments, the microphone of the electronic device is connected to a microprocessor, the microprocessor remains powered on, and the AP of the electronic device is not powered on. The microphone transmits collected voice information (e.g., voice command 1) to the microprocessor, the microprocessor recognizes the voice information and, based on the voice information, decides whether to wake up the AP, i.e., whether to power on the AP. For example, a microprocessor wakes up the AP when it recognizes that the voice information contains a preset wake-up keyword. In some embodiments, the AP performs a response action corresponding to the received voice information only after it has recognized the preset wake-up keyword in the voice information. The preset wake-up keyword may be set by default by the electronic device before delivery, or it may be preset by the user within the electronic device based on the user's request. This is not specifically limited herein.

[0272] S103: The electronic device 100 recognizes whether the voice command 1 matches the preset user's voiceprint characteristics. If the voice command 1 matches the preset user's voiceprint characteristics, S104 is performed.

[0273] In some embodiments of this application, a preset user includes user 1, and the electronic device 100 pre-stores voiceprint features input by user 1. The electronic device 100 may perform a matching between the voiceprint features of voice command 1 and user 1. When the degree of matching reaches a preset threshold 2, the electronic device 100 determines that voice command 1 is a match for user 1's voiceprint features. For example, the preset threshold 2 is equal to 95%.

[0274] In this embodiment, if the electronic device 100 recognizes that the voice command 1 does not match the voiceprint characteristics of a preset user, the electronic device 100 may discard the data associated with the voice command 1 and will not perform a response operation corresponding to the voice command 1.

[0275] In some embodiments, step S103 may be an optional step. Alternatively, after receiving a voice command, the user may decide whether voice command 1 triggers a locked low-risk application or a locked low-risk application function.

[0276] S104: The electronic device 100 determines whether the voice command 1 triggers a locked low-risk application (or a locked low-risk application function). If the voice command 1 triggers a locked low-risk application (or a locked low-risk application function), S105 is performed.

[0277] In this embodiment of the application, locked low-risk applications (or locked low-risk application functions) may be configured by the user or by default by the electronic device 100. For example, see the related descriptions in Figures 5A to 5G for an implementation of an interface in which applications are locked in this embodiment of the application. Details are not described again here. For an implementation of an interface in which application functions are locked in this embodiment of the application, see the related descriptions in Figures 5H to 5M. Details are not described again here. For an embodiment of an interface in which locked low-risk applications are configured, see the related descriptions in Figures 7A to 7C. Details are not described again here. As shown in Figure 7C, applications 1 and Gallery are locked low-risk applications. For example, by default, the electronic device 100 configures all application functions such as settlement, remittance, and red packets as high-risk application functions.

[0278] In some embodiments, step S104 may be an optional step. The user may perform step S105 after recognizing that voice command 1 matches the preset user voiceprint characteristics. Specifically, after determining local consecutive authentication failures of electronic device 100, cross-device authentication is initiated to obtain identity authentication information for electronic device 200. In some embodiments, steps S103 and S104 may be optional steps. After receiving voice command 1, the user may perform step S105 to initiate cross-device authentication.

[0279] In some embodiments, when the electronic device 100 determines that voice command 1 triggers a locked high-risk application (or a locked high-risk / low-risk application function), the electronic device 100 may discard the associated data of voice command 1 and not perform a response action corresponding to voice command 1. See, for example, Figures 8A and 8B. The user is attempting to open a payment application by controlling the electronic device 100 based on voice command 1. Since the payment application is a locked high-risk application, the electronic device 100 may not open the payment application and instead send the prompt information "Please unlock" as shown in Figure 8B. See Figures 8C and 8D. The user is attempting to make a money transfer by controlling the electronic device 100 based on voice command 1. Since the money transfer is a locked high-risk application function, the electronic device 100 may not make the transfer and instead send the prompt information "Please unlock" as shown in Figure 8D.

[0280] In some embodiments of this application, the electronic device 100 determines whether voice command 1 triggers a locked application (or locked application function). If it determines that voice command 1 triggers a locked application (or locked application function), the electronic device 100 performs step S105. See, for example, voice control scenario 2 shown in Figures 6A to 6J. When the electronic device 100 determines that voice command 1 triggers a locked application (or locked application function), the electronic device initiates cross-device authentication to obtain identity authentication information for the electronic device 200. As shown in Figure 5E, applications 1 and Gallery may be locked applications, and application 2 may be an unlocked application function. As shown in Figure 5E, Me and "Messages" in application 2 may be locked application functions.

[0281] S105: When determining that local serial authentication has failed for electronic device 100, electronic device 100 initiates cross-device authentication and sends acquisition request 1 to electronic device 200, which is used to obtain identity authentication information from electronic device 200.

[0282] In this embodiment of the application, when a preset user is not within the detection range of the electronic device 100's local continuous authentication, the electronic device 100 cannot collect the preset user's biometric feature information. In this case, the local authentication result of the electronic device 100 is authentication failure. For example, the authentication method for local continuous authentication is facial recognition, and the detection range of the electronic device 100's local continuous authentication is the shooting range of a low-power camera configured to collect facial images. See, for example, Figures 4A-4D and Figures 6A-6J. The preset user is User 1, and User 1 is not within the detection range of the electronic device 100, resulting in a local continuous authentication failure for the electronic device 100.

[0283] In some embodiments, if a preset user is within the detection range of the electronic device 100's local continuous authentication, the electronic device 100 may perform a response operation corresponding to the voice command 1 when it determines that the local authentication result of the electronic device 100 is successful.

[0284] S106: In response to acquisition request 1, electronic device 200 transmits its identity authentication information to electronic device 100, and electronic device 100 receives the identity authentication information of electronic device 200.

[0285] In this embodiment of the application, electronic device 100 may alternatively obtain the identity authentication information of electronic device 200 in a different manner. In some embodiments, when electronic device 200 performs local sequential authentication, electronic device 200 broadcasts its identity authentication information in real time. When electronic device 100 fails local sequential authentication, electronic device 100 may listen for the identity authentication information of another device (e.g., electronic device 200) to obtain the identity authentication information of electronic device 200. In some embodiments, when electronic device 200 performs local sequential authentication, electronic device 200 may write its identity authentication information to a distributed database in real time, and electronic device 100 may read the identity authentication information of electronic device 200 from the distributed database when electronic device 100 fails local sequential authentication.

[0286] S107: Electronic device 100 determines whether the identity authentication information of electronic device 200 matches the preset information. If the identity authentication information of electronic device 200 matches the preset information, S108 is performed.

[0287] In this embodiment of the application, when electronic device 100 determines that the identity authentication information of electronic device 200 does not match the preset information, electronic device 100 may discard the associated data of voice command 1 and not perform a response operation corresponding to voice command 1. See, for example, Figures 4C, 4D, 6C, 6D, 6G, and 6H. A local continuous authentication failure occurs for electronic device 200 when user 1 is outside the detection range of electronic device 200. When electronic device 100 determines that a local continuous authentication failure has occurred for electronic device 200, it may send the voice response "Please unlock."

[0288] S108: When the identity authentication information of electronic device 200 is the local authentication result of electronic device 200, electronic device 100 determines whether the priority of the authentication method of electronic device 200 is lower than the priority of the authentication method of electronic device 100's local sequential authentication. If the priority of the authentication method of electronic device 200 is not lower, S109 is performed.

[0289] In one implementation, electronic device 100 pre-stores the authentication methods of multiple devices connected to electronic device 100. In another implementation, electronic device 100 may send an authentication method query request to electronic device 200 and receive an authentication method identifier sent by electronic device 200. In yet another implementation, the local authentication result sent by electronic device 200 may further carry the authentication method identifier of electronic device 200, and electronic device 100 may directly learn the authentication method of electronic device 200 based on the local authentication result of electronic device 200.

[0290] In this embodiment of the application, the priority of the authentication methods for local sequential authentication may be set by the electronic device 100 or by the user. For example, the priority of the authentication methods for local sequential authentication may be sorted in descending order, such as face recognition (iris recognition), heart rate detection, gait recognition, and screen touch behavior recognition. Optionally, in some embodiments of the application, the priorities of some combinations of authentication methods may differ. For example, the priority of face recognition + fingerprint recognition may be higher than the priority of gait recognition + screen touch behavior. For example, the authentication method of electronic device 100 may be face recognition, and the authentication method of electronic device 200 may be screen touch behavior recognition. If, after electronic device 100 has initiated cross-device authentication, it determines that the priority of the authentication method of electronic device 200 is lower than the priority of the authentication method of electronic device 100, electronic device 100 may directly determine that cross-device authentication of electronic device 200 has failed.

[0291] When the authentication method of electronic device 200 has a low priority, electronic device 100 may determine that the identity authentication information of electronic device 200 is not secure, and it can be understood that electronic device 100 will discard the associated data of voice command 1 and will not perform a response action corresponding to voice command 1.

[0292] S109: Electronic device 100 determines whether the distance between electronic device 100 and electronic device 200 is less than the preset distance 1. If the distance between electronic device 100 and electronic device 200 is less than the preset distance 1, S110 is performed.

[0293] In this embodiment of the application, the electronic device 100 may measure the distance between the electronic device 100 and the electronic device 200 using positioning technology such as Bluetooth positioning technology, UWB positioning technology, or Wi-Fi positioning technology.

[0294] For example, electronic device 100 measures the distance between electronic device 100 and electronic device 200 using Bluetooth positioning technology. Specifically, in one implementation, electronic device 100 sends a measurement request to electronic device 200. Based on the received measurement request, electronic device 200 sends a measurement response to electronic device 100 after a preset period has elapsed. Electronic device 100 may determine the one-way flight period of the signal based on the moment of transmission of the measurement request, the moment of reception of the measurement response, and the preset period, and may further determine the distance between electronic device 200 and electronic device 100 based on the one-way flight period and the propagation speed of the electromagnetic wave.

[0295] When electronic device 100 determines that the distance between electronic device 100 and electronic device 200 is greater than or equal to a preset distance of 1, electronic device 100 may determine that the identity authentication information of electronic device 200 is not secure, and it can be understood that electronic device 100 may discard the associated data of voice command 1 and not perform a response operation corresponding to voice command 1.

[0296] S110: Electronic device 100 determines whether electronic device 200 is in a secure state. If electronic device 200 is in a secure state, S111 is performed.

[0297] In one implementation, electronic device 100 may send a query request to electronic device 200. The query request is used to query whether electronic device 200 is in a secure state. For example, when it is determined that electronic device 200 is in a non-root state, electronic device 200 sends a query response to electronic device 100. The query response is used to indicate that electronic device 200 is in a secure state. In another implementation, the identity authentication information sent by electronic device 200 may also carry an identifier for the secure state of electronic device 200, and electronic device 100 may directly learn the secure state of electronic device 200 based on the identity authentication information of electronic device 200. For information on determining whether an electronic device is in a secure state, see the relevant definition of the secure state described above. Further details are not provided here.

[0298] When electronic device 100 determines that electronic device 200 is not in a secure state, it can be understood that electronic device 100 determines that the identity authentication information of electronic device 200 is not secure, and therefore electronic device 100 discards the associated data of voice command 1 and does not perform a response action corresponding to voice command 1.

[0299] In this embodiment of the application, the execution sequence of steps S108 to S110 is not specifically limited. For example, the electronic device 100 may alternatively perform steps S108 to S110 simultaneously. For example, the electronic device 100 may first determine the secure state of the electronic device 200, determine the priority of the authentication method of the electronic device 200 when it determines that the electronic device 200 is in a secure state, and determine the distance of the electronic device 200 when the priority of the authentication method of the electronic device 200 is not low. When the distance of the electronic device 200 is less than the preset distance 1, the electronic device 100 performs a response operation corresponding to the voice command 1.

[0300] In some embodiments, at least one of steps S108 to S110 is an optional step. For example, steps S107 to S109 are all optional steps. After receiving the identity authentication information of the electronic device 200, the electronic device 100 performs a response operation corresponding to voice command 1 when it determines that the identity authentication information of the electronic device 200 does not match the preset information. For example, step S107 is an optional step. After receiving the identity authentication information of the electronic device 200, the electronic device 100 determines that the identity authentication information of the electronic device 200 does not match the preset information, determines that the distance to the electronic device 200 is less than the preset distance 1, and determines that the electronic device 100 is in a secure state, and only when the electronic device 100 determines that the identity authentication information of the electronic device 200 is secure and reliable does the electronic device 100 perform a response operation corresponding to voice command 1.

[0301] S111: The electronic device 100 performs a response operation corresponding to the voice command 1.

[0302] For example, in voice control scenario 1, Music is an unlocked application. See Figures 4A and 4B. Voice command 1 is "Hey Celia, play song 1". When electronic device 100 determines that cross-device authentication is successful, it may play song 1 and send the voice response "Okay, playing song 1" as shown in Figure 4B. In voice control scenario 2, application 1 is a locked application. See Figures 6E and 6F. Voice command 1 is "Hey Celia, use application 1 to send Anna 'Are you going home?'". Electronic device 100 determines that application 1 is a locked application. When determining that cross-device authentication is successful, electronic device 100 may use application 1 to send the message "Are you going home?" to Anna and send the voice response "Are you going home? sent to Anna" as shown in Figure 6F. In voice control scenario 3, application 1 is a locked low-risk application. See Figures 6E and 6F. Voice command 1 is, "Hey Celia, use application 1 to send Anna 'Are you going home?'" Electronic device 100 determines that application 1 is a locked, low-risk application. Upon determining that cross-device authentication is successful, electronic device 100 may use application 1 to send the message "Are you going home?" to Anna and send the voice response "Are you going home? has been sent to Anna" as shown in Figure 6F.

[0303] For example, Figures 17A and 17B illustrate a cross-device authentication method in a cast control scenario according to one embodiment of this application. The cross-device authentication method includes, but is not limited to, steps S201 to S208.

[0304] S201: Electronic device 200 performs local sequential authentication to obtain identity authentication information.

[0305] In this embodiment of the application, for a specific implementation of how the electronic device 200 performs local serial authentication and obtains identity authentication information, please refer to the relevant description of S101 in the embodiment of the method shown in Figures 16A and 16B. Further details are not described again here.

[0306] S202: Electronic device 100 receives a cast operation from the user.

[0307] For related content regarding cast settings, please refer to the related explanations in Figures 9A to 9H. Further details will not be explained again here. For example, Figures 9A to 9D illustrate a casting method in which electronic device 100 actively casts to electronic device 200 according to one embodiment of this application. The casting operation may also be performed by the user tapping option 401A of electronic device 200 shown in Figure 9B. Figures 9E to 9H illustrate a casting method in which electronic device 200 actively acquires cast content from electronic device 100 according to one embodiment of this application. The casting operation may also be performed by the user tapping option 410A of electronic device 100 shown in Figure 9G.

[0308] S203: In response to the cast operation, electronic device 100 transmits cast content 1 to electronic device 200.

[0309] S204: After receiving cast content 1, the electronic device displays cast window 1, and the content displayed in cast window 1 is cast content 1.

[0310] For example, Cast Window 1 may be Cast Window 403 shown in Figure 9D, and Cast Content 1 may be User Interface 32 shown in Figure 9D. Alternatively, Cast Window 1 may be Cast Window 411 shown in Figure 9G, and Cast Content 1 may be User Interface 32 shown in Figure 9G.

[0311] S205: Electronic device 100 sends acquisition request 2 to electronic device 200, and acquisition request 2 is used to acquire identity authentication information from electronic device 200.

[0312] S206: In response to the received acquisition request 2, electronic device 200 transmits its identity authentication information to electronic device 100.

[0313] In this embodiment of the application, for a specific embodiment in which the electronic device 200 transmits identity authentication information of the electronic device 200 to the electronic device 100, see the relevant description of S106 in the embodiment of the method shown in Figures 16A and 16B. Further details are not described again here.

[0314] S207: When electronic device 100 determines that the identity authentication information of electronic device 200 does not match the preset information, electronic device 100 stops sending the cast content to electronic device 200.

[0315] S208: Electronic device 200 stops displaying cast content 1.

[0316] For example, see Figures 9I and 9J. After the user of electronic device 200 switches from user 1 to user 2, cross-device authentication fails, and electronic device 200 stops displaying the cast content of electronic device 100, and the prompt information "Cast interrupted" shown in Figure 9J is displayed in the cast window 403.

[0317] In some embodiments of this application, after step S203, the cross-device authentication method may further include, but is not limited to, at least one of steps S209 to S221.

[0318] S209: The electronic device 200 receives a touch action 1 performed by the user on the cast content 1.

[0319] See, for example, Figures 10A and 10C. Touch action 1 may be the user tapping the music icon 404C. See, Figures 10E and 10G. Touch action 1 may be the user tapping the gallery icon 404B. See, Figure 11A. Touch action 1 may be the user tapping the application 2 icon 404D. See, Figure 12A. Touch action 1 may be the user tapping the email icon 404E.

[0320] S210: Electronic device 200 transmits the touch parameters of touch operation 1 to electronic device 100, and electronic device 100 receives the touch parameters of touch operation 1.

[0321] S211: The electronic device 100 determines, based on the touch parameters of touch action 1, whether touch action 1 triggers a locked low-risk application or application function. If touch action 1 does not trigger a locked low-risk application or application function, S212 is performed; if touch action 1 triggers a locked low-risk application or application function, S213 is performed.

[0322] In some embodiments, electronic device 200 determines the touch parameters of touch action 1 on cast content 1 and transmits the touch parameters to electronic device 100. Based on the touch parameters of touch action 1, electronic device 100 determines the trigger event corresponding to touch action 1. The touch parameters may include touch coordinates, touch duration, etc. See, for example, Figure 10E. Electronic device 200 obtains the user's touch coordinates and touch duration within the user interface 32 and transmits the touch coordinates and touch duration to electronic device 100. Based on the touch coordinates and touch duration of touch action 1, electronic device 100 determines that the trigger event corresponding to touch action 1 is a tap action performed on gallery icon 404B. See Figure 7C. The gallery is a locked low-risk application, and electronic device 100 determines that touch action 1 triggers the locked low-risk application. In addition to touch coordinates and touch duration, the touch parameters may further include other parameters, which are not specifically limited herein.

[0323] In some embodiments, step S211 may be an optional step. After receiving the touch parameters of touch operation 1, the electronic device 100 performs a specific step S213, specifically, initiating cross-device authentication to obtain the identity authentication information of the electronic device 200.

[0324] S212: Electronic device 100 stops transmitting cast content to electronic device 200.

[0325] When electronic device 100 determines, based on the touch parameters of touch action 1, that touch action 1 triggers a locked high-risk application or application function, electronic device 100 stops sending cast content to electronic device 200, and electronic device 200 stops displaying the cast content of electronic device 100. See, for example, Figure 12A. Electronic device 100 may also determine, based on the touch parameters of touch action 1, that the trigger event corresponding to touch action 1 is a tap action performed on the email icon 404E. Email is a locked high-risk application, and electronic device 100 determines that touch action 1 triggers a locked high-risk application.

[0326] S213: Electronic device 100 sends acquisition request 3 to electronic device 200, and acquisition request 3 is used to acquire identity authentication information from electronic device 200.

[0327] S214: In response to the received acquisition request 3, electronic device 200 transmits its identity authentication information to electronic device 100, and electronic device 100 receives the identity authentication information of electronic device 200.

[0328] In this embodiment of the application, for a specific implementation of how electronic device 200 transmits identity authentication information of electronic device 200 to electronic device 100, see the relevant description of S106 in the embodiment of the method shown in Figures 16A and 16B. Further details are not described again here.

[0329] S215: Electronic device 100 determines whether the identity authentication information of electronic device 200 matches the preset information. If the identity authentication information of electronic device 200 matches the preset information, S216 is performed; otherwise, if the identity authentication information of electronic device 200 does not match the preset information, S212 is performed.

[0330] In this embodiment of the application, when electronic device 100 determines that the identity authentication information of electronic device 200 does not match the preset information, electronic device 100 stops transmitting cast content to electronic device 200, and electronic device 200 stops displaying the cast content of electronic device 100. For example, see Figures 10C, 10D, 10H, and 10I for cast control scenario 2. An unauthorized user 2 is using electronic device 200, and the identity authentication information of electronic device 200 does not match the preset information, so electronic device 100 stops transmitting cast content to electronic device 200, and electronic device 200 stops displaying the cast content of electronic device 100 in the cast window 403, or electronic device 200 closes the cast window 403.

[0331] S216: Electronic device 100 determines whether the authentication method priority of electronic device 200 is lower than that of electronic device 100's local sequential authentication. If the authentication method priority of electronic device 200 is not lower, S217 is performed; otherwise, S212 is performed.

[0332] In this embodiment of the application, for a specific implementation of how electronic device 100 determines whether the authentication method of electronic device 200 has a lower priority, see the relevant description of S108 in the embodiment of the method in Figures 16A and 16B. Further details are not described again here.

[0333] S217: Electronic device 100 determines whether the distance between electronic device 100 and electronic device 200 is less than the preset distance 1. If the distance between electronic device 100 and electronic device 200 is less than the preset distance 1, S218 is performed; otherwise, if the distance between electronic device 100 and electronic device 200 is greater than or equal to the preset distance 1, S212 is performed.

[0334] For a specific embodiment of how electronic device 100 determines whether the distance between electronic device 100 and electronic device 200 is less than a preset distance of 1, see the relevant description of S109 in the embodiment of the method shown in Figures 16A and 16B. Further details are not described again here.

[0335] S218: Electronic device 100 determines whether electronic device 200 is in a secure state. If electronic device 200 is in a secure state, S219 is performed; otherwise, S212 is performed.

[0336] In this embodiment of the application, for a specific embodiment of how electronic device 100 determines whether electronic device 200 is in a secure state, see the relevant description of S110 in the embodiment of the method in Figures 16A and 16B. Further details are not described again here.

[0337] In this embodiment of the application, the execution sequence of steps S216, S217, and S218 is not specifically limited. The electronic device 100 may alternatively perform steps S216 to S218 simultaneously. In some embodiments, at least one of steps S216 to S218 is an optional step. For example, steps S216 to S218 are all optional steps. After receiving the identity authentication information of the electronic device 200, when it determines that the identity authentication information of the electronic device 200 matches the preset information, the electronic device 100 performs a function triggered by the touch action 1 and draws the cast content 2 corresponding to that function. For example, step S216 is an optional step. After receiving the identity authentication information of electronic device 200, if electronic device 100 determines that the identity authentication information of electronic device 200 matches the preset information, determines that the distance to electronic device 200 is less than the preset distance 1, and determines that electronic device 100 is in a secure state, then electronic device 100 determines that the identity authentication information of electronic device 200 is secure and trustworthy, and electronic device 100 starts the function triggered by touch action 1 and draws the cast content 2 corresponding to that function.

[0338] S219: The electronic device 100 performs a response operation corresponding to the touch operation 1 and draws the corresponding cast content 2.

[0339] S220: Electronic device 100 transmits cast content 2 to electronic device 200, and electronic device 200 receives cast content 2 transmitted by electronic device 100.

[0340] S221: Electronic device 200 displays cast content 2 in cast window 1.

[0341] In voice control scenario 3, the gallery is a locked application. In cast control scenario 4, the gallery is a locked low-risk application. See, for example, Figures 10E and 10F. Electronic device 100 determines that touch action 1 is a tap action performed on the gallery icon 404B, and electronic device 100 determines that the gallery triggered by touch action 1 is a locked application (or a locked low-risk application). When electronic device 100 obtains its identity authentication information and determines that cross-device authentication is successful, electronic device 100 draws the gallery's user interface 36 and sends the user interface 36 to electronic device 200. As shown in Figure 10F, the electronic device displays the user interface 36 in the cast window 403. For cast window 1, see cast window 403 shown in Figure 10F. For cast window 2, see user interface 36 shown in Figure 10F.

[0342] For example, Figure 18 shows a cross-device authentication method according to one embodiment of this application. The cross-device authentication method includes, but is not limited to, steps S301 to S306.

[0343] S301: The first electronic device receives the first operation.

[0344] In this embodiment of the application, the first electronic device may be the electronic device 100 in the embodiments described above. In some embodiments, the first action may be a voice command received by the electronic device 100 in the voice control scenario described above. For example, as shown in Figure 6E, the electronic device 100 receives the voice command "Hey Celia, use application 1 to send 'Are you going home?' to Anna." In some embodiments, the first action may be a cast action received by the electronic device 100 in the cast control scenario described above. For example, the first action may be the user tapping option 401A of the electronic device 200 shown in Figure 9B. In some embodiments, the first action may be a touch action indirectly received by the electronic device 100 using the electronic device 200 in cast control scenarios 2-4. Note that after receiving the user's touch action, the electronic device 200 may send the touch parameters of the touch action to the electronic device 100, which then determines the trigger event corresponding to the touch action and further performs the corresponding response action. For example, the first action may be the user tapping the music icon 404C in the cast window 403 shown in Figure 10A.

[0345] S302: In response to receiving the first operation, the first electronic device detects whether the local authentication result of the first electronic device is successful.

[0346] Specifically, the first electronic device collects biometric feature information of users within detection range and determines whether the collected biometric feature information matches the biometric feature information of a preset user. If the collected biometric feature information matches the biometric feature information of a preset user, the local authentication result of the first electronic device is local authentication success. For the implementation of determining whether the collected biometric feature information matches the biometric feature information of a preset user, refer to the relevant description in the embodiments described above, and for preset users, refer to the relevant descriptions of User 1 and Authorized User 3 in the embodiments described above. Further details are not described again here.

[0347] In some embodiments, after the first electronic device receives a first action, the method further includes the first electronic device detecting whether the first action triggers a locked low-risk application, and in response to detecting that the first action triggers a locked low-risk application, the first electronic device detecting whether the local authentication result of the first electronic device is successful. See the relevant descriptions for voice control scenario 3 and cast control scenario 4. In some embodiments of this application, the locked application may include a locked low-risk application. See the relevant descriptions for setting up a locked application in Figures 5A to 5G. See the relevant descriptions for setting up a locked low-risk application in Figures 7 to 7C.

[0348] In some embodiments, when the first operation is a first voice command, the method further includes the first electronic device detecting whether the voiceprint features of the first voice command match the voiceprint features of a preset user, and in response to detecting that the voiceprint features of the first voice command match the voiceprint features of a preset user, the first electronic device detecting whether the local authentication result of the first electronic device is successful. The first voice command refers to a voice command received by the electronic device 100 in a voice control scenario, for example, voice command 1.

[0349] In some embodiments, the voiceprint features in the first voice command are considered to fit the preset user's voiceprint when the degree of matching between the voiceprint features in the first voice command and the voiceprint features of the preset user reaches a preset threshold 2. For example, the preset threshold 2 is equal to 95%.

[0350] In some embodiments, the first electronic device performs local sequential authentication and generates a local authentication result for the first electronic device when it receives a first action or after it has received a first action. The method by which the first electronic device performs local sequential authentication includes at least one of facial recognition authentication, iris recognition authentication, and screen touch behavior recognition authentication. The local authentication result for the first electronic device may indicate whether the identity authentication performed by the first electronic device on the user was successful.

[0351] S303: In response to detecting that the local authentication result of the first electronic device is an authentication failure, the first electronic device sends a request to the second electronic device to obtain the local authentication result of the second electronic device.

[0352] In some embodiments, the second electronic device performs local sequential authentication and generates a local authentication result for the second electronic device when the first electronic device receives a first action, or before the first electronic device receives a first action. The method by which the second electronic device performs local sequential authentication includes at least one of facial recognition authentication, iris recognition authentication, and screen touch behavior recognition authentication. The local authentication result for the second electronic device may indicate whether the identity authentication performed by the second electronic device on the user was successful.

[0353] In this embodiment of the application, the second electronic device may be electronic device 200.

[0354] S304: The first electronic device is of the second electronic device and receives the local authentication result transmitted by the second electronic device.

[0355] S305: In response to receiving the local authentication result of the second electronic device, the first electronic device detects whether the local authentication result of the second electronic device is successful.

[0356] S306: In response to the detection of a successful local authentication result by the second electronic device, the first electronic device executes an instruction corresponding to the first operation.

[0357] In this embodiment of the application, the first action may be voice command 1 in the relevant embodiment of Figures 16A and 16B, and the command corresponding to the first action may be a response action corresponding to voice command 1 in the relevant embodiment of Figures 16A and 16B. The first action may alternatively be touch action 1 in the relevant embodiment of Figures 17A and 17B. The command corresponding to the first action may be a response action corresponding to touch action 1 in the relevant embodiment of Figures 17A and 17B. For example, voice command 1 is "Hey Celia, use application 1 to send 'Are you going home?' to Anna" as shown in Figure 6E, and the response action corresponding to voice command 1 is that the first electronic device (i.e., electronic device 100) uses application 1 to send "Are you going home?" to the contact "Anna". For example, touch action 1 is when the user taps the music icon 404C in the cast window 403 shown in Figure 10A, and the response action corresponding to touch action 1 is when the first electronic device (i.e., electronic device 100) starts the music application and casts the music interface content onto the second electronic device (i.e., electronic device 200).

[0358] In some embodiments, the method further includes the first electronic device detecting the distance between the first electronic device and the second electronic device before the first electronic device executes a command corresponding to the first operation, and the first electronic device executing a command corresponding to the first operation in response to detecting that the distance between the first electronic device and the second electronic device is less than a first preset distance. The first preset distance may also be called preset distance 1. For a method of measuring the distance between the first electronic device and the second electronic device, see the relevant description of measuring the distance between electronic device 100 and electronic device 200 in embodiments of Figures 16A and 16B. Further details are not described again here.

[0359] In some embodiments, the method further includes, before the first electronic device executes an instruction corresponding to a first operation, the first electronic device detecting whether the first electronic device is in a secure state, and, in response to detecting that the first electronic device is in a secure state, the first electronic device executing an instruction corresponding to a first operation. For the determination of whether an electronic device is in a secure state, see the relevant description of the secure state above. Details are not described again here.

[0360] In some embodiments, before the first electronic device executes a command corresponding to a first operation, the method further includes the first electronic device detecting whether the local continuity authentication priority of the second electronic device is lower than the local continuity authentication priority of the first electronic device, and in response to detecting that the local continuity authentication priority of the second electronic device is not lower than the local continuity authentication priority of the first electronic device, the first electronic device executes a command corresponding to a first operation. The local continuity authentication priority is the priority of the local continuity authentication method. For details on the local continuity authentication method priority, see the relevant descriptions in the embodiments described above. Details are not described again here. For example, the local continuity authentication methods include facial recognition, iris recognition, heart rate detection, gait recognition, and screen touch behavior recognition. The local continuity authentication method priorities are sorted in descending order, such as facial recognition (iris recognition), heart rate detection, gait recognition, and screen touch behavior recognition. Facial recognition and iris recognition have the same priority.

[0361] To further understand the cross-device authentication method provided in the embodiments of this application, the software system of the electronic device provided in the embodiments of this application will be described below.

[0362] Figure 19 is a block diagram of the software structure of a software system for an electronic device according to an example embodiment of this application. The electronic device may be electronic device 100 or electronic device 200. Hereinafter, electronic device 100 will be used as an example. Electronic device 100 can implement voice control and cast control of electronic device 100 based on identity authentication information of an electronic device connected to electronic device 100 (e.g., electronic device 200), thereby effectively improving the convenience and security of cross-device authentication and improving the user experience.

[0363] As shown in Figure 10A, in a layered architecture, the software is divided into several layers, each with a distinct role and task. These layers communicate with each other through software interfaces. In some embodiments, the Android system may be divided from top to bottom into an application layer, an application framework layer, a protocol stack, a hardware abstraction layer (abnormality management, HAL) layer, and a kernel layer.

[0364] The application layer includes a series of application packages, such as Application 1, Application 2, Music, Gallery, and Email, and may further include applications such as Bluetooth, Phone, or Video.

[0365] The application framework layer provides an application programming interface (API) and a programming framework for applications within the application layer. The application framework layer includes several predefined functions.

[0366] The application framework layer includes a continuous feature acquisition module, a continuous feature authentication module, a local authentication result management module, an authentication mode management module, and a cross-device authentication information acquisition module. The continuous feature acquisition module is configured to collect biometric feature information. The continuous feature authentication module is configured to obtain the current local authentication result by matching the biometric feature information collected by the continuous feature acquisition module with pre-stored biometric feature information. The local authentication result management module manages the local authentication result determined by the continuous feature authentication module and, when the local authentication result changes, notifies the authentication mode management module to switch the authentication mode. The cross-device authentication information acquisition module may be configured to acquire identity authentication information for another connected device (e.g., electronic device 200).

[0367] The application framework layer may further include Bluetooth services, UWB services, Wi-Fi services, etc. Electronic device 100 may detect the distance to another connected device by calling one or more short-range communication services in services such as Bluetooth services, UWB services, and Wi-Fi services. Alternatively, electronic device 100 may connect to a nearby device and transmit data by calling one or more short-range communication services in services such as Bluetooth services, UWB services, and Wi-Fi services. In some embodiments, when electronic device 100 determines that the distance between electronic device 100 and electronic device 200 is less than a preset distance 1, electronic device 100 determines that the identity authentication information of electronic device 200 is secure and trustworthy.

[0368] The Android Runtime includes the kernel libraries and the virtual machine. The Android Runtime is responsible for scheduling and managing the Android system.

[0369] The core library consists of two parts: functions that need to be called in the Java language, and the Android kernel library.

[0370] The application layer and application framework layer run on a virtual machine. The virtual machine converts Java files in the application layer and application framework layer into binary files for execution. The virtual machine is configured to perform functions such as object lifecycle management, stack management, thread management, security and anomaly management, and garbage collection.

[0371] The kernel layer is the layer between hardware and software. The kernel layer may include display drivers, camera drivers, and touch chip drivers, and may also include sensor drivers, audio drivers, and so on. The HAL layer and the kernel layer (kernel) may perform corresponding operations in response to functions called by the application framework layer.

[0372] In this embodiment of the application, the electronic device 100 may perform local sequential authentication using one or more authentication methods such as facial recognition, iris recognition, or screen touch behavior recognition.

[0373] In some embodiments, the electronic device 100 performs local sequential authentication by facial recognition. After the screen of the electronic device 100 is unlocked, the electronic device 100 collects an image using a camera (e.g., a low-power camera). The electronic device 100 uses a camera driver in the kernel layer to send the image to a sequential feature acquisition module in the application framework layer. The sequential feature acquisition module acquires facial feature information from the image and sends the facial feature information to the sequential feature authentication module. The sequential feature authentication module matches the facial feature information with the biometric feature information of a preset user of the electronic device 100. When the matching degree reaches a preset threshold of 1, it is determined that identity authentication is successful, or when the matching degree does not reach a preset threshold of 1, it is determined that identity authentication is failed. In some embodiments, the electronic device 100 performs local sequential authentication by screen touch behavior recognition. The electronic device 100 may use a touch sensor on the touch screen to collect N touch inputs from the user. The touch chip acquires touch parameters for N touch inputs (the touch parameters may include the coordinates of the contact area of ​​the touch input and capacitance information for each coordinate point). The touch chip uses a touch chip driver to send the touch parameters for the N touch inputs to a continuous feature acquisition module in the application framework layer. The continuous feature acquisition module is configured to acquire touch feature information for the N touch inputs based on the touch parameters of the N touch inputs and to send the touch feature information to a continuous feature authentication module. The continuous feature authentication module matches the screen touch feature information with the screen touch feature information of a preset user of the electronic device 100. Identity authentication is determined to be successful when the matching degree reaches a preset threshold of 1, or to be considered a failure when the matching degree does not reach a preset threshold of 1. The touch feature information for a touch input includes information on at least one item, such as the touch position, touch area, touch force, touch direction, and touch time of the touch input. N is a positive integer greater than 0.The preset user may be user 1 in the aforementioned embodiment, or an additional authorized user 3 in the aforementioned embodiment.

[0374] In some embodiments, the continuous feature authentication module transmits the acquired local authentication result to the local authentication result management module. When the local authentication result changes from "authentication successful" to "authentication failed," the local authentication result management module may notify the authentication mode management module to switch the continuous authentication mode to cross-device continuous authentication. When the local authentication result changes from "authentication failed" to "authentication successful," the local authentication result management module may notify the authentication mode management module to switch the continuous authentication mode to local continuous authentication mode. When the continuous authentication mode is cross-device continuous authentication mode, the cross-device authentication information acquisition module may call a communication service to acquire identity authentication information of another connected device (e.g., electronic device 200). For example, the cross-device authentication information acquisition module may acquire identity authentication information of electronic device 200 by calling a Bluetooth service, the Bluetooth service may call a Bluetooth chip driver at the kernel layer, and the Bluetooth chip driver may drive a Bluetooth antenna to send an acquisition request to electronic device 200. The acquisition request is used to acquire the local authentication result of the electronic device 200. For example, the acquisition request may be acquisition request 1 in the embodiments of Figures 16A and 16B, or acquisition requests 2 and 3 in the embodiments of Figures 17A and 17B. The electronic device 100 may use a Bluetooth chip driver to acquire identity authentication information of the electronic device 200 and received by the Bluetooth antenna. The Bluetooth chip driver may transmit the identity authentication information of the electronic device 200 to a cross-device authentication information acquisition module in the application framework layer. In this embodiment of the application, the electronic device may implement voice control and cast control of the electronic device 100 based on the identity authentication information of the electronic device 200 and acquired by the cross-device authentication information acquisition module.

[0375] In some embodiments, the electronic device 100 also has local sequential authentication capability. The electronic device 100 may also use a Bluetooth chip driver to acquire acquisition requests of the electronic device 200 and received by a Bluetooth antenna. The acquisition requests are used to acquire the local authentication results of the electronic device 100. The Bluetooth chip driver may transmit the acquisition requests to a local authentication result management module or a sequential feature acquisition module in the application framework layer. The local authentication result management module may transmit the local authentication results to the Bluetooth chip driver, and the sequential feature acquisition module may transmit the collected biometric feature information to the Bluetooth chip driver, and the Bluetooth chip driver may use a Bluetooth antenna to transmit the local authentication results or biometric feature information of the electronic device 100 to the electronic device 200.

[0376] In this embodiment of the application, the electronic device 100 is of the electronic device 200, and voice control and cast control of the electronic device 100 may be implemented based on local authentication results obtained by a cross-device authentication information acquisition module.

[0377] Refer to Voice Control Scenario 2 and Cast Control Scenario 3. The electronic device 100 may initiate cross-device authentication for a locked application, but may not initiate cross-device authentication for an unlocked application (or application function). Refer to Voice Control Scenario 3 and Cast Control Scenario 4. The electronic device 100 may initiate cross-device authentication for a locked low-risk application (or application function), but may not initiate cross-device authentication for a locked high-risk application (or application function). In some embodiments of this application, the application framework may include an application security management module. The application security management module stores identifiers for locked applications (or application functions) and / or locked low-risk applications (or application functions). When receiving a user input action, the electronic device 100 may call the application security management module to determine whether the application (or application function) triggered by the input action is a locked application (or application function), or whether the application (or application function) triggered by the input action is a locked low-risk application (or application function).

[0378] In some embodiments, the microphone of electronic device 100 receives a voice command 1, electronic device 100 uses the kernel layer to send the voice command 1 to the application framework layer, the application framework layer invokes the speech recognition algorithm of the HAL layer to recognize the voice command 1 and trigger application 1. The application framework layer may then invoke the application security management module to determine that application 1 is a locked application. Since application 1 is a locked application, when the local authentication result management module determines a local authentication failure, the local authentication result management module invokes the cross-device authentication information acquisition module to obtain the identity authentication information of electronic device 200.

[0379] Refer to Cast Control Scenario 2 and Cast Control Scenario 4. Electronic device 100 may receive touch parameters of touch operations performed on cast content on electronic device 200.

[0380] In some embodiments of this application, the application framework layer further includes a cast service, the cast service including a coordinate transformation module. After receiving touch parameters (including touch coordinates, touch duration, etc.) transmitted by electronic device 200 using the communication service, electronic device 100 may call the coordinate transformation module to convert the touch coordinates of electronic device 200 in the touch parameters to the touch coordinates of electronic device 100, and further determine the event triggered by the touch action. For example, after the touch coordinates are converted to the touch coordinates of electronic device 100, it is determined that the touch coordinates of electronic device 100 correspond to the area where the gallery icon is located. Furthermore, electronic device 100 may determine that the touch action is a tap action performed on the gallery icon based on parameters such as the touch duration of the touch parameters.

[0381] All or part of the embodiments described above may be implemented using software, hardware, firmware, or any combination thereof. When software is used to implement the embodiments described above, all or some of the embodiments may be implemented in the form of a computer program product. A computer program product includes at least one computer instruction. When the computer program instruction is loaded and executed on a computer, all or part of the procedures or functions in the embodiments of this application are produced. The computer may be a general-purpose computer, a dedicated computer, a computer network, or other programmable device. The computer instruction may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instruction may be transmitted from a website, computer, server, or data center to another website, computer, server, or data center by wire (e.g., coaxial cable, optical fiber, or digital subscriber line) or wirelessly (e.g., infrared, radio, or microwave). The computer-readable storage medium may be any available medium that can be accessed by a computer, or a data storage device such as a server or data center that integrates one or more available media. Usable media include magnetic media (e.g., floppy disks, hard disks, or magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state drives).

[0382] Those skilled in the art will understand that all or part of the steps of the method in the embodiments may be implemented by a computer program that instructs the relevant hardware. The program may be stored on a computer-readable storage medium. When the program is run, the process in the embodiments of the method is executed. The storage medium includes any medium capable of storing program code, such as ROM, random memory (RAM), magnetic disk, or compact disk.

Claims

1. A cross-device authentication method applied to a first electronic device, wherein the first electronic device is connected to a second electronic device. The first electronic device receives a first operation input by a user to the first electronic device, wherein the first electronic device stores preset information. The first electronic device performs local authentication in response to the first operation, The first electronic device performs local authentication for the first operation in response to the first operation, In response to the first operation, the first electronic device obtains the identity authentication information of the user who inputs the first operation, The first electronic device matches the user's identity authentication information with the preset information, The first electronic device determines, based on the matching result, whether the local authentication result of the first electronic device is successful. In response to the first electronic device detecting that the local authentication result of the first electronic device is an authentication failure, cross-device authentication is initiated, wherein the cross-device authentication is used by the first electronic device to perform authentication using the second electronic device. The first electronic device obtains the cross-device authentication result, The first electronic device determines that the cross-device authentication result is successful, and the first electronic device executes an instruction corresponding to the first operation, A method wherein the first electronic device and the second electronic device log in to the same user account, the user account being one of an instant messaging account, an email account, and a mobile phone number.

2. Initiating cross-device authentication using the first electronic device means that The first electronic device transmits a first request message to the second electronic device, the first request message being used to request the acquisition of a local authentication result from the second electronic device, Obtaining cross-device authentication results using the first electronic device is: The method according to claim 1, comprising: receiving a first response message from the second electronic device by the first electronic device, wherein the first response message includes the cross-device authentication result, and the cross-device authentication result is the local authentication result of the second electronic device.

3. Initiating cross-device authentication using the first electronic device means that The first electronic device transmits a second request message to the second electronic device, the second request message being used to request the acquisition of identity authentication information from the second electronic device. The first electronic device receives a second response message from the second electronic device, the second response message includes the identity authentication information of the second electronic device, and the first electronic device receives a second response message from the second electronic device, Obtaining cross-device authentication results using the first electronic device is: The method according to claim 1, comprising using the first electronic device to authenticate the first operation based on the identity authentication information of the second electronic device and generating the cross-device authentication result.

4. The first electronic device stores other preset information, The first electronic device authenticates the first operation based on the identity authentication information of the second electronic device and generates the cross-device authentication result, The first electronic device matches the identity authentication information transmitted by the second electronic device with the other preset information to generate a matching result. The method according to claim 3, comprising: when the matching result is greater than a first preset threshold, the first electronic device determines that the local authentication result of the second electronic device is successful; or when the matching result is not greater than a first preset threshold, the first electronic device determines that the local authentication result of the second electronic device is unsuccessful.

5. The first electronic device determines, based on the matching result, whether the local authentication result of the first electronic device is successful. The first electronic device compares the degree of matching of the matching result with a preset threshold, The method according to claim 1, comprising: determining that the local authentication result of the first electronic device is successful when the matching degree is greater than a second preset threshold; or determining that the local authentication result of the first electronic device is unsuccessful when the matching degree is not greater than a second preset threshold.

6. The method according to any one of claims 3 to 5, wherein the identity authentication information includes one or more of facial information, fingerprint information, voiceprint information, iris information, and screen touch behavior information, and the preset information includes one or more of facial information, fingerprint information, voiceprint information, iris information, and screen touch behavior information.

7. The method according to any one of claims 1 to 6, wherein the first operation is one of the following: a screen unlock operation, an application unlock operation, or an operation performed on the functionality of an application.

8. The first electronic device further includes detecting the distance between the first electronic device and the second electronic device, If the first electronic device determines that the cross-device authentication result is successful, the command corresponding to the first operation is executed. The method according to any one of claims 1 to 7, wherein if the first electronic device determines that the cross-device authentication result is successful and the distance between the first electronic device and the second electronic device is less than a first preset distance, the first electronic device executes the command corresponding to the first operation.

9. The first electronic device detects the distance between the first electronic device and the second electronic device, The method according to claim 8, wherein the first electronic device detects the distance between the first electronic device and the second electronic device using Bluetooth positioning technology, ultra-wideband UWB positioning technology, or wireless fidelity Wi-Fi positioning technology.

10. The method according to any one of claims 1 to 9, wherein the connection of the first electronic device to the second electronic device includes the first electronic device establishing a connection to the second electronic device using a near-field communication protocol, the near-field communication protocol being connected to the second electronic device by using one or more of the following: Wireless Fidelity Wi-Fi communication protocol, UWB communication protocol, Bluetooth communication protocol, Zigbee communication protocol, or Near-Field Communication NFC protocol.

11. Before initiating cross-device authentication using the first electronic device, The first electronic device receives a second action input by a user to the first electronic device, the second action being used to trigger the initiation of a cross-device authentication function, further comprising: In response to the first electronic device detecting that the local authentication result of the first electronic device is an authentication failure, initiating cross-device authentication means that The method according to any one of claims 1 to 10, comprising initiating cross-device authentication by the first electronic device in response to the second operation and in response to the first electronic device detecting that the local authentication result is an authentication failure.

12. The first electronic device further includes obtaining security status information of the second electronic device, If the first electronic device determines that the cross-device authentication result is successful, the command corresponding to the first operation is executed. The method according to any one of claims 1 to 11, wherein the first electronic device determines that the cross-device authentication result is successful and that the security status information of the second electronic device indicates that the second electronic device is in a secure state, the first electronic device executes the command corresponding to the first operation.

13. An electronic device, wherein the electronic device is connected to a second electronic device, and the electronic device includes a memory and one or more processors, the memory is coupled to the one or more processors, the memory is configured to store computer program code, the computer program code includes computer instructions, and the one or more processors call the computer instructions so that the electronic device performs the method according to any one of claims 1 to 12.

Citation Information

Patent Citations

  • Entrance guard management method and corresponding entrance guard system thereof

    CN108550201A

  • Authentication apparatus, authentication system, authentication method, and method program

    JP2005284452A

  • Biometric authentication system, biometric authentication method and biometric authentication program

    JP2014119830A

  • Mobile terminal privacy protection method, protection device, and mobile terminal

    JP2018517960A