Communication method, electronic device, chip system, and storage medium

By acquiring and matching biometric data during a call, and utilizing a trusted execution environment and biometric extraction technology, the problem of identity impersonation by criminals is solved, improving call security, raising user awareness, and enhancing the call experience.

WO2026148882A1PCT designated stage Publication Date: 2026-07-16HUAWEI TECH CO LTD

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
HUAWEI TECH CO LTD
Filing Date
2025-08-29
Publication Date
2026-07-16

AI Technical Summary

Technical Problem

Criminals use generative artificial intelligence technology to create fake content to impersonate call users, resulting in financial losses and a degraded call experience.

Method used

During a call, the system acquires and matches the biometric data of the caller, outputs prompts to verify identity, ensures call security, and employs a trusted execution environment and biometric extraction technology to prevent call fraud.

Benefits of technology

It improves the reliability and security of calls, enhances users' awareness of preventing call fraud, and improves the call experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025118075_16072026_PF_FP_ABST
    Figure CN2025118075_16072026_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of terminals, and provides a communication method, an electronic device, a chip system, and a storage medium. The method comprises: during a call service between a first terminal device and a second terminal device, acquiring first biometric data of a call object, wherein the call object is an object using the second terminal device to make a call; matching the first biometric data with second biometric data to obtain a matching result, the second biometric data being determined on the basis of first multimedia data, and the first multimedia data being multimedia data that is sent by the second terminal device during the call service and used for being presented to a user using the first terminal device; and outputting prompt information on the basis of the matching result, the prompt information being used for prompting the security status of a call. The method can enhance the awareness of users for preventing phone scam behaviors, thereby improving the call experience of users.
Need to check novelty before this filing date? Find Prior Art

Description

A communication method, electronic device, chip system, and storage medium

[0001] This application claims priority to Chinese Patent Application No. 202510045671.8, filed on January 10, 2025, entitled "A Communication Method, Electronic Device, Chip System and Storage Medium", the entire contents of which are incorporated herein by reference. Technical Field

[0002] This application relates to the field of terminals, and more particularly to a communication method, electronic device, chip system, and storage medium. Background Technology

[0003] Currently, with the rapid development of generative artificial intelligence (AIGC) technology, criminals can use AIGC to synthesize fake voices and images and seamlessly integrate this fake content into phone calls to impersonate the caller's relatives or friends. During the call, criminals often fabricate emergency situations to induce users to transfer money or provide sensitive information, such as bank card numbers or passwords. This can lead to financial losses for users and negatively impact their call experience. Summary of the Invention

[0004] This application provides a communication method, electronic device, chip system, and storage medium that can enhance users' awareness of preventing call fraud, thereby improving users' call experience.

[0005] In a first aspect, a communication method is provided, comprising: during a call between a first terminal device and a second terminal device, acquiring first biometric data of the call subject, wherein the call subject is the user of the second terminal device making the call; matching the first biometric data and the second biometric data to obtain a matching result, wherein the second biometric data is determined based on first multimedia data, wherein the first multimedia data is multimedia data sent by the second terminal device during the call and presented to the user of the first terminal device; and outputting a prompt message based on the matching result, the prompt message being used to indicate the call security status.

[0006] The method can be executed by the first terminal device, or by a module (such as a processor, chip, or chip system) applied in the first terminal device, or by a logic module or software that can implement all or part of the functions of the terminal device.

[0007] Based on the above scheme, during a call between the first and second terminal devices, the identity of the call participants can be verified to output security alerts, enabling users to prevent call fraud and ensuring the reliability and security of the call service, thus improving the user's call experience. This process of verifying the identity of the call participants and outputting security alerts can be called the anti-fraud authentication process.

[0008] It should be understood that the first terminal device can be a terminal device that answers a call during a call service, and the second terminal device can be a terminal device that initiates a call during a call service. Of course, the first terminal device can also be a terminal device that initiates a call during a call service, and the second terminal device can be a terminal device that answers a call during a call service.

[0009] The first terminal device and the second terminal device can communicate directly, or they can communicate through a server.

[0010] In one possible implementation, the first biometric data may be sent by the second terminal device. Alternatively, the first biometric data may be determined by the first terminal device based on second multimedia data from the second terminal device. The second multimedia data is multimedia data collected by the multimedia data acquisition component of the second terminal device during a call between the first and second terminal devices.

[0011] In one possible implementation, obtaining the first biometric data of the call subject includes: receiving first data and a first signature corresponding to the first data from a second terminal device, wherein the first data is used to determine the first biometric data; verifying the first signature, and, if the verification is successful, determining the first biometric data based on the first data. The first data and the first signature can be sent directly from the second terminal device to the first terminal device; alternatively, the first data and the second signature can also be sent from the second terminal device to the first terminal device via a server.

[0012] The first data and its corresponding first signature can be actively sent by the second terminal device. This indicates that the anti-fraud authentication is triggered by the second terminal device during the call.

[0013] Of course, the first data and the corresponding first signature can also be sent by the second terminal device based on an acquisition request, which is a request sent by the first terminal device to acquire the first data. In this case, it can be indicated that the anti-fraud authentication is triggered by the first terminal device during the call.

[0014] Based on the above scheme, by verifying the first signature, the integrity and authenticity of the first data used to obtain the first biometric data can be ensured, and the first data can be prevented from being tampered with or forged during transmission, thereby enhancing data security.

[0015] In one possible implementation, determining the first biometric data based on the first data includes: the first data being the first biometric data.

[0016] Based on the above scheme, no additional biometric extraction steps are required, which simplifies the process of obtaining the first biometric data and improves the efficiency of obtaining the first biometric data.

[0017] In one possible implementation, the first data is second multimedia data, and determining the first biometric data based on the first data includes: performing liveness detection on the second multimedia data to obtain the first biometric data.

[0018] Based on the above scheme, it can be ensured that the extracted first biometric data comes from real and reliable data sources, thereby improving the authenticity and accuracy of biometric extraction.

[0019] In one possible implementation, if there are no reproduced images in the second multimedia data and the object corresponding to the second multimedia data is a living object, the biometric data obtained by extracting biometric features from the second multimedia data is determined as the first biometric data.

[0020] In one possible implementation, for video call services, the second multimedia data can be image data; or, the second multimedia data can be a combination of image data and audio data. The first biometric data can be obtained by the second terminal device through processing such as face recognition, liveness detection, re-encoding detection, and biometric extraction based on the second multimedia data.

[0021] In one possible implementation, the first terminal device includes a first trusted application (TA), which is set in a trusted execution environment (TEE) to verify the first signature, including: verifying the first signature using the device's anti-fraud public key through the first TA.

[0022] Among them, TEE provides an isolated trusted execution environment that can protect sensitive data and business logic from external attacks.

[0023] Based on the above scheme, verifying the first signature in the TEE can ensure that the first signature is not tampered with or forged during the verification process, thereby enhancing the reliability of the verification.

[0024] In one possible implementation, a device certificate and a first anti-fraud certificate are received from a second terminal device. The first anti-fraud certificate is generated based on the device's private key and is used to prove the identity of the second terminal device. If the device certificate is found to be valid based on the device's root public key, the device public key corresponding to the device's private key is extracted from the device certificate. If the first anti-fraud certificate is found to be valid based on the device's public key, the device anti-fraud public key is extracted from the first anti-fraud certificate.

[0025] Among them, the device root public key is the root public key of the device PKI system.

[0026] In one possible implementation, a second anti-fraud certificate is received from a second terminal device; if the legitimacy of the second anti-fraud certificate is determined based on the anti-fraud authentication root public key, the device's anti-fraud public key is extracted from the second anti-fraud certificate.

[0027] The anti-fraud authentication root public key is the root public key of the anti-fraud PKI system. The second anti-fraud certificate is verified using the anti-fraud authentication root public key; if the verification passes, the second anti-fraud certificate is deemed legitimate.

[0028] In one possible implementation, before receiving the first data and the first signature corresponding to the first data from the second terminal device, the method further includes: sending an acquisition request to the second terminal device to acquire the first data.

[0029] Based on the above scheme, by sending an acquisition request to obtain the first data, it can be shown that the anti-fraud authentication in the call service is actively triggered by the first terminal device, so that identity verification can be performed based on the first data. This will prompt the user using the first terminal device to the current call security status, which can enhance the user's awareness of preventing call fraud and thus improve the user's call experience.

[0030] In one possible implementation, the retrieval request carries a session random number.

[0031] Based on the above scheme, by including a session random number in the retrieval request, it can be ensured that the retrieval request is unique, and thus the data obtained based on the retrieval request is also unique. This method can effectively prevent replay attacks and avoid attackers using historically obtained first-time data for call fraud.

[0032] In one possible implementation, receiving first data and a first signature corresponding to the first data from a second terminal device includes: receiving ciphertext from the second terminal device; decrypting the ciphertext to obtain the first data and the first signature.

[0033] Based on the above scheme, by carrying the first data and the first signature in encrypted transmission, the first data can be prevented from being stolen during transmission, thus improving the security of the first data transmission.

[0034] In one possible implementation, the first biometric data includes a face image or facial feature data extracted from a face image.

[0035] Based on the above solution, identity verification through facial images or facial feature data during video calls can improve the accuracy of identity verification and further improve the accuracy of the output prompts.

[0036] In one possible implementation, extracting biometric features from the second multimedia data to obtain the first biometric data includes: for voice call services, the second multimedia data can be audio data, and liveness detection can be performed based on the audio data. If the liveness detection result indicates that the object corresponding to the audio data is a live object, then voiceprint features are extracted from the audio data to obtain voiceprint data as the first biometric data. Here, biometric feature extraction is specifically voiceprint feature extraction.

[0037] It should be noted that the order of liveness detection and voiceprint feature extraction can be flexibly set according to business needs. This application embodiment does not limit the order of liveness detection and voiceprint feature extraction.

[0038] Based on the above scheme, it is ensured that the acquired first biometric data comes from a real living object, which enhances the reliability and accuracy of subsequent identity verification based on the first and second biometric data, further improves the reliability and accuracy of the output prompt information, thereby enhancing users' awareness of preventing call fraud and improving users' call experience.

[0039] For video call services, the second multimedia data can be image data, or the second multimedia data can be both image data and audio data.

[0040] For example, if the second multimedia data consists of image data and audio data, then image data can be used for re-enactment detection, and liveness detection can be performed based on the image data and audio data. If the re-enactment detection result indicates that no re-enacted image exists in the image data, and the liveness detection result indicates that the object corresponding to the image data and audio data is a live object, then the face data obtained by extracting facial features from the image data and the voiceprint data obtained by extracting voiceprint features from the audio data are used as the first biometric data. Biometric extraction includes face feature extraction and voiceprint feature extraction. Liveness detection may include face recognition.

[0041] In another example, if the second multimedia data is image data, then image data can be used for re-enactment detection and liveness detection. If the re-enactment detection result indicates that no re-enacted image exists in the image data, and the liveness detection result indicates that the object corresponding to the image data is a live object, then the facial data obtained by extracting facial features from the image data is used as the first biometric data. Here, biometric extraction refers to facial feature extraction. Liveness detection may include face recognition.

[0042] It should be noted that the order of image capture detection, liveness detection, and biometric extraction can be flexibly set according to business requirements. In this embodiment, the order of image capture detection, liveness detection, and biometric extraction is not limited.

[0043] Based on the above scheme, it is possible to effectively identify reproduced or forged images, ensuring that the image data used for biometric extraction is authentic and unaltered. Simultaneously, by combining it with liveness detection technology, the system further verifies that the object corresponding to the image data is a real, living person, thereby improving the accuracy and reliability of the collected primary biometric data. This further enhances the reliability and accuracy of the output alerts, strengthens users' awareness of call fraud prevention, and improves the user's call experience.

[0044] In one possible implementation, during a call between a first terminal device and a second terminal device, first biometric data of the call participants is periodically acquired; for each period, the first biometric data is matched with second biometric data acquired in that period to obtain a matching result; based on the matching result, a prompt message is output to indicate the call security status.

[0045] The above solution can periodically perform anti-fraud authentication during the call between the first terminal device and the second terminal device, and output prompt information to indicate the call security status. This can enhance users' awareness of preventing call fraud and further improve the security and reliability of the call process.

[0046] Secondly, a communication method is provided, which can be executed by a second terminal device, by a component of the second terminal device, or by a logic module or software that can implement or partially implement the functions of the second terminal device.

[0047] The method includes: during a call between a first terminal device and a second terminal device, collecting first data, the first data being used to determine the first biometric data of the call subject, the call subject being the person using the second terminal device to make the call; signing the second data containing the first data to obtain a first signature; and sending the first data and the first signature to the first terminal device.

[0048] In one possible implementation, the first data may be actively collected by the second terminal device and sent to the first terminal device. Alternatively, the first data may be collected by the second terminal device based on an acquisition request, which is used to acquire the first data.

[0049] In one possible implementation, the first data is second multimedia data, which is collected by the multimedia data acquisition component of the second terminal device during a call between the first terminal device and the second terminal device.

[0050] In one possible implementation, the second terminal device includes a second trusted application (TA), which is set in the trusted execution environment (TEE) of the second terminal device. The first data is first biometric data. Collecting the first data includes: during a call between the first terminal device and the second terminal device, collecting second multimedia data through the multimedia data acquisition component of the second terminal device; and determining the first biometric data based on the second multimedia data through the second TA.

[0051] Based on the above scheme, the first data is collected in the TEE environment of the second terminal device. Due to the security isolation mechanism of the TEE environment, it can effectively prevent the access and tampering of malicious software, thereby significantly enhancing the security of the collected first data.

[0052] In one possible implementation, determining the first biometric data based on the second multimedia data includes: if there is no reproduced image in the second multimedia data and the object corresponding to the second multimedia data is a living object, then the biometric data obtained by extracting biometric features from the second multimedia data is determined as the first biometric data.

[0053] In one possible implementation, signing the second data containing the first data to obtain the first signature includes:

[0054] The first signature is obtained by signing the second data using the second TA and the device's anti-fraud private key.

[0055] In one possible implementation, the TEE contains a device certificate for the second terminal device, which is used to prove the identity of the second terminal device. The method further includes: sending a device certificate and a first anti-fraud certificate to the first terminal device. The first anti-fraud certificate is generated based on the device's private key and carries a device anti-fraud public key corresponding to the device's anti-fraud private key. The device certificate carries a device public key corresponding to the device's private key. Alternatively, sending a second anti-fraud certificate to the first terminal device. The second anti-fraud certificate is generated based on the anti-fraud authentication root private key and carries a device anti-fraud public key.

[0056] In one possible implementation, the second anti-fraud certificate is obtained by: signing the device anti-fraud public key based on the device private key to obtain a second signature; sending a processing request to the server to generate the second anti-fraud certificate, the processing request carrying the device anti-fraud public key, the second signature, and the device certificate; and receiving the second anti-fraud certificate from the server, the second anti-fraud certificate being generated based on the device anti-fraud public key, the second signature, and the device certificate.

[0057] In one possible implementation, before collecting the first data during a call between the first terminal device and the second terminal device, the method further includes: receiving an acquisition request, the acquisition request being used to acquire the first data.

[0058] In one possible implementation, the retrieval request carries a session random number, and the second data also includes the session random number.

[0059] In one possible implementation, sending the first data and the first signature to the first terminal device includes: sending ciphertext to the first terminal device, wherein the ciphertext carries the first data and the first signature.

[0060] In one possible implementation, the first biometric data includes a face image or facial feature data extracted from a face image.

[0061] The beneficial effects of each implementation method in the second aspect can be found in the description of the first aspect, and will not be repeated here.

[0062] Thirdly, a communication method is provided, which can be executed by a server, by a component of the server (such as a processor, chip, or chip system), or by a logic module or software capable of implementing all or part of the server's functions.

[0063] The method includes: during a call between a first terminal device and a second terminal device, receiving first data and a first signature corresponding to the first data from the second terminal device, wherein the first data is used to determine the first biometric data of the call subject, and the call subject is the person using the second terminal device to make the call; and forwarding the first data and the first signature to the first terminal device.

[0064] In one possible implementation, during a call between the first terminal device and the second terminal device, before receiving the first data and the first signature from the second terminal device, the method further includes: receiving an acquisition request from the first terminal device, the acquisition request being used to acquire the first data; and forwarding the acquisition request to the second terminal device.

[0065] In one possible implementation, the retrieval request carries a session random number.

[0066] In one possible implementation, the method further includes: receiving a processing request from a second terminal device for generating a second anti-fraud certificate, the processing request carrying a device anti-fraud public key, a second signature, and a device certificate, the device certificate being used to prove the identity of the second terminal device; if the second signature is verified successfully based on the device certificate, generating a second anti-fraud certificate using an anti-fraud authentication root private key, the second anti-fraud certificate carrying the device anti-fraud public key; and sending the second anti-fraud certificate to the second terminal device.

[0067] The beneficial effects of each implementation method in the third aspect can be found in the description of the first aspect, and will not be repeated here.

[0068] Fourthly, a communication method is provided, which can be executed by a server, by a component of the server (such as a processor, chip, or chip system), or by a logic module or software capable of implementing all or part of the server's functions.

[0069] The method includes: receiving a processing request from a second terminal device for generating a second anti-fraud certificate, the processing request carrying a device anti-fraud public key, a second signature, and a device certificate, the device certificate being used to prove the identity of the second terminal device; if the second signature is verified successfully based on the device certificate, generating a second anti-fraud certificate using an anti-fraud authentication root private key, the second anti-fraud certificate carrying the device anti-fraud public key; and sending the second anti-fraud certificate to the second terminal device.

[0070] The beneficial effects of each implementation method in the fourth aspect can be found in the description of the first aspect, and will not be repeated here.

[0071] Fifthly, a communication system is provided, comprising a first terminal device and a second terminal device, wherein a communication connection is established between the first terminal device and the second terminal device, wherein:

[0072] The second terminal device is used to collect first data during a call between the first terminal device and the second terminal device. The first data is used to determine the first biometric data of the call subject, who is the user of the second terminal device. The second terminal device signs the second data containing the first data to obtain a first signature. The second terminal device sends the first data and the first signature to the first terminal device. The first terminal device receives the first data and the first signature from the second terminal device, verifies the first signature, and, if the verification is successful, determines the first biometric data based on the first data. The first biometric data and the second biometric data are matched to obtain a matching result. The second biometric data are determined based on first multimedia data, which is multimedia data sent by the second terminal device during the call and presented to the user of the first terminal device. Based on the matching result, the first terminal device outputs a prompt message to indicate the call security status.

[0073] In one possible implementation, the second terminal device includes a second trusted application (TA), which is set in the TEE of the second terminal device. Specifically, the second terminal device is used to sign the second data using the device anti-fraud private key through the second TA to obtain a first signature.

[0074] In one possible implementation, the first terminal device includes a first TA, which is set in the TEE of the first terminal device, wherein: the first terminal device is specifically used to verify the first signature by means of the first TA using the device anti-fraud public key corresponding to the device anti-fraud private key.

[0075] Sixthly, a communication system is provided, comprising a first terminal device, a second terminal device, and a server, wherein the server establishes communication connections with both the first terminal device and the second terminal device, wherein:

[0076] The second terminal device is used to collect first data during a call between the first terminal device and the second terminal device. The first data is used to determine the first biometric data of the call subject, who is the user of the second terminal device in the call. The device then signs the second data containing the first data to obtain a first signature. The device then sends the first data and the first signature to a server. The server receives the first data and the first signature and forwards the first data and the first signature to the first terminal device. The first terminal device receives the first data and the first signature from the server, verifies the first signature, and, if the verification is successful, determines the first biometric data based on the first data. It then matches the first biometric data with the second biometric data to obtain a matching result. The second biometric data is determined based on first multimedia data, which is multimedia data sent by the second terminal device during the call and presented to the user of the first terminal device. Based on the matching result, the device outputs a prompt message to indicate the call security status.

[0077] In one possible implementation, the second terminal device includes a second trusted application (TA), which is set in the TEE of the second terminal device. Specifically, the second terminal device is used to sign the second data using the device anti-fraud private key through the second TA to obtain a first signature.

[0078] In one possible implementation, the first terminal device includes a first TA, which is set in the TEE of the first terminal device, wherein: the first terminal device is specifically used to verify the first signature by means of the first TA using the device anti-fraud public key corresponding to the device anti-fraud private key.

[0079] In a seventh aspect, embodiments of this application provide an electronic device, which includes a processor and a memory. The memory is used to store a computer program, and the processor is used to call and run the computer program from the memory, causing the electronic device to perform the method in any of the above aspects or any possible implementation of any of the above aspects.

[0080] Eighthly, embodiments of this application provide a computer-readable storage medium storing a computer program that, when executed by a processor, causes the processor to perform the method in any of the above aspects or any possible implementations of any of the above aspects.

[0081] Ninthly, embodiments of this application provide a computer program product, which includes: computer program code, which, when executed by an electronic device, causes the electronic device to perform the method in any of the above aspects or any possible implementation of any of the above aspects.

[0082] In a tenth aspect, embodiments of this application provide a chip system, which includes a processing circuit and a storage medium storing computer program instructions; the computer program instructions are executed by the processing circuit using the methods in any of the above aspects or any possible implementations of any of the above aspects.

[0083] Optionally, the processing circuitry in the above-mentioned chip system can be replaced by a processor, and the storage medium can be replaced by a memory. Optionally, the chip system may also include a communication interface for enabling communication between the chip system and external devices.

[0084] The beneficial effects of the technical solutions in the second to tenth aspects of this application can be referred to the beneficial effects of the technical solutions in the first aspect, and will not be repeated here. Attached Figure Description

[0085] Figure 1 is a schematic diagram of the structure of an electronic device provided in an embodiment of this application;

[0086] Figure 2 is a software structure block diagram of an electronic device 100 according to an embodiment of this application;

[0087] Figure 3 is a schematic diagram of interface changes of a terminal device in a communication method provided in an embodiment of this application;

[0088] Figure 4 is a schematic diagram of interface changes of a group of terminal devices in a communication method provided in an embodiment of this application;

[0089] Figure 5 is a schematic diagram of interface changes of another group of terminal devices in a communication method provided in an embodiment of this application;

[0090] Figure 6 is a schematic diagram of the interface changes of the terminal device in another communication method provided in an embodiment of this application;

[0091] Figure 7 is a schematic diagram of interface changes of a group of terminal devices in another communication method provided in an embodiment of this application;

[0092] Figure 8 is a schematic diagram of interface changes of another set of terminal devices in another communication method provided in the embodiments of this application;

[0093] Figure 9 is a schematic diagram illustrating the changes in the user experience at the receiving end in a communication method provided in an embodiment of this application;

[0094] Figure 10 is a flowchart illustrating a communication method 1000 provided in an embodiment of this application;

[0095] Figure 11 is a flowchart illustrating another communication method 1100 provided in an embodiment of this application;

[0096] Figure 12 is a flowchart illustrating another communication method 1200 provided in an embodiment of this application;

[0097] Figure 13 is a flowchart illustrating another communication method 1300 provided in an embodiment of this application;

[0098] Figure 14 is a schematic diagram of the registration process of a communication method applicable to this application, provided in an embodiment of this application;

[0099] Figure 15 is a schematic diagram of the structure of a communication system 15 provided in an embodiment of this application;

[0100] Figure 16 is a schematic diagram of the control flow of a communication system 16 provided in an embodiment of this application;

[0101] Figure 17 is a schematic diagram of the data flow of a communication system 16 provided in an embodiment of this application;

[0102] Figure 18 is a flowchart illustrating a communication method 1800 provided in an embodiment of this application;

[0103] Figure 19 is a flowchart illustrating a communication method 1900 provided in an embodiment of this application;

[0104] Figure 20 is a flowchart illustrating a communication method 2000 provided in an embodiment of this application;

[0105] Figure 21 is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0106] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.

[0107] In the description of the embodiments of this application, unless otherwise stated, " / " means "or"; for example, A / B can mean A or B; "and / or" in this document is merely a description of the relationship between related objects, indicating that three relationships can exist; for example, A and / or B can mean: A exists alone, A and B exist simultaneously, or B exists alone. Furthermore, in the description of the embodiments of this application, "multiple" refers to two or more.

[0108] Hereinafter, the terms "first," "second," and "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first," "second," or "third" may explicitly or implicitly include one or more of that feature.

[0109] This application provides an electronic device for executing the communication method provided in this application. In some embodiments of this application, the electronic device may be a mobile phone, tablet computer, wearable device, in-vehicle device, augmented reality (AR) / virtual reality (VR) device, laptop computer, ultra-mobile personal computer (UMPC), netbook, personal digital assistant (PDA), etc., or may be other devices or apparatuses capable of communication. This application does not limit the specific type of electronic device.

[0110] For example, FIG1 is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application.

[0111] As shown in Figure 1, the electronic device 100 may include a processor 101, an external memory interface 102, an internal memory 103, a universal serial bus (USB) interface 104, a button 105, a display screen 106, an antenna 1, an antenna 2, a mobile communication module 107, a wireless communication module 108, an audio module 109, a speaker 110, a receiver 111, a microphone 112, and a camera 113.

[0112] It is understood that the structures illustrated in the embodiments of this application do not constitute a specific limitation on the electronic device 100. In other embodiments of this application, the electronic device 100 may include more or fewer components than illustrated, or combine some components, or split some components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.

[0113] Processor 101 may include one or more processing units, such as: application processor (AP), modem processor, graphics processing unit (GPU), image signal processor (ISP), controller, memory, video codec, digital signal processor (DSP), baseband processor, and / or neural network processing unit (NPU), etc. Different processing units may be independent devices or integrated into one or more processors.

[0114] The controller can be the nerve center and command center of the electronic device 100. The controller can generate operation control signals according to the instruction opcode and timing signals to complete the control of fetching and executing instructions.

[0115] The processor 101 may also include a memory for storing instructions and data. In some embodiments, the memory in the processor 101 is a cache memory. This memory can store instructions or data that the processor 101 has just used or that are used repeatedly. If the processor 101 needs to use the instruction or data again, it can retrieve it directly from the memory. This avoids repeated accesses, reduces the waiting time of the processor 101, and thus improves the efficiency of the system.

[0116] The processor 101 and the display screen 106 communicate through a display serial interface (DSI) to realize the display function of the electronic device 100.

[0117] The wireless communication function of electronic device 100 can be implemented through antenna 1, antenna 2, mobile communication module 107, wireless communication module 108, modem processor, and baseband processor.

[0118] Antennas 1 and 2 are used to transmit and receive electromagnetic wave signals. The structures of antennas 1 and 2 in Figure 1 are merely one example. Each antenna in the electronic device 100 can be used to cover one or more communication frequency bands. Different antennas can also be reused to improve antenna utilization. For example, antenna 1 can be reused as a diversity antenna for a wireless local area network. In some other embodiments, the antennas can be used in conjunction with a tuning switch.

[0119] Electronic device 100 implements display functions through a GPU, display screen 106, and application processor. The GPU is a microprocessor for image processing, connected to the display screen 106 and the application processor. The GPU is used to perform mathematical and geometric calculations and for graphics rendering. Processor 101 may include one or more GPUs, which execute program instructions to generate or modify display information.

[0120] The display screen 106 is used to display images, videos, etc. The display screen 106 includes a display panel. The display panel can be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a Miniled LED, a MicroLED, a Micro-OLED, a quantum dot light-emitting diode (QLED), etc. In some embodiments, the electronic device 100 may include one or N display screens 106, where N is a positive integer greater than 1.

[0121] The external storage interface 102 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the electronic device 100. The external memory card communicates with the processor 101 through the external storage interface 102 to perform data storage functions. For example, music, video, and other files can be saved on the external memory card.

[0122] Buttons 105 include a power button, volume buttons, etc. Buttons 105 can be mechanical buttons or touch-sensitive buttons. The electronic device 100 can receive button input and generate key signal inputs related to user settings and function control of the electronic device 100.

[0123] The processor 101 can be coupled to the audio module 109 via the integrated circuit sound (I2S) bus to enable communication between the processor 101 and the audio module 109. In some embodiments, the audio module 109 can transmit audio signals to the wireless communication module 108 via the I2S bus to enable the function of answering phone calls through a Bluetooth headset.

[0124] Pulse code modulation (PCM) interfaces can also be used for audio communication, sampling, quantizing, and encoding analog signals. In some embodiments, audio module 109 can also transmit audio signals to wireless communication module 108 via the PCM interface, enabling the function of answering phone calls through a Bluetooth headset. Both I2S and PCM interfaces can be used for audio communication.

[0125] The Universal Asynchronous Receiver / Transmitter (UART) interface is a universal serial data bus used for asynchronous communication. This bus can be a bidirectional communication bus. In some embodiments, the audio module 109 can transmit audio signals to the wireless communication module 108 through the UART interface to enable music playback via Bluetooth headphones.

[0126] Electronic device 100 can perform shooting functions through ISP, camera 113, video codec, GPU, display screen and application processor 101.

[0127] The ISP (Image Signal Processor) is used to process data fed back from the camera 113. For example, when taking a picture, the shutter is opened, and light is transmitted through the lens to the photosensitive element of the camera 113. The light signal is converted into an electrical signal, and the photosensitive element of the camera 113 transmits the electrical signal to the ISP for processing, converting it into an image visible to the naked eye. The ISP can also perform algorithmic optimization on image noise and brightness. The ISP can also optimize parameters such as exposure and color temperature of the shooting scene. In some embodiments, the ISP can be set in the camera 113.

[0128] Camera 113 is used to capture still images or videos. An object is projected onto a photosensitive element by generating an optical image through the lens. The photosensitive element can be a charge-coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the light signal into an electrical signal, which is then passed to an ISP for conversion into a digital image signal. The ISP outputs the digital image signal to a DSP for processing. The DSP converts the digital image signal into image signals in standard RGB, YUV, or other formats. In some embodiments, the electronic device 100 may include one or N cameras 113, where N is a positive integer greater than 1.

[0129] The software system of electronic device 100 can adopt a layered architecture, event-driven architecture, microkernel architecture, microservice architecture, or cloud architecture. This application embodiment uses a layered Android system as an example to illustrate the software structure of electronic device 100.

[0130] Figure 2 is a software structure block diagram of an electronic device 100 according to an embodiment of this application.

[0131] It should be understood that a layered architecture can divide software into several layers, each with a clear role and division of labor; the layers can communicate with each other through software interfaces.

[0132] As shown in Figure 2, the Android system can be divided into four layers: from top to bottom, the application layer, the application framework layer, the Android runtime and system libraries, and the kernel layer. The application layer can include a series of application packages.

[0133] As shown in Figure 2, the application package can include applications such as camera, gallery, map, navigation, WLAN, Bluetooth, music, SMS, and communication applications. Communication applications include telecommunications applications and internet audio / video applications. For example, a telecommunications application could be a telephone service. An internet audio / video application could be a connection service like MeeTime.

[0134] The application framework layer provides application programming interfaces (APIs) and a programming framework for applications in the application layer. The application framework layer includes some predefined functions.

[0135] As shown in Figure 2, the application framework layer may include a window manager, content provider, view system, phone manager, resource manager, notification manager, etc.

[0136] The application framework layer provides application programming interfaces (APIs) and a programming framework for applications in the application layer. The application framework layer includes some predefined functions.

[0137] As shown in Figure 2, the application framework layer may include a window manager, content provider, view system, phone manager, resource manager, notification manager, etc.

[0138] The window manager is used to manage windowed applications. It can retrieve screen size, determine the presence of a status bar, lock the screen, and capture screenshots, among other things.

[0139] Content providers are used to store and retrieve data, making that data accessible to applications. This data can include videos, images, audio, phone calls made and received, browsing history and bookmarks, phone books, and more.

[0140] A view system includes visual controls, such as controls for displaying text and controls for displaying images. View systems can be used to build applications. A display interface can consist of one or more views.

[0141] The phone manager is used to provide communication functions for electronic device 100. For example, it manages call status (including connection and disconnection).

[0142] The file explorer provides applications with various resources, such as localized strings, icons, images, layout files, video files, and more.

[0143] The notification manager allows applications to display notification information in the status bar. It can be used to convey informational messages and can disappear automatically after a short time without user interaction.

[0144] The Android runtime consists of core libraries and a virtual machine. The Android runtime is responsible for scheduling and managing the Android system.

[0145] The core library consists of two parts: one part is the functionalities that need to be called by the Java language, and the other part is the Android core library.

[0146] The application layer and application framework layer run in a virtual machine. The virtual machine executes the Java files of the application layer and application framework layer as binary files. The virtual machine is used to perform functions such as object lifecycle management, stack management, thread management, security and exception management, and garbage collection.

[0147] The system library can include multiple functional modules, such as: surface manager, media libraries, 3D graphics processing libraries (e.g., Open Graphics Library for Embedded Systems, OpenGL ES) and 2D graphics engines (e.g., Skia Graphics Library, SGL).

[0148] The Surface Manager is used to manage the display subsystem and provides the blending of 2D and 3D layers for multiple applications.

[0149] The media library supports playback and recording of various audio and video formats, as well as still image files. It supports multiple audio and video encoding formats, such as MPEG4, H.264, Moving Picture Experts Group Audio Layer III (MP3), Advanced Audio Coding (AAC), Adaptive Multi-rate (AMR), Joint Photographic Experts Group (JPG), and Portable Network Graphics (PNG).

[0150] The 3D graphics processing library is used to implement 3D graphics drawing, image rendering, compositing, and layer processing.

[0151] A 2D graphics engine is a graphics engine for 2D drawing.

[0152] The kernel layer is the layer between hardware and software. The kernel layer contains at least the display driver, camera driver, audio driver, and sensor driver.

[0153] To facilitate understanding of the technical solution of this application, the relevant terms involved in this application are introduced below:

[0154] AIGC refers to the technology that uses artificial intelligence techniques such as generative adversarial networks and large-scale pre-trained models to learn from and recognize existing data, thereby possessing appropriate generalization capabilities and generating relevant content.

[0155] Deepfake technology refers to artificial intelligence technology that uses deep learning and generative adversarial networks to learn from a large number of samples, splicing together facial expressions, sounds and body movements from images or videos to generate fake content that is indistinguishable from real ones.

[0156] Artificial intelligence (AI) refers to a technology that uses computer technology to simulate certain human thought processes and intelligent behaviors.

[0157] A rich execution environment (REE) is an open execution environment that allows various general-purpose operating systems and applications to run. The operating system can be, for example, a... wait.

[0158] A Trusted Execution Environment (TEE) is a secure area built on a computing platform using hardware and software methods, ensuring that code and data loaded within this secure area are protected. A TEE can serve as a trusted application runtime environment.

[0159] Trusted application (TA): refers to a trusted application running in a TEE.

[0160] A trusted UI (TUI) refers to a user interface that runs within a TEE (Trusted Interface Environment). It ensures that when users interact with the TUI, their data and operations are protected from being stolen or tampered with by malware or attackers.

[0161] Deepfake technology refers to artificial intelligence technology that uses deep learning and generative adversarial networks to learn from a large number of samples, splicing together facial expressions, sounds and body movements from images or videos to generate fake content that is indistinguishable from real ones.

[0162] Public key infrastructure (PKI) is a cryptographic system based on the public-private key hierarchy, including PKI policies, hardware and software systems, certificate authorities (CAs), registration authorities (RAs), certificate issuance systems, and PKI applications.

[0163] Replay attack: A replay attack is a type of network attack in which the attacker repeatedly sends previously intercepted valid data packets to deceive the receiving end.

[0164] Camera service: This is a service provided by the operating system that is responsible for managing camera devices and controlling their capture of image or video data.

[0165] For ease of understanding, the communication method provided in the embodiments of this application will be specifically described below with reference to the accompanying drawings and application scenarios. Exemplarily, the first terminal device, the second terminal device, or the server in the following embodiments can be the electronic devices shown in Figures 1 and 2.

[0166] Currently, malicious actors collect audio and video footage of targets (such as a user's relatives and friends), then use this footage, AIGC technology, and Deepfake technology to train a model capable of generating audio and video content highly similar to the target. These fraudulent actors then inject this fake audio and video content into phone calls, making the user believe they are speaking to a real friend or relative. During the call, the criminals often fabricate emergencies to trick the user into transferring money or providing sensitive information such as bank card numbers or passwords. This fraudulent activity leads to financial losses for users and degrades their call experience.

[0167] In related technologies, phone number tagging is commonly used to reduce call risks. This approach relies on the spontaneous actions of a large number of users, who tag phone numbers, and then a specialized tagging website aggregates and organizes this data. When a user receives an incoming call, the phone number and its tagging information are displayed as a risk warning. However, this phone number tagging method depends on human intervention, which limits its accuracy, resulting in relatively poor call security and a degraded user experience.

[0168] Based on this, embodiments of this application provide a communication method applied to a first terminal device. This method, during a call between the first and second terminal devices, outputs a prompt message based on the matching result between the first biometric data of the call participant and the second biometric data of the participant corresponding to the first multimedia data. The prompt message is used to indicate the call security status. The first multimedia data is multimedia data sent by the second terminal device during the call and presented to the user of the first terminal device. This allows users to prevent call fraud based on the prompt message, ensuring the reliability and security of the call service and improving the user's call experience.

[0169] It should be understood that the notification message can be presented in at least one of the following forms: text, icon, vibration, light, etc. The first biometric data can be called trusted biometric data, and the second biometric data can be called communication biometric data.

[0170] The matching result can represent the degree of matching between the first biometric data and the second biometric data. Alternatively, the matching result can also represent whether the first biometric data and the second biometric data match. This matching can be determined based on the degree of matching between the first and second biometric data; for example, if the degree of matching is greater than or equal to a target matching threshold, the first and second biometric data are considered to match; if the degree of matching is less than the target matching threshold, the first and second biometric data are considered not to match.

[0171] It should be understood that the first terminal device can be a terminal device that answers a call during a call service, and the second terminal device can be a terminal device that initiates a call during a call service. Of course, the first terminal device can also be a terminal device that initiates a call during a call service, and the second terminal device can be a terminal device that answers a call during a call service.

[0172] It should be noted that the communication method provided in this paper can be applied only to the terminal device receiving the call or only to the device initiating the call during a call between the first and second terminal devices. Alternatively, it can be applied to both the terminal device receiving the call and the device initiating the call; in other words, anti-fraud authentication is bidirectional during a call between the first and second terminal devices.

[0173] The following provides an exemplary explanation of how the interface changes of the communication method provided in the embodiments of this application change in specific scenarios.

[0174] First, let's take a mobile phone as the first terminal device and a video call scenario as an example for explanation.

[0175] Example 1: During a video call, the mobile phone can display the first display interface 31 shown in Figure 3. When a match is detected between the first biometric data and the second biometric data, the second display interface 41 shown in Figure 4(a) or the third display interface 42 shown in Figure 4(b) can be displayed. The second display interface 41 displays a prompt message: "Friendly reminder: The person shown in the video call is consistent with the actual person in front of the other party's phone camera," along with an icon 411. The third display interface 42 displays a prompt message: "Friendly reminder: There is no risk in video calls," along with an icon 411. No prompt is displayed when a mismatch is detected between the first and second biometric data, or when the first biometric data cannot be obtained; the mobile phone continues to display the first display interface 31 shown in Figure 3.

[0176] Based on the above scheme, the user is prompted when the first biometric data matches the second biometric data, allowing the user to make a call with peace of mind. In other cases, the user is not prompted to avoid disturbing the user and improve the user experience.

[0177] Example 2: During a video call, the mobile phone can display the first display interface 31 shown in Figure 3. No prompt is made when the first biometric data matches the second biometric data, or when the first biometric data cannot be obtained; the phone continues to display the first display interface 31 shown in Figure 3. When the first biometric data does not match the second biometric data, the phone can display the fourth display interface 51 shown in Figure 5(a) or the fifth display interface 52 shown in Figure 5(b). The fourth display interface 51 displays a prompt message: "Warning: The person shown in the video call is inconsistent with the actual person in front of the other party's phone camera," along with an icon 511. The fifth display interface 52 displays a prompt message: "Warning: Video call carries risks," along with an icon 511.

[0178] Based on the above scheme, the user is only alerted when the first biometric data does not match the second biometric data, so that the user can quickly realize the potential security threat and take corresponding preventive measures, thereby improving the security of the call. In other cases, the user is not alerted to avoid disturbing the user and improve the user experience.

[0179] Example 3: During a video call, the mobile phone can display the first display interface 31 shown in Figure 3. When a match is detected between the first biometric data and the second biometric data, the second display interface 41 shown in Figure 4(a) or the third display interface 42 shown in Figure 4(b) can be displayed. When it is determined that the first biometric data and the second biometric data do not match, the mobile phone can display the fourth display interface 51 shown in Figure 5(a) or the fifth display interface 52 shown in Figure 5(b). When the first biometric data cannot be obtained, no prompt is given; the mobile phone continues to display the first display interface 31 shown in Figure 3.

[0180] Based on the above scheme, regardless of whether the first biometric data matches the second biometric data, the user can be prompted, enabling the user to fully understand the current video call environment, make corresponding judgments and actions, improve call security, and further enhance the user's call experience.

[0181] The following explanation uses a mobile phone as the first terminal device and a telephone call scenario as an example.

[0182] Example 1: During a phone call, the mobile phone can display the sixth display interface 61 shown in Figure 6. When the first biometric data matches the second biometric data, it can display either the seventh display interface 71 shown in Figure 7(a) or the eighth display interface 72 shown in Figure 7(b). The seventh display interface 71 displays a prompt message: "Friendly reminder: The person speaking in the call matches the person in front of the other party's phone microphone." The eighth display interface 72 displays a prompt message: "Friendly reminder: There is no risk in the call." No prompt is displayed when the first biometric data does not match the second biometric data, or when the first biometric data cannot be obtained; the mobile phone continues to display the sixth display interface 61 shown in Figure 6.

[0183] Based on the above scheme, the user is prompted when the first biometric data matches the second biometric data, allowing the user to make a call with peace of mind. In other cases, the user is not prompted to avoid disturbing the user and improve the user experience.

[0184] Example 2: During a phone call, the mobile phone can display the sixth display interface 61 shown in Figure 6. No prompt is made when the first biometric data matches the second biometric data, or when the first biometric data cannot be obtained; the phone continues to display the sixth display interface 61 shown in Figure 6. When a mismatch is detected between the first and second biometric data, the phone can display the ninth display interface 81 shown in Figure 8(a) or the tenth display interface 82 shown in Figure 8(b). The ninth display interface 81 displays a prompt message: "Warning: The person speaking in the call is inconsistent with the person in front of the microphone on the other end of the phone." The tenth display interface 82 displays a prompt message: "Warning: There is a risk in the call."

[0185] Based on the above scheme, the user is only alerted when the first biometric data does not match the second biometric data, so that the user can quickly realize the potential security threat and take corresponding preventive measures, thereby improving the security of voice calls. In other cases, the user is not alerted to avoid disturbing the user and improve the user experience.

[0186] Example 3: During a phone call, the mobile phone can display the sixth display interface 61 shown in Figure 6. When the first biometric data matches the second biometric data, it can display the seventh display interface 71 shown in Figure 7(a) or the eighth display interface 72 shown in Figure 7(b). When it is determined that the first biometric data does not match the second biometric data, the mobile phone can display the ninth display interface 81 shown in Figure 8(a) or the tenth display interface 82 shown in Figure 8(b). When the first biometric data cannot be obtained, no prompt is given; the mobile phone continues to display the sixth display interface 61 shown in Figure 6.

[0187] Based on the above scheme, regardless of whether the first biometric data matches the second biometric data, the user can be prompted, enabling the user to fully understand the current voice call environment, so as to make corresponding judgments and actions, improve call security, and further enhance the user's call experience.

[0188] The following example illustrates the changes in user experience when the communication method provided in this application is applied to the first terminal device (i.e., the receiving user's device) in a call service, with the first terminal device being the terminal device that answers the call (i.e., the sending user's device) and the second terminal device being the terminal device that initiates the call (i.e., the sending user's device).

[0189] As shown in Figure 9(a), when the sending user (i.e., the user initiating the call) is a normal user, during the video call between the first terminal device and the second terminal device, the first terminal device can output a prompt message indicating that there is no risk in the video call. The receiving user (i.e., the user answering the call) can use this prompt message to confirm that the current video call is reliable and secure, thus allowing them to continue the call with peace of mind. For example, the prompt message might be the text "Friendly Reminder: There is no risk in the video call" and icon 411 in the third display interface 42 shown in Figure 4(b).

[0190] Conversely, as shown in Figure 9(b), if the sending user is a criminal, during a video call between the first and second terminal devices, the first terminal device can output a warning message indicating a risk associated with the video call. This means the person and their speech seen on the video interface by the receiving user may be fake (e.g., synthesized using Deepfake technology). Based on this warning message, the receiving user can increase their vigilance and prevent potential call fraud. For example, the warning message could be the text "Warning: Video call is risky" and icon 511 in the fifth display interface 52 shown in Figure 5(b).

[0191] Furthermore, as shown in Figure 9(c), if the second terminal device does not support audio / video detection, the first terminal device will not output any prompt message. Alternatively, if the second terminal device does not support audio / video detection, the first terminal device can also output a prompt message to inform the other party device that it does not support audio / video detection. For example, the message "The other party device does not support audio / video detection" can be displayed on the video call interface of the first terminal device.

[0192] For example, the second terminal device may not support audio and video detection functions because the anti-fraud authentication service has not been activated on the second terminal device.

[0193] The communication method provided in the embodiments of this application will be explained in detail below with reference to several examples.

[0194] Figure 10 is a flowchart illustrating a communication method 1000 provided in an embodiment of this application. This communication method 1000 is applied to a first terminal device. Both the first and second terminal devices are equipped with communication applications, including internet audio / video applications and telecommunications applications, where the telecommunications application can be a telephone call. This communication method 1000 can be applied to scenarios where communication applications on the first and second terminal devices conduct voice calls. As shown in Figure 10, the communication method 1000 includes steps S1001 to S1003. The communication method 1000 is not limited to the specific order shown in Figure 10. It should be understood that in other embodiments, the order of some steps in the communication method 1000 can be interchanged according to actual needs, or some steps can be omitted or deleted. The following provides a detailed explanation of each step.

[0195] S1001. During a call between the first terminal device and the second terminal device, the first terminal device acquires the first biometric data of the call subject, wherein the call subject is the person using the second terminal device to make the call.

[0196] The first biometric data can be collected by the second terminal device in a TEE environment. The first biometric data identifies the person using the second terminal device to make a call.

[0197] It should be understood that the call service can be either a voice call service or a video call service. Voice calls can be implemented through telecommunications applications or internet audio / video applications. For example, a telecommunications application could be a telephone, and an internet audio / video application could be a streaming service like MeeTime.

[0198] In one possible implementation, when the call service is a voice call service, the first biometric data can be the voiceprint data of the person making the call using the second terminal device; wherein, the voiceprint data includes feature data such as tone, timbre and speech rate.

[0199] In one possible implementation, when the call service is a video call service, the first biometric data can be the facial data of the person making the call using the second terminal device, or the first biometric data can be the facial data and voiceprint data of the person making the call using the second terminal device. The facial data can be a facial image or facial feature data extracted from a facial image; the facial feature data includes features such as the shape of facial features and facial contours.

[0200] In this embodiment, the first biometric data may be sent by the second terminal device, or it may be determined based on the second multimedia data sent by the second terminal device. The second multimedia data is collected by the multimedia data acquisition component of the second terminal device during a call between the first and second terminal devices.

[0201] In one possible implementation, obtaining the first biometric data of the call subject in step S1001 includes: receiving first data and a first signature corresponding to the first data from a second terminal device, wherein the first data is used to determine the first biometric data; verifying the first signature, and, if the verification is successful, determining the first biometric data based on the first data. The first data and the first signature can be sent directly from the second terminal device to the first terminal device; alternatively, the first data and the second signature can also be sent from the second terminal device to the first terminal device via a server.

[0202] The first data and its corresponding first signature can be actively sent by the second terminal device. This indicates that the anti-fraud authentication is triggered by the second terminal device during the call.

[0203] Of course, the first data and the corresponding first signature can also be sent by the second terminal device based on an acquisition request, which is a request sent by the first terminal device to acquire the first data. In this case, it can be indicated that the anti-fraud authentication is triggered by the first terminal device during the call.

[0204] Based on the above scheme, by verifying the first signature, the integrity and authenticity of the first data used to obtain the first biometric data can be ensured, and the first data can be prevented from being tampered with or forged during transmission, thereby enhancing the security of the first data.

[0205] In one possible implementation, first biometric data is determined based on first data, wherein the first data is first biometric data, or the first data is second multimedia data.

[0206] S1002, the first terminal device matches the first biometric data and the second biometric data to obtain a matching result. The second biometric data is determined based on the first multimedia data, which is the multimedia data sent by the second terminal device during the call service to be presented to the user using the first terminal device.

[0207] The matching result can represent the degree of matching between the first biometric data and the second biometric data. Alternatively, the matching result can represent whether the first biometric data and the second biometric data match.

[0208] In one possible implementation, if the matching degree between the first biometric data and the second biometric data is greater than or equal to a target matching degree threshold, a matching result indicating a match between the first biometric data and the second biometric data is generated. If the matching degree is less than the target matching degree threshold, a matching result indicating a mismatch between the first biometric data and the second biometric data is generated.

[0209] For example, if the first biometric data and the second biometric data match, it can be determined that the person making the call using the second terminal device is the same as the person corresponding to the first multimedia data. If the first biometric data and the second biometric data do not match, it indicates that the person making the call using the second terminal device is not the same as the person corresponding to the first multimedia data.

[0210] In one possible implementation, when the call service is a voice call, the second biometric data can be the voiceprint data of the object corresponding to the first multimedia data; wherein, the voiceprint data includes feature data such as pitch, timbre, and speech rate. When the call service is a video call, the second biometric data can be the face data of the object corresponding to the first multimedia data, or, the second biometric data can be the face data and voiceprint data of the object corresponding to the first multimedia data. The face data can be a face image or face feature data extracted from a face image; the face feature data includes feature data such as the shape of facial features and facial contours.

[0211] S1003. Based on the matching result, output a prompt message. The prompt message is used to indicate the security status of the call.

[0212] It should be understood that call security can be considered from at least one of two dimensions: the authentication of the call participant and the security risks during the call. The call participant is the person using a second terminal device to conduct the call. The notification information can be presented in at least one of the following forms: text, icon, vibration, light, etc.

[0213] In this application embodiment, the authentication of the call subject can be reflected in whether the call subject is consistent with the object corresponding to the first multimedia data, or in the similarity between the call subject and the object corresponding to the first multimedia data. The call security status during the call can be reflected in whether there are any risks during the call.

[0214] In one possible implementation, the similarity between the call subject and the object corresponding to the first multimedia data can be consistent with the matching degree between the first biometric data and the second biometric data.

[0215] For example, the matching degree between the first biometric data and the second biometric data is 90%, and the similarity between the call subject and the object corresponding to the first multimedia data is also 90%.

[0216] In one possible implementation, the similarity between the call subject and the object corresponding to the first multimedia data can be determined based on the matching degree between the first biometric data and the second biometric data, as well as the target correspondence. The target correspondence represents the correspondence between the preset matching degree and the preset similarity.

[0217] For example, the matching degree between the first biometric data and the second biometric data is 90%, and the similarity between the call object determined based on the matching degree and the target correspondence and the object corresponding to the first multimedia data can be 95%.

[0218] In one possible implementation, a corresponding prompt can be given regardless of the matching result. For example, the matching result represents the matching degree between the first biometric data and the second biometric data. The similarity between the call subject and the object corresponding to the first multimedia data can be determined based on the matching degree, and then a prompt message can be output to indicate the similarity between the call subject and the object corresponding to the first multimedia data.

[0219] Taking video call service as an example, the prompt message could be something like "The person shown in the video call has a 90% similarity to the actual person in front of the other party's phone camera," or it could be something like "The person shown in the video call has a 5% similarity to the actual person in front of the other party's phone camera."

[0220] Based on the above scheme, the similarity between the caller and the object corresponding to the first multimedia data can be indicated to the user, so that the user can judge whether there is a risk in the call based on this similarity, enhance the user's awareness of preventing call fraud, and improve the user's call security and call experience.

[0221] In one possible implementation, the decision to issue a prompt is based on the matching result. For example, a prompt message is only output if there is a mismatch between the first biometric data and the second biometric data. This prompt message indicates that the person being called is not the same as the person corresponding to the first multimedia data or that there is a risk in the call.

[0222] Based on the above solution, users can quickly recognize potential security threats based on the prompts and take corresponding preventative measures, thereby improving call security. In other situations, no prompts are given to avoid disturbing the user and enhancing the user experience.

[0223] The following section provides a detailed explanation of how S1003 outputs prompt information based on the matching results, using application scenarios as examples.

[0224] In one possible implementation, the prompt message is a first prompt message. If the matching degree between the first biometric data and the second biometric data is greater than or equal to a target matching degree threshold (i.e., the first biometric data and the second biometric data match), the first prompt message is output. This first prompt message indicates that the call recipient matches the object corresponding to the first multimedia data, that the call is not risky, or indicates the similarity between the call recipient and the object corresponding to the first multimedia data. If the matching degree between the first biometric data and the second biometric data is less than the target matching degree threshold (i.e., the first biometric data and the second biometric data do not match), no prompt is given.

[0225] For example, for video call services, the first prompt message is used to indicate that the person being called is consistent with the person corresponding to the first multimedia data. The first prompt message is, for example, the text "Friendly reminder: The person displayed in the video call is consistent with the actual person in front of the other party's phone camera" and icon 411 in the second display interface 41 shown in Figure 4(a). Alternatively, the first prompt message is used to indicate that there is no risk in the call. The first prompt message is, for example, the text "Friendly reminder: There is no risk in the video call" and icon 411 in the third display interface 42 shown in Figure 4(b).

[0226] For example, for voice call services, the first prompt message is used to indicate that the call recipient is consistent with the recipient corresponding to the first multimedia data. The first prompt message is, for example, the text "Friendly reminder: The person speaking in the call is consistent with the person in front of the microphone of the other party's mobile phone" in the seventh display interface 71 shown in Figure 7(a). Or the first prompt message is, for example, the text "Friendly reminder: There is no risk in the call" in the eighth display interface 72 shown in Figure 7(b).

[0227] Based on the above scheme, the first prompt message can be output only when the matching degree between the first biometric data and the second biometric data is greater than or equal to the target matching degree threshold (i.e., the first biometric data and the second biometric data match), so as to remind the user that the call is safe and allow the user to make a call with peace of mind. In other cases, the user will not be prompted to avoid disturbing the user and improve the user experience.

[0228] In one possible implementation, the prompt message is a second prompt message. If the matching degree between the first biometric data and the second biometric data is greater than or equal to a target matching degree threshold (i.e., the first biometric data and the second biometric data match), no prompt is made. If the matching degree between the first biometric data and the second biometric data is less than the target matching degree threshold (i.e., the first biometric data and the second biometric data do not match), the second prompt message is output. The second prompt message is used to indicate that the call recipient is inconsistent with the recipient corresponding to the first multimedia data, that the call is risky, or the similarity between the call recipient and the recipient corresponding to the first multimedia data.

[0229] For example, for video call services, the second prompt message is used to indicate that the person being called is inconsistent with the person corresponding to the first multimedia data. The second prompt message is, for example, the text "Warning: The person displayed in the video call is inconsistent with the actual person in front of the other party's phone camera" and icon 511 in the fourth display interface 51 shown in Figure 5(a). Alternatively, the second prompt message indicates that the call is at risk. The second prompt message is the text "Warning: Video call is at risk" and icon 511 in the fifth display interface 52 shown in Figure 5(b).

[0230] For example, for voice call services, the second prompt message is used to indicate that the person being called is inconsistent with the person corresponding to the first multimedia data. The second prompt message could be, for example, the text "Warning: The person speaking in the call is inconsistent with the person in front of the microphone on the other party's mobile phone" in the ninth display interface 81 shown in Figure 8(a). Alternatively, the second prompt message can be used to indicate that the call is at risk, and the second prompt message could be the text "Warning: The call is at risk" in the tenth display interface 82 shown in Figure 8(b).

[0231] Based on the above scheme, a second prompt message can be output only when the matching degree between the first biometric data and the second biometric data is less than the target matching degree threshold (i.e., the first biometric data and the second biometric data do not match). This prompts the user that the call is unsafe, allowing the user to quickly realize the potential security threat and take corresponding preventive measures, thereby improving call security. In other cases, no prompt is given to avoid disturbing the user and improving the user experience.

[0232] In one possible implementation, if the matching degree between the first biometric data and the second biometric data is greater than the target matching degree threshold (i.e., the first biometric data and the second biometric data match), a first prompt message is output; if the matching degree between the first biometric data and the second biometric data is less than the target matching degree threshold (i.e., the first biometric data and the second biometric data do not match), a second prompt message is output.

[0233] Based on the above scheme, when the matching degree between the first and second biometric data is greater than or equal to the target matching degree threshold (i.e., the first and second biometric data match), a first prompt message is output, which enhances the user's sense of trust and security. When the matching degree between the first and second biometric data is less than the target matching degree threshold (i.e., the first and second biometric data do not match), a second prompt message is output, enabling the user to quickly recognize potential security threats and take corresponding preventive measures, thereby improving call security. In this way, users can fully understand the current call environment, enhancing the security and reliability of the call process.

[0234] It should be noted that in practical applications, the presentation format and timing of prompts can be flexibly set, enabling users to understand the current call security status in a timely manner, thereby preventing call fraud and improving the user's call experience.

[0235] This application provides a communication method that, during a call between a first terminal device and a second terminal device, outputs a notification message indicating the call security status. This allows the user to prevent call fraud based on the notification message, ensuring the reliability and security of the call service and improving the user's call experience.

[0236] Figure 11 is a flowchart illustrating another communication method 1100 provided in an embodiment of this application. Communication method 1100 can be a refinement of communication method 1000 in the above embodiments. Both the first terminal device and the second terminal device have a communication application installed, such as an internet audio / video application. This communication method 1100 can be applied to scenarios where the internet audio / video application on the first terminal device and the internet audio / video application on the second terminal device conduct call services, such as voice calls or video calls. This communication method 1100 is not limited to the specific order shown in Figure 11. It should be understood that in other embodiments, the order of some steps in this communication method 1100 can be interchanged according to actual needs, or some steps can be omitted or deleted. The following provides a detailed explanation of each step.

[0237] S1101. During a call between the first terminal device and the second terminal device, the first terminal device sends a request to the second terminal device to obtain first data. The first data is used to determine the first biometric data of the call subject, and the call subject is the person using the second terminal device to make the call.

[0238] In one possible implementation, the request could be a request to obtain first biometric data.

[0239] In one possible implementation, the request can be for acquiring second multimedia data; the second multimedia data is multimedia data acquired by the multimedia data acquisition component of the second terminal device during a call between the first and second terminal devices. Specifically, for voice calls, the second multimedia data may be, for example, audio data. For video calls, the second multimedia data may be, for example, audio data and image data, or the second multimedia data may be image data.

[0240] S1102, The second terminal device receives the acquisition request.

[0241] S1103. In response to the acquisition request, the second terminal device collects the first data and signs the second data containing the first data using the device's anti-fraud private key to obtain the first signature.

[0242] The first data is either the first biometric data or the second multimedia data.

[0243] The following distinction between scenarios provides a detailed explanation of the collection of the first biometric data and the collection of the second multimedia data.

[0244] In one possible implementation, for video call services, the second terminal device can capture image data within its field of view using a front-facing camera and use it as second multimedia data. Alternatively, the second terminal device can capture image data within its field of view using a front-facing camera and audio data within its pickup range using a microphone, using both image and audio data as second multimedia data.

[0245] The first biometric data can be obtained by a second terminal device through processing such as face recognition, liveness detection, image capture detection, and biometric extraction based on the second multimedia data. Face recognition can be performed using a front-facing camera, and voiceprint extraction can be performed using an audio chip. The camera can be a Swing camera, meaning it can acquire images and perform face recognition in low-power mode.

[0246] For example, if the second multimedia data is image data, the second terminal device can perform image re-capture detection and liveness detection based on the image data. If the image data represented by the image re-capture detection result does not contain a re-captured image and the object corresponding to the image data represented by the liveness detection result is a live object, the face data obtained by extracting facial features from the image data will be used as the first biometric data. Here, biometric extraction refers to face feature extraction.

[0247] For example, if the second multimedia data consists of image data and audio data, the second terminal device can perform image re-engraving detection on the image data and liveness detection based on the image data and audio data. If the image data represented by the image re-engraving detection result does not contain a re-engraved image, and the object corresponding to the image data and audio data represented by the liveness detection result is a live object, the face data obtained by extracting facial features from the image data and the voiceprint data obtained by extracting voiceprint features from the audio data are used as the first biometric data. The biometric extraction includes face feature extraction and voiceprint feature extraction.

[0248] It should be noted that the order of face recognition, image capture detection, liveness detection, and biometric extraction can be flexibly configured according to business requirements. This application embodiment does not impose a limitation on the order of face recognition, image capture detection, liveness detection, and biometric extraction.

[0249] Based on the above scheme, it is possible to effectively identify reproduced or forged images, ensuring that the image data used for biometric extraction is authentic and unaltered. Simultaneously, by combining it with liveness detection technology, the system further verifies that the object corresponding to the image data is a real, living person, thereby improving the accuracy and reliability of the collected primary biometric data. This further enhances the reliability and accuracy of the output alerts, strengthens users' awareness of call fraud prevention, and improves the user's call experience.

[0250] In one possible implementation, facial data can be a facial image or facial feature data extracted from a facial image. Facial feature data includes features such as the shape of facial features and facial contours. Voiceprint data includes features such as pitch, timbre, and speech rate.

[0251] In one possible implementation, for voice call services, the second terminal device can collect audio data within the pickup range using a microphone and use this audio data as second multimedia data.

[0252] For example, liveness detection can be performed based on audio data. If the liveness detection indicates that the object corresponding to the audio data is a live object, then the voiceprint data obtained by extracting voiceprint features from the audio data can be used as the first biometric data. Here, biometric extraction is voiceprint feature extraction.

[0253] It should be noted that the order of liveness detection and voiceprint feature extraction can be flexibly set according to business needs. This application embodiment does not limit the order of liveness detection and voiceprint feature extraction.

[0254] Based on the above scheme, it is ensured that the acquired first biometric data comes from a real living object, which enhances the reliability and accuracy of subsequent identity verification based on the first and second biometric data, and further improves the reliability and accuracy of the output prompt information.

[0255] In one possible implementation, the second terminal device includes a second TA, which is set in the TEE of the second terminal device. The first data is first biometric data. Collecting the first data includes: during a call between the first terminal device and the second terminal device, collecting second multimedia data through the multimedia data acquisition component of the second terminal device; and determining the first biometric data based on the second multimedia data through the second TA.

[0256] Based on the above scheme, the first data is collected in the TEE environment of the second terminal device. Due to the security isolation mechanism of the TEE environment, it can effectively prevent the access and tampering of malicious software, thereby significantly enhancing the security of the collected first data.

[0257] In this embodiment, signing the second data containing the first data using the device's anti-fraud private key to obtain the first signature includes: the second terminal device signing the second data using the device's anti-fraud private key via a second TA to obtain the first signature. The second TA is located in the TEE.

[0258] The device anti-fraud private key can be generated by the second terminal device based on the device certificate of the second terminal device stored in the TEE. This device certificate is used to prove the identity of the second terminal device.

[0259] It should be understood that a TEE (Technical Equipment Environment) is a secure environment combining hardware and software. It provides an isolated space for protecting the storage and processing of sensitive data, ensuring the security of device certificates during storage. Within the TEE, a second TA (Technical Agreement) is used to sign the second data, ensuring the security of the signing process.

[0260] In this embodiment, the manufacturer embeds the device certificate and device private key into the TEE (Transport Equipment Environment) when the terminal device leaves the factory. This ensures the authenticity and integrity of the device certificate, providing a solid foundation for subsequent verification of the identity of the second terminal device based on the device certificate. The device certificate carries the device public key corresponding to the device private key. The device certificate is generated based on the root private key of the device PKI system.

[0261] In one possible implementation, the second data can be the first data.

[0262] In another possible implementation, the second data includes the first data and a session random number. The session random number can be carried in a retrieval request used to retrieve the first data.

[0263] Based on the above scheme, by including a session random number in the retrieval request, it can be ensured that the retrieval request is unique, and thus the data obtained based on the retrieval request is also unique. This method can effectively prevent replay attacks and avoid attackers using historically obtained first-time data for call fraud.

[0264] It should be noted that S1101 to S1103 in Figure 11 indicate that the first data is collected by the second terminal device in response to the acquisition request, and the anti-fraud authentication is triggered on the side of the first terminal device. S1101 to S1103 are only one example. The first data can also be actively collected by the second terminal device during a call between the first terminal device and the second terminal device. In other words, the anti-fraud authentication is triggered on the side of the second terminal device.

[0265] In one possible implementation, the second terminal device sends first data and a first signature to the first terminal device. The first data and the first signature can be transmitted directly or transmitted in encrypted form. Figure 11 illustrates an example where the first data and the first signature are transmitted in encrypted form.

[0266] S1104. The second terminal device encrypts the first data and the first signature to obtain ciphertext.

[0267] The encryption can employ either a symmetric or asymmetric encryption algorithm. In practical applications, the encryption algorithm can be flexibly set. This application does not specify the specific encryption algorithm used for "encrypting the first data and the first signature".

[0268] Based on the above scheme, by sending the first data and the first signature in encrypted form, the first data can be prevented from being stolen during transmission, thus improving the security of data transmission.

[0269] S1105. The second terminal device sends encrypted text, a device certificate, and a first anti-fraud certificate to the first terminal device. The first anti-fraud certificate is generated based on the device private key. The first anti-fraud certificate carries the device anti-fraud public key corresponding to the device anti-fraud private key. The device certificate carries the device public key corresponding to the device private key.

[0270] The first anti-fraud certificate is generated by the second terminal device using its private key within the device PKI system. Both the device private key and the device certificate are set in the TEE (Transfer Equipment) when the second terminal device leaves the factory.

[0271] S1106, The first terminal device receives the encrypted text, device certificate, and first anti-fraud certificate.

[0272] S1107. The first terminal device decrypts the ciphertext to obtain the first data and the first signature.

[0273] The encryption algorithm and the decryption algorithm are corresponding.

[0274] S1108. The first terminal device verifies the first signature based on the device certificate and the first anti-fraud certificate.

[0275] In one possible implementation, the first terminal device includes a first TA, which is configured in a Trusted Execution Environment (TEE). Verifying the first signature based on the device certificate and the first anti-fraud certificate includes: verifying the first signature using the first TA, based on the device certificate and the first anti-fraud certificate.

[0276] Specifically, the device certificate is verified using the device root public key via the first TA. If the device certificate verification is successful, it indicates that the device certificate is legitimate, and the device public key can be extracted from the device certificate. The first anti-fraud certificate is then verified based on the device public key. If the verification is successful, the device anti-fraud public key is extracted from the first anti-fraud certificate and used to verify the first signature.

[0277] Among them, the device root public key refers to the root public key in the device PKI system.

[0278] Based on the above scheme, by verifying the first signature, the integrity and authenticity of the first data used to obtain the first biometric data can be ensured, and the first data can be prevented from being tampered with or forged during transmission, thereby enhancing data security.

[0279] S1109. If the verification is successful and the first data is the first biometric data, the first terminal device matches the first biometric data with the second biometric data to obtain a matching result.

[0280] S1110. If the verification is successful and the first data is the second multimedia data, the first terminal device determines the first biometric data based on the second multimedia data, and matches the first biometric data with the second biometric data to obtain a matching result. The second multimedia data is collected by the multimedia data acquisition component of the second terminal device during the call service between the first terminal device and the second terminal device.

[0281] The first biometric data can be obtained by the first terminal device through processes such as face recognition, liveness detection, and biometric extraction based on the second multimedia data.

[0282] In one possible implementation, for video call services, the second multimedia data can be image data. If the image data representing the re-capture detection result does not contain a re-captured image and the object corresponding to the image data representing the liveness detection result is a live object, the first terminal device can use the facial data obtained by extracting facial features from the image data as the first biometric data.

[0283] If the second multimedia data can be image data and audio data, the first terminal device can perform image re-engraving detection on the image data and liveness detection based on the image data and audio data. If the image data represented by the image re-engraving detection result does not contain a re-engraved image and the object corresponding to the image data and audio data represented by the liveness detection result is a live object, the face data obtained by extracting facial features from the image data and the voiceprint data obtained by extracting voiceprint features from the audio data will be used as the first biometric data.

[0284] Based on the above scheme, by performing liveness detection and re-enactment detection on the image data in the second multimedia data, it can be ensured that the extracted first biometric data comes from a real and reliable data source, thereby improving the authenticity and accuracy of biometric extraction.

[0285] In one possible implementation, for voice call services, the second multimedia data can be audio data. The first terminal device can perform liveness detection and voiceprint feature extraction based on the audio data. If the liveness detection result indicates that the object corresponding to the audio data is a live object, the voiceprint data obtained by extracting voiceprint features from the audio data can be used as the first biometric data.

[0286] S1111, The first terminal device outputs a prompt message based on the matching result. The prompt message is used to indicate the security status of the call.

[0287] The implementation process of S1111 is the same as the implementation process of outputting prompt information based on matching results in S1003 in the aforementioned embodiment. For details, please refer to the implementation process of S1003. This application embodiment will not repeat the details here.

[0288] It should be noted that the descriptions of the same steps and contents in the embodiments of this application as in other embodiments can be referred to the descriptions in other embodiments, and will not be repeated here.

[0289] This application provides a communication method that, during a call between a first terminal device and a second terminal device, outputs a notification message indicating the call security status. This allows the user to prevent call fraud based on the notification message, ensuring the reliability and security of the call service and improving the user's call experience.

[0290] Figure 12 is a flowchart illustrating another communication method 1200 provided in an embodiment of this application. Communication method 1200 can be a refinement of communication method 1000 in the above embodiments. Both the first terminal device and the second terminal device are equipped with a communication application, such as an internet audio / video application. This communication method 1200 can be applied to scenarios where the internet audio / video application on the first terminal device and the internet audio / video application on the second terminal device conduct call services, such as voice calls or video calls. This communication method 1200 is not limited to the specific order shown in Figure 12. It should be understood that in other embodiments, the order of some steps in this communication method 1200 can be interchanged according to actual needs, or some steps can be omitted or deleted. The following provides a detailed explanation of each step.

[0291] S1201. The second terminal device signs the device anti-fraud public key based on the device's private key to obtain a second signature.

[0292] Among them, the device anti-fraud public key is generated based on the device certificate of the second terminal device.

[0293] In this embodiment of the application, the device anti-fraud public key is signed with the device private key, which can ensure the integrity of the device anti-fraud public key during transmission and prevent it from being tampered with.

[0294] S1202, the second terminal device sends a processing request to the server to generate a second anti-fraud certificate. The processing request carries the device's anti-fraud public key, a second signature, and a device certificate. The device certificate is used to prove the identity of the second terminal device.

[0295] S1203, The server receives the processing request.

[0296] S1204. If the server determines that the device certificate is valid based on the device root public key, it extracts the device public key from the device certificate and uses the device public key to verify the second signature.

[0297] Among them, the device root public key is the root public key of the device PKI system.

[0298] In this embodiment of the application, the device root public key can be used to verify the device certificate. If the verification is successful, it indicates that the device certificate is legitimate, and the device public key can be extracted from the device certificate.

[0299] S1205. If the server passes the verification, it generates a second anti-fraud certificate using the anti-fraud authentication root private key. The second anti-fraud certificate carries the device's anti-fraud public key.

[0300] Among them, the anti-fraud authentication root public key is the root public key of the anti-fraud PKI system.

[0301] This application embodiment uses two PKI systems. The first anti-fraud certificate can be generated by the second terminal device based on its private key within the device PKI system. The second anti-fraud certificate is generated by the server within the anti-fraud PKI system based on the anti-fraud authentication root private key, requested by the second terminal device. Both the first and second anti-fraud certificates can be used to carry the device's anti-fraud public key. In practical applications, either the first or second anti-fraud certificate can be flexibly selected for generation to facilitate signature verification on the first terminal device side during the subsequent anti-fraud authentication process (i.e., verifying the first signature).

[0302] S1206. The server sends the second anti-fraud certificate to the second terminal device.

[0303] S1207, The second terminal device receives the second anti-fraud certificate.

[0304] S1201 to S1207 are the process steps for the second terminal device to obtain a second anti-fraud certificate during the registration phase. S1208 to S1218 are the anti-fraud process steps during the business phase.

[0305] S1208. During a call between the first terminal device and the second terminal device, the first terminal device sends a request to the second terminal device to obtain first data. The first data is used to determine the first biometric data of the call subject, and the call subject is the person using the second terminal device to make the call.

[0306] S1209, The second terminal device receives the acquisition request.

[0307] S1210, the second terminal device responds to the acquisition request, collects the first data, and uses the device anti-fraud private key to sign the second data containing the first data to obtain the first signature.

[0308] The first data is either the first biometric data or the second multimedia data.

[0309] S1211, The second terminal device encrypts the first data and the first signature to obtain ciphertext.

[0310] S1212, The second terminal device sends encrypted text and the second anti-fraud certificate to the first terminal device.

[0311] S1213, The first terminal device receives the encrypted text and the second anti-fraud certificate.

[0312] S1214. The first terminal device decrypts the ciphertext to obtain the first data and the first signature.

[0313] S1215. The first terminal device verifies the first signature based on the second anti-fraud certificate.

[0314] In this embodiment, the first terminal device can verify the second anti-fraud certificate based on the anti-fraud authentication root public key, and extract the device's anti-fraud public key from the second anti-fraud certificate if the verification is successful. Subsequently, the device's anti-fraud public key is used to verify the first signature. The anti-fraud authentication root public key can be sent to the first terminal device by the server.

[0315] S1216. If the verification is successful and the first data is the first biometric data, the first terminal device matches the first biometric data with the second biometric data to obtain a matching result.

[0316] S1217. If the verification is successful and the first data is the second multimedia data, the first terminal device determines the first biometric data based on the second multimedia data, and matches the first biometric data with the second biometric data to obtain a matching result. The second multimedia data is collected by the multimedia data acquisition component of the second terminal device during the call service between the first terminal device and the second terminal device.

[0317] S1218. The first terminal device outputs a prompt message based on the matching result. The prompt message is used to indicate the security status of the call.

[0318] It should be noted that the descriptions of the same steps and contents in the embodiments of this application as in other embodiments can be referred to the descriptions in other embodiments, and will not be repeated here.

[0319] This application provides a communication method that, during a call between a first terminal device and a second terminal device, outputs a notification message indicating the call security status. This allows the user to prevent call fraud based on the notification message, ensuring the reliability and security of the call service and improving the user's call experience.

[0320] Figure 13 is a flowchart illustrating another communication method 1300 provided in an embodiment of this application. Communication method 1200 can be a refinement of communication method 1000 in the above embodiments. Both the first terminal device and the second terminal device are equipped with communication applications, including internet audio / video applications and telecommunications applications. For example, the internet audio / video application could be a mobile connection, and the telecommunications application could be a telephone. This communication method 1300 can be applied to scenarios where the internet audio / video application on the first terminal device and the internet audio / video application on the second terminal device conduct a call. It can also be applied to scenarios where the telecommunications application on the first terminal device and the telecommunications application on the second terminal device conduct a call, such as a voice call or a video call. This communication method 1300 is not limited to the specific order shown in Figure 13. It should be understood that in other embodiments, the order of some steps in this communication method 1300 can be interchanged according to actual needs, or some steps can be omitted or deleted. The following provides a detailed explanation of each step.

[0321] S1301. During a call between the first terminal device and the second terminal device, the first terminal device sends a request to the second terminal device to obtain first data. The first data is used to determine the first biometric data of the call subject, and the call subject is the person using the second terminal device to make the call.

[0322] S1302, The server forwards the acquisition request to the second terminal device.

[0323] In this embodiment of the application, the server receives an acquisition request sent from the first terminal device and forwards the acquisition request to the second terminal device.

[0324] S1303, The second terminal device receives the acquisition request.

[0325] S1304. In response to the acquisition request, the second terminal device collects the first data and signs the second data containing the first data using the device's anti-fraud private key to obtain the first signature.

[0326] S1305, the second terminal device encrypts the first data and the first signature to obtain ciphertext.

[0327] S1306 can be executed after S1305. S1306 can be implemented by S13061 to S13064, or S13065 to S13068.

[0328] S13061. Send ciphertext, device certificate and first anti-fraud certificate to the server. The first anti-fraud certificate is generated by the second terminal device based on the device private key. The first anti-fraud certificate carries the device anti-fraud public key corresponding to the device anti-fraud private key. The device certificate carries the device public key corresponding to the device private key.

[0329] S13062. The server forwards the encrypted text, device certificate, and first anti-fraud certificate to the first terminal device.

[0330] S13063, The first terminal device receives encrypted text, device certificate and first anti-fraud certificate.

[0331] S13064. The first terminal device decrypts the ciphertext to obtain the first data and the first signature, and verifies the first signature based on the device certificate and the first anti-fraud certificate.

[0332] S13065, The second terminal device sends encrypted text and the second anti-fraud certificate to the server.

[0333] S13066. The server forwards the encrypted text and the second anti-fraud certificate to the first terminal device. The second anti-fraud certificate is generated by the server based on the anti-fraud root private key and carries the device anti-fraud public key corresponding to the device's anti-fraud private key.

[0334] S13067, The first terminal device receives the encrypted text and the second anti-fraud certificate.

[0335] S13068. The first terminal device decrypts the ciphertext to obtain the first data and the first signature, and verifies the first signature based on the second anti-fraud certificate.

[0336] S1307. If the verification is successful and the first data is the first biometric data, the first terminal device matches the first biometric data with the second biometric data to obtain a matching result.

[0337] S1308. If the verification is successful and the first data is the second multimedia data, the first terminal device determines the first biometric data based on the second multimedia data, and matches the first biometric data with the second biometric data to obtain a matching result. The second multimedia data is collected by the multimedia data acquisition component of the second terminal device during the call service between the first terminal device and the second terminal device.

[0338] S1309. The first terminal device outputs a prompt message based on the matching result. The prompt message is used to indicate the security status of the call.

[0339] It should be noted that the descriptions of the same steps and contents in the embodiments of this application as in other embodiments can be referred to the descriptions in other embodiments, and will not be repeated here.

[0340] This application provides a communication method that, during a call between a first terminal device and a second terminal device, outputs a notification message indicating the call security status. This allows the user to prevent call fraud based on the notification message, ensuring the reliability and security of the call service and improving the user's call experience.

[0341] The above text provides a detailed introduction to methods 1000, 1100, 1200, and 1300, as well as their possible implementations. To facilitate understanding, the following text will further explain methods 1000, 1100, 1200, and 1300, as well as their possible implementations, in conjunction with the architecture and application scenarios of the communication system.

[0342] In the above method embodiments, the first and second anti-fraud certificates can be generated during the registration phase before the call service begins. Specifically, the first anti-fraud certificate is generated by the second terminal device within the device PKI system. The second anti-fraud certificate is generated by the server within the anti-fraud PKI system upon request from the second terminal device. The generation of the second anti-fraud certificate will be explained in detail below with reference to Figure 14.

[0343] Figure 14 is a schematic diagram of a registration process for a communication method applicable to this application, provided in an embodiment of this application. As shown in Figure 14, the application environment of the terminal device includes REE and TEE, wherein the anti-fraud authentication service is configured in the REE, and the TA is configured in the TEE. The terminal device is, for example, the first terminal device and the second terminal device in the above embodiments. As shown in Figure 14, the registration process specifically includes the following steps:

[0344] S1401, Activate anti-fraud authentication service.

[0345] Among them, the anti-fraud authentication service is a service provided by the operating system to identify and prevent call fraud.

[0346] In this embodiment of the application, the anti-fraud authentication service may be started automatically during the operation of the terminal device or in response to user operation.

[0347] For example, the terminal device's settings interface has a tab for user management of whether to enable the anti-fraud authentication service. Users can click this tab to access the permission configuration page. On this permission configuration page, clicking the option to enable the anti-fraud authentication service will cause the terminal device to respond to the user's action and activate the anti-fraud authentication service.

[0348] S1402. The anti-fraud authentication service sends an acquisition request to the TA, which is used to obtain the device anti-fraud public key for the terminal device.

[0349] S1403, TA receives the acquisition request.

[0350] S1404. In response to the acquisition request, TA generates a device anti-fraud public-private key pair based on the device certificate of the terminal device stored in TEE.

[0351] The device anti-fraud public-private key pair includes the device anti-fraud public key and the device anti-fraud private key.

[0352] Device certificates are used for authentication of terminal devices, ensuring that the terminal devices are legitimate and trusted. TEE is a secure environment combining hardware and software, providing an isolated space for protecting the storage and processing of sensitive data, and ensuring the security of device certificates during storage.

[0353] S1405, TA storage device anti-fraud private key, and send device anti-fraud public key to anti-fraud authentication service.

[0354] S1406, Anti-fraud authentication service receives the anti-fraud public key from the device.

[0355] S1407. The anti-fraud authentication service sends a processing request to the server to generate a device anti-fraud certificate. The processing request carries the device certificate, the device anti-fraud public key, and the signature of the device anti-fraud public key.

[0356] The device certificate is obtained by the anti-fraud authentication service from the TA. The signature of the device anti-fraud public key is obtained by the TA signing the device anti-fraud public key using the device's private key.

[0357] S1408, The server receives and processes the request.

[0358] S1409. In response to the processing request, the server verifies the device certificate using the root public key of the device PKI system (i.e., the device root public key). If the verification is successful, the server retrieves the device public key from the device certificate.

[0359] S1410. The server verifies the signature of the device anti-fraud public key using the device's public key. If the verification is successful, the server generates a device anti-fraud certificate using the root private key of the anti-fraud PKI system (i.e., the anti-fraud authentication root private key). The device anti-fraud certificate contains the device anti-fraud public key.

[0360] The anti-fraud authentication root private key is generated by the server.

[0361] In one possible implementation, the anti-fraud authentication root private key is used to sign information such as the device anti-fraud public key, the validity period of the device anti-fraud certificate, and the identifier of the terminal device to obtain the device anti-fraud certificate.

[0362] S1411. The server generates an end-to-cloud communication key and encrypts the end-to-cloud communication key using the device anti-fraud public key to obtain the ciphertext of the end-to-cloud communication key.

[0363] S1412. The server sends the anti-fraud authentication root public key, the device anti-fraud certificate, and the end-to-cloud communication secret key to the anti-fraud authentication service.

[0364] S1413. The anti-fraud authentication service receives the anti-fraud authentication root public key, the device anti-fraud certificate, and the encrypted end-to-cloud communication key.

[0365] S1414 The anti-fraud authentication service decrypts the encrypted end-to-end communication key to obtain the end-to-end communication key.

[0366] S1415. The anti-fraud authentication service sends the anti-fraud authentication root public key, the device anti-fraud certificate, and the end-to-cloud communication key to the TA.

[0367] S1416,TA stores the anti-fraud authentication root public key, the device anti-fraud certificate, and the end-to-cloud communication key.

[0368] The endpoint-cloud communication key is used for communication between the terminal device and the server during call services; the device anti-fraud certificate is used for communication between the terminal device and other terminal devices during call services. This provides a trusted cryptographic foundation for communication between the terminal device and the server, and between the terminal device and other terminal devices.

[0369] Furthermore, the device certificate is configured in the terminal device's TEE at the factory, and it cannot be forged or tampered with, ensuring the authenticity and integrity of the device certificate. Based on the device certificate, the system can effectively exclude virtual devices, thus providing a security guarantee for subsequent call services. Virtual devices cannot perform the above registration process, which can also be understood as virtual devices being unable to initiate anti-fraud authentication.

[0370] For example, when the terminal device shown in FIG14 is the second terminal device in the above embodiment, the device anti-fraud certificate generated in FIG14 is the second anti-fraud certificate in the above embodiment, and the signature corresponding to the device anti-fraud public key is the second signature in the above embodiment.

[0371] Figure 15 is a schematic diagram of the structure of a communication system 15 provided in an embodiment of this application. Methods 1000, 1100, 1200, 1300, and 1400 described above can be applied to this communication system 15. As shown in Figure 15, the communication system 15 includes at least a first terminal device and a second terminal device. Both the first and second terminal devices include a communication application, a service, a TA (Technical Information Acquisition) component, and a multimedia data acquisition component. The communication application includes telecommunications applications or internet audio-visual applications; for example, a telephone application, or an internet audio-visual application like a mobile internet connection. The service includes an anti-fraud authentication service. For ease of distinction, the first terminal device includes a first communication application, a first anti-fraud authentication service, and a first TA. The second terminal device includes a second communication application, a second anti-fraud authentication service, and a second TA.

[0372] As shown in Figure 15, during a call between the first and second terminal devices, the second terminal device can collect trusted data (i.e., first data) through its own multimedia data collection system. It then signs and encrypts the first data via a second TA (Technical Authentication Service), and sends the signed and encrypted first data to a second anti-fraud authentication service for transmission. The first terminal device can send the signed and encrypted first data to a first TA via a first anti-fraud authentication service. The first TA decrypts the first data to obtain the first data and its corresponding first signature. Subsequently, the first TA verifies the first signature. If verification is successful, trusted biometric data (i.e., first biometric data) is obtained based on the first data and matched with communication biometric data (i.e., second biometric data) obtained through a first communication application to obtain a matching result. Finally, based on the matching result, a prompt message is output to alert the user to the call security status, enhancing the user's awareness of call fraud prevention and improving the user's call experience.

[0373] For example, communication biometric data can also be obtained through the system output unit (such as screen, speaker, etc.) of the first terminal device.

[0374] In one possible implementation, the notification message may be presented in the form of text and / or icons. The notification message may be displayed on the interface of the first communication application; or, the notification message may be displayed on the system interface through the first anti-fraud authentication service; or, the notification message may also be displayed on the TUI interface through the first TA.

[0375] Figure 16 is a schematic diagram of the control flow of a communication system 16 provided in an embodiment of this application. This communication system 16 is a refinement of the communication system 15. As shown in Figure 16, the communication system 16 includes a first terminal device and a second terminal device. The control flow is illustrated using a call service between two internet audio / video applications on the first terminal device, where the internet audio / video application is "Changlian". The first anti-fraud authentication service of the first terminal device includes a first video call fraud detection service, and the second anti-fraud authentication service of the second terminal device includes a second face frame service, a second video call fraud detection service, and a camera service. The TEE environment of the second terminal device is configured with not only a second TA but also a first face recognition TA. The multimedia data acquisition components of the second terminal device include a time-of-flight (TOF) camera, an RGB camera, and an ISP.

[0376] As shown in Figure 16, during the video call service conducted through the seamless connection of the first terminal device and the seamless connection of the second terminal device, the control flow of the communication system 16 includes the following steps:

[0377] 1. The first video call fraud detection service can periodically (e.g., every 30 seconds) send an acquisition request to the first terminal device's Changlian service. This acquisition request is used to obtain trusted biometric data (i.e., the first biometric data). The first terminal device's Changlian service can then send this acquisition request to the second terminal device's Changlian service.

[0378] 2. The second terminal device's seamless connection can forward the acquisition request to the second video call fraud detection service.

[0379] 3. The second video call fraud detection service responds to the request by invoking the second face frame service.

[0380] 4. The second face frame service controls the TOF camera to acquire TOF images. These TOF images include depth images and infrared (IR) images. Subsequently, the second face frame service can invoke the second face recognition TA to perform liveness detection based on the TOF images to determine whether the object corresponding to the TOF image is a live object, and store the liveness detection results.

[0381] 5. The second video call fraud detection service can send an acquisition command to a trusted application (TA), which is used to acquire trusted biometric data.

[0382] 6. The second TA, in response to the acquisition command, can acquire a liveness detection result from the second face recognition TA. If the liveness detection result indicates that the object corresponding to the TOF image is a live object, a face image can be acquired from the second face recognition TA. This face image can be determined by the second face recognition TA from the TOF image. The second TA can use this face image as trusted biometric data, sign and encrypt the trusted biometric data, and transmit the signed and encrypted trusted biometric data to the second video call fraud detection service, so that the signed and encrypted trusted biometric data can be transmitted to the first TA of the first terminal device through the second video call fraud detection service.

[0383] The following explanation, with reference to Figure 17, illustrates the process of transmitting reliable biometric data.

[0384] Figure 17 is a schematic diagram of the data flow of a communication system 16 provided in an embodiment of this application. As shown in Figure 17, the TOF image captured by the TOF camera is stored in the ISP. The second face recognition TA can retrieve the TOF image from the ISP and perform liveness detection based on the TOF image to determine whether the object corresponding to the TOF image is a live object, and store the liveness detection result. If the liveness detection result indicates that the object corresponding to the TOF image is a live object, the second face recognition TA provides a face image to the second TA. The second TA uses the face image as trusted biometric data, signs and encrypts the trusted biometric data, and provides the signed and encrypted trusted biometric data to the second video call fraud detection service. The second video call fraud detection service can transmit the signed and encrypted trusted biometric data to the first TA in sequence through the connection of the second terminal device, the connection of the first terminal device, and the first video call fraud detection service. The first TA can decrypt and verify the signature. If the signature verification is successful (i.e., the first signature verification is successful), the trusted biometric data and the communication biometric data are matched to obtain the matching result, and a prompt message is output based on the matching result. The communication biometric data can be determined from image data in multimedia data sent by the second terminal device and presented to the user using the first terminal device. As shown in Figure 17, this image data can be captured by the RGB camera of the second terminal device and stored in the ISP, and then transmitted to the first TA through the Camera service of the second terminal device, the MeeTime service of the second terminal device, the MeeTime service of the first terminal device, and the first video call fraud detection service.

[0385] Based on the foregoing embodiments, this application provides a communication method 1800, which is applied to the aforementioned communication system 15 or communication system 16. Figure 18 is a flowchart illustrating a communication method 1800 provided in this application. Both the first terminal device and the second terminal device are equipped with a communication application, such as an internet audio / video application. This communication method 1800 can be applied to scenarios where the internet audio / video application on the first terminal device and the internet audio / video application on the second terminal device conduct call services, such as voice calls or video calls. This communication method 1800 is not limited to the specific order shown in Figure 18. It should be understood that in other embodiments, the order of some steps in this communication method 1800 can be interchanged according to actual needs, or some steps can be omitted or deleted. The following provides a detailed explanation of each step.

[0386] S1801. During a video call between the first terminal device and the second terminal device, the first communication application sends a start request to the first anti-fraud authentication service to initiate an anti-fraud authentication session.

[0387] S1802, The first anti-fraud authentication service transmits a notification message to the first communication application, which is used to notify that the start request has been received.

[0388] S1803. In response to the startup request, the first anti-fraud authentication service sends a request to the first TA to generate a random number for obtaining the session.

[0389] S1804. The first TA responds to the request, generates a session random number, and sends the session random number to the first anti-fraud authentication service.

[0390] S1805, The first anti-fraud authentication service sends a request to the second communication application through the first communication application to obtain trusted biometric data, and the request carries a session random number.

[0391] S1806, The second communication application receives the acquisition request.

[0392] S1807. The second communication application transmits an acquisition request to the second TA via the second anti-fraud authentication service.

[0393] S1808, the second TA responds to the acquisition request by acquiring image data through the multimedia data acquisition component, and performs liveness detection and re-photographing detection based on the image data to extract reliable biometric data.

[0394] S1809, the second TA signs the trusted biometric data and the session random number to obtain the first signature.

[0395] S1810, the second TA sends trusted biometric data and the first signature to the second communication application.

[0396] S1811, The second communication application encrypts the trusted biometric data and the first signature to obtain ciphertext.

[0397] S1812, The second communication application sends encrypted text and the second anti-fraud certificate to the first communication application.

[0398] S1813, The first communication application receives the encrypted text and the second anti-fraud certificate.

[0399] S1814. The first communication application decrypts the ciphertext to obtain trusted biometric data and the first signature.

[0400] S1815, The first communication application sends a response message to the first anti-fraud authentication service in response to a request for obtaining trusted biometric data, the response message carrying trusted biometric data, a first signature, and a second anti-fraud certificate.

[0401] S1816, The first anti-fraud authentication service sends a request to the first communication application to obtain communication biometric data.

[0402] S1817. The first communication application sends a response message to the first anti-fraud authentication service in response to the acquisition request, the response message carrying communication biometric data.

[0403] S1818, The first anti-fraud authentication service sends communication biometric data, trusted biometric data, first signature and second anti-fraud certificate to the first TA.

[0404] S1819. The first TA uses the anti-fraud authentication root public key to verify the second anti-fraud certificate. If the verification is successful, the device anti-fraud public key is extracted from the second anti-fraud certificate and used to verify the first signature.

[0405] S1820. If the verification is successful, the first TA will match the communication biometric data and the trusted biometric data to obtain the matching result.

[0406] S1821. Output prompt information based on the matching results.

[0407] In one possible implementation, the notification message can be displayed through the application interface of the first communication application. Alternatively, the notification message can be displayed through the first anti-fraud authentication service (i.e., displayed on the system interface). Or, the notification message can be displayed through the first TA (i.e., displayed through the TUI interface).

[0408] It should be noted that the descriptions of the same steps and contents in the embodiments of this application as in other embodiments can be referred to the descriptions in other embodiments, and will not be repeated here.

[0409] This application provides a communication method that, during a call between a first terminal device and a second terminal device, outputs a notification message indicating the call security status. This allows the user to prevent call fraud based on the notification message, ensuring the reliability and security of the call service and improving the user's call experience.

[0410] Based on the foregoing embodiments, this application provides a communication method 1900, which is applied to the aforementioned communication system 15 or communication system 16. Figure 19 is a flowchart illustrating a communication method 1900 provided in this application. Both the first terminal device and the second terminal device are equipped with a communication application, such as a telecommunications application. This communication method 1900 can be applied to scenarios where a telecommunications application on the first terminal device and a telecommunications application on the second terminal device conduct a call, such as a voice call or a video call. This communication method 1900 is not limited to the specific order shown in Figure 19. It should be understood that in other embodiments, the order of some steps in this communication method 1900 can be interchanged according to actual needs, or some steps can be omitted or deleted. The following provides a detailed explanation of each step.

[0411] S1901, During the video call between the first terminal device and the second terminal device, a request is sent to the first TA to generate and obtain a random number for the session.

[0412] S1902. The first TA responds to the request, generates a session random number, and sends the session random number to the first anti-fraud authentication service.

[0413] S1903, The first anti-fraud authentication service sends a request to the server to obtain trusted biometric data, and the request carries a session random number.

[0414] S1904. The server forwards the request to the second anti-fraud authentication service.

[0415] S1905, The second anti-fraud authentication service receives the request.

[0416] S1906, The second anti-fraud authentication service sends an acquisition request to the second TA.

[0417] S1907, the second TA responds to the acquisition request by acquiring image data through the multimedia data acquisition component, and performs liveness detection and re-photographing detection based on the image data to extract reliable biometric data.

[0418] S1908, the second TA signs the trusted biometric data and the session random number to obtain the first signature, and encrypts the first signature and the trusted biometric data to obtain the ciphertext.

[0419] S1909, the second TA transmits encrypted messages to the second anti-fraud authentication service.

[0420] S1910, Second Anti-Fraud Authentication Service receives encrypted messages.

[0421] S1911, The second anti-fraud authentication service sends encrypted text and the second anti-fraud certificate to the server.

[0422] S1912, The server forwards the encrypted text and the second anti-fraud certificate to the first anti-fraud authentication service.

[0423] S1913, The first anti-fraud authentication service receives encrypted text and the second anti-fraud certificate.

[0424] S1914. The first anti-fraud authentication service decrypts the ciphertext to obtain trusted biometric data and the first signature.

[0425] S1915, The first anti-fraud authentication service sends a request to the first communication application to obtain communication biometric data.

[0426] S1916. The first communication application sends a response message to the first anti-fraud authentication service in response to the acquisition request, the response message carrying communication biometric data.

[0427] S1917, The first anti-fraud authentication service sends communication biometric data, trusted biometric data, first signature and second anti-fraud certificate to the first TA.

[0428] S1918. The first TA uses the anti-fraud authentication root public key to verify the second anti-fraud certificate. If the verification is successful, the device anti-fraud public key is extracted from the second anti-fraud certificate and used to verify the first signature.

[0429] S1919. If the verification is successful, the first TA will match the communication biometric data and the trusted biometric data to obtain the matching result.

[0430] S1920. Output prompt information based on the matching results.

[0431] In one possible implementation, the notification message can be displayed through the application interface of the first communication application. Alternatively, the notification message can be displayed through the first anti-fraud authentication service (i.e., displayed on the system interface). Or, the notification message can be displayed through the first TA (i.e., displayed through the TUI interface).

[0432] It should be noted that Communication Method 1900 can be applied not only to call scenarios between internet audio and video applications, but also to call scenarios between telecommunications applications. For call scenarios between telecommunications applications, if these applications cannot directly establish a communication connection, anti-fraud authentication can be achieved through server relay.

[0433] It should be noted that the descriptions of the same steps and contents in the embodiments of this application as in other embodiments can be referred to the descriptions in other embodiments, and will not be repeated here.

[0434] This application provides a communication method that, during a call between a first terminal device and a second terminal device, outputs a notification message indicating the call security status. This allows the user to prevent call fraud based on the notification message, ensuring the reliability and security of the call service and improving the user's call experience.

[0435] Figure 20 is a flowchart illustrating a communication method 2000 provided in an embodiment of this application. Before step S1901 of the communication method 1900 provided in the aforementioned embodiment, communication method 2000 can also be executed. This communication method 2000 is used to establish a communication link between a first anti-fraud authentication service on a first terminal device and a second anti-fraud authentication service on a second terminal device. This communication link includes a server, which is used to forward data between the first anti-fraud authentication service and the second anti-fraud authentication service. The steps are explained in detail below.

[0436] S2001. During a video call between the first terminal device and the second terminal device, the second communication application sends a start request to the second anti-fraud authentication service to initiate an anti-fraud authentication session.

[0437] Accordingly, the second anti-fraud authentication service receives the activation request.

[0438] S2002, the second anti-fraud authentication service sends a notification message to the second communication application, which is used to notify that the startup request has been received.

[0439] S2003, the second anti-fraud authentication service sends a connection request 1 to the server to establish a call anti-fraud session. The connection request 1 carries the identifier of the second communication application (e.g., "telephone"), the user identifier of the source communication application (i.e., the user identifier of the second communication application), and the user identifier of the target communication application (i.e., the user identifier of the first communication application).

[0440] S2004. The server sends a notification message to the second anti-fraud authentication service, which is used to notify that the connection request 1 has been received.

[0441] S2005. During a video call between the first terminal device and the second terminal device, the first communication application sends a start request to the first anti-fraud authentication service to initiate an anti-fraud authentication session.

[0442] S2006. The first anti-fraud authentication service sends a notification message to the first communication application, which is used to notify that the startup request has been received.

[0443] S2007. The first anti-fraud authentication service sends a connection request 2 to the server to establish a call anti-fraud session. The connection request 2 carries the identifier of the first communication application (e.g., "telephone"), the user identifier of the source communication application (i.e., the user identifier of the first communication application), and the user identifier of the target communication application (i.e., the user identifier of the second communication application).

[0444] S2008. The server sends a notification message to the first anti-fraud authentication service, which is used to notify that the connection request 2 has been received.

[0445] It should be noted that S2001 to S2004 and S2005 to S2008 are executed asynchronously.

[0446] S2009. Based on connection request 1 and connection request 2, the server establishes a communication link between the first anti-fraud authentication service and the second anti-fraud authentication service.

[0447] For example, if the server determines, based on connection request 1 and connection request 2, that the identifier of the first communication application matches the identifier of the second communication application, the user identifier of the second communication application matches, and the user identifier of the first communication application matches, then the server establishes a communication link between the first anti-fraud authentication service and the second anti-fraud authentication service.

[0448] In one possible implementation, the following steps may be performed after S2009: the server sends a target notification message to the first anti-fraud authentication service, which is used to notify that a communication link has been established between the first anti-fraud authentication service and the second anti-fraud authentication service.

[0449] In the communication method presented in this paper, the first and second anti-fraud authentication services are integrated into a unified PKI system, enabling secure communication between them. The secure zone (i.e., TEE environment) of the second terminal device can directly collect trusted biometric data and securely transmit it to the first terminal device. The first terminal device can compare the trusted biometric data with the communication biometric data. If the trusted biometric data matches the communication biometric data, the object corresponding to the communication biometric data is not a fake user synthesized using deepfake technology. Thus, it is possible to identify whether the object corresponding to the communication biometric data is a fake user, outputting a prompt message to alert the user to the call security status, enhancing the user's awareness of fraud prevention, and thereby improving the user's call experience.

[0450] The communication method provided by the embodiments of this application has been described in detail above. In the various embodiments of this application, unless otherwise specified or logically conflicting, the terms and / or descriptions between the various embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.

[0451] It is understood that, in order to achieve the above-mentioned functions, electronic devices include hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should readily recognize that, based on the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application. This application can divide the execution of communication methods into functional units based on the above method examples; for example, each function can be divided into separate functional units, or two or more functions can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. It should be noted that the unit division in this application is illustrative and only represents one logical functional division; other division methods may exist in actual implementation.

[0452] The electronic device provided in the embodiments of this application will now be described in detail with reference to FIG21. It should be understood that the description of the device embodiments corresponds to the description of the method embodiments. Therefore, for the sake of brevity, the contents not described in detail can be referred to the method embodiments above.

[0453] Figure 21 shows a schematic diagram of the structure of an electronic device provided in this application. The dashed lines in Figure 21 indicate that the unit or module is optional. The electronic device 21 can be used to implement the methods described in the above method embodiments. The electronic device 21 can be a first terminal device, a second terminal device, or a server, or it can be a chip (system).

[0454] The electronic device 21 includes one or more processors 2101, which can support the electronic device 21 in implementing the methods described in the above-described method embodiments. The processor 2101 can be a general-purpose processor or a dedicated processor. For example, the processor 2101 can be a central processing unit (CPU). The CPU can be used to control the electronic device 21, execute software programs, and process data from the software programs. The electronic device 21 may also include a communication unit 2105 for implementing signal input (reception) and output (transmission).

[0455] The aforementioned electronic device 21 may be a chip (system) including a memory and a processor, wherein the processor is configured to execute a computer program stored in the memory to implement the methods shown in the various embodiments above.

[0456] The communication unit 2105 may be an input and / or output circuit of the chip (system), or the communication unit 2105 may be a communication interface of the chip (system), and the chip (system) may be a component of the electronic device 21.

[0457] For example, communication unit 2105 may be a transceiver of electronic device 21, or communication unit 2105 may be a transceiver circuit of electronic device 21. Electronic device 21 may include one or more memories 2102, which store program 2104. Program 2104 may be executed by processor 2101 to generate instructions 2103, causing processor 2101 to execute the method described in the above method embodiments according to instructions 2103. Optionally, memory 2102 may also store data. Optionally, processor 2101 may also read data stored in memory 2102, which may be stored at the same memory address as program 2104, or the data may be stored at a different memory address than program 2104.

[0458] The processor 2101 and memory 2102 can be configured separately or integrated together, for example, integrated on a system-on-chip (SOC) of an electronic device. For details on how the processor 2101 performs the bag detection method, please refer to the relevant description in the method embodiments.

[0459] It should be understood that the steps of the above method embodiments can be implemented by hardware logic circuits or software instructions in the processor 2101. The processor 2101 may be a CPU, a digital signal processor (DSP), a field programmable gate array (FPGA), or other programmable logic devices, such as discrete gate, transistor logic devices, or discrete hardware components.

[0460] This application also provides a computer program product that, when executed by processor 2101, implements the method of any of the method embodiments in this application. The computer program product can be stored in memory 2102, for example, as program 2104. Program 2104 undergoes preprocessing, compilation, assembly, and linking processes to ultimately be converted into an executable object file that can be executed by processor 2101.

[0461] This application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a computer, implements the method of any of the method embodiments of this application. The computer program may be a high-level language program or an executable object program.

[0462] The computer-readable storage medium is, for example, memory 2102. Memory 2102 can be volatile memory or non-volatile memory, or memory 2102 can include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static RAM (SRAM), Dynamic RAM (DRAM), Synchronous DRAM (SDRAM), Double Data Rate SDRAM (DDR SDRAM), Enhanced Synchronous DRAM (ESDRAM), SynchLink DRAM (SLDRAM), and Direct Rambus RAM (DRRAM).

[0463] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process and technical effects of the above-described apparatus and equipment can be referred to the corresponding processes and technical effects in the foregoing method embodiments, and will not be repeated here.

[0464] The systems, apparatuses, and methods disclosed in the embodiments provided in this application can be implemented in other ways. For example, some features of the method embodiments described above may be omitted or not performed. The apparatus embodiments described above are merely illustrative; the division of units is only a logical functional division, and in actual implementation, there may be other division methods. Multiple units or components may be combined or integrated into another system. Furthermore, the coupling between units or components can be direct or indirect, including electrical, mechanical, or other forms of connection.

[0465] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.

[0466] Finally, the above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A communication method, characterized in that, Applied to a first terminal device, the method includes: During a call between the first terminal device and the second terminal device, the first biometric data of the call subject is acquired, wherein the call subject is the person using the second terminal device to make the call; The first biometric data and the second biometric data are matched to obtain a matching result. The second biometric data is determined based on the first multimedia data, which is the multimedia data sent by the second terminal device during the call service and presented to the user using the first terminal device. Based on the matching results, a prompt message is output, which is used to indicate the security status of the call.

2. The method according to claim 1, characterized in that, The acquisition of the first biometric data of the call subject includes: Receive first data and a first signature corresponding to the first data from the second terminal device, wherein the first data is used to determine the first biometric data; The first signature is verified, and if the verification is successful, the first biometric data is determined based on the first data.

3. The method according to claim 2, characterized in that, The first data is the first biometric data.

4. The method according to claim 2, characterized in that, The first data is the second multimedia data, and the step of determining the first biometric data based on the first data includes: If there is no reproduced image in the second multimedia data and the object corresponding to the second multimedia data is a living object, the biometric data obtained by extracting biometric features from the second multimedia data will be determined as the first biometric data. The second multimedia data is collected by the multimedia data acquisition component of the second terminal device during the call service between the first terminal device and the second terminal device.

5. The method according to any one of claims 2 to 4, characterized in that, The first terminal device includes a first trusted application (TA), which is configured in the trusted execution environment (TEE) of the first terminal device. The verification of the first signature includes: The first signature is verified using the device's anti-fraud public key via the first TA.

6. The method according to claim 5, characterized in that, The device's anti-fraud public key is obtained through the following methods: Receive a device certificate and a first anti-fraud certificate from the second terminal device. The first anti-fraud certificate is generated based on the device private key. The device certificate is used to prove the identity of the second terminal device. If the device certificate is deemed valid based on the device root public key, the device public key corresponding to the device private key is extracted from the device certificate. If the first anti-fraud certificate is deemed legitimate based on the device's public key, the device's anti-fraud public key is extracted from the first anti-fraud certificate.

7. The method according to claim 5, characterized in that, The device's anti-fraud public key is obtained through the following methods: Receive the second anti-fraud certificate from the second terminal device; If the second anti-fraud certificate is deemed legitimate based on the anti-fraud authentication root public key, the device anti-fraud public key is extracted from the second anti-fraud certificate.

8. The method according to any one of claims 2 to 7, characterized in that, Before receiving the first data from the second terminal device and the first signature corresponding to the first data, the method further includes: Send a request to the second terminal device to obtain the first data.

9. The method according to claim 8, characterized in that, The request contains a session random number.

10. The method according to any one of claims 2 to 9, characterized in that, The receiving of first data and the first signature corresponding to the first data from the second terminal device includes: Receive encrypted text from the second terminal device; The ciphertext is decrypted to obtain the first data and the first signature.

11. The method according to any one of claims 2 to 10, characterized in that, The first biometric data includes a face image or facial feature data extracted from the face image.

12. A communication method, characterized in that, Applied to a second terminal device, the method includes: During a call between a first terminal device and a second terminal device, first data is collected. The first data is used to determine the first biometric data of the call subject, and the call subject is the person using the second terminal device to make the call. Sign the second data containing the first data to obtain the first signature; Send the first data and the first signature to the first terminal device.

13. The method according to claim 12, characterized in that, The first data is the second multimedia data, which is collected by the multimedia data acquisition component of the second terminal device during a call between the first terminal device and the second terminal device.

14. The method according to claim 12, characterized in that, The second terminal device includes a second trusted application (TA), which is configured in the trusted execution environment (TEE) of the second terminal device. The first data is the first biometric data. The collection of the first data includes: During a call between the first terminal device and the second terminal device, second multimedia data is collected by the multimedia data acquisition component of the second terminal device. The first biometric data is determined based on the second multimedia data using the second TA.

15. The method according to claim 14, characterized in that, The step of determining the first biometric data based on the second multimedia data includes: If there are no reproduced images in the second multimedia data and the object corresponding to the second multimedia data is a living object, the biometric data obtained by extracting biometric features from the second multimedia data will be determined as the first biometric data.

16. The method according to any one of claims 12 to 15, characterized in that, The second terminal device includes a second TA, which is disposed in the TEE of the second terminal device. The step of signing the second data containing the first data to obtain a first signature includes: The first signature is obtained by signing the second data using the second TA and the device's anti-fraud private key.

17. The method according to claim 16, characterized in that, The TEE contains a device certificate for the second terminal device, which is used to verify the identity of the second terminal device. The method further includes: Send the device certificate and the first anti-fraud certificate to the first terminal device. The first anti-fraud certificate is generated based on the device private key and carries a device anti-fraud public key corresponding to the device anti-fraud private key. The device certificate carries a device public key corresponding to the device private key; or, Send a second anti-fraud certificate to the first terminal device. The second anti-fraud certificate is generated based on the anti-fraud authentication root private key and carries the device's anti-fraud public key.

18. The method according to claim 17, characterized in that, The second anti-fraud certificate was obtained through the following methods: A second signature is obtained by signing the device's anti-fraud public key based on the device's private key; A processing request for generating the second anti-fraud certificate is sent to the server, the processing request carrying the device's anti-fraud public key, the second signature, and the device certificate; Receive a second anti-fraud certificate from the server, the second anti-fraud certificate being generated based on the device's anti-fraud public key, the second signature, and the device certificate.

19. The method according to any one of claims 12 to 18, characterized in that, Before collecting the first data during a call between the first terminal device and the second terminal device, the method further includes: A request is received, the request being used to obtain the first data.

20. The method according to claim 19, characterized in that, The acquisition request carries a session random number, and the second data also includes the session random number.

21. The method according to any one of claims 12 to 20, characterized in that, Sending the first data and the first signature to the first terminal device includes: Send encrypted text to the first terminal device, the encrypted text carrying the first data and the first signature.

22. The method according to any one of claims 12 to 21, characterized in that, The first biometric data includes a face image or facial feature data extracted from the face image.

23. A communication method, characterized in that, Applied to a server, the method includes: During a call between a first terminal device and a second terminal device, first data and a first signature corresponding to the first data are received from the second terminal device. The first data is used to determine the first biometric data of the call subject, and the call subject is the person using the second terminal device to make a call. The first data and the first signature are forwarded to the first terminal device.

24. The method according to claim 23, characterized in that, Before receiving the first data and the first signature from the second terminal device during a call between the first terminal device and the second terminal device, the method further includes: Receive an acquisition request from the first terminal device, the acquisition request being used to acquire the first data; The acquisition request is forwarded to the second terminal device.

25. The method according to claim 24, characterized in that, The request contains a session random number.

26. The method according to any one of claims 23 to 25, characterized in that, The method further includes: The system receives a processing request from the second terminal device to generate a second anti-fraud certificate. The processing request carries the device's anti-fraud public key, a second signature, and a device certificate, which is used to prove the identity of the second terminal device. If the second signature is verified successfully based on the device certificate, the second anti-fraud certificate is generated using the anti-fraud authentication root private key, and the second anti-fraud certificate carries the device anti-fraud public key. Send the second anti-fraud certificate to the second terminal device.

27. A communication system, characterized in that, The communication system includes a first terminal device and a second terminal device, and a communication connection is established between the first terminal device and the second terminal device, wherein: The second terminal device is configured to collect first data during a call between the first terminal device and the second terminal device, wherein the first data is used to determine the first biometric data of the call subject, and the call subject is the person using the second terminal device to make the call; sign the second data containing the first data to obtain a first signature; and send the first data and the first signature to the first terminal device. The first terminal device is configured to receive the first data and the first signature from the second terminal device, verify the first signature, and, if the verification is successful, determine the first biometric data based on the first data, match the first biometric data and the second biometric data to obtain a matching result, wherein the second biometric data is determined based on first multimedia data, which is multimedia data sent by the second terminal device during the call service and presented to the user using the first terminal device; and, based on the matching result, output a prompt message, which is used to indicate the call security status.

28. The communication system according to claim 27, characterized in that, The second terminal device includes a second trusted application (TA), which is configured in the trusted execution environment (TEE) of the second terminal device, wherein: The second terminal device is specifically used to sign the second data using the device's anti-fraud private key via the second TA to obtain the first signature.

29. The communication system according to claim 28, characterized in that, The first terminal device includes a first TA, which is configured in the TEE of the first terminal device, wherein: The first terminal device is specifically used to verify the first signature using the first TA and the device anti-fraud public key corresponding to the device anti-fraud private key.

30. A communication system, characterized in that, The communication system includes a first terminal device, a second terminal device, and a server. The server establishes communication connections with both the first terminal device and the second terminal device, respectively. The second terminal device is configured to collect first data during a call between the first terminal device and the second terminal device, wherein the first data is used to determine the first biometric data of the call subject, and the call subject is the person using the second terminal device to make the call; sign the second data containing the first data to obtain a first signature; and send the first data and the first signature to the server. The server is configured to receive the first data and the first signature from the second terminal device; and forward the first data and the first signature to the first terminal device. The first terminal device is configured to receive the first data and the first signature from the server, verify the first signature, and, if the verification is successful, determine the first biometric data based on the first data, match the first biometric data and the second biometric data to obtain a matching result, wherein the second biometric data is determined based on first multimedia data, which is multimedia data sent by the second terminal device during the call service and presented to the user using the first terminal device; and, based on the matching result, output a prompt message, which is used to indicate the call security status.

31. The communication system according to claim 30, characterized in that, The second terminal device includes a second trusted application (TA), which is configured in the trusted execution environment (TEE) of the second terminal device, wherein: The second terminal device is specifically used to sign the second data using the device's anti-fraud private key via the second TA to obtain the first signature.

32. The communication system according to claim 31, characterized in that, The first terminal device includes a first TA, which is configured in the TEE of the first terminal device, wherein: The first terminal device is specifically used to verify the first signature using the first TA and the device anti-fraud public key corresponding to the device anti-fraud private key.

33. An electronic device, characterized in that, include: A memory, one or more processors, and one or more programs; wherein the one or more programs are stored in the memory; When the one or more processors execute the one or more programs, they cause the electronic device to perform the method described in any one of claims 1 to 11, 11 to 22, or 23 to 26.

34. A chip system, characterized in that, The chip system includes a memory and a processor, the processor being configured to execute a computer program stored in the memory to implement the method as described in any one of claims 1 to 11, 11 to 22, or 23 to 26.

35. A computer-readable storage medium having a computer program or instructions stored thereon, characterized in that, When the computer program or instructions are executed, they cause the computer to perform the method as described in any one of claims 1 to 11, 11 to 22, or 23 to 26.

36. A computer program product, characterized in that, Includes computer program instructions that cause the computer to perform the method as described in any one of claims 1 to 11, 11 to 22, or 23 to 26.