Method for associating identity credentials, and communication system and electronic device
By associating the identity credentials of different electronic devices under user authorization and using association keys and credential association proofs, the security risks of cross-device identity authentication are solved, and the security and reliability of identity authentication are improved.
Patent Information
- Application Number
- PCT/CN2024/115917
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-06
- Filing Date
- 2024-08-30
- Publication Date
- 2025-08-14
AI Technical Summary
In the prior art, cross-device identity authentication has security risks, and malicious applications may cause local devices to mistakenly trust the results of identity authentication, resulting in information stolen by illegal users.
By associating multiple identity credentials on different electronic devices under user authorization, different devices trust the identity authentication results of the associated identity credentials, use the association key and credential association to prove the validity, and improve authentication security.
Under user authorization, the security of cross-device identity authentication is improved, direct trust in other trusted devices is avoided, and the legality and reliability of identity authentication results are ensured.
Smart Images

Figure CN2024115917_14082025_PF_FP_ABST
Abstract
Description
Identity credential association method, communication system and electronic equipment
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on February 6, 2024, with application number 202410172355.2 and application name “A method for associating identity credentials, a communication system and an electronic device”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the technical field of electronic devices, and more particularly to an identity credential association method, a communication system, and an electronic device. Background Art
[0003] Currently, when users use some functions of electronic devices, such as account login, online transactions or resource transfer, the electronic devices need to pass the user's identity authentication before allowing the user to use these functions normally. Among them, there are various ways of identity authentication, and different identity authentication methods use different identity credentials. Identity credentials refer to private data or public data declared to prove the authenticity of the user's identity. For example, the identity credentials used when identity authentication is based on the user's biometrics can be the user's fingerprint, face, voiceprint, etc. The identity credentials used when identity authentication is based on content known by the user can be the password set by the user, password, etc. As users own more and more electronic devices, users will register identity credentials on each electronic device to ensure that each electronic device can use the identity credentials registered on the local device when performing user identity authentication, thereby realizing user identity authentication on the local device.
[0004] Currently, local devices can also establish trust relationships with other electronic devices, so that when the local device cannot realize user identity authentication, it can also use other trusted electronic devices to perform cross-device identity authentication. In other words, the local device can currently trust the identity authentication results of other electronic devices based on the trust relationship between devices, thereby realizing cross-device identity authentication. However, this cross-device identity authentication method has security risks. For example, once there is a malicious application on other trusted electronic devices, it is easy for other electronic devices to be manipulated by the malicious application to send the identity authentication result to the local device without identity authentication, thereby causing the local device to mistakenly trust the identity authentication result, resulting in the information being stolen by illegal users.
[0005] Summary of the Invention
[0006] This application provides an identity credential association method, a communication system, and an electronic device that can, with user authorization, associate multiple identity credentials on different electronic devices, so that the authentication results of the associated identity credentials can be trusted between different electronic devices, thereby improving the security of identity authentication.
[0007] To achieve the above objectives, the present invention adopts the following technical solutions:
[0008] In a first aspect, a method for associating identity credentials is provided, which is applied to a first device in a communication system, wherein the communication system also includes a second device, and the method includes: receiving a first request sent by the second device; in response to the first request, determining whether the user authorizes n identity credentials on the second device to be associated with m identity credentials on the first device, where n and m are positive integers; in response to the user's authorization, associating the n identity credentials with the m identity credentials, wherein the association is used to indicate that the first device and the second device trust an identity authentication result based on the associated identity credentials.
[0009] In the solution provided by the first aspect above, when the identity credentials on the second device need to be associated with the identity credentials on the first device, the first device needs to determine whether to obtain user authorization. And when it is determined that the user authorization is obtained, the first device can associate the identity credentials on the second device with the identity credentials on the first device. In this way, with the authorization of the user, multiple identity credentials on different electronic devices can be associated, so that the identity authentication results of the associated identity credentials can be trusted between different electronic devices. That is, among the associated identity credentials, the identity authentication result corresponding to any identity credential can be recognized by the electronic devices where the other associated identity credentials are located. In this way, by limiting the local device to trust the identity authentication results of the associated identity credentials, the local device can avoid direct trust in the identity authentication results of other trusted electronic devices, thereby improving the security of identity authentication.
[0010] In one possible implementation, the method for associating identity credentials may further include: obtaining a second request triggered on the first device; sending a first identity authentication request to the second device in response to the second request; receiving a first identity authentication result from the second device, the first identity authentication result being a successful authentication result when the second device performs local identity authentication; and performing an operation corresponding to the second request in response to the first identity authentication result. In this way, when the identity credentials on the second device are associated with the identity credentials on the first device, if the first device entrusts the second device to perform cross-device identity authentication, the first device can directly trust the successful authentication result of the second device and respond accordingly.
[0011] Optionally, the second request triggered on the first device may be an operation request that requires identity authentication on the first device, such as logging in to an account, making a transaction payment, unlocking the first device, etc. It is understood that when it is inconvenient for the user to perform identity authentication on the first device, the first device may entrust the second device to perform cross-device identity authentication.
[0012] In a possible embodiment, the method for associating the identity credentials may also include: receiving a first identity authentication result sent by the second device, the first identity authentication result being the result of the identity authentication passing when the second device performs local identity authentication for a second request triggered on the second device; and executing an operation corresponding to the second request in response to the first identity authentication result.
[0013] Optionally, the second request triggered on the second device may be an operation request that requires identity authentication on the first device, such as controlling the first device to perform related operations (such as unlocking) or accessing resources of the first device (such as pictures).
[0014] In this way, when the identity credentials on the second device are associated with the identity credentials on the first device, if the second device needs to control the first device to perform related operations or access the resources of the first device, the second device can directly perform local identity authentication, and the first device can directly trust the identity authentication result of the second device and respond accordingly, such as performing related operations or opening access rights to resources.
[0015] In one possible implementation, the identity credential association method may further include: receiving a second identity authentication request from a second device; performing local identity authentication in response to the second identity authentication request; and, after successful authentication, sending the second identity authentication result to the second device. In this manner, when the identity credential on the second device is associated with the identity credential on the first device, if the second device delegates cross-device identity authentication to the first device, then after the first device performs local identity authentication, the second device can directly trust the successful authentication result of the first device and respond accordingly.
[0016] In one possible implementation, the above-mentioned identity authentication result includes the identity credentials used during the identity authentication. In this way, when the local device entrusts another device to perform cross-identity authentication, it can verify whether the identity credentials used in the cross-identity authentication are associated with the identity credentials of the local device, thereby determining whether the identity authentication result of the other device can be trusted.
[0017] Optionally, the local device may store credential information of the associated identity credential, which may include at least one of a credential identifier (e.g., credential ID), a device identifier (e.g., device ID) to which the credential belongs, and an associated tag (e.g., group ID) for the credential. The local device can then verify, based on this stored information, whether the identity credential used for cross-identity authentication is the associated identity credential.
[0018] Optionally, the identity authentication result may include at least one of a credential identifier of the identity credential used during the identity authentication, a device identifier to which the credential belongs, and an associated tag of the credential, so that the device can confirm whether the identity credential used during the authentication is the associated identity credential.
[0019] In one possible implementation, the above-mentioned identity authentication result includes the identity credentials used during the identity authentication and a credential association certificate for the used identity credentials. The credential association certificate is used to prove whether the identity credentials were associated with the user's authorization and can only be issued when the user authorizes the association. In this way, when the local device entrusts another device to perform cross-identity authentication, it can not only verify whether the identity credentials used in the cross-identity authentication are associated with the identity credentials of the local device, but also verify the legitimacy of the association, that is, whether the association is authorized by the user.
[0020] In one possible implementation, determining, in response to a first request, whether a user authorizes the association of n identity credentials on a second device with m identity credentials on a first device includes: outputting a first prompt in response to the first request, the first prompt prompting the user whether to authorize the association of n identity credentials on the second device with m identity credentials on the first device; and determining, in response to the user's authorization operation on the first device, whether the user authorized the association. Thus, upon receiving the association request from the second device, the first device can collect the user's authorization intent to determine whether the user authorized the association.
[0021] In one possible implementation, determining, in response to the first request, whether the user authorizes the association of n identity credentials on the second device with m identity credentials on the first device includes: determining, in response to the first request, whether the user authorizes the association of n identity credentials on the second device with m identity credentials on the first device; and determining, in response to the user's authorization operation on the second device, that the user authorized the association. Thus, upon receiving the association request from the second device, the first device may also delegate the second device to collect the user's authorization intent to determine whether the user authorized the association.
[0022] Optionally, the second device may also automatically collect the user's authorization intent before sending the association request, and upon confirming the user's authorization, send the user's authorization instruction along with the association request to the first device. This allows the first device to directly confirm the user's authorization of the association and perform the association operation.
[0023] Optionally, upon receiving an association request from a second device, the first device may also send a first instruction to the second device, instructing the second device to collect the user's authorization intent. Upon receiving the first instruction, the second device may output a first prompt prompting the user whether to authorize the association of n identity credentials on the second device with m identity credentials on the first device. In response to the user's authorization operation on the second device, the second device may return an authorization indication to the first device confirming the user's authorization of the association. The first device can then confirm the user's authorization of the association and execute the association operation.
[0024] In one possible implementation, the aforementioned associating the n identity credentials with the m identity credentials in response to the user's authorization includes: performing local identity authentication in response to the user's authorization; and associating the n identity credentials with the m identity credentials when the identity authentication succeeds. After confirming the user's authorization for the association, the first device may verify the legitimacy of the authorization, i.e., whether the user has permission to authorize the association.
[0025] Optionally, the user with the authorization association permission may be the user to whom the m identity credentials belong, or may be a user trusted by the m identity credentials.
[0026] In one possible implementation, performing local identity authentication in response to user authorization includes: outputting a second prompt in response to the user's authorization, the second prompt prompting the user to enter identity authentication information; and performing local identity authentication in response to the user's input operation on the first device. In this manner, after detecting the user's intention to authorize the association, the first device can locally collect the user's authentication information to authenticate the user and verify the legitimacy of the authorized association.
[0027] In one possible implementation, performing local identity authentication in response to user authorization includes: obtaining identity authentication information entered by the user on the second device in response to the user's authorization; and performing local identity authentication based on the identity authentication information. In this manner, after the first device detects the user's intent to authorize the association, it may delegate the collection of the user's authentication information to the second device, which then returns the information to the first device for identity authentication to verify the legitimacy of the authorized association.
[0028] In one possible implementation, when the user authorized to associate the identity may be the user to whom the m identity credentials belong, performing local identity authentication includes performing local identity authentication based on an authentication method corresponding to at least one of the m identity credentials. Thus, upon receiving a request from the second device for association with the identity credentials, the first device performs authentication using the authentication method corresponding to those identity credentials to ensure that the association is authorized by the user to whom the identity credentials belong.
[0029] In one possible implementation, after associating the n identity credentials with the m identity credentials, the method further includes: sending a first response to the second device, the first response being used to indicate a successful association between the n identity credentials and the m identity credentials. Thus, after associating the n identity credentials with the m identity credentials, the first device can return the first response to the second device, thereby notifying the second device of the successful association between the n identity credentials and the m identity credentials.
[0030] In one possible implementation, the first response includes at least one of the following: an association key; a credential association certificate; and successful association indication information.
[0031] The successful association indication information may be a simple indication of successful association, or it may include association information for n identity credentials and m identity credentials. The association information may be an association tag. For example, when the association is expressed in the form of a group, the successful association indication information may include the group ID to which the n identity credentials and m identity credentials successfully joined. Subsequently, the first device and the second device may trust the identity authentication result of any identity credential in the group ID.
[0032] The credential association certificate is used to prove that the user has authorized the association of n identity credentials with m identity credentials. Upon user authorization of the association, the first device can issue a credential association certificate for the n identity credentials and the m identity credentials. This allows the first and second devices to trust the identity authentication results issued for the identity credentials with the credential association certificate, thereby improving authentication security.
[0033] It is understandable that if the local device entrusts other devices to perform cross-identity authentication, if the identity credentials used by the other devices for cross-identity authentication are not issued with a credential association certificate, the local device may not trust the cross-identity authentication result.
[0034] The association key is used to verify the legitimacy of the credential association. It is only available on the device where the user-authorized identity credentials are located. That is, if the user authorizes the association of n identity credentials with m identity credentials, both the first and second devices will have the association key.
[0035] Therefore, if there is an identity credential stating that it has been successfully associated, the first device and the second device can both use the association key to verify the legitimacy of the association of the identity credential.
[0036] As a method, the credential association certificate is issued by the first device using the association key. Therefore, if an identity credential claims to have been successfully associated, both the first and second devices can use the association key to verify the credential association certificate of the identity credential. Successful verification proves that the identity credential is indeed the identity credential authorized by the user.
[0037] It can be understood that since the user authorized the association of n identity credentials with m identity credentials, the first device can send the association key to the second device. This allows the second device to issue a credential association certificate. When another device sends an association request to the second device, the second device can detect the user's authorization intent, perform the association operation upon confirming the user's authorization, and simultaneously issue a credential association certificate using the association key.
[0038] In one possible implementation, the m identity credentials correspond to a first user, and the n identity credentials correspond to a second user, and the first user and the second user are the same user or different users. In this way, the same user can associate his or her identity credentials on different devices, so that from the device side, the associated identity credentials all belong to the same user, and the identity authentication result of any of the identity credentials is the identity authentication result of the same user. Of course, the user can also associate the identity credentials of other different users with his or her own identity credentials. Since from the device side, the associated identity credentials all belong to the same natural person, in some scenarios involving identity authentication, the user and other different users can both be successfully authenticated.
[0039] In one possible implementation, m identity credentials correspond to a first account, and n identity credentials correspond to a second account, where the first account and the second account can be the same account or different accounts. In this way, identity credentials of the same account on different devices can be associated, and identity credentials of different accounts can also be associated.
[0040] In one possible implementation, m identity credentials have been added to a first association, and determining whether the user authorizes the association of n identity credentials on the second device with the m identity credentials on the first device includes determining whether the user authorizes the addition of n identity credentials on the second device to the first association. Optionally, when the first association is represented by group A, the first device may determine whether the user authorizes the addition of n identity credentials on the second device to group A.
[0041] Optionally, the first association is created by the first device based on m identity credentials. Upon successful creation, the m identity credentials are automatically added to the first association. Optionally, the first association is created by another device based on other identity credentials. Upon successful creation, the first device may request the other device to add the m identity credentials to the first association. The other device may add the m identity credentials to the first association upon confirming user authorization.
[0042] In one possible implementation, the method further includes: obtaining a third request triggered on the first device; in response to the third request, determining whether the user authorizes the association of the (m+1)th identity credential on the first device with the m identity credentials; and in response to the user's authorization, associating the (m+1)th identity credential with the m identity credentials. In this way, when unassociated identity credentials exist locally on the first device, the first device may also trigger an association request locally to associate the unassociated identity credential with the m identity credentials.
[0043] In one possible implementation, the communication system further includes a third device, and the method further includes: obtaining a third request triggered on the first device; in response to the third request, determining whether the user authorizes the third device to associate p identity credentials with m identity credentials, where p is a positive integer; and in response to the user's authorization, associating the p identity credentials with the m identity credentials. In this way, the first device can also proactively locally associate the p identity credentials of other devices with the m identity credentials.
[0044] Optionally, when m identity credentials have been added to the established first association, the first device can display the credential information in the first association. The first device can also selectively add p identity credentials on other devices to the first association in response to a user's operation to add credentials to the first association. The first device can obtain authorization only from the user to whom the m identity credentials belong, or it can obtain authorization from the users to whom both the m and p identity credentials belong.
[0045] In one possible implementation, m identity credentials correspond to a first user, p identity credentials correspond to a third user, and the user authorization includes the authorization of the first user and the authorization of the third user. In this way, when it is necessary to associate identity credentials of different users, authorization of both users is required.
[0046] Similarly, when obtaining the authorization intentions of both different users, the legitimacy of the authorizations of both different users needs to be verified.
[0047] Optionally, the aforementioned associating the p identity credentials with the m identity credentials in response to the user's authorization includes: performing local identity authentication in response to the first user's authorization; and after the identity authentication is successful, upon receiving a third identity authentication result from a third device, associating the p identity credentials with the m identity credentials, where the third identity authentication result is a result of successful local identity authentication performed by the third device in response to the third user's authorization. In this manner, upon determining that the authorizations of the different users are legitimate, the first device may associate the identity credentials of the different users.
[0048] In one possible implementation, p identity credentials, n identity credentials, and m identity credentials are successfully associated, and the method further includes: obtaining a fourth request triggered on the first device; in response to the fourth request, sending a third identity authentication request to a target device, where the target device is the second device or the third device; receiving a fourth identity authentication result sent by the target device, where the fourth identity authentication result is a result of successful identity authentication when the target device performs local identity authentication; and in response to the fourth identity authentication result, performing an operation corresponding to the fourth request. In a distributed scenario where identity credentials on multiple devices are associated, the local device can select a device from among the devices where the associated identity credentials are located to delegate cross-device authentication.
[0049] Optionally, the local device can send an authentication request to the target device, or broadcast the authentication request to all devices in a distributed scenario and only recognize the authentication result of the device where the associated identity credential is located.
[0050] In a possible implementation, the target device is a device selected by the user. Thus, when there are multiple devices with associated identity credentials, the user can adaptively select a device for identity authentication.
[0051] In one possible implementation, the target device is a device that meets preset conditions, including at least one of the following: the distance between the device and the user is less than a first threshold; the authentication security level of the identity credentials associated with the device is greater than a second threshold; the device's usage frequency is greater than a third threshold; the authentication method corresponding to the identity credentials associated with the device is compatible with the current environment; and the device is in use. In this way, if there are multiple devices with associated identity credentials, the device can intelligently recommend the best device for authentication.
[0052] In a second aspect, a method for associating identity credentials is provided, which is applied to a second device in a communication system, and the communication system also includes a first device. The method includes: sending a first request to the first device, the first request being used to instruct the first device to associate n identity credentials on the second device with m identity credentials on the first device when determining user authorization, where n and m are positive integers; receiving a first response sent by the first device, the first response being used to indicate a successful association between the n identity credentials and the m identity credentials, and the association being used to indicate that the first device and the second device trust an identity authentication result based on the associated identity credentials.
[0053] In the solution provided by the second aspect above, when the identity credentials on the second device need to be associated with the identity credentials on the first device, the second device can send an association request to the first device to wait for the first device to confirm user authorization, and when it is determined that the user authorization is obtained, wait for the first device to associate the identity credentials on the second device with the identity credentials on the first device. Then, a first response indicating a successful association is received from the first device. In this way, multiple identity credentials on different electronic devices can be associated with each other under user authorization, so that the identity authentication results of the associated identity credentials can be trusted between different electronic devices.
[0054] In one possible implementation, the method further includes: obtaining a second request triggered on the second device; performing local identity authentication in response to the second request; and sending a first identity authentication result to the first device after the identity authentication is passed, the first identity authentication result being used to instruct the first device to perform an operation corresponding to the second request. In this way, when the identity credentials on the second device are successfully associated with the identity credentials on the first device, if the user needs to access the resources of the first device or control the first device to perform a preset operation on the second device, the user can perform local identity authentication directly on the second device. The first device can directly trust the identity authentication result of the second device and respond accordingly, such as developing access rights to resources or performing preset operations.
[0055] Optionally, the second request triggered on the second device may be an operation request that requires identity authentication on the first device, such as accessing resources, logging into an account, making a transaction payment, unlocking the first device, etc. It is understood that when it is inconvenient for the user to authenticate on the first device, the user may also authenticate directly on the second device.
[0056] In one possible implementation, the identity credential association method may further include: obtaining a second request triggered on the second device; sending a first identity authentication request to the first device in response to the second request; receiving a first identity authentication result sent by the first device, the first identity authentication result being a successful identity authentication result when the first device performs local identity authentication; and performing an operation corresponding to the second request in response to the first identity authentication result. In this way, when the identity credentials on the second device are successfully associated with the identity credentials on the first device, if the second device entrusts the first device to perform cross-device identity authentication, the second device can directly trust the successful identity authentication result of the first device and respond accordingly.
[0057] Optionally, the second request triggered on the second device may be an operation request requiring identity authentication on the second device, such as accessing resources, logging into an account, making a transaction payment, unlocking the second device, etc. It is understood that when it is inconvenient for the user to perform identity authentication on the second device, the second device may also entrust the first device to perform cross-device identity authentication.
[0058] In a possible embodiment, the method for associating the identity credentials may also include: receiving a second identity authentication result sent by the first device, the second identity authentication result being the result of the identity authentication passing when the first device performs local identity authentication for the second request triggered on the first device; and performing an operation corresponding to the second request in response to the second identity authentication result.
[0059] Optionally, the second request triggered on the first device may be an operation request that requires identity authentication on the second device, such as controlling the second device to perform related operations (such as unlocking) or accessing resources of the second device (such as pictures).
[0060] In this way, when the identity credentials on the second device are associated with the identity credentials on the first device, if the first device needs to control the second device to perform related operations or access the resources of the second device, the first device can directly perform local identity authentication, and the second device can directly trust the identity authentication result of the first device and respond accordingly, such as performing related operations or opening access rights to resources.
[0061] In one possible implementation, the identity credential association method may further include: receiving a second identity authentication request from the first device; performing local identity authentication in response to the second identity authentication request; and, after successful authentication, sending the second identity authentication result to the first device. In this manner, when the identity credential on the second device is associated with the identity credential on the first device, if the first device delegates cross-device identity authentication to the second device, then after the second device performs local identity authentication, the first device can directly trust the successful authentication result of the second device and respond accordingly.
[0062] In one possible embodiment, the identity authentication result includes the identity credentials used during the identity authentication; or, the identity authentication result includes the identity credentials used during the identity authentication and a certificate of credential association of the used identity credentials. In this way, when the local device entrusts another device to perform cross-identity authentication, it can verify whether the identity credentials used in the cross-identity authentication are associated with the identity credentials of the local device, thereby determining whether the identity authentication result of the other device can be trusted.
[0063] In one possible implementation, sending a first request to a first device includes: outputting a first prompt prompting a user whether to authorize the association of n identity credentials on a second device with m identity credentials on the first device; and sending the first request to the first device in response to the user's authorization operation on the second device. In this manner, the second device can also automatically collect the user's authorization intent before sending the association request, and upon confirming user authorization, send the user's authorization instruction along with the association request to the first device. This allows the first device to directly confirm the user's authorization of the association and execute the association operation.
[0064] In one possible implementation, after sending the first request to the first device, the method further includes: receiving a first instruction from the first device; in response to the first instruction, outputting a first prompt, the first prompt prompting the user whether to authorize the association of n identity credentials on the second device with m identity credentials on the first device; and in response to the user's authorization operation on the second device, sending an authorization instruction to the first device. In this way, the second device can receive the authentication information collection delegation instruction from the first device and collect the user's authorization intent on behalf of the first device.
[0065] In one possible embodiment, in response to the user's authorization operation on the second device, a first request is sent to the first device, including: in response to the user's authorization operation on the second device, outputting a second prompt, the second prompt being used to prompt the user to enter identity authentication information; in response to the user's input operation on the second device, sending a first request to the first device, the first request being used to instruct the first device to perform local identity authentication based on the identity authentication information entered by the user on the second device when determining user authorization.
[0066] Alternatively, in response to a user authorization operation on a second device, sending an authorization indication to the first device includes: outputting a second prompt in response to the user authorization operation on the second device, the second prompt being used to prompt the user to enter identity authentication information; and in response to the user input operation on the second device, sending an authorization indication to the first device, the authorization indication being used to instruct the first device to perform local identity authentication based on the identity authentication information entered by the user on the second device when determining user authorization. In this manner, after confirming the user authorization association, the second device can collect the user's authentication information and return it to the first device to verify the legitimacy of the authorization, i.e., whether the user has permission to authorize the association.
[0067] In one possible implementation, the first response includes at least one of the following: an association key; a credential association certificate; and successful association indication information.
[0068] In one possible implementation, m identity credentials have been added to a first association, and a first request is sent to a first device, including: displaying a first interface, the first interface including at least one association, the at least one association including the first association; and in response to a user selecting the first association, sending a first request to the first device, the first request being used to instruct the first device to add the n identity credentials on the second device to the first association upon determining user authorization. In this manner, when multiple established associations exist in the communication system, the second device can select one of the associations to add the n local identity credentials.
[0069] In one possible implementation, the communication system further includes another device, and identity credentials on the other device are already added to the first association; in response to a user selecting the first association, sending a first request to the first device includes: in response to the user selecting the first association, sending the first request to the first device and the other device. In this way, when n identity credentials wish to join the first association, and identity credentials of multiple devices are already added to the first association, the second device can send association requests to the multiple devices to request to join the first association.
[0070] In one possible embodiment, in response to a user selecting a first association, sending a first request to a first device includes: in response to the user selecting the first association, sending the first request to a first device among the first device and other devices, where the first device is a device selected by the user or a device that meets a preset condition. Thus, when n identity credentials wish to be added to a first association that already includes identity credentials of multiple devices, the second device may also send an association request to the device selected by the user among the multiple devices, or may intelligently determine a device that meets the conditions to send the association request to.
[0071] In one possible implementation, the pre-set conditions include at least one of the following: the distance between the device and the user is less than a first threshold; the authentication security level of the identity credential associated with the device is greater than a second threshold; the device usage frequency is greater than a third threshold; the authentication method corresponding to the identity credential associated with the device is compatible with the current environment; and the device is in use. In this way, if there are multiple devices with associated identity credentials, the device can intelligently recommend the best device for user authorization and perform the association operation when user authorization is confirmed.
[0072] In one possible embodiment, the communication system further includes a third device. After receiving the first response sent by the first device, the method further includes: receiving a third request sent by the third device; in response to the third request, determining whether the user has authorized the association of p identity credentials with n identity credentials and m identity credentials on the third device, where p is a positive integer; and in response to the user's authorization, associating the p identity credentials with the n identity credentials and m identity credentials, where the association indicates that the first device, the second device, and the third device trust the identity authentication result based on the associated identity credentials. In this way, after the identity credentials on the second device are successfully associated with the identity credentials on the first device, the second device can also receive association requests from other devices and confirm whether the user has authorized the association, so as to perform the association operation if the user has authorized the association.
[0073] In one possible embodiment, the communication system also includes a third device, and the p identity credentials on the third device are successfully associated with the n identity credentials and the m identity credentials. The method also includes: obtaining a second request triggered on the second device; sending a first identity authentication request to the third device in response to the second request; receiving a second identity authentication result sent by the third device, the second identity authentication result being the result of the identity authentication passing when the third device performs local identity authentication; sending the second identity authentication result to the first device, the second identity authentication result being used to instruct the first device to perform an operation corresponding to the second request. In this way, in a distributed scenario where the identity credentials of the first device, the second device, and the third device are successfully associated, if the second device needs to access the resources of the first device or control the first device to perform a preset operation, the second device may also entrust other devices, such as the third device currently being used by the user, to perform cross-device identity authentication. The first device can directly trust the identity authentication result of the third device and respond accordingly, such as developing access rights to resources or performing preset operations.
[0074] According to a third aspect, an identity authentication method is provided, which is applied to a communication system, wherein the communication system includes a first device and a second device, and the method includes: the second device sends a first request to the first device; the first device receives the first request sent by the second device; the first device determines, in response to the first request, whether the user authorizes n identity credentials on the second device to be associated with m identity credentials on the first device, where n and m are positive integers; the first device associates the n identity credentials with the m identity credentials in response to the user's authorization, and the association is used to indicate that the first device and the second device trust the identity authentication result based on the associated identity credentials.
[0075] In a possible embodiment, the method of associating the identity credentials may also include: the first device obtains a second request triggered on the first device; the first device sends a first identity authentication request to the second device in response to the second request; the second device receives the first identity authentication request sent by the first device; the second device performs local identity authentication in response to the first identity authentication request; after the identity authentication is passed, the second device sends a first identity authentication result to the first device; the first device receives the first identity authentication result sent by the second device; the first device performs an operation corresponding to the second request in response to the first identity authentication result.
[0076] In a possible embodiment, the method of associating the identity credentials may also include: the second device obtains a second request triggered on the second device; the second device sends a first identity authentication request to the first device in response to the second request; the first device receives the first identity authentication request sent by the second device; the first device performs local identity authentication in response to the first identity authentication request; after the identity authentication is passed, the first device sends a first identity authentication result to the second device; the second device receives the first identity authentication result sent by the first device; the second device performs an operation corresponding to the second request in response to the first identity authentication result.
[0077] In a possible implementation, the method for associating the identity credentials may also include: the second device obtains a second request triggered on the second device; the second device performs local identity authentication in response to the second request; after the identity authentication is passed, the second device sends a first identity authentication result to the first device; the first device receives the first identity authentication result sent by the second device; the first device performs an operation corresponding to the second request in response to the first identity authentication result.
[0078] In a possible implementation, the method for associating the identity credentials may also include: the first device obtains a second request triggered on the first device; the first device performs local identity authentication in response to the second request; after the identity authentication is passed, the first device sends a first identity authentication result to the second device; the second device receives the first identity authentication result sent by the first device; the second device performs an operation corresponding to the second request in response to the first identity authentication result.
[0079] In a possible implementation, the identity authentication result includes the identity credentials used during the identity authentication, or the identity authentication result includes the identity credentials used during the identity authentication and a credential association certificate of the used identity credentials.
[0080] In one possible implementation, the first device determines, in response to a first request, whether the user authorizes the association of n identity credentials on the second device with m identity credentials on the first device, including: the first device outputs a first prompt in response to the first request, the first prompt being used to prompt the user whether to authorize the association of n identity credentials on the second device with m identity credentials on the first device; the first device determines that the user authorizes the association in response to the user's authorization operation on the first device.
[0081] In one possible implementation, a first device, in response to a first request, determines whether a user authorizes the association of n identity credentials on a second device with m identity credentials on the first device, including: the first device, in response to the first request, sends a first instruction to the second device; the second device receives the first instruction sent by the first device; the second device, in response to the first instruction, outputs a first prompt, the first prompt being used to prompt the user whether to authorize the association of n identity credentials on the second device with m identity credentials on the first device; the second device, in response to the user's authorization operation on the second device, sends an authorization indication to the first device; the first device receives the authorization indication sent by the second device. In response to the authorization indication, the first device determines that the user authorized the association.
[0082] In one possible implementation, the second device sends a first request to the first device, including: the second device outputs a first prompt, the first prompt being used to prompt the user whether to authorize the association of n identity credentials on the second device with m identity credentials on the first device; the second device sends the first request to the first device in response to the user's authorization operation on the second device.
[0083] In one possible implementation, the first device associates n identity credentials with m identity credentials in response to the user's authorization, including: the first device performs local identity authentication in response to the user's authorization; when the identity authentication is passed, the first device associates n identity credentials with m identity credentials.
[0084] In one possible implementation, the first device performs local identity authentication in response to the user's authorization, including: the first device outputs a second prompt in response to the user's authorization, where the second prompt is used to prompt the user to input identity authentication information; the first device performs local identity authentication in response to the user's input operation on the first device.
[0085] In one possible implementation, the first device performs local authentication in response to user authorization, including: the first device sends a second instruction to the second device in response to user authorization; the second device receives the second instruction from the first device; the second device outputs a second prompt in response to the second instruction, and the second prompt is used to prompt the user to input authentication information; the second device sends the user-input authentication information to the first device in response to the user's input operation on the second device; the first device receives the authentication information sent by the second device; and the first device performs local authentication based on the authentication information.
[0086] In a possible implementation, the first device performs local identity authentication, including: the first device performs local identity authentication based on an authentication method corresponding to at least one identity credential among the m identity credentials.
[0087] In a possible implementation, after the first device associates the n identity credentials with the m identity credentials, the method further includes: the first device sends a first response to the second device, where the first response is used to indicate a successful association between the n identity credentials and the m identity credentials.
[0088] In one possible implementation, the first response includes at least one of the following: an association key; a credential association certificate; and successful association indication information.
[0089] In a possible implementation, the m identity credentials correspond to a first user, and the n identity credentials correspond to a second user. The first user and the second user are the same user or different users.
[0090] In a possible implementation, m identity credentials correspond to a first account, n identity credentials correspond to a second account, and the first account and the second account are the same account or different accounts.
[0091] In one possible implementation, m identity credentials have been added to a first association with an established association relationship, and the first device determines whether the user authorizes the n identity credentials on the second device to be associated with the m identity credentials on the first device, including: the first device determines whether the user authorizes the addition of n identity credentials on the second device to the first association.
[0092] In one possible implementation, m identity credentials have been added to a first association in which an association relationship has been established, and the second device sends a first request to the first device, including: the second device displays a first interface, the first interface includes at least one association, and the at least one association includes the first association; the second device responds to the user's selection of the first association and sends a first request to the first device, the first request being used to instruct the first device to add n identity credentials on the second device to the first association when determining user authorization.
[0093] In a possible implementation, the communication system further includes other devices, and identity credentials exist on the other devices and have been added to the first association;
[0094] The second device sends the first request to the first device in response to the user's selection of the first association, including: the second device sends the first request to the first device and the other device in response to the user's selection of the first association; or
[0095] In response to the user's selection of the first association, the second device sends a first request to a first device among the first device and the other devices, where the first device is a device selected by the user or a device that meets a preset condition.
[0096] In one possible embodiment, the preset conditions include at least one of the following: the distance between the device and the user is less than a first threshold; the authentication security level of the identity credentials associated with the device is greater than a second threshold; the frequency of use of the device is greater than a third threshold; the authentication method corresponding to the identity credentials associated with the device is adapted to the current environment; and the device is in use.
[0097] In a possible implementation, the method further includes: the first device obtains a third request triggered on the first device; the first device determines, in response to the third request, whether the user authorizes the (m+1)th identity credential on the first device to be associated with the m identity credentials; the first device associates the (m+1)th identity credential with the m identity credentials in response to the user's authorization.
[0098] In a possible embodiment, the communication system also includes a third device, and the method also includes: the first device obtains a third request triggered on the first device; the first device determines, in response to the third request, whether the user authorizes the association of p identity credentials with m identity credentials on the third device, where p is a positive integer; the first device associates the p identity credentials with the m identity credentials in response to the user's authorization.
[0099] Optionally, the first device sends a second response to the third device, where the second response is used to indicate a successful association between the p identity credentials and the m identity credentials.
[0100] In a possible implementation, m identity credentials correspond to the first user, p identity credentials correspond to the third user, and the user authorization includes the authorization of the first user and the authorization of the third user.
[0101] The above-mentioned first device responds to the third request and determines whether the user authorizes the association of p identity credentials with m identity credentials on the third device, including: the first device outputs a third prompt in response to the third request, and the third prompt is used to prompt the user whether to authorize the association of p identity credentials with m identity credentials on the third device; the first device determines that the first user authorizes the association in response to the first user's authorization operation on the first device; the first device sends a fourth request to the third device; the third device receives the fourth request of the first device; the third device outputs a fourth prompt in response to the fourth request, and the fourth prompt is used to prompt the user whether to authorize the association of p identity credentials with m identity credentials on the third device; the third device determines that the third user authorizes the association in response to the third user's authorization operation on the third device; the third device sends an authorization indication of the third user authorizing the association to the first device; the first device receives the authorization indication sent by the third device; the first device determines that both the first user and the third user authorize the association.
[0102] Optionally, it is also necessary to verify the legitimacy of the authorization association by both the first user and the third user.
[0103] The above-mentioned first device determines the first user authorization association in response to the first user's authorization operation on the first device, including: the first device performs local identity authentication in response to the first user's authorization operation on the first device; after the identity authentication is passed, the first device determines the first user authorization association.
[0104] The third device determines the third user authorization association in response to the third user's authorization operation on the third device, including:
[0105] The third device performs local identity authentication in response to the authorization operation of the third user on the third device; after the identity authentication is passed, the third device determines that the first user is authorized to associate.
[0106] In a possible embodiment, the above-mentioned p identity credentials, n identity credentials, and m identity credentials are successfully associated, and the method also includes: the first device obtains a fourth request triggered on the first device; the first device sends a second identity authentication request to the target device in response to the fourth request, and the target device is the second device or the third device; the target device receives the second identity authentication request of the first device; the target device performs local identity authentication in response to the second identity authentication request; after the identity authentication is passed, the target device sends the second identity authentication result to the first device; the first device receives the fourth identity authentication result sent by the target device; the first device performs an operation corresponding to the fourth request in response to the fourth identity authentication result.
[0107] In one possible embodiment, the above-mentioned p identity credentials are successfully associated with n identity credentials and m identity credentials, and the method also includes: the second device obtains a second request triggered on the second device; the second device sends a second identity authentication request to the third device in response to the second request; the third device receives the second identity authentication request of the second device; the third device performs local identity authentication in response to the second identity authentication request; after the identity authentication is passed, the third device sends the second identity authentication result to the second device; the second device receives the second identity authentication result sent by the third device; the second device sends the second identity authentication result to the first device; the first device receives the second identity authentication result sent by the second device; the first device performs the operation corresponding to the second request in response to the second identity authentication result.
[0108] In a fourth aspect, an identity authentication method is provided, which is applied to a first device in a communication system, wherein the communication system includes multiple devices, the multiple devices include the first device, and the identity credentials on the multiple devices are successfully associated. The method includes: obtaining a first request triggered on the first device; in response to the first request, sending an identity authentication request to a second device among the multiple devices; receiving an identity authentication result sent by the second device, the identity authentication result being a result of passing the identity authentication when the second device performs local identity authentication; and in response to the identity authentication result, executing an operation corresponding to the first request.
[0109] Optionally, the first device may be any device in the communication system, i.e., any device in the communication system may have identity authentication requirements and may be used to determine whether the user is legitimate. The second device may be any device in the communication system other than the first device, i.e., any device in the communication system may have cross-identity authentication capabilities.
[0110] The solution provided in the first aspect above is for a communication system consisting of multiple electronic devices. If the identity credentials on the multiple electronic devices are linked, then when the first device needs to perform identity authentication, it can delegate cross-device identity authentication to any other device in the communication system, trust the cross-device identity authentication result, and execute the corresponding response. In this way, by linking the identity credentials on multiple electronic devices, distributed authentication of multiple electronic devices can be achieved.
[0111] In one possible implementation, the second device is a device currently being used by the user. For example, if the user is using a smart TV for video chatting, the smart TV can be entrusted to perform user identity authentication. For another example, if the user is using a smartphone, the smartphone can be entrusted to perform user identity authentication.
[0112] In one possible implementation, the second device is the device closest to the user. For example, if the user is exercising, the smartwatch may be entrusted to authenticate the user.
[0113] In one possible implementation, the second device is a device selected by the user. For example, the first device displays a first interface including multiple devices, and in response to the selection of the second device from the multiple devices, the first device sends a cross-device authentication request to the second device.
[0114] In one possible implementation, the second device is a device that meets the authentication security level required by the first request. For example, if the first request is a payment request, the second device can be entrusted to perform identity authentication on a device such as a smartphone or tablet that has a password associated with the first request. This allows the smartphone or tablet to use a password authentication method with a high authentication security level to authenticate the user.
[0115] In a possible implementation, the identity authentication result sent by the second device may include identity credentials used by the second device when performing local identity authentication.
[0116] In a possible implementation, the identity authentication result sent by the second device may include the identity credential used by the second device when performing local identity authentication and a credential association certificate of the identity credential.
[0117] In a possible implementation, the authentication method adopted by the second device when performing local identity authentication is the authentication method corresponding to the identity credential with the highest authentication security level added to the associated identity credential on the second device.
[0118] In one possible implementation, the authentication method is adapted to the user's current environment. For example, if a user's face, password, and voiceprint are all associated with a smart TV, and the user is using the smart TV for a video chat, the smart TV can use the smart TV's facial authentication method to authenticate the user. For another example, if the user is using a voice assistant, which indicates they may not have hands available, voiceprint authentication can be used to authenticate the user. For another example, if the user is exercising, a smartwatch can be used to authenticate the user using a non-invasive PPG authentication method.
[0119] In a possible implementation, the authentication mode is an authentication mode selected by the user.
[0120] In a possible embodiment, the above-mentioned communication system also includes a third device, and the identity authentication method also includes: obtaining a second request triggered on the first device; in response to the second request, sending an identity authentication request to a second device among the multiple devices; receiving an identity authentication result sent by the second device, the identity authentication result being the result of the identity authentication passing when the second device performs local identity authentication; sending the identity authentication result to the third device, the identity authentication result being used to instruct the third device to perform an operation corresponding to the second request. In this way, when the first device needs to access the resources of the third device or control the third device to perform a preset operation, the first device can entrust the second device to perform cross-device authentication. The third device can then trust the cross-device identity authentication result of the second device and respond accordingly, such as giving the first device permission to access resources, being controlled by the first device to perform preset operations, etc.
[0121] In a fifth aspect, a device for associating identity credentials is provided. The device is included in an electronic device and has the function of implementing the first aspect, the second aspect, or any possible design thereof. The function can be implemented through hardware or through hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the above functions.
[0122] As an example, the identity credential association device may include a receiving module, an authentication module, and an association module. The receiving module is configured to receive a first request sent by a second device; the authentication module is configured to determine, in response to the first request, whether the user authorizes the association of n identity credentials on the second device with m identity credentials on the first device, where n and m are positive integers; and the association module is configured to associate the n identity credentials with the m identity credentials in response to the user's authorization, where the association indicates that the first device and the second device trust an identity authentication result based on the associated identity credentials.
[0123] Optionally, the identity credential association device may further include an acquisition module, a sending module, and an execution module. The acquisition module is configured to acquire a second request triggered on the first device; the sending module is configured to send a first identity authentication request to the second device in response to the second request; the receiving module may also be configured to receive a first identity authentication result sent by the second device, the first identity authentication result being a result of successful local identity authentication performed by the second device; and the execution module is configured to execute an operation corresponding to the second request in response to the first identity authentication result.
[0124] Optionally, the receiving module may also be configured to receive a second identity authentication request sent by a second device. The identity credential association apparatus may further include an authentication module configured to perform local identity authentication in response to the second identity authentication request. The sending module may be configured to send the second identity authentication result to the second device after the identity authentication is successful.
[0125] It should be noted that the above-mentioned first aspect and any possible implementation scheme thereof can be implemented by corresponding functional modules on the associated device of the identity credential, which will not be described in detail here.
[0126] As another example, the identity credential association device may include a sending module and a receiving module. The sending module is configured to: send a first request to a first device, the first request being configured to instruct the first device to associate n identity credentials on a second device with m identity credentials on the first device when determining user authorization, where n and m are positive integers; and the receiving module is configured to: receive a first response sent by the first device, the first response being configured to indicate a successful association between the n identity credentials and the m identity credentials, wherein the association is configured to indicate that the first device and the second device trust an identity authentication result based on the associated identity credentials.
[0127] It should be noted that the above-mentioned second aspect and any possible implementation scheme thereof can be implemented by corresponding functional modules on the associated device of the identity credential, which will not be described in detail here.
[0128] In a sixth aspect, an identity authentication device is provided, which is included in an electronic device and has the function of implementing the fourth aspect or any possible design thereof. This function can be implemented through hardware or through hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the above-mentioned functions.
[0129] As an example, the identity authentication device may include an acquisition module, a sending module, a receiving module, and an execution module. The acquisition module is configured to acquire a first request triggered on a first device; the sending module is configured to send an identity authentication request to a second device among the multiple devices in response to the first request; the receiving module is configured to receive an identity authentication result sent by the second device, where the identity authentication result is a result of passing the local identity authentication performed by the second device; and the receiving module is configured to execute an operation corresponding to the first request in response to the identity authentication result.
[0130] It should be noted that the above-mentioned fourth aspect and any possible implementation scheme thereof can be implemented by corresponding functional modules on the associated device of the identity credential, which will not be repeated here.
[0131] In the seventh aspect, an electronic device is provided, which includes a memory and one or more processors; the memory is used to store a program, and when the processor executes the program, the electronic device executes the identity credential association method in any possible implementation of the above-mentioned first aspect, or executes the identity credential association method in any possible implementation of the above-mentioned second aspect, or executes the identity authentication method in any possible implementation of the above-mentioned fourth aspect.
[0132] In an eighth aspect, a communication system is provided, which includes a first device and a second device, the first device being used to execute the identity credential association method in any possible implementation of the second aspect, and the second device being used to execute the identity credential association method in any possible implementation of the second aspect.
[0133] Optionally, the first device and the second device may also execute the identity authentication method in any possible implementation of the fourth aspect above.
[0134] In a ninth aspect, a chip system is provided. The chip system includes one or more interface circuits and one or more processors. The interface circuit and the processor are interconnected via a line. The interface circuit is used to receive a signal from a memory of an electronic device and send the signal to the processor, where the signal includes an instruction stored in the memory. When the processor executes the instruction, the electronic device executes the identity credential association method in any possible implementation of the first aspect, or executes the identity credential association method in any possible implementation of the second aspect, or executes the identity authentication method in any possible implementation of the fourth aspect.
[0135] In the tenth aspect, a readable storage medium is provided, comprising instructions, which, when executed on an electronic device, causes the electronic device to execute the identity credential association method of any possible implementation of the first aspect, or execute the identity credential association method of any possible implementation of the second aspect, or execute the identity authentication method of any possible implementation of the fourth aspect.
[0136] In the eleventh aspect, a computer program product is provided. When the computer program product runs on a computer, it enables the computer to execute the identity credential association method in any possible implementation of the above-mentioned first aspect, or execute the identity credential association method in any possible implementation of the above-mentioned second aspect, or execute the identity authentication method in any possible implementation of the above-mentioned fourth aspect.
[0137] It can be understood that the beneficial effects that can be achieved by the method of the third aspect, the device of the fifth aspect, the device of the sixth aspect, the equipment of the seventh aspect, the system of the eighth aspect, the chip system of the ninth aspect, the readable storage medium of the tenth aspect, and the program product of the eleventh aspect provided above can refer to the beneficial effects in the first aspect, the second aspect, the fourth aspect and any possible implementation of them, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0138] FIG1 is a schematic diagram of an application scenario provided by an embodiment of the present application;
[0139] FIG2 is a second schematic diagram of an application scenario provided by an embodiment of the present application;
[0140] FIG3 is a third schematic diagram of an application scenario provided in an embodiment of the present application;
[0141] FIG4 is a fourth schematic diagram of an application scenario provided by an embodiment of the present application;
[0142] FIG5 is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present application;
[0143] FIG6 is a schematic diagram of the software structure of an electronic device provided in an embodiment of the present application;
[0144] FIG7 is a system schematic diagram of a communication system provided in an embodiment of the present application;
[0145] FIG8 is a fifth schematic diagram of an application scenario provided in an embodiment of the present application;
[0146] FIG9 is a first schematic diagram of a user interface provided in an embodiment of the present application;
[0147] FIG10 is a flowchart of an identity credential association method provided in an embodiment of the present application;
[0148] FIG11 is a second schematic diagram of a user interface provided in an embodiment of the present application;
[0149] FIG12 is a flowchart of another method for associating identity credentials provided in an embodiment of the present application;
[0150] FIG13 is a third schematic diagram of a user interface provided in an embodiment of the present application;
[0151] FIG14 is a fourth schematic diagram of a user interface provided in an embodiment of the present application;
[0152] FIG15 is a flowchart of another method for associating identity credentials provided in an embodiment of the present application;
[0153] FIG16 is a fifth schematic diagram of a user interface provided in an embodiment of the present application;
[0154] FIG17 is a flowchart of another method for associating identity credentials provided in an embodiment of the present application;
[0155] FIG18 is a sixth schematic diagram of a user interface provided in an embodiment of the present application;
[0156] FIG19 is a flow chart of an identity authentication method provided in an embodiment of the present application;
[0157] FIG20 is a sixth schematic diagram of an application scenario provided in an embodiment of the present application;
[0158] 21 is a flowchart of an authorization token verification process in an identity authentication method provided in an embodiment of the present application;
[0159] FIG22 is a flowchart of another identity authentication method provided in an embodiment of the present application;
[0160] FIG23 is a seventh schematic diagram of a user interface provided in an embodiment of the present application;
[0161] FIG24 is a flowchart of another identity authentication method provided in an embodiment of the present application;
[0162] FIG25 is a fifth schematic diagram of identity credential association provided in an embodiment of the present application;
[0163] Figure 26 is a seventh schematic diagram of the application scenario provided by an embodiment of the present application. DETAILED DESCRIPTION
[0164] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application. In the description of the embodiments of the present application, unless otherwise specified, " / " means or, for example, A / B can mean A or B; "and / or" in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships, for example, A and / or B can mean: A, B, and AB. In addition, in the description of the embodiments of the present application, "multiple" means two or more than two; "including" indicates the existence of the described features, wholes, steps, operations, elements and / or components, but does not exclude the existence or addition of one or more other features, wholes, steps, operations, elements, components and / or their collections; "first", "second", "third", etc. are only used to distinguish the description and cannot be understood as indicating or implying relative importance.
[0165] Before describing the embodiments of the present application, the relevant terms involved in the embodiments of the present application are first introduced.
[0166] Identity authentication, also known as "verification" or "authorization," refers to the process of verifying a user's identity through certain means. Authentication is the process of verifying the identity of the person accessing the system, confirming that the accessing person is who they claim to be. For example, if an unknown user, X, claims to be A, X is compared with the identity credentials of A in the database. If the system's predefined conditions are met, authentication is successful; otherwise, it fails. Current identity authentication methods typically include knowledge-based authentication, ownership-based authentication, and feature-based authentication.
[0167] Identity credentials: refers to private or public data declared to prove the authenticity of a user's identity. Different identity authentication methods correspond to different types of identity credentials. For example, knowledge-based authentication involves identity authentication based on what the user knows, and the corresponding identity credentials can be static passwords, pre-shared keys, public-private key pairs, digital certificates, etc. Another example is ownership-based authentication, which involves identity authentication based on what the user possesses, and the corresponding identity credentials can be smart cards, dynamic token cards (such as random verification codes sent via SMS), etc. Another example is feature-based authentication, which involves identity authentication based on the user's own biometrics, which are further divided into physiological biometrics and behavioral biometrics. For authentication based on physiological biometrics, the corresponding identity credentials can be face, fingerprint, palm print, gait, voiceprint, iris, etc.; for authentication based on behavioral biometrics, the corresponding identity credentials can be keyboard input, handwritten signature, etc.
[0168] Authorization token (or auth-token): A token issued within the device's secure environment after a user's identity is successfully authenticated. This token serves as a user authentication credential and is used for system access control.
[0169] Authentication trust level (ATL): Also known as the "authentication security level," this indicates the degree of confidence in a user's authentication results. This level depends on the accuracy of the authentication algorithm and the security level of the authentication system. The higher the confidence in the user's authentication result, the higher the corresponding ATL.
[0170] Generally, identity authentication is the first step in access control. For example, as shown in (a) in Figure 1, a lock screen function can be set on a smartphone and requires the user to enter at least one data such as a password, fingerprint, or face to unlock the phone. Users who have the right to use a smartphone, such as the smartphone owner, can register their own identity credentials on the smartphone, such as entering their own fingerprint, face, and setting a password they know, to ensure that they can unlock the phone. These identity credentials registered by the user can be saved in the smartphone's identity authentication system, which is used to implement the smartphone's identity authentication function.
[0171] As shown in Figure 1 (b), when the smartphone is in the locked screen state and user 1 wishes to unlock the smartphone, the smartphone can authenticate user 1 through one or more authentication methods, such as password authentication, fingerprint authentication, or facial authentication. Typically, the authentication method verifies whether user 1 is a user with access rights to the smartphone. For example, if fingerprint authentication is used to authenticate user 1, the fingerprint currently input by user 1 is compared with the fingerprints of users with access rights to the smartphone in a database. If the system's predefined conditions are met, user 1's identity authentication is successful, confirming that user 1 is a user with access rights to the smartphone. The smartphone can then be unlocked.
[0172] As users acquire more and more electronic devices, they often register different types of identity credentials on multiple devices. As shown in Figure 2, users register multiple identity credentials, such as fingerprints, facial recognition, and passwords, on their smartphones; register their passwords (which can be the same or different from the password registered on their smartphones) and photoplethysmography (PPG) or electrocardiogram signals on their smartwatches; and register their voiceprint, a single identity credential, on smart speakers.
[0173] These identity credentials scattered across various electronic devices are not related in any way and are primarily used for local device user authentication. This means that local device user authentication is achieved by utilizing the identity credentials registered on the local device. For example, when the owner returns home and controls the smart door lock to open the door by entering a password, face recognition, or other information, the smart door lock can use the owner's registered password, face recognition, and other identity credentials to perform user authentication and, upon successful authentication, unlock the door.
[0174] With the continuous development of IoT and terminal technologies, these electronic devices of different types and functions generally have communication capabilities, capable of communicating with one or more other electronic devices through one or more communication protocols to achieve one or more types of data interaction, such as the transmission of multimedia files, application data, and user data. For example, when it is necessary to perform an operation requiring identity authentication, such as payment or unlocking, on electronic device A, cross-device identity authentication can be performed through electronic device B, thereby enabling cross-device payment and unlocking.
[0175] For example, as shown in Figure 3, if a visitor rings the doorbell and the owner is not near the smart door lock, the smart door lock can send a door opening request to the owner's electronic device, such as a smartphone. In response to the door opening request, the smartphone displays a pop-up window prompting the user to open the door for the visitor. When the owner decides to open the door, the smartphone can use the fingerprint, face, and other identity credentials registered on the smartphone to authenticate the user. After the authentication is successful, the smartphone can send the door opening command to the smart door lock. After verifying that the door opening command comes from a trusted smartphone, the smart door lock can execute the door opening command, thus achieving cross-device unlocking.
[0176] It can be seen that this method is based on the trust relationship between devices to achieve cross-device recognition of identity authentication results. In other words, the identity authentication results of the user on the smartphone can be recognized and acknowledged on the smart door lock. In essence, this is achieved through the trust relationship established between the smart door lock and the smartphone. This trust relationship can be established through device certificates, code scanning, touch and other methods. It can be used to establish a secure connection between mutually trusted electronic devices in the future, ensuring the reliability of the interaction, that is, the interaction information cannot be stolen or tampered with.
[0177] However, this method is less secure, as it reduces the trust root for opening the door with a smart door lock from one based on highly secure identity credentials authentication to one based on a trusted relationship between two electronic devices. This means that as long as the user authorizes the two electronic devices to establish a trusted relationship, the smart door lock will execute the door-opening command sent by the smartphone, regardless of whether the user is authenticated or not. As shown in Figure 4, once a smartphone is compromised, such as if a malicious application exists on the smartphone, it is likely to automatically control the smartphone to send a door-opening command to the smart door lock without the owner's knowledge, allowing others to break in illegally. Furthermore, the application scenarios of this method are relatively limited. Public devices such as smart TVs that serve multiple users are not suitable for cross-device authentication as trusted devices, because multiple users' identity credentials may be registered on public devices. It is possible that the public device may request certain operations from user A's private device based on user B's identity authentication results. Therefore, cross-device authentication can only be performed using private devices such as smartphones.
[0178] Therefore, to solve the problem of how a user's identity authentication result on one device can be recognized on another device, an embodiment of the present application provides an identity credential association method that can associate the identity credentials of the same user on different electronic devices through user authorization. Thus, among the associated identity credentials, the identity authentication result corresponding to any identity credential can be recognized by the electronic devices where the other associated identity credentials are located. This solves the problem of user identity authentication results being recognized across different electronic devices.
[0179] The identity credential association method provided in the embodiments of the present application can be applied to electronic devices such as tablet computers (hereinafter referred to as tablets), smart phones, smart home devices (such as smart speakers, smart TVs, smart door locks), wearable devices (such as smart watches and smart bracelets), vehicle-mounted devices, augmented reality (AR) / virtual reality (VR) devices, laptops, ultra-mobile personal computers (UMPCs), netbooks, personal digital assistants (PDAs), etc. The embodiments of the present application do not limit the specific types of electronic devices.
[0180] For example, Figure 5 shows a schematic diagram of the structure of an electronic device. As shown in Figure 5, the electronic device 100 may include a processor 110, a memory 120, an antenna, a communication module 130, an audio module 140, a sensor module 150, a camera 160, and a display 170. The sensor module 150 may include a fingerprint sensor, a touch sensor, a pressure sensor, a distance sensor, etc., and may also include other sensors such as a gyroscope sensor, an acceleration sensor, and a proximity light sensor. The embodiments of this application do not limit the type and number of sensors included in the electronic device.
[0181] It should be understood that the structures illustrated in the embodiments of this application do not constitute a specific limitation on the electronic device 100. In other embodiments, the electronic device 100 may include more or fewer components than shown, or may combine or separate certain components, or arrange the components differently. The illustrated components may be implemented in hardware, software, or a combination of software and hardware. For example, the electronic device 100 may also include a charging management module, a battery, and the like.
[0182] Processor 110 may include one or more processing units. For example, processor 110 may include an application processor (AP), a graphics processing unit (GPU), an image signal processor (ISP), a controller, memory, a video codec, a digital signal processor (DSP), etc. The different processing units may be independent devices or integrated into one or more processors. Processor 110 can run multiple tasks (e.g., applications) simultaneously to provide users with a variety of services and functions.
[0183] The controller may be the nerve center and command center of the electronic device 100. The controller may generate an operation control signal according to the instruction operation code and the timing signal to complete the control of fetching and executing instructions.
[0184] Processor 110 may also include a memory for storing instructions and data. In some embodiments, the memory in processor 110 is a cache memory. This memory can store instructions or data that have just been used or are being recycled by processor 110. If processor 110 needs to use the same instruction or data again, it can directly retrieve it from the memory. This avoids duplicate accesses, reduces processor 110 latency, and thus improves system efficiency.
[0185] In some embodiments, the processor 110 may include one or more interfaces, such as a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, etc. The processor 110 may be connected to other components via one or more of these interfaces.
[0186] The memory 120 can be used to implement the data storage function of the electronic device 100. For example, files such as music and videos are stored in the memory 120. The memory 120 can also be used to store computer executable program codes, and the executable program codes include instructions. The processor 110 executes various functional applications and data processing of the electronic device 100 by running the instructions stored in the memory 120. The memory 120 may include a program storage area and a data storage area. Among them, the program storage area may store an operating system, an application required for at least one function (such as an unlocking function, a payment function, etc.), etc. The data storage area may store data created during the use of the electronic device 100 (such as user registered identity credentials, associated identity credentials, etc.), etc. In addition, the memory 120 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), etc.
[0187] The communication module 130 and the antenna are used to implement the wireless communication function of the electronic device 100. The communication module 130 can provide solutions for wireless communications such as 2G / 3G / 4G / 5G applied to the electronic device 100, and can also provide solutions for wireless communications such as wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared technology (IR), etc. applied to the electronic device 100.
[0188] In an embodiment of the present application, the electronic device 100 can establish a communication connection with at least one electronic device via the communication module 130. After the connection is established, the electronic device 100 can receive first information from the at least one electronic device, where the first information includes an association request for n identity credentials on the at least one electronic device, requesting the establishment of an association with m identity credentials on the electronic device 100, where n and m are positive integers. The electronic device 100 can also send second information to the at least one electronic device via the communication module 130, where the second information includes information about establishing an association between the n identity credentials and the m identity credentials.
[0189] The audio module 140 can implement audio functions of the electronic device 100, such as recording, music playback, etc. Among them, the audio module 140 can be used to convert digital audio information into analog audio signal output, and also to convert analog audio input into digital audio signals. The audio module 140 can also be used to encode and decode audio signals. In some embodiments, the audio module 140 can be provided in the processor 110, or some functional modules of the audio module 140 can be provided in the processor 110.
[0190] The audio module 140 may include a microphone, a speaker, a receiver, a headphone jack, and the like. The microphone, also known as a "microphone," is used to convert sound signals into electrical signals. When waking up the electronic device 100 or sending a voice message, the user can speak close to the microphone to input the sound signal. The electronic device 100 may be equipped with one or more microphones. In this embodiment of the present application, the microphone can be used to collect voiceprints.
[0191] The fingerprint sensor is used to collect fingerprints. The electronic device 100 can use the collected fingerprint characteristics to implement fingerprint unlocking, access application locks, fingerprint payment, fingerprint photography, fingerprint call answering, and other functions involving fingerprint authentication.
[0192] A touch sensor, also known as a "touch panel," can be provided on the display screen 170. The touch sensor and the display screen 170 form a touch screen, also known as a "touch screen." The touch sensor is used to detect touch operations applied thereto or in the vicinity thereof. The touch sensor can transmit the detected touch operations to an application processor to determine the type of touch event. Visual output related to the touch operations can be provided via the display screen 170. In other embodiments, the touch sensor can also be provided on the surface of the electronic device 100, at a location different from that of the display screen 170.
[0193] The pressure sensor is used to sense pressure signals and convert them into electrical signals. In some embodiments, the pressure sensor can be provided on the display screen 170. There are many types of pressure sensors, such as resistive pressure sensors, inductive pressure sensors, and capacitive pressure sensors. When a touch operation is performed on the display screen 170, the electronic device 100 detects the intensity of the touch operation based on the pressure sensor. The electronic device 100 can also calculate the location of the touch based on the detection signal from the pressure sensor. The distance sensor is used to measure distance. The electronic device 100 can measure distance using infrared or laser.
[0194] The electronic device 100 can implement a shooting function through an ISP, a camera 160, a GPU, a display screen 170, and an application processor. The ISP is used to process data fed back by the camera 160. In some embodiments, the ISP can be set in the camera 160.
[0195] The camera 160 is used to capture still images or videos. The object generates an optical image through the lens and projects it onto the photosensitive element. The photosensitive element converts the optical signal into an electrical signal, which is then transmitted to the ISP for conversion into a digital image signal. The ISP outputs the digital image signal to the DSP for processing. The DSP converts the digital image signal into an image signal in a standard RGB, YUV, or other format. In some embodiments, the electronic device 100 may include one or N cameras 160, where N is a positive integer greater than one. In the embodiment of the present application, the camera 160 may be used to capture a human face.
[0196] Electronic device 100 can implement display functions using a GPU, display screen 170, and an application processor. A GPU is a microprocessor for image processing that connects display screen 170 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. Processor 110 may include one or more GPUs that execute program instructions to generate or modify display information.
[0197] The display screen 170 is used to display images, videos, etc. The display screen 170 includes a display panel. The display panel can be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode or an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), Miniled, MicroLed, Micro-oLed, a quantum dot light-emitting diode (QLED), etc. In some embodiments, the electronic device 100 may include 1 or N display screens 170, where N is a positive integer greater than 1. In an embodiment of the present application, the display screen 170 can be used to display a pop-up window, which includes request information for requesting to establish an association between at least two identity credentials.
[0198] The software system of the electronic device 100 can adopt a layered architecture, an event-driven architecture, a micro-core architecture, a micro-service architecture, or a cloud architecture. Taking the system as an example, the software structure of the electronic device 100 is exemplarily described.
[0199] Figure 6 is a software structure diagram of the electronic device 100 according to an embodiment of the present application. The layered architecture divides the software into several layers, each with clear roles and division of labor. The layers communicate with each other through software interfaces. In some embodiments, the Android system is divided into four layers, namely, the application layer, the application framework layer, the Android runtime (Android runtime) and the system library, and the kernel layer, from top to bottom. The application layer may include a series of application packages.
[0200] As shown in Figure 6, the application package may include applications such as Gallery, Bluetooth, Music, Video, Wallet, Short Message, and Settings. For ease of description, the application is referred to as "application" below. The application on the electronic device can be a native application or a third-party application, which is not limited in this embodiment of the application.
[0201] The application framework layer provides an application programming interface (API) and programming framework for applications in the application layer. The application framework layer includes some predefined functions.
[0202] As shown in FIG6 , the application framework layer may include an identity authentication framework, which includes a credential management module and an identity authentication module.
[0203] The credential management module includes a local credential management unit and an associated credential management unit. The local credential management unit is used to manage the identity credentials of at least one user registered on the electronic device 100. In addition to basic credential information such as credential identifier, credential type, and user identifier to which the credential belongs, the identity credentials managed by the local credential management unit may also include specific credential features, such as fingerprint features and facial features.
[0204] The associated credential management unit is used to manage association information between identity credentials. In some embodiments, when electronic device 100 establishes a network with at least one electronic device through methods such as scanning a code or tapping, the associated credential management unit can also be used to manage association information between identity credentials on electronic devices in the network. This information may include association information associated with the identity credentials on electronic device 100, as well as association information associated with other identity credentials perceived by other electronic devices in the network.
[0205] In some embodiments, the associated credential management unit can also be used to broadcast the credential information of the identity credentials on the electronic device 100 to other electronic devices in the network, as well as manage basic credential information such as the credential identifier, credential type, and user identifier of the identity credentials on other electronic devices in the network, which does not include specific credential characteristics.
[0206] The identity authentication module may include an authentication resource scheduling unit and a token issuance / verification unit. The authentication resource scheduling unit is used to call relevant identity credentials for identity authentication. The token issuance / verification unit is used to issue an authentication pass credential, i.e., an authorization token (auth-token), using an issuance key within the device's secure environment after successful identity authentication.
[0207] In the embodiment of the present application, the information carried in the identity authentication credential, i.e., the authorization token, may include not only the authentication user ID, the authentication method used for authentication, a timestamp, and the integrity protection signature of the authorization token, but also the credential information of the identity credential used for authentication. The credential information of the identity credential used for authentication may include the credential identifier of the identity credential, the device identifier of the electronic device to which the identity credential belongs, and the associated information of the identity credential.
[0208] In the embodiment of the present application, the token issuance / verification unit is also used to verify the identity authentication certificate, i.e., the authorization token, after receiving the identity authentication certificate of another device. The verification of the authorization token may include verifying the integrity of the authorization token and verifying whether the identity credentials used for authentication in the authorization token are associated with the target identity credentials locally registered by the electronic device 100.
[0209] It is understood that the association information between identity credentials managed by the newly added associated credential management unit of this solution can be used to support the identity authentication module. On the one hand, it provides the identity authentication module with the identity credential registration status of the user to be authenticated on various electronic devices within the network when deciding the authentication method. On the other hand, the token issuance / verification unit provides a query function to determine whether the identity credential is associated with the target identity credential registered locally on the electronic device 100.
[0210] In some embodiments, the application framework layer may further include other service frameworks, such as an input manager service (IMS), a view system, a resource manager, a notification manager, etc. This application does not limit the service functions included in the application framework layer.
[0211] The system library can include multiple functional modules, such as the surface manager and media libraries. The surface manager manages the display subsystem and provides fusion of 2D and 3D layers for multiple applications. The media library supports playback and recording of various common audio and video formats, as well as static image files.
[0212] The kernel layer is the layer between hardware and software. It includes display drivers, input / output device drivers (for example, keyboards, touch screens, headphones, speakers, microphones, etc.), device nodes, camera drivers, audio drivers, and sensor drivers. Users perform input operations through input devices, and the kernel layer generates corresponding raw input events based on these input operations and stores them in device nodes.
[0213] It should be understood that the components included in the software structure shown in Figure 6 do not constitute a specific limitation on the electronic device 100. In other embodiments, the electronic device 100 may include more or fewer components than shown, or combine or split some components, or arrange the components differently.
[0214] Based on the hardware structure, software system and related concepts described above, the application scenarios of the identity credential association method provided in the embodiment of the present application are introduced below with reference to the accompanying drawings.
[0215] Please refer to Figure 7, which shows a schematic diagram of the architecture of a communication system provided in an embodiment of the present application. The communication system 700 includes multiple electronic devices, such as a first device 710 and a second device 720. The hardware structure and software system of the electronic devices can refer to the hardware structure and software system of the electronic device 100 in Figure 6.
[0216] Optionally, multiple electronic devices may form one or more networks, each of which includes at least two electronic devices, and any two electronic devices in the network may communicate with each other. For example, the first device 710 and the second device 720 may form a network. The communication methods may be various, for example, communicating via a connection or using future communication technologies to transmit data. The connection methods may include a variety of different connection methods, such as wired or wireless connections. Furthermore, the connection may refer to a direct connection or an indirect connection. For example, the first device 710 and the second device 720 may be connected via a USB data cable; the wireless connection between the first device 710 and the second device 720 may be through establishing a Wi-Fi connection, a proximity connection for near-field communication, a Bluetooth code scanning connection, or the like; the first device 710 and the second device 720 may be connected via an intermediate node (e.g., a switch). The first device 710 and the second device 720 may also use future communication technologies, for example, by installing different or the same applications on the first device 710 and the second device 720, and transmitting data via a 5G communication network. The embodiments of the present application do not limit the connection method or communication method between any two electronic devices.
[0217] Optionally, multiple electronic devices in the network may have a mutual trust relationship and may share all or part of the application data. For example, the first device 710 and the second device 720 may establish a trust relationship through device certificates, code scanning, or a touch. The data that can be shared between any two electronic devices in the network may be determined based on a pre-set setting, or may be determined based on negotiation between the two electronic devices, or may be determined by other available methods, and this is not specifically limited in the embodiments of the present application.
[0218] In the embodiments of the present application, data that can be shared between any two electronic devices in a network can be data that does not involve identity authentication, that is, data that does not require user authorization. When any two electronic devices in a network need to share data that requires identity authentication, such as private data such as images and files, data sharing can be achieved after identity authentication is passed.
[0219] Optionally, multiple electronic devices can use any one or more of the following methods to form a network: all electronic devices logged in with the same account (such as a Huawei account) constitute a network; all electronic devices in the super terminal system constitute a network; electronic devices that establish connections through touch, code scanning, etc. constitute a network; all electronic devices in the same local area network constitute a network.
[0220] Among them, the super terminal system (or super terminal) refers to the integration of the capabilities of multiple electronic devices through distributed technology, storing them in a virtual hardware resource pool, and uniformly managing, scheduling, and integrating the capabilities of each electronic device according to business needs to provide external services, enabling fast connection, mutual assistance, and resource sharing between different electronic devices. For example, a mobile phone and a laptop computer form a super terminal, which can realize the screen projection function of the mobile phone interface to the laptop computer; a mobile phone and a smart speaker form a super terminal, which can realize the function of remote control of the smart speaker by the mobile phone, etc.
[0221] It can be understood that the super terminal is only an exemplary term and can be replaced by other terms, such as smart collaboration, multi-device collaboration, smart interconnection, etc., and the embodiments of this application are not limited thereto.
[0222] It should be noted that, in addition to the above-mentioned method, the embodiment of the present application may also adopt other methods to form a network, and the embodiment of the present application does not make specific limitations on this.
[0223] In the embodiments of the present application, within a network, a user's multiple identity credentials can be distributed across one or more different electronic devices. These electronic devices can be the user's private devices, such as mobile phones and tablets, or public devices serving multiple users, such as smart TVs. Of course, in some embodiments, these electronic devices can also be private devices of other users, such as friends and family.
[0224] For example, in a distributed networking scenario using hyperterminals, see Figure 8 . User A's tablet, user A's smartphone, user A's smartwatch, and a public device such as a smart TV at home can constitute hyperterminal A, while the public device smart TV and user B's smartphone can constitute hyperterminal B. The smart TV is a public device that can be used by multiple users, such as user A and user B.
[0225] As shown in Figure 8, user A can register their identity credentials, such as password 111 and face 111, on their smartphone; they can also register their identity credentials, such as password 112 and face 112, on their tablet; they can also register their identity credentials, such as password 113 and PPG, on their smartwatch; and they can also register their identity credentials, such as face 113, on a public device, such as a smart TV at home. Similarly, user B can also register their identity credentials, such as password 114 and face 114, on their smartphone; and they can also register their identity credentials, such as password 115 and face 115, on a public device, such as a smart TV at home. It can be seen that multiple users' identity credentials can be registered on a public device, such as a smart TV at home.
[0226] In an embodiment of the present application, multiple identity credentials of the same user or the same account on different electronic devices can be associated, so that the associated multiple identity credentials belong to the same user or the same account. The associated multiple identity credentials can be different types of identity credentials or the same type of identity credentials. The same type of identity credentials can be the same (such as password 111 and password 112 are the same number combination 111111) or different (such as face 111 and face 112 are facial images captured at different times).
[0227] In an embodiment of the present application, a user can choose to associate his or her identity credentials on a certain electronic device with the identity credentials on another electronic device. Taking the identity credential face 113 of user A on a public device such as a smart TV at home as an example, user A can choose to associate the face 113 on the smart TV with the identity credential password 111 and face 111 on his or her smartphone, or can choose to associate the face 113 on the smart TV with the identity credential password 112 and face 112 on his or her tablet. At this time, the smart TV at home can log in to the account of user A or the account of user B. That is, the identity credential association method of the embodiment of the present application is not affected by the user account actually logged in on the current public device. Even if the account of user B is logged in on the current public device such as the smart TV at home, user A can choose to associate the face 113 on the smart TV with the identity credential password 111 and face 111 on his or her smartphone.
[0228] In some embodiments, when user A's identity credentials, password 111, and face 111 on their smartphone have been successfully associated with identity credentials, password 112, and face 112 on their tablet, and the user chooses to associate face 113 on the smart TV with the identity credentials, password 111, and face 111 on their smartphone, face 113 on the smart TV can also be associated with identity credentials, password 112, and face 112 on their tablet. That is, face 113 is successfully associated with password 111, face 1, password 112, and face 112. It can be seen that the associated identity credentials, face 113, password 111, face 111, password 112, and face 112, all belong to user A, and these associated identity credentials are of different types.
[0229] In some embodiments, a group may be created to add the associated identity credentials to the group, which may be referred to as a credential group. One credential group corresponds to one user, and the identity credentials in the credential group belong to the same user.
[0230] For example, a credential group A may be created corresponding to user A. Thus, face 113, password 111, face 111, password 112, and face 112 associated with user A's identity credential may be added to credential group A.
[0231] For another example, a credential group B may be created corresponding to user B. Thus, password 114, face 114, password 115, and face 115 associated with the identity credential of user B may be added to credential group B.
[0232] In some scenarios, when the password 111 and face 111 on user A's smartphone are added to credential group A, user A can also view all identity credentials in credential group A on their smartphone. For example, the smartphone can display a credential display interface as shown in FIG9 , which displays all identity credentials in credential group A. Optionally, the interface can also identify the electronic device to which each identity credential belongs.
[0233] The following is a detailed introduction to the identity credential association method provided in the embodiment of the present application in conjunction with the accompanying drawings.
[0234] The identity credential association method provided in the embodiment of the present application can be jointly executed by any two electronic devices in the above-mentioned communication system, wherein one electronic device can be referred to as an association initiating device that initiates an association request for the identity credential, and the other electronic device can be referred to as an association authorization device that authorizes the identity credential to be associated. Here, the identity credential association method provided in the embodiment of the present application is introduced by taking the second device in the above-mentioned communication system as the association initiating device and the first device as the association authorization device as an example.
[0235] Please refer to Figure 10, which shows a flow chart of a method for associating identity credentials provided by an embodiment of the present application. The method includes:
[0236] S1000. The second device sends first information to the first device, where the first information is used to request that n identity credentials of the second user on the second device be associated with m identity credentials of the first user on the first device, where n and m are positive integers.
[0237] In the embodiments of the present application, multiple identity credentials on a first device and a second device can be associated with each other with user authorization, ensuring that the authentication result corresponding to any of the multiple associated identity credentials is trusted by the electronic devices where the other associated identity credentials are located. This solves the problem of user authentication results being recognized across different electronic devices.
[0238] It should be noted that the first user and the second user may be the same natural person user or different natural person users. In the embodiment of the present application, if multiple identity credentials on the first device and the second device are successfully associated, then these associated multiple identity credentials can be regarded by the first device or the second device as coming from the same user for the association management of multiple identity credentials. The identity authentication result corresponding to any one of the associated multiple identity credentials can be regarded by the first device or the second device as the identity authentication result of the same user.
[0239] That is to say, the identity credentials of the same user registered on the first device and the second device respectively can be associated to ensure that the associated identity credentials belong to the identity credentials of the same user. Of course, in some scenarios, with the user's authorization, multiple identity credentials of different users (such as a husband and wife) can also be associated. Optionally, if the multiple identity credentials of the husband and wife are successfully associated, these associated multiple identity credentials will be regarded by the first device or the second device as coming from the same user, such as from the wife or from the husband, and the identity authentication result corresponding to any one of the associated multiple identity credentials can be regarded by the first device or the second device as the identity authentication result of the wife or the husband.
[0240] In an embodiment of the present application, when it is necessary to associate the identity credentials on the second device with the identity credentials on the first device, the second device may send a first message to the first device, wherein the first message is used to request that the identity credentials registered on the second device be associated with the identity credentials registered on the first device.
[0241] Optionally, the first information may include basic credential information of the identity credential to be associated, wherein the basic credential information may include at least one of the following information: a credential identifier of the identity credential, a device identifier of a device to which the identity credential belongs, a credential type of the identity credential, an authentication security level (ATL) supported by the identity credential, etc.
[0242] Among them, the credential identifier can be the credential name, credential identity document (ID), etc.; the device identifier can be the device name, device ID, device address (such as Internet Protocol (IP) address), etc., and the credential type can be fingerprint, face, password, passcode, voiceprint, handwritten signature, public-private key pair, etc. The authentication security level ATL can be divided into the first level, second level, third level, etc. according to the security and credibility from low to high.
[0243] The second device can establish a communication connection with the first device, so that the second device can send the first information to the first device through the communication connection. The communication connection can be a local area network connection, a Bluetooth connection, a Wi-Fi direct connection, etc. This application does not limit the communication connection method between the second device and the first device. Optionally, the second device can send each piece of information in the first information directly, concatenate and send it, or encrypt it and send it to the first device.
[0244] Optionally, x user identity credentials are registered on the first device, where x is a positive integer. Each of the x users may have one or more identity credentials registered on the first device. The multiple registered identity credentials may be different types of identity credentials, such as fingerprints, faces, etc., or may be the same type of identity credentials, such as the fingerprint of the left thumb and the fingerprint of the right thumb.
[0245] Optionally, the multiple identity credentials registered on the first device may be registered in the same scenario. For example, when setting the lock screen function of the first device, multiple identity credentials may be registered to ensure that the user can unlock the first device using the authentication method corresponding to any identity credential. Of course, the multiple identity credentials registered on the first device may also be registered separately in different scenarios.
[0246] Optionally, similar to the first device, the second device may also have y user identity credentials registered on it, where y is a positive integer. Each of the y users may have one or more identity credentials registered on the second device. The multiple registered identity credentials may be of different types or the same type. The multiple registered identity credentials may be registered simultaneously in a single scenario or separately in different scenarios.
[0247] The x users and the y users may be completely identical, completely identical, or partially identical.
[0248] The following describes a process of associating identity credentials on the first device and the second device by taking an example where x users include the first user and y users include the second user.
[0249] The first user has m identity credentials registered on the first device, and the m identity credentials may be all or part of the identity credentials registered by the first user on the first device. The second user has n identity credentials registered on the second device, and the n identity credentials may be all or part of the identity credentials registered by the second user on the second device.
[0250] In some embodiments, the second device may send a first message to the first device to request that the n identity credentials be associated with the m identity credentials. The first message includes credential information for the n identity credentials. Optionally, the first message may also include credential information for the m identity credentials.
[0251] The credential information of n identity credentials may include the credential identifiers of the n identity credentials, the device identifier of the device to which the n identity credentials belong, the credential type of the n identity credentials, the ATL supported by the n identity credentials, etc. The credential information of m identity credentials may include the credential identifiers of the m identity credentials, the device identifier of the device to which the m identity credentials belong, the credential type of the m identity credentials, the ATL supported by the m identity credentials, etc.
[0252] Optionally, when the n identity credentials are a single identity credential, that is, n=1, the first information can be used to request that an identity credential of the second user on the second device be associated with the m identity credentials, thereby implementing a solution of associating other identity credentials at the granularity of a single identity credential.
[0253] Optionally, when the n identity credentials are all the identity credentials registered by the second user on the second device, the first information can be used to request that all the identity credentials of the second user on the second device be associated with the aforementioned m identity credentials at once. This implements a user-based granularity solution, that is, all identity credentials under a user name on the second device are associated with other identity credentials.
[0254] In one scenario, the m identity credentials are already associated, and the first information can be used to request that the n identity credentials be added to the established association of the m identity credentials, thereby adding the identity credentials on the second device to the existing association.
[0255] As an implementation, the association can be embodied in the form of a group. This group can be referred to as a credential group, and already associated identity credentials can be added to this credential group. For example, there is a credential group 1, which includes m already associated identity credentials. The first information can be used to request that the n identity credentials be added to credential group 1, so as to be associated with the m identity credentials in credential group 1.
[0256] In one scenario, the m identity credentials may be unassociated identity credentials. The first information may be used to request the creation of an association between the n identity credentials and the m identity credentials, thereby creating an association between the identity credentials on the first device and the second device.
[0257] As an implementation method, when the association is embodied in the form of a group, the first information can be used to request the creation of a credential group 1, to which the n identity credentials and the m identity credentials can be added to realize the association between the n identity credentials and the m identity credentials.
[0258] Optionally, the first information may be autonomously sent by the second device, or may be sent after a user using the second device expresses an intention to associate credentials.
[0259] S1010. A first device receives first information sent by a second device.
[0260] Optionally, after the second device sends the first information, the first device may receive the first information sent by the second device through the communication connection between the first device and the second device.
[0261] Optionally, when the first information is encrypted information, when the first device receives the first information sent by the second device, it may also decrypt the information to obtain the decrypted first information.
[0262] In some embodiments, the first device and the second device have a mutual trust relationship, that is, the first device and the second device authenticate each other. Therefore, the first device and the second device can establish a secure and reliable communication connection based on the trust relationship between the devices for subsequent information interaction.
[0263] Optionally, the first device and the second device may exchange their respective device information based on the above-mentioned secure and reliable communication connection. The exchanged device information may include at least one of the following: device identification (such as device name, device ID, device address, etc.), device type, and device public key (PK). The device private key corresponding to the device public key does not need to be exchanged and can be saved on each device. The device public key and the device private key are a pair of public-private key pairs. The public key in the public-private key pair is used to encrypt plaintext or verify digital signatures, and the private key in the public-private key pair is used to decrypt ciphertext or create digital signatures.
[0264] Typically, the device public key and device private key can be used to implement integrity protection for one or more information exchanges between devices. In an embodiment of the present application, the device public key and device private key can be used to implement integrity protection for information exchanges related to identity credentials between devices.
[0265] As a method, the first message sent by the second device and received by the first device may include signature information. This signature information is a signature of the first message using the second device's device private key, such as "Private Key 2," to ensure the integrity of the first message and to ensure that the first message has not been tampered with. Since the first device can obtain the second device's device public key, such as "Public Key 2," through the aforementioned device information exchange, and "Public Key 2" and "Private Key 2" form a public-private key pair, the first device can verify the signature information in the first message using the second device's device public key, such as "Public Key 2," to determine whether the first message was sent by the second device and whether the content of the first message was tampered with during transmission.
[0266] The above-mentioned process of signing and verifying the signature using the public-private key pair can refer to the process in the relevant technology, and the embodiments of this application will not be described in detail.
[0267] S1020. The first device displays a first interface based on the first information, where the first interface is used to prompt the above request.
[0268] Since the first information is used to request to associate n identity credentials of the second user on the second device with m identity credentials of the first user on the first device, in this scenario the first device can first obtain the consent of the first user on the local device to associate its identity credentials with other identity credentials with the authorization of the first user.
[0269] In an embodiment of the present application, the first device may display a first interface based on the first information to prompt the first user that there are n identity credentials and request association with its own m identity credentials.
[0270] As an embodiment, the first interface may include association prompt content, an "Agree" button, and a "Reject" button, so that the user currently using the first device can determine whether to agree to the association request based on the association prompt content.
[0271] The association prompt content is determined based on the first information, such as "The second user's n identity credentials on the second device request to be associated with your m identity credentials on this device. Do you agree?" Optionally, the association prompt content may also include a statement of authorization content, a privacy statement, etc.
[0272] In one scenario, the first device is a private device of the first user, so the user currently using the first device is usually the first user. If the user currently using the first device clicks the "Agree" (or "Confirm") button, it means that the first user agrees to associate the above-mentioned n identity credentials with the m identity credentials, and then the first device and the second device can subsequently perform related association operations. If the user currently using the first device clicks the "Reject" (or "Cancel") button, it means that the first user does not agree to associate the above-mentioned n identity credentials with the m identity credentials, and then the first device and the second device cannot subsequently perform related association operations.
[0273] For example, assuming that the first device is user A's smartphone, registered with user A's password 111 and face 111, and the second device is user A's tablet, registered with user A's password 112 and face 112, as an example, as shown in (a) of Figure 11, the tablet can send a first message to the smartphone to request that user A's face 112 on the tablet be associated with user A's password 111 and face 111 on the smartphone. After receiving the first message, the smartphone can display a first interface, as shown in (b) of Figure 11, to prompt the user of the identity credential association request from the tablet. The first interface may also include association prompt content, an "Agree" button, and a "Reject" button. The smartphone can determine whether user A authorizes the association based on the user's operation on these two buttons by the current smartphone user.
[0274] Optionally, when the association is embodied in the form of a group, the above-mentioned association prompt content is the prompt content for joining the group, such as "n identity credentials of the second user on the second device request to join your credential group, do you agree?"
[0275] Optionally, the user may express their intention to associate credentials on the second device, in which case an interface similar to (b) in Figure 11 may not be presented on the first device. For example, a pop-up window may be displayed on the second device prompting whether to trigger the association of the n identity credentials with the m identity credentials. When the user confirms the triggering of the association by pressing the "Agree" button, the first device no longer needs to display an interface similar to (b) in Figure 11, and may directly present an interface similar to (d) in Figure 11.
[0276] As another embodiment, the first interface may include associated prompt content, an identity authentication area, and a "Reject" button. The identity authentication area may be used to prompt the user currently using the first device to perform identity authentication so that the first device can determine whether the user currently using the first device is the first user, and the first device can confirm whether the first user's consent has been obtained.
[0277] If the user currently using the first device performs identity authentication and the identity authentication is passed, it means that the user currently using the first device is the first user, and it is the first user himself who agrees to associate the above-mentioned n identity credentials with the m identity credentials. If the user currently using the first device refuses to perform identity authentication, it means that the user currently using the first device does not agree to associate the above-mentioned n identity credentials with the m identity credentials. If the user currently using the first device performs identity authentication but the identity authentication fails, for example, it may be because the user currently using the first device is not the first user, etc., resulting in the user not having the authority to agree to the above-mentioned association request. At this time, the first device can confirm that it has not obtained the consent of the first user himself, which is equivalent to the first user himself not agreeing to associate the above-mentioned n identity credentials with the m identity credentials.
[0278] For example, in the above example, after receiving the first information, the smartphone may display the first interface shown in (c) of FIG11 to prompt the user of the identity credential association request from the tablet. The first interface may include association prompt content, a password authentication area, and a "Reject" button. The password authentication area is used to verify whether the password entered by the user currently using the smartphone is the password 111 registered by user A on the smartphone. If so, the smartphone is verified to be the user A who registered password 111. At this point, the smartphone can confirm that user A has agreed to the identity credential association request from the tablet.
[0279] Optionally, the authentication method used by the identity authentication area may be determined based on the m identity credentials of the first user to be associated in the first information. For example, in the above example, since the identity credential association request from the tablet needs to be associated with user A's password 111 and face 111, the authentication method used by the identity authentication area may be the password authentication method corresponding to password 111 and / or the face authentication method corresponding to face 111.
[0280] Optionally, the authentication method used in the identity authentication area can also be determined based on the identity credentials registered by the first user on the first device. For example, in the above example, since the smartphone is user A's personal device, user A may also have registered other identity credentials on the smartphone in addition to face 111 and password 111, such as fingerprint 111 registered by the user in the smartphone's lock screen function. In this case, the authentication method used in the identity authentication area can also be the fingerprint authentication method corresponding to fingerprint 111.
[0281] In the embodiment of the present application, there is no limitation on the authentication method adopted in the identity authentication area, as long as the user currently using the first device can be authenticated as the first user himself.
[0282] Optionally, in addition to prompting the above request through a display interface, the first device may also prompt the above request through voice.
[0283] S1030: The first device detects an approval request operation.
[0284] The consent request operation is an operation performed when the user agrees to the credential association request.
[0285] As an embodiment, when the first interface includes an "Agree" button and a "Reject" button, such as the first interface shown in (b) of Figure 11, the consent request operation can be a touch operation performed by the user currently using the first device on the "Agree" button, such as a click operation. It can also be a specified gesture operation performed by the user currently using the first device on the first interface. When the user performs the specified gesture operation, it can be considered that the "Agree" button has been clicked. For example, drawing a "check √", drawing a "circle ○", knuckle tapping gesture, etc. The embodiment of the present application does not limit the consent request operation.
[0286] In one scenario, the first device is a private device of the first user, and therefore the user currently using the first device is typically the first user. When the first device detects a consent request operation, the first device may confirm that the first user agrees to the credential association request from the second device. In this case, the first device may respond to the detected consent request operation. If the consent request operation is responded to, the first device may return relevant association information to the second device.
[0287] Optionally, when the first device detects a rejection request operation, the first device may confirm that the user does not agree to the above-mentioned credential association request from the second device. The first device may not respond to the detected rejection request operation, or it may respond to the rejection request operation and return a rejection association instruction to the second device. The rejection request operation is the operation performed when the user rejects the above-mentioned credential association request. For example, the rejection request operation can be a touch operation performed on the "Reject" button by the user currently using the first device, such as a click operation. It can also be a specified gesture operation performed on the first interface by the user currently using the first device. When the user performs the specified gesture operation, it can be considered that the "Reject" button is clicked. Such as drawing a "cross", swiping left to return, etc. The embodiment of the present application does not limit the rejection request operation.
[0288] In some distributed scenarios, the first device can also entrust the second device to collect consent request operations. For example, the first device instructs the second device to display a pop-up window prompting whether to trigger the association of the above-mentioned n identity credentials with m identity credentials. In this way, the user can express the intention to associate credentials on the second device. The first device no longer needs to collect consent request operations and can directly respond to the user's consent request operation on the second device and return relevant association information to the second device. In this way, the user only needs to perform a series of operations on the second device to achieve credential association with the user's authorization.
[0289] In another scenario, since the user currently using the first device may not be the first user, the first device may also initiate identity authentication after detecting the consent request operation to verify whether the user currently using the first device is an authorized user, that is, a user with permission to authorize the association of the n credentials indicated by the first information. For example, whether the user is the first user. Another example is whether the user is a trusted user with whom the first user has established a trust relationship. Another example is whether the user is an authorized user who has granted the first user permission to associate the credentials.
[0290] As an exemplary scenario, it may be inconvenient for the elderly or children themselves to perform credential association authorization. In this case, the guardian of the elderly or children can be granted credential association authorization permission, so that the guardian has the authority to agree whether to associate the relevant identity credentials.
[0291] When identity authentication is used to verify whether the user currently using the first device is the first user, the authentication method for initiating identity authentication may be determined based on the m identity credentials of the first user to be associated in the first information, or may be determined based on the identity credentials registered by the first user on the first device. When identity authentication is used to verify whether the user currently using the first device is a trusted user or an authorized user, or other authorized user, the authentication method for initiating identity authentication may be determined based on the identity credentials registered by the trusted user or the authorized user, or other authorized user, on the first device.
[0292] Optionally, when identity authentication succeeds, the first device may confirm that the user is an authorized user, such as the first user himself, and agrees to the credential association request from the second device. In this case, the first device may respond to the detected consent request operation and return relevant association information to the second device.
[0293] Optionally, if identity authentication fails, the first device may confirm that the user currently using the first device does not have permission to agree to the credential association request from the second device. At this point, the first device may confirm that it has not obtained credential association authorization, for example, because the first user does not agree to the credential association request. Therefore, the first device may not respond to the detected consent request, or it may respond to the consent request by returning a rejection instruction to the second device.
[0294] Optionally, when the user cancels identity authentication, the first device may confirm that the user currently using the first device does not agree to the credential association request from the second device. At this time, the first device may not respond to the detected consent request operation, or it may respond to the consent request operation and return a rejection association instruction to the second device.
[0295] For example, in the first interface shown in FIG11(b), after the current smartphone user clicks the "Agree" button, the smartphone may display the face authentication interface shown in FIG11(d). Alternatively, a password authentication interface, fingerprint authentication interface, etc. may be displayed. The current smartphone user may then face the smartphone directly, allowing the smartphone to collect facial information and verify whether the collected facial information meets system-defined conditions, such as whether facial features are consistent, with the face 111 registered by user A on the smartphone. If so, facial authentication is successful, and the smartphone may respond to the current smartphone user's click of the "Agree" button. If not, facial authentication fails, and the smartphone may not respond to the current smartphone user's click of the "Agree" button, or may respond to the current smartphone user's click of the "Agree" button by returning a rejection instruction to the tablet.
[0296] In some scenarios, the first device can also delegate the collection of user-entered authentication information to a second device. For example, the first device can instruct the second device to display an interface prompting the user to enter authentication information. The user can then enter their authentication information on the second device. The first device then retrieves the user's authentication information from the second device and performs local authentication. This allows the user to perform only a series of operations on the second device to establish credential association with user authorization.
[0297] As another embodiment, when the first interface includes an identity authentication area and a "Reject" button, the consent request operation can be an operation in which the user currently using the first device performs identity authentication in the identity authentication area and passes the authentication. When the first device detects the consent request operation, the first device can confirm that the first user agrees to the credential association request from the second device. At this point, the first device can respond to the detected consent request operation. If the consent request operation is responded to, the relevant association information is returned to the second device.
[0298] Similarly, when the first device detects a rejection request, it can confirm that the user does not agree to the credential association request from the second device. Alternatively, when the first device detects that the user currently using the first device is performing identity authentication in the identity authentication area and fails the authentication, the first device can confirm that the user currently using the first device is not the first user and does not have the authority to agree to the credential association request from the second device, which is equivalent to the first user not agreeing to the credential association request. In this case, the first device may not respond or may return a rejection instruction to the second device.
[0299] Optionally, when the first device prompts the above request through voice, if the first device receives a voice consent instruction issued by the user, it can directly perform voiceprint authentication on the voice confirmation instruction, and if the authentication is successful, it can be confirmed that the consent request operation has been detected.
[0300] S1040. In response to the consent request operation, the first device sends second information to the second device, where the second information includes association information between the n identity credentials and the m identity credentials.
[0301] In an embodiment of the present application, after obtaining the consent of the first user, the first device may associate n identity credentials with m identity credentials, and return the association information between the processed n identity credentials and the m identity credentials to the second device. Thus, the second device can subsequently recognize the identity authentication result corresponding to the associated n identity credentials and any one of the m identity credentials based on the association information. The first device can also recognize the identity authentication result corresponding to the associated n identity credentials and any one of the m identity credentials based on the association information. This facilitates the implementation of various business scenarios involving cross-device identity authentication, such as cross-device payment and cross-device unlocking.
[0302] Optionally, the first device associates n identity credentials with m identity credentials by marking the n identity credentials and the m identity credentials with the same association tag, i.e., association ID. The same association tag is used to identify that the n identity credentials and the m identity credentials come from the same user, i.e., belong to the same user.
[0303] Optionally, the association tag is globally unique and will not conflict with other association tags. At this point, from the perspective of the device side, one association tag can correspond to one user (such as a user ID such as a user account), and all identity credentials marked with the same association tag belong to the same user. It can be understood that in this case, for the identity credentials of the same user identified by the device side on different electronic devices, when an association is requested at any time and on any device, if the user agrees to authorize the association, the association tags marked on the identity credentials requested for association are the same, to ensure that the identity credentials of the same user are identified with one association tag. This makes it possible to uniformly associate the identity credentials of the user scattered on different electronic devices.
[0304] Alternatively, in more complex design scenarios, the association tag is globally unique within a certain range. For example, the association tag is globally unique within a local area network (LAN). Thus, when the same user identified by the device side associates identity credentials across multiple LANs, each user in each LAN may correspond to an association tag. In this case, when the same user identified by the device side has multiple association tags, these multiple association tags may have some interrelated identifiable logic, so that the identity credentials created by the same user across different devices and at different points in time can be associated based on this logic.
[0305] For example, the first user may correspond to association tag A-1 and association tag A-2, association tag A-1 is used to associate the identity credentials of the first user in the first local area network, and association tag A-2 is used to associate the identity credentials of the first user in the second local area network.
[0306] Optionally, the same user identified by the device side may also correspond to multiple association tags in a local area network. These multiple association tags can implement differentiated management such as private identity credential association and shared identity credential association. For example, in a local area network, the first user may correspond to association tag A-1 and association tag A-2. Association tag A-1 is used to uniformly associate the first user's identity credentials, such as the m identity credentials of the first user mentioned above. Association tag A-2 is used to associate the first user's identity credentials with the identity credentials of other users, such as the m identity credentials of the first user mentioned above with the n identity credentials of the second user.
[0307] It is understandable that, although one association tag corresponds to one user on the device side, in actual usage scenarios, there will be differences in how natural users use the function, resulting in one association tag possibly corresponding to more than one natural user. For example, for some public use devices, such as smart large screens, in order to more conveniently use the large screen through credential association, the large screen user group (such as a couple or a family) can use the method described in the embodiments of this application to establish an identity credential association that can be shared by this group.
[0308] In an embodiment of the present application, after obtaining the consent of the first user, the first device may send second information to the second device, where the second information includes association information between the n identity credentials and the m identity credentials.
[0309] Optionally, the association information may include at least one of the following: an association tag, a user identifier of the associated user, and credential information of the successfully associated identity credential, i.e., the successfully associated identity credential with the association tag. The credential information of the successfully associated identity credential may include basic credential information such as the credential identifier, credential type, and supported ATL, but does not include the entered credential template information. The credential template information may be the original information or credential features collected by the device during identity credential entry. For example, the credential template information for a face may be the facial image or facial features collected by the device during face entry.
[0310] The user identifier may be a user ID used to identify the user. The credential information of the successfully associated identity credentials may include credential information of n successfully associated identity credentials on the second device. Optionally, the credential information of the successfully associated identity credentials may also include credential information of m successfully associated identity credentials on the first device, or credential information of successfully associated identity credentials on each device in the communication system.
[0311] For example, when m identity credentials on the first device have been associated with other identity credentials, the credential information of the successfully associated identity credentials returned by the first device to the second device may also include the credential information of all identity credentials in the association, that is, the credential information of m identity credentials + the credential information of n identity credentials + the credential information of other identity credentials.
[0312] Optionally, the first device may send the second information to the second device via the aforementioned communication connection with the second device, wherein the first device may send each piece of information in the second information directly, concatenate and send, or encrypt and send it to the second device.
[0313] As an implementation, the aforementioned tagging of the n identity credentials and the m identity credentials with the same association tag may involve creating a group to add the associated n identity credentials and the m identity credentials to the group, which may be referred to as a credential group. Optionally, the created credential group may be credential group 1 of the first user, which is used to include the identity credentials from the first user.
[0314] From the device's perspective, a credential group can correspond to a user (e.g., a user identifier such as a user account), and all identity credentials in the credential group belong to the same user. The association tag can be a group identifier of the credential group, which can be a group ID used to globally uniquely identify the credential group.
[0315] Similarly, although a credential group corresponds to one user on the device side, in actual usage scenarios, a credential group may correspond to more than one natural person user. For example, for a smart screen, a group of users (such as a couple or a family) can create a credential group that this group can share.
[0316] Optionally, the association information, i.e., credential group information, sent by the first device to the second device may include at least one of the following information: the group identifier of the credential group to be joined (such as credential group 1), the user identifier of the user to whom the credential group to be joined belongs (such as the first user ID belonging to credential group 1), and the credential information of the identity credentials that have successfully joined the credential group on the second device (such as the credential information of n identity credentials that have successfully joined credential group 1 on the second device).
[0317] In one scenario, when the m identity credentials on the first device are associated identity credentials, such as a credential group 1 of the first user has been created and the credential group 1 contains m identity credentials, the above-mentioned first device associates the n identity credentials with the m identity credentials, which can be to add the n identity credentials to the credential group 1 of the first user.
[0318] In another scenario, when the m identity credentials on the first device are unassociated identity credentials, the first device may associate the n identity credentials with the m identity credentials by creating a credential group belonging to the first user based on the user identifier of the first user, and then automatically adding the n identity credentials and the m identity credentials to the newly created credential group. For example, based on the first user's globally unique user ID, credential group 1 belonging to the first user is created, and the n identity credentials and the m identity credentials are automatically added to credential group 1.
[0319] Optionally, the association information sent by the first device to the second device may also include credential information of the identity credentials that have successfully joined the credential group on the first device (e.g., credential information of m identity credentials that have successfully joined credential group 1 on the first device). Optionally, the association information sent by the first device to the second device may include credential information of all identity credentials in the credential group (e.g., credential information of the identity credentials that have successfully joined credential group 1 on the first device + second device + other electronic devices). In this way, the second device can not only obtain information about the credential group to which the n identity credentials on its own device have joined, but also obtain information about other identity credentials in the joined credential group.
[0320] Optionally, after obtaining the first user's consent and associating the n identity credentials with the m identity credentials, the first device may also display a prompt pop-up window to indicate that the association is successful. The prompt pop-up window may also display the credential information of the successfully associated n identity credentials and the m identity credentials.
[0321] S1050. The second device receives the second information sent by the first device.
[0322] Optionally, after the first device sends the second information, the second device may receive the second information sent by the first device through the aforementioned communication connection between the second device and the first device.
[0323] Optionally, when the second information is encrypted information, when the second device receives the second information sent by the first device, it may also decrypt the second information to obtain the decrypted second information.
[0324] As one approach, the second information sent by the first device and received by the second device may include signature information. This signature information is a signature of the second information using the first device's device private key, such as "Private Key 1," to ensure the integrity of the second information and to ensure that the second information has not been tampered with. Since the second device can obtain the first device's device public key, such as "Public Key 1," through the aforementioned device information exchange, the second device can verify the signature information in the second information using the first device's device public key, such as "Public Key 1," to determine whether the second information was sent by the first device and whether the content of the second information was tampered with during transmission.
[0325] In an embodiment of the present application, after receiving the second message sent by the first device, the second device can save the association information contained in the second message. This allows the second device to subsequently associate with new identity credentials based on the already associated identity credentials, thereby expanding the number of associated identity credentials and thus associating all identity credentials of the same user. Alternatively, when the second device subsequently performs cross-identity authentication with the help of the first device, it can verify whether the identity authentication result on the first device is the identity authentication result in the associated identity credentials, so that the second device can determine whether to approve the identity authentication result of the first device.
[0326] For example, the second information received by the second device may include credential group information such as credential group 1, the first user ID belonging to credential group 1, and credential information of n identity credentials added to credential group 1. The second device may store this credential group information. Subsequently, the second device can recognize the identity authentication result corresponding to any identity credential in the credential group based on this credential group information. This facilitates various business scenarios involving cross-device identity authentication, such as cross-device payment and cross-device unlocking.
[0327] Optionally, after receiving the second information sent by the first device, the second device may also display a prompt pop-up window to indicate that the association is successful, as shown in (e) in Figure 11. The second device may also display the credential information of the successfully associated n identity credentials and m identity credentials in the prompt pop-up window. When the m identity credentials are identity credentials that have already been associated, such as when the credential group 1 of the first user has been created, the second device may also jump to the credential display interface of the credential group 1 to display the credential information that has been added to the credential group 1, such as the credential information of the n identity credentials and m identity credentials. As shown in (f) in Figure 11, the tablet can display the face 112 of user A on the successfully associated tablet and the password 111 and face 111 of user A on the smartphone.
[0328] The identity credential association method provided in the embodiments of the present application can, with user authorization, associate the user's identity credentials on different electronic devices. Thus, the identity authentication result corresponding to any associated identity credential can be recognized by the electronic devices where the other associated identity credentials are located. This solves the problem of user identity authentication results being recognized across different electronic devices.
[0329] In one scenario, the first device is a private device (such as a smart phone) with a registered user's identity credentials, and the second device is a public device (such as a smart TV) with a registered identity credentials of multiple users. By executing the identity credential association method provided in the embodiment of the present application, the identity credentials of the user on the private device and the public device can be associated with each other under the authorization of the user, so that among the associated identity credentials, even the identity authentication results corresponding to the identity credentials on the public device can be recognized by the private device where the other associated identity credentials are located. In this way, users can also use public devices for cross-identity authentication, which solves the problem of recognition of the identity authentication results on the public device on the private device and improves the diversity of application scenarios.
[0330] Of course, in another scenario, the first device and the second device may both be private devices. For example, the first device is a private device of user A, registered with the identity credentials of user A, while the second device is a private device of user B, registered with the identity credentials of user B. User A and user B may be the same user, that is, the first device and the second device are two private devices of the same user. By executing the identity credential association method provided in the embodiments of the present application, the identity credentials of the same user on different private devices can be associated with each other with the user's authorization.
[0331] In some scenarios, user A and user B may also be different users, such as a husband and wife. That is, the first device and the second device are private devices of different users. By executing the identity credential association method provided in the embodiment of the present application, the identity credentials of user A and user B on their respective private devices can be associated with each other under the authorization of the users. At this time, these multiple associated identity credentials will be regarded as coming from the same user by the private devices of user A and user B. Therefore, in the associated identity credentials, the identity authentication results corresponding to the identity credentials on the private device of any user of user A and user B can be recognized by the private devices where the other associated identity credentials are located. In this way, the problem of recognition of the identity authentication results of mutually trusted users between different private devices is solved, so that two mutually trusted users (or multiple users) can use each other's private devices and perform identity authentication.
[0332] Of course, in another scenario, the first device may be a public device and the second device may be a private device, or both the first device and the second device may be public devices. The embodiment of the present application does not limit the device types of the first device and the second device.
[0333] Of course, in some scenarios, the identity credential association method of the embodiment of the present application can also be implemented locally on the first device only, without the participation of the second device. For example, the user can also choose to associate his (m+1)th identity credential with the mth identity credential on the first device. The first device can also perform user authorization confirmation and, when confirming the user authorization, associate its (m+1)th identity credential with the mth identity credential.
[0334] In some embodiments, the communication system includes more electronic devices in addition to the first device and the second device, and these devices can form a network.
[0335] The identity credential association method provided in the embodiments of the present application can also be applied to a communication system with more than three devices. The following describes the identity credential association method provided in the embodiments of the present application, taking a communication system consisting of a first device, a second device, and a third device as an example. Of course, the communication system can also include other electronic devices.
[0336] Please refer to Figure 12, which shows a flow chart of another method for associating identity credentials provided by an embodiment of the present application. The method includes:
[0337] S1200: The first device detects a first association creation operation, and the third device detects a second association creation operation.
[0338] The first association creation operation and the second association creation operation are operations performed when a user chooses to create an identity credential association based on his / her registered identity credential. The created identity credential association can be used to associate the identity credentials of the same user on at least one electronic device.
[0339] In some embodiments, the created identity credential association is globally unique, and one identity credential association corresponds to one user, so as to facilitate unified management of related identity credentials of the same user.
[0340] Taking the example of a first user registering their identity credentials on a first device and a third user registering their identity credentials on a third device, the first association creation operation may be an operation performed when the first user selects to create an association with the identity credentials corresponding to the first user based on the m identity credentials registered on the first device. The second association creation operation may be an operation performed when the third user selects to create an association with the identity credentials corresponding to the third user based on the p identity credentials registered on the third device.
[0341] The m identity credentials and the p identity credentials may be newly registered identity credentials or previously registered identity credentials. The first user and the third user may be the same or different.
[0342] The following takes the first association creation operation as an example to introduce the content of S1200.
[0343] In one scenario, when a first user registers a new identity credential on a first device, the first user may choose to create an identity credential association to associate the first user's identity credential. It is understood that since the first user has just registered a new identity credential on the first device, the created identity credential association may associate the newly registered identity credential.
[0344] For example, as shown in Figure 13 (a), user A clicks the "+" control corresponding to the face authentication method in the login authentication management interface of an application displayed on the smartphone. In response to this click, the smartphone may display the face entry interface shown in Figure 13 (b). After user A successfully enters their facial information in this face entry interface, the smartphone may save user A's newly registered identity credential, such as face 111. At this time, the smartphone may display the login authentication management interface shown in Figure 13 (c), which may display user A's newly registered identity credential - face 111.
[0345] Optionally, after detecting that user A has registered a new identity credential, the smartphone can check whether a corresponding identity credential association for user A already exists. If no identity credential association exists for user A, the smart device can prompt user A to create a new identity credential association. For example, the smartphone can display a pop-up window as shown in (d) in Figure 13. This pop-up window prompts the user whether to create an identity credential association.
[0346] As one approach, the prompt pop-up window may include an association creation prompt, a "Yes" or "Agree" button, and a "No" or "Reject" button. If user A clicks the "Yes" or "Agree" button, indicating that the user chooses to create an association with their own identity credentials, the smart device detects the first association creation operation. Conversely, if user A clicks the "No" or "Reject" button, indicating that the user does not choose to create an association with their own identity credentials, the smart device does not detect the first association creation operation. In this case, the smart device can close the prompt pop-up window.
[0347] Optionally, when the first user registers multiple new identity credentials on the first device at the same time, the first user may also choose to create an association. The created association may associate the multiple newly registered identity credentials.
[0348] In another scenario, if the first user has previously registered identity credentials on the first device and no identity credential association exists for the first user, the first user can select at least one identity credential from the previously registered identity credentials to create an identity credential association. In this case, the created identity credential association can associate the at least one identity credential selected by the first user.
[0349] In other embodiments, the created identity credential association can correspond to multiple users, facilitating unified management of the related identity credentials of multiple users. For example, when a first user creates an identity credential association based on m identity credentials registered by the first user on a first device, the created identity credential association can correspond to the first user. If the identity credential association includes the identity credentials of other users, the identity credential association can also correspond to the other users.
[0350] S1210. The first device creates a first association in response to the first association creation operation, and the third device creates a second association in response to the second association creation operation, wherein the first association is used to associate m identity credentials of the first user on the first device, and the second association is used to associate p identity credentials of the third user on the third device.
[0351] In an embodiment of the present application, on a first device, when a first user chooses to create an identity credential association corresponding to the first user based on the m identity credentials registered on the first device, the first device may create a first association to associate the m identity credentials of the first user on the first device. The first association corresponds to the first user, i.e., belongs to the first user and is responsible for unified management of the first user's identity credentials.
[0352] Similarly, the third device can create a second association to associate the p identity credentials of the third user on the third device. The second association corresponds to the third user, that is, belongs to the third user and is responsible for unified management of the identity credentials of the third user.
[0353] Optionally, when the first device creates a first association, it may create an association tag, i.e., an association ID, corresponding to the first user, and tag all identity credentials added to the first association with this association tag. When the third device creates a second association, it may create an association tag corresponding to the third user and tag all identity credentials added to the second association with this association tag. In this way, multiple identity credentials with the same association tag are considered by the device to originate from, and therefore belong to, the same user.
[0354] As an implementation, the first device creates a first association, which may be to create a credential group 1 for the first user and add the first user's m identity credentials to the credential group 1. The third device creates a second association, which may be to create a credential group 2 for the third user and add the third user's p identity credentials to the credential group 2.
[0355] For example, taking the first device as user A's smartphone, in the above example, after user A clicks the "Yes" button in the prompt pop-up window shown in (d) in Figure 13, in response to the click operation, the smartphone can create a credential group A (first association) corresponding to user A, and add the identity credential that user A just registered - face 111, to credential group A.
[0356] Optionally, after successfully creating the credential group A corresponding to user A, the smartphone can display the information display interface of the credential group A as shown in (e) in Figure 13, which can display the credential information of the identity credentials added to the credential group A, that is, the credential information of the face 111.
[0357] The credential information of the identity credential displayed in the information display interface may include all or part of the aforementioned basic credential information, such as the credential name - face 111, the device name of the device to which the credential belongs - this device, etc.
[0358] It is understandable that if a user chooses to create an identity credential association based on multiple newly registered or selected identity credentials, after the identity credential association is successfully created, the newly registered or selected identity credentials can be automatically associated in the identity credential association.
[0359] For example, if the third device is user B's tablet, and user B has previously registered multiple identity credentials such as face 116 and password 116 on their tablet and has not created their own credential group, user B can select multiple identity credentials such as face 116 and password 116 to create credential group B corresponding to user B (second association). The selected multiple identity credentials such as face 116 and password 116 can then be added to credential group B.
[0360] Optionally, after successfully creating credential group B, user B's tablet can display the information display interface of credential group B as shown in (f) in Figure 13, which can display the credential information of the identity credentials added to credential group B, that is, the credential information of face 116 and password 116.
[0361] In the embodiment of the present application, after the first device creates the first association, the first device may save relevant information about the first association. For example, the association tag of the first association, the user ID of the user to whom the association belongs, and the credential information of the m identity credentials successfully added to the first association when the first association was created. Similarly, after the third device creates the second association, the third device may save relevant information about the second association.
[0362] Optionally, to ensure the reliability of the identity credential association, the first device may generate an association shared key for the first association when creating the first association. Similarly, the third device may also generate an association shared key for the second association when creating the second association.
[0363] The associated shared key can be a public-private key pair or a symmetric key. When a symmetric key is used to encrypt information, the encrypted information becomes the signature, and the same symmetric key can be used to decrypt the signature to obtain the original information.
[0364] The shared key is used to issue a credential joining certificate for the successfully associated identity. This certificate is a credential-association user authorization certificate issued within the device's security environment for an identity when a user authorizes the identity to join an association.
[0365] Optionally, the credential association proof may include: proof information of association, device identification of the association authorization device, device signature, association signature, etc. As shown in Table 1:
[0366] Table 1
[0367] Optionally, the proof information for joining the association may include at least one of the following information: an association tag, a user ID of the user to whom the association belongs, and credential information of the identity credentials for joining the association (such as the aforementioned basic credential information such as the credential ID and credential type). The proof information for joining the association can be used to indicate which identity credentials the user has authorized to join which association.
[0368] For example, when the association is expressed in the form of a group, the certification information for joining the association, ie, the certification information for joining the group, may include the group ID, the user ID of the user belonging to the group, and the credential information of the identity credential for joining the group.
[0369] The device identifier of the association authorization device, which can be a device ID, IP address, or name, indicates the device on which the user authorized the identity credential to be associated. This device is the device that issues the aforementioned credential association certificate and is also called the association authorization device. In other words, when the user agrees to associate a specific identity credential on the association authorization device, the association authorization device issues the credential association certificate for that identity credential.
[0370] The device signature is the signature of the device private key of the associated authorized device on the proof information of joining the association, which is used to verify the integrity of the proof information of joining the association, ensure that the credential joining association proof containing the proof information of joining the association is issued by the associated authorized device, and that the proof information of joining the association has not been tampered with.
[0371] The association signature is a signature of the proof of joining the association, signed using the association shared key. It is used to verify the authenticity of the proof of joining the association. For example, when the association is represented as a group, the association shared key is the group shared key. The association authorization device can use the group shared key to sign the proof of joining the group to obtain the group signature, also known as the association signature.
[0372] In this embodiment of the present application, only electronic devices that possess the associated shared key can use the associated shared key to sign the associated certification information. Therefore, if the identity credential has not been verified by the associated signature, the source of the associated certification information may not be reliable, and the device may not recognize the identity credential for the association.
[0373] Optionally, the first device only sends the shared key associated with the first association to electronic devices whose identity credentials have been authorized by the user to join the first association. In other words, only when an identity credential on an electronic device has been authorized by the user to join the first association can the electronic device obtain the shared key associated with the first association from the first device.
[0374] Similarly, the third device will only send the shared key associated with the second association to electronic devices whose identity credentials have been authorized by the user to join the second association. In other words, only when an electronic device's identity credentials have been authorized by the user to join the second association can the electronic device obtain the shared key associated with the second association from the third device.
[0375] As an example, since the first association is created by the first device when the first user chooses to create an identity credential association based on their m identity credentials, it is equivalent to the first user authorizing the m identity credentials to be added to the first association on the first device. Therefore, the first device can issue a credential addition certificate for the m identity credentials based on the association shared key of the first association generated when the first association was created, such as "shared key 1." The credential addition certificate may include: proof information 1 for adding to the first association, the device identifier of the association authorization device, i.e., the first device, the device signature 1 of the first device, and the association signature 1 of the first association.
[0376] The proof information 1 added to the first association may include at least one of the following information: an association tag for the first association, a user identifier of the first user to whom the first association belongs, and credential information for the identity credentials added to the association, i.e., credential information for the m identity credentials. The device signature 1 of the first device is a signature of the proof information 1 added to the association by the first device using its own device private key, such as "private key 1." The association signature 1 of the first association is a signature of the proof information 1 added to the association by the first device using the association shared key of the first association, such as "shared key 1."
[0377] Similarly, the third device may also issue a credential joining association certificate for the p identity credentials based on the associated shared key of the second association generated when the second association is created, such as "shared key 2".
[0378] It is understood that the first device may also store the association shared key of the first association and the credentials issued by the first device for the m identity credentials joining the first association in the association certificate. The third device may also store the association shared key of the second association and the credentials issued by the third device for the p identity credentials joining the second association in the association certificate.
[0379] S1220: The first device sends association information of the first association to the second device and the third device, and the third device sends association information of the second association to the first device and the second device.
[0380] In an embodiment of the present application, after the first device successfully creates the first association, the first device may broadcast and synchronize the association information of the created first association in the communication system, that is, the first device may send the association information of the first association to the second device and the third device.
[0381] Similarly, after successfully creating the second association, the third device may broadcast and synchronize the association information of the created second association in the communication system, that is, the third device may send the association information of the second association to the first device and the second device.
[0382] It can be understood that if the communication system further includes other devices, the first device and the second device may also send the association information of the first association and the second association to the other devices.
[0383] Optionally, the broadcasted association information may refer to the description of the aforementioned embodiment, such as including at least one of the following information: an association tag marked on the identity credential, a user identifier of the associated user, and credential information of the identity credential successfully added to the association.
[0384] Optionally, in addition to the aforementioned basic credential information, the credential information of the identity credential that has successfully joined the association may also include a credential joining association certificate to verify whether the identity credential that has successfully joined the association currently broadcast is authorized by the user to join the association.
[0385] For example, taking the first association as credential group A, the broadcasted association information of the first association, i.e., credential group information, may include credential group A, user A to which credential group A belongs, and credential information of m identity credentials that the first device has added to credential group A. The credential information may include the credential ID, the device ID of the device to which it belongs, the credential type, the supported ATL, and proof of credential addition to the association.
[0386] It can be understood that the credential information of the successfully associated identity credentials included in the broadcasted association information is the credential information of the identity credentials claimed by each device to have joined the association, and the authenticity of these identity credentials joining the association needs to be verified using the association shared key. However, the broadcasted association information does not include the association shared key. Therefore, when an electronic device that already possesses the association shared key receives the broadcasted association information, it can verify the authenticity of the successfully associated identity credentials currently being broadcasted. However, when an electronic device that does not already possess the association shared key receives the broadcasted association information, it cannot verify the authenticity of the successfully associated identity credentials currently being broadcasted and may temporarily store the association information.
[0387] In some embodiments, the first device, the second device, and the third device may be devices in a network, and the devices in the network may broadcast and synchronize their respective device information, such as device identification, device public key, etc., so that each device can store the device information of other devices in the network.
[0388] Optionally, each device in the network may broadcast and synchronize the credential information of the identity credentials registered on each device, so that each device can save the credential information of the identity credentials on other devices in the network.
[0389] Optionally, each device in the network can broadcast and synchronize the associated information of the identity credentials on each device. This allows each device to store the associated information of all identity credentials in the network. The exchanged association information does not include the associated shared key associated with the identity credentials.
[0390] It is understood that when exchanging association information, only the association information of the identity credentials on each device that have been associated can be exchanged. This association information contains the credential information of the identity credentials that have been associated on each device, and there is no need to exchange information of other devices. This is because each device will also exchange association information with other devices. For example, when the association is reflected in the form of a credential group, each device is responsible for exchanging the credential information of the identity credentials on its device that have been added to the credential group, and the credential information of the identity credentials on its device that have been added to the credential group with other devices.
[0391] For example, when a third device joins the network, other devices already in the network, such as the first device, discover that the third device has joined the network. The first device can then detect whether the third device's device information exists. If not, the first device establishes a communication connection with the third device to exchange and store the device information with the third device through the communication connection. For example, the first device can store the third device's device identifier "Device 3" and device public key "Public Key 3." The third device can also store the first device's device identifier "Device 1" and device public key "Public Key 1."
[0392] Optionally, the first device and the third device may also exchange credential information of identity credentials registered on their respective devices. For example, the first device may store p identity credentials registered by a third user on the third device, where p is a positive integer. The third device may store m identity credentials registered by the first user on the first device.
[0393] Optionally, the first device and the third device may also exchange association information associated with the identity credentials on their respective devices. For example, the first device may send association information of a first association to which the identity credentials on its device are added to the third device. The association information of the first association may include an association tag of the first association, such as credential group A, a user belonging to credential group A, such as user A, and credential information of the m identity credentials on its device added to credential group A.
[0394] The third device may also send the association information of the second association of the identity credentials on its own device to the first device. The association information of the second association may include an association tag such as credential group B, the user to whom credential group B belongs, such as user B, and the credential information of the p identity credentials on its own device added to credential group B.
[0395] Optionally, after the first device and the third device exchange their respective device public keys, they may use the other device's device public key to encrypt subsequent interactive information, such as the encrypted exchanged credential information and association information, to ensure the integrity of the interactive information.
[0396] Similarly, the second device can also exchange the above information with the first device and the third device, so that the second device can save the device information of other devices in the network, and can also save the credential information of all identity credentials in the network, and also save the association information associated with all identity credentials in the network.
[0397] Optionally, with the support of auxiliary security policies, the current device can also exchange the above information on other devices within the authorized scope, such as association information of identity credentials on other devices, credential information of identity credentials registered on other devices, etc.
[0398] In some embodiments, in addition to the broadcasting and synchronization of the above-mentioned credential information and / or association information between various devices in the network during the networking stage, if new associations and / or identity credentials are created on various devices in the network, the newly created associations and / or identity credentials can also be broadcast and synchronized between the networking devices.
[0399] S1230: The second device receives the association information of the first association sent by the first device, and the second device receives the association information of the second association sent by the third device.
[0400] In the embodiment of the present application, after receiving the association information of the first association and the association information of the second association, the second device may save the association information of the first association and the association information of the second association.
[0401] For example, when the association is reflected in the form of a group, the second device may save the credential information of credential group A, user A belonging to credential group A, and m identity credentials that the first device has joined in credential group A, as well as the credential information of credential group B, user B belonging to credential group B, and p identity credentials that the third device has joined in credential group B.
[0402] In some embodiments, the association information of the first association received by the second device may include a credential joining association certificate, wherein the credential joining association certificate may include two signature information: a device signature and an association signature.
[0403] Regarding the device signature, since the second device has already obtained the first device's device public key (e.g., "Public Key 1") through the aforementioned device information exchange, the second device can verify the device signature using the first device's device public key (e.g., "Public Key 1"). If verification succeeds, it can be confirmed that the credential joining association certificate was sent by the first device and that the content of the credential joining association certificate was not tampered with during transmission, thus ensuring the integrity of the credential joining association certificate.
[0404] Regarding the association signature, in the embodiment of the present application, only the electronic device containing the identity credential authorized by the user to join the association possesses the associated shared key, and only the identity credential authorized by the user to join the association will be issued with the associated shared key to obtain the credential joining the association certificate. Therefore, after receiving the broadcasted credential information, the electronic device that possesses the associated shared key can verify the association signature contained in the credential joining the association certificate in the credential information. Only when the verification is passed will the credential information be recognized as authorized by the user to join the association, and the electronic device will update the credential information to the locally stored reliable association information.
[0405] Optionally, if the second device does not have the identity credentials to join the first association, it does not know the shared key associated with the first association. Therefore, the second device cannot verify the authenticity of the content of the credential joining the association certificate and cannot confirm that the currently broadcasted identity credentials successfully joining the association are authorized by the user. In this case, the second device may temporarily store the association information of the first association.
[0406] Optionally, when an identity credential is present on a second device to join a first association, the second device may possess the shared key associated with the first association. Therefore, the second device can verify the credential joining proof using the shared key associated with the first association to verify whether the identity credential currently broadcasted as successfully joining the association is authorized by the user. If verification succeeds, the second device can store the verified identity credential as reliable association information.
[0407] The association information of the second association is similar and will not be elaborated here.
[0408] As an example, taking the first device as a smartphone, the second device as a smart TV, and the third device as a tablet, when the association is expressed in group form, the smart TV can store the credential group information of credential group A sent by the smartphone and the credential group information of credential group B sent by the tablet. The credential group information of the identity credentials stored by the smart TV is shown in Table 2:
[0409] Table 2
[0410] Table 2 shows that when the smart TV does not have identity credentials added to Credential Group A for User A and Credential Group B for User B, the smart TV does not know the group shared key for Credential Groups A and B, and the group shared key field can be left blank. Consequently, when the smart TV receives broadcast or exchanged credential group information, such as Credential Groups A and B, it cannot verify the authenticity of the group credential information list in the credential group information. In other words, while the smart TV can store the broadcast or exchanged credential group information for Credential Groups A and B, it does not recognize the credential information of the identity credentials claimed to have joined the group.
[0411] S1240: The second device detects an association triggering operation.
[0412] The association trigger operation is an operation performed when a user chooses to associate with other identity credentials based on the identity credentials registered by the user.
[0413] Taking the second user registering his / her own identity credentials on the second device as an example, the association triggering operation may be an operation performed when the second user selects other identity credentials for association based on the n identity credentials registered by the second user on the second device.
[0414] The n identity credentials may be newly registered identity credentials or previously registered identity credentials.
[0415] In one scenario, when the second user registers n new identity credentials on the second device, the second user may choose to associate the n new identity credentials with other identity credentials.
[0416] For example, as shown in Figure 14 (a), after user A enters his or her facial information on the smart TV, the smart TV may display a pop-up window as shown in Figure 14 (b), prompting user A to associate the newly entered identity credentials with other identity credentials. When user A clicks the "Yes" button, the smart TV may detect the association trigger operation.
[0417] In another scenario, when the second user has previously registered identity credentials on the second device, the second user may also select n identity credentials from the previously registered identity credentials and associate the n identity credentials with other identity credentials.
[0418] For example, as shown in (e) in FIG14 , after user A logs in to his account in an application on the smart TV, he clicks to select face 113 in the login authentication management interface of his account. In response to the click and selection operation, as shown in (f) in FIG14 , the smart TV may display an operation page for face 113 in a floating manner. The operation page includes a “Join Association” control, which may trigger the association of face 113 with other identity credentials.
[0419] Optionally, when user A clicks the "Add Association" control, the smart TV may detect the association triggering operation. Optionally, when user A clicks the "Add Association" control, the smart TV may also display a prompt pop-up window to prompt user A whether to associate the selected identity credential with other identity credentials. When user A clicks the "Yes" button, the smart TV may detect the association triggering operation.
[0420] Optionally, when a certain application on the smart TV logs in to another user's account, user A may also select his own identity credentials on the smart TV to trigger association and associate with other identity credentials.
[0421] For another example, the login authentication management interface may also include an association indicator control. When a user clicks the association indicator control, all identity credentials in the login authentication management interface are placed in a pending state. The user can select all or select n identity credentials from the list to associate with other identity credentials. When the user confirms the selection, the smart TV can detect the association trigger operation.
[0422] S1250: In response to the association triggering operation, the second device displays an association list, where the association list includes the first association and the second association.
[0423] In an embodiment of the present application, after detecting an association trigger operation, the second device may display an association list based on association information associated with the identity credentials stored locally on the second device.
[0424] In some embodiments, the association information associated with the identity credentials stored locally on the second device may include the association information associated with the identity credentials previously received and sent by various electronic devices, so that the association information associated with the identity credentials received may be displayed in the association list.
[0425] Optionally, the association list may display association information of a first association sent by the first device and association information of a second association sent by the third device. The association information displayed in the association list may be all or part of the stored association information. For example, only the association tag and the user ID of the user to whom the association belongs may be displayed in the association list.
[0426] As an example, when the association is reflected by credential groups, in the above example, in response to user A clicking the "Yes" button, the smart TV can display a credential group list as shown in (c) in Figure 14, which includes the group identifiers of each credential group, such as credential group A and credential group B.
[0427] In some embodiments, the association information of the identity credentials stored locally on the second device may also include the association information of the identity credentials created locally on the second device, so that the association information of the identity credentials created locally can be displayed in the association list.
[0428] For example, when the association is reflected by credential groups, if user C has previously created his own credential group C based on his own identity credential 1 on the second device, then in the above example, in response to user A clicking the "Yes" button, the credential group list displayed on the smart TV may include credential group A, credential group B and credential group C.
[0429] Optionally, when the association desired by the second user does not exist in the association list, the association list may further include an association creation control to trigger the second device to create an association corresponding to the second user based on the n identity credentials of the second user.
[0430] It can be understood that if the identity credential association of the second user already exists in the network, the creation of the second device fails. At this time, the second device can display a pop-up window to prompt that the identity credential association of the second user already exists, and can also prompt whether to add n identity credentials to the identity credential association of the second user. In this way, the second device can determine whether to execute subsequent association request initiation and association request authorization based on the user's selection.
[0431] In some embodiments, after detecting an association trigger, the second device may also detect whether there is locally stored association information for identity credential associations, or search for established identity credential associations within the network. If so, the second device may display an association list based on the stored or searched association information for identity credential associations. If not, the second device may display a pop-up window prompting the second user to establish an identity credential association. The details of establishing an association can be found in the description of the previous embodiment and are not detailed here.
[0432] S1260: The second device detects an association selection operation, where the association selection operation is used to select a first association.
[0433] The association selection operation is used for the second user to select which identity credentials to associate his / her n identity credentials with.
[0434] As one method, the second user can select an association from the association list provided by the second device and add the n selected identity credentials to the association. Each association in the association list provided by the second device already has an identity credential added to it. For example, the first association already has m identity credentials added to it, and the second association already has p identity credentials added to it.
[0435] The following describes the identity credential association method provided in an embodiment of the present application by taking an example in which the second user selects the first association to associate his own n identity credentials with the m identity credentials of the first user in the first association.
[0436] Optionally, the second user and the first user are the same user.
[0437] For example, when the second user and the first user are the same user A, since user A has created his own credential group A (first association) on his own smartphone (first device), user A chooses on the smart TV to add his own face 113 to his own credential group A. As shown in (c) of FIG14 , user A can click and select his own credential group A in the credential group list displayed on the smart TV to join it.
[0438] Optionally, in addition to the first user's m identity credentials, the first association may also include other identity credentials of the first user, such as the first user's identity credentials on other electronic devices. When the user selects the first association, it indicates that the user has chosen to associate their n identity credentials with the first user's m identity credentials and the first user's identity credentials on other electronic devices.
[0439] Optionally, the second user and the first user are different users, such as a husband and wife who trust each other. For example, when the second user is user C and the first user is user A, user C can also choose to add his face 113 to the credential group A of user A that he trusts on the smart TV.
[0440] S1270. In response to the association selection operation, the second device sends first information to the first device, where the first information is used to request that n identity credentials of the second user on the second device be added to the first association.
[0441] In an embodiment of the present application, when the second user chooses to add the above n identity credentials selected by himself to the first association, the second device can send first information to the first device, and the first information is used to request to add the above n identity credentials to the first association.
[0442] Because the first association includes the m identity credentials registered by the first user on the first device, the request to add the n identity credentials to the first association is equivalent to requesting that the n identity credentials be associated with the m identity credentials of the first user. In this case, the first user's consent is required to associate the n identity credentials with the m identity credentials of the first user with the first user's authorization. The first information sent by the second device can be found in the description of the previous embodiment and is not repeated here.
[0443] Since the first user has authorized the first device to add his / her m identity credentials to the first association, the first device can serve as the association authorization device to determine whether the first user has authorized the n identity credentials to be added to the first association. At this time, the second device can send the first information to the first device.
[0444] Optionally, if the first association includes, in addition to the m identity credentials of the first user on the first device, other identity credentials of the first user on other devices, the first device or other electronic device may serve as an association authorization device to determine whether the first user authorizes the addition of the n identity credentials to the first association. Therefore, the second device may send a first message to the first device or other electronic device requesting the addition of the n identity credentials to the first association.
[0445] In some embodiments, if multiple electronic devices have identity credentials authorized by the first user to join the first association, the second device, in response to the association selection operation, can select the first device from the multiple electronic devices as the association authorization device based on the intelligent decision-making of the association authorization device. This can determine the appropriate association authorization device and determine whether the first user has authorized the aforementioned n identity credentials to join the first association.
[0446] Optionally, when the second device makes an intelligent decision to associate with the authorized device, it may refer to at least one of the following information: device distance (such as the distance from the second device, the distance from the first user or the second user, etc.), device status (such as the electronic device currently online, the electronic device currently being used by the first user, etc.), the authentication security level ATL of the identity credentials, and the current environment (such as dim light, bright light, etc.).
[0447] As one approach, the first device is the electronic device closest to the first user or the second user among the multiple electronic devices.
[0448] As another example, the first device is an electronic device currently being used by the first user among the multiple electronic devices.
[0449] As another method, the first device is an electronic device containing an identity credential with an ATL greater than or equal to a target level. The target level may be a preset ATL level. For example, when the target level is level 3 with high security and trustworthiness, an electronic device containing an identity credential with an ATL greater than or equal to level 3, such as a password or 3D face, is required as the associated authorization device. An electronic device containing an identity credential with an ATL lower than level 3, such as a voiceprint or PPG, cannot be used as the associated authorization device.
[0450] The target level can also be the highest ATL of the n identity credentials. For example, if the n identity credentials include a Level 3 identity credential with the highest security and trustworthiness, such as face 113, the target level is Level 3. This means that an electronic device containing an identity credential with an ATL lower than Level 3, such as a voiceprint, cannot be used as an associated authorization device. In other words, the ATL of the identity credential being added to the first association by the associated authorization device cannot be lower than the ATL of the n identity credentials to be added to the first association.
[0451] As another way, the first device is an electronic device that contains identity credentials adapted to the current environment. For example, when the light in the current environment is dim, it is not suitable for face authentication. Therefore, the first device can be an electronic device that contains identity credentials such as a password or fingerprint.
[0452] Of course, if there are only m identity credentials on the first device in the first association that are authorized by the first user to join, the second device can directly use the first device as the associated authorized device to send the first information to the first device.
[0453] In some embodiments, if there are identity credentials on multiple electronic devices in the first association that are authorized by the first user to join, the second device may also broadcast the first information to the multiple electronic devices, so that any of the multiple electronic devices can determine whether the first user authorizes the above n identity credentials to join the first association.
[0454] S1280. The first device receives the first information sent by the second device.
[0455] After receiving the first information, the first device can detect a request to add the above-mentioned n identity credentials to the first association, which is equivalent to a request to associate the above-mentioned n identity credentials with the m identity credentials of the first user in the first association on the local device. Therefore, the first device needs to obtain the consent of the first user on the local device to add the above-mentioned n identity credentials to the first association with the authorization of the first user.
[0456] The process in which the first device needs to obtain the consent of the first user on the local device can be found in the description of the aforementioned embodiment and will not be repeated here.
[0457] S1290. The first device displays a first interface based on the first information, where the first interface is used to prompt the above request.
[0458] For example, when the association is reflected in the form of a group, if the first device is the smartphone of user A, when the smartphone receives the first information for requesting to add the face 113 of user A on the smart TV to the credential group A of user A, the smartphone can display the first interface as shown in (d) in Figure 14 to prompt the user of the request to add the face 113 of user A to the credential group A.
[0459] For another example, when the first information received by the smartphone is used to request that the face 113 of user C on the smart TV be added to the credential group A of user A, the smartphone may also display a first interface to prompt the user with the request to add the face 113 of user C to the credential group A.
[0460] S1300: The first device detects an approval request operation.
[0461] For example, in the first interface shown in (d) of FIG14 , the consent request operation may be a click operation performed by the user currently using the smartphone on the “Agree” button.
[0462] For another example, since the user currently using the smartphone may not be user A who belongs to credential group A, the smartphone may also initiate identity authentication after detecting that the user currently using the smartphone clicks the "Agree" button, such as entering the face recognition interface to verify whether the user currently using the smartphone is user A based on the face 111 of user A who has joined credential group A on the smartphone.
[0463] If facial authentication succeeds, the smartphone can confirm that user A has approved the request on the smart TV to add user A's face 113 to credential group A. The smartphone can then respond to the detected click on the "Agree" button. If so, the smartphone returns a successful indication of the successful addition of face 113 to credential group A to the smart TV.
[0464] If facial authentication fails, the smartphone can confirm that the current user is not user A and does not have the authority to approve the request for face 113 to be added to credential group A. The smartphone can confirm that it has not obtained authorization from user A and therefore not respond. The request for face 113 to be added to credential group A may fail due to a timeout. Alternatively, the smartphone can return a request rejection instruction to the smart TV.
[0465] Of course, if the user currently using the smartphone cancels identity authentication, the smartphone can also confirm that it has not obtained authorization from user A himself.
[0466] It is understood that when the aforementioned face 113 wishes to be added to credential group A, it must obtain authorization from user A, a member of credential group A. By utilizing the identity credentials of user A already in credential group A for identity authentication, it is possible to accurately determine whether user A's authorization has been obtained. For example, since user A's face 111 on a smartphone is already added to credential group A, the smartphone can utilize the face 111 already locally added to credential group A for identity authentication.
[0467] S1310: In response to the consent request operation, the first device sends second information to the second device, where the second information includes association information after the n identity credentials are added to the first association.
[0468] In the embodiment of the present application, after obtaining authorization from the first user, the first device may perform association processing on the n identity credentials to add the n identity credentials to the first association, that is, to associate the n identity credentials with the m identity credentials in the first association. The association information after the n identity credentials are added to the first association is returned to the second device.
[0469] Among them, the first device associates the n identity credentials with the m identity credentials in the first association, and the second information sent by the first device can be found in the description of the aforementioned embodiment, which will not be repeated here.
[0470] For example, the first device tags the n identity credentials with the same association tag as the m identity credentials in the first association. The second information can be the association tag of the first association that is tagged on the n identity credentials, the user ID of the user to whom the first association belongs, credential information of the successfully associated identity credentials, etc.
[0471] For another example, the first association is a credential group for the first user, which already has m identity credentials added to it. The first device can add n identity credentials to the credential group for the first user, so that the credential group includes m identity credentials and n identity credentials. The second information can include the group ID of the credential group for the first user to which the n identity credentials are added, the user ID of the first user to whom the group belongs, credential information of the identity credentials that have successfully added to the credential group for the first user, and so on.
[0472] Optionally, to ensure the reliability of the first association, the first device may issue a credential joining certificate for each of the n newly added identity credentials to the first association, certifying that the n identity credentials were added to the first association with the authorization of the first user. The issuance of the credential joining certificate can be found in the description of the preceding embodiment and is not further elaborated here.
[0473] In one embodiment, the second information sent by the first device to the second device may include a certificate of credential joining the association and the associated shared key of the first association. Thus, the second device may possess the associated shared key of the first association and use the associated shared key of the first association to securely and reliably obtain credential information of the identity credential in the first association.
[0474] In order to ensure the security of the associated shared key of the first association, the first device may also use the device public key of the second device, such as "public key 2", to encrypt the associated shared key of the first association.
[0475] Among them, the credential joining association proof can be the credential joining association proof of n identity credentials on the second device, or the credential joining association proof of n identity credentials on the second device and the credential joining association proof of m identity credentials on the first device, or the credential joining association proof of all identity credentials in the first association.
[0476] As an example, in the above example, when the first information is used to request that user A's face 113 on the smart TV be added to user A's credential group A, the smartphone initiates facial authentication of the current smartphone user after the smartphone user clicks the "Agree" button in the pop-up window shown in FIG14 (d). Once facial authentication is successful, i.e., upon confirming that the current smartphone user is user A, the smartphone can respond to the "Agree" button click and add user A's face 113 to credential group A.
[0477] Optionally, the smartphone may also display the updated credential group A. For example, on the information display interface of credential group A, the smartphone not only displays the credential information of the identity credentials originally added to credential group A, such as the credential information of user A's face 111 on the smartphone, but also displays the credential information of user A's face 113 on the smart TV that has been newly added to credential group A.
[0478] Optionally, the smartphone may issue a credential joining association certificate for the face 113 of user A. The credential joining association certificate and the group shared key of credential group A, such as "Shared Key A," are packaged to generate a second message, which is then sent together to the smart TV. The smartphone may use the smart TV's device public key to encrypt the group shared key of credential group A before sending it to the smart TV. The smart TV can thereby obtain the credential joining association certificate and the group shared key of credential group A. The credential joining association certificate issued by the smartphone for the face 113 may include: proof of joining credential group A, the smartphone's device ID, the device signature, and the group signature.
[0479] The proof of joining credential group A may include the ID of the group being joined (e.g., credential group A), the ID of the user to whom the group is being joined (e.g., user A), and basic credential information of the newly joined group's identity credential (e.g., the credential ID of user A's face 113, credential type, supported ATL Level 3, etc.). The device signature is a signature of the proof of joining credential group A by the smartphone using its own device private key. The group signature is a signature of the proof of joining credential group A by the smartphone using the group shared key of credential group A, such as "Shared Key A."
[0480] Optionally, the smartphone may also send the credential association certificate of the identity credentials that have joined the group on the local device, or the credential association certificate of all identity credentials in the group (issued by the smartphone or other associated authorized device), together with the credential association certificate of face 113 to the smart TV.
[0481] Optionally, the smartphone may also add the basic credential information of the identity credentials of the local device that have joined the group (such as the face 111 of user A), or the basic credential information of all identity credentials in the group, to the above-mentioned proof information of joining the credential group A, so that the smart TV not only understands the identity credentials of the device that has joined the group, but also understands the identity credentials of the peer smartphone that has joined the group, or understands all the identity credentials in the group.
[0482] As another example, in the above example, when the first information is used to request that the face 113 of user C on the smart TV be added to the credential group A of user A, in the prompt pop-up window shown in (d) of Figure 14, after the user currently using the smartphone clicks the "Agree" button, the smartphone initiates facial authentication of the user currently using the smartphone. When the facial authentication is successful, that is, after confirming that the user currently using the smartphone is user A, the smartphone can respond to the "Agree" button operation and add the face 113 of the above-mentioned user C to the credential group A. In other words, the smartphone can issue a credential joining association certificate for the face 113 of the above-mentioned user C. The smartphone can then package the credential joining association certificate and the group shared key of credential group A, such as "shared key A", to generate the second information and send it together to the smart TV.
[0483] Of course, in the pop-up window shown in FIG14(d), the current smartphone user can also click the "Reject" button to refuse to add user C's face 113 to user A's credential group A. In this case, the smartphone can respond to the "Reject" button operation and return a command to the smart TV rejecting the request. Alternatively, the smartphone may not respond, causing the request to fail due to a timeout.
[0484] Optionally, a process such as that shown in (b)-(d) in FIG. 11 may be used to determine that the user agrees and can authorize the association of the identity credentials.
[0485] S1320. The second device receives the second information sent by the first device.
[0486] In an embodiment of the present application, after the second device receives the second information sent by the first device, it can save the second information.
[0487] Optionally, the association information received by the second device may include the credentials joining the association certificate for the n identity credentials and the association shared key of the first association. If the association shared key of the first association has been encrypted using the device public key of the second device, the second device may decrypt it using its own device private key "Private Key 2" to obtain and store the association shared key of the first association.
[0488] Optionally, after obtaining the association shared key of the first association, the second device may use the association shared key to verify whether the identity credentials for successfully joining the first association in the locally stored association information of the first association are authorized by the user.
[0489] The locally stored association information of the first association includes the association information of the first association broadcast and synchronized by the aforementioned first device. The association information includes credential information of the m identity credentials that have successfully joined the association. The credential information may include proof of credential joining the association for the m identity credentials. In some scenarios, the locally stored association information of the first association includes credential information of at least one identity credential that is broadcast and synchronized by other electronic devices and claims to have successfully joined the association.
[0490] That is, when an identity credential on a second device is first added to an association, the second device needs to verify all previously received credential information for identities claiming to have successfully joined the first association using the association shared key of the first association. The second device may delete credential information for identities that fail verification. Furthermore, all subsequent credential information for identities claiming to have successfully joined the first association received by the second device must also be verified using the association shared key of the first association, thereby ensuring the reliability of the credential information stored on the second device for those identities that have joined the first association.
[0491] For example, as shown in Table 2, since the smart TV does not know the group shared key of credential group A, it cannot verify the authenticity of the credential information of m identity credentials claimed to be added to credential group A in the credential group information previously broadcast and synchronized by the smartphone. The smart TV temporarily stores the broadcasted credential group information of credential group A locally.
[0492] At this point, since the smartphone has obtained authorization from user A to add user A's face 113 on the smart TV to credential group A, the smartphone can issue a credential joining association certificate for user A's face 113 and send this credential joining association certificate and the group shared key for credential group A, such as "Shared Key A," to the smart TV. The smart TV now possesses the group shared key for credential group A, such as "Shared Key A," and can store it. The smart TV can then use this group shared key to verify the credential joining association certificates for the identity credentials claimed to have joined credential group A in the locally stored credential group information for credential group A, and delete the credential information for the identity credentials that fail verification. This ensures that the group credential information list for credential group A stored on the smart TV contains only credential information for credential credentials that have been authorized by the user to join credential group A, is recognized by the smart TV, and appears to the smart TV to belong to the identity credentials of user A.
[0493] Optionally, the credential joining and association certificate for the m identity credentials may also include the device signature of the smartphone that issued the credential joining and association certificate. Therefore, the smart TV may first verify the device signature using the smartphone's device public key to ensure the integrity of the credential information for the m identity credentials. It will be appreciated that if the integrity verification fails, it may indicate that the credential information for the m identity credentials purportedly joined to credential group A may have been tampered with. The smart TV may delete or discard the credential information for the m identity credentials.
[0494] When the integrity check passes, the smart TV can determine whether it knows the group shared key of credential group A. Here, since the face 113 of user A has been added to credential group A on the smart TV, the smart TV can know and use the group shared key of credential group A to verify the validity of the credential joining association certificate of the m identity credentials. It can be understood that since the credential joining association certificate of the m identity credentials is issued by the smartphone using the same group shared key of credential group A, the smart TV passes the validity check for the m identity credentials. The other identity credentials that failed the check have been deleted. At this time, the credential group information of the identity credentials stored by the smart TV has been updated, as shown in Table 3:
[0495] Table 3
[0496] Referring to Table 3, when the smart TV does not have an identity credential locally that has joined a credential group, such as credential group B, it means that the smart TV does not know the group shared key of credential group B. The smart TV directly saves the credential information of the identity credential that claims to have joined credential group B and waits for subsequent verification.
[0497] In some embodiments, on a second device, when a second user selects to add their n identity credentials to a first association, if the second device already has local identity credentials added to the first association, the second device may also serve as an association authorization device, or as a preferred association authorization device, to determine whether the first user authorizes the n identity credentials to be added to the first association. Optionally, in response to the association selection operation, the second device may display a first interface, the first interface being used to prompt a request to add the n identity credentials to the first association. In response to the approval request operation, the second device generates and stores association information after the n identity credentials are added to the first association.
[0498] In some embodiments, the second device may also broadcast and synchronize the credential information of the n newly associated identity credentials on the local device in the communication system. The credential information may include proof of the credential joining of the n identity credentials. For example, the credential information of each identity credential broadcast by the second device may carry the content shown in Table 4:
[0499] Table 4
[0500] Therefore, after receiving the credential information broadcast by the second device, other electronic devices in the communication system (such as a third device) can verify the credential joining association certificate of the n identity credentials. After the verification is passed, the other electronic devices can add the n identity credentials to the association information of the first association stored locally.
[0501] In some embodiments, in Internet of Things (IoT) device scenarios, some IoT accessories with weak device capabilities that cannot register identity credentials can also apply to join the association, thereby reliably using the identity authentication results of the corresponding identity credentials in the association. However, to prevent the association shared key from being leaked from these weak IoT accessories, a verification shared key can be added.
[0502] The shared key verification is used to issue a device association certificate for devices that have successfully joined the association. A device association certificate is a device association user authorization certificate issued to a device in the device's security environment when a user authorizes the device to join the association.
[0503] Optionally, the device association proof may include: association proof information, device identification of the association authorization device, device signature, association signature, verification signature, etc. The verification signature is a signature of the verification shared key on the association proof information.
[0504] Optionally, an electronic device that possesses the association shared key also possesses the verification shared key. However, an electronic device that possesses the verification shared key does not necessarily possess the association shared key. Similarly, the verification shared key is only sent to devices that the user has authorized to join the first association.
[0505] The identity credential association method provided in the embodiment of the present application can establish an identity credential association that is exclusive to a certain user (such as the first association of the first user) to associate the identity credentials of the user, and when there are n identity credentials on a device that want to be added to the established identity credential association, the device needs to obtain authorization from the user to whom the identity credential association belongs. The present application can determine whether the authorization of the user to whom the identity credential association belongs (such as the first user to whom the first association belongs) is obtained through the electronic device (such as the first device) where the identity credential that has been added to the identity credential association is located, and after confirming that the authorization has been obtained, it can add n identity credentials to the established identity credential association.
[0506] In some scenarios, users can also selectively add at least one of their own identity credentials to the established identity credential association, thereby associating multiple identity credentials.
[0507] For example, please refer to FIG15, which shows a flow chart of another method for associating identity credentials provided by an embodiment of the present application. The method includes:
[0508] S1500. The first device displays a first association in which m identity credentials of a first user on the local device have been added.
[0509] In an embodiment of the present application, at least one piece of associated information of an identity credential is stored on the first device, which may include associated information of an identity credential created on the first device, and may also include associated information of an identity credential received from other electronic devices.
[0510] The first device may display the identity credential association based on the stored association information of the identity credential association.
[0511] The following describes a first association displayed by a first device based on stored association information as an example. The first association belongs to a first user and is used to associate the first user's identity credentials on at least one electronic device. m identity credentials of the first user on the first device have been added to the first association.
[0512] Optionally, the first device displays the first association by displaying an association list including the first association, wherein the association list can be used to display all identity credential associations stored on the first device, or identity credential associations to which the identity credential on the first device has been added.
[0513] For example, when the association is reflected in the form of a group, the smartphone of user A can display the credential group management interface shown in Figure 16 (a). The credential group association interface shows the credential group A to which the identity credentials of the local user A have joined, and also shows the credential group B to which the identity credentials of the local user A that do not exist and that the smartphone has joined are found in the network.
[0514] Optionally, the first device displays the first association by displaying all identity credentials that have been added to the first association, including the m identity credentials.
[0515] For example, taking the first association as credential group A, user A's smartphone may display a credential display interface for credential group A as shown in FIG16( b), where the credential display interface displays credential information of user A's face 111, which is added to credential group A. It will be appreciated that if identity credentials on other devices are also added to credential group A, the credential display interface may also display identity credentials on other devices.
[0516] In one scenario, the first device may provide a functional control for identity credential association services, such as adding a credential group management control to the device interface. When the user clicks the functional control, the first device may display the aforementioned association list. When the user clicks the option corresponding to the first association in the association list, the first device may display all identity credentials added to the first association.
[0517] There are many ways to add the m identity credentials of the first user on the first device to the first association, which are not limited here.
[0518] For example, when the first association is created by the first device based on m identity credentials of the first user, the first device automatically adds the m identity credentials to the first association after creating the first association. Of course, the first association may also include other identity credentials that the first user continues to add.
[0519] For another example, when the first association is created by another electronic device, the other electronic device may, with the first user's consent, add the first user's m identity credentials on the first device to the first association. Simultaneously, the other electronic device may also send association information after adding the m identity credentials to the first association to the first device.
[0520] S1510: The first device detects a credential adding operation, where the credential adding operation is used to add n identity credentials of a second user on the second device in the first association.
[0521] The credential adding operation is the operation performed when the user selects to add identity credentials in his / her own identity credential association.
[0522] Taking the first user adding identity credentials in his / her first association as an example, the credential adding operation may be an operation performed by the first user when adding n identity credentials of the second user on the second device in the first association.
[0523] In some embodiments, the first user and the second user are the same user.
[0524] For example, when the smartphone displays the credential display interface for credential group A of user A shown in FIG16(b), the smartphone can automatically detect whether there are other identity credentials of user A that have not been added to credential group A. When it is detected that the identity credential of user A on the public device smart TV, such as face 113, has not been added to credential group A, the smartphone can display a prompt pop-up window shown in FIG16(c) to prompt the user whether to add the identity credential on the smart TV to credential group A. When the user clicks the "Yes" button, the smart TV can detect the credential addition operation.
[0525] For another example, after user A clicks the "+" control in the upper right corner of the credential display interface, in response to the click operation, the smartphone can display the identity credentials of user A who has not yet been added to credential group A, such as user A's face 113 on the smart TV. After user A selects all or some of the identity credentials to confirm the addition, the smart TV can detect the credential addition operation.
[0526] For another example, in the credential group management interface shown in Figure 16(a), when user A clicks or long-presses the option control for credential group A, the smartphone may display a floating operation page for credential group A, which includes an "Add Identity Credential" control. After user A clicks this control, in response to this click, the smartphone may display at least one identity credential of user A that has not yet been added to credential group A. After user A selects all or some of the identity credentials to confirm the addition, the smart TV may detect the credential addition operation.
[0527] In one scenario, the first device is a private device of a first user, and the user currently using the first device is usually the first user. When the first device detects a credential adding operation, the first device may confirm that the credential adding operation is performed by the first user himself.
[0528] In another scenario, since the user currently using the first device may not be the first user, the first device may also initiate identity authentication after detecting the credential addition operation to verify whether the user currently using the first device is the first user, so that the first device can confirm whether the credential addition operation was performed by the first user. The authentication method of the identity authentication may be determined based on the m identity credentials of the first user that have been added to the first association on the first device, or based on other identity credentials registered by the first user on the first device.
[0529] For example, in the pop-up window shown in Figure 16 (c), after the current smartphone user clicks the "Yes" button to confirm adding the identity credential, such as face 113, on the smart TV to credential group A, the smartphone may display the facial authentication interface shown in Figure 16 (d). The current smartphone user can then face the smartphone directly, allowing it to collect facial information and verify whether the collected facial information and face 111 meet the system's predefined conditions. Face 111 represents the identity credential of user A, who has been added to credential group A on the smartphone. If so, facial authentication succeeds. The smartphone can then confirm that user A performed the credential addition operation and, therefore, respond to the smartphone user's click of the "Yes" button. If not, facial authentication fails, and the smartphone may display a pop-up window to inform the user that they do not have permission and that the identity credential failed to be added to the group. Of course, if facial authentication is canceled, the smart device may also display a pop-up window to inform the user that identity authentication was not performed and that the identity credential failed to be added to the group.
[0530] In other embodiments, the first user and the second user are different users, that is, the first user may also choose to add the identity credentials of other users to the association of his or her own identity credentials.
[0531] For example, after user A clicks the "+" control in the upper right corner of the above-mentioned credential display interface, the smartphone can display the face 113 of user B on the smart TV, the password 111 of user A on the smartphone, and other identity credentials that are not added to the credential group A. After user A selects the face 113 of user B to confirm the addition, the smart TV can detect the credential addition operation.
[0532] S1520. In response to the credential adding operation, the first device sends second information to the second device. The second information includes association information after the n identity credentials are added to the first association.
[0533] In an embodiment of the present application, in response to a credential addition operation, the first device may associate n identity credentials to add the n identity credentials to a first association, that is, to associate the n identity credentials with the m identity credentials in the first association. The first device may also locally store the association information after the n identity credentials are added to the first association.
[0534] Optionally, after the first device adds n identity credentials to the first association, it may also update and display the first association, for example, displaying all identity credentials added to the first association, including the m identity credentials and the n identity credentials.
[0535] Among them, the first device associates the n identity credentials with the m identity credentials in the first association, and the n identity credentials sent by the first device are added to the association information after the first association. Please refer to the description of the above embodiment and will not be repeated here.
[0536] S1530. The second device receives the second information sent by the first device.
[0537] In an embodiment of the present application, after the second device receives the second information sent by the first device, it can save the second information.
[0538] In some embodiments, if there are other identity credentials of the first user locally on the first device that have not been added to the first association, the first user may also choose to add the other identity credentials of the first user locally to the first association. In this case, the first device responds to the credential addition operation by adding the n identity credentials to the first association and locally stores the association information after the n identity credentials are added to the first association.
[0539] The identity credential association method provided in the embodiment of the present application enables the user to choose to add identity credentials in the established identity credential association to add the identity credentials on the local device or other electronic devices (such as the second device) to the established identity credential association, thereby associating the added identity credentials with all identity credentials in the established identity credential association.
[0540] In some scenarios, in addition to being able to associate their own identity credentials and perform operations such as adding identity credentials, users can also perform other processing operations, such as deleting identity credentials in an identity credential association, updating identity credentials in an identity credential association, renaming identity credentials in an identity credential association, etc. This embodiment of the application does not limit the processing operations that users can perform based on their own identity credential associations.
[0541] In some scenarios, when the communication system includes more electronic devices such as a third device in addition to the first device and the second device, the user can also actively add the identity credentials on at least one device to the established identity credential association.
[0542] Optionally, when a user selectively adds identity credentials on a device to an established identity credential association, the user also needs to obtain authorization from the user to whom the identity credential belongs on the device, so that the identity credential can be added to the established identity credential association with the user's authorization.
[0543] For example, please refer to FIG17, which shows a flowchart of another method for associating identity credentials provided by an embodiment of the present application. The method includes:
[0544] S1700. The second device sends third information to the first device and the third device, and the third device sends fourth information to the first device and the second device. The third information includes credential information of n identity credentials of the second user on the second device, and the fourth information includes credential information of p identity credentials of the third user on the third device.
[0545] Optionally, the first device, the second device, and the third device are devices in a network. Each device in the network can broadcast and synchronize credential information of identity credentials registered on each device. The credential information can be the identity credentials of multiple users or one or more identity credentials of a single user. Thus, each device can store the credential information of the identity credentials of other devices in the network.
[0546] Taking the example of a second user registering their n identity credentials on a second device, the second device can broadcast and synchronize third information within the network. This third information includes the credential information of the second user's n identity credentials on the local device. Similarly, taking the example of a third user registering their p identity credentials on a third device, the third device can broadcast and synchronize fourth information within the network. This fourth information includes the credential information of the third user's p identity credentials on the local device.
[0547] The n identity credentials are all the identity credentials registered on the second device, or the identity credentials newly registered on the second device. The same applies to the p identity credentials.
[0548] Optionally, the third information is sent when the second device joins the network, or the third information is sent when a new identity credential is registered on the second device. The same applies to the fourth information.
[0549] The time when the second device broadcasts the synchronized third information may be the same as or different from the time when the third device broadcasts the synchronized fourth information.
[0550] S1710. The first device receives third information sent by the second device, and the first device receives fourth information sent by the third device.
[0551] The time when the first device receives the third information and the fourth information may be the same or different.
[0552] After the first device receives the third information and the fourth information respectively, it can save the third information and the fourth information to facilitate subsequent users to view the identity credential registration status of each electronic device in the network.
[0553] S1720. The first device displays a first association in which m identity credentials of the first user on the local device have been added.
[0554] When the first user wants to add identity credentials to his / her first association, the first user can control the first device to display the first association so that the first user can perform relevant processing operations on the first association.
[0555] S1730: The first device detects an add trigger operation for the first association.
[0556] Optionally, when displaying the first association, the first device may also display an operation control for the first association. The operation control may include a control 1 for instructing to add the identity credential to the identity credential association. When the first user clicks control 1, the first device may detect the add trigger operation for the first association, at which point the first device may trigger the first device to enter a process for adding the identity credential to the first association.
[0557] Optionally, control 1 is the “+” control in the upper right corner of the credential display interface shown in FIG16( b ) in the aforementioned embodiment.
[0558] Optionally, in the aforementioned embodiment, in the credential group management interface shown in FIG16( a ), when user A clicks or long presses the option control of credential group A, the smartphone may float and display an operation page for credential group A. Control 1 is the “Add Identity Credentials” control in the operation page.
[0559] Optionally, when the first user, the second user, and the third user are the same user, such as user A, and the n identity credentials and the P identity credentials have not been added to the identity credential association, the first device can detect that the n identity credentials and the P identity credentials of the first user have not been added to the first association based on the credential information of the identity credentials stored locally on each electronic device. At this time, the first device can display a prompt pop-up window, which includes prompt content to prompt the first user whether to add the n identity credentials and the P identity credentials to the first association, as well as a "Yes" button and a "No" button. Control 1 is the "Yes" button in the prompt pop-up window.
[0560] In the embodiment of the present application, when adding an identity credential to a certain identity credential association, authorization must be obtained from the user to whom the identity credential association belongs to ensure that all identity credentials in the identity credential association are added with the user's consent. In other words, identity credentials can only be added to the first association with the consent of the first user.
[0561] In one scenario, the first device is a private device of a first user associated with the first association, and the user currently using the first device is typically the first user. When the first device detects an add trigger operation for the first association, the first device can confirm that the add trigger operation was performed by the first user associated with the first association, which is equivalent to the first user associated with the first association agreeing to add identity credentials to the first association.
[0562] In another scenario, since the user currently using the first device may not be the first user of the first association, the first device may also initiate identity authentication after detecting the add trigger operation for the first association to verify whether the user currently using the first device is the first user of the first association. This allows the first device to confirm whether the add trigger operation was performed by the first user of the first association. The authentication method of the identity authentication may be determined based on the m identity credentials of the first user that have been added to the first association on the first device, or may be determined based on other identity credentials registered by the first user on the first device.
[0563] For example, in the credential display interface for credential group A shown in Figure 18 (a), the current smartphone user can click the "+" control in the upper right corner to trigger the addition of identity credentials to credential group A. The smartphone can then respond to this click by displaying the facial authentication interface shown in Figure 18 (b). The current smartphone user can then face the smartphone directly, allowing it to collect facial information and verify whether the collected facial information and face 111 meet the system's predefined conditions. Face 111 represents the identity credential of user A, who has been added to credential group A on the smartphone. If these conditions are met, facial authentication succeeds, and the smartphone can respond to the current smartphone user clicking the "Yes" button. If not, facial authentication fails, and the smartphone can display a pop-up window to inform the user that permission is not granted and that identity credential addition failed. Of course, if facial authentication is canceled, the smart device can also display a pop-up window to inform the user that identity authentication was not performed and that identity credential addition failed.
[0564] S1740. In response to the add trigger operation, the first device displays a credential list, where the credential list includes n identity credentials and p identity credentials.
[0565] In an embodiment of the present application, after detecting an add trigger operation for a first association, the first device may display a credential list based on the credential information of the identity credentials stored locally on the first device. The credential list may include one or more identity credentials. The credential list may display all or part of the credential information of the stored identity credentials, for example, only the credential identifier and the device identifier of the device to which the credential belongs may be displayed in the credential list.
[0566] For example, the smartphone may display a credential list as shown in FIG18(c), which may include identity credentials such as password 112 and face 112 registered by user A on a tablet, face 113 registered by user A on a smart TV, and password 113 and PPG registered by user A on a smartwatch. The current smartphone user may select one or more identity credentials from the list and add them to credential group A.
[0567] In some embodiments, the credential information of the identity credentials stored locally on the first device may include credential information of identity credentials previously received from various electronic devices, so that the credential information of these received identity credentials may be displayed in a credential list.
[0568] Optionally, the above-mentioned credential list may display credential information of n identity credentials of the second user broadcast and synchronized by the second device, and credential information of p identity credentials of the third user broadcast and synchronized by the third device.
[0569] In some embodiments, the credential information of the identity credentials stored locally on the first device may include credential information of the identity credentials registered on the local device, so that the credential information of the identity credentials on the local device can be displayed in the credential list.
[0570] Optionally, the credential list is used to display all identity credentials in the network that are not associated with the identity credentials, that is, n identity credentials and p identity credentials are identity credentials that are not associated with the identity credentials.
[0571] Optionally, the credential list is used to display all identity credentials in the network that are not included in the first association, that is, n identity credentials and p identity credentials are identity credentials that are not included in the first association.
[0572] Optionally, since this is an add trigger operation for the first association, the credential list may only display the identity credentials of the first user belonging to the first association registered on various devices in the network, such as the identity credentials bound to the same account of the first user on various devices.
[0573] S1750. The first device detects a credential adding operation, where the credential adding operation is used to select n identity credentials to be added to the first association.
[0574] The credential adding operation is used for the first user to select which identity credentials to add to his or her own identity credential association, i.e., the first association. For example, the first user may select n identity credentials of the second user on the second device to add to the first association.
[0575] Optionally, when the second user and the first user are the same user, such as user A, as shown in (c) in Figure 18, user A can choose to add his face 113 on the smart TV to his credential group A (first association).
[0576] Optionally, the second user and the first user are different users, such as when the first user is user A and the second user is user B, user A may also choose to add user B's face 113 on the smart TV to his or her credential group A (first association).
[0577] Optionally, in addition to the first user's m identity credentials, the first association may also include other identity credentials of the first user, such as the first user's identity credentials on other electronic devices. When the user selects n identity credentials, it indicates that the user chooses to associate their m identity credentials, as well as their identity credentials on other electronic devices, with the n identity credentials.
[0578] In one scenario, the first device may also initiate identity authentication when detecting a credential addition operation to verify whether the user currently using the first device is the first user to whom the first association belongs, so that the first device can confirm whether the first user to whom the first association belongs agrees to add identity credentials in the first association.
[0579] S1760. The first device sends first information to the second device in response to the credential adding operation, where the first information is used to request to add n identity credentials in the first association.
[0580] In an embodiment of the present application, when the first user chooses to add n identity credentials of the second user on the second device to the first association, the first device can send first information to the second device, where the first information is used to request to add the above n identity credentials to the first association.
[0581] Because the n identity credentials above belong to the second user and are registered on the second device, it is necessary to obtain the second user's consent on the second device so that, with the second user's authorization, the n identity credentials above are added to the first association and associated with the first user's m identity credentials. The first information sent by the first device can be found in the description of the previous embodiment and is not repeated here.
[0582] S1770. The second device receives the first information sent by the first device.
[0583] After receiving the first information, the second device can detect a request to add the n identity credentials of the second user on the local device to the first association. Therefore, the second device needs to obtain the consent of the second user on the local device to add the above n identity credentials to the first association with the authorization of the second user.
[0584] S1780. The second device displays a first interface based on the first information, where the first interface is used to prompt the above request.
[0585] For example, when the association is reflected in the form of a group, if the second device is a smart TV, when the smart TV receives the first information for requesting to add the face 113 of user A on the smart TV to the credential group A, the smart TV can display the first interface as shown in (d) in Figure 18 to prompt the user of the request to add the face 113 of user A to the credential group A.
[0586] For another example, when the first information received by the smart TV is used to request that the face 113 of user B on the smart TV be added to credential group A, the smart TV may also display a first interface to prompt the user of the request to add the face 113 of user B to credential group A.
[0587] S1790: The second device detects an approval request operation.
[0588] For example, in the first interface shown in (d) of FIG18 , the consent request operation may be a click operation performed by the user currently using the smart TV on the “Agree” button.
[0589] For another example, since the user currently using the smart TV may not be user A (or user B) himself, the smart TV may also initiate identity authentication after detecting that the user currently using the smart TV clicks on the "Agree" button, such as entering the face authentication interface shown in (e) in Figure 18, to verify whether the user currently using the smart TV is user A (or user B) himself based on the face 113 of user A (or the face 113 of user B) on the smart TV.
[0590] When facial authentication succeeds, the smart TV can confirm that it is user A (or user B) who has agreed to the request to add user A's face 113 (or user B's face 113) on the smart TV to credential group A. At this point, the smart TV can respond to the detected click on the "Agree" button. If so, the smart TV will return an instruction to the smartphone approving the request.
[0591] If the facial authentication fails, the smart TV may confirm that it has not obtained authorization from user A (or user B), so the smart TV may not respond, and the request for face 113 to join credential group A may fail due to a timeout. Alternatively, the smart TV may return a command to the smartphone rejecting the request.
[0592] S1800: The second device sends a consent instruction to the first device in response to the consent request operation.
[0593] The consent instruction is used to indicate that the second user has agreed to the request to add the second user's n identity credentials to the first association.
[0594] S1810. The first device receives a consent instruction sent by the first device.
[0595] S1820. The first device sends second information to the second device. The second information includes association information after n identity credentials are added to the first association.
[0596] In an embodiment of the present application, after obtaining authorization from a second user, the first device may associate the second user's n identity credentials to add them to a first association, that is, to associate the n identity credentials with the m identity credentials in the first association. The first device then sends association information related to the addition of the n identity credentials to the first association to the second device. The first device may also locally store the association information related to the addition of the n identity credentials to the first association.
[0597] Optionally, after the first device adds n identity credentials to the first association, the first association may also be updated and displayed.
[0598] For example, in the above example, after the smart TV returns an approval instruction to the smartphone, the smartphone can add the face 113 of user A (the face 113 of user B) on the smart TV to the credential group A, and can update the credential display interface of the credential group A to that shown in (f) in Figure 18, which includes the face 111 of user A on the smartphone that has previously joined the credential group A, and the face 113 of user A (the face 113 of user B) on the smart TV that is currently newly joined to the credential group A.
[0599] Optionally, to ensure the reliability of the first association, the first device may issue a credential joining certificate for each of the n newly added identity credentials to the first association, certifying that the n identity credentials were added to the first association with the authorization of the first user. The issuance of the credential joining certificate can be found in the description of the preceding embodiment and is not further elaborated here.
[0600] In one embodiment, the second information sent by the first device to the second device may include a certificate of credential joining the association and the associated shared key of the first association. Thus, the second device may possess the associated shared key of the first association and use the associated shared key of the first association to securely and reliably obtain credential information of the identity credential in the first association.
[0601] In some embodiments, the first device may also broadcast and synchronize the credential information of the n newly added identity credentials in the first association in the communication system. The credential information may include the credentials joining the association certificate of the n identity credentials. Thus, after receiving the credential information broadcast by the first device, other electronic devices in the communication system (such as a third device) may verify the credentials joining the association certificate of the n identity credentials. After the verification is passed, the other electronic devices may add the n identity credentials to the association information of the first association stored locally.
[0602] S1830. The second device receives the second information sent by the first device.
[0603] In an embodiment of the present application, after the second device receives the second information sent by the first device, it can save the second information.
[0604] Optionally, the association information received by the second device may include credential joining association certificates of n identity credentials and an association shared key of the first association.
[0605] Optionally, after obtaining the association shared key of the first association, the second device may use the association shared key to verify whether the identity credentials for successfully joining the first association in the locally stored association information of the first association are authorized by the first user to join.
[0606] In some embodiments, on the first device, the first user may also choose to add the identity credentials on the local device to the first association. Optionally, in response to the credential addition operation, the second device may display a first interface prompting a request to add the n identity credentials to the first association. In response to the approval request, the first device generates and stores association information after the n identity credentials are added to the first association.
[0607] In some embodiments, the second device may also broadcast and synchronize the credential information of the n newly associated identity credentials on the local device in the communication system. The credential information may include proof of credential association of the n identity credentials.
[0608] The identity credential association method provided in the embodiment of the present application can establish an identity credential association exclusively for a certain user (such as the first association of the first user) to associate the identity credentials of the user, and the user himself can also actively and selectively add the identity credentials of at least one device in his own identity credential association.
[0609] It can be understood that, through the above method, after the user authorizes to associate his or her identity credentials on different electronic devices, the identity authentication result corresponding to any of the associated identity credentials can be recognized by the electronic devices where the other associated identity credentials are located.
[0610] Based on the above-mentioned associated identity credentials, an embodiment of the present application further provides an identity authentication method. When an electronic device entrusts another electronic device to perform cross-device identity authentication, the electronic device can obtain the credential information of the identity credentials used by the other electronic device during the cross-device identity authentication, and use the credential information to verify whether the identity credentials used by the other electronic device are associated with the identity credentials of the local device. If so, the electronic device can recognize the identity authentication result of the other electronic device and thus can perform a corresponding response operation.
[0611] The following is a detailed introduction to the identity authentication method provided in the embodiment of the present application with reference to the accompanying drawings.
[0612] Please refer to Figure 19, which shows a flow chart of an identity authentication method provided by an embodiment of the present application. The method includes:
[0613] S1900. The first device sends a cross-device authentication request to the second device.
[0614] It is understandable that when a user uses some functions of the first device, such as account login, device unlocking, network transactions or resource access, the first device needs to pass the user's identity authentication before allowing the user to use these functions normally.
[0615] In some embodiments, upon detecting that a user currently using the first device performs a first operation, the first device may initiate identity authentication of the user to confirm whether the user is a user with corresponding permissions and whether the first operation has been authorized by the user with corresponding permissions. The first operation may be an operation involving identity authentication, such as account login, device unlocking, network transaction, or resource access. This application does not limit the first operation.
[0616] Taking the first user as an example, the identity authentication initiated by the first device can be used to verify whether the first operation is authorized by the first user himself.
[0617] Optionally, the first device initiates identity authentication for the user, which may be local user identity authentication using a first identity credential. The first identity credential is the identity credential registered by the first user on the first device (for example, it may be one of the m identity credentials mentioned above), and the first user is a user with corresponding permissions. The first device can thus determine whether the user currently performing the first operation is the first user and whether the first operation has been authorized by the first user.
[0618] For example, if the first device is a smart door lock, the first identity credential can be a password or facial recognition registered by the owner on the smart door lock. The smart door lock initiates local user identity authentication, which can use the owner's password, facial recognition, or other identity credentials registered on the smart door lock to authenticate the user who currently triggers the smart door lock to open the door, to determine whether the door opening operation was triggered by the owner.
[0619] Optionally, the first device initiates identity authentication for the user, or it may utilize other electronic devices for cross-device authentication. The other electronic devices are devices to which other identity credentials associated with the first identity credential belong. Since the first identity credential and the other identity credentials are associated with the first user with their consent, and the associated multiple identity credentials all appear to belong to the first user from the device's perspective, the other electronic devices to which the associated identity credentials belong can also determine whether the first operation has been authorized by the first user.
[0620] For example, as shown in Figure 20, when a visitor rings the doorbell, if the owner, such as User A, is not near the smart door lock, the smart door lock can entrust the owner's electronic device, such as a smartphone, to perform user identity authentication to determine whether the owner has authorized the door to be opened. The owner's registered password and facial recognition credentials on the smart door lock are associated with the owner's registered facial recognition, fingerprint, and other credentials on the smartphone, such as being added to the owner's credential group A.
[0621] Taking the example of a first device entrusting a second device to perform cross-device authentication, the first device may send a cross-device authentication request to the second device, the cross-device authentication request being used to instruct the second device to initiate identity authentication, wherein the second device has identity credentials associated with the first identity credentials.
[0622] Optionally, the cross-device authentication request may include credential information of the first identity credential used by the first device for local authentication, or a user identifier of a user with corresponding permissions, such as the first user. This allows the second device to accurately use the corresponding identity credential locally for identity authentication, thereby ensuring that the second device obtains an authentication result that is acceptable to the first device.
[0623] As an example, a cross-device authentication request includes credential information of a first identity credential used by a first device when performing local authentication of a first user. The second device may perform authentication based on a local identity credential associated with the first identity credential. Because the local identity credential is associated with the first identity credential, the authentication result of the local identity credential is also considered by the first device and the second device to be an authentication result of the first user, and the first device can recognize the authentication result of the local identity credential.
[0624] As an example, a cross-device authentication request includes a user identifier of the first user required for authentication when the first device performs local authentication of the first user. The second device may determine an identity credential association of the first user based on the user identifier of the first user, such as the first association. The second device may then perform identity authentication based on the local identity credential successfully added to the first association.
[0625] Optionally, the cross-device authentication request may include specifying an authentication method for the second device to perform identity authentication. The authentication method is determined based on credential information of the second identity credential. The second identity credential is an identity credential on the second device that is associated with the first identity credential. The first device may locally store identity credentials associated with the first identity credential.
[0626] In some embodiments, the cross-device authentication request may also carry relevant information of the first operation, so that the user of the second device can determine whether to perform the authorization operation based on the relevant information of the first operation.
[0627] In an embodiment of the present application, the second device and the first device may establish a communication connection, so that the first device may send a cross-device authentication request to the second device via the communication connection. This application does not limit the communication connection method between the second device and the first device.
[0628] S1910. The second device receives a cross-device authentication request sent by the first device.
[0629] S1920. The second device responds to the cross-device authentication request and performs identity authentication using a second identity credential, where the second identity credential is an identity credential registered by the second user on the second device.
[0630] After receiving the cross-device authentication request, the second device may detect that the identity authentication of the first user is required. At this time, the second device may call local identity authentication capabilities to authenticate the first user.
[0631] Take the second device using the second identity credential for identity authentication as an example, wherein the second identity credential is the identity credential registered by the second user on the second device, and the second identity credential is associated with the first identity credential.
[0632] Optionally, the second user and the first user are the same user.
[0633] Optionally, when the second user and the first user are different users, since the second identity credential is associated with the first identity credential, the device appears to the second identity credential and the first identity credential to belong to the same user, such as the first user. This means that when the second device uses the second identity credential for identity authentication and the authentication is successful, the second device can confirm that it has obtained authorization from the first user.
[0634] Optionally, the second device may store association information of various identity credentials. Based on the locally stored association information and the credential information of the first identity credential carried in the cross-device authentication request, the second device may determine one or more identity credentials associated therewith (such as the n identity credentials described above). The one or more identity credentials include the second identity credential.
[0635] As a method, the second device may store a first association of the first user, in which the first identity credential and the second identity credential have been added. The second device may determine the first association of the first user based on the locally stored identity credential associations of each user and the user identifier of the first user carried in the cross-device authentication request, and determine one or more identity credentials (such as the n identity credentials mentioned above) added to the first association on the second device. The one or more identity credentials include the second identity credential.
[0636] For example, as shown in FIG20 , when a visitor arrives and rings the doorbell, if the owner decides to open the door, the smartphone can perform user identity authentication using the fingerprint or face registered on the owner's smartphone.
[0637] S1930. After the identity authentication is passed, the second device sends an authentication result to the first device. The authentication result includes the second identity credentials used for authentication.
[0638] In an embodiment of the present application, after the second device passes the identity authentication, the second device may send an authentication result to the first device, and the authentication result may include credential information of the second identity credential used for authentication.
[0639] Optionally, the authentication result is presented as an authorization token (auth-token). This authorization token is a certificate of identity verification issued by the second device within the device's secure environment after the user's identity is successfully authenticated. This allows authentication of the user's identity and issuance of the certificate of identity verification within the device's secure environment only with the user's cooperation.
[0640] As a method, the authorization token may include at least one information including the user identification of the authenticated user, the authentication method used for authentication, a timestamp, and the credential information of the second identity credential used for authentication in addition to the credential information of the second identity credential used for authentication.
[0641] The user identifier of the authenticated user is the user identity confirmed when the identity authentication is passed, such as the first user.
[0642] The authentication method used corresponds to the type of identity credential, for example, a fingerprint-type identity credential corresponds to the fingerprint authentication method.
[0643] The credential information of the second identity credential used for authentication may include the credential identifier of the second identity credential, the device identifier of the device to which the second identity credential belongs (such as the device ID of the second device), and the association tag added to the second identity credential (such as the first association).
[0644] The integrity protection signature of the authorization token may be a signature of the authorization token by the second device using its own device private key.
[0645] Optionally, the device private key used to sign the authorization token here can be different from the device private key used to sign the proof of association for the credential. For example, the electronic device may include a first private key and a second private key. The first private key can be the private key of the token issuance / verification unit of the electronic device, used to sign the authorization token. The second private key can be the private key of the associat...
Claims
1. A method for associating identity credentials, characterized in that: A method for applying a first device to a communication system, wherein the communication system further includes a second device, includes: receiving a first request sent by the second device; In response to the first request, determining whether the user authorizes association of n identity credentials on the second device with m identity credentials on the first device, where n and m are positive integers; In response to the user's authorization, the n identity credentials are associated with the m identity credentials, and the association is used to indicate that the first device and the second device trust an identity authentication result based on the associated identity credentials.
2. The method according to claim 1, characterized in that The method further comprises: Obtain a second request triggered on the first device; In response to the second request, sending a first identity authentication request to the second device; receiving a first identity authentication result sent by the second device, where the first identity authentication result is a result of passing identity authentication when the second device performs local identity authentication; In response to the first identity authentication result, perform an operation corresponding to the second request.
3. The method according to claim 1, characterized in that The method further comprises: receiving a first identity authentication result sent by the second device, where the first identity authentication result is a result of identity authentication passing when the second device performs local identity authentication on a second request triggered on the second device; In response to the first identity authentication result, perform an operation corresponding to the second request.
4. The method according to any one of claims 1 to 3, characterized in that The method further comprises: receiving a second identity authentication request sent by the second device; performing local identity authentication in response to the second identity authentication request; After the identity authentication is passed, a second identity authentication result is sent to the second device.
5. The method according to any one of claims 1 to 4, characterized in that The identity authentication result includes the identity credentials used during identity authentication; or The identity authentication result includes the identity credentials used during identity authentication and the credential association certificate of the used identity credentials.
6. The method according to any one of claims 1 to 5, characterized in that Determining, in response to the first request, whether the user authorizes association of n identity credentials on the second device with m identity credentials on the first device includes: In response to the first request, output a first prompt, where the first prompt is used to prompt the user whether to authorize association of the n identity credentials on the second device with the m identity credentials on the first device; In response to an authorization operation performed by the user on the first device, determining that the user authorizes the association; or, Determining, in response to the first request, whether the user authorizes association of n identity credentials on the second device with m identity credentials on the first device includes: In response to the first request, determining whether the user authorizes on the second device to associate the n identity credentials on the second device with the m identity credentials on the first device; In response to an authorization operation performed by the user on the second device, it is determined that the user authorizes the association.
7. The method according to any one of claims 1 to 6, characterized in that The associating the n identity credentials with the m identity credentials in response to the user's authorization includes: In response to the user's authorization, performing local identity authentication; When the identity authentication is passed, the n identity credentials are associated with the m identity credentials.
8. The method according to claim 7, characterized in that The performing of local identity authentication in response to the user's authorization includes: In response to the user's authorization, output a second prompt, wherein the second prompt is used to prompt the user to enter identity authentication information; performing local identity authentication in response to an input operation by the user on the first device; or, The performing of local identity authentication in response to the user's authorization includes: In response to the user's authorization, obtaining identity authentication information input by the user on the second device; Based on the identity authentication information, local identity authentication is performed.
9. The method according to claim 7 or 8, characterized in that The performing of local identity authentication includes: Perform local identity authentication based on the authentication method corresponding to at least one of the m identity credentials.
10. The method according to any one of claims 1 to 9, characterized in that After associating the n identity credentials with the m identity credentials, the method further includes: A first response is sent to the second device, where the first response is used to indicate a successful association between the n identity credentials and the m identity credentials.
11. The method according to claim 10, characterized in that The first response includes at least one of the following: associated key; Proof of credential association; Indication of a successful association.
12. The method according to any one of claims 1 to 11, characterized in that The m identity credentials correspond to a first user, the n identity credentials correspond to a second user, and the first user and the second user are the same user or different users; or, The m identity credentials correspond to a first account, the n identity credentials correspond to a second account, and the first account and the second account are the same account or different accounts.
13. The method according to any one of claims 1 to 12, characterized in that The m identity credentials have been added to the first association, and determining whether the user authorizes the n identity credentials on the second device to be associated with the m identity credentials on the first device includes: Determine whether the user authorizes adding the n identity credentials on the second device to the first association.
14. The method according to any one of claims 1 to 13, characterized in that The method further comprises: Obtaining a third request triggered on the first device; In response to the third request, determining whether the user authorizes the (m+1)th identity credential on the first device to be associated with the m identity credentials; In response to the user's authorization, the (m+1)th identity credential is associated with the m identity credentials.
15. The method according to any one of claims 1 to 13, characterized in that The communication system further includes a third device, and the method further includes: Obtaining a third request triggered on the first device; In response to the third request, determining whether the user authorizes association of p identity credentials on the third device with the m identity credentials, where p is a positive integer; In response to the user's authorization, the p identity credentials are associated with the m identity credentials.
16. The method according to claim 15, characterized in that The m identity credentials correspond to a first user, the p identity credentials correspond to a third user, and the user authorization includes the authorization of the first user and the authorization of the third user; The associating the p identity credentials with the m identity credentials in response to the user's authorization includes: In response to the authorization of the first user, performing local identity authentication; After the identity authentication is passed, if the third identity authentication result sent by the third device is received, the p identity credentials are associated with the m identity credentials. The third identity authentication result is the result of the identity authentication passing when the third device performs local identity authentication for the authorization of the third user.
17. The method according to claim 15 or 16, characterized in that The p identity credentials, the n identity credentials, and the m identity credentials are successfully associated, and the method further includes: Obtaining a fourth request triggered on the first device; In response to the fourth request, sending a third identity authentication request to a target device, where the target device is the second device or the third device; receiving a fourth identity authentication result sent by the target device, where the fourth identity authentication result is a result of passing the identity authentication when the target device performs local identity authentication; In response to the fourth identity authentication result, an operation corresponding to the fourth request is performed.
18. The method according to claim 17, characterized in that The target device is a device selected by the user or a device that meets a preset condition, where the preset condition includes at least one of the following: The distance between the device and the user is less than a first threshold; The authentication security level of the identity credential associated with the device is greater than a second threshold; The frequency of use of the device is greater than a third threshold; The authentication method corresponding to the identity credentials associated with the device is compatible with the current environment; The device is in use.
19. A method for associating identity credentials, characterized in that: A second device is applied to a communication system, wherein the communication system further includes a first device, and the method includes: Sending a first request to the first device, where the first request is used to instruct the first device to associate n identity credentials on the second device with m identity credentials on the first device when determining user authorization, where n and m are positive integers; Receive a first response sent by the first device, where the first response is used to indicate a successful association between the n identity credentials and the m identity credentials, and the association is used to indicate that the first device and the second device trust an identity authentication result based on the associated identity credentials.
20. The method according to claim 19, characterized in that The method further comprises: Obtain a second request triggered on the second device; In response to the second request, performing local identity authentication; After the identity authentication is passed, a first identity authentication result is sent to the first device, where the first identity authentication result is used to instruct the first device to perform an operation corresponding to the second request.
21. The method according to claim 19 or 20, characterized in that The identity authentication result includes the identity credentials used during identity authentication; or The identity authentication result includes the identity credentials used during identity authentication and the credential association certificate of the used identity credentials.
22. The method according to any one of claims 19 to 21, characterized in that The sending the first request to the first device includes: Output a first prompt, where the first prompt is used to prompt the user whether to authorize association of n identity credentials on the second device with m identity credentials on the first device; In response to an authorization operation performed by the user on the second device, sending a first request to the first device; or, After sending the first request to the first device, the method further includes: receiving a first instruction from the first device; In response to the first instruction, output a first prompt, where the first prompt is used to prompt the user whether to authorize association of n identity credentials on the second device with m identity credentials on the first device; In response to the user's authorization operation on the second device, an authorization indication is sent to the first device.
23. The method according to claim 22, characterized in that The sending a first request to the first device in response to the user's authorization operation on the second device includes: In response to the user's authorization operation on the second device, outputting a second prompt, where the second prompt is used to prompt the user to enter identity authentication information; In response to an input operation by the user on the second device, sending a first request to the first device, wherein the first request is used to instruct the first device to perform local identity authentication based on the identity authentication information input by the user on the second device when determining user authorization; or, The sending an authorization indication to the first device in response to the user's authorization operation on the second device includes: In response to the user's authorization operation on the second device, outputting a second prompt, where the second prompt is used to prompt the user to enter identity authentication information; In response to the user's input operation on the second device, an authorization indication is sent to the first device, where the authorization indication is used to instruct the first device to perform local identity authentication based on the identity authentication information input by the user on the second device when determining user authorization.
24. The method according to any one of claims 19 to 23, characterized in that The first response includes at least one of the following: associated key; Proof of credential association; Indication of a successful association.
25. The method according to any one of claims 19 to 24, characterized in that The m identity credentials have been added to the first association, and the sending of the first request to the first device includes: Displaying a first interface, wherein the first interface includes at least one association, and the at least one association includes the first association; In response to the user's selection of the first association, a first request is sent to the first device, where the first request is used to instruct the first device to add n identity credentials on the second device to the first association when determining user authorization.
26. The method according to claim 25, characterized in that The communication system further includes other devices, and identity credentials exist on the other devices and have been added to the first association; The sending a first request to the first device in response to the user selecting the first association includes: In response to a user selecting the first association, sending a first request to the first device and the other device; or, The sending a first request to the first device in response to the user selecting the first association includes: In response to the user's selection of the first association, a first request is sent to the first device among the first device and the other devices, where the first device is the device selected by the user or the device that meets a preset condition.
27. The method according to claim 26, characterized in that The preset conditions include at least one of the following: The distance between the device and the user is less than a first threshold; The authentication security level of the identity credential associated with the device is greater than a second threshold; The frequency of use of the device is greater than a third threshold; The authentication method corresponding to the identity credentials associated with the device is compatible with the current environment; The device is in use.
28. The method according to any one of claims 19 to 27, characterized in that The communication system further includes a third device, and after receiving the first response sent by the first device, the method further includes: receiving a third request sent by the third device; In response to the third request, determining whether the user authorizes association of p identity credentials on the third device with the n identity credentials and the m identity credentials, where p is a positive integer; In response to the user's authorization, the p identity credentials are associated with the n identity credentials and the m identity credentials, and the association is used to instruct the first device, the second device and the third device to trust the identity authentication result based on the associated identity credentials.
29. The method according to any one of claims 19 to 28, characterized in that The communication system further includes a third device, and the p identity credentials on the third device are successfully associated with the n identity credentials and the m identity credentials. The method further includes: Obtain a second request triggered on the second device; In response to the second request, sending a first identity authentication request to the third device; receiving a second identity authentication result sent by the third device, where the second identity authentication result is a result of passing the identity authentication when the third device performs local identity authentication; The second identity authentication result is sent to the first device, where the second identity authentication result is used to instruct the first device to perform an operation corresponding to the second request.
30. An electronic device, characterized in that: The electronic device includes a processor and a memory, the memory is used to store instructions, and the processor is used to call the instructions in the memory, so that the electronic device executes the method according to any one of claims 1 to 18, or executes the method according to any one of claims 19 to 29.
31. A chip system, characterized in that: The chip system is applied to an electronic device; the chip system includes an interface circuit and a processor; the interface circuit and the processor are interconnected through lines; the interface circuit is used to receive signals from the memory of the electronic device and send signals to the processor, the signals including instructions stored in the memory; when the processor executes the instructions, the chip system executes the method according to any one of claims 1 to 18, or executes the method according to any one of claims 19 to 29.
32. A readable storage medium, characterized in that The method comprises a program, which, when executed on an electronic device, causes the electronic device to execute the method according to any one of claims 1 to 18, or the method according to any one of claims 19 to 29.
33. A communication system, characterized in that: The communication system includes a first device and a second device, the first device is configured to execute the method according to any one of claims 1 to 18, and the second device is configured to execute the method according to any one of claims 19 to 29.
Citation Information
Patent Citations
Display method and device
CN111917916A
Identity credential application method, identity authentication method, equipment and device
CN113872765A
User login method and electronic equipment
CN117131481A
System and method for processing a digital transaction
US20190012674A1