Credential management method, and device

By using user accounts to associate target credentials with authentication in electronic devices, automated credential management is achieved, solving the problems of complex credential storage and insufficient security, and improving convenience and security.

WO2026103528A1PCT designated stage Publication Date: 2026-05-21HUAWEI TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
HUAWEI TECH CO LTD
Filing Date
2025-10-30
Publication Date
2026-05-21

AI Technical Summary

Technical Problem

The process of saving and managing credentials on electronic devices is complex and inconvenient, resulting in a poor user experience. Credentials are also easily leaked or reset, leading to insufficient security.

Method used

By associating target credentials with user accounts and using authentication information for credential management, the system enables automated storage and transmission of credentials, ensuring that credentials can only be obtained or used after successful authentication.

Benefits of technology

It improves the convenience and security of credential management, prevents credential leakage and reset, and enhances the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025131276_21052026_PF_FP_ABST
    Figure CN2025131276_21052026_PF_FP_ABST
Patent Text Reader

Abstract

The embodiments of the present application relate to the technical field of electronic devices. Provided are a credential management method, and a device. The method is applied to a first device, and comprises: a first device determining that a user account is to be used to associate a target credential, wherein the target credential is used for encrypting user data managed by the first device; the first device further acquiring identity verification information of a user on the basis of the determination that the user account is to be used to associate the target credential; and the first device further sending the target credential to a third device when determining, on the basis of the identity verification information, that the identity verification of the user is successful. Therefore, it is not necessary for a user to manually save a target credential, thereby improving the convenience of credential management. Furthermore, the user can subsequently acquire the target credential only upon successful identity verification, such that the flexibility and security of credential management are improved.
Need to check novelty before this filing date? Find Prior Art

Description

A credential management method and device

[0001] This application claims priority to Chinese Patent Application No. 202411639268.X, filed on November 15, 2024, entitled "A Method and Device for Voucher Management", the entire contents of which are incorporated herein by reference. Technical Field

[0002] This application relates to the field of electronic equipment technology, and in particular to a credential management method and device. Background Technology

[0003] Currently, when users access functions such as account login, online transactions, or resource transfers on electronic devices, the devices require user authentication before these functions can be executed, allowing users to use these functions normally. For example, users can use credentials to authenticate on electronic devices. Credentials can include account passwords, keys, and identity tokens.

[0004] However, the composition of credentials is often complex and highly random, leading users to copy them onto physical slips of paper or take photos during the saving process. This manual saving method is inconvenient and reduces the user experience. Summary of the Invention

[0005] This application provides a credential management method and device that manages credentials by associating target credentials with user accounts and combining user authentication, thereby improving the convenience and security of credential management.

[0006] To achieve the above objectives, this application adopts the following technical solution:

[0007] Firstly, this application provides a credential management method applied to a first device. The method includes: the first device determining that a target credential is associated with a user account, the target credential being used to encrypt user data managed by the first device; the first device also obtaining user authentication information based on determining that the target credential is associated with a user account; and the first device further sending the target credential to a third device if it determines that the user's authentication is successful based on the authentication information.

[0008] Therefore, this embodiment of the application eliminates the need for users to manually save target credentials, improving the convenience of credential management. Furthermore, this embodiment also provides a method for saving target credentials by associating them with the user account after successful user authentication. Subsequent users will still need to authenticate to obtain the target credentials. This enhances the flexibility and security of credential management. Thus, even if a user account is leaked, the target credentials will not be easily leaked or reset, thereby improving the user experience.

[0009] In one feasible approach, during the process of the first device acquiring the user's authentication information, a second interface can be displayed. This second interface prompts the user to perform authentication. The first device can also acquire input actions related to the second interface to determine the authentication information.

[0010] Therefore, this embodiment of the application requires determining the user's authentication information after the user enters the authentication information. This facilitates the subsequent storage of target credentials using the user account once the user's authentication is successful. This improves the flexibility and security of credential management.

[0011] In one feasible approach, during the process of obtaining the user's authentication information, the first device obtains the authentication information of the user during authentication, provided that the user has authenticated before associating the target credentials with the user account.

[0012] Thus, this application embodiment can directly obtain the user's authentication information when the user has already authenticated. This facilitates the subsequent storage of target credentials using the user account after successful user authentication. It improves the flexibility, security, and user convenience of credential management.

[0013] In one possible implementation, the first device may further display a first interface, which includes at least one method for storing the target credentials. During the process of determining whether to associate the target credentials with a user account, the first device may obtain a first operation on the first interface, determining a first method among the at least one storage method, the first method being used to instruct the association of the target credentials with a user account.

[0014] Thus, this application embodiment can provide users with multiple methods for saving target credentials, including a first method. After the user selects the first method, the first device can associate the target credentials with the user account. This eliminates the need for the user to manually save the target credentials, improving the convenience of credential management.

[0015] In one possible implementation, the first device may further acquire a second operation for the first interface, determining a second method among at least one storage method, the second method being used to instruct the storage of the target credentials using a trusted device corresponding to the first device. The first device may also acquire the user's authentication information based on the second method.

[0016] Thus, the second method is included among the various methods for storing the target credentials in this application embodiment. After the user selects the second method, the first device can utilize a trusted device to store the target credentials. This eliminates the need for the user to manually save the target credentials, improving the convenience of credential management.

[0017] In one possible implementation, during the process of sending the target credentials to the third device, the first device may send an identifier used to index the target credentials to the third device. This identifier includes a user identifier and / or a device identifier of the first device.

[0018] Thus, in this embodiment, the identifier used to index the target credential can also be sent to a third device, so that the third device can store the target credential based on the identifier used to index the target credential. This eliminates the need for users to manually save the target credential, improving the convenience of credential management.

[0019] In one possible implementation, the user data managed by the first device includes at least one of the following: data locally stored on the first device, data stored by the user on a server or a remote user device that can be managed by the first device, or data in a device directly connected to the first device.

[0020] In one possible implementation, the first device can also send an authentication request to the server, the authentication request including authentication information, the authentication request being used to request the server to authenticate the user based on the received authentication information.

[0021] The identity verification information includes the user's name information and ID card information, as well as at least one of the following: the user's bank card information, the bank's registered mobile phone number, or the user's current biometric information. The ID card information includes the ID card number or an image of the ID card.

[0022] Thus, the first device in this application embodiment can determine whether user authentication is successful based on authentication information, which may include real-name authentication. Target credentials can only be stored after successful user authentication. This improves the flexibility and security of credential management. Therefore, even if a user account is leaked, the target credentials will not be easily leaked or reset. This, in turn, enhances the user experience.

[0023] In one possible implementation, during the display of the first interface, the first device can acquire a trigger operation for the target functional interface, display the first interface, and the trigger operation is used to indicate the activation of the target credentials.

[0024] Thus, in this embodiment, after the first device enables the target function, it triggers the display of the first interface to prompt the user to select a method for saving the target credentials. By providing the target function, the user can enable and manage the target credentials, thereby improving the user experience and the flexibility of interaction with the first device.

[0025] In one feasible approach, the first device may also generate target credentials and use those target credentials to encrypt user data managed by the first device.

[0026] Thus, by encrypting user data managed by the first device using the generated target credentials, the embodiments of this application can improve the security of user data managed by the first device during transmission and storage. This, in turn, enhances the user experience.

[0027] In one feasible approach, the first device may encrypt the target credentials using a preset encryption rule and send the encrypted target credentials to the third device during the process of sending the target credentials to the third device.

[0028] Thus, by encrypting the target credentials, the embodiments of this application can improve the security during the transmission and storage of the target credentials.

[0029] In one feasible approach, the third device includes a server and / or a trusted device of the first device.

[0030] Secondly, embodiments of this application provide a credential management method applied to a second device, the method comprising:

[0031] The second device can perform migration operations on the target data, including user account verification. The target data is part or all of the user data managed by the first device. If the user account verification is successful, the second device can obtain the user's authentication information. Furthermore, if the second device determines that the user's authentication is successful based on the authentication information, it can send a credential retrieval request to the third device. This request retrieves the target credentials corresponding to the target data, which are then used to decrypt the target data, enabling the migration of the target data to the second device. The second device then receives the target credentials sent by the third device.

[0032] Thus, in this embodiment, the second device can obtain the target credentials after the user account verification and identity verification are successful, thereby migrating the target data to the second device. This improves the flexibility and security of credential management, ultimately enhancing the user experience.

[0033] In one possible implementation, the second device can display a third interface while acquiring the user's authentication information. This third interface prompts the user to authenticate. The second device can also acquire input from the third interface to confirm the authentication information.

[0034] Therefore, this embodiment of the application requires determining the user's authentication information after the user enters the authentication information. This facilitates the subsequent acquisition of target credentials once the user's authentication is successful, thereby improving the flexibility and security of credential management.

[0035] In one feasible approach, during the process of obtaining user authentication information, the second device can send an information retrieval request to its trusted device. This request is used to obtain the authentication information. The second device can also receive authentication information sent by its trusted device.

[0036] Thus, this application embodiment also supports entering user authentication information on a trusted device, avoiding situations where the user cannot complete user authentication if they are not near a second device. This improves the flexibility and convenience of user authentication.

[0037] In one possible implementation, the second device can send an authentication request to the server, the authentication request including authentication information, the authentication request being used to request the server to authenticate the user based on the received authentication information.

[0038] The identity verification information includes the user's name information and the user's ID card information, as well as at least one of the following: the user's bank card information, the bank's registered mobile phone number, or the user's current biometric information. The ID card information includes the ID card number or ID card image information.

[0039] Thus, in the process of acquiring the target credentials, the second device in this application embodiment can determine whether the user's authentication has passed based on the authentication information, which may include real-name authentication. The target credentials can only be acquired after the user's authentication is successful. This improves the flexibility and security of credential management. Therefore, even if a user account is leaked, the target credentials will not be easily leaked or reset. This, in turn, enhances the user experience.

[0040] In one feasible approach, the second device can acquire encrypted target data, which is encrypted based on target credentials. The second device can also decrypt the encrypted target data using the target credentials, obtain the target data, and then save and display it.

[0041] Thus, this embodiment of the application can decrypt encrypted target data using the target credentials after obtaining them, and directly display the target data. This eliminates the need for users to manually input the target credentials and directly displays the target data, improving user convenience.

[0042] In one feasible approach, after receiving the target credentials sent by the third device, the second device can also display the target credentials.

[0043] Thus, this embodiment of the application can directly display the target credential after it has been obtained. Users can also save the target credential, improving the flexibility of target credential management and the ease of use for users.

[0044] In one feasible approach, the second device can display a decryption interface that prompts the user to decrypt the encrypted target data. The second device can also receive input from the decryption interface, decrypt the encrypted target data using the target credentials, obtain the target data, and then save and display the target data.

[0045] Thus, this embodiment of the application can decrypt encrypted target data based on the target credentials entered by the user after obtaining the target credentials, and directly display the target data. This eliminates the need for the user to manually enter the target credentials and directly displays the target data, improving user convenience.

[0046] Thirdly, embodiments of this application provide a credential management method applied to a third device, the third device including a server, the method comprising:

[0047] Once the server confirms that the user authentication corresponding to the first device is successful, it can receive the target credentials sent by the first device. The target credentials are used to decrypt some or all of the user data managed by the first device, so as to migrate some or all of the user data to the second device.

[0048] The server can also send target credentials to the second device if it determines that the user authentication corresponding to the second device has been successful.

[0049] Thus, in this embodiment, the server can receive the target credentials sent by the first device after confirming that the user authentication corresponding to the first device has passed. The server can also send the target credentials to the second device after confirming that the user authentication corresponding to the second device has passed. This eliminates the need for users to manually save the target credentials, improving the flexibility and security of target credential management.

[0050] In one possible implementation, the server can also receive a verification request sent by the first device, the verification request including authentication information. If the authentication information is present, the server determines that the user corresponding to the first device has been successfully authenticated.

[0051] The server can also receive authentication requests from the second device, which include authentication information. If the authentication information sent by the second device matches the authentication information sent by the first device, the server determines that the user authentication of the second device is successful.

[0052] Thus, in this embodiment, the server can determine whether the user's identity verification is successful based on the authentication information sent by the first device and the second device. This facilitates the subsequent execution of the processes of saving and retrieving target credentials by the first and second devices, respectively. This improves the flexibility and security of the target credential management process.

[0053] Fourthly, embodiments of this application provide a communication system, which includes a first device and a second device.

[0054] The first device is configured to determine whether to associate target credentials with a user account, the target credentials being used to encrypt user data managed by the first device.

[0055] The first device is also configured to obtain the user's authentication information based on the target credentials associated with the user account.

[0056] The first device is also configured to send target credentials to the third device if the user's authentication is successful based on the authentication information. The target credentials are used to decrypt some or all of the data in the user data to achieve the migration of some or all of the data in the user data to the second device.

[0057] The second device is configured to perform migration operations on the target data and perform user account verification. The target data is part or all of the user data managed by the first device.

[0058] The second device is also configured to obtain the user's identity verification information if the user's account verification is successful.

[0059] The second device is also configured to send a credential retrieval request to the third device if the user's authentication is successful based on the authentication information. The credential retrieval request is used to retrieve the target credentials corresponding to the target data.

[0060] The second device is also configured to receive target credentials sent by the third device.

[0061] Fifthly, embodiments of this application provide a credential management method applied to a communication system, the communication system including a first device and a second device, the method comprising:

[0062] The first device determines to use the user account to associate target credentials, which are used to encrypt user data managed by the first device.

[0063] The first device obtains the user's identity verification information by determining the target credentials associated with the user account.

[0064] If the first device determines that the user's authentication is successful based on the authentication information, it sends the target credentials to the third device. The target credentials are used to decrypt part or all of the user data to achieve the migration of part or all of the user data to the second device.

[0065] The second device acquires the migration operation for the target data and performs user account verification. The target data is part or all of the user data managed by the first device.

[0066] Once the user's account is verified, the second device obtains the user's identity verification information.

[0067] If the second device determines that the user's authentication is successful based on the authentication information, it sends a credential retrieval request to the third device. The credential retrieval request is used to obtain the target credentials corresponding to the target data.

[0068] The second device receives the target credentials sent by the third device.

[0069] In a sixth aspect, embodiments of this application provide an electronic device, which includes a memory and one or more processors; the memory is coupled to the processors; wherein the memory stores computer program code, which includes computer instructions, and when the computer instructions are executed by the processor, the electronic device performs the method described in the first aspect above, or performs the method described in the second aspect above.

[0070] In a seventh aspect, embodiments of this application provide a computer-readable medium storing instructions that, when executed on an electronic device, cause the electronic device to perform the method described in the first aspect above, or to perform the method described in the second aspect above.

[0071] Eighthly, embodiments of this application provide a computer program product containing instructions that, when executed on a computer or processor, cause the computer or processor to perform the method described in the first aspect above, or to perform the method described in the second aspect above. Attached Figure Description

[0072] Figure 1 is a schematic diagram of an interface for a credential provided in an embodiment of this application;

[0073] Figure 2 is a schematic diagram of the structure of a communication system provided in an embodiment of this application;

[0074] Figure 3 is a schematic diagram of the hardware structure of a laptop computer provided in an embodiment of this application;

[0075] Figure 4 is a flowchart illustrating a credential management method provided in an embodiment of this application;

[0076] Figure 5 is a schematic diagram of a target function interface provided in an embodiment of this application;

[0077] Figure 6 is a schematic diagram of a first interface provided in an embodiment of this application;

[0078] Figure 7 is a schematic diagram of a verification prompt information interface provided in an embodiment of this application;

[0079] Figure 8 is a schematic diagram of a data selection interface provided in an embodiment of this application;

[0080] Figure 9 is a schematic diagram of a target application interface provided in an embodiment of this application;

[0081] Figure 10 is a schematic diagram of an account verification interface provided in an embodiment of this application;

[0082] Figure 11 is a schematic diagram of a verification prompt information interface provided in an embodiment of this application;

[0083] Figure 12 is a schematic diagram of a process for displaying target data according to an embodiment of this application;

[0084] Figure 13 is a schematic diagram of an interface for displaying target credentials provided in an embodiment of this application;

[0085] Figure 14 is a schematic diagram of the structure of multiple modules in an electronic device provided in an embodiment of this application;

[0086] Figure 15 is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0087] The technical solutions of the embodiments of this application will be described below with reference to the accompanying drawings. In the description of this application, unless otherwise stated, " / " indicates that the objects before and after are in an "or" relationship. For example, A / B can represent A or B. "And / or" in this application is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, and B alone, where A and B can be singular or plural. Furthermore, in the description of this application, unless otherwise stated, "multiple" refers to two or more. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple. In addition, in order to clearly describe the technical solutions of the embodiments of this application, the terms "first" and "second" are used in the embodiments of this application to distinguish the same or similar items with basically the same function and effect.

[0088] Those skilled in the art will understand that the terms "first," "second," etc., do not limit the quantity or order of execution, and that "first," "second," etc., are not necessarily different. Furthermore, in some embodiments of this application, words such as "exemplary" or "for example" are used to indicate that something is being described as an example, illustration, or description. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner for ease of understanding.

[0089] Furthermore, the device architecture and business scenarios described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of device architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.

[0090] When users use functions such as account login, online transactions, or resource transfer on electronic devices, the electronic devices can only perform these functions after the user has been authenticated.

[0091] For example, in a scenario where a user uses an electronic device to transfer resources (such as data migration), in order to successfully recover data after loss, the user needs to create credentials corresponding to the data to protect its security, so that these credentials can be used for subsequent data recovery. The electronic device will generate and display the credentials corresponding to the data for the user to save. Simultaneously, during the subsequent data recovery process, the electronic device needs to verify the user's identity before using the credentials to perform the data recovery process.

[0092] Credentials refer to data declared to prove a user's identity. Credentials can include account passwords, keys, and identity tokens (GitHub access tokens), etc. Credentials can also be understood as credentials used to authenticate data.

[0093] To enhance the security of the authentication process, credentials are typically complex and highly randomized. Referring to Figure 1(A), electronic devices in related technologies can display credentials within the current user interface. Users can save credentials by copying them onto a physical piece of paper or taking a photograph. Manual saving requires a series of complex operations and is not very convenient. Furthermore, the credentials cannot be viewed after exiting the current interface, thus reducing the user experience.

[0094] Referring to Figure 1(B), the electronic device in the related technology can prompt the user to associate credentials with their internet account, such as "Allow internet account to unlock data." In this way, the user can subsequently obtain credentials through their internet account. Also, referring to Figure 1(C), the user can reset credentials after logging into their internet account and verifying their identity (such as SMS verification code verification). However, if the internet account is compromised, the credentials can be easily reset, leading to user data leakage. The above-mentioned methods of credential management have low security, thus reducing the user experience.

[0095] To address the aforementioned technical problems, embodiments of this application provide a credential management method. The method includes: a first device determining that a target credential is associated with a user account, the target credential being used to encrypt user data managed by the first device; the first device also obtaining user authentication information based on the determination that the target credential is associated with a user account; and the first device further sending the target credential to a third device if the user's authentication is successful based on the authentication information, the target credential being used to decrypt some or all of the user data, thereby migrating some or all of the user data to a second device.

[0096] In other words, users can associate target credentials with their user accounts. Furthermore, before associating target credentials with user accounts, the first device obtains the user's authentication information, and only after the user's authentication is successful can the target credentials be sent to the third device.

[0097] Therefore, this embodiment eliminates the need for users to manually save target credentials, improving the convenience of credential management. Furthermore, this embodiment provides a method for saving target credentials by associating them with the user account after successful user authentication. Subsequent user authentication is still required to retrieve the target credentials. This enhances the flexibility and security of credential management. Consequently, even if a user account is leaked, the target credentials will not be easily leaked or reset, thus improving the user experience.

[0098] The credential management method provided in this application embodiment can be applied to a communication system. Referring to Figure 2, a communication system provided in this application embodiment includes a first device 101 (e.g., a user's first laptop), a second device 102 (e.g., a user's second laptop), a trusted device 103 (e.g., a user's mobile phone), and a server 104.

[0099] In some embodiments, a communication connection is established between the first device 101, the second device 102, the trusted device 103, and the server 104. The server 104 can serve as an interaction medium between the first device 101, the second device 102, and the trusted device 103. The server 104 is used to execute the corresponding credential management services in the embodiments of this application to complete communication between devices. The server 104 can be implemented as a server cluster consisting of multiple servers, or as a single server.

[0100] The trusted device 103 can be a device that has established a trusted relationship with the first device 101 and / or the second device 102. For example, the two devices may be logged into the same user account. Another example is that the user accounts logged into by the two devices are related accounts.

[0101] In some embodiments, the first device 101, the second device 102, and the trusted device 103 may include a wired communication connection or a wireless communication connection. The communication connection established between the server 104 and the aforementioned devices may include a wireless communication connection.

[0102] In some embodiments, the wireless communication technologies used to establish wireless communication connections include, but are not limited to, at least one of the following: wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT) (e.g., classic Bluetooth or Bluetooth Low Energy (BLE) Bluetooth), near field communication (NFC), Zigbee, frequency modulation (FM), and infrared (IR).

[0103] In some examples, the first device stores the target data, such as user data managed by the first device. When a user migrates the target data from the first device to a second device, the security of the data migration can be improved by setting target credentials to protect the target data. Furthermore, the set target credentials can be used to retrieve the target data subsequently.

[0104] The process of migrating user data managed by the first device may include the process of the second device acquiring the user data managed by the first device from the first device. For example, the second device may acquire the user data managed by the first device from a storage device in the first device. Another example is that the user data managed by the first device is stored in a third device, and the second device acquires the user data managed by the first device from the third device. The third device may include a trusted device of the first device, a server, etc.

[0105] Currently, the process of migrating user data managed by the first device may also include the process of setting and / or obtaining target credentials for the user data managed by the first device. For example, setting the storage method of the target credentials on the first device side, such as associating the target credentials with a user account. Another example is the process of obtaining the target credentials using a user account on the second device side.

[0106] Understandably, target credentials can act as a "key" to target data, enabling the encryption and decryption of some or all of the data. Target credentials can also identify the user; only the user with the "key" can "unlock" or "lock" the target data.

[0107] In some examples, the first device can send the target credentials to a third device, allowing the third device to hold the target credentials. The second device can also complete the authentication process through the third device.

[0108] In some embodiments, the first device 101, the second device 102, and the trusted device 103 may include at least one of the following: laptop computer, desktop computer, mobile phone, foldable electronic device, tablet computer, desktop computer, laptop computer, handheld computer, ultra-mobile personal computer (UMPC), netbook, cellular phone, personal digital assistant (PDA), augmented reality (AR) device, virtual reality (VR) device, artificial intelligence (AI) device, wearable device, in-vehicle device, smart home device, or smart city device. This application embodiment does not impose any special limitations on the specific types of the first device 101, the second device 102, and the trusted device 103.

[0109] The operating systems installed on the first device 101, the second device 102, and the trusted device 103 include, but are not limited to, those that ... installed on the first device 101, the second device 102, and the trusted device 103. Alternatively, other operating systems may be used. Of course, electronic devices may not have an operating system installed. This application does not limit the specific types of the first device 101, the second device 102, and the trusted device 103, whether or not they have an operating system installed, or the type of operating system if they do have an operating system installed.

[0110] Of course, the communication system provided in this application embodiment may also include other electronic devices besides the first device 101, the second device 102, the trusted device 103, and the server 104. The communication system provided in this application embodiment includes, but is not limited to, information interaction between four devices, and may also include information interaction between one device and multiple devices. Those skilled in the art can determine the type and number of electronic devices according to actual needs, and these designs do not exceed the protection scope of this application embodiment.

[0111] The first device 101, the second device 102, and the trusted device 103 in this application embodiment can be implemented using different or the same devices. For example, the first device 101 and the second device 102 in this application embodiment can be implemented using the laptop computer 100 in FIG3.

[0112] Figure 3 shows a schematic diagram of the hardware structure of a laptop computer provided in an embodiment of this application.

[0113] As shown in Figure 3, the laptop 100 may include: a processor 120, an external memory interface 130, an internal memory 131, a universal serial bus (USB) interface 140, a charging management module 150, a power management module 151, a battery 152, an antenna, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, a headphone jack 170D, a sensor module 180, buttons 190, a motor 191, an indicator 192, a camera 193, and a display screen 194, etc.

[0114] It is understood that the structures illustrated in the embodiments of this application do not constitute a specific limitation on the laptop computer 100. In other embodiments of this application, the laptop computer 100 may include more or fewer components than illustrated, or combine some components, or split some components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.

[0115] Processor 120 may include one or more processing units, such as: application processor (AP), modem processor, graphics processing unit (GPU), image signal processor (ISP), controller, memory, video codec, digital signal processor (DSP), baseband processor, and / or neural network processing unit (NPU), etc. Different processing units may be independent devices or integrated into one or more processors.

[0116] The controller can serve as the central nervous system and command center of the laptop computer 100. Based on the instruction opcode and timing signals, the controller generates operation control signals to control the fetching and execution of instructions.

[0117] The processor 120 may also include a memory for storing instructions and data. In some embodiments, the memory in the processor 120 is a cache memory. This memory can store instructions or data that the processor 120 has just used or that are used repeatedly. If the processor 120 needs to use the instruction or data again, it can retrieve it directly from the memory. This avoids repeated accesses, reduces the waiting time of the processor 120, and thus improves the efficiency of the system.

[0118] In some embodiments, the processor 120 may include one or more interfaces. Interfaces may include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface, etc.

[0119] The wireless communication function of the laptop 100 can be achieved through an antenna, a wireless communication module 160, a modem processor, and a baseband processor.

[0120] Antennas are used to transmit and receive electromagnetic wave signals. Each antenna in the laptop 100 can be used to cover one or more communication frequency bands. Different antennas can also be reused to improve antenna utilization.

[0121] In other embodiments, the antenna can be used in conjunction with a tuning switch.

[0122] The wireless communication module 160 can provide solutions for wireless communication applications on the laptop 100, including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), and infrared (IR) technologies. The wireless communication module 160 can be one or more devices integrating at least one communication processing module. The wireless communication module 160 receives electromagnetic waves via an antenna, performs frequency modulation and filtering of the electromagnetic wave signals, and sends the processed signal to the processor 120. The wireless communication module 160 can also receive signals to be transmitted from the processor 120, perform frequency modulation and amplification, and convert them into electromagnetic waves for radiation via the antenna.

[0123] The laptop computer 100 implements display functions through a GPU, a display screen 194, and an application processor. The GPU is a microprocessor for image processing, connecting the display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. The processor 120 may include one or more GPUs, which execute program instructions to generate or modify display information.

[0124] Display screen 194 is used to display user interfaces, etc.

[0125] For example, the user interface can be used to prompt the user to authenticate. As another example, the user interface can display the target credentials. As yet another example, the user interface can be used to display the association method (also known as the storage method) corresponding to the target credentials.

[0126] The display screen 194 includes a display panel. The display panel may be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a minimized display, a microLED, a quantum dot light-emitting diode (QLED), etc. In some embodiments, the laptop computer 100 may include one or N displays 194, where N is a positive integer greater than 1.

[0127] The laptop computer 100 can achieve shooting functions through ISP, camera 193, video codec, GPU, display 194 and application processor.

[0128] The ISP (Image Signal Processor) is used to process data fed back from the camera 193. For example, when taking a picture, the shutter is opened, and light is transmitted through the lens to the camera's photosensitive element. The light signal is converted into an electrical signal, and the camera's photosensitive element transmits the electrical signal to the ISP for processing, transforming it into an image visible to the naked eye. The ISP can also perform algorithmic optimization of image noise, brightness, and skin tone. The ISP can also optimize parameters such as exposure and color temperature of the shooting scene. In some embodiments, the ISP can be set in the camera 193.

[0129] The laptop computer 100 can perform audio functions, such as music playback and recording, through an audio module 170, speakers 170A, receiver 170B, microphone 170C, headphone jack 170D, and application processor.

[0130] The following will use a laptop computer as an example to specifically describe the credential management method provided in the embodiments of this application.

[0131] Figure 4 is a flowchart illustrating a credential management method according to an embodiment of this application. As shown in Figure 4, the method may include the following steps S401-S404.

[0132] S401, The first device responds to the user's trigger operation and enables the target credentials corresponding to the user data managed by the first device.

[0133] S402. The first device sends a credential management request to the server. The credential management request includes the target credential.

[0134] In some embodiments of this application, when a user performs resource transfer using a first device, such as migrating user data managed by the first device, the user data managed by the first device can be protected. For example, a user can encrypt the user data managed by the first device using target credentials generated by the first device and store the target credentials so that the user data managed by the first device can be retrieved on other devices later using the target credentials. This completes the data migration process. For ease of description later, the user data managed by the first device will be referred to as user data.

[0135] The target credentials are used to encrypt user data, or to decrypt part or all of the user data.

[0136] In some examples, the user data managed by the first device includes at least one of the following: data stored locally on the first device, data stored by the user on a server or a remote user device that can be managed by the first device, or data in a device directly connected to the first device.

[0137] In other words, a user can first encrypt user data using a target credential via a first device. Subsequently, the user can obtain the target credential through other devices. Then, the target credential can be used to decrypt part or all of the encrypted user data to retrieve that part or all of the data. Since only the user knows the target credential, it can also be used to identify the user during data migration. Thus, in this embodiment, the target credential can not only be used to encrypt user data, decrypt part or all of the user data, and retrieve user data, but also to verify user identity.

[0138] In some embodiments of this application, the first device can display a target function interface corresponding to the target function, and the user can perform a trigger operation on the target function interface to use the target function.

[0139] For example, the target function may include encryption functionality for user data. For instance, data encryption protection and recovery functionality. It should be noted that this application embodiment does not specifically limit the name corresponding to the target function.

[0140] Specifically, the first device can respond to the user's trigger operation, that is, the trigger operation for the target function interface, and start the target function.

[0141] For example, the first device may be a user's first laptop. The aforementioned target function may include encryption protection for one or more files on a disk in the first laptop. The aforementioned target function may also include encryption protection for all files on a disk in the first laptop.

[0142] It should be noted that the embodiments of this application do not limit the amount or format of user data.

[0143] In one possible implementation, the target functional interface may include a target control, and the aforementioned triggering operation is an operation performed on the target control.

[0144] For example, the first device can activate the target function corresponding to the target control in response to an activation operation. Subsequently, after activating the target function, the first device can generate target credentials corresponding to the user data and use the target credentials to encrypt the user data.

[0145] In some examples, the triggering method for the above target function can be in the form of an independent switch, such as presented in the interface of the application in the first device.

[0146] For example, referring to Figure 5(A), the management interface of the application settings in the first device may include a function control 501 corresponding to the target function, such as a function control 501 corresponding to data encryption protection and recovery. The user can click on the function control 501, and the mobile phone responds to the user's click on the function control 501 by triggering entry into the target function interface.

[0147] Referring to Figure 5(B), the target function interface includes target controls, such as the recovery credential control 502 corresponding to the data encryption service. Users can click on the recovery credential control 502, and the mobile phone responds to the user's operation of opening the recovery credential control 502 by enabling the target function.

[0148] Of course, if the target function is enabled, the user can click on the restore credentials control 502 again. The phone will then respond to the user's action of closing the restore credentials control 502 and disable the target function. It should be noted that the above is only an example using the settings application and target function interface; this application embodiment does not limit the specific location of the target control.

[0149] In another possible approach, the triggering method corresponding to the target function can also be in the form of an integrated switch, such as integrating the target function with a mode switch such as privacy mode.

[0150] For example, continuing to refer to Figure 5(A), the management interface of the settings application in the first device may include a privacy control corresponding to the privacy mode, such as privacy control 503. The user can click on privacy control 503, and the phone responds to the user's click on privacy control 503 by enabling privacy mode and the target function. It should be noted that the above is only an example of privacy mode, and this application embodiment does not specifically limit the mode integration method.

[0151] In other examples, the target function can also be triggered via a physical button.

[0152] For example, referring to Figure 5(C), the first device may have a physical button 504 corresponding to the target function on its housing. The user can press the physical button 504, and the phone will activate the target function in response to the user's press of the physical button 504. Of course, when the target function is activated, the user can press the physical button 504 again, and the phone will deactivate the target function in response to the user's press of the physical button 504.

[0153] It should be noted that the embodiments of this application do not specifically limit the implementation method of the physical buttons corresponding to the target function.

[0154] In some embodiments of this application, the first device may generate target credentials corresponding to user data in response to a trigger operation on a target function interface, such as a click operation on the restore credentials control 502.

[0155] For example, the first device can randomly generate target credentials corresponding to user data according to a preset generation algorithm.

[0156] The preset generation algorithm can include symmetric encryption algorithms, asymmetric algorithms, and hash algorithms.

[0157] It should be noted that the embodiments of this application do not specifically limit the process of generating the target credential.

[0158] Thus, this application provides a way to subsequently encrypt user data using target credentials to ensure security during data migration.

[0159] In some embodiments of this application, after generating the target credentials, the first device can use the target credentials to encrypt user data.

[0160] In one feasible approach, the first device can encrypt user data managed by the first device using target credentials. The first device can also store the encrypted user data.

[0161] In another possible implementation, the first device can also generate a data encryption key, which is used to encrypt or decrypt user data. It should be noted that the data encryption key can include symmetric keys, asymmetric keys, etc., and can be derived once or multiple times from a preset key. The first device can use the data encryption key to encrypt user data, and can also use target credentials to encrypt the data encryption key. The first device can store both the encrypted user data and the encrypted data encryption key.

[0162] Thus, by encrypting user data managed by the first device using the generated target credentials, the embodiments of this application can improve the security of user data managed by the first device during transmission and storage. This, in turn, enhances the user experience.

[0163] In some embodiments of this application, encrypted user data, or encrypted user data and encrypted data encryption keys, can be stored in a storable medium in the first device. The storable data medium may include a removable hard drive, a solid-state drive, a recordable optical disc, and a Flash storage device, etc.

[0164] In this way, in subsequent scenarios involving the migration of user data, encrypted user data, or encrypted user data and encrypted data encryption keys, can be transmitted using storable media to improve the security of the transmission process.

[0165] In some embodiments of this application, encrypted user data, or encrypted user data and encrypted data encryption keys, can be stored on a third device. This third device may include a server and / or a trusted device. Thus, in subsequent scenarios involving user data migration, other devices can also obtain the encrypted user data through the third device to complete the user data migration process.

[0166] In some embodiments of this application, the first device can acquire a trigger operation for a target functional interface and display the first interface. The trigger operation is used to indicate the activation of the target credentials.

[0167] The first interface includes at least one method for saving the target credentials.

[0168] In other words, after the first device activates the target function, it can trigger the display of the first interface to prompt the user to select a method for saving the target credentials. This application embodiment provides the target function to facilitate user activation and management of target credentials, thereby improving the user experience and the flexibility of interaction with the first device.

[0169] For example, at least one storage method includes a first method, which represents using a user account to associate the target credentials for storage. The user account may include a communication account (internet account) used by the user, such as one in the first device. Accounts, etc. This application does not specifically limit user accounts.

[0170] Referring to Figure 6(A), the first interface includes a first method for storing the target credentials, such as storing the target credentials through an internet account. It should be noted that storing the target credentials can include saving and managing the target credentials, such as storing the target credentials, distributing the target credentials, etc.

[0171] The user can input a first operation in response to a first method, triggering the storage of target credentials using the user account. The first device acquires the first operation on the first interface, determines a first method among at least one storage method, and the first method is used to instruct the user account to associate the target credentials.

[0172] Thus, this application embodiment can provide users with multiple methods for saving target credentials, including a first method. After the user selects the first method, the first device can associate the target credentials with the user account to store the target credentials. This eliminates the need for users to manually save the target credentials, improving the convenience of credential management.

[0173] After the first device obtains the first operation for the first method, it can display a second interface, which is used to prompt the user to verify identity.

[0174] In some embodiments of this application, after the user authenticates using the first device, the first device can send the target credentials to the third device if the user's authentication is successful.

[0175] In some embodiments of this application, referring to Figure 6(B), the second interface may include at least one authentication method, such as real-name authentication. That is, users can use real-name authentication to authenticate themselves.

[0176] For example, a user can select a real-name authentication method on the second interface to trigger the corresponding verification process. The first device can receive the second operation on the second interface and display verification prompt information. The verification prompt information prompts the user to perform real-name authentication. The user can enter authentication information at the target location in the verification prompt information. In this way, the first device can determine the authentication information in response to the second operation on the second interface.

[0177] In one possible implementation, a user can enter authentication information on a second interface, and the first device can respond to the user's second action by determining the authentication information.

[0178] Therefore, this embodiment of the application requires determining the user's authentication information after the user enters the authentication information. This facilitates the subsequent storage of target credentials using the user account once the user's authentication is successful. This improves the flexibility and security of credential management.

[0179] In another possible approach, the user may have already been authenticated. The first device can obtain the authentication information from when the user authenticated, provided that the user has already been authenticated before the target credentials are associated with the user account.

[0180] Thus, this application embodiment can directly obtain the user's authentication information when the user has already authenticated. This facilitates the subsequent storage of target credentials using the user account after successful user authentication. It improves the flexibility, security, and user convenience of credential management.

[0181] In some embodiments of this application, the first device may send a verification request to the server. The verification request includes authentication information and is used to request the server to perform user authentication based on the received authentication information. The server may receive the verification request and, based on the authentication information, determine that the user authentication corresponding to the first device has been successful.

[0182] The identity verification information includes the user's name information and ID card information, as well as at least one of the following: the user's bank card information, the bank's registered mobile phone number, or the user's current biometric information. The ID card information includes the ID card number or an image of the ID card.

[0183] Thus, the first device in this application embodiment can determine whether user authentication is successful based on authentication information, which may include real-name authentication. This improves the flexibility and security of credential management. Consequently, even if a user account is leaked, the target credentials will not be easily leaked or reset. This, in turn, enhances the user experience.

[0184] In some embodiments of this application, the server may pre-store the correspondence between the user's name information and the user's ID card information in the authentication information. The server can determine whether the user's name information and the user's ID card information in the verification request match based on the correspondence. If the user's name information and the user's ID card information in the verification request match, the server determines that the user authentication corresponding to the first device is successful.

[0185] Of course, the server can also send the verification result to the first device, and the verification result is used to notify the user that the authentication has been successful.

[0186] In some embodiments of this application, during the user's authentication process using real-name authentication, it can be either an initial authentication of identity information or a subsequent authentication of identity information, where the authentication is based on that information. In other words, the user can input some or all of the authentication information.

[0187] In one possible implementation, referring to (A) in Figure 7, the authentication prompt message is used to prompt the user to enter authentication information, i.e., to prompt the user to enter all authentication information, in the case that the user has never authenticated before.

[0188] In another possible implementation, as shown in Figure 7(B), if the user has already been authenticated, a verification prompt message is used to prompt the user to verify authentication information. For example, prompting the user to fill in partial authentication information.

[0189] In this way, users can choose to store target credentials through their user accounts, and the primary device determines that it is necessary to associate the user account with the target credentials. The primary device can also prompt users to set up or verify authentication information to enhance the security of target credential management.

[0190] For example, a user can enter their name and ID card number on the second interface. In this way, the first device can obtain the user's name and ID card number for identity verification.

[0191] For example, users can also enter their name and upload a picture of their ID card on the second interface. In this way, the first device can obtain the user's name and ID card image for identity verification.

[0192] For example, users can also enter their name, ID card number, bank card information, and bank-registered mobile phone number on the second interface, and then perform verification code verification for the bank-registered mobile phone number. In this way, the identity verification information that the first device can obtain includes the user's name, ID card number, bank card information, and bank-registered mobile phone number.

[0193] For example, users can also enter their name, ID card number, and facial information on the second interface. In this way, the first device can obtain identity verification information including name, ID card number, and facial information.

[0194] It should be noted that this application does not specifically limit the verification process of real-name authentication or the implementation method of authentication information.

[0195] In some embodiments of this application, the first device may send the target credentials to a third device after the user authentication is successful. The third device may include a server and / or a trusted device.

[0196] The first device may also send an identifier used to index the target credentials to the third device. This identifier includes a user identifier and / or the device identifier of the first device. The user identifier can be a user's account.

[0197] Thus, in this embodiment, the identifier used to index the target credential can also be sent to a third device, so that the third device can store the target credential based on the identifier used to index the target credential. This eliminates the need for users to manually save the target credential, improving the convenience of credential management.

[0198] In one possible implementation, after a user is verified using a real-name authentication method, the first device can send a credential management request to the server so that the server can store the target credentials.

[0199] The credential management request instructs the server to associate the target credentials with the user account for safekeeping. The credential management request may include the target credentials and the user account.

[0200] In some embodiments of this application, users can not only use their user accounts to store target credentials, but also choose other methods to store target credentials, such as storing target credentials through trusted devices.

[0201] Specifically, continuing to refer to Figure 6(A), at least one storage method also includes a second method, which instructs the target credentials to be stored using a trusted device corresponding to the first device. For example, hosted on a trusted device.

[0202] Among them, the trusted device corresponding to the first device is the device that has established a trusted relationship with the first device.

[0203] For example, the account information of the trusted device corresponding to the first device is the same user account as the account information of the first device, thus the two devices have a trusted relationship.

[0204] For example, the account information of the trusted device corresponding to the first device and the account information of the first device are related accounts with a trust relationship, thus the two devices have a trust relationship.

[0205] For example, the trusted device corresponding to the first device is the external storage device of the first device.

[0206] It should be noted that the embodiments of this application do not specifically limit the way the trusted relationship is established.

[0207] In some embodiments of this application, the user can select a second method on the first interface to entrust the target credentials to a trusted device.

[0208] Specifically, the first device can obtain a second operation for the first interface and determine a second method among at least one storage method, the second method being used to instruct the storage of the target credentials using a trusted device corresponding to the first device.

[0209] Of course, the first device can also obtain the user's authentication information using the second method. It should be noted that the process of obtaining the user's authentication information is similar to the above embodiments and will not be repeated here.

[0210] In this way, the first device can send the target credentials to the trusted device. Alternatively, the first device can send both the target credentials and its own device identifier to the trusted device.

[0211] Thus, the second method is included among the various methods for storing the target credentials in this application embodiment. After the user selects the second method, the first device can utilize a trusted device to store the target credentials. This eliminates the need for the user to manually save the target credentials, improving the convenience of credential management.

[0212] In some embodiments of this application, the first device may encrypt the target credential using a preset encryption rule during the process of sending the target credential to the trusted device. The first device may also send the encrypted target credential to the trusted device.

[0213] Of course, the first device can encrypt the target credentials using preset encryption rules during the process of sending the target credentials to the server.

[0214] Thus, by encrypting the target credentials, the embodiments of this application can improve the security during the transmission and storage of the target credentials.

[0215] In some embodiments of this application, the preset encryption rules may include encrypting target credentials based on a pre-shared key, which is obtained by the first device and the trusted device through key negotiation.

[0216] For example, the first device can pre-negotiate a key with the trusted device to synchronously obtain a pre-shared key. The first device can then use the pre-shared key to encrypt the target credentials. Subsequently, the trusted device can decrypt the target credentials and utilize them.

[0217] Thus, in this embodiment, the first device can pre-share a key to encrypt the target credential and send the encrypted target credential. The trusted device can not only store the target credential but also decrypt and utilize the encrypted target credential. This improves both the storage security and the flexibility of using the target credential.

[0218] In some embodiments of this application, the first device may display a data selection interface before displaying the first interface. Users can operate on the data selection interface to select user data to be encrypted.

[0219] For example, the data selection interface includes data from two disks in the first device, such as "Disk E" and "Disk F". Referring to Figure 8, the data selection interface may include a selection control 801 and a drop-down control 802. For instance, a user can operate the selection control 801 corresponding to disk E to select all the data on disk E. Similarly, a user can operate the drop-down control 802 corresponding to disk E to view the data on disk E. Of course, a user can also operate the selection control 801 corresponding to the data on disk E to select only a portion of the data on disk E.

[0220] Thus, the embodiments of this application not only provide encryption functionality during data migration but also offer data selection capabilities. This allows users to flexibly control the data that can be migrated, avoiding unnecessary data migration and thus preventing waste of device resources. It enhances the flexibility of data migration and the user experience.

[0221] S403. The server responds to the credential management request by saving the target credential.

[0222] In some embodiments of this application, the server receives a credential management request sent by the first device and, in response to the credential management request, associates target credentials with the user account.

[0223] Specifically, the server can associate target credentials, user accounts, and authentication information to facilitate subsequent user authentication based on the authentication information.

[0224] For example, authentication information includes name information and ID card number information. The server can associate the target credentials, user account, name information, and ID card number information to obtain a first association relationship. The server can also save the first association relationship.

[0225] As another example, the server can also associate the target credentials and user account to obtain a second association. The server can also obtain the ID card photo information corresponding to the ID card number information, and associate the name information, ID card number information and ID card photo information to obtain a third association.

[0226] It should be noted that the embodiments of this application do not limit the specific implementation method of saving the target credentials.

[0227] S404. In response to the migration operation for the target data, the second device sends a credential retrieval request to the server.

[0228] S405. In response to the credential retrieval request, the server sends the target credentials to the second device.

[0229] In some embodiments of this application, a user can restore user data managed by the first device on a second device, i.e., migrate user data. The target data mentioned above can be part or all of the user data managed by the first device.

[0230] For example, the first device can be the same device as the second device. User data in the first device is deleted, but the user can continue to use the first device (or the second device) to retrieve the target data; this can also be referred to as recovering the target data or exporting the target data.

[0231] As another example, the first device and the second device can be different devices. If one or more components of the first device are damaged, causing the first device to be unable to use the target data normally, the target user can recover the target data through the second device.

[0232] For another example, if the target user can only use the second device and needs to use the target data, then the user can restore the target data through the second device.

[0233] It should be noted that the credential management method provided in this application is not limited to data migration scenarios between the same or different devices, but can also be applied to other scenarios. This application does not limit the application scenarios.

[0234] In some embodiments of this application, a user can recover user data using a target application on a second device. The user can export user data from the target application interface, and the second device can acquire migration operations (such as export operations) of the target data and perform user account verification.

[0235] The target application may include resource transfer applications, such as migration assistant applications and file transfer applications. This application does not limit the specific implementation of the target application.

[0236] For example, the target application is a migration assistant application. Referring to Figure 9, the target application interface of the migration assistant application may include a retrieval control 901 corresponding to obtaining target credentials. The user can click on the retrieval control 901 to trigger the migration process of the target data.

[0237] The second device can trigger the user account verification process in response to migration operations targeting target data (such as a click operation targeting control 901).

[0238] Specifically, in response to a migration operation targeting the data, the second device can display an account verification interface, which prompts the user to verify their user account. The user account being verified is the same as the user account on the first device.

[0239] Referring to Figure 10, the user can enter their user account and corresponding password information at the target location on the account verification interface. The second device can respond to the user's input operation and obtain the user account and corresponding password information from the first device.

[0240] In one feasible approach, the second device can perform user account verification. The second device can match the acquired user account with the corresponding password information. If the user account and its password match successfully, the second device determines that the user account verification was successful.

[0241] In another possible approach, the second device can verify the user account through a server. The second device can send the obtained user account and its corresponding password information to the server. If the user account and its corresponding password information match successfully, the server can send a matching result to the second device. The matching result indicates that the user account verification was successful.

[0242] In some embodiments of this application, the second device can obtain the user's identity verification information if the user account verification is successful.

[0243] Specifically, the second device can display a third interface, which prompts the user to authenticate. The second device can receive input from the third interface and determine the authentication information. The third interface may include at least one authentication method.

[0244] In one feasible approach, at least one authentication method may include real-name authentication. The user can enter authentication information on a third interface, and the second device can determine the authentication information in response to the user's input.

[0245] Therefore, this embodiment of the application requires determining the user's authentication information after the user enters the authentication information. This facilitates the subsequent acquisition of target credentials once the user's authentication is successful, thereby improving the flexibility and security of credential management.

[0246] In some embodiments of this application, the second device may send a verification request to the server. The verification request includes authentication information and is used to request the server to perform user authentication based on the received authentication information. The server may receive the verification request and, based on the authentication information, determine that the user authentication corresponding to the second device has been successful.

[0247] The identity verification information includes the user's name information and ID card information, as well as at least one of the following: the user's bank card information, the bank's registered mobile phone number, or the user's current biometric information. The ID card information includes the ID card number or an image of the ID card.

[0248] Thus, in the process of acquiring the target credentials, the second device in this application embodiment can determine whether the user's authentication has passed based on the authentication information, which may include real-name authentication. The target credentials can only be acquired after the user's authentication is successful. This improves the flexibility and security of credential management. Therefore, even if a user account is leaked, the target credentials will not be easily leaked or reset. This, in turn, enhances the user experience.

[0249] In one possible implementation, referring to Figure 11(A), the user can enter their name and ID card information at the target location of the verification prompt.

[0250] In another possible implementation, referring to Figure 11(B), the user can input their facial information at the target location of the verification prompt. A second device can then capture the user's facial information, such as a facial image, via a camera.

[0251] In some other embodiments of this application, if the user account verification is successful, the user authentication can also be completed by using the trusted device corresponding to the second device, that is, the second device can obtain the user's authentication information from the trusted device.

[0252] For example, a user can delegate the migration of target data to another user using a second device. In this case, the other user operating on the second device is not the actual user and cannot pass user authentication. Therefore, the other user can control the trusted device through the second device to perform the user authentication process, allowing the user to enter authentication information on the trusted device.

[0253] In one feasible approach, other users can select a trusted device on the second device, enabling user authentication on that trusted device. The second device can send an information retrieval request to its trusted device to obtain authentication information. The second device can then receive the authentication information sent by its trusted device.

[0254] Specifically, in response to a selection operation for a trusted device, the second device can send an information retrieval request to its trusted device based on the trusted device's device identifier. This information retrieval request is used to obtain authentication information. The user can then enter authentication information into the trusted device, which will then send the authentication information back to the second device. The second device will then receive the authentication information sent by its trusted device.

[0255] In another feasible approach, other users can also select authentication path information on the second device. The second device can display the authentication path information, which can be in the form of a QR code, data matrix (DM), DotCode, Code49, or other formats. The trusted device on the second device can then trigger a redirect to the authentication interface based on the authentication path information, allowing the user to enter authentication information on the trusted device's authentication interface.

[0256] For example, a second device can display a QR code or link. A trusted device on the second device can then scan and recognize the QR code or link, redirecting the user to an authentication interface. In this way, the user can complete authentication on the trusted device on the second device.

[0257] Thus, this application embodiment also supports entering user authentication information on a trusted device, avoiding situations where the user cannot complete user authentication if they are not near a second device. This improves the flexibility and convenience of user authentication.

[0258] In some embodiments of this application, during the process of determining that the user authentication for the second device has passed, the server may match the authentication information sent by the second device with the authentication information sent by the first device. If the authentication information sent by the second device matches the authentication information sent by the first device, the server determines that the user authentication for the second device has passed.

[0259] Of course, the server can also send the verification result to a second device, which is used to notify the user that the authentication has been successful.

[0260] For example, the authentication information sent by the second device may include the user's name and ID card information. The server can compare the user's name and ID card information in the authentication information sent by the second device with the user's name and ID card information in the authentication information sent by the first device. If they match, the server determines that the user authentication of the second device is successful.

[0261] As another example, the authentication information sent by the second device may include the user's current biometric information, such as facial information. The server can compare the facial information in the authentication information with the facial information in the authentication information sent by the first device. If they match, the server determines that the user authentication of the second device is successful.

[0262] As another example, the authentication information sent by the second device may include the user's current biometric information, such as facial information. The server can compare the facial information in the authentication information with the user's ID card information in the authentication information sent by the first device. If a correlation exists between the two, the server determines that the user authentication by the second device is successful.

[0263] It should be noted that the embodiments of this application do not limit the specific implementation process of user authentication.

[0264] In some embodiments of this application, if the second device determines that the user's authentication is successful based on the authentication information, it may send a credential acquisition request to the third device. The credential acquisition request is used to obtain the target credential corresponding to the target data. The target credential is used to decrypt the target data to migrate the target data to the second device. In response to the credential acquisition request, the third device sends the target credential to the second device. The second device can receive the target credential sent by the third device.

[0265] In some embodiments of this application, after obtaining the target credentials, the second device also needs to obtain the encrypted target data. In this way, the second device can use the target credentials to decrypt the encrypted target data and then display it.

[0266] Specifically, referring to Figure 12, the second device acquires the encrypted target data, which is encrypted based on the target credentials (S1201). After acquiring the encrypted target data, the second device can decrypt the encrypted target data using the target credentials to obtain the target data (S1202). Then, the second device can save and display the target data (S1203).

[0267] The encrypted target data can be stored in a storage medium of the first device. The second device can retrieve the encrypted target data from the storage medium of the first device. For example, the storage medium can be a removable hard drive, which the user can insert into the second device. The second device can then read the encrypted target data from the removable hard drive in the first device. Alternatively, the second device can also retrieve the encrypted target data from a server.

[0268] It should be noted that the embodiments of this application do not specifically limit the method of obtaining the target data.

[0269] Thus, this embodiment of the application can decrypt encrypted target data using the target credentials after obtaining them, and directly display the target data. This eliminates the need for users to manually input the target credentials and directly displays the target data, improving user convenience.

[0270] In some embodiments of this application, the second device may also display the target credentials after obtaining them, so that subsequent users can manually decrypt the encrypted target data using the target credentials.

[0271] For example, referring to Figure 13(A), the second device can display the target credentials, such as "Please confirm and record the following credentials: Please be sure to record and keep them safe for use in recovering device data QD7SE156F". The user can record the target credentials, which will be used later to export the target data. Next, the second device can display a data selection interface. The user can operate on the data selection interface to select the target data to be exported. For example, referring to Figure 13(B), the data selection interface includes data from the first device, such as "Disk E". The user can operate on the selection control 1301 corresponding to Disk E to select all the data corresponding to Disk E. At the same time, click the export control 1302 to export all the data corresponding to Disk E. Referring to Figure 13(C), in response to the operation on the selection control 1301, the second device displays a decryption interface, which prompts the user to decrypt the encrypted target data. The user can enter the target credentials in the decryption interface to facilitate the subsequent export of the selected target data.

[0272] Therefore, the second device can respond to an input operation on the decryption interface, using the target credentials to decrypt the encrypted target data. The input operation is used to input the target credentials. The second device can then save and display the target data.

[0273] In some embodiments of this application, user data managed by a first device is used as an example of target data. Users may also select a portion of the user data managed by the first device. For example, all data on disk E is user data managed by the first device, and users may select a portion of the data on disk E. A second device may also obtain a portion of the encrypted user data managed by the first device. It should be noted that this application does not specifically limit the amount of data a user can recover.

[0274] In some embodiments of this application, the second device can obtain encrypted target data from the third device and / or the first device. The second device can also obtain the encrypted target data and the encrypted data encryption key from the third device and / or the first device. The second device can first decrypt the encrypted data encryption key using the target credentials, and then decrypt the encrypted target data using the data encryption key to obtain and display the target data.

[0275] In some embodiments of this application, the first device and the second device may display the target credential according to preset rules during the display process. These preset rules may include event disabling rules, which are used to disable copy events, cut events, select events, and forwarding events corresponding to the target credential.

[0276] In other words, during the display of the target credentials, both the first and second devices disable the copy, cut, select, and forward functions corresponding to the target credentials. This allows the target credentials to be displayed in a secure environment, reducing the number of times the target credentials are transmitted and displayed, and improving the security of the target credentials.

[0277] In some embodiments of this application, the target credentials can also be used to assist in resetting the device password in the first device. The device password may include the lock screen password of the first device, the lock password for encrypted folders / files in the first device, and the login password for applications in the first device, etc. When a user forgets the device password in the first device, they can enter the target credentials to trigger the corresponding device password reset process.

[0278] It should be noted that the embodiments of this application do not limit the specific implementation of the device password in the first device and the corresponding device password reset process.

[0279] Therefore, the target credentials provided in this application embodiment can be used not only in data migration scenarios but also in device password reset scenarios. This enhances the flexibility of using the target credentials and improves user convenience.

[0280] In some embodiments of this application, the first device and the second device described above may be the same device or different devices. This application does not specifically limit the device on which the credential management method is applied.

[0281] In some embodiments of this application, referring to FIG14, the software system in the electronic device may include a display module, a credential management module, a user interaction module, and a device interaction module, etc.

[0282] In some examples, the display module is used to display the user interface. For instance, the user interface can prompt the user to authenticate. More exemplarily, the user interface can display the target credentials. Even more exemplarily, the user interface can display the storage method corresponding to the target credentials. The credential management module is used to manage the target credentials, such as encrypting them, or setting the access method for the target credentials (e.g., user account access, real-name authentication information access, etc.). The user interaction module is used to receive user interaction operations and process the target credentials. These interaction operations can include selecting the storage method for the target credentials, selecting the authentication method, etc. The device interaction module is used to interact with other devices, such as servers.

[0283] In some solutions, multiple embodiments of this application can be combined, and the combined solution can be implemented. Optionally, some operations in the process of each method embodiment may be combined, and / or the order of some operations may be changed. Furthermore, the execution order between the steps of each process is merely exemplary and does not constitute a limitation on the execution order between steps; other execution orders are also possible. It is not intended to indicate that the execution order is the only possible order in which these operations can be performed.

[0284] Those skilled in the art will conceive of various ways to reorder the operations described in the embodiments of this application. Furthermore, it should be noted that process details involved in one embodiment of this application are similarly applicable to other embodiments, or different embodiments can be combined.

[0285] Furthermore, some steps in the method embodiments can be equivalently replaced with other possible steps. Alternatively, some steps in the method embodiments may be optional and can be deleted in certain use cases. Or, other possible steps may be added to the method embodiments.

[0286] Furthermore, the various method embodiments can be implemented individually or in combination.

[0287] This application also provides an electronic device, such as the aforementioned laptop computer, as shown in FIG15. The laptop computer may include one or more processors 1510, memory 1520 and communication interface 1530.

[0288] The memory 1520, communication interface 1530, and processor 1510 are coupled together. For example, the memory 1520, communication interface 1530, and processor 1510 can be coupled together via bus 1540.

[0289] The communication interface 1530 is used for data transmission with other devices. The memory 1520 stores computer program code. The computer program code includes computer instructions, which, when executed by the processor 1510, cause the electronic device to perform the relevant method steps described in this application embodiment.

[0290] Processor 1510 may be a processor or controller, such as a central processing unit (CPU), a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It may implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with this disclosure. The processor may also be a combination that implements computational functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc.

[0291] Bus 1540 can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The aforementioned bus 1540 can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used in Figure 15, but this does not indicate that there is only one bus or one type of bus.

[0292] This application also provides an electronic device, which includes a memory and one or more processors; the memory is coupled to the processors; wherein the memory stores computer program code, which includes computer instructions, and when the computer instructions are executed by the processor, the electronic device performs the relevant method steps in the above method embodiments.

[0293] This application also provides a communication device, which includes a memory and one or more processors; the memory is coupled to the processors; wherein the memory stores computer program code, which includes computer instructions, and when the computer instructions are executed by the processor, the communication device performs the relevant method steps in the above method embodiments.

[0294] This application also provides a computer-readable storage medium storing computer program code. When the processor executes the computer program code, the electronic device executes the relevant method steps in the above method embodiments.

[0295] This application also provides a computer program product containing instructions that, when executed on a computer or processor, cause the computer or processor to perform the relevant method steps as described in the above method embodiments.

[0296] This application also provides a chip system, including: a processor coupled to a memory, the memory being used to store programs or instructions, and when the program or instructions are executed by the processor, the chip system enables the methods in any of the above method embodiments.

[0297] Optionally, the chip system may include one or more processors. These processors can be implemented in hardware or software. When implemented in hardware, the processor can be a logic circuit, an integrated circuit, etc. When implemented in software, the processor can be a general-purpose processor, implemented by reading software code stored in memory.

[0298] Optionally, the chip system may contain one or more memories. The memory may be integrated with the processor or disposed separately from it; this application embodiment does not limit this. For example, the memory may be a non-transient processor, such as a read-only memory (ROM), which may be integrated with the processor on the same chip or disposed separately on different chips. This application embodiment does not specifically limit the type of memory or the arrangement of the memory and processor.

[0299] For example, the chip system may be a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on chip (SoC), a central processor unit (CPU), a network processor (NP), a digital signal processor (DSP), a micro controller unit (MCU), a programmable logic device (PLD), or other integrated chips.

[0300] The electronic devices, computer storage media, or computer program products provided in this application are all used to execute the corresponding methods provided above. Therefore, the beneficial effects they can achieve can be referred to the beneficial effects in the corresponding methods provided above, and will not be repeated here.

[0301] Through the above description of the embodiments, those skilled in the art can clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.

[0302] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another apparatus, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0303] The units described as separate components may or may not be physically separate. A component shown as a unit can be one or more physical units, located in one place or distributed in multiple different locations. Some or all of the units can be selected to achieve the purpose of this embodiment, depending on actual needs.

[0304] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0305] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solutions of the embodiments of this application, or the contributing parts, or all or part of the technical solutions, can be embodied in the form of a software product. This software product is stored in a storage medium and includes several instructions to cause a device (which may be a microcontroller, chip, etc.) or processor to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0306] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A credential management method, characterized by, Applied to a first device, the method includes: The user account is used to associate target credentials, which are used to encrypt user data managed by the first device. Based on the determination of the target credentials associated with the user account, the user's identity verification information is obtained; If the user's authentication is successful based on the authentication information, the target credentials are sent to a third device. The target credentials are used to decrypt part or all of the data in the user data, so as to realize the migration of part or all of the data in the user data to the second device.

2. The method of claim 1, wherein, The process of obtaining user authentication information includes: A second interface is displayed, which prompts the user to verify their identity. The input operation for the second interface is obtained, and the authentication information is determined.

3. The method of claim 1, wherein, The process of obtaining user authentication information includes: If the user has been authenticated before the user account is associated with the target credentials, then obtain the authentication information of the user when the user was authenticated.

4. The method according to any one of claims 1 to 3, characterized in that, The method further includes: Display a first interface, the first interface including at least one method of saving the target credentials; The determination of the target credentials associated with the user account includes: Obtain a first operation for the first interface, determine a first method among the at least one saving methods, the first method being used to instruct the user account to associate the target credentials.

5. The method of claim 4, wherein, The method further includes: Obtain a second operation for the first interface, determine a second method among the at least one saving methods, the second method being used to instruct the target credentials to be saved using a trusted device corresponding to the first device; According to the second method, the user's authentication information is obtained.

6. The method according to any one of claims 1 to 5, characterized in that, Sending the target credentials to the third device further includes: The identifier used to index the target credentials is sent to the third device; The identifier used to index the target credentials includes a user identifier and / or a device identifier of the first device.

7. The method according to any one of claims 1 to 6, characterized in that, The user data managed by the first device includes at least one of the following: data stored locally on the first device, data stored by the user on a server or a remote user device that can be managed by the first device, or data in a device directly connected to the first device.

8. The method according to any one of claims 1 to 7, characterized in that, The method further includes: Send a verification request to the server, the verification request including the authentication information, the verification request being used to request the server to perform user authentication based on the received authentication information; The identity verification information includes the user's name information and the user's ID card information, as well as at least one of the following: the user's bank card information, the bank's registered mobile phone number, or the user's current biometric information. The ID card information includes ID card number information or ID card image information.

9. The method of claim 4, wherein, The display of the first interface includes: Obtain a trigger operation for the target function interface, and display the first interface. The trigger operation is used to instruct the activation of the target credentials.

10. The method according to any one of claims 1 to 9, characterized in that, The method further includes: Generate the target credentials; The target credentials are used to encrypt the user data managed by the first device.

11. The method according to any one of claims 1 to 10, characterized in that, Sending the target credentials to the third device includes: The target credentials are encrypted using a preset encryption rule; Send the encrypted target credentials to the third device.

12. The method according to any one of claims 1 to 11, characterized in that, The third device includes a server and / or a trusted device of the first device.

13. A credential management method, characterized by, Applied to a second device, the method includes: Obtain migration operations for the target data and perform user account verification, wherein the target data is part or all of the user data managed by the first device; If the user account is successfully verified, obtain the user's identity verification information; If the user's authentication is successful based on the authentication information, a credential acquisition request is sent to the third device. The credential acquisition request is used to obtain the target credential corresponding to the target data. The target credential is used to decrypt the target data in order to migrate the target data to the second device. Receive the target credentials sent by the third device.

14. The method of claim 13, wherein, The process of obtaining user authentication information includes: A third interface is displayed, which prompts the user to verify their identity. The system obtains input operations for the third interface and determines the authentication information.

15. The method of claim 13, wherein, The process of obtaining user authentication information includes: Send an information acquisition request to the trusted device of the second device, the information acquisition request being used to acquire the authentication information; Receive the authentication information sent by the trusted device of the second device.

16. The method according to any one of claims 13-15, characterized in that, The method further includes: Send a verification request to the server, the verification request including the authentication information, the verification request being used to request the server to perform user authentication based on the received authentication information; The identity verification information includes the user's name information and the user's ID card information, as well as at least one of the following: the user's bank card information, the bank's registered mobile phone number, or the user's current biometric information. The ID card information includes ID card number information or ID card image information.

17. The method according to any one of claims 13-16, characterized by, The method further includes: Obtain the encrypted target data, which is encrypted based on the target credentials; The encrypted target data is decrypted using the target credentials to obtain the target data; Save and display the target data.

18. The method according to any one of claims 13-16, characterized by, After receiving the target credentials sent by the third device, the method further includes: Display the target credentials.

19. The method of claim 18, wherein, The method further includes: The decryption interface is displayed, which prompts the user to decrypt the encrypted target data. Obtain input operations for the decryption interface, and use the target credentials to decrypt the encrypted target data to obtain the target data; Save and display the target data.

20. A communication system, characterized by The communication system includes a first device and a second device; The first device is configured to determine to associate target credentials with a user account, the target credentials being used to encrypt user data managed by the first device; The first device is further configured to obtain the user's authentication information based on the determined target credentials associated with the user account; The first device is further configured to send the target credentials to the third device when the user authentication is determined to be successful based on the authentication information. The target credentials are used to decrypt part or all of the data in the user data to achieve the migration of part or all of the data in the user data to the second device. The second device is configured to acquire migration operations for target data and perform user account verification, wherein the target data is part or all of the user data managed by the first device; The second device is also configured to obtain the user's identity verification information if the user account verification is successful; The second device is further configured to send a credential acquisition request to the third device when it is determined that the user's authentication is successful based on the authentication information. The credential acquisition request is used to acquire the target credentials corresponding to the target data. The second device is also configured to receive the target credentials sent by the third device.

21. A credential management method, comprising: Applied to a communication system, the communication system including a first device and a second device, the method includes: The first device determines to associate target credentials with a user account, the target credentials being used to encrypt user data managed by the first device; The first device obtains the user's identity verification information by using the target credentials associated with the user account as determined by the determination. When the first device determines that the user's authentication is successful based on the authentication information, it sends the target credentials to the third device. The target credentials are used to decrypt part or all of the data in the user data, so as to realize the migration of part or all of the data in the user data to the second device. The second device acquires a migration operation for the target data and performs user account verification. The target data is part or all of the user data managed by the first device. The second device obtains the user's identity verification information after the user account verification is successful; When the second device determines that the user's authentication is successful based on the authentication information, it sends a credential acquisition request to the third device. The credential acquisition request is used to obtain the target credentials corresponding to the target data. The second device receives the target credentials sent by the third device.

22. An electronic device, comprising: The electronic device includes a memory and one or more processors; the memory is coupled to the processors; wherein the memory stores computer program code, the computer program code including computer instructions, which, when executed by the processor, cause the electronic device to perform the method as described in any one of claims 1-12, or to perform the method as described in any one of claims 13-19.

23. A computer readable medium characterized by The computer-readable storage medium stores instructions that, when executed on an electronic device, cause the electronic device to perform the method as described in any one of claims 1-12, or the method as described in any one of claims 13-19.

24. A computer program product, characterised in that, The computer program product comprises instructions which, when executed on a computer or processor, cause the computer or the processor to carry out the method according to any one of claims 1-12, or the method according to any one of claims 13-19.