WO2025260656A1 - 一种通信方法及装置 - Google Patents

一种通信方法及装置

Info

Publication number
WO2025260656A1
WO2025260656A1 PCT/CN2024/140071 CN2024140071W WO2025260656A1 WO 2025260656 A1 WO2025260656 A1 WO 2025260656A1 CN 2024140071 W CN2024140071 W CN 2024140071W WO 2025260656 A1 WO2025260656 A1 WO 2025260656A1
Authority
WO
WIPO (PCT)
Prior art keywords
terminal
user
contact
relationship chain
chain identifier
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
PCT/CN2024/140071
Other languages
English (en)
French (fr)
Inventor
王春风
曹文砚
曾秋阳
高伟
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Huawei Technologies Co Ltd
Original Assignee
Huawei Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority claimed from CN202411507240.0A external-priority patent/CN121193707A/zh
Application filed by Huawei Technologies Co Ltd filed Critical Huawei Technologies Co Ltd
Publication of WO2025260656A1 publication Critical patent/WO2025260656A1/zh
Pending legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/45Network directories; Name-to-address mapping
    • H04L61/4594Address books, i.e. directories containing contact information about correspondents

Definitions

  • This application relates to the field of communication technology, and in particular to a communication method and apparatus.
  • the terminal can obtain the user's identity information to access the contacts associated with that identity information, and then communicate with those contacts' terminals.
  • This application provides a communication method and apparatus that can reduce the risk of personal information leakage.
  • a communication method which can be applied to a first terminal, wherein the first terminal is logged into the account of a first user, the first terminal stores a relationship chain identifier of the first user and a relationship chain identifier of a second user, the second user being a contact of the first user, and the relationship chain identifier is generated based on the account of the user logged into the terminal's system; the method may include: receiving a first operation to initiate a communication connection to the second user; in response to the first operation, obtaining a communication identifier of the second user's second terminal based on the second user's relationship chain identifier; and sending a communication connection request to the second user's second terminal based on the communication identifier.
  • the first terminal when the first terminal communicates with the second terminal, it can query the communication identifier of the second user's second terminal based on the contact relationship chain identifier, without having to search for the user in the second terminal through private information such as mobile phone number or email address, thereby reducing the risk of leakage of user privacy information.
  • the first terminal may store the association between the second user's relationship chain identifier and the second user's communication identifier on the second terminal.
  • the first terminal may also query the server for the second user's communication identifier and directly use that identifier to initiate a communication connection with the second terminal.
  • the first terminal may also establish a communication connection with the second terminal through the server. For instance, as one possible implementation, the first terminal sends the second user's relationship chain identifier to the server, and the server determines the second user's communication identifier accordingly. Then, the server establishes a communication connection between the first terminal and the second terminal based on the second user's communication identifier. This method can be implemented independently of the first aspect.
  • the method further includes a process whereby the first terminal obtains the relationship chain identifier of a contact from the server; this process may be referred to as downloading the relationship chain identifier.
  • the first terminal downloading the relationship chain identifier can be implemented by: sending the contact information of at least one contact of the first user to the server; and receiving the relationship chain identifier of at least one contact of the first user sent by the server.
  • the at least one contact includes a second user.
  • the terminal may store the relationship chain identifier of the second user.
  • the server may return the relationship chain identifiers of all or some of the contacts. For example, if some contacts do not have Huawei accounts, the server will not return the relationship chain identifiers of those contacts.
  • the method also includes a registration process between the first terminal and the server. As one possible implementation, this registration process may include: the first terminal sending the first user's contact information and the first user's relationship chain identifier to the server.
  • each terminal can upload its own user's contact information and their respective user's relationship chain identifier, so that the terminal can download the corresponding contact's relationship chain identifier from the server.
  • the terminal's use of the contact's relationship chain identifier can reduce security risks.
  • the above example uses the terminal generating the relationship chain identifier of the terminal user, and the terminal reporting the contact information and relationship chain identifier of the terminal user.
  • the terminal may report the account of the terminal user (such as a Huawei account), and the server may generate the relationship chain identifier of the terminal user and return the relationship chain identifier of the terminal user to the terminal.
  • applications on the terminal can share system-level relationship chain identifiers, resulting in low maintenance costs.
  • Applications using relationship chain identifiers such as the Connect app and the Near Field Sharing app, can quickly determine whether a contact is a local friend by querying the system-level contact database when they need to identify the contact's identity.
  • the method may further include: receiving a communication identifier of the at least one contact sent by the server.
  • the first terminal may store the association between the relationship chain identifier and the communication identifier of the at least one contact.
  • the method further includes: receiving a second operation to modify the contact information of the first user; and in response to the second operation, sending the modified contact information of the first user to a server.
  • the server can know that the contact information of the first user on the terminal has been modified.
  • the server can then modify the association between the first user's contact information and the first user's relationship chain identifier so that the first user's contact terminal can download the modified first user's relationship chain identifier.
  • the method further includes: receiving a third operation to add a third user as a contact; in response to the third operation, sending the contact information of the third user to a server; and receiving and storing the relationship chain identifier of the third user sent by the server.
  • the first terminal After the first terminal adds a third user as a contact, it can obtain the third user's relationship chain identifier from the server, so that it can subsequently query the third user's communication identifier based on the relationship chain identifier, thereby improving information security.
  • the method further includes: receiving and storing the communication identifier of the third user sent by the server.
  • the method further includes: receiving a fourth operation to delete a fourth user as a contact; and in response to the fourth operation, deleting the stored relationship chain identifier of the fourth user.
  • the method further includes: deleting the communication identifier of the fourth user in response to the fourth operation.
  • the method further includes: in response to the fourth operation, sending the contact information of the fourth user to the server.
  • the first terminal further stores the contact information of a fifth user and the relationship chain identifier of the fifth user, wherein the fifth user is a contact of the first user; the method further includes: receiving a fifth operation to update the contact information of the fifth user from a first contact information to a second contact information; in response to the fifth operation, updating the contact information corresponding to the relationship chain identifier of the fifth user from the first contact information to the second contact information.
  • the first terminal can quickly become aware of the update and promptly update the association between the fifth user's relationship chain identifier and contact information.
  • the method further includes: in response to the fifth operation, sending the first contact information and the second contact information of the fifth user to the server.
  • the first terminal further stores the contact information of at least one of the first user's contacts, and the contact information of each contact corresponds one-to-one with the relationship chain identifier of the contact; the method further includes: receiving a notification message sent by a server, the notification message being used to notify the first terminal to modify the association relationship between the stored contact information and the relationship chain identifier; wherein, modifying the association relationship between the stored contact information and the relationship chain identifier includes one or more of the following:
  • the first terminal can modify the association between the stored contact information and the relationship chain identifier based on the notification message from the server.
  • the server sends a notification message to both the first terminal and the fifth terminal to synchronize the association between the contact information and the relationship chain identifier stored in the first terminal and the fifth terminal.
  • the server will not send a notification message to the fifth terminal when the association between the first terminal's contact information and relationship chain identifier changes.
  • the communication connection request is used to initiate audio and video communication;
  • the first terminal also stores capability information of at least one of the first user's contacts, the capability information of the contacts corresponds one-to-one with the relationship chain identifier of the contacts, and the capability information is used to indicate whether the corresponding contact has audio and video communication capability;
  • the capability information of the second user is used to indicate that the second user has audio and video communication capability.
  • the first terminal can determine whether a contact has audio and video communication capabilities based on the contact's ability information.
  • the first terminal can use the contact's relationship chain identifier to initiate an audio and video communication connection to the contact's terminal, thereby reducing security risks during information transmission.
  • the method further includes sending the capability information of the first user to the server.
  • the server can determine the account-level capability information of each user. Subsequently, based on the corresponding user's capability information, the communication process can be controlled to improve communication security.
  • the method further includes receiving a notification message sent by a server, which notifies the first terminal to modify the stored association between the communication identifier and the relationship chain identifier. For example, after adding a new device A with login account A, the terminal can add an association between the relationship chain identifier and the communication identifier of device A.
  • the contact information includes one or more of the following: telephone number, fax number, or email address.
  • a communication method which can be applied to a server.
  • the method may include: receiving contact information of at least one contact of a first user from a first terminal; and sending a relationship chain identifier of at least one contact of the first user to the first terminal.
  • the method may further include sending the communication identifier of the at least one contact to the first terminal.
  • the at least one contact includes a second user; before sending the relationship chain identifier of at least one of the first user's contacts to the first terminal, the method further includes: receiving the contact information of the second user and the relationship chain identifier of the second user sent by the second terminal of the second user.
  • the method further includes: sending capability information of at least one contact of the first user to the first terminal, the capability information being used to indicate whether the corresponding contact has audio and video communication capabilities.
  • the method further includes: receiving modified contact information of the first user sent by the first terminal; the modification includes one or more of the following: adding contact information, deleting contact information, updating contact information; sending a first notification message to a third terminal, the first notification message being used to notify the third terminal to modify the association relationship between the first user's contact information and the first user's relationship chain identifier; the contact information of the third terminal's user's contacts includes the added contact information of the first user.
  • the method further includes: sending a notification message to a third terminal, the notification message being used to notify the third terminal to modify the association between the communication identifier of the first user and the relationship chain identifier of the first user.
  • the method further includes: receiving modified contact information of a third user from the first terminal; the modification includes one or more of the following: adding the third user as a contact, deleting the third user from the contacts, and updating the contact information of the third user;
  • a second notification message is sent to the fourth terminal.
  • the second notification message is used to notify the fourth terminal to modify the association between the stored contact information and the relationship chain identifier.
  • the account logged in by the fourth terminal is the same as the account logged in by the first terminal.
  • the server stores the contact information of at least one contact of the first user of the first terminal and the association relationship of the first user's relationship chain identifier;
  • the method further includes:
  • the stored association relationship is modified.
  • the method further includes: modifying the association between the stored communication identifier and the relationship chain identifier.
  • the communication method provided in this application can be applied to identity authentication scenarios.
  • the following describes the specific implementation process of terminal identity authentication based on relationship chain identifier through the method described in the third aspect.
  • a communication method is provided, applied to a first terminal, wherein the first terminal is logged into a first user's account, the first terminal stores a first user's relationship chain identifier and a device hash of the first terminal, the relationship chain identifier is generated based on the user's account logged into the terminal, and the device hash is generated based on the terminal's device identifier; the method includes: receiving an operation to trigger the first terminal to search for a device; receiving a first broadcast from a second terminal, the first broadcast including a second user's relationship chain identifier and/or the second terminal's device hash; and displaying a first interface when a first condition is met; the first condition includes determining that the second user is a contact of the first user based on the second user's relationship chain identifier, and/or determining that the second terminal is a device with which the first terminal has shared data based on the second terminal's device hash; the first interface includes a first object, the first object including information of the second
  • the first terminal when the first terminal communicates with the second terminal, it can perform identity authentication based on the relationship chain identifier and device hash, without needing to authenticate using private information such as phone numbers or email addresses. This reduces the risk of user privacy information leakage and increases communication security and efficiency. Furthermore, authentication based on the relationship chain identifier and device hash simplifies the authentication process and improves authentication efficiency.
  • the first user's relationship chain identifier is obtained by hashing the account the first user logged into on the first terminal.
  • the hash value of the first terminal is obtained by hashing the device identifier of the first terminal.
  • the relationship chain identifier is used to identify users, eliminating the need for private information such as phone numbers and email addresses, thus reducing the risk of user privacy leaks.
  • Device hashes are used to identify devices for quick device filtering.
  • the second terminal is the one that has enabled the data sharing function and is set to be visible to contacts and shared devices.
  • the relationship chain identifier of the second user is obtained by hashing the account logged into by the second user on the second terminal.
  • the hash value of the second terminal is obtained by hashing the device identifier of the second terminal.
  • the first terminal includes a contact database, which includes relationship chain identifiers corresponding to the contacts of the first user.
  • the method further includes: determining that the second user is a contact of the first user if the contact database includes at least a portion of the relationship chain identifier of the second user.
  • the first broadcast includes a relationship chain identifier for the second user.
  • the first terminal matches the second user's relationship chain identifier against the contact database, and if the contact database includes the second user's relationship chain identifier, determines that the second user is a contact of the first user.
  • the first broadcast includes a relationship chain identifier for the second user.
  • the first terminal truncates the second user's relationship chain identifier to obtain partial bytes. Based on these partial bytes, a match is made in the contact database. If the contact database includes these partial bytes, the second user is determined to be a contact of the first user.
  • the first broadcast includes partial bytes of the second user's relationship chain identifier. That is, the second terminal truncates the second user's relationship chain identifier, carrying only partial bytes of it in the first broadcast.
  • the first terminal matches it against its contact database based on the partial bytes of the second user's relationship chain identifier in the first broadcast. If the contact database includes the partial bytes of the second user's relationship chain identifier, the first terminal determines that the second user is a contact of the first user.
  • the first terminal includes a historical sharing database, which includes device hashes corresponding to devices that have shared data with the first terminal.
  • the method further includes determining that the second terminal is a device that has shared data with the first terminal, provided that the historical sharing database includes at least a portion of the device hash of the second terminal.
  • the first broadcast includes the device hash of the second terminal.
  • the first terminal matches the device hash of the second terminal in the historical sharing database, and if the historical sharing database includes the device hash of the second terminal, it determines that the second terminal is a device that has shared data with the first terminal.
  • the first broadcast includes the device hash of the second terminal.
  • the first terminal truncates the device hash of the second terminal, obtaining partial bytes of the device hash. These partial bytes are then matched against a historical sharing database. If the historical sharing database includes partial bytes of the second terminal's device hash, the second terminal is determined to be a device that has shared data with the first terminal.
  • the first broadcast includes a portion of the device hash of the second terminal. That is, the second terminal truncates its device hash, and when sending the first broadcast, it carries a portion of the device hash in the broadcast. Upon receiving the first broadcast, the first terminal matches the portion of the second terminal's device hash in the historical sharing database. If the historical sharing database includes a portion of the second terminal's device hash, the first terminal determines that it is a device that has shared data with the first terminal.
  • the first terminal can quickly filter based on the contact database and historical sharing database to quickly determine whether the first condition is met, thereby improving response speed and helping to improve authentication efficiency.
  • the second user's contacts as the first user include: the relationship chain identifier of the second user obtained by the first terminal is the same as the first authentication identifier determined by the first terminal, and the first authentication identifier is determined based on the account of the second user obtained by the first terminal.
  • a first interface is displayed, which includes a first object.
  • the first terminal responds to the user's first operation on the first object, the first terminal interacts with the second terminal to obtain the second user's account.
  • a first authentication identifier is obtained by performing a hash operation based on the second user's account. If the relationship chain identifier of the second user obtained by the first terminal matches the first authentication identifier determined by the first terminal, authentication is successful.
  • a connection is established with the second terminal corresponding to the second user to send data. That is, in this example, an initial screening is performed, and the results are displayed. Then, the object selected by the authenticated user is connected to the authenticated object.
  • the first terminal after the first terminal determines that the contact database includes the second user's relationship chain identifier, the first terminal interacts with the second terminal to obtain the second user's account. A hash operation is performed on the second user's account to obtain a first authentication identifier. If the relationship chain identifier of the second user obtained by the first terminal matches the first authentication identifier determined by the first terminal, authentication is confirmed successful, and a first interface is displayed.
  • the first interface includes a first object, which contains the information of the authenticated second user and/or the information of the second terminal. That is, in this example, an initial screening is performed first, then the initial screening results are authenticated, and the successful initial screening results are displayed.
  • the devices for which the second terminal has shared data with the first terminal include: the device hash of the second terminal obtained by the first terminal is the same as the second authentication identifier determined by the first terminal, and the second authentication identifier is determined based on the device identifier of the second terminal obtained by the first terminal.
  • a first interface is displayed, which includes a first object.
  • the first terminal interacts with the second terminal to obtain the device identifier of the second terminal.
  • a second authentication identifier is obtained by hashing the device identifier of the second terminal. If the device hash of the second terminal obtained by the first terminal matches the second authentication identifier determined by the first terminal, authentication is successful.
  • a connection is then established with the second terminal corresponding to the second user to send data.
  • the first terminal after the first terminal determines that the historical sharing database includes the device hash of the second terminal, the first terminal interacts with the second terminal to obtain the device identifier of the second terminal.
  • a second authentication identifier is obtained by hashing the device identifier of the second terminal. If the device hash of the second terminal obtained by the first terminal is the same as the second authentication identifier determined by the first terminal, authentication is successful, and a first interface is displayed.
  • the first interface includes a first object, which contains information about the authenticated second terminal and/or information about the second user.
  • the first authentication identifier and the second authentication identifier are complete data obtained after hash calculation, or the first authentication identifier and the second authentication identifier are partial bytes obtained after hash calculation and truncation.
  • This method by authenticating devices and accounts to ensure their legitimacy and preventing fraudulent activities, can improve security, enhance data protection, and prevent information leakage. Furthermore, when a terminal contacts other terminals, it can verify the legitimacy of the peer, potentially enhancing the security of the communication process, increasing user trust in the communication, and improving the user experience.
  • the method further includes: receiving a second broadcast from a third terminal, the second broadcast including a second user relationship chain identifier of the third terminal and a device hash of the third terminal; displaying a second interface when a second condition is met, the second condition including determining that the second user is a contact of the first user based on the second user relationship chain identifier, and/or determining that the third terminal is a device shared by the first terminal based on the device hash of the third terminal, the second interface including a first object and a second object, the second object including information of the second user, and/or information of the third terminal.
  • the same information is displayed when showing information about the same contact, providing consistent visual recognition for the same contact. This makes it easier for users to quickly and intuitively identify and categorize contacts, avoiding confusion and improving the user experience.
  • the method further includes: deleting the device hash of the device that shared data with the first terminal if the storage time of the device hash of the device that shared data with the first terminal exceeds a preset time; the preset time is the storage time of the device hash of the device that shared data with the first terminal in the preset historical sharing database.
  • each device hash in the historical sharing database can have its own preset duration, and the preset durations for different device hashes are different.
  • each device hash in the history sharing database can have the same preset duration, and the device hash is only valid within the preset duration.
  • the real-time nature of device hashes in the historical sharing database can be guaranteed, information redundancy can be avoided, and authentication efficiency can be improved.
  • an electronic device which has the function of implementing the methods described in any of the above aspects and designs.
  • This function can be implemented by hardware or by hardware executing corresponding software.
  • the hardware or software includes one or more modules corresponding to the above functions.
  • an electronic device comprising: a processor and a memory coupled to the processor, the memory being used to store program code including instructions, the processor reading the instructions from the memory to cause the electronic device to perform the method as described in any of the foregoing aspects and any of the designs therein.
  • a sixth aspect is a computer-readable storage medium comprising a computer program that, when executed on an electronic device, causes the electronic device to perform the method as described in any of the foregoing aspects and any of the designs thereof.
  • a computer program product comprising: a computer program or instructions that, when executed on a computer, cause the computer to perform the method as described in any of the foregoing aspects and any of the designs thereof.
  • a communication system including a first terminal and a server, wherein the first terminal is configured to perform the method as described in the first aspect and any of the designs therein, and the server is configured to perform the method as described in the second aspect and any of the designs therein.
  • this application provides a chip system including at least one processor and at least one interface circuit, the at least one interface circuit being used to perform transceiver functions and send instructions to at least one processor, and when at least one processor executes instructions, at least one processor performs the method as described in any of the foregoing aspects and any of the designs therein.
  • the present application provides a communication device, comprising: a processor configured to execute the methods in any of the above aspects and any of their implementations.
  • the device may also include a memory and/or a communication interface.
  • the communication interface is used to receive and/or transmit signals.
  • the communication interface is coupled to the processor.
  • the memory is used to store computer programs, and the processor is configured to perform the method described in the first aspect and any of its implementations, which can be implemented as: executing the computer program stored in the memory to perform the method described in the first aspect and any of its implementations.
  • the processor can also be a hardware-implemented circuit, such as an artificial intelligence (AI) processor, to improve operating speed.
  • AI artificial intelligence
  • the communication device can be a complete device or a module within the device, such as a chip.
  • FIGS 1 and 2 are schematic diagrams of the architecture provided in the embodiments of this application.
  • Figure 3A is a schematic diagram of the relationship network provided in an embodiment of this application.
  • Figure 3B is a schematic diagram illustrating the association between communication identifiers and accounts provided in an embodiment of this application;
  • Figure 4 is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.
  • Figure 5 is a schematic diagram of another structure of an electronic device provided in an embodiment of this application.
  • Figure 6 is a flowchart illustrating the method provided in an embodiment of this application.
  • Figure 7 is a schematic diagram of a business scenario provided in an embodiment of this application.
  • Figure 8A is a schematic diagram of the business scenario provided in the embodiment of this application.
  • Figure 8B is a schematic flowchart of the method provided in the embodiment of this application.
  • Figure 9 is a schematic diagram of a scenario where the association between the relationship chain identifier and the contact information is modified, as provided in an embodiment of this application.
  • Figure 10 is a flowchart illustrating the method provided in this embodiment of the application.
  • Figure 11 is a schematic diagram of the visibility requirements of electronic devices provided in the relevant specifications according to the embodiments of this application.
  • Figure 12 is a schematic diagram of the user interface of a contact authentication method provided in an embodiment of this application.
  • Figure 13 is a schematic diagram of the identity authentication method provided in an embodiment of this application.
  • Figure 14 is a schematic diagram of a preliminary screening based on truncated hash values provided in an embodiment of this application;
  • FIG 15 is a schematic diagram of the identity authentication method provided in an embodiment of this application (II).
  • FIG 16 is a schematic diagram of the identity authentication method provided in the embodiment of this application.
  • FIG 17 is a schematic flowchart of the communication method provided in an embodiment of this application.
  • Figure 18 is a schematic diagram of a communication device provided in an embodiment of this application.
  • Figure 19 is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.
  • Figure 20 is a schematic diagram of the chip system provided in an embodiment of this application.
  • references to "one embodiment” or “some embodiments” in this specification mean that one or more embodiments of this application include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases “in one embodiment,” “in some embodiments,” “in other embodiments,” “in still other embodiments,” etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean “one or more, but not all, embodiments,” unless otherwise specifically emphasized.
  • the terms “comprising,” “including,” “having,” and variations thereof mean “including but not limited to,” unless otherwise specifically emphasized.
  • connection includes direct connections and indirect connections, unless otherwise stated. "First” and “second” are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated.
  • the words “exemplarily” or “for example” are used to indicate examples, illustrations, or explanations. Any embodiment or design described as “exemplarily” or “for example” in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design solutions. Specifically, the use of the words “exemplarily” or “for example” is intended to present the relevant concepts in a specific manner.
  • “Used for” can mean “specifically for” or “can be used for”, without being limited to “specifically for”. For example, in addition to being used for xx, it can have other uses, without restriction.
  • the data sent from the terminal to the server can be referred to as uplink data.
  • the data sent from the server to the terminal can be referred to as downlink data.
  • a first terminal logs into a first user's account.
  • the first terminal stores the first user's relationship chain identifier and the relationship chain identifiers of at least one of the first user's contacts.
  • the first terminal receives a first operation to initiate a communication connection with a second user among the first user's at least one contact.
  • the communication identifier of the second user's second terminal is obtained; based on the communication identifier, a communication connection request is sent to the second user's second terminal.
  • the first terminal when the first terminal communicates with the second terminal, it can query the contact's communication identifier based on the contact's relationship chain identifier, without needing to search for users in the second terminal using private information such as phone numbers or email addresses, thereby reducing the risk of user privacy information leakage.
  • the aforementioned Account Encrypt ID is used to identify/identify a user's identity (corresponding to the user on the terminal) and is different from the user's contact information, thus not involving privacy.
  • the contact information can be a mobile phone number, email address, fax number, etc.
  • the terminal login account (AccountId) can also be called a system account, which is a system-level account. For example, the account could be a Huawei account.
  • the relationship chain identifier can be determined based on the user's logged-in account on their terminal. This can be achieved by encrypting the associated account.
  • the encryption method can be hashing, but is not limited to it.
  • the aforementioned communication identifier is used to address the terminal.
  • the communication identifier can be a device identifier (DeviceID) or a communication address.
  • the communication address can be the device's Internet Protocol (IP) address.
  • IP Internet Protocol
  • the device identifier can be the device's serial number or other unique identifier that addresses the device.
  • One terminal corresponds to one communication identifier. Different terminals have different communication identifiers. This article uses DeviceID as an example for consistent explanation, and will not repeat this detail below.
  • the user's relationship chain identifier can be determined based on that account. This relationship chain identifier corresponds to the terminal's DeviceID. Subsequently, other terminals can use the user's relationship chain identifier to find the terminal's DeviceID, thereby locating the terminal.
  • the method of this embodiment can be applied to a system including a server 100 (or cloud) and multiple terminals 200 (200a-200e shown in Figure 1).
  • the terminals 200 can connect to the server via a wired network or a wireless network.
  • a wired network for example, through a local area network, cellular network, wireless fidelity (Wi-Fi) or other communication connections.
  • Wi-Fi wireless fidelity
  • the server can be a standalone server or a server cluster consisting of multiple regions, multiple data centers, and multiple servers, without any restrictions.
  • terminal 200 can be a mobile phone, tablet computer, handheld computer, netbook, as well as a personal digital assistant (PDA), artificial intelligence (AI) device, or wearable device.
  • Wearable devices include, but are not limited to, smartwatches, smart bracelets, smart ankle bracelets, and other various devices.
  • the operating system installed on terminal 200 is not limited. This application does not limit the specific type of terminal 200 or the operating system installed on it.
  • Figure 2 illustrates another system architecture example provided by an embodiment of this application.
  • the server may include an account cloud, a relationship chain service, and a push service.
  • This server may be referred to as a relationship chain server.
  • Account Cloud also known as cloud space or account cloud service, can be used to receive uplink data uploaded by various terminals.
  • the uplink data uploaded by the terminals may include: the terminal user's relationship chain identifier and the terminal user's contact information.
  • the relationship chain identifier does not involve sensitive privacy information and has a high level of security.
  • the uplink data may also include: contact information for at least one contact of the end user.
  • the terminal can report some information about the terminal user and some information about its contacts. This information can be used by the terminal to obtain the contact's relationship chain identifier from the server. Subsequently, the terminal can use the contact's relationship chain identifier to initiate a communication connection with the contact's terminal.
  • a user's contact information may include, but is not limited to, at least one of the following: telephone number, email address, or fax number.
  • different contacts may use the same or different contact information types. For example, all contacts may use telephone numbers. Alternatively, some contacts may use telephone numbers, while others may use email addresses.
  • a contact's contact information corresponds one-to-one with the contact's relationship chain identifier. That is, the contact information, relationship chain identifier, and account are all linked one-to-one. For example, if user A's contact B registers a Huawei account using phone number B, there is a one-to-one correspondence between phone number B and the registered Huawei account; different Huawei accounts are bound to different phone numbers.
  • terminal A uploads to the account cloud the relationship chain identifier of user 1 (e.g., Account encrypt Id_A), user A's phone number (e.g., PhoneNum_A), and user A's email address (e.g., Email_A).
  • user 1 e.g., Account encrypt Id_A
  • user A's phone number e.g., PhoneNum_A
  • user A's email address e.g., Email_A
  • other terminals upload to the account cloud the contact information of their respective users and their relationship chain identifiers.
  • terminal A can also upload contact B's mobile phone number (e.g., PhoneNum_B) and contact C's email address (e.g., Email_C) to the account cloud.
  • terminal A can upload contact information in the following format: ⁇ AccountOwnerID_A, PhoneNum_B; AccountOwnerID_A, Email_C ⁇ .
  • PhoneNum_B represents contact B's phone number
  • AccountOwnerID_A indicates that contact B is a contact of user A on terminal A.
  • user A's contact C's email address is Email_C.
  • the contact person may also be referred to as a friend, and the name is not limited.
  • each terminal can also upload its own push token to the server.
  • terminal A uploads pushToken_A.
  • the server can push information to the terminal corresponding to the push token. For example, it can push a message to instruct the terminal to modify the contact's relationship chain identifier.
  • the terminal logs into its account, and after the user agrees to the privacy statement, the terminal can upload the aforementioned uplink data to the account cloud.
  • the uplink data reported by terminals A, C, and D are shown in Figure 2.
  • Account Cloud After receiving the uplink data from various terminals, Account Cloud can aggregate the data and establish a relationship network between users.
  • This network represents the friendships between users.
  • arrows indicate friendships.
  • User A's contacts include users G, F, E, D, C, and B;
  • user B's contacts include users A and K;
  • user C's contacts include users A and B, and so on.
  • the relationship network may also be called a relationship chain network, a relationship chain cloud, or a relationship chain, without any restrictions on the name.
  • Account Cloud After receiving uplink data from various terminals, Account Cloud can also determine and store relationship information between users based on this uplink data.
  • This relationship information can be used to represent the aforementioned relationship network, that is, to represent the friendship relationships between users.
  • the relationship information stored by Account Cloud is shown in Figure 3A.
  • the first row of relationship information indicates that user A's contact B's phone number is PhoneNum_B, and contact B's relationship chain identifier is Account encrypt Id_B.
  • Account Cloud After receiving uplink data from various terminals, Account Cloud can also determine and store relevant communication information based on this uplink data.
  • Communication information may include the DeviceID used to address the contact's device.
  • the communication information stored by Account Cloud is shown in Figure 3A.
  • the first line of communication information indicates: User A's relationship chain identifier is Account encrypt Id_A, User A's terminal A's DeviceID A, User A's phone number is PhoneNum_A, and User A's email address is Email_A.
  • the second-to-last line of communication information indicates: User E's relationship chain identifier is Account encrypt Id_E, User E's terminal E1's DeviceID E1, User E's phone number is PhoneNum_E, and User E's email address is Email_E.
  • the last line of communication information indicates: User E's relationship chain identifier is Account encrypt Id_E, User E's terminal E2's DeviceID E2, User E's phone number is PhoneNum_E, and User E's email address is Email_E.
  • the relationship chain identifier is associated with DeviceID.
  • Figure 3B illustrates the association between account and DeviceID.
  • User 1's account is Account 1
  • User 1's DeviceIDs include DeviceID 1-DeviceID 3.
  • DeviceIDs 1-3 represent the DeviceIDs of three different devices belonging to User 1.
  • User 2's account is Account 2
  • User 2's DeviceIDs include DeviceIDs 4-6.
  • the relationship chain service in the server can be used to send the relationship chain identifier of a contact to the terminal based on the data stored in the account cloud.
  • the relationship chain service can also be used to send the Device ID of a contact to the terminal.
  • contact E's Device ID includes Device ID E1 of terminal E1 and Device ID E2 of terminal E2.
  • the terminal can obtain the contact's DeviceID based on the contact's relationship chain identifier and use the contact's DeviceID to initiate a communication connection to the contact's terminal.
  • the server may return all or part of the contact's relationship chain identifiers to the terminal. For example, in Figure 2, if user A's contact X on terminal A does not have a Huawei account, the server will not return the relationship chain identifier of contact X to the terminal.
  • the relationship chain service can query whether the account cloud has already stored the relationship chain identifiers of contact B and contact C. If the account cloud has already stored the relationship chain identifiers of contact B and contact C, the relationship chain service can return the relationship chain identifiers of contact B and contact C to terminal A.
  • the server can return the DeviceID of contact B and the DeviceID of contact C to terminal A.
  • the relationship chain service can store these identifiers in the account cloud and then return them to terminal A.
  • the server can return the DeviceID of contact B and the DeviceID of contact C to terminal A.
  • terminal A After receiving the relationship chain identifiers of contacts B and C from the relationship chain server, terminal A can store these identifiers in the contact database. Similarly, other terminals can obtain the relationship chain identifiers of contacts from the server. In some scenarios, a terminal can obtain a contact's DeviceID based on the contact's relationship chain identifier and use that DeviceID to initiate a communication connection to that contact's terminal. See later sections for details on the implementation.
  • the terminal can also query the contact database based on the other party's relationship chain identifier and identify whether the other party is a contact of the local device based on the query results.
  • the contact database based on the other party's relationship chain identifier and identify whether the other party is a contact of the local device based on the query results.
  • the contact database also known as the relationship database
  • this contact database is a system-level or account-level database.
  • the address book corresponding to this system-level database can be called the system address book.
  • Table 1-1 shows the relationship chain identifiers of contacts B and C stored in terminal A. Each row represents M contact methods associated with a relationship chain identifier. M is a positive integer.
  • Table 1-2 shows the relationship chain identifiers of contacts B and C stored in terminal A. Each row represents a contact method associated with a relationship chain identifier. M contact methods for one contact correspond to M rows.
  • the terminal storage relationship chain identification method can be other than the formats shown in Table 1-1 and Table 1-2.
  • the push service on the server can be used to push change messages to the push service on the terminal. For example, when a user's relationship chain identifier changes, the push service pushes a change message to the terminals of that user's contacts, instructing those terminals to modify the user's relationship chain identifier. Subsequently, the contact's terminal can initiate a communication connection to the user's terminal based on the modified relationship chain identifier.
  • the aforementioned relationship chain server is used to update relationship chain-related information.
  • a terminal initiates a service, it no longer connects to the relationship chain server in real time, but instead connects to the service server to implement the service.
  • the service server receives message A from the first terminal and, based on the packet header parsing result of message A, identifies that the destination device of the first terminal is the second terminal.
  • the service server can check whether the second user of the second terminal is online. If not, the service server can send message B to bring the second user of the second terminal back online.
  • message A may include the DeviceID of the second user's second terminal.
  • the terminal can obtain the latest relationship chain information from the relationship chain server when initiating a service.
  • the business server and the relationship chain server connect to the cloud to ensure the accuracy and real-time nature of relationship chain-related information.
  • the system may also include a signaling server to enable reliable voice interaction.
  • Figure 4 shows a schematic diagram of the structure of an electronic device provided in an embodiment of this application.
  • the electronic device may be the terminal 200 or the server 100 described above.
  • the electronic device includes a processor 501, a memory 502, and a transceiver 503.
  • the implementation of the processor 501 and memory 502 can be found in the implementation of the processor and memory of the terminal shown in Figure 5.
  • the transceiver 503 is used for interaction between the electronic device and other devices.
  • the transceiver 503 can be a device based on protocols such as Wi-Fi, Bluetooth, or other communication protocols.
  • Figure 5 shows another structural schematic diagram of a terminal 500 provided in an embodiment of this application.
  • the terminal 500 may include a processor 510, a memory 520, and a display screen 530, etc.
  • Processor 510 may include one or more processing units, such as an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a video codec, a digital signal processor (DSP), a baseband processor, and/or a neural network processing unit (NPU). These different processing units may be independent devices or integrated into one or more processors.
  • AP application processor
  • GPU graphics processing unit
  • ISP image signal processor
  • DSP digital signal processor
  • NPU neural network processing unit
  • the controller can generate operation control signals based on the instruction opcode and timing signals to complete the control of instruction fetching and execution.
  • the processor 510 may also include a memory for storing instructions and data.
  • the memory in the processor 510 is a cache memory. This memory can store instructions or data that the processor 510 has just used or that are used repeatedly. If the processor 510 needs to use the instruction or data again, it can retrieve it directly from the memory. This avoids repeated accesses, reduces the waiting time of the processor 510, and thus improves the efficiency of the system.
  • the processor 510 may include one or more interfaces. These one or more interfaces can be used to connect the processor 510 to the memory 520, the display 530, and the like.
  • the processor 510 can be used to verify whether the received relationship chain identifier is a relationship chain identifier of a stored contact friend. Please refer to the following text for details.
  • the memory 520 can be used to store executable program code, including instructions.
  • the memory 520 may include a program storage area and a data storage area.
  • the program storage area may store the operating system, at least one application program required for a given function (such as image playback), etc.
  • the data storage area may store data created during the use of the terminal 500.
  • the processor 510 executes various functional applications and data processing of the terminal 500 by running instructions stored in the memory 520 and/or instructions stored in memory located within the processor.
  • Terminal 500 implements display functions through a GPU, display screen 530, and application processor.
  • the GPU is a microprocessor for image processing, connected to the display screen 530 and the application processor.
  • the GPU is used to perform mathematical and geometric calculations and for graphics rendering.
  • Processor 510 may include one or more GPUs, which execute program instructions to generate or modify display information.
  • Display screen 530 is used to display images, videos, etc.
  • Display screen 530 includes a display panel.
  • the display panel may be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a minimized LED, a microLED, a quantum dot light-emitting diode (QLED), etc.
  • terminal 500 may include one or N displays 530, where N is a positive integer greater than 1.
  • the display screen 530 can be used to display various interfaces. For example, it may prompt users who have received the relationship chain identifier to add them as contacts.
  • the terminal may include more or fewer components than those shown in FIG. 5, or combine some components, or split some components, or have different component arrangements.
  • the illustrated components may be implemented in hardware, software, or a combination of software and hardware.
  • Figures 4 and 5 above are merely possible examples of the structure of the terminal and server in the above system, and do not constitute a limitation on the structure of the terminal and server.
  • Figure 6 illustrates a flowchart example of the technical solution of this application embodiment. As shown in Figure 6, the method may include the following steps:
  • the first terminal receives the first operation of initiating a communication connection to the second user.
  • the system login on the first terminal uses the account of the first user.
  • the system login on the first terminal uses the Huawei account of the first user.
  • the account used for system login can be referred to simply as an account.
  • the first terminal stores a relationship chain identifier for a first user and a relationship chain identifier for a second user, where the second user is a contact of the first user.
  • the relationship chain identifier is generated based on the user's account logged into the terminal's system. For example, the first user's relationship chain identifier is generated based on the first user's account, and the relationship chain identifier for the first user's contact is determined based on the contact's account.
  • the relationship chain identifier can be obtained by hashing the account.
  • Terminal A logs in to user A's Huawei account A, and the hash value of Huawei account A yields user A's relationship chain identifier, Account encrypt Id_A.
  • Terminal B logs in to user B's Huawei account B, and the hash value of Huawei account B yields user B's relationship chain identifier, Account encrypt Id_B.
  • the relationship chain identifier can be determined based on other methods, which are not limited in this embodiment.
  • the account can be processed using SHA-256, or MD5, to obtain the relationship chain identifier.
  • the contacts of the first user include contact 1 and contact 2
  • the first terminal may store the relationship chain identifier of contact 1, the relationship chain identifier of contact 2, and the relationship chain identifier of the first user.
  • the first terminal may also store the contact information of at least one of the first user's contacts.
  • terminal A detects that user A clicked the video call control 102 corresponding to user B (Jane) (an example of the first operation), and terminal A determines that user A has initiated a communication connection with user B.
  • the first operation can be other operations without restriction. For example, in a near-field sharing scenario, the first operation could be clicking the icon of the searched other party.
  • applications can generate their own address books based on content downloaded from the server. In other words, applications can maintain their own address books on top of the existing relationship chains in the system's address book.
  • Application-specific address books offer finer granularity, for example, they can identify each device's DeviceID (an example of a communication identifier). Applications can initiate communication with corresponding devices based on these finer-grained address books.
  • An application-specific address book can be called an application-level address book. For example, Changlian maintains the address book shown in Table 2, through which Changlian can index the DeviceID of each device.
  • Applications can index communication devices through their own address book, depending on their own implementation; the specific implementation method is not limited.
  • the smart screen, tablet, and mobile phone are logged into the same account.
  • the mobile phone and tablet present a single contact, and when a call is made, all devices ring simultaneously.
  • the smart screen can be treated as a separate device, with its own identifier displayed in the MeeTime Contacts, and the terminal can call the smart screen independently.
  • terminal A detects that user A clicked the video call control 102 corresponding to user B (Jane) (an example of the first operation).
  • Terminal A knows that the video call control corresponds to user B.
  • Terminal A can query a table such as Table 2 based on user B's relationship chain identifier to obtain the DeviceID of user B's device.
  • user B's terminal B includes mobile phone 1 and mobile phone 2.
  • user B's device DeviceID includes the DeviceID of mobile phone 1: 887XXX1 and the DeviceID of mobile phone 2: 887XXX2.
  • terminal A can query a table such as Table 2 based on Jeff's relationship chain identifier to obtain Jeff's Smart Screen's DeviceID: 887XXX4.
  • the first terminal Based on the communication identifier, the first terminal sends a communication connection request to the second user's second terminal.
  • this communication connection request is used to initiate audio and video communication.
  • terminal A sends a communication connection request to user B's terminal B (such as a mobile phone) based on user B's DeviceID (an example of a communication identifier).
  • Terminal B responds to the communication connection request and establishes a communication connection with terminal A.
  • Terminal A and terminal B can communicate through this communication connection, such as transmitting audio and video data during an interactive call.
  • an application in the first terminal communicates with an application in the second terminal, it can query the communication identifier of the contact based on the contact's relationship chain identifier, without having to search for the user in the second terminal through private information such as phone number or email address, thereby reducing the risk of leakage of user's privacy information.
  • the above example uses the association between the contact's relationship chain identifier and the contact's DeviceID stored on the first terminal itself.
  • the terminal does not pre-obtain and store the contact's DeviceID from the server.
  • the first terminal queries the server for the contact's DeviceID. This implementation method is described below:
  • the first terminal when there is a business requirement, sends the second user's relationship chain identifier to the server and receives the second user's DeviceID from the server. Then, based on the DeviceID, the first terminal sends a communication connection request to the second terminal.
  • the server can store the correspondence between the relationship chain identifier and DeviceID for each of the multiple users.
  • the information stored on the server includes: the relationship chain identifier of user B and the DeviceID B1 (such as the identifier of a mobile phone) of the terminal B used by user B; the relationship chain identifier of user C and the DeviceID C1 (such as the identifier of a tablet) of the terminal C used by user C.
  • terminal A detects that user A clicked the video call control 102 corresponding to user B (Jane) (an example of the first operation).
  • Terminal A sends user B's relationship chain identifier to the server to query user B's DeviceID.
  • the server queries the stored correspondence to obtain the DeviceID B1 of user B associated with that relationship chain identifier. Then, the server returns user B's DeviceID B1 to terminal A.
  • terminal A can send a communication connection request to user B's terminal B based on that DeviceID.
  • the communication connection request sent to terminal B may include user A's relationship chain identifier.
  • Terminal B can query its contact database based on user A's relationship chain identifier. If the query finds user A's relationship chain identifier in the database, it indicates that user A is user B's friend. Terminal B can then display a call request interface for a friend. Conversely, if terminal B determines that the other party in the call request is not user B's friend, terminal B can display a call request interface for a non-friend. In other words, terminal B can display call request interfaces for friends and non-friends using different user interface (UI) styles.
  • UI user interface
  • user B has multiple devices logged into the same account.
  • user B's terminal B1 e.g., a mobile phone
  • terminal B2 e.g., a tablet
  • the information stored on the server may include: user B's relationship chain identifier and the DeviceID B1 of the mobile phone used by user B; user B's relationship chain identifier and the DeviceID B2 of the tablet used by user B; and user C's relationship chain identifier and the DeviceID C1 of the terminal C used by user C.
  • terminal A can send user B's relationship chain identifier to the server to query the DeviceID of user B's terminal.
  • the server queries the stored correspondence to obtain the DeviceID B1 (e.g., the DeviceID of user B's mobile phone) and DeviceID B2 (e.g., the DeviceID of user B's tablet) of the terminal associated with that relationship chain identifier. Then, the server returns user B's DeviceID B1 and DeviceID B2 to terminal A. Terminal A can then use user B's DeviceID B1 to send a video call request to user B's mobile phone.
  • DeviceID B1 e.g., the DeviceID of user B's mobile phone
  • DeviceID B2 e.g., the DeviceID of user B's tablet
  • terminal A can use user B's DeviceID B2 to send a video call request to user B's tablet.
  • all devices logged into the same account by user B will receive the video call request, and user B can choose to accept the video call request on any device and use that device to conduct a video call with user A.
  • the above example illustrates how the first terminal queries the server for the DeviceID of the second user's second terminal and directly uses that DeviceID to initiate a communication connection with the second terminal.
  • the first terminal can also establish a communication connection with the second terminal through the server.
  • terminal A sends the relationship chain identifier of user B to the server.
  • the server queries its locally stored communication information to determine that the DeviceID of user B's terminal is B1.
  • the server establishes a communication connection between terminal A and terminal B based on user B's terminal DeviceID.
  • the server that triggers the establishment of the communication connection between the terminals can be the same server or a different server than the server that implements other functions described herein.
  • the communication connection between the first terminal and the second terminal can be a direct connection or an indirect connection.
  • the connection between the first terminal and the second terminal can be a point-to-point (P2P) connection.
  • P2P point-to-point
  • the first terminal and the second terminal can be connected via a relay.
  • the relay includes, but is not limited to, a server.
  • the server acting as a relay can be the same server as the server implementing other functions in this document, or a different server.
  • the contact information of the first user of the first terminal, or the contact information of the first terminal's contacts may change.
  • the first terminal or the server needs to perform corresponding update operations so that subsequent terminals can use the updated relationship chain identifier to initiate communication connections. The following describes different scenarios:
  • Scenario 1 The first user of the first terminal changes their own contact information.
  • the terminal of the first user's contact modifies the association between the first user's contact information and the first user's relationship chain identifier.
  • a first terminal receives a second operation to modify the contact information of a first user.
  • the first terminal can send the modified contact information of the first user to the server.
  • the server can send a first notification message to a third terminal.
  • the first notification message is used to notify the third terminal of the modification of the first user's contact information and the association relationship between the first user and the first user's relationship chain identifier.
  • the contact information of the third terminal's user's contacts includes the contact information of the added first user.
  • the server can notify the contacts' terminals to modify the association relationship between the first user's contact information and the first user's relationship chain identifier.
  • the server modifies the association between the first user's contact information and the first user's relationship chain identifier.
  • Optional modifications include one or more of the following: adding contact information, deleting contact information, and updating contact information.
  • the following example uses terminal A as the first terminal and user A as the first user.
  • terminal A can then report this phone number 189xxx to the server. Specifically, terminal A reports the relationship chain identifier between the phone number 189xxx and user A.
  • the server can then modify user A's communication information accordingly. For instance, it can add the phone number 179xxx to user A's communication information.
  • the server Based on the received information, the server sends a first communication message to the terminals of user A's contacts to notify them to modify the association between user A's contact information and user A's relationship chain identifier. For example, based on the stored relationship information example shown in Figure 2, the server can determine that user A's contacts include user B and user C, and then send a first notification message to the terminals of user B and user C respectively.
  • this first notification message includes user A's relationship chain identifier, user A's new phone number 189xxx, and terminal B's push token (push token B).
  • Terminal B adds the association between the new phone number 189xxx and user A's relationship chain identifier based on the first notification message.
  • Table 3-2 below, compared to Table 3-1, terminal B adds a second row, Account encrypt Id_A, 189xxx, to Table 3-2 to indicate the association between the new phone number 189xxx and user A's relationship chain identifier, Account encrypt Id_A.
  • the email address in the second row of Table 3-2 can be Email_A or empty, without restriction.
  • user A deletes their contact information on terminal A.
  • User A can delete some or all of the contact information. For instance, user A can delete only the phone number, or delete both the phone number and email address.
  • Terminal A can report its deleted contact information to the server. Specifically, Terminal A reports the deleted contact information and User A's relationship chain identifier. After receiving the information reported by Terminal A, the server sends a first notification message to the terminals of User A's contacts that store the deleted contact information. For example, the first notification message includes the deleted contact information, User A's relationship chain identifier, and a push token. The terminals of User A's contacts can delete the association between User A's contact information and User A's relationship chain identifier based on the first notification message. In some examples, as shown in Table 4-2 below, compared to Table 4-1, Terminal B has deleted the first row in Table 4-2.
  • Terminal B has deleted the phone number 189yyy from the first row of Table 5-2, but the association between the relationship chain identifier Account encrypt Id_A and the email address Email_A still exists.
  • terminal A can report both phone number A and phone number B to the server.
  • the server can send a first notification message to the contact terminal that stores phone number A.
  • the first notification message may include: phone number A, phone number B, user A's relationship chain identifier, and the push token of that contact terminal.
  • contact terminal B can, based on the first notification message, delete the association between phone number A and user A's relationship chain identifier, and add the association between phone number B and user A's relationship chain identifier.
  • Scenario 2 The first user on the first terminal modifies the contact information of the contact person.
  • the first terminal modifies the association relationship of the contact's relationship chain identifier.
  • the server can modify the stored association relationship between the contact's (e.g., a third user's) contact information and the relationship chain identifier based on the modified contact's contact information.
  • a first user on a first terminal adds contact information to a contact.
  • the first terminal receives a third operation to add a third user as a contact.
  • the first terminal sends the third user's contact information to the server.
  • the first terminal receives and stores the third user's relationship chain identifier sent by the server.
  • the first terminal may also receive and store the Device ID of the third user's terminal sent by the server.
  • terminal A can report friend B's contact information to the server. Specifically, terminal A reports: friend B's contact information and user A's relationship chain identifier.
  • the server locates the relationship chain identifier of friend B in the storage space and pushes it to terminal A. For example, the server sends a push message containing friend B's contact information, relationship chain identifier, and a corresponding push token, indicating the association between friend B's contact information and relationship chain identifier.
  • the server can also send the Device ID of the terminal containing the newly added friend B to terminal A.
  • the first terminal also stores the contact information of at least one of the first user's contacts.
  • the first user of the first terminal can delete the contact information of one or more contacts.
  • the first terminal receives a fourth operation to delete a fourth user as a contact.
  • the first terminal deletes the stored relationship chain identifier of the fourth user.
  • the first terminal can also delete the Device ID of the fourth user's terminal.
  • the first terminal will delete the stored relationship chain identifier of friend B and the Device ID of friend B's terminal.
  • the first terminal responding to the fourth operation, can also send the contact information of the fourth user to the server.
  • terminal A can also report the contact information of friend B to the server, and the server can delete the association between friend B's contact information and friend B's relationship chain identifier.
  • the first terminal also stores the contact information of at least one of the first user's contacts.
  • the first user of the first terminal can update the contact information of one or more contacts.
  • the first terminal also stores the contact information of a fifth user and a relationship chain identifier for that fifth user, who is a contact of the first user.
  • the first terminal can receive a fifth operation to update the fifth user's contact information from a first contact information to a second contact information, and in response to the fifth operation, update the contact information corresponding to the fifth user's relationship chain identifier from the first contact information to the second contact information.
  • terminal A can delete the association between friend B's number 1 and friend B's relationship chain identifier, and add the association between friend B's number 2 and friend B's relationship chain identifier.
  • the first terminal can promptly update the association between the fifth user's relationship chain identifier and contact information.
  • the first terminal responding to the fifth operation, can also send the fifth user's first and second contact information to the server.
  • terminal A can also notify the server of the changed number 2 of friend B, instructing the server to delete the association between number 1 and friend B's relationship chain identifier, and add the association between number 2 and friend B's relationship chain identifier.
  • the server can quickly learn of the fifth user's updated contact information and update the association between the fifth user's relationship chain identifier and contact information accordingly.
  • the server can also send notification messages to the terminals of the fifth user's contacts to instruct those terminals to modify the association between the fifth user's contact information and the relationship chain identifier.
  • user A's friend B's phone number is updated from number 1 to number 2.
  • the server determines that friend B's contacts also include contact C and contact K. Then, the server can send notification messages to the terminals of contact C and contact K to instruct them to update the association between friend B's relationship chain identifier and contact information.
  • terminals C and K can delete the association between friend B's number 1 and friend B's relationship chain identifier, and add the association between friend B's number 2 and friend B's relationship chain identifier.
  • the server can also send push messages to user A's other devices to indicate the deletion, addition, or update of friend B's contact information and the association relationship of friend B's relationship chain identifier.
  • the above mainly uses the Changlian Communication far-field communication as an example to introduce the solution of the embodiment of this application.
  • the solution can also be applied to near-field communication.
  • terminal A can send the contact information of its friend, user B, to the server and receive user B's relationship chain identifier from the server.
  • terminal B sends a broadcast, which can carry terminal B's user B's relationship chain identifier.
  • Terminal A searches for nearby devices, and in doing so, it finds terminal B's broadcast.
  • Terminal A determines whether the relationship chain identifier from the broadcast is already stored in its contact database. If it is, terminal B is user A's contact. Conversely, if terminal A does not store the relationship chain identifier, terminal B is not user A's contact.
  • terminal A can display contacts and non-contacts differently.
  • the UI style of the contact icon is Style 1
  • the UI style of the non-contact icon is Style 2.
  • FIG 8A user B is a contact.
  • terminal A can establish a communication connection with terminal B.
  • Figure 8B shows a flow example of the scenario shown in Figure 8A.
  • terminal A can be configured to support interaction with all users found in the search.
  • terminal A can establish a communication connection with the found user.
  • This user can be a contact or a non-contact.
  • terminal A can be configured to interact only with contacts. In this case, terminal A can establish a communication connection with the searched contacts. For non-contacts found in the search, terminal A can display a prompt message suggesting that they be added as contacts before communication. After user A adds the searched party as a contact, terminal A can establish a communication connection with that contact.
  • the terminal carries a relationship chain identifier in the broadcast, rather than sensitive information such as the phone number, which can improve information security and avoid privacy leaks.
  • multiple devices may also share relationship chain identifiers.
  • the first terminal also stores the contact information of at least one of the first user's contacts, with each contact's contact information corresponding one-to-one with its relationship chain identifier.
  • the first terminal receives a notification message from the server, which notifies the first terminal to modify the association between the stored contact information and the relationship chain identifier.
  • Modifying the association between the stored contact information and the relationship chain identifier includes one or more of the following: deleting the association between the contact information of the sixth user among the first user's at least one contact and the relationship chain identifier; updating the contact information corresponding to the relationship chain identifier of the seventh user among the first user's at least one contact; and adding the association between the contact information of the eighth user and the relationship chain identifier.
  • the server can receive modified contact information for a third user from the first terminal. Modifications may include one or more of the following: adding the third user as a contact, deleting the third user from the contacts list, or updating the third user's contact information.
  • the server can send a second notification message to the fourth terminal, informing it of the modification of the association between the stored contact information and the relationship chain identifier.
  • the fourth terminal logs in using the same account as the first terminal.
  • a user adds the phone number 180xxx of contact B to mobile phone A1.
  • Mobile phone A1 can query the server for the relationship chain identifier of contact B.
  • mobile phone A1 receives a notification message from the server, which includes the phone number 180xxx of contact B and the relationship chain identifier Account encrypt Id_B of contact B, to instruct mobile phone A1 to add the association between the phone number 180xxx and the relationship chain identifier Account encrypt Id_B.
  • tablet A2 logged into the same Huawei account A as mobile phone A1, has enabled cloud synchronization.
  • the server can then send the aforementioned notification message (an example of the second notification message) to tablet A2, instructing it to add the association between phone number 180xxx and the relationship chain identifier Account encrypt Id_B.
  • devices with cloud synchronization enabled can obtain not only their own device's contact relationship chain identifier from the server, but also the contact relationship chain identifiers of devices with the same account (such as mobile phones with the same account).
  • the device can obtain data from the contact database of devices with the same account. In other words, devices with the same account may have completely identical data in their contact databases.
  • computer A3 which is logged into the same account A as mobile phone A1, does not have cloud synchronization enabled. Therefore, the server does not need to send the aforementioned notification message to computer A3.
  • Computer A3 cannot obtain the contact relationship chain identifier of devices with the same account (such as mobile phones with the same account).
  • each terminal may store the capability information of its respective contacts.
  • the first terminal also stores the capability information of at least one of the first user's contacts.
  • the capability information of a contact corresponds one-to-one with the contact's relationship chain identifier, and the capability information is used to indicate whether the corresponding contact has audio and video communication capabilities.
  • the capability information of the second user is used to indicate that the second user has audio and video communication capabilities.
  • the contact's capability information represents the capabilities possessed by the contact's account. Different accounts may have different capabilities.
  • different relationship chain identifiers may correspond to different capability information.
  • each terminal can also store the capability information of its own local user.
  • the format of capability information can be bit-based.
  • the capability information of user A's contact B is: 000001100.
  • Contact B's capability information is: 000001101.
  • the 6th, 7th, 8th, and 9th bits of the 9-bit capability information represent the Huawei Connect application capability, Huawei Share capability, Long Tail Application 1 capability, and Long Tail Application 2 capability, respectively. Therefore, the above capability information can respectively indicate that: contact B's Huawei account has activated the Huawei Connect application capability and the Huawei Share capability; contact C's Huawei account has activated the Huawei Connect application capability, the Huawei Share capability, and the Long Tail Application 2 capability.
  • the number of bits and the meaning of each bit here are only examples; the number of bits and the meaning of each bit can also be other, without limitation.
  • the format of capability information can also be other, without limitation.
  • the Huawei account has enabled the MeeTime application capability, which can be understood or replaced as follows:
  • the terminal can implement the methods of the embodiments of this application to conduct audio and video communication through the MeeTime application and improve the security of audio and video communication. For example, obtaining the local user's relationship chain identifier and uploading the local user's contact information and relationship chain identifier to the server.
  • Another example is receiving the relationship chain identifier of a contact from the server.
  • Yet another example is using the contact's relationship chain identifier to initiate an audio connection request or video connection request to the contact's terminal.
  • the Huawei account has enabled Huawei Share capability, which can be understood or replaced as follows:
  • the terminal can implement the methods of the embodiments of this application to transmit data through Huawei Share and improve the security of data transmission. For example, receiving the contact's relationship chain identifier from the server. Another example is using the contact's relationship chain identifier to query the contact's terminal's Device ID. Yet another example is using the contact's terminal's Device ID to initiate a communication connection to the contact's terminal.
  • the Huawei account has other capabilities enabled, which can be understood or replaced as: in the corresponding scenario, the terminal can implement the methods of the embodiments of this application to improve the security of communication in that scenario.
  • each terminal can upload its own user capability information to the server.
  • the first terminal can send the capability information of the first user to the server.
  • the server can determine the account-level capability information of each user. Subsequently, based on the corresponding user's capability information, the corresponding communication process can be controlled to improve communication security. Specific implementation details are provided below.
  • the server can send contact capability information to each terminal.
  • Each terminal can store the capability information of at least one contact.
  • the server can send the capability information of at least one contact of a first user to a first terminal; this capability information indicates whether the corresponding contact has audio and video communication capabilities.
  • Table 7 shows an example of the capability information of the contact (second user) stored in the first terminal.
  • the first terminal may also store the second user's nickname, avatar information, etc., without limitation.
  • the server can also store device-level capability information to identify devices that have the appropriate capabilities enabled.
  • the terminal may also store device-level capability information.
  • This application embodiment does not limit the storage granularity of capability information.
  • terminal A can use user B's relationship chain identifier to communicate with user B's terminal.
  • terminal A does not use user B's relationship chain identifier to communicate with user B's terminal; terminal A can use relevant technical solutions to communicate with user B's terminal.
  • the terminal can also distinguish the capability information of contacts and determine the UI style of different contact information accordingly.
  • the first terminal can mark contacts that support audio and video capabilities in the Contacts application. For instance, for contacts that support MeeTime audio and video capabilities, the first terminal displays a corresponding icon for that contact, such as the MeeTime icon, to indicate that the contact supports MeeTime audio and video capabilities. Using this method, the first terminal can quickly retrieve a specific capability from its contacts, improving communication efficiency.
  • the terminal can call system-level relationship chain information to generate a friend list.
  • the terminal's friend list can only display friends who support communication through the Changlian application, or a special marker can be used to indicate whether a friend supports communication through the Changlian application.
  • This application embodiment also provides a communication method in which a communication token (comToken) is required as a security credential before the first terminal communicates with the second terminal.
  • a communication token (comToken) is required as a security credential before the first terminal communicates with the second terminal.
  • the method for obtaining the communication token may include:
  • the contact database management module sends request A, which is used to request an authentication code (AuthCode).
  • AuthCode authentication code
  • the terminal may include a contact database management module, which can be used to manage the contact database.
  • An authentication code can be used to represent the application's identity information.
  • the request may include the application's identifier (APP ID).
  • APP ID application's identifier
  • the application sends request A to the account management module in the terminal.
  • the terminal sends request B to the server.
  • request B may include the application's package name and the application's identifier.
  • request B may also include the application's key.
  • the terminal sends request B to the account cloud on the server through the account management module to request an authentication code.
  • the server returns the signature fingerprint and authentication code to the terminal.
  • the server's account cloud After receiving request B, the server's account cloud obtains the application's signature fingerprint and returns the signature fingerprint and authentication code to the terminal.
  • the application's signature fingerprint is used to verify that the signature fingerprint comes from the server.
  • Account Cloud uses its own private key to digitally sign the Huawei account associated with the application, thus obtaining the application's signature fingerprint.
  • the account management module If the signature fingerprint is valid, the account management module returns the authentication code and relationship chain identifier to the contact database management module.
  • the account management module verifies the application signature fingerprint from the server. If the signature fingerprint passes verification, it indicates that the fingerprint originated from the server and has not been tampered with, meaning that the Huawei account used to obtain the fingerprint has not been altered. Subsequently, the terminal can determine the user's relationship chain identifier based on this accurate Huawei account. For example, the terminal can also upload this relationship chain identifier to the server.
  • the account management module can obtain the Huawei account based on the signature fingerprint and calculate the terminal user's relationship chain identifier based on the Huawei account. The specific calculation method for the relationship chain identifier can be found in other sections of this document. Afterwards, the account management module can return the relationship chain identifier and the authorized authentication code to the contact database management module.
  • the contact database management module sends request C to the server.
  • Request C is used to request a communication token.
  • the communication token serves as a security credential for the terminal, granting the terminal that obtains the communication token permission to retrieve the contact relationship chain identifier from the server.
  • the terminal that obtains the communication token may also have permission to retrieve the Device ID of the terminal whose contacts are being retrieved from the server.
  • the contact database management module can send the request C to the server's relationship chain service.
  • the request C may include an authentication code.
  • the request C may also include the end user's relationship chain identifier.
  • the request C may also include the application's package name.
  • the request C may also include the terminal's Device ID.
  • the server confirms and returns a communication token.
  • the relationship chain service verifies the relationship chain identifier and Device ID.
  • the relationship chain service determines whether the end user's relationship chain identifier and the terminal's Device ID are valid. For example, if the relationship chain identifier is not in the relationship chain whitelist and the Device ID is not in the Device ID whitelist, it means that the relationship chain identifier and Device ID have security risks. Based on this, the server rejects request C and determines not to return a communication token to the terminal's contact database management module.
  • the package name verification passes. Conversely, if the package name does not exist in the package name blacklist, the package name verification passes.
  • the relationship chain service obtains the application's key.
  • the relationship chain service can obtain the application identifier based on the package name and obtain the key of the application corresponding to that identifier.
  • the Relationship Chain Service sends Request D to the Account Cloud.
  • Request D is used to request a communication token.
  • tokens include, but are not limited to, access tokens (AT) and/or refresh tokens (RT).
  • request D may carry an authentication code, the application's key, and the application's identifier.
  • the verification code in the account cloud verification request D is a valid verification code. If it is an authorized and valid verification code, then the verification code passes the verification.
  • Account Cloud can also verify the association between authentication codes, keys, and application identifiers.
  • the authentication code carried in request D is the authentication code corresponding to the application identifier
  • the application key in request D is the key corresponding to the application identifier
  • Account Cloud returns a communication token to the Relationship Chain Service.
  • both the authentication code and the application key pass verification, it means that the application is initially trusted, and the account cloud returns a communication token to the relationship chain service.
  • the relationship chain service returns a communication token to the terminal.
  • the relationship chain service returns a communication token to the terminal's contact database management module.
  • the terminal uses the communication token as a security credential to communicate with the server.
  • the terminal sends the communication token and the contact information of at least one of the terminal's users' contacts to the server.
  • the server can determine that the terminal has permission to obtain the relationship chain identifier of at least one contact.
  • the server may send the relationship chain identifier of at least one contact to the terminal.
  • the server may also send the Device ID of the terminal of at least one contact to the terminal.
  • the terminal After obtaining the relationship chain identifier of at least one contact from the server, the terminal can store the relationship chain identifier of at least one contact in the contact database.
  • the terminal can store the Device ID of the terminal of at least one contact (such as in Table 2 above). Subsequently, the terminal can look up the Device ID of the contact's terminal through the relationship chain identifier and use the Device ID of the contact's terminal to initiate a communication connection to the contact's terminal.
  • the terminal's contact database management module uses the aforementioned communication token to communicate with the server.
  • communication tokens can be updated. For example, a communication token can be set to be valid for a certain period. After this period expires, the terminal can request a new communication token from the server. Similarly, if a terminal service fails, it can request a new communication token from the server. This prevents communication tokens from remaining valid for an extended period, improving the security and robustness of the communication system.
  • the validity period of the communication token is not fixed.
  • the token for the first communication is valid for 7 days, and the token for the second communication is valid for 5 days.
  • the validity period of the communication token can be fixed.
  • One possible implementation is to use random numbers as communication tokens. This minimizes the correlation between different communication tokens and improves communication security.
  • a malicious application on a malicious terminal obtains the communication token and user B's relationship chain identifier. Then, the malicious terminal sends a communication connection request to user B based on user B's device ID. Upon receiving this request, user B can determine that the malicious terminal's relationship chain identifier does not exist in its contact database. This means user B and the malicious terminal's user are not friends, and user B can display a "Unknown caller" message to indicate that the caller is not a friend.
  • the malicious terminal obtains the communication token (a security credential), user B's relationship chain identifier, and user B's device ID, user B can still determine from its contact database that user B and the malicious terminal's user are not friends, thus preventing potential security risks from communicating with non-friends.
  • the communication token a security credential
  • user B's relationship chain identifier a security credential
  • user B's device ID a security credential
  • the scenarios applicable to the embodiments of this application are not limited to the above-listed scenarios such as MeeTime and Huawei Share.
  • the solutions of the embodiments of this application can also be used in scenarios such as SMS and calls, so as to obtain the Device ID of the contact's terminal by using the relationship chain identifier, thereby reducing the probability of user identity information (such as mobile phone number) being leaked.
  • the communication method provided in the above embodiments can be applied to near-field communication, and the relationship chain identifier is used to obtain the Device ID of the terminal of the contact.
  • the relationship chain identifier in the above embodiments can also be applied to the identity authentication process, such as contact authentication.
  • the relationship chain identifier is used to improve the efficiency and accuracy of contact authentication.
  • terminal A can initiate a broadcast to search for nearby devices.
  • Terminal A's system is logged into user A's account, and the broadcast can carry a relationship chain identifier A generated based on user A's account.
  • Terminal B in the nearby devices can receive the broadcast, and terminal B's system is logged into user B's account.
  • Terminal B can determine whether user A is user B's contact based on the relationship chain identifier A in the broadcast.
  • terminal A can send a broadcast response to terminal A, which can carry a relationship chain identifier B generated based on user B's account. If not, it does not reply to terminal A. If terminal A receives a broadcast response from terminal B, terminal A can determine whether user B is user A's contact based on the relationship chain identifier B in the broadcast response.
  • Terminals can use near-field communication (NFC) technology to share data with other terminals.
  • NFC near-field communication
  • a first terminal shares data such as files with a second terminal.
  • the first terminal as the sending end, needs to discover or search for a nearby second terminal and establish a connection with it before it can perform operations such as file sharing.
  • the first and second terminals can be unfamiliar devices, meaning the first user associated with the first terminal and the second user associated with the second terminal are strangers to each other, or the first and second terminals have never shared data before.
  • the first terminal may not have added or stored the second user's identity information, and/or the second terminal may not have added or stored the first user's identity information.
  • the first terminal may not have added or stored the second terminal's device identifier, and/or the second terminal may not have added or stored the first terminal's device identifier.
  • the first and second terminals can be familiar devices, meaning the first user associated with the first terminal and the second user associated with the second terminal are contacts to each other, or the first and second terminals have shared data before.
  • relevant regulations require terminals to provide a switch to enable or disable the visibility of nearby devices before performing the aforementioned data sharing operations.
  • the regulations specify the activation time for this function. For example, a second terminal acting as the receiving end will automatically deactivate the "visible to all" function after 10 minutes. Therefore, within 10 minutes of the second terminal enabling the "visible to all” function, other nearby terminals can discover or search for the second terminal. After the second terminal's "visible to all" function is enabled, all contacts or strangers of the second user associated with the second terminal can discover or search for the second terminal if they are nearby.
  • the first terminal acting as the sending end can discover the second terminal within 10 minutes.
  • the first user associated with the first terminal can be either a contact of the second user or a stranger of the second user.
  • the 10-minute duration in the above example is an example duration.
  • the visibility of the device to other nearby devices can also be turned off based on other durations, and there are no restrictions on this.
  • the relevant specifications also stipulate the visibility of the sending end, meaning that the first terminal acting as the sending end must not be discovered or searchable by the second terminal acting as the receiving end at any time.
  • Figure 11 illustrates the visibility requirements of the relevant specifications.
  • the second terminal acting as the receiving end should have a visibility switch. When this switch is turned on, it means that the second terminal can be discovered by other terminals for a certain period of time, such as the 10 minutes shown in Figure 11, i.e., "visible to all.” In this way, other terminals can establish connections with the second terminal and share data with it.
  • the first terminal in Figure 11 can discover the second terminal within 10 minutes after the "visible to all" function is turned on. When the "visible to all" function has been on for more than 10 minutes, the second terminal will automatically turn off the function.
  • the relevant specifications require that the sending device must not be discovered by other terminals at any time.
  • terminals Due to the aforementioned regulations, terminals rely on the visibility of the peer device before sharing data with unfamiliar or familiar devices. For example, the first terminal can only successfully share data with the second terminal if the second terminal, acting as the receiving end, enables its visibility and is discovered by the first terminal, acting as the sending end, within a specified time. This undoubtedly negatively impacts the efficiency of data sharing.
  • some terminals offer a "visible only to contacts" function. For example, if the second terminal at the receiving end enables this function, the second terminal can be discovered by the first terminal when the terminals corresponding to its contacts (e.g., the first terminal) are nearby.
  • the second terminal's "visible only to contacts" function is enabled, upon receiving a search broadcast from the first terminal, the second terminal needs to authenticate the identity information of the first user carried in the broadcast to confirm the first user's identity and whether the first user is a contact of the second user. Only after the first and second terminals mutually authenticate and confirm that the first and second users are contacts can the first terminal share data with the second terminal.
  • RD hash-signed "record data (RD)" is used. RD contains the device's UUID and contact identifiers from all contacts in the device's address book. The sending device can sign the aforementioned RD to obtain RD(s), where s represents the corresponding certificate.
  • the receiving device calculates a hash value, such as SHA2, for each contact identifier in its address book and compares it with the hash value contained in the RD(s) to verify whether the device UUID matches the certificate of the current Transport Layer Security (TLS) link. If the sending or receiving end fails to provide a valid signed TLS certificate or does not provide an RD, authentication between the terminals cannot be completed.
  • a hash value such as SHA2
  • TLS Transport Layer Security
  • the terminal in this application embodiment can perform identity authentication based on the relationship chain identifier described above.
  • This application embodiment provides an identity authentication method. Applying the identity authentication method provided in this application embodiment, the terminal can perform initial screening of contacts and/or devices by matching a contact database and/or a historical sharing database, quickly authenticating their identities. Simultaneously, the initially screened contacts and/or devices can be displayed on the terminal in a corresponding area for user identification and further user operation. This application embodiment can quickly filter nearby contacts by matching the contact database. When neither terminal nor device has been added as a contact, this application embodiment can also quickly filter devices that have previously shared data using the historical sharing database. Based on this, when a user needs to share data with an initially screened contact or device through the terminal, the terminal can perform further identity authentication on that contact or device.
  • the embodiments of this application can quickly display contacts and/or devices that meet certain conditions through initial screening, allowing users to select the contacts or devices from which data needs to be shared, and then perform further identity authentication on the selected contacts or devices. Compared with the prior art, which requires contact identity authentication before displaying them to the user, this can improve the speed and efficiency of contact or device screening, and also help improve the efficiency of data sharing. That is, the embodiments of this application can display multiple contacts and/or devices through initial screening, and only perform identity authentication on the contacts or devices that need to share data; while the prior art requires identity authentication on all displayed contacts. The embodiments of this application simplify the identity authentication process and improve the efficiency of identity authentication. Moreover, the embodiments of this application do not require the sending of privacy information, reducing the risk of privacy leakage.
  • the authentication method provided in this application can be applied to terminals.
  • this method can be applied to the first terminal in the aforementioned example.
  • the first terminal can use this method to quickly achieve authentication with the second terminal.
  • the first terminal and the second terminal can be of the same type.
  • both the first terminal and the second terminal can be mobile phones, or both can be tablet computers.
  • the first terminal and the second terminal can be terminals of different types.
  • the first terminal can be a mobile phone and the second terminal can be a tablet computer, or the first terminal can be a tablet computer and the second terminal can be a wearable device, such as a smartwatch, etc.
  • This application does not limit the type of terminal.
  • Figure 12 is a schematic diagram of the user interface of an authentication method provided in this application.
  • Figure 12(a) shows a schematic diagram of a data sharing function setting page using near-field communication (NFC) technology, such as the "Huawei Share” function 1200 shown in Figure 12(a).
  • Figure 12(a) shows three options displayed on the current terminal, such as a second terminal's data sharing function setting page: "Visible to all (10 minutes)" option 1201, "Visible to contacts and shared devices" option 1202, and "Invisible” option 1203.
  • the "Invisible” option 1203 in Figure 12(a) is selected, the current second terminal cannot be discovered or searched by other nearby terminals, such as the first terminal. The first terminal cannot share data with the second terminal via NFC technology.
  • the first terminal is a device that has shared data with the second terminal, even if the first user associated with the first terminal is not a contact of the second user, the second terminal can be discovered by the first terminal when it is near the first terminal after the "Contacts and Shared Devices Visible" option 1202 is selected in Figure 12(a).
  • the second terminal can use the method provided in this application embodiment to authenticate with the first terminal.
  • the second terminal and the first terminal can perform an initial screening based on the contact database and/or historical sharing database to identify contacts and/or shared devices belonging to the second user, which are then displayed in the corresponding area of the second terminal.
  • the second terminal can display information about the second user's contacts, including the contact's user information.
  • user information may include profile picture, user ID, user name, etc.
  • the second terminal can also display information about shared devices.
  • device information may include device name, device model, device type, device image, etc.
  • information about the device associated with that contact can also be displayed, such as device name and device model.
  • information about the user associated with that shared device can also be displayed, such as username.
  • the embodiments of this application do not limit how the preliminary screening results (i.e., the second user's contacts and/or shared devices) are displayed, or the information contained in the preliminary screening results.
  • Figure 12(b) shows a schematic diagram of a page displaying information about contacts and devices obtained from the initial screening.
  • Figure 12(b) may display contacts and shared devices of a second user located near the current second terminal. For example, in display area 1204 of Figure 12(b), Contact 1, Contact 2, Device 1, and Device 2 are displayed. Contact 1 and Contact 2 are contacts of the second user associated with the second terminal, and Device 1 and Device 2 are devices that have shared data with the second terminal.
  • FIG12(c) is another schematic diagram of a page displaying the information of contacts and devices obtained through initial screening.
  • the second terminal can display them in different areas according to the contacts and shared devices. For example, as shown in FIG12(c), nearby contacts are displayed in the same area, such as contact 1 and contact 2 displayed in contact display area 1205; nearby shared devices are displayed in another area, such as device 1 and device 2 displayed in device display area 1206.
  • This application embodiment does not limit the display method of contacts and shared devices.
  • the second terminal may also contain information about other devices and/or non-contacts.
  • non-contacts refers to contacts who failed the initial screening
  • other devices refers to devices that failed the initial screening.
  • the contacts and/or devices displayed above can be obtained after initial screening according to the method provided in the embodiments of this application. Through initial screening, the terminal can quickly display possible nearby contacts and/or shared devices in the corresponding area, facilitating subsequent operations by the user.
  • the second terminal shown in FIG12 can be a receiving terminal. That is, the receiving second terminal can enable the "Huawei Share” function and set “Contacts and Shared Devices Visible” according to the requirements of relevant specifications. After the second terminal in FIG12 establishes a connection with other nearby contacts or devices and completes mutual authentication, the second terminal can receive data shared from other devices.
  • the second terminal in Figure 12 acts as the sending terminal. After enabling the "Huawei Share" function and setting "Contacts and Shared Devices Visible," the second terminal can connect with other nearby contacts or devices and complete mutual authentication. Thus, other authenticated contacts or devices can be displayed in the corresponding area of the second terminal. That is, other authenticated contacts or devices are also visible to the second terminal. In this way, the second terminal can act as the sending terminal to share data with other authenticated contacts or devices.
  • Figure 13 is a schematic flowchart of an identity authentication method provided in an embodiment of this application.
  • Figure 13 shows the specific process of mutual identity authentication between the first terminal 41 and the peripheral device 40.
  • the peripheral device 40 may include multiple terminals, such as the second terminal 42 in Figure 13.
  • the first terminal 41 may be a sending terminal
  • the second terminal 42 in the peripheral device 40 may be a receiving terminal.
  • the second terminal 42 is the device that, after authentication according to the method provided in this embodiment, can share data with the first terminal 41. That is, the first terminal 41 is the initiating device for data sharing, and the second terminal 42, after successful authentication, becomes the receiving device in data sharing.
  • the identity authentication process shown in Figure 13 may specifically include the following steps S401-S406:
  • the first terminal initiates a broadcast search.
  • the system login on the first terminal uses the account of the first user.
  • the system login on the first terminal uses the Huawei account of the first user.
  • the account used for system login can be referred to simply as an account.
  • the first terminal 41 can act as an initiating device to search for nearby contacts or other devices that can share data.
  • the first terminal 41 can initiate the search via broadcast.
  • the message broadcast by the first terminal 41 may include the first user's relationship chain identifier and the first terminal's device hash.
  • the first user's relationship chain identifier can be obtained by hashing the first user's account.
  • the first user's relationship chain identifier can be obtained by hashing the first user's account ID.
  • the first terminal's device hash can be obtained by hashing the first terminal 41's device identifier.
  • the first terminal's device hash can be obtained by hashing the first terminal's unique device identifier (UDID).
  • This embodiment does not limit the type of hash algorithm used for the hash operation.
  • the coverage area of the broadcast message sent by the first terminal 41 can be determined based on the hardware capabilities of the first terminal 41.
  • the number of terminals included in the peripheral device 40 may differ under different coverage areas. This embodiment does not limit this.
  • the first terminal receives a broadcast response from the peripheral device.
  • the peripheral device 40 near the first terminal 41 may be a terminal with the data sharing function enabled.
  • some or all of the terminals in the peripheral device 40 have enabled the "Huawei Share” function as shown in FIG12 and are set to "visible to contacts and shared devices".
  • the terminals in the peripheral device 40 When some or all of the terminals in the peripheral device 40 receive the broadcast message sent by the first terminal 41, they can reply to the broadcast message.
  • the second terminal 42 in the peripheral device 40 can reply to the broadcast message of the first terminal 41.
  • the second terminal 42 may reply to the first terminal 41 in the form of broadcast, that is, reply to the first terminal 41 with a message via broadcast.
  • the user of the second terminal 42 logs in to an account within the system of the second terminal 42.
  • the user of the second terminal 42 logs in to a Huawei account within the system of the second terminal 42.
  • the account logged into the system can be referred to as an account.
  • the broadcast reply sent by the second terminal 42 may carry the relationship chain identifier of the second user and the device hash of the second terminal.
  • the relationship chain identifier of the second user may be obtained by hashing the second user's account.
  • the device hash of the second terminal may be obtained by hashing the device identifier of the second terminal 42.
  • the second user of the second terminal can be a contact of the first user, and the user of the second terminal can also be a user who has logged into a device shared with the first terminal 41.
  • the second terminal 42 when the second terminal 42 is set to "visible to contacts and shared devices", after receiving a broadcast message sent by the first terminal 41, the second terminal 42 can match the broadcast message and perform a preliminary screening based on the broadcast message and the second terminal 42's contact database and/or historical sharing database to determine whether to send a broadcast reply to the first terminal 41. If it is determined to send a broadcast reply, a broadcast reply carrying the second user's relationship chain identifier and the second terminal's device hash is sent to the first terminal 41; otherwise, no broadcast reply is sent.
  • the first user is a contact of the second user. If so, a broadcast reply is sent to the first terminal 41, including the second user's relationship chain identifier and the device hash of the second terminal. If not, based on the device hash of the first terminal 41 and the historical sharing database of the second terminal 42, it is determined whether the first terminal 41 is a device that has shared data with the second terminal 42. If so, a broadcast reply is sent to the first terminal 41, including the second user's relationship chain identifier and the device hash of the second terminal. If not, no broadcast reply is given.
  • the second terminal can filter out the first terminal associated with the first user so that it can subsequently interact with the first terminal to exchange data.
  • the judgment is first based on the contact database, and then on the historical sharing database. In practical applications, the judgment can also be based first on the historical sharing database, and then on the contact database. This application does not limit the comparison.
  • the first terminal performs initial screening based on the broadcast response.
  • the first terminal 41 can perform a preliminary screening based on the broadcast reply sent by the peripheral device 40 to determine whether the peripheral device 40 includes devices associated with the contacts of the first user of the first terminal 41, and whether the devices have shared data with the first terminal 41.
  • the first terminal 41 performs initial screening based on broadcast replies. This can mean that the first terminal 41 processes and identifies broadcast replies received from other devices (such as the second terminal 42) to determine whether they meet the screening criteria.
  • the screening criteria include: the user associated with the other device is a contact of the first terminal 41, and/or the other device is a device that has shared data with the first terminal 41.
  • the first terminal 41 may include a local hash database, which includes a contact database and a historical sharing database.
  • the contact database may include information about each contact of the first user associated with the first terminal 41
  • the historical sharing database may include information about devices that have shared data with the first terminal.
  • the contact database may include relationship chain identifiers for each contact
  • the historical sharing database may include device hashes of devices that have shared data with the first terminal.
  • the contact database may also include information about the devices associated with each contact.
  • the historical sharing database may also include information about users associated with devices that have shared data.
  • the data in the contact database can be stored in tables, and the relationship chain identifiers of the contacts stored in the contact database are obtained by hashing the contact's account. Therefore, the contact database can also be described as a contact list, or a contact hash data table, etc.
  • the data in the historical sharing database can also be stored in tables, and the device hashes of the devices stored in the historical sharing database are obtained by hashing the device identifier. Therefore, the historical sharing database can also be described as a historical share list, a recent share list, or a historical share device hash data table, etc. This application does not impose any limitations on this.
  • the first terminal 41 can match the broadcast reply with the aforementioned local hash database to determine whether the filtering conditions are met.
  • the broadcast reply includes the second user's relationship chain identifier and/or the second terminal's device hash.
  • the first terminal 41 matches the second user's relationship chain identifier and/or the second terminal's device hash in its local hash database to determine whether the filtering conditions are met. If it is determined that the second user is a contact of the first user, and/or the second terminal 42 is a device that has shared data with the first terminal 41, then the filtering conditions are met.
  • the data shared between the second terminal 42 and the first terminal 41 includes data shared by the first terminal 41 to the second terminal 42, or data shared by the second terminal 42 to the first terminal 41.
  • the first terminal 41 performs preliminary screening, which can be based on the contact database and/or historical sharing database of the first terminal 41.
  • the first terminal 41 determines whether the second user is a contact of the first user based on the second user's relationship chain identifier in the reply broadcast and the first terminal 41's contact database. If the contact database includes the second user's relationship chain identifier, then the second user is determined to be a contact of the first user, satisfying the filtering condition. If the contact database does not include the second user's relationship chain identifier, then the first terminal 41 determines whether the second terminal 42 is a device that has shared data with the first terminal 41 based on the second terminal's device hash in the reply broadcast and the first terminal 41's historical sharing database.
  • the second terminal 42 is determined to be a device that has shared data with the first terminal 41, satisfying the filtering condition. Otherwise, it is determined that the second user is not a contact of the first user, and the second terminal 42 is a device that has shared data with the first terminal 41, not satisfying the filtering condition.
  • the first terminal 41 determines whether the second terminal 42 is a device that has shared data with the first terminal 41, based on the device hash of the second terminal in the reply broadcast and the first terminal 41's historical sharing database. If the historical sharing database includes the device hash of the second terminal, then the second terminal 42 is determined to be a device that has shared data with the first terminal 41, satisfying the filtering condition. Otherwise, the first terminal 41 determines whether the second user is a contact of the first user, based on the second user's relationship chain identifier in the reply broadcast and the first terminal 41's contact database. If the contact database includes the second user's relationship chain identifier, then the second user is determined to be a contact of the first user, satisfying the filtering condition. Otherwise, the second user is determined not to be a contact of the first user, and the second terminal 42 is a device that has shared data with the first terminal 41, not satisfying the filtering condition.
  • the first terminal 41 obtains information that meets the filtering conditions for subsequent display.
  • preprocessing is performed on the broadcast response, and the initial screening is based on the preprocessed data.
  • the preprocessing involves truncation. For example, if the broadcast response includes the relationship chain identifier of the second user and the device hash of the second device, the relationship chain identifier of the second user and the device hash of the second device are truncated respectively, and the initial screening is performed based on the truncated relationship chain identifier of the second user and the truncated device hash of the second device.
  • both the initial screening process performed by the first terminal 41 based on the broadcast message replied by the second terminal 42, and the initial screening process performed by the second terminal 42 based on the broadcast message initiated by the first terminal 41 can involve preprocessing the data in the broadcast before performing the initial screening.
  • Figure 14 illustrates a preliminary screening of contacts based on preprocessed data, as provided in this embodiment of the application.
  • the hash value 12345678 shown in Figure 14 can be the relationship chain identifier of the second user or the device hash of the second terminal.
  • N characters can be selected for truncation.
  • the first N characters can be selected for truncation; or the last N characters can be selected for truncation; or characters between the a-th and b-th characters can be extracted, etc.
  • N, a, and b are positive integers, and a ⁇ b.
  • selecting the first 4 characters for truncation results in a hash value of 1234.
  • the first terminal 41 can use the truncated hash value to match in its local hash database, and determine whether the screening conditions are met based on whether the local hash database contains the truncated hash value.
  • Figure 14 shows a hash value 12345115 in the local hash database.
  • This hash value could be the relationship chain identifier of a contact in the contact database of the first terminal 41, or the device hash of a device in the history sharing database.
  • the first terminal 41 can use the truncated hash value 1234 to match in the local hash database.
  • the truncated hash value of "hash value 12345115" in the contact database is also 1234. Therefore, it is determined that the truncated hash value 1234 can match the hash value 12345115 in the contact database, meaning that the hash value 12345115 contains a string identical to the truncated hash value. This indicates that the second user corresponding to the truncated hash value 1234 matches the contact database of the first terminal 41, and the second user is a contact of the first user.
  • the first terminal after receiving a broadcast reply from the second terminal, the first terminal truncates the data in the broadcast reply and performs initial screening based on the truncated data.
  • the terminal can first truncate the relationship chain identifier and/or device hash.
  • the broadcast can carry the truncated relationship chain identifier and/or device hash.
  • the peer device can then perform initial screening based on the truncated relationship chain identifier and/or device hash, which can speed up the processing.
  • the contact database in the terminal's local hash database may include the relationship chain identifiers of multiple contacts of the user associated with the terminal.
  • the terminal can determine the user's relationship chain identifier based on the system login account and obtain the relationship chain identifiers of the terminal user's contacts from the server. It is understood that the specific implementation method for the terminal to obtain the contact relationship chain identifiers is as described above, and the terminal can store the obtained contact relationship chain identifiers in the contact database of the local hash database.
  • the historical sharing database in the terminal's local hash database may include device hashes of multiple devices that have shared data with the terminal. After the terminal shares data with other devices, the terminal can interact with the device to obtain its device hash. Alternatively, the terminal can obtain the device identifier of the device and perform a hash operation on the device identifier to obtain the device hash. The terminal can store the device hashes of the devices that have shared data in the historical sharing database of the local hash database.
  • each device hash in the historical sharing database can have its own aging period (or can be described as a preset duration), and the aging periods for different device hashes are different.
  • the device hash is valid within its aging period.
  • the retention period of a device hash exceeds the aging period, the device hash becomes invalid.
  • the terminal can delete the invalid device hash.
  • the retention period is counted from the time the device hash is acquired.
  • the device hashes in the historical sharing database can have the same aging period.
  • the retention time of a certain device hash in the historical sharing database reaches the time corresponding to the aging period, that device hash can become invalid, while other device hashes that have not reached their aging period can remain valid.
  • the device hashes in the historical sharing database can also become invalid simultaneously.
  • the aging period can be the aging period of a historical sharing database. That is, when the generation time of the historical sharing database reaches the time corresponding to the aging period, the historical sharing database becomes invalid. Accordingly, all device hashes in the historical sharing database become invalid.
  • the first terminal displays a first interface, which includes information about contacts obtained from the initial screening and/or information about devices that have been shared.
  • the first terminal 41 can display the contact information and/or shared device information in the corresponding area of the first interface, as shown in (b) or (c) of Figure 12. In this way, the user can select to connect to a specific contact or device for data sharing.
  • the first terminal 41 can display the same avatar to indicate that multiple contacts are the same person.
  • an account can log in to multiple devices.
  • user A uses account A to log in to device a, device b, and device c.
  • the user associated with devices a, b, and c is user A, and each device generates the same relationship chain identifier based on account A, which is relationship chain identifier a.
  • Devices a, b, and c each generate device hashes based on their respective UDIDs: device a generates device hash a, device b generates device hash b, and device c generates device hash c. Therefore, the device hash corresponding to relationship chain identifier a includes device hash a, device hash b, and device hash c.
  • the relationship chain identifier can be used to determine whether contacts are the same; for the same contact, the same information can be used to represent that contact.
  • the first terminal authenticates the contacts and/or devices that have been shared by the initial screening.
  • the authentication of contact information and/or shared device information by the first terminal 41 can be performed after the initial screening is completed. After the initial screening is completed, the first terminal 41 can display the filtered contact information and/or shared device information on the first interface.
  • the initial screening process is not a rigorous authentication process. It matches information based on limited data and does not determine the security of the user's account, device, etc. For example, it doesn't verify whether the user's account was registered through official channels, or whether the account holder has the right to use the account. It also doesn't determine whether the device is a legitimate product. Therefore, the first terminal 41 needs to further authenticate the contact person or the device they shared with, to improve the accuracy and security of identity verification through this re-verification.
  • the first terminal authenticates the target object in response to a user's touch operation.
  • the target object may be contact information, or it may be information about a shared device.
  • the first terminal's response to the user's touch operation triggers a communication connection to the terminal corresponding to the target object, which can be understood as the first operation in the above embodiment.
  • the target object may include a second user's avatar.
  • the first device authenticates the second user in response to the user's touch operation on the second user's avatar.
  • the first terminal after receiving a broadcast response, the first terminal first performs an initial screening based on the broadcast response, then displays the initially screened data, and finally authenticates the initially screened data.
  • the first terminal may also, after receiving a broadcast, first perform an initial screening based on the broadcast data, then authenticate the initially screened data, and finally display the authenticated data.
  • the first terminal includes a first list and a second list.
  • the first list includes device identifiers of trusted devices, and the second list includes information about trusted accounts.
  • a trusted device is a device deemed secure by the platform or service provider, and a trusted account is an account deemed secure by the platform or service provider. Trusted devices and trusted accounts can be determined through identity authentication and trust assessment.
  • the first terminal interacts with the second terminal corresponding to the second user to obtain the device identifier of the second terminal and the account of the second user.
  • the second terminal is authenticated based on its device identifier and the first list. If the first list includes the device identifier of the second terminal, the first terminal authenticates the second user based on the obtained account of the second user and the second list.
  • a first authentication credential is obtained by hashing the account. If the first authentication credential matches the relationship chain identifier of the second user, the second user is confirmed to be authenticated. And/or, a second authentication credential is obtained by hashing the device identifier of the second terminal. If the first authentication credential matches the device hash of the second terminal, the second terminal is confirmed to be authenticated.
  • the above method is used to authenticate the contacts and/or shared devices obtained from the initial screening.
  • Figure 15 is a schematic flowchart of an account authentication method provided in an embodiment of this application.
  • Figure 15 shows the further authentication process between the first terminal 41 and the second terminal 42 after the initial screening of contacts is completed. After completing the authentication process shown in Figure 15, the first terminal 41 and the second terminal 42 can share data.
  • the first terminal 41 and the second terminal 42 need to inform each other of their own account IDs. Specifically, the first terminal 41 informs the second terminal 42 of its own account ID, and the second terminal 42 informs the first terminal 41 of its own account ID. To achieve this, before authentication, the first terminal 41 and the second terminal 42 need to obtain each other's account IDs to generate their respective second lists. Both the first terminal 41 and the second terminal 42 need to complete a series of identical operations. As shown in Figure 15, the first terminal 41 and the second terminal 42 first need to log in to their accounts and register credentials. Then, they exchange account IDs (which can also be described as user identification (UID)) and account device authentication credentials to authenticate the accounts. This determines whether the account ID is trustworthy.
  • account IDs which can also be described as user identification (UID)
  • the account ID is used to identify the user. Furthermore, the first terminal 41 and the second terminal 42 also need to negotiate using their own private keys and the other terminal's public keys. This process can be implemented based on the SPEKE protocol, a simple password exponential key exchange protocol. In this way, the first terminal 41 and the second terminal 42 can obtain the account ID of the other end and store it in their own second list for subsequent account authentication to verify the authenticity of the account ID.
  • the first terminal interacts with the second terminal to obtain the second user's account, and verifies the trustworthiness of the second user's account based on a second list and the second user's account. If the second user's account is included in the second list, the second terminal is deemed trustworthy.
  • the account ID logged in by the second terminal 42 can be a contact's mobile phone number.
  • the first terminal 41 and the second terminal 42 respectively inform the other end of their own account ID.
  • the first terminal 41 can query the trusted account IDs of the other end, as well as the account ID-contact mapping table, to confirm the contact corresponding to the mobile phone number logged in by the other end. Then, the first terminal 41 can specify an account ID and authenticate whether the other end device, i.e., the second terminal 42, belongs to that account ID. If the second terminal 42 belongs to the specified account ID, the second terminal is considered to have passed authentication, and the device belongs to that account.
  • the second terminal 42 can also query the trusted account IDs of the other end, as well as the account ID-contact mapping table, to confirm the contact corresponding to the mobile phone number logged in by the other end.
  • the second terminal 42 can authenticate whether the other end device, i.e., the first terminal 41, belongs to the trusted account list specified by the data sharing service. If the first terminal 41 belongs to the trusted account list specified by the data sharing service, it means that the first terminal 41 has passed authentication.
  • the second terminal 42 can query the trusted account list through a service registration callback.
  • the first terminal can obtain a first list from the server.
  • the server obtains device identifiers from multiple terminals, identifies trusted devices, and generates a first list.
  • the first terminal interacts with the server to obtain the first list.
  • the first terminal obtains the device identifier of a second terminal and authenticates the trustworthiness of the second terminal based on the first list and the device identifiers of the second terminal. If the first list includes the device identifier of the second terminal, the second terminal is determined to be trustworthy.
  • accounts and device identifiers can be linked to establish an association between accounts and devices for the purpose of authenticating accounts or devices.
  • the first interface of the first terminal 41 can be updated to display information about the contact who has been authenticated or information about the devices that have been shared.
  • the first terminal may share data with the terminal corresponding to the authenticated contact or the device that has been shared.
  • Figure 16 is a schematic flowchart of another contact authentication method provided in this application embodiment.
  • Figure 16 illustrates the different processing procedures for the sender and receiver during the contact authentication process when distinguishing between the sender and receiver.
  • the sender can be the first terminal 41 in the aforementioned embodiments
  • the receiver can be the second terminal 42 in the aforementioned embodiments.
  • the first terminal 41 which sends the message, can broadcast to search for devices of contacts or devices that have been shared in the vicinity.
  • the second terminal 42 can act as a receiver to reply to the broadcast initiated by the first terminal 41. Both can complete the authentication of the other device's account through the initial screening and authentication process described in the foregoing embodiments.
  • the visibility of the second terminal 42 in the above embodiment is "visible to contacts and devices that have shared with it".
  • the first terminal 41 of the sender and the second terminal 42 of the receiver can adopt different initial screening and authentication strategies for different scenarios.
  • Scenario 1 The sender has contacts and/or devices that have shared with the device, and the message is visible to all recipients.
  • the first terminal 41 stores information about contacts and/or information about devices that have been shared, while the second terminal 42, as the receiver, has enabled the "visible to all" option under the data sharing function. Therefore, the first terminal 41, as the sender, can discover or search for the second terminal 42 for a certain period of time after the second terminal 42 has enabled the "visible to all” option. For example, within 10 minutes.
  • the initial screening and authentication strategy for contacts is unidirectional. That is, the sending terminal 41 authenticates the receiving terminal 42 to determine if the second terminal 42 is trustworthy. If so, the first terminal 41 can display the information of the second terminal 42 or its second user. Otherwise, the first terminal may not display the information of the second terminal 42 or its second user.
  • Scenario 2 The sender has no contacts or devices that have been shared with, while the recipient's contacts and devices that have been shared with are visible.
  • the first terminal 41 does not have information about contacts or shared devices
  • the second terminal 42 has enabled the "visible only to contacts and shared devices" option under the data sharing function. Therefore, the first terminal 41, as the sender, can only discover or search for the second terminal 42 if the device belongs to a contact of the second user of the second terminal 42 or is a shared device.
  • the initial screening and authentication strategy for contacts is also one-way, that is, the second terminal 42 of the receiver authenticates the first terminal 41 of the sender to determine whether the first terminal 41 is the device of the second user's contact or a device that has been shared.
  • Scenario 3 The sender has contacts and/or devices that have been shared with the device, and the recipient's contacts and devices that have been shared with the device are visible to them.
  • the first terminal 41 stores information about contacts and/or information about devices that have been shared.
  • the second terminal 42 as the receiver, has enabled the "visible only to contacts and shared devices" option under the data sharing function. Therefore, the first terminal 41, as the sender, can only discover or search for the second terminal 42 if the device belongs to a contact of the second user of the second terminal 42 or is a device that has been shared.
  • the initial screening and authentication strategy for contacts can be bidirectional. That is, the sending terminal 41 authenticates the receiving terminal 42 to determine whether the second terminal 42 is trustworthy. At the same time, the receiving terminal 42 also authenticates the sending terminal 41 to determine whether the first terminal 41 is the device of the second user's contact or a device that has been shared.
  • Scenario 4 The sender has no contacts or devices that have shared with the device, and the message is visible to all recipients.
  • the first terminal 41 as the sender, has no contact or shared device information, while the second terminal 42, as the receiver, has enabled the "Visible to All" option under the data sharing function.
  • the first terminal 41 as the sender, can discover or search for the second terminal 42 for a certain period of time after the second terminal 42 has enabled the "Visible to All” option. For example, within 10 minutes.
  • the first terminal 41 and the second terminal 42 do not need to authenticate each other and can share data in the manner of existing technology.
  • Figure 17 illustrates another communication method provided by an embodiment of this application, which may include the following steps S1701-S1703:
  • the first terminal receives an operation to trigger the first terminal to search for the device.
  • the first terminal logs in to the account of the first user.
  • the first terminal stores the relationship chain identifier of the first user and the device hash of the first terminal.
  • the relationship chain identifier is generated based on the account of the user logged in to the system on the terminal, and the device hash is generated based on the device identifier of the terminal.
  • the first user's relationship chain identifier is obtained by hashing the account the first user logged into on the first terminal.
  • the first user's relationship chain identifier is obtained by hashing the first user's account ID.
  • the first terminal's hash value is obtained by hashing the first terminal's device identifier.
  • the first terminal's device hash is obtained by hashing the first terminal's unique device identifier (UDID).
  • the relationship chain identifier is used to identify users, eliminating the need for identifying users through private information such as phone numbers and email addresses, thus reducing the risk of user privacy information leakage.
  • the device hash is used to identify devices for quick device filtering.
  • the operation that triggers the first terminal to search for devices could be the user activating the "Huawei Share" function, and the first terminal responds to this operation by searching for nearby devices.
  • the first terminal may also send a second broadcast in response to triggering the first terminal to search for devices.
  • the second broadcast includes the relationship chain identifier of the first user and the device hash of the first terminal.
  • the first terminal acting as the initiating device, broadcasts a second message to search for nearby devices.
  • the number of nearby devices can be one or more, and the device types of these devices can be the same or different.
  • the device types of the nearby devices and the first terminal can also be the same or different.
  • the first terminal receives a first broadcast from the second terminal, the first broadcast including the relationship chain identifier of the second user of the second terminal and/or the device hash of the second terminal.
  • the second terminal is a terminal that has enabled the data sharing function and is set to be "visible to contacts and shared devices".
  • the second terminal since the second terminal is set to be visible to "contacts and shared devices," upon receiving a broadcast from another device, it needs to determine whether the device sending the broadcast meets the condition of being visible to "contacts and shared devices.” If it does, it replies to the broadcast to facilitate subsequent connection and data sharing; otherwise, it does not reply.
  • a second terminal is located near a first terminal.
  • the second terminal receives a second broadcast from the first terminal.
  • the second terminal determines whether the following conditions are met: the first user is a contact of the second terminal, and/or the first terminal is a device that has shared data with the second terminal. If either of these conditions is met, the second terminal generates a first broadcast and sends it to the first terminal.
  • the first broadcast includes the relationship chain identifier of the second user of the second terminal and/or the device hash of the second terminal.
  • the relationship chain identifier of the second user is obtained by hashing the account logged into by the second user on the second terminal.
  • the hash value of the second terminal is obtained by hashing the device identifier of the second terminal.
  • the implementation of the second terminal determining whether the first user is a contact of the second user, or whether the first terminal is a device that has shared data with the second terminal is the same as the implementation of the first terminal determining whether the second user is a contact of the first user, or whether the second terminal is a device that has shared data with the first terminal.
  • the specific implementation process please refer to the parts of S403 or S1703.
  • the first terminal displays the first interface;
  • the first condition includes determining that the second user is a contact of the first user based on the second user's relationship chain identifier, and/or determining that the second terminal is a device that the first terminal has shared data with based on the device hash of the second terminal;
  • the first interface includes a first object, the first object including the information of the second user, and/or the information of the second terminal.
  • the first terminal includes a contact database, which includes relationship chain identifiers corresponding to the contacts of the first user.
  • the method further includes: determining that the second user is a contact of the first user when the contact database includes at least a portion of the relationship chain identifier of the second user.
  • the first broadcast includes a relationship chain identifier for the second user.
  • the first terminal matches the second user's relationship chain identifier against the contact database, and if the contact database includes the second user's relationship chain identifier, determines that the second user is a contact of the first user.
  • the first broadcast includes a relationship chain identifier for the second user.
  • the first terminal truncates the second user's relationship chain identifier to obtain partial bytes. Based on these partial bytes, a match is made in the contact database. If the contact database includes these partial bytes, the second user is determined to be a contact of the first user.
  • the first broadcast includes partial bytes of the second user's relationship chain identifier. That is, the second terminal truncates the second user's relationship chain identifier, carrying only partial bytes of it in the first broadcast.
  • the first terminal matches it against its contact database based on the partial bytes of the second user's relationship chain identifier in the first broadcast. If the contact database includes the partial bytes of the second user's relationship chain identifier, the first terminal determines that the second user is a contact of the first user.
  • the first terminal includes a historical sharing database, which includes device hashes corresponding to devices that have shared data with the first terminal.
  • the method further includes: determining that the second terminal is a device that has shared data with the first terminal if the historical sharing database includes at least a portion of the device hash of the second terminal.
  • the first broadcast includes the device hash of the second terminal.
  • the first terminal matches the device hash of the second terminal in the historical sharing database, and if the historical sharing database includes the device hash of the second terminal, it determines that the second terminal is a device that has shared data with the first terminal.
  • the first broadcast includes the device hash of the second terminal.
  • the first terminal truncates the device hash of the second terminal, obtaining partial bytes of the device hash. These partial bytes are then matched against a historical sharing database. If the historical sharing database includes partial bytes of the second terminal's device hash, the second terminal is determined to be a device that has shared data with the first terminal.
  • the first broadcast includes a portion of the device hash of the second terminal. That is, the second terminal truncates its device hash, and when sending the first broadcast, it carries a portion of the device hash in the broadcast. Upon receiving the first broadcast, the first terminal matches the portion of the second terminal's device hash in the historical sharing database. If the historical sharing database includes a portion of the second terminal's device hash, the first terminal determines that it is a device that has shared data with the first terminal.
  • the storage time of the device hash of a device that has shared data with the first terminal exceeds a preset time, the device hash of the device that has shared data with the first terminal is deleted; the preset time is the storage time of the device hash of the device that has shared data with the first terminal in the preset historical sharing database.
  • the historical sharing database of the first terminal stores the device hashes of devices that have shared data with the first terminal. To ensure data real-time performance and accuracy, and to avoid information redundancy, only the device hashes of devices that have recently performed data analysis with the first terminal can be stored. Therefore, a preset duration can be set to save the device hashes of devices that have shared data with the first terminal according to the preset duration.
  • the preset duration is the aging period mentioned above.
  • each device hash in the historical sharing database can have its own preset duration, and the preset durations for different device hashes are different.
  • each device hash in the history sharing database can have the same preset duration, and the device hash is only valid within the preset duration.
  • the first broadcast includes a second user's relationship chain identifier and a second terminal's device hash.
  • the first terminal matches against the second user's relationship chain identifier in the contact database and against the second terminal's device hash in the historical sharing database. If the contact database includes the second user's relationship chain identifier, and/or the historical sharing database includes the second terminal's device hash, then a first condition is determined to be met.
  • the first broadcast includes a second user's relationship chain identifier and a second terminal's device hash.
  • the first terminal truncates the second user's relationship chain identifier and the second terminal's device hash to obtain partial bytes of the second user's relationship chain identifier and partial bytes of the second terminal's device hash, respectively.
  • Matching is performed in the contact database based on the partial bytes of the second user's relationship chain identifier, and in the historical sharing database based on the partial bytes of the second terminal's device hash. If the contact database includes partial bytes of the second user's relationship chain identifier, and/or the historical sharing database includes partial bytes of the second terminal's device hash, a first condition is determined to be satisfied.
  • the first broadcast includes partial bytes of the second user's relationship chain identifier and partial bytes of the second terminal's device hash. That is, the second terminal truncates the second user's relationship chain identifier and the second terminal's device hash, and when sending the first broadcast, the broadcast carries partial bytes of the second user's relationship chain identifier and partial bytes of the second terminal's device hash.
  • the first terminal matches the second user's relationship chain identifier in the contact database and the second terminal's device hash in the historical sharing database. If the contact database includes partial bytes of the second user's relationship chain identifier, and/or the historical sharing database includes partial bytes of the second terminal's device hash, then the first condition is satisfied.
  • the first terminal can quickly filter and determine whether the first condition is met based on the contact database and the historical sharing database, which helps to improve authentication efficiency.
  • the above example is a specific implementation of the first terminal performing initial screening based on the first broadcast reply from the second terminal.
  • the second user being a contact of the first user includes: the relationship chain identifier of the second user obtained by the first terminal is the same as the first authentication identifier determined by the first terminal, and the first authentication identifier is determined based on the account of the second user obtained by the first terminal.
  • a first interface is displayed, which includes a first object.
  • the first terminal responds to the user's first operation on the first object, the first terminal interacts with the second terminal to obtain the second user's account.
  • a first authentication identifier is obtained by performing a hash operation based on the second user's account. If the relationship chain identifier of the second user obtained by the first terminal matches the first authentication identifier determined by the first terminal, authentication is successful.
  • a connection is established with the second terminal corresponding to the second user to send data. That is, in this example, an initial screening is performed, and the results are displayed. Then, the object selected by the authenticated user is connected to the authenticated object.
  • the first terminal after the first terminal determines that the contact database includes the second user's relationship chain identifier, the first terminal interacts with the second terminal to obtain the second user's account. A hash operation is performed on the second user's account to obtain a first authentication identifier. If the relationship chain identifier of the second user obtained by the first terminal matches the first authentication identifier determined by the first terminal, authentication is confirmed successful, and a first interface is displayed.
  • the first interface includes a first object, which contains the information of the authenticated second user and/or the information of the second terminal. That is, in this example, an initial screening is performed first, then the initial screening results are authenticated, and the successful initial screening results are displayed.
  • the device for which the second terminal has shared data with the first terminal includes: the device hash of the second terminal obtained by the first terminal is the same as the second authentication identifier determined by the first terminal, and the second authentication identifier is determined based on the device identifier of the second terminal obtained by the first terminal.
  • a first interface is displayed, which includes a first object.
  • the first terminal interacts with the second terminal to obtain the device identifier of the second terminal.
  • a second authentication identifier is obtained by hashing the device identifier of the second terminal. If the device hash of the second terminal obtained by the first terminal matches the second authentication identifier determined by the first terminal, authentication is successful.
  • a connection is then established with the second terminal corresponding to the second user to send data.
  • the first terminal after the first terminal determines that the historical sharing database includes the device hash of the second terminal, the first terminal interacts with the second terminal to obtain the device identifier of the second terminal.
  • a second authentication identifier is obtained by hashing the device identifier of the second terminal. If the device hash of the second terminal obtained by the first terminal is the same as the second authentication identifier determined by the first terminal, authentication is successful, and a first interface is displayed.
  • the first interface includes a first object, which contains information about the authenticated second terminal and/or information about the second user.
  • first authentication identifier and the second authentication identifier can be complete data obtained after hash calculation, or they can be partial bytes obtained after hash calculation and truncation.
  • authentication ensures the legitimacy of devices and accounts, preventing fraudulent activities such as fake accounts, thereby improving security, enhancing data protection, and preventing information leakage. Furthermore, when a terminal contacts other terminals, the legitimacy of the peer can be verified, potentially enhancing the security of the communication process, increasing user trust in the communication, and improving the user experience.
  • the method further includes: receiving a second broadcast from a third terminal, the second broadcast including a second user relationship chain identifier of the third terminal and a device hash of the third terminal; displaying a second interface when a second condition is met, the second condition including determining that the second user is a contact of the first user based on the second user's relationship chain identifier, and/or determining that the third terminal is a device shared by the first terminal based on the device hash of the third terminal, the second interface including a first object and a second object, the second object including information of the second user, and/or information of the third terminal.
  • a user has multiple devices, such as a mobile phone and a tablet, and is logged into the same account, such as account 1.
  • the mobile phone and the platform enable data sharing and are set to "visible to contacts and shared devices," they receive a broadcast from the computer.
  • the mobile phone and the computer have recently shared data, and the computer and the tablet have also recently shared data with the mobile phone. Therefore, the mobile phone and the tablet respectively return broadcasts to the computer.
  • Broadcast 1 from the mobile phone carries a relationship chain identifier 1 generated based on account 1 and a device hash 1 generated from the mobile phone's device identifier.
  • Broadcast 2 from the tablet carries a relationship chain identifier 1 generated based on account 1 and a device hash 2 generated from the tablet's device identifier.
  • the computer determines that the mobile phone and the tablet are the most recently shared devices, and the relationship chain identifiers in the broadcasts sent by the mobile phone and the platform are the same, both being relationship chain identifier 1.
  • the computer displays the user information of the mobile phone user and the user information of the tablet user, the user information of the mobile phone user and the user information of the tablet user are the same. For example, the profile picture information of the mobile phone user and the user information of the tablet user are the same.
  • authentication can be performed based on the relationship chain identifier and device hash, without needing to use private information such as phone numbers or email addresses. This reduces the risk of user privacy information leakage and increases communication security and efficiency. Furthermore, authentication based on the relationship chain identifier and device hash simplifies the authentication process and improves authentication efficiency.
  • the electronic device includes hardware structures and/or software modules corresponding to the execution of each function.
  • the embodiments of this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by a computer driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the technical solutions of the embodiments of this application.
  • This application provides embodiments for dividing an electronic device into functional modules based on the above method examples.
  • each function can be divided into its own functional modules, or two or more functions can be integrated into a single processing unit.
  • the integrated unit can be implemented in hardware or as a software functional module. It should be noted that the unit division in this application embodiment is illustrative and represents only one logical functional division; in actual implementation, other division methods may be used.
  • FIG. 18 a structural block diagram of a communication device provided by an embodiment of this application is shown.
  • This device can be applied to the terminal in the aforementioned embodiments, such as the first terminal.
  • the device may specifically include the following modules: processing module 1801 and display module 1802.
  • the processing module 1801 is used to support the communication device in performing any of the processing functions in Figures 1 to 9 or Figures 11 to 17.
  • the display module 1802 is used to support the communication device in performing any of the display functions in Figures 1 to 9 or Figures 11 to 17.
  • the technical effects of the communication device shown in Figure 18 can be referred to the technical effects of the method described in the above method embodiments, and will not be repeated here.
  • the processing module 1801 involved in the communication device shown in Figure 18 can be implemented by a processor or processor-related circuit components, and can be a processor or processing module.
  • the display module 1802 can be implemented by display screen-related components.
  • the communication device may include at least one processor, which performs any of the processing functions described in the above embodiments.
  • the communication device may also include a communication interface for receiving and/or transmitting signals.
  • FIG 19 shows a schematic diagram of the structure of an electronic device provided in an embodiment of this application.
  • This electronic device 2200 can be used to implement the methods described in the above method embodiments. For example, it can execute the methods described in the various method embodiments of the first terminal. Or, it can execute the methods described in the various method embodiments of the server.
  • the electronic device 2200 may specifically include a processing unit 2201 and a display unit 2202.
  • the processing unit 2201 is used to support the electronic device 2200 in performing any of the processing functions in Figures 1 to 9 or Figures 11 to 17.
  • Display unit 2202 is optional and is used to support electronic device 2200 in performing the display function of any one of Figures 1 to 9 or Figures 11 to 17.
  • the electronic device 2200 shown in FIG19 may further include a communication unit (not shown in FIG19) for supporting the electronic device 2200 in performing the steps of communication between the electronic device and other electronic devices in the embodiments of this application.
  • a communication unit (not shown in FIG19) for supporting the electronic device 2200 in performing the steps of communication between the electronic device and other electronic devices in the embodiments of this application.
  • the electronic device 2200 shown in FIG19 may further include a storage unit 2203, which stores programs or instructions.
  • the processing unit 2201 executes the program or instructions, the electronic device 2200 shown in FIG19 can perform the method shown in the above-described method embodiment.
  • the technical effects of the electronic device 2200 shown in Figure 19 can be referred to the technical effects of the method shown in the above method embodiments, and will not be repeated here.
  • the processing unit 2201 involved in the electronic device 2200 shown in Figure 19 can be implemented by a processor or processor-related circuit components, and can be a processor or processing module.
  • the communication unit can be implemented by a transceiver or transceiver-related circuit components, and can be a transceiver or transceiver module.
  • the display unit 2202 can be implemented by display screen-related components.
  • This application also provides a chip system, as shown in FIG20, which includes at least one processor 2301 and at least one interface circuit 2302.
  • the processor 2301 and the interface circuit 2302 can be interconnected via lines.
  • the interface circuit 2302 can be used to receive signals from other devices.
  • the interface circuit 2302 can be used to send signals to other devices (e.g., the processor 2301).
  • the interface circuit 2302 can read instructions stored in a memory and send the instructions to the processor 2301.
  • the electronic device can perform the various steps performed by the electronic device in the above embodiments.
  • the chip system may also include other discrete devices, which are not specifically limited in this application.
  • the chip system may contain one or more processors.
  • processors can be implemented in hardware or software.
  • the processor can be a logic circuit, an integrated circuit, etc.
  • the processor can be a general-purpose processor, implemented by reading software code stored in memory.
  • the chip system may contain one or more memories.
  • the memory may be integrated with the processor or disposed separately from it; this application does not limit this.
  • the memory may be a non-transient processor, such as a read-only memory (ROM), which may be integrated with the processor on the same chip or disposed separately on different chips.
  • ROM read-only memory
  • This application does not specifically limit the type of memory or the arrangement of the memory and processor.
  • the chip system may be a field-programmable gate array (FPGA), an application-specific integrated circuit (ASIC), a system-on-chip (SoC), a central processor (CPU), a network processor (NP), a digital signal processor (DSP), a microcontroller unit (MCU), a programmable logic device (PLD), or other integrated chips.
  • FPGA field-programmable gate array
  • ASIC application-specific integrated circuit
  • SoC system-on-chip
  • CPU central processor
  • NP network processor
  • DSP digital signal processor
  • MCU microcontroller unit
  • PLD programmable logic device
  • each step in the above method embodiments can be completed by integrated logic circuits in the processor hardware or by instructions in software form.
  • the method steps disclosed in the embodiments of this application can be directly manifested as being executed by a hardware processor, or being executed by a combination of hardware and software modules in the processor.
  • This application also provides a computer storage medium storing computer instructions, which, when executed on an electronic device, cause the electronic device to perform the methods described in the above-described method embodiments.
  • This application provides a computer program product, which includes a computer program or instructions that, when run on a computer, cause the computer to perform the methods described in the above-described method embodiments.
  • this application also provides an apparatus, which may specifically be a chip, component or module.
  • the apparatus may include a connected processor and a memory.
  • the memory is used to store computer execution instructions.
  • the processor can execute the computer execution instructions stored in the memory to cause the apparatus to perform the methods in the above-described method embodiments.
  • the electronic device, computer storage medium, computer program product or chip are all used to execute the corresponding method provided above. Therefore, the beneficial effects that can be achieved can be referred to the beneficial effects of the corresponding method provided above, and will not be repeated here.
  • a component shown as a unit can be one or more physical units; that is, it can be located in one place or distributed in multiple different locations. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
  • the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
  • the integrated unit can be implemented in hardware or as a software functional unit.
  • the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium.
  • This software product is stored in a storage medium and includes several instructions to cause a device (which may be a microcontroller, chip, etc.) or processor to execute all or part of the steps of the methods of the various embodiments of this application.
  • the aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Telephonic Communication Services (AREA)

Abstract

一种通信方法及装置,涉及通信技术领域,能够减少了用户的隐私信息泄露的风险。该方法可应用于第一终端,第一终端的系统登录第一用户的账号,第一终端存储有第一用户的关系链标识,和第二用户的关系链标识,第二用户是第一用户的联系人,关系链标识基于终端的系统登录的用户的账号生成;该方法可包括:接收向第二用户发起通信连接的第一操作;响应于第一操作,基于第二用户的关系链标识获取第二用户的第二终端的通信标识;基于通信标识,向第二用户的第二终端发送通信连接请求。如此,第一终端在与第二终端通信时,可以基于联系人的关系链标识,查询第二用户的第二终端的通信标识,减少了用户的隐私信息泄露的风险。

Description

一种通信方法及装置
本申请要求于2024年6月20日提交国家知识产权局、申请号为202410808178.2、申请名称为“一种关系链构建方法及装置”的中国专利申请的优先权,以及要求于2024年6月20日提交国家知识产权局、申请号为202410808194.1、申请名称为“联系人认证方法、装置和电子设备”的中国专利申请的优先权,以及要求于2024年8月12日提交国家知识产权局、申请号为202411109200.0、申请名称为“一种通信方法及装置”的中国专利申请的优先权,以及要求于2024年10月25日提交国家知识产权局、申请号为202411507240.0、申请名称为“一种通信方法及装置”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本申请涉及通信技术领域,尤其涉及一种通信方法及装置。
背景技术
用户使用终端中的某一个软件时,终端可以通过获取用户的身份信息,得到该用户的身份信息关联的联系人,从而与该联系人的终端通信。相关技术中,通过获取用户的手机号码、邮箱等识别该用户的身份信息,存在用户的个人信息泄露的风险。
发明内容
本申请提供一种通信方法及装置,可以减少个人信息泄露的风险。
为了实现上述目的,本申请实施例提供了以下技术方案:
第一方面,提供一种通信方法,该方法可应用于第一终端,所述第一终端的系统登录第一用户的账号,所述第一终端存储有所述第一用户的关系链标识,和第二用户的关系链标识,所述第二用户是所述第一用户的联系人,所述关系链标识基于终端的系统登录的用户的账号生成;该方法可包括:接收向所述第二用户发起通信连接的第一操作;响应于所述第一操作,基于所述第二用户的关系链标识获取所述第二用户的第二终端的通信标识;基于所述通信标识,向所述第二用户的第二终端发送通信连接请求。
采用该方法,第一终端在与第二终端通信时,可以基于联系人的关系链标识,查询第二用户的第二终端的通信标识,而不需要通过手机号、邮箱号等隐私信息查找第二终端中的用户,从而减少了用户的隐私信息泄露的风险。
示例性的,第一终端可存储第二用户的关系链标识和第二用户的第二终端的通信标识的关联关系。另一些实施例中,第一终端还可向服务器查询第二用户的通信标识,并直接使用该通信标识向第二终端发起通信连接。另一些实施例中,第一终端还可通过服务器建立与第二终端之间的通信连接。比如,作为一种可能的实现方式,第一终端向服务器发送第二用户的关系链标识,服务器据此确定第二用户的通信标识。之后,服务器根据第二用户的通信标识,建立第一终端与第二终端之间的通信连接。该方法可独立于第一方面单独实施。
在一种可能的设计中,所述方法还包括第一终端从服务器获取联系人的关系链标识的过程,该过程可称为下载关系链标识的过程。示例性的,第一终端下载关系链标识,可以实现为:向服务器发送所述第一用户的至少一个联系人的联系方式;接收所述服务器发送的所述第一用户的至少一个联系人的关系链标识。所述至少一个联系人包括第二用户。终端可存储第二用户的关系链标识。
其中,服务器可能返回全部或部分联系人的关系链标识。例如,部分联系人无华为账号,则服务器不返回该部分联系人的关系链标识。在一种可能的设计中,所述方法还包括第一终端向服务器的注册过程。作为一种可能的实现方式,该注册过程可包括:第一终端向服务器发送所述第一用户的联系方式和所述第一用户的关系链标识。
采用该方法,各终端可上传各自用户的联系方式和各自用户的关系链标识,以便终端可从服务器下载对应联系人的关系链标识。如前文所描述,终端使用联系人的关系链标识可降低安全隐患。
上述以终端生成该终端用户的关系链标识,终端上报该终端用户的联系方式和该终端用户的关系链标识为例,另一些实施例中,终端可上报该终端用户的账号(如华为账号),由服务器生成该终端用户的关系链标识,还向该终端返回该终端用户的关系链标识。
此外,本申请实施例中,终端上应用可共享系统级的关系链标识,维护成本低。使用关系链标识的应用例如畅连应用、近场分享应用,需要识别联系人身份时,通过查询系统级的联系人数据库,就可以及时地知道对方是否属于本机好友。
在一种可能的设计中,该方法还可包括:接收所述服务器发送的所述至少一个联系人的通信标识。第一终端可存储所述至少一个联系人的关系链标识和通信标识之间的关联关系。
在一种可能的设计中,所述方法还包括:接收修改所述第一用户的联系方式的第二操作;响应于所述第二操作,向服务器发送修改的所述第一用户的联系方式。
采用该方法,服务器可获知终端所述第一用户的联系方式已被修改,服务器可据此修改第一用户的联系方式和所述第一用户的关系链标识的关联关系,以便后续第一用户的联系人终端能够下载修改后的第一用户的关系链标识。
在一种可能的设计中,所述方法还包括:接收添加第三用户为联系人的第三操作;响应于所述第三操作,向服务器发送所述第三用户的联系方式;接收并存储所述服务器发送的所述第三用户的关系链标识。
采用该方法,第一终端添加第三用户为联系人后,可从服务器获取第三用户的关系链标识,以便后续基于该关系链标识查询第三用户的通信标识,提升信息安全性。
在一种可能的设计中,所述方法还包括:接收并存储所述服务器发送的所述第三用户的通信标识。
在一种可能的设计中,所述方法还包括:接收删除第四用户为联系人的第四操作;响应于所述第四操作,删除存储的所述第四用户的关系链标识。
在一种可能的设计中,所述方法还包括:响应于所述第四操作,删除所述第四用户的通信标识。
在一种可能的设计中,所述方法还包括:响应于所述第四操作,向所述服务器发送所述第四用户的联系方式。
在一种可能的设计中,所述第一终端还存储有第五用户的联系方式和所述第五用户的关系链标识,所述第五用户是所述第一用户的联系人;所述方法还包括:接收将所述第五用户的联系方式由第一联系方式更新为第二联系方式的第五操作;响应于所述第五操作,将与所述第五用户的关系链标识的对应的联系方式由所述第一联系方式更新为所述第二联系方式。
采用该方法,在联系人(第五用户)的联系方式更新的场景中,第一终端可以快速知悉,并可以及时更新第五用户的关系链标识与联系方式的关联关系。
在一种可能的设计中,所述方法还包括:响应于所述第五操作,向所述服务器发送所述第五用户的所述第一联系方式和所述第二联系方式。
在一种可能的设计中,所述第一终端还存储有所述第一用户的至少一个联系人的联系方式,所述联系人的联系方式与所述联系人的关系链标识一一对应;所述方法还包括:接收服务器发送的通知消息,述通知消息用于通知所述第一终端修改存储的联系方式与关系链标识的关联关系;其中,所述修改存储的联系方式与关系链标识的关联关系包括以下一个或多个:
删除所述第一用户的至少一个联系人中第六用户的联系方式与关系链标识的关联关系;
更新所述第一用户的至少一个联系人中第七用户的关系链标识对应的联系方式;
增加第八用户的联系方式与关系链标识的关联关系。
采用该方法,第一终端可根据来自服务器的通知消息,修改存储的联系方式与关系链标识的关联关系。
一些示例中,若某个终端(如第五终端)与第一终端登录相同的账号,且第五终端开启了云同步功能,则服务器向第一终端和第五终端均发送通知消息,以便同步第一终端和第五终端中存储的联系方式与关系链标识的关联关系。
另一些示例中,若与第一终端登录相同账号的第五终端,未开启云同步功能,则第一终端的联系方式与关系链标识的关联关系发生变化时,服务器不向第五终端发送通知消息。
在一种可能的设计中,所述通信连接请求用于发起音视频通信;所述第一终端还存储有所述第一用户的至少一个联系人的能力信息,所述联系人的能力信息与所述联系人的关系链标识一一对应,所述能力信息用于指示对应联系人是否具备音视频通信能力;所述第二用户的所述能力信息用于指示所述第二用户具备音视频通信能力。
采用该方法,第一终端可根据联系人的能力信息,获知联系人是否具备音视频通信能力。当联系人具备音视频通信能力,第一终端可使用联系人的关系链标识,向联系人的终端发起音视频通信连接,以降低信息传输过程的安全隐患。
在一种可能的设计中,所述方法还包括:向服务器发送所述第一用户的所述能力信息。
采用该方法,服务器可确定各用户的账号级别的能力信息。后续,可以根据相应用户的能力信息,对相应通信的过程进行控制,以提升通信的安全性。
在一种可能的设计中,所述方法还包括:接收服务器发送的通知消息,该通知消息用于通知所述第一终端修改存储的通信标识与关系链标识的关联关系。例如,新增登录账号A的设备A之后,终端可新增关系链标识与该设备A的通信标识的关联关系。
在一种可能的设计中,所述联系方式包括以下一个或多个:电话号码、传真号码或电子邮箱。
第二方面,提供一种通信方法,可应用于服务器,该方法可包括:接收来自第一终端的第一用户的至少一个联系人的联系方式;向所述第一终端发送所述第一用户的至少一个联系人的关系链标识。
在一种可能的设计中,该方法还可包括:向所述第一终端发送所述至少一个联系人的通信标识。
在一种可能的设计中,所述至少一个联系人包括第二用户;在向所述第一终端发送所述第一用户的至少一个联系人的关系链标识之前,所述方法还包括:接收所述第二用户的第二终端发送的所述第二用户的联系方式和所述第二用户的关系链标识。
在一种可能的设计中,所述方法还包括:向所述第一终端发送所述第一用户的至少一个联系人的能力信息,所述能力信息用于指示对应联系人是否具备音视频通信能力。
在一种可能的设计中,所述方法还包括:接收所述第一终端发送的修改的所述第一用户的联系方式;所述修改包括以下一个或多个,添加联系方式,将删除联系方式,更新联系方式;向第三终端发送第一通知消息,所述第一通知消息用于通知所述第三终端修改所述第一用户的联系方式和所述第一用户的关系链标识的关联关系;所述第三终端的用户的联系人的联系方式包括添加的所述第一用户的联系方式。
在一种可能的设计中,所述方法还包括:向第三终端发送通知消息,该通知消息用于通知所述第三终端修改所述第一用户的通信标识和所述第一用户的关系链标识的关联关系。
在一种可能的设计中,所述方法还包括:接收来自所述第一终端的修改的第三用户的联系方式;所述修改包括以下一个或多个,添加所述第三用户为联系人,将从联系人中删除所述第三用户,更新所述第三用户的联系方式;
向第四终端发送第二通知消息,所述第二通知消息用于通知所述第四终端修改存储的联系方式与关系链标识的关联关系,所述第四终端登录的账号与所述第一终端登录的账号相同。
在一种可能的设计中,所述服务器存储有所述第一终端的所述第一用户的至少一个联系人的联系方式和所述第一用户的关系链标识的关联关系;
在所述接收来自所述第一终端的修改的第三用户的联系方式之后,所述方法还包括:
基于修改的所述第三用户的联系方式,修改存储的所述关联关系。
在一种可能的设计中,所述方法还包括:修改存储的通信标识与关系链标识之间的关联关系。
在一些实施例中,本申请实施例提供的通信方法可应用于身份认证场景,下面通过第三方面所述的方法,对终端基于关系链标识进行身份认证的具体实现过程进行介绍。
第三方面,提供一种通信方法,应用于第一终端,第一终端的系统登录第一用户的账号,第一终端存储有第一用户的关系链标识和第一终端的设备哈希,关系链标识基于终端的系统登录的用户的账号生成,设备哈希基于终端的设备标识生成;该方法包括:接收用于触发第一终端搜索设备的操作;接收来自第二终端的第一广播,第一广播包括第二终端的第二用户的关系链标识和/或第二终端的设备哈希;在满足第一条件的情况下,显示第一界面;第一条件包括根据第二用户的关系链标识确定第二用户为第一用户的联系人,和/或,根据第二终端的设备哈希确定第二终端为第一终端分享过数据的设备;第一界面包括第一对象,第一对象包括第二用户的信息,和/或,第二终端的信息。
采用该方法,第一终端在与第二终端通信时,可以基于关系链标识和设备哈希进行身份认证,而不需要通过手机号、邮箱号等隐私信息进行身份认证,减少了用户的隐私信息泄露的风险,增加了通信的安全性和效率。而且,基于关系链标识和设备哈希进行身份认证,简化了身份认证的操作流程,提高了身份认证的效率。
其中,第一用户的关系链标识基于第一用户在第一终端的系统登录的账号进行哈希运算得到。第一终端的哈希值基于第一终端的设备标识进行哈希运算得到。
采用该方法,关系链标识用于标识用户,不需要通过手机号、邮箱号等隐私信息标识用户,减少了用户隐私信息泄露的风险。设备哈希用于标识设备,以便快速筛选设备。
其中,第二终端为启动数据分享功能,且被设置为“联系人和分享过的设备可见”的终端。第二用户的关系链标识基于第二用户在第二终端的系统登录的账号进行哈希运算得到。第二终端的哈希值基于第二终端的设备标识进行哈希运算得到。
在一种可能的设计中,第一终端包括联系人数据库,联系人数据库包括第一用户的联系人对应的关系链标识,该方法还包括:在联系人数据库包括至少第二用户的关系链标识的部分字节情况下,确定第二用户为第一用户的联系人。
在一些示例中,第一广播中包括第二用户的关系链标识。第一终端根据该第二用户的关系链标识在联系人数据库中进行匹配,在联系人数据库包括第二用户的关系链标识的情况下,确定第二用户为第一用户的联系人。
在另一些示例中,第一广播中包括第二用户的关系链标识。第一终端对第二用户的关系链标识进行截断处理,得到第二用户的关系链标识的部分字节。根据第二用户的关系链标识的部分字节在联系人数据库中进行匹配,在联系人数据库包括第二用户的关系链标识的部分字节的情况下,确定第二用户为第一用户的联系人。
在另一些示例中,第一广播中包括第二用户的关系链标识的部分字节。也即,第二终端对第二用户的关系链标识进行截断处理,在发送第一广播时,广播中携带第二用户的关系链标识的部分字节。第一终端在接收到第一广播后,根据第一广播中的第二用户的关系链标识的部分字节,在联系人数据库中进行匹配,在联系人数据库包括第二用户的关系链标识的部分字节的情况下,确定第二用户为第一用户的联系人。
在一种可能的设计中,第一终端包括历史分享数据库,历史分享数据库包括与第一终端分享过数据的设备对应的设备哈希,该方法还包括:在历史分享数据库包括至少第二终端的设备哈希的部分字节情况下,确定第二终端为与第一终端分享过数据的设备。
在一些示例中,第一广播中包括第二终端的设备哈希。第一终端根据该第二终端的设备哈希在历史分享数据库中进行匹配,在历史分享数据库包括第二终端的设备哈希的情况下,确定第二终端为与第一终端分享过数据的设备。
在另一些示例中,第一广播中包括第二终端的设备哈希。第一终端对第二终端的设备哈希进行截断处理,得到第二终端的设备哈希的部分字节。根据第二终端的设备哈希的部分字节在历史分享数据库中进行匹配,在历史分享数据库包括第二终端的设备哈希的部分字节的情况下,确定第二终端为与第一终端分享过数据的设备。
在另一些示例中,第一广播中包括第二终端的设备哈希的部分字节。也即,第二终端对第二终端的设备哈希进行截断处理,在发送第一广播时,广播中携带第二终端的设备哈希的部分字节。第一终端在接收到第一广播后,根据第一广播中的第二终端的设备哈希的部分字节,在历史分享数据库中进行匹配,在历史分享数据库包括第二终端的设备哈希的部分字节的情况下,确定第二终端为与第一终端分享过数据的设备。
采用该方法,第一终端基于联系人数据库和历史分享数据库可以快速筛选,快速确定是否满足第一条件,提升了响应速度,有助于提高认证效率。
在一种可能的设计中,第二用户为第一用户的联系人包括:第一终端获取到的第二用户的关系链标识与第一终端确定的第一认证标识相同,第一认证标识基于第一终端获取到的第二用户的账号确定。
在一些示例中,在第一终端确定联系人数据库包括第二用户的关系链标识之后,显示第一界面,第一界面中包括第一对象。第一终端响应于用户对第一对象的第一操作,与第二终端交互,获取第二用户的账号。根据第二用户的账号进行哈希运算得到第一认证标识,在第一终端获取到的第二用户的关系链标识与第一终端确定的第一认证标识相同的情况下,确定认证通过。与第二用户对应的第二终端建立连接,以发送数据。也即,在该示例中,先进行初筛,显示初筛结果。然后认证用户选定的对象,与认证通过的对象建立连接。
在另一些示例中,在第一终端确定联系人数据库包括第二用户的关系链标识之后,第一终端与第二终端交互,获取第二用户的账号。根据第二用户的账号进行哈希运算得到第一认证标识,在第一终端获取到的第二用户的关系链标识与第一终端确定的第一认证标识相同的情况下,确定认证通过,显示第一界面。第一界面中包括第一对象,第一对象为认证通过后的第二用户的信息,和/或,第二终端的信息。也即,在该示例中,先进行初筛,再对初筛结果进行认证,显示认证通过的初筛结果。
在一种可能的设计中,第二终端为第一终端分享过数据的设备包括:第一终端获取到的第二终端的设备哈希与第一终端确定的第二认证标识相同,第二认证标识基于第一终端获取到的第二终端的设备标识确定。
在一些示例中,在第一终端确定历史分享数据库包括第二终端的设备哈希之后,显示第一界面,第一界面中包括第一对象。第一终端响应于用户对第一对象的第一操作,与第二终端交互,获取第二终端的设备标识。根据第二终端的设备标识进行哈希运算得到第二认证标识,在第一终端获取到的第二终端的设备哈希与第一终端确定的第二认证标识相同的情况下,确定认证通过。与第二用户对应的第二终端建立连接,以发送数据。
在另一些示例中,在第一终端确定历史分享数据库包括第二终端的设备哈希之后,第一终端与第二终端交互,获取第二终端的设备标识。根据第二终端的设备标识进行哈希运算得到第二认证标识,在第一终端获取到的第二终端的设备哈希与第一终端确定的第二认证标识相同的情况下,确定认证通过,显示第一界面。第一界面中包括第一对象,第一对象为认证通过后的第二终端的信息,和/或,第二用户的信息。
其中,第一认证标识和第二认证标识为进行哈希计算后得到的完整的数据,或者,第一认证标识和第二认证标识为先进行哈希运算,再进行截断处理后得到的部分字节。
采用该方法,通过认证确保设备、账号的合法性,防止虚假账号等行为,可以提高安全性,增强数据保护,防止信息泄露。而且,终端联系其他终端时,可以验证对端的合法性,可能增强通信过程的安全性,增强用户对通信的信任度,提升用户体验。
在一种可能的设计中,该方法还包括:接收来自第三终端的第二广播,第二广播包括第三终端的第二用户关系链标识和第三终端的设备哈希;在满足第二条件的情况下,显示第二界面,第二条件包括根据第二用户的关系链标识确定第二用户为第一用户的联系人,和/或,根据第三终端的设备哈希确定第三终端为第一终端分享过的设备,第二界面包括第一对象和第二对象,第二对象包括第二用户的信息,和/或,第三终端的信息。
采用该方法,相同联系人显示用户的信息时显示同一信息,为同一联系人提供一致的视觉识别,方便用户快速、直观地识别和分类联系人,避免混淆,提升了用户体验。
在一种可能的设计中,该方法还包括:在与所述第一终端分享过数据的设备的设备哈希的保存时长超过预设时长的情况下,删除与第一终端分享过数据的设备的设备哈希;预设时长为预设的历史分享数据库中与第一终端分享过数据的设备的设备哈希的保存时长。
在一些示例中,历史分享数据库中的每一设备哈希可以具有各自的预设时长,不同的设备哈希的预设时长不同。
在另一些示例中,历史分享数据库中的每一设备哈希可以具有相同的预设时长,设备哈希仅在预设时长内有效。
采用该方法,可以保证历史分享数据库中设备哈希的实时性,避免信息冗余,提升认证效率。
第四方面,提供一种电子设备,该电子设备具有实现如上述任意方面及其中任一设计所述的方法的功能。该功能可以通过硬件实现,也可以通过硬件执行相应的软件实现。该硬件或软件包括一个或多个与上述功能相对应的模块。
第五方面,提供一种电子设备,包括:处理器和存储器,所述存储器与所述处理器耦合,所述存储器用于存储程序代码,所述程序代码包括指令,所述处理器从所述存储器中读取所述指令,以使得所述电子设备执行如上述任意方面及其中任一设计所述的方法。
第六方面,一种计算机可读存储介质,所述计算机可读存储介质包括计算机程序,当所述计算机程序在电子设备上运行时,使得所述电子设备执行如上述任意方面及其中任一设计所述的方法。
第七方面,提供一种计算机程序产品,所述计算机程序产品包括:计算机程序或指令,当所述计算机程序或指令在计算机上运行时,使得所述计算机执行如上述任意方面及其中任一设计所述的方法。
第八方面,提供一种通信系统,包括第一终端以及服务器,所述第一终端用于执行如上述第一方面及其中任一设计所述的方法,所述服务器用于执行如上述第二方面及其中任一设计所述的方法。
第九方面,本申请提供一种芯片系统,包括至少一个处理器和至少一个接口电路,至少一个接口电路用于执行收发功能,并将指令发送给至少一个处理器,当至少一个处理器执行指令时,至少一个处理器执行如上述任意方面及其中任一设计所述的方法。
第十方面,本申请技术方案提供一种通信装置,包括:处理器,被配置为用于执行上述任意方面及其中任一种实现方式中的方法。
可选的,装置还包括存储器和/或通信接口。
通信接口用于接收和/或发送信号。可选的,通信接口与处理器耦合。
存储器用于存储计算机程序,处理器,被配置为用于执行上述第一方面及其中任一种实现方式中所述的方法,可实现为:用于执行存储器中存储的计算机程序,以执行上述第一方面及其中任一种实现方式中所述的方法。
或者,处理器也可以是硬件实现的电路,如人工智能(artificial intelligence,AI)处理器,以提升运行速度。本申请不限制处理器具体的实现方式。
可选的,通信装置可以为整机设备,或设备中的模块,如芯片。
需要说明的是,上述第二方面至第十方面中任一设计所带来的技术效果可以参见第一方面中对应设计所带来的技术效果,此处不再赘述。
附图说明
图1、图2为本申请实施例提供的架构示意图;
图3A为本申请实施例提供的关系网络的示意图;
图3B为本申请实施例提供的通信标识与账号的关联关系的示意图;
图4为本申请实施例提供的一种电子设备的结构示意图;
图5为本申请实施例提供的一种电子设备的另一种结构示意图;
图6为本申请实施例提供的方法的流程示意图一;
图7为本申请实施例提供的业务场景的示意图一;
图8A为本申请实施例提供的业务场景的示意图二;
图8B为本申请实施例提供的方法的流程示意图二;
图9为本申请实施例提供的修改关系链标识与联系方式的关联关系的场景示意图;
图10为本申请实施例提供的方法的流程示意图三;
图11为本申请实施例提供的相关规范对电子设备可见性要求的示意图;
图12为本申请实施例提供的一种联系人认证方法的用户操作界面的示意图;
图13为本申请实施例提供的身份认证方法流程示意图一;
图14为本申请实施例提供的一种根据截断后的哈希值进行初筛的示意图;
图15为本申请实施例提供的身份认证方法流程示意图二;
图16为本申请实施例提供的身份认证方法流程示意图三;
图17为本申请实施例提供的通信方法流程示意图;
图18为本申请实施例提供的一种通信装置的示意图;
图19为本申请实施例提供的一种电子设备的结构示意图;
图20为本申请实施例提供的芯片系统的结构示意图。
具体实施方式
下面结合本申请实施例中的附图,对本申请实施例中的技术方案进行描述。其中,在本申请实施例的描述中,以下实施例中所使用的术语只是为了描述特定实施例的目的,而并非旨在作为对本申请的限制。如在本申请的说明书和所附权利要求书中所使用的那样,单数表达形式“一个”、“一种”、“所述”、“上述”、“该”和“这一”旨在包括例如“一个或多个”这种表达形式,除非其上下文中明确地有相反指示。还应当理解,在本申请以下各实施例中,“至少一个”、“一个或多个”是指一个或两个以上(包含两个)。
在本说明书中描述的参考“一个实施例”或“一些实施例”等意味着在本申请的一个或多个实施例中包括结合该实施例描述的特定特征、结构或特点。由此,在本说明书中的不同之处出现的语句“在一个实施例中”、“在一些实施例中”、“在其他一些实施例中”、“在另外一些实施例中”等不是必然都参考相同的实施例,而是意味着“一个或多个但不是所有的实施例”,除非是以其他方式另外特别强调。术语“包括”、“包含”、“具有”及它们的变形都意味着“包括但不限于”,除非是以其他方式另外特别强调。术语“连接”包括直接连接和间接连接,除非另外说明。“第一”、“第二”仅用于描述目的,而不能理解为指示或暗示相对重要性或者隐含指明所指示的技术特征的数量。
在本申请实施例中,“示例性地”或者“例如”等词用于表示作例子、例证或说明。本申请实施例中被描述为“示例性地”或者“例如”的任何实施例或设计方案不应被解释为比其它实施例或设计方案更优选或更具优势。确切而言,使用“示例性地”或者“例如”等词旨在以具体方式呈现相关概念。
本申请实施例的技术方案中,所涉及的用户个人信息的收集、存储、使用、加工、传输、提供和公开等处理,均符合相关法律法规的规定,且不违背公序良俗。例如,本申请实施例的技术方案中,对用户个人信息处理是在用户授权的情况下进行的,在此统一说明,以下不再赘述。
“用于”,可以是“专用于”,或“可用于”,不限“专用于”。比如,除用于xx,还可有其他作用,不予限制。
本申请实施例中,终端向服务器发送的数据可称为上行数据。反之,服务器向终端发送的数据可称为下行数据。
本申请实施例提供一种通信方法,第一终端的系统登录第一用户的账号,第一终端存储有第一用户的关系链标识和第一用户的至少一个联系人的关系链标识。第一终端接收向第一用户的至少一个联系人中的第二用户发起通信连接的第一操作。响应于第一操作,获取第二用户的第二终端的通信标识;基于通信标识,向第二用户的第二终端发送通信连接请求。采用该方法,第一终端在与第二终端通信时,可以基于联系人的关系链标识,查询联系人的通信标识,而不需要通过手机号、邮箱号等隐私信息查找第二终端中的用户,从而减少了用户的隐私信息泄露的风险。
上述关系链标识(Account encrypt Id)用于表征/标识用户身份(与终端的用户对应),且与该用户的联系方式不同,不涉及隐私。其中,联系方式可以是手机号、邮箱号、传真号码等。用户的关系链标识与该用户的账号之间一一对应,例如关系链标识可以基于该用户的终端登录的账号确定。终端登录的账号(AccountId)还可以称为系统账号,系统账号是系统级的账号。如账号可以是华为账号。
关系链标识可以基于该用户的终端登录的账号确定,可以实现为:关系链标识可以基于对关联的账号进行加密获得。加密方法如哈希,但不限制。
上述通信标识用于寻址终端,例如通信标识可以是设备标识(DeviceID)、通信地址。例如通信地址可以是设备网际互联协议(internet protocol,IP)地址。例如,设备标识可以是设备的序列号,或其他唯一寻址到设备的标识。一个终端对应一个通信标识。不同终端的通信标识不同。本文以通信标识是DeviceID为例,在此统一说明,下文不再赘述。
在一个终端登录了账号的情况下,可基于该账号确定该终端的用户的关系链标识。该关系链标识与该终端的DeviceID对应。之后,其他终端可基于该终端的用户的关系链标识,查找到该终端的DeviceID,从而寻址该终端。
参照图1,本申请实施例的方法可以应用于包含服务器100(或称为云端)和多个终端200(图1中所示的200a-200e)的系统中。可选的,终端200可以通过有线网络或无线网络与服务器连接。比如通过局域网、蜂窝网络、无线保真(wireless fidelity,Wi-Fi)等通信连接。
示例性的,服务器可以是独立的服务器,或者是多地域、多机房、多服务器所组成的服务器集群,不予限制。
示例性的,终端200可以是手机、平板电脑、手持计算机、上网本,以及个人数字助理(personal digital assistant,PDA)、人工智能(artificial intelligence,AI)设备、可穿戴式设备,可穿戴设备包括但不限于智能手表、智能手环、智能脚环等各种设备。终端200安装的操作系统不限。本申请对终端200的具体类型、安装的操作系统均不作限制。
示例性的,图2示出了本申请实施例提供的另一系统架构示例。示例性的,服务器可包括账号云、关系链服务和推送服务。该服务器可称为关系链服务器。
其中,账号云,还可称为云空间或账号云服务。账号云,可用于接收各终端上传的一些上行数据。可选的,终端上传的上行数据可包括:终端用户的关系链标识以及终端用户的联系方式。其中,关系链标识不涉及敏感的隐私信息,安全性较高。
可选的,上行数据还可包括:终端用户的至少一个联系人的联系方式。
也就是说,终端可上报该终端用户的一些信息以及联系人的一些信息,这些信息可用于终端从服务器获取联系人的关系链标识。后续,终端可通过联系人的关系链标识,向联系人的终端发起通信连接。
可选的,用户的联系方式包括但不限于如下至少一种:电话号码、电子邮箱或传真号码。可选的,不同联系人的联系方式的类型可以相同或不同。比如,联系人的联系方式的类型均为电话号码。再如,部分联系人的联系方式为电话号码,部分联系人的联系方式为电子邮箱。
可选的,联系人的联系方式与联系人的关系链标识一一对应。也就是,联系人的联系方式、关系链标识、账号之间彼此一一对应。比如,用户A的联系人B使用电话号码B注册华为账号,该电话号码B与注册的该华为账号之间一一对应,不同华为账号绑定的电话号码不同。
示例性的,如图2,终端A向账号云上传终端A的用户1的关系链标识(如记作Account encrypt Id_A)、用户A的电话号码(如记作PhoneNum_A)以及用户A的电子邮箱(如记作Email_A)。类似的,其他终端向账号云上传该其他终端用户的联系方式以及该其他终端用户的关系链标识。
仍如图2,终端A还可向账号云上传联系人B的手机号码(如记作PhoneNum_B)、联系人C的电子邮箱(如记作Email_C)。一些示例中,如图2,终端A可按照如下格式上传联系人的联系方式:{AccountOwnerID_A,PhoneNum_B;AccountOwnerID_A,Email_C},对于联系人B,PhoneNum_B表示联系人B的电话号码,AccountOwnerID_A表示该联系人B为终端A的用户A的联系人。类似的,对于联系人C,用户A的联系人C的电子邮箱是Email_C。
类似的,其他终端上传各自联系人的联系方式。
本申请的一个或多个实施例中,联系人还可称为好友,名称不限。
可选的,各终端还可向服务器上传各自的推送令牌(pushToken)。例如,图2中,终端A上传pushToken_A。后续,服务器可向推送令牌对应的终端推送信息。比如,推送消息,以指示终端修改联系人的关系链标识。
可选的,各终端还可上传各自的DeviceID。比如,终端A上传DeviceID A(通信标识的一种示例)。
作为一种可能的实现方式,终端登录账号,在用户同意隐私声明后,终端可向账号云上传上述上行数据。终端A、C、D各自上报的上行数据如图2。
账号云接收各终端上传的上行数据后,可根据该上行数据进行汇总,建立用户之间的关系网络,关系网络可表征用户之间的好友关系。例如,如图3A,箭头表示好友关系。用户A的联系人包括用户G、F、E、D、C、B,用户B的联系人包括用户A、K,用户C的联系人包括用户A和用户B,以此类推。
本文中,关系网络还可称关系链网络或关系链云或关系链,不限名称。
账号云接收各终端上传的上行数据后,还可根据该上行数据确定并存储用户之间的关系信息。关系信息可用于表征上述关系网络,也就是可表征用户之间的好友关系。例如,账号云存储的关系信息如图3A,第一行的关系信息表示:用户A的联系人B的电话号码为PhoneNum_B,联系人B的关系链标识为Account encrypt Id_B。
账号云接收各终端上传的上行数据后,还可根据该上行数据确定并存储相关的通信信息。通信信息可包括用于寻址到联系人设备的DeviceID。例如,账号云存储的通信信息如图3A,第一行的通信信息表示:用户A的关系链标识是Account encrypt Id_A,用户A的终端A的DeviceID A,用户A的电话号码是PhoneNum_A,用户A的电子邮箱是Email_A。倒数第二行的通信信息表示:用户E的关系链标识是Account encrypt Id_E,用户E的终端E1的DeviceID E1,用户E的电话号码是PhoneNum_E,用户E的电子邮箱是Email_E。最后一行的通信信息表示:用户E的关系链标识是Account encrypt Id_E,用户E的终端E2的DeviceID E2,用户E的电话号码是PhoneNum_E,用户E的电子邮箱是Email_E。
由上可知,关系链标识与DeviceID具有关联关系。相应的,账号与DeviceID之间具有关联关系。图3B示出了账号与DeviceID之间的关联关系。用户1的账号为账号1,用户1的DeviceID包括DeviceID 1-DeviceID 3。例如,DeviceID 1-3分别为用户1的三个不同设备的DeviceID。用户2的账号为账号2,用户2的DeviceID包括DeviceID 4-6。
服务器中的关系链服务,可用于基于账号云中存储的数据,向终端下发联系人的关系链标识。关系链服务,还可用于向终端下发联系人的DeviceID。如图3A,以联系人E为例,联系人E的DeviceID包括终端E1的DeviceID E1和终端E2的DeviceID E2。
后续,终端可基于联系人的关系链标识获取联系人的DeviceID,并使用联系人的DeviceID向联系人的终端发起通信连接。可选的,服务器可能向终端返回全部或部分联系人的关系链标识。比如,图2中,终端A的用户A的联系人X无华为账号,则服务器不向终端返回该联系人X的关系链标识。
示例性的,终端A向账号云上传联系人B、联系人C的联系方式之后,关系链服务可查询账号云中是否已存储联系人B、联系人C的关系链标识。若账号云中已存储联系人B、联系人C的关系链标识,关系链服务可向终端A返回联系人B、联系人C的关系链标识。可选的,服务器可向终端A返回联系人B的DeviceID以及联系人C的DeviceID。
可选的,若账号云中没有联系人B、联系人C的关系链标识,则关系链服务可以在账号云中存储联系人B、联系人C的关系链标识后,向终端A返回联系人B、联系人C的关系链标识。可选的,服务器可向终端A返回联系人B的DeviceID以及联系人C的DeviceID。
终端A接收来自关系链服务器的联系人B、联系人C的关系链标识之后,可以将联系人B、联系人C的关系链标识存储到联系人数据库。类似的,其他终端可以从服务器获取联系人的关系链标识。一些场景中,终端可以基于联系人的关系链标识获取该联系人的DeviceID,并使用该联系人的DeviceID,向该联系人的终端发起通信连接,具体实现可参考后文。
一些场景中,比如华为分享场景中,终端还可以基于对方的关系链标识,查询联系人数据库,并根据查询结果识别该对方是否为本机联系人,具体实现可参考后文。
本文中,联系人数据库,也可称关系链数据库,不限名称。示例性的,该联系人数据库是系统级或账号级的数据库。该系统级的数据库对应的通讯录,可称为系统通讯录。
例如,表1-1示出了终端A中存储的联系人B、C的关系链标识。其中,每行表示一个关系链标识关联的M个联系方式。M是正整数。
表1-1
再如,表1-2示出了终端A中存储的联系人B、C的关系链标识。其中,每行表示一个关系链标识关联的一个联系方式。一个联系人的M个联系方式对应M行。
表1-2
或者,终端存储关系链标识的方式还可以为其他,不限于表1-1、表1-2所示格式。
服务器中的推送服务,可用于向终端的推送服务推送变更消息。比如,当某个用户的关系链标识发生变化,推送服务向该用户的联系人的终端推送变更消息,以指示该终端修改该用户的关系链标识。后续,该联系人的终端可以基于修改后的关系链标识,向该用户的终端发起通信连接。
上述关系链服务器用于更新关系链相关的信息。一些示例中,终端发起业务时,不再实时连接关系链服务器,而是可以连接业务服务器实现业务。终端需要变更关系链相关的信息时,连接关系链服务器进行获取。例如,业务服务器接收第一终端的消息A,并根据该消息A的包头解析结果,识别到第一终端的目的设备是第二终端。再如,业务服务器可以查看第二终端的第二用户是否在线,如果不在线,业务服务器可下发消息B,以拉起第二终端的第二用户在线。例如,消息A可包括第二用户的第二终端的DeviceID。
另一些示例中,为了提升信息的准确性,终端可以在发起业务时,从关系链服务器获取最新的关系链相关信息。
另一些示例中,业务服务器和关系链服务器进行云之间的对接,以保证关系链相关信息的准确性和实时性。
作为一种可能的实现方式,针对通话等业务,上述系统可能还包括信令服务器,以实现可靠性的语音交互。
示例性的,图4示出了本申请实施例提供的一种电子设备的结构示意图。该电子设备可以是上述终端200或服务器100。
如图4所示,电子设备包括:处理器501、存储器502、收发器503。处理器501、存储器502的实现可参见图5所示终端的处理器、存储器的实现。收发器503,用于电子设备与其他设备交互。收发器503可以是基于诸如Wi-Fi、蓝牙或其他通信协议的器件。
再示例性的,图5示出了本申请实施例提供的一种终端500的另一种结构示意图。
如图5所示,终端500可以包括处理器510,存储器520,以及显示屏530等。
处理器510可以包括一个或多个处理单元,例如:处理器510可以包括应用处理器(application processor,AP),调制解调处理器,图形处理器(graphics processing unit,GPU),图像信号处理器(image signal processor,ISP),控制器,视频编解码器,数字信号处理器(digital signal processor,DSP),基带处理器,和/或神经网络处理器(neural-network processing unit,NPU)等。其中,不同的处理单元可以是独立的器件,也可以集成在一个或多个处理器中。
控制器可以根据指令操作码和时序信号,产生操作控制信号,完成取指令和执行指令的控制。
处理器510中还可以设置存储器,用于存储指令和数据。在一些实施例中,处理器510中的存储器为高速缓冲存储器。该存储器可以保存处理器510刚用过或循环使用的指令或数据。如果处理器510需要再次使用该指令或数据,可从存储器中直接调用。避免了重复存取,减少了处理器510的等待时间,因而提高了系统的效率。
在一些实施例中,处理器510可以包括一个或多个接口。这一个或多个接口可用于处理器510与存储器520、显示屏530等相连接。
在本申请的一些实施例中,处理器510可用于验证接收到的关系链标识是否为已经存储的联系人好友的关系链标识。具体介绍请参考后文。
存储器520可以用于存储计算机可执行程序代码,可执行程序代码包括指令。存储器520可以包括存储程序区和存储数据区。其中,存储程序区可存储操作系统,至少一个功能所需的应用程序(比如图像播放功能等)等。存储数据区可存储终端500使用过程中所创建的数据等。处理器510通过运行存储在存储器520的指令,和/或存储在设置于处理器中的存储器的指令,执行终端500的各种功能应用以及数据处理。
终端500通过GPU,显示屏530,以及应用处理器等实现显示功能。GPU为图像处理的微处理器,连接显示屏530和应用处理器。GPU用于执行数学和几何计算,用于图形渲染。处理器510可包括一个或多个GPU,其执行程序指令以生成或改变显示信息。
显示屏530用于显示图像,视频等。显示屏530包括显示面板。显示面板可以采用液晶显示屏(liquid crystal display,LCD),有机发光二极管(organic light-emitting diode,OLED),有源矩阵有机发光二极体或主动矩阵有机发光二极体(active-matrix organic light emitting diode的,AMOLED),柔性发光二极管(flex light-emitting diode,FLED),Miniled,MicroLed,Micro-oLed,量子点发光二极管(quantum dot light emitting diodes,QLED)等。在一些实施例中,终端500可以包括1个或N个显示屏530,N为大于1的正整数。
在本申请的一些实施例中,显示屏530可用于显示各类界面。比如,提示将接收到关系链标识的用户作为添加为联系人。
可以理解的是,本申请实施例示意的结构并不构成对终端的具体限定。在本申请另一些实施例中,终端可以包括比图5所示的更多或更少的部件,或者组合某些部件,或者拆分某些部件,或者不同的部件布置。图示的部件可以以硬件,软件或软件和硬件的组合实现。
上述图4、图5仅为上述系统中终端、服务器的结构的可能示例,并不构成对终端、服务器的结构的限制。
下面结合本申请实施例中的附图,对本申请实施例提供的通信方法进行描述。需要说明的是,本申请的实施例中各个设备之间交互的消息名称或消息数目或消息中的参数名称等只是一个示例,具体实现中也可以采用其他的名称。比如,请求A,还可称为其他请求,或其他消息名称。
此外,本申请的各实施例之间涉及的动作,术语等均可以相互参考,不予限制。
图6示出了本申请实施例的技术方案的流程示例。如图6,该方法可包括如下步骤:
S101、第一终端接收向第二用户发起通信连接的第一操作。
其中,第一终端的系统登录第一用户的账号。示例性的,第一终端的系统登录第一用户的华为账号。系统登录的账号,可称为账号。
第一终端存储有第一用户的关系链标识,和第二用户的关系链标识,所述第二用户是所述第一用户的联系人,所述关系链标识基于终端的系统登录的用户的账号生成。示例性的,第一用户的关系链标识是基于第一用户的账号生成的,第一用户的联系人的关系链标识是基于该联系人的账号确定的。
可选的,关系链标识可以是对账号进行哈希运算得到的。终端A登录用户A的华为账号A,对华为账号A取哈希值得到用户A的关系链标识Account encrypt Id_A。终端B登录用户B的华为账号B,对华为账号B取哈希值得到用户B的关系链标识Account encrypt Id_B。或者,也可以基于其他方式确定关系链标识,本申请实施例不予限制。比如,对账号进行SHA-256处理,或SHA-256处理,或MD5处理,得到关系链标识。
示例性的,第一用户的联系人包括联系人1和联系人2,第一终端中可存储联系人1的关系链标识、联系人2的关系链标识,以及第一用户的关系链标识。
可选的,第一终端还可存储有第一用户的至少一个联系人的联系方式。
以第一终端是终端A,终端A的用户A向终端B的用户B发起视频通话为例,如图7,终端A检测到用户A点击了用户B(Jane)对应的视频通话控件102(第一操作的一个示例),终端A确定用户A向用户B发起通信连接。这里仅是对第一操作的一个示例,另一些场景下,第一操作还可以是其他操作,不予限制。比如,在近场分享场景中,第一操作可以是点击搜索到的对方的图标。
S102、响应于第一操作,基于第二用户的关系链标识获取第二用户的第二终端的通信标识。
作为一种可能的实现方式,应用可以根据从服务器下载的内容,生成自己的通讯录。也就是说,应用可以在系统通讯录已有关系链的基础上,维护自己的通讯录。应用自己的通讯录具有更细粒度,比如可标明每个设备的DeviceID(通信标识的示例)。应用可以基于更细粒度的通讯录,向相应设备发起通信。应用自己的通讯录可称为应用级的通讯录。例如,畅连维护如表2所示的通讯录,畅连通过该通讯录可以索引到每个设备的DeviceID。
表2
应用可根据应用自身的实现,通过自身的通讯录索引到通信设备,具体实现方式不限。
示例性的,多个终端登录相同的账号,在畅连通讯录中,该多个终端可对外呈现一个联系人。以表2为例,假设登录账号A的联系人为Jane,Jane的关系链标识1关联手机1、手机2,如图7,畅连通讯录界面101中,Jane的手机1、手机2被呈现为一个联系人。响应于用户点击视频通话控件102,终端A会呼叫手机1和手机2,手机1和手机2均振铃。
示例性的,智慧屏、平板、手机登录了相同的账号。在畅连通讯录中,手机、平板对外呈现一个联系人,呼叫时,多设备共同振铃。智慧屏可作为一个单独设备,在畅连通讯录中可单独呈现智慧屏的标识,终端可单独呼叫该智慧屏。
仍以表2为例,假设登录账号B的联系人为Jeff,Jeff的关系链标识2关联智慧屏、平板以及其他设备,如图7,畅连通讯录界面101中,Jeff的智慧屏被呈现为一个单独联系人。Jeff的另外一些设备被呈现为另一个联系人。响应于用户点击“Jeff的智慧屏”对应的视频通话控件,终端A会单独呼叫智慧屏。响应于用户点击“Jeff”对应的视频通话控件,终端A会呼叫Jeff的平板以及其他设备。
示例性的,仍如图7,终端A检测到用户A点击了用户B(Jane)对应的视频通话控件102(第一操作的一个示例),终端A知晓该视频通话控件对应用户B,终端A可基于用户B的关系链标识,查询诸如表2所示的表格,获取用户B的设备的DeviceID。比如,用户B的终端B包括手机1和手机2,相应的,用户B的设备的DeviceID包括手机1的DeviceID:887XXX1和手机2的DeviceID:887XXX2。
再示例性的,仍如图7,若终端A检测到用户A点击了“Jeff的智慧屏”对应的视频通话控件,则终端A可基于Jeff的关系链标识,查询诸如表2所示的表格,获取Jeff的智慧屏的DeviceID:887XXX4。
S103、第一终端基于该通信标识,向第二用户的第二终端发送通信连接请求。
一些场景中,该通信连接请求用于发起音视频通信。
示例性的,终端A基于用户B的DeviceID(通信标识的示例),向用户B的终端B(如手机)发送通信连接请求。终端B响应该通信连接请求,建立与终端A之间的通信连接。终端A与终端B可通过该通信连接进行通信,如交互畅连通话过程中的音视频数据。
采用该方法,第一终端中的应用在与第二终端中的应用通信时,可以基于联系人的关系链标识,查询联系人的通信标识,而不需要通过手机号、邮箱号等隐私信息查找第二终端中的用户,从而减少了用户的隐私信息泄露的风险。
上述以第一终端自身存储联系人的关系链标识和联系人的DeviceID的关联关系为例,另一些实施例中,终端不从服务器预先获取并存储联系人的DeviceID。当第一终端有业务需求时,第一终端向服务器查询联系人的DeviceID。如下对该实施方式进行介绍:
作为一种可能的实现方式,有业务需求的情况下,第一终端向服务器发送第二用户的关系链标识,并接收来自服务器的第二用户的DeviceID。之后,第一终端基于DeviceID,向第二终端发送通信连接请求。
作为一种可能的实现方式,服务器可存储多个用户中每个用户的关系链标识和DeviceID的对应关系。
一些示例中,如图7,服务器存储的信息包括:用户B的关系链标识和用户B使用的终端B的DeviceID B1(如手机的标识);用户C的关系链标识和用户C使用的终端C的DeviceID C1(如平板的标识)。
如图7,终端A检测到用户A点击了用户B(Jane)对应的视频通话控件102(第一操作的一个示例),终端A向服务器发送用户B的关系链标识,以查询用户B的DeviceID。服务器从终端A接收用户B的关系链标识之后,查询存储的上述对应关系,以获取该关系链标识关联的用户B的DeviceID B1。之后,服务器向终端A返回用户B的DeviceID B1。终端A从服务器查询到用户B的DeviceID之后,可基于该DeviceID,向用户B的终端B发送通信连接请求。
可选的,向终端B发送的该通信连接请求中可包括用户A的关系链标识。终端B可根据用户A的关系链标识查询终端B的联系人数据库,经查询,联系人数据库中存在用户A的关系链标识,说明用户A是用户B的好友。终端B可据此显示好友的通话请求界面。反之,若终端B确定通话请求的对方不是用户B的好友,终端B可显示非好友的通话请求界面。也就是,终端B可以不同的用户界面(userinterface,UI)样式显示好友和非好友的通话请求界面。
另一些示例中,用户B具有多个登录相同账号的设备,比如,用户B的终端B1(如手机)和终端B2(如平板)登录相同的账号,相应的,该手机与该平板具有相同的关系链标识。该示例中,服务器存储的信息可包括:用户B的关系链标识以及用户B使用的手机的DeviceID B1;用户B的关系链标识以及用户B使用的平板的DeviceID B2;用户C的关系链标识以及用户C使用的终端C的DeviceID C1。
该示例中,终端A想要向用户B的终端发起视频通话,则终端A可向服务器发送用户B的关系链标识,以查询用户B的终端的DeviceID。服务器从终端A接收用户B的关系链标识之后,查询存储的上述对应关系,以获取该关系链标识关联的用户B的终端的DeviceID B1(如用户B的手机的DeviceID)和DeviceID B2(如用户B的平板的DeviceID)。之后,服务器向终端A返回用户B的终端的DeviceID B1和DeviceID B2。终端A可使用用户B的终端的DeviceID B1,向用户B的手机发送视频通话请求。并且,终端A可使用用户B的终端的DeviceID B2,向用户B的平板发送视频通话请求。这样一来,用户B的登录相同账号的设备均会收到视频通话请求,用户B可选择在任意设备上接受视频通话请求,并使用该设备与用户A进行视频通话。
上述以第一终端向服务器查询第二用户的第二终端的DeviceID,并直接使用该DeviceID向第二终端发起通信连接为例,另一些实施例中,第一终端还可通过服务器建立与第二终端之间的通信连接。比如,终端A向服务器发送用户B的关系链标识,服务器据此查询本地存储的通信信息,确定用户B的终端的DeviceID为B1。之后,服务器根据用户B的终端的DeviceID,建立终端A与终端B之间的通信连接。触发终端之间通信连接建立的服务器,与实现本文其他功能的服务器可以是同一服务器,或不同服务器。
可选的,第一终端和第二终端之间的通信连接,可以是直接连接或间接连接。比如,第一终端和第二终端的连接可以是点到点(point to point,P2P)连接。或者,第一终端和第二终端之间通过中继连接。中继包括但不限于服务器。作为中继的服务器与实现本文其他功能的服务器可以是同一服务器,或不同服务器。
一些实施例中,第一终端的第一用户的联系方式,或第一终端的联系人的联系方式可能发生变化,此种情况下,第一终端或服务器需进行相应的更新操作,以便后续相应终端能够使用更新后的关系链标识发起通信连接。如下,分情况进行介绍:
情况1:第一终端的第一用户修改自身的联系方式
该情况中,第一用户的联系人的终端修改第一用户的联系方式和第一用户的关系链标识的关联关系。
作为一种可能的实现方式,第一终端接收修改第一用户的联系方式的第二操作。响应于该第二操作,第一终端可向服务器发送修改的第一用户的联系方式。服务器接收第一终端发送的修改的第一用户的联系方式之后,可向第三终端发送第一通知消息,第一通知消息用于通知第三终端修改第一用户的联系方式和第一用户的关系链标识的关联关系。第三终端的用户的联系人的联系方式包括添加的第一用户的联系方式。也就是说,第一用户修改自身的联系方式的场景中,服务器可通知联系人的终端修改第一用户的联系方式和第一用户的关系链标识的关联关系。
作为一种可能的实现方式,服务器修改第一用户的联系方式和第一用户的关系链标识的关联关系。
可选的,修改包括以下一个或多个,添加联系方式,将删除联系方式,更新联系方式。
如下,以第一终端是终端A,第一用户是用户A为例举例。
例如,用户A在终端A中添加了自己的一个电话号码189xxx,终端A可以将该电话号码189xxx上报给服务器。具体的,终端A上报电话号码189xxx和用户A的关系链标识。服务器可据此修改用户A的通信信息。比如,在用户A对应的通信信息中增加电话号码179xxx。
服务器根据接收的信息,向用户A的联系人的终端发送第一通信消息,以通知联系人的终端修改用户A的联系方式和用户A的关系链标识的关联关系。例如,服务器可根据存储的如图2所示的关系信息示例,获知用户A的联系人包括用户B和用户C,则服务器向用户B和用户C的终端分别发送第一通知消息。
以服务器向用户B的终端B发送第一通信消息为例,该第一通知消息中包括用户A的关系链标识、用户A的新电话号码189xxx以及终端B的推送令牌(push Token B)。终端B根据第一通知消息添加新电话号码189xxx和用户A的关系链标识的关联关系。如下述表3-2,相比于表3-1,终端B在表3-2中添加了第二行Account encrypt Id_A,189xxx,以表示新电话号码189xxx和用户A的关系链标识Account encrypt Id_A关联。可选的,表3-2中第二行的邮箱可以是Email_A,或为空,不予限制。
表3-1
表3-2

再如,用户A在终端A中删除了自己的联系方式。其中,用户A可以删除部分联系方式,或删除全部联系方式。比如,用户A仅删除电话号码,或删除电话号码和邮箱。
终端A可以将用户A删除的自身联系方式上报给服务器。具体的,终端A上报:删除的联系方式和用户A的关系链标识。服务器接收终端A上报的信息后,向存储有该已删联系方式的用户A的联系人的终端发送第一通知消息。比如,第一通知消息包括已删的联系方式、用户A的关系链标识和推送令牌,用户A的联系人的终端可根据第一通知消息,删除用户A的该联系方式和用户A的关系链标识的关联关系。一些示例中,如下述表4-2,相比于表4-1,终端B在表4-2中删除了第一行。
表4-1
表4-2
另一些示例中,如下述表5-2,相比于表5-1,终端B在表5-2中删除了第一行的电话号码189yyy,关系链标识Account encrypt Id_A与邮箱Email_A的关联关系仍存在。
表5-1
表5-2
再如,用户A在终端A中将电话号码A更新为电话号码B,终端A可以将电话号码A和电话号码B均上报给服务器。服务器接收来自终端A的信息之后,可以向存储有电话号码A的联系人终端发送第一通知消息,第一通知消息中可包括:电话号码A,电话号码B,用户A的关系链标识以及该联系人终端的推送令牌。如下述表6-1和表6-2,联系人终端B可根据第一通知消息,删除电话号码A和用户A的关系链标识的关联关系,增加电话号码B和用户A的关系链标识的关联关系。
表6-1
表6-2

情况2:第一终端的第一用户修改联系人的联系方式
该情况中,第一终端相应的修改联系人的关系链标识的关联关系。相应的,服务器可基于该修改的联系人的联系方式,修改存储的该联系人(如第三用户)的联系方式与关系链标识的关联关系。
一些场景中,第一终端的第一用户添加联系人的联系方式。作为一种可能的实现方式,第一终端接收添加第三用户为联系人的第三操作,响应于第三操作,第一终端向服务器发送第三用户的联系方式。第一终端接收并存储服务器发送的第三用户的关系链标识。一些示例中,第一终端还可接收并存储服务器发送第三用户的终端的Device ID。
例如,用户A在终端A中添加了一个好友B的联系方式,终端A可以向服务器上报好友B的联系方式。具体的,终端A上报:好友B的联系方式和用户A的关系链标识。
服务器在存储空间中查找该好友B的关系链标识,并将好友B的关系链标识推送给该终端A。比如,服务器发送推送(push)消息,该推送消息中包括好友B的联系方式,好友B的关系链标识以及相应的推送令牌,用于指示添加好友B的联系方式和好友B的关系链标识的关联关系。服务器还可向终端A发送该新增好友B的终端的Device ID。
一些场景中,第一终端还存储有第一用户的至少一个联系人的联系方式。第一终端的第一用户可删除某一个或一些联系人的联系方式。作为一种可能的实现方式,第一终端接收删除第四用户为联系人的第四操作。响应于第四操作,第一终端删除存储的第四用户的关系链标识。一些示例中,第一终端还可删除第四用户的终端的Device ID。
例如,用户A在终端A中删除了一个好友B的联系方式,第一终端删除存储的好友B的关系链标识以及该好友B的终端的Device ID。
该场景中,第一终端响应于第四操作,还可以向服务器发送第四用户的联系方式。例如,终端A还可以将好友B的联系方式上报给服务器,服务器删除好友B的联系方式和好友B的关系链标识的关联关系。
一些场景中,第一终端还存储有第一用户的至少一个联系人的联系方式。第一终端的第一用户可更新某一个或多个联系人的联系方式。
作为一种可能的实现方式,第一终端还存储有第五用户的联系方式和该第五用户的关系链标识,该第五用户是第一用户的联系人。第一终端可接收将第五用户的联系方式由第一联系方式更新为第二联系方式的第五操作,响应于第五操作,将与第五用户的关系链标识的对应的联系方式由第一联系方式更新为第二联系方式。
例如,用户A将好友B的电话号码由号码1变更为号码2,终端A可以删除好友B的号码1和好友B的关系链标识的关联关系,并增加好友B的号码2和好友B的关系链标识的关联关系。如此,在第五用户的联系方式更新的场景中,第一终端可以及时更新第五用户的关系链标识与联系方式的关联关系。
该场景中,第一终端响应于第五操作,还可向服务器发送第五用户的第一联系方式和第二联系方式。例如,终端A还可以将变更后的好友B的号码2通知服务器,以指示服务器删除号码1和好友B的关系链标识的关联关系,并增加号码2和好友B的关系链标识的关联关系。如此,服务器可以快速知悉第五用户的联系方式更新,并对应更新第五用户的关系链标识与联系方式的关联关系。
该场景中,服务器接收第五用户的第一联系方式和第二联系方式之后,还可以向第五用户的联系人的终端发送通知消息,以指示该联系人终端修改第五用户的联系方式与关系链标识的关联关系。比如,用户A的好友B的电话号码由号码1更新为号码2。服务器根据图3A所示的关系网络,确定好友B的联系人还包括联系人C和联系人K。那么,服务器可向联系人C和联系人K的终端发送通知消息,以指示终端C和终端K更新好友B的关系链标识与联系方式的关联关系。具体的,终端C、K可以删除好友B的号码1和好友B的关系链标识的关联关系,并增加好友B的号码2和好友B的关系链标识的关联关系。
情况2中,作为一种可能的实现方式,如果用户A还有其他设备,服务器还可以向用户A的其他设备发送push消息,以指示删除或添加或更新好友B的联系方式和好友B的关系链标识的关联关系。
上述主要以畅连通信这一远场通信为例介绍本申请实施例的方案,该方案还可适用近场通信。
示例性的,终端A可向服务器发送好友用户B的联系方式,并接收服务器发送的用户B的关系链标识。如图8A,华为分享场景中,终端B发送广播,广播可携带终端B的用户B的关系链标识。终端A搜索附近的设备,其中终端A搜索到终端B的广播。终端A判断联系人数据库中是否已存储有该广播中的关系链标识,如果已存储该关系链标识,说明终端B是用户A的联系人。反之,如果终端A没存储该关系链标识,说明终端B不是用户A的联系人。
可选的,终端A对联系人和非联系人的显示方式可不同。比如,如图8A,联系人的图标的UI样式为样式一,非联系人的图标的UI样式为样式二。
一些示例中,如图8A,用户B是联系人。响应于用户A点击该联系人的图标103,终端A可以和终端B建立通信连接。图8B示出了图8A所示场景的流程示例。
作为一种可能的实现方式,终端A可设置支持与搜索到的所有用户交互。此种情况下,终端A可以与搜索到的对方建立通信连接。该对方可以是联系人或非联系人。
作为另一些可能的实现方式,终端A可设置仅和联系人交互。此种情况下,终端A可以与搜索到的联系人建立通信连接。对于搜索到的非联系人,终端A可显示提示信息,以提示添加为联系人后进行通信。用户A将搜索到的对方添加为联系人之后,终端A可以与该联系人建立通信连接。
采用该方法,近场通信场景中,终端在广播中携带关系链标识,而非手机号等敏感信息,能够提升信息安全性,避免隐私泄露。
一些实施例中,多设备之间还可共享关系链标识。作为一种可能的实现方式,第一终端还存储有第一用户的至少一个联系人的联系方式,联系人的联系方式与联系人的关系链标识一一对应。第一终端接收服务器发送的通知消息,通知消息用于通知第一终端修改存储的联系方式与关系链标识的关联关系。其中,修改存储的联系方式与关系链标识的关联关系包括以下一个或多个:删除第一用户的至少一个联系人中第六用户的联系方式与关系链标识的关联关系;更新第一用户的至少一个联系人中第七用户的关系链标识对应的联系方式;增加第八用户的联系方式与关系链标识的关联关系。
服务器可接收来自第一终端的修改的第三用户的联系方式。修改包括以下一个或多个,添加第三用户为联系人,将从联系人中删除第三用户,更新第三用户的联系方式。服务器可向第四终端发送第二通知消息,第二通知消息用于通知第四终端修改存储的联系方式与关系链标识的关联关系,第四终端登录的账号与第一终端登录的账号相同。
示例性的,用户在手机A1中增加联系人B的电话号码180xxx。手机A1可向服务器查询联系人B的关系链标识。如图9,手机A1接收来自服务器的通知消息,该通知消息包括联系人B的电话号码180xxx和联系人B的关系链标识Account encrypt Id_B,以指示手机A1增加电话号码180xxx和关系链标识Account encrypt Id_B的关联关系。
如图9,与手机A1登录相同华为账号A的平板A2开启了云同步功能。那么,服务器也可向平板A2发送上述通知消息(第二通知消息的一个示例),以指示平板A2增加电话号码180xxx和关系链标识Account encrypt Id_B的关联关系。可见,开启云同步功能的设备,不仅能从服务器获取自身设备的联系人的关系链标识,还能获取同账号设备(如同账号的手机)的联系人的关系链标识。或者,可以理解为,开启云同步功能后,设备可获得同账号设备的的联系人数据库中的数据。也就是,同账号的设备,联系人数据库中的数据可能完全相同。
如图9,与手机A1登录相同账号A的电脑A3未开启云同步功能。那么,服务器可以不向电脑A3发送上述通知消息。电脑A3不能获取同账号设备(如同账号的手机)的联系人的关系链标识。
一些实施例中,各终端可存储各自联系人的能力信息(capability information)。以第一终端为例,第一终端还存储有第一用户的至少一个联系人的能力信息,联系人的能力信息与联系人的关系链标识一一对应,能力信息用于指示对应联系人是否具备音视频通信能力。第二用户的能力信息用于指示第二用户具备音视频通信能力。也可以理解或替换为:联系人的能力信息表示联系人的账号所具有的能力。不同账号可具有不同的能力。相应的,不同关系链标识可能对应不同的能力信息。
作为一种可能的实现方式,各终端还可存储各自本机用户的能力信息。
示例性的,能力信息的格式可以是bit位格式。比如,用户A的联系人B的能力信息:000001100。联系人B的能力信息:000001101。其中,能力信息9位中的第6、7、8、9位分别表示畅连应用能力,华为分享能力,长尾应用1能力,长尾应用2能力。那么,上述能力信息分别可表示:联系人B的华为账号开通了畅连应用能力和华为分享能力;联系人C的华为账号开通了畅连应用能力、华为分享能力以及长尾应用2能力。此处的bit位数以及各bit位代表的含义仅为示例,位数和各bit位的含义还可以为其他,不予限制。能力信息的格式还可以为其他,不予限制。
华为账号开通了畅连应用能力,可以理解或替换为:畅连应用登录华为账号之后,终端可实施本申请实施例的方法,以通过畅连应用进行音视频通信,并提升音视频通信的安全性。比如,获取本机用户的关系链标识,向服务器上传本机用户的联系方式和本机用户的关系链标识。再如,接收来自服务器的联系人的关系链标识。再如,使用联系人的关系链标识,向联系人的终端发起音频连接请求或视频连接请求。
华为账号开通了华为分享能力,可以理解或替换为:华为分享场景中,终端可实施本申请实施例的方法,以通过华为分享传输数据,并提升数据传输的安全性。比如,接收来自服务器的联系人的关系链标识。再如,使用联系人的关系链标识,查询联系人的终端的Device ID。再如,使用联系人的终端的Device ID,向联系人的终端发起通信连接。
类似的,华为账号开通了其他能力,可以理解或替换为:相应场景中,终端可实施本申请实施例的方法,以提升该场景中通信的安全性。
作为一种可能的实现方式,各终端可向服务器上传各自用户的能力信息。以第一终端为例,第一终端可向服务器发送第一用户的能力信息。这样一来,服务器可确定各用户的账号级别的能力信息。后续,可以根据相应用户的能力信息,对相应通信的过程进行控制,以提升通信的安全性。具体实现可参考后文。
作为一种可能的实现方式,服务器可向各终端发送联系人的能力信息。终端可存储至少一个联系人的能力信息。比如,服务器可向第一终端发送第一用户的至少一个联系人的能力信息,能力信息用于指示对应联系人是否具备音视频通信能力。
示例性的,表7示出了第一终端存储的联系人(第二用户)的能力信息的示例。可选的,第一终端还可存储第二用户的昵称、头像信息等,不予限制。
表7
作为一种替代的实现方式,服务器还可存储设备级别的能力信息,以便确定开启相应能力的设备。
作为一种替代的实现方式,终端也可存储设备粒度的能力信息,本申请实施例对能力信息的存储粒度不做限制。
示例性的,用户A的华为账号开通了畅连应用能力,且用户A的联系人B的能力信息指示:用户B的华为账号开通了畅连应用能力。那么,终端A可以使用用户B的关系链标识与用户B的终端通信。
再示例性的,用户A的华为账号开通了系统应用3能力,且用户B的华为账号未开通系统应用3能力。此示例中,终端A不使用用户B的关系链标识与用户B的终端通信,终端A可使用相关技术的方案与用户B的终端通信。
作为一种可能的实现方式,终端也可区分联系人的能力信息,并据此确定不同联系人信息的UI样式。
示例性的,第一终端可以在联系人应用中,将支持音视频能力的联系人进行标记。例如,对于支持畅连音视频能力的联系人,第一终端显示该联系人的对应图标,比如畅连图标,用于表示该联系人支持畅连音视频能力。采用该方法,第一终端可从联系人中快速检索对应的某种能力,提升通信效率。
再示例性的,以畅连为例,启用畅连时,终端可以调用系统级的关系链信息生成好友列表。终端的好友列表中可以只显示支持通过畅连应用进行通信的好友。或通过特殊标记表明好友是否支持通过畅连应用进行通信。
本申请实施例还提供一种通信方法,第一终端与第二终端通信前,需获取作为安全凭证的通信令牌(comToken)。如图10,获取通信令牌的方法可包括:
S201、联系人数据库管理模块发送请求A,该请求A用于请求认证码(AuthCode)。
其中,终端可包括联系人数据库管理模块,联系人数据库管理模块可用于管理联系人数据库。认证码可用于表示应用的身份信息。
示例性的,该请求中可包括该应用的标识(APP ID)。
示例性的,应用向终端中的账号管理模块发送该请求A。
S202、终端向服务器发送请求B。
示例性的,该请求B中可包括该应用的包名称(PackageName)以及该应用的标识。可选的,该请求B中还可包括该应用的密钥。
示例性的,终端通过账号管理模块向服务器的账号云发送请求B,以请求认证码。
S203、服务器向终端返回该签名指纹和认证码。
示例性的,服务器的账号云接收该请求B之后,获取应用的签名指纹,并向终端返回该签名指纹和认证码。
其中,应用的签名指纹用于验证该签名指纹来自服务器。例如,账号云使用自身的私钥,对该应用所关联的华为账号进行数字签名,得到该应用的签名指纹。
S204、若签名指纹合法,账号管理模块向联系人数据库管理模块返回认证码和关系链标识。
作为一种可能的实现方式,账号管理模块对来自服务器的应用签名指纹进行验证,若签名指纹通过验证,说明该签名指纹来自服务器,且未经过篡改,意味着,用于得到该签名指纹的华为账号未经过篡改。后续,终端可基于该准确的华为账号确定该终端的用户的关系链标识。示例性的,终端还可向服务器上传该关系链标识。
签名指纹校验通过的情况下,账号管理模块可根据签名指纹获得该华为账号,并根据该华为账号计算该终端用户的关系链标识。关系链标识的具体计算方式可参考本文其他部分的内容。之后,账号管理模块可向联系人数据库管理模块返回该关系链标识和经授权的认证码。
S205、联系人数据库管理模块向服务器发送请求C,该请求C用于请求通信令牌。
其中,通信令牌可作为终端的安全凭证,获得通信令牌的终端具有从服务器获取联系人的关系链标识的权限。可选的,获得通信令牌的终端还可具有从服务器获取联系人的终端的Device ID的权限。
作为一种可能的实现方式,联系人数据库管理模块可向服务器的关系链服务发送该请求C。示例性的,该请求C中可包括认证码。示例性的,该请求C中还可包括该终端用户的关系链标识。可选的,该请求C中还可包括应用的包名称。可选的,该请求C中还可包括终端的Device ID。
S206、服务器确定返回通信令牌。
S2061、关系链服务验证关系链标识和Device ID。
作为一种可能的实现方式,关系链服务接收该请求C之后,判断终端用户的关系链标识和该终端的Device ID是否合法。比如,关系链白名单中不存在该关系链标识,且Device ID白名单中不存在该Device ID,意味着该关系链标识和Device ID存在安全隐患,服务器据此拒绝该请求C,确定不向终端的联系人数据库管理模块返回通信令牌。
S2062、关系链服务验证包名称。
作为一种可能的实现方式,如果包名白名单中存在该包名称,则该包名称校验通过。再如,若包名黑名单中不存在该包名称,则该包名称校验通过。
S2063、关系链服务获取应用的密钥。
作为一种可能的实现方式,若关系链标识、Device ID、包名称均通过验证,则关系链服务可根据包名称,获取应用的标识,并获取该标识所对应的应用的密钥。
S2064、关系链服务向账号云发送请求D,该请求D用于请求通信令牌。
可选的,令牌包括但不限于接入令牌(access token,AT)和/或刷新令牌(refresh token,RT)。
示例性的,请求D中可携带认证码、应用的密钥和应用的标识。
S2065、账号云校验认证码和应用的密钥。
例如,账号云校验请求D中的认证码是否为合法认证码,若为经授权的合法认证码,则认证码通过校验。
再如,账号云还可校验认证码、密钥和应用标识之间的关联性。一些示例中,若请求D中携带的认证码为该应用标识对应的认证码,且请求D中的应用密钥为该应用标识对应的密钥,则该密钥和认证码通过校验。
S2066、账号云向关系链服务返回通信令牌。
若认证码和应用密钥的校验均通过,意味着该应用是初步可信的,账号云向关系链服务返回通信令牌。
S207、关系链服务向终端返回通信令牌。
示例性的,关系链服务向终端的联系人数据库管理模块返回通信令牌。
可以看出,终端从服务器获取通信令牌的过程中,无需传输电话号码或者邮箱等敏感的身份信息,能够降低信息的安全风险。
S208、终端将该通信令牌作为安全凭证,使用该通信令牌与服务器通信。
示例性的,终端向服务器发送该通信令牌以及该终端的用户的至少一个联系人的联系方式。服务器接收到该通信令牌以及该终端的用户的至少一个联系人的联系方式后,可获知该终端具有获得至少一个联系人的关系链标识的权限。该服务器可向该终端发送的至少一个联系人的关系链标识。可选的,该服务器还可向终端发送至少一个联系人的终端的Device ID。
终端从服务器获取至少一个联系人的关系链标识后,可将至少一个联系人的关系链标识存储至联系人数据库。可选的,终端从服务器获取至少一个联系人的终端的Device ID后,可将至少一个联系人的终端的Device ID进行存储(如存储到诸如上述表2中)。后续,终端可通过联系人的关系链标识查找联系人的终端的Device ID,并使用联系人的终端的Device ID,向联系人的终端发起通信连接。
作为一种可能的实现方式,终端的联系人数据库管理模块,使用上述通信令牌与服务器通信。
作为一种可能的实现方式,通信令牌可更新。比如,通信令牌被设置为在一段时间内有效。超过该有效期,终端可重新向服务器请求通信令牌。再如,终端业务失败的情况下,可向服务器重新请求通信令牌。如此,能防止通信令牌长期有效,提升通信系统的安全性和健壮性。
作为一种可能的实现方式,通信令牌的有效期不固定。比如,第一次通信的令牌的有效期为7天,第二次通信的令牌的有效期为5天。或者,通信令牌的有效期固定。
作为一种可能的实现方式,通信令牌是随机数。如此,可尽量降低不同通信令牌之间的关联性,提升通信安全性。
一些场景中,恶意终端的恶意应用获取到通信令牌以及用户B的关系链标识。之后,恶意终端根据用户B的终端的Device ID,向终端B发送通信连接请求。终端B可在接收到来自该恶意终端的通信连接请求之后,确定联系人数据库中不存在该恶意终端用户的关系链标识,意味着终端B确定用户B与恶意终端的用户不是好友,终端B可在界面中提示“陌生来电”,以提示来电的对方不是好友。可见,即使恶意终端获取到作为安全凭证的通信令牌、用户B的关系链标识以及用户B的终端的Device ID,终端B也可根据联系人数据库确定用户B与恶意终端的用户不是好友,以防止与非好友通信可能导致的安全风险。
本申请实施例适用的场景不限上述列举的畅连、华为分享场景,短信、通话等场景也可使用本申请实施例的方案,以便通过使用关系链标识获取联系人的终端的Device ID,降低用户身份信息(如手机号)被泄露的概率。
上述实施例中提供的通信方法可以应用于近场通信,关系链标识用于获取联系人的终端的Device ID。上述实施例中的关系链标识还可以应用于身份认证的过程中,如联系人认证。基于关系链标识以提高联系人认证的效率和准确性。例如,终端A可以发起广播以搜索周边设备,该终端A的系统登录用户A的账号,该广播中可以携带基于用户A的账号生成的关系链标识A。周边设备中的终端B可以接收到该广播,该终端B的系统登陆用户B的账号。终端B可以根据该广播中的关系链标识A确定用户A是否为用户B的联系人。若是,则可以向终端A发送广播响应,该广播响应中可以携带基于用户B的账号生成的关系链标识B。若不是,则不回复终端A。若终端A接收到终端B回复的广播响应,则终端A可以根据广播响应中的关系链标识B确定用户B是否为用户A的联系人。
下文,将关系链标识在近场通信过程中进行身份认证的一种可能的具体应用过程进行详细介绍。
终端使用近距离无线通信技术可以将数据分享给其他终端。例如,第一终端将文件等数据分享给第二终端。上述过程中,作为发送端的第一终端需要发现或搜索到附近的第二终端,并在与第二终端建立连接后,才能进行文件的分享等操作。其中,第一终端与第二终端可以是陌生设备,即第一终端关联的第一用户与第二终端关联的第二用户相互间为陌生人,或者,第一终端与第二终端之间未分享过数据。第一终端中未添加或存储有第二用户的身份信息,和/或,第二终端中未添加或存储有第一用户的身份信息。第一终端中未添加或存储有第二终端的设备标识,和/或,第二终端中未添加或存储有第一终端的设备标识。第一终端与第二终端也可以是熟悉设备,即第一终端关联的第一用户与第二终端关联的第二用户相互间为联系人,或者,第一终端与第二终端之间分享过数据。
为了提高数据分享的安全性,降低非法数据在终端间的分享,相关规范要求终端在实现前述数据分享等操作前,应当提供开启或关闭附近其他设备可见功能的开关。并且,相关规范对该功能的开启时间进行了明确。例如,作为接收端的第二终端在开启“所有人可见”功能后10分钟将会自动关闭。因此,在第二终端开启上述“所有人可见”功能后的10分钟内,附近的其他终端可以发现或搜索到该第二终端。在第二终端“所有人可见”功能开启后,第二终端关联的第二用户的所有联系人或陌生人所使用的终端,只要处于第二终端附近,均可以发现或搜索到第二终端。例如,前述示例中作为发送端的第一终端可以在10分钟内发现第二终端。其中,第一终端关联的第一用户可以是第二用户的联系人,也可以是第二用户的陌生人。
应理解,上述示例中10分钟为示例时长,实际应用中,也可以根据其他时长关闭附近其他设备可见功能,对此不作限制。
另一方面,相关规范还对发送端的可见性进行了规定,即作为发送端的第一终端在任何时间均不能被接收端的第二终端发现或搜索到。如图11所示,是相关规范对终端可见性要求的示意图。按照图11所示,作为接收端的第二终端上应当具有可见性开关,当该可见性开关被开启后,表示第二终端可以在一定时间内,例如图11中所示的10分钟内,被其他终端发现,即“所有人可见”。这样,其他终端可以通过与第二终端建立连接,向第二终端分享数据。例如,图11中的第一终端可以在“所有人可见”功能开启后10分钟内发现第二终端。当上述“所有人可见”功能开启超过10分钟时,第二终端将自动关闭该功能。对于发送端的第一终端,相关规范则要求在任何时间发送端设备均不能被其他终端发现。
受上述相关规范要求的影响,终端在向陌生设备或熟悉设备分享数据前,需要依赖于对端设备的可见性。例如,只有作为接收端的第二终端开启可见性开关且在规定时间内被作为发送端的第一终端发现,第一终端才能够顺利地将数据分享给第二终端。这无疑将会对数据分享的高效性带来不利影响。
为了降低相关规范要求对数据分享带来的不利影响,部分终端提供了“仅联系人可见”的功能。例如,在接收端的第二终端开启“仅联系人可见”功能后,当第二终端的各个联系人对应的终端,例如第一终端处于第二终端附近时,第二终端可以被第一终端发现。当第二终端“仅联系人可见”功能开启后,第二终端在接收到第一终端的搜索广播后,第二终端需要对广播中携带的第一用户的身份信息进行认证,以确认第一用户的身份,第一用户是否为第二用户的联系人。只有在第一终端与第二终端相互认证,确认第一用户和第二用户为联系人后,第一终端才能够向第二终端分享数据。
现有技术中,“仅联系人可见”情况下进行的身份认证,终端需要证明对端设备拥有与用户账号相关联的联系人标识符,如电话号码、电子邮箱等。并且,该标识符需存在于终端的联系人通讯录中。当用户使用用户账号登录设备后,将会被分配一个唯一的通用唯一标识符(universally unique identifier,UUID),用于标识设备。在进行身份验证时,将会使用哈希散列形式的签名的“记录数据(record data,RD)”,RD包含了设备UUID与所有设备中的通讯录中的联系人标识符。发送端设备可以对上述RD进行签名,得到RD(s),其中s表示相应的证书。
进行认证时,接收端设备将会对其通讯录中的每个联系人标识符计算哈希值,例如SHA2,并将其与RD(s)中包含的哈希值进行比较,验证设备UUID是否与当前安全传输层协议(transport layer security,TLS)链接的证书相匹配。如果发送端或接收端未能提供有效的经过签名的TLS证书或者没有提供RD,则无法完成终端间的身份认证。可见,现有技术中要实现针对联系人的安全性校验,流程繁琐、复杂,部署成本也较高。但如果不进行联系人的安全性校验,则又存在依据相关规范要求需要在“所有人可见”功能开启后一定时间内,自动关闭该功能的问题。
针对现有技术中存在的问题,本申请实施例中的终端可以基于上文所述的关系链标识进行身份认证。本申请实施例提供了一种身份认证方法。应用本申请实施例提供的身份认证方法,终端可以通过匹配联系人数据库和/或历史分享数据库,对联系人和/或设备进行初筛,快速进行身份认证。同时,初筛得到的联系人和/或设备可以被终端显示在相应区域,以便用户识别,供用户进一步操作。本申请实施例可以通过匹配联系人数据库,快速地筛选出附近的联系人。当终端双方未被添加为联系人时,本申请实施例也可以借助历史分享数据库,快速地筛选出曾经进行过数据分享的设备。在此基础上,当用户需要通过终端向初筛得到的联系人或设备分享数据时,终端可以对该联系人或设备作进一步的身份认证。
可以理解的是,上文中的关联系标识应用于终端初筛联系人的过程中,具体实现方式参见下文。
可以理解的是,本申请实施例可以通过初筛快速地将符合一定条件的联系人和/或设备显示出来,供用户从中选择需要分享数据的联系人或设备,然后再对选中的联系人或设备作进一步的身份认证。相较于现有技术需要完成联系人的身份认证后再显示给用户,可以提高联系人或设备筛选的速度和效率,也有助于提高数据分享的效率。即,本申请实施例可以通过初筛显示多个联系人和/或设备,并仅对需要进行数据分享的联系人或设备进行身份认证;而现有技术则需要对所有被显示的联系人进行身份认证,本申请实施例简化了身份认证的操作流程,提高了身份认证的效率。而且,本申请实施例中无需发送隐私信息,减少了隐私泄露的风险。
本申请实施例提供的身份认证方法可以应用于终端。例如,本方法可以应用于前述示例中的第一终端。第一终端可以应用本方法快速地实现与第二终端之间的身份认证。其中,第一终端和第二终端可以是相同类型的终端。例如,第一终端和第二终端可以均为手机,或第一终端和第二终端也可以均为平板电脑。或者,第一终端和第二终端也可以是不同类型的终端。例如,第一终端可以为手机,第二终端可以为平板电脑,或第一终端可以为平板电脑,第二终端可以为可穿戴设备,如智能手表等等。本申请实施例对终端的类型不作限定。
如图12所示,是本申请实施例提供的一种身份认证方法的用户操作界面的示意图。其中,图12中的(a)示出了使用近距离无线通信技术进行数据分享功能设置页面的示意图,例如该功能可以是图12中的(a)所示的“华为分享”功能1200。图12中的(a)中示出了显示于当前的终端,例如可以是第二终端数据分享功能设置页面上的3个选项,即“所有人可见(10分钟)”选项1201、“联系人和分享过的设备可见”选项1202,以及“不可见”选项1203。当图12中的(a)中“不可见”选项1203被选中时,当前的第二终端不能被附近的其他终端,例如第一终端等发现或搜索到。第一终端等也不能通过近距离无线通信技术向第二终端分享数据。当图12中的(a)中“所有人可见(10分钟)”选项1201被选中时,可以表示在10分钟内,第二终端可以被附近的其他终端发现。附近的其他终端例如第一终端等可以向第二终端分享数据。在所有人可见的情况下,其他终端与第二终端建立连接以及进行联系人身份认证的过程可以按照与现有技术相同的方式进行,本申请实施例对此不再赘述。
当图12中的(a)中“联系人和分享过的设备可见”选项1202被选中时,第二终端的页面可以如图12中的(a)所示。这表示“华为分享”功能被开启。此时,第二终端关联的第二用户的联系人,以及曾经向第二终端分享过数据的其他终端,或者被第二终端分享过数据的终端,在位于第二终端当前位置附近时,均能够发现或搜索到第二终端。这样,第二终端可以作为被分享数据的接收端设备,在完成与其他终端的身份认证后,接收来自其他终端分享的数据。
如果第一终端关联的第一用户是第二终端关联的第二用户的联系人,也即第一用户使用第一终端,第二用户使用第二终端,第一终端关联的第一用户的身份信息存储于第二终端中,则在图12中的(a)中“联系人和分享过的设备可见”选项1202被选中后,第二终端位于第一终端附近时可以被第一终端发现。
如果第一终端是与第二终端进行过数据分享的设备,即使第一终端关联的第一用户不是第二用户的联系人,在图12中的(a)中“联系人和分享过的设备可见”选项1202被选中后,第二终端位于第一终端附近时也可以被第一终端发现。
在联系人和分享过的设备可见的情况下,第二终端可以采用本申请实施例提供的方法,与第一终端进行身份认证。第二终端与第一终端可以根据联系人数据库和/或历史分享数据库进行初筛,初筛得到是第二用户的联系人,和/或分享过的设备,并显示在第二终端的相应区域中。
本申请实施例中,第二终端可以显示第二用户的联系人的信息,该联系人的信息包括联系人的用户信息。例如,用户信息可以包括头像信息、用户ID、用户名称等信息。第二终端还可以显示分享过的设备的信息。例如,该设备的信息可以设备名称、设备型号、设备类型、设备图像等信息。
可选的,在显示第二用户的联系人的信息时,还可以显示该联系人关联的设备的信息,如,设备名称、设备型号等。在显示分享过的设备的信息时,还可以显示该分享过的设备关联的用户的信息,如,用户名称等。
可以理解的是,本申请实施例不限定如何显示初筛结果(即第二用户的联系人,和/或分享过的设备),以及初筛结果所包含的信息。
如图12中的(b)所示,是一种显示初筛得到的联系人和设备的信息的页面示意图。图12中的(b)中显示的可以是位于当前的第二终端附近的第二用户的联系人和分享过的设备。例如,在图12中的(b)中的显示区域1204中显示的联系人1、联系人2、设备1和设备2。其中,联系人1和联系人2为第二终端相关的第二用户的联系人,设备1和设备2为与第二终端分享过数据的设备。
在本申请实施例的一种可能的实现方式中,如图12中的(c)所示,是另一种显示初筛得到的联系人和设备的信息的页面示意图。在按照本申请实施例提供的方法初筛得到附近的联系人和分享过的设备后,第二终端可以按照联系人和分享过的设备,分区域对其进行显示。例如,如图12中的(c)中所示,将附近的联系人显示在同一区域,如联系人显示区域1205中显示的联系人1和联系人2;将附近分享过的设备显示在另一区域,如设备显示区域1206中显示的设备1和设备2,本申请实施例对联系人和分享过的设备的显示方式不作限定。
可选的,第二终端中还可以其他设备和/或非联系人的信息。其中,非联系人为初筛未通过的联系人,其他设备为初筛未通过的设备。
上述显示的联系人和/或设备可以是按照本申请实施例提供的方法进行初筛后得到的。通过初筛,终端可以将附近可能的联系人和/或分享过的设备快速地显示在相应区域中,方便用户进行后续操作。
在本申请实施例中,初筛的过程可能存在一定的误差。例如,显示的联系人并非终端关联的用户的联系人,显示的分享过的设备也可能并非与该终端进行过数据分享的设备。因此,在进行数据分享时,终端还需要对上述联系人或设备作进一步的认证。
当用户希望向某一设备分享数据时,例如图12中的(d)所示,用户希望向初筛得到的设备1分享数据时,用户可以在设备显示区域1206中点击该设备1的图像。此时,当前的终端可以与设备1作进一步的认证,以确认双方具备相应的权限,可以相互进行数据的分享。
在本申请实施例的一种可能的实现方式中,图12中所示的第二终端可以是作为接收端的终端。即,接收端的第二终端可以按照相关规范的要求,开启“华为分享”功能,并设置“联系人和分享过的设备可见”。在图12中的第二终端建立起与附近其他联系人或设备的连接,并完成相互间的认证后,第二终端可以接收来自其他设备分享的数据。
在本申请实施例的另一种可能的实现方式中,图12中的第二终端作为发送端的终端,开启“华为分享”功能,并设置“联系人和分享过的设备可见”后,第二终端可以与附近其他联系人或设备连接,并完成相互间的认证。这样,认证通过的其他联系人或设备可以显示在第二终端的相应区域中。也即,认证通过的其他联系人或设备对第二终端来说,也是可见的。这样,第二终端可以作为发送端的终端,向认证通过的其他联系人或设备分享数据。
下面,结合具体的示例,对图12所示的操作过程中涉及的各个技术点,分别进行介绍。
如图13所示,是本申请实施例提供的一种身份认证方法流程示意图。图13中示出了第一终端41与周边设备40相互进行身份认证的具体过程。其中,周边设备40可以包括多个终端,例如图13中的第二终端42等等。在图13中,第一终端41可以是发送端终端,周边设备40中的第二终端42可以是接收端终端,该第二终端42也即是按照本申请实施例提供的方法进行认证后,能够与第一终端41进行数据分享的设备。也即,第一终端41是数据分享的发起设备,第二终端42在认证通过后,为数据分享中的接收设备。图13所示的身份认证流程具体可以包括如下步骤S401-S406:
S401、第一终端发起广播搜索。
其中,第一终端的系统登录第一用户的账号。示例性的,第一终端的系统登录第一用户的华为账号。系统登录的账号,可称为账号。
在本申请实施例中,第一终端41可以作为发起设备,搜索周边是否存在可进行数据分享的联系人或其他设备。例如,第一终端41可以以广播的方式发起搜索。第一终端41对外广播的报文中可以包括第一用户的关系链标识和第一终端的设备哈希。该第一用户的关系链标识可以是基于第一用户的账号进行哈希运算得到的。例如,基于第一用户的账号ID进行哈希运算得到第一用户的关系链标识。第一终端的设备哈希可以是根据第一终端41的设备标识进行哈希运算得到的。例如,基于第一终端的唯一设备标识符(unique device identifier,UDID)进行哈希运算得到第一终端的设备哈希。本申请实施例对哈希运算所采用的哈希算法的类型不作限定。
在本申请实施例中,第一终端41发送的广播报文的覆盖范围可以根据第一终端41的硬件能力确定。在不同的覆盖范围下,周边设备40包含的终端的数量可能不同。本申请实施例对此不作限定。
S402、第一终端收到周边设备的广播回复。
在本申请实施例中,第一终端41附近的周边设备40可以是开启了数据分享功能的终端,例如,周边设备40中的部分或全部终端按照如图12所示开启了“华为分享”功能,并被设置为“联系人和分享过的设备可见”。
当周边设备40中的部分或全部终端接收到第一终端41发送的广播报文后,可以对该广播报文进行回复。例如,周边设备40中的第二终端42可以回复第一终端41的广播报文。
在本申请实施例的一种可能的实现方式中,第二终端42回复第一终端41的方式也可以是广播的形式,即通过广播向第一终端41回复报文。
其中,第二终端42的用户在第二终端42的系统中登录账号。示例性的,第二终端42的用户在第二终端42的系统中登录华为账号。系统登录的账号,可称为账号。
在本申请实施例的一种可能的实现方式中,第二终端42发送的广播回复中可以携带有第二用户的关系链标识和第二终端的设备哈希,该第二用户的关系链标识可以是基于第二用户的账号进行哈希运算得到的。第二终端的设备哈希可以是根据第二终端42的设备标识进行哈希运算得到的。本申请实施例对哈希运算所采用的哈希算法的类型不作限定。
在本申请实施例中,第二终端的第二用户可以是第一用户的联系人,第二终端的用户还可以是登录与第一终端41分享过的设备的用户。
在本申请实施例的一种可能的实现方式中,当第二终端42被设置为“联系人和分享过的设备可见”后,第二终端42在接收到第一终端41发送的广播报文后,可以对该广播报文进行匹配,基于广播报文,以及第二终端42的联系人数据库和/或历史分享数据库进行初筛,以确定是否向第一终端41发送广播回复。若确定发送广播回复,则将携带有第二用户的关系链标识和第二终端的设备哈希的广播回复发送给第一终端41;否则,不发送广播回复。
例如,根据广播报文中的第一用户的关系链标识和第二终端42的联系人数据库,确定第一用户是否为第二用户的联系人,若是,则向第一终端41发送广播回复,广播回复中包括第二用户的关系链标识和第二终端的设备哈希。若否,则根据第一终端41的设备哈希和第二终端42的历史分享数据库,确定第一终端41是否为与第二终端42分享过数据的设备。若是,则向第一终端41发送广播回复,广播回复中包括第二用户的关系链标识和第二终端的设备哈希。若否,则不回复广播。
可以理解的是,上述示例中,第二用户确定第一用户为第二用户的联系人,则表明第一用户和第二用户是好友,因此,第二终端可以筛选出第一用户关联的第一终端,以便后续与该第一终端交互数据。
可以理解的,以先基于联系人数据库进行判断,再基于历史分享数据库进行判断。在实际应用中,也可以先基于历史分享数据库进行判断,再基于联系人数据库进行判断。本申请对比不作限定。
可以理解的是,第二终端根据接收到的第一终端41的广播报文进行初筛的具体实现方式,与S403中第一终端41根据广播回复进行初筛的过程相同,具体过程可以参见S403部分的说明。
S403、第一终端根据广播回复进行初筛。
在本申请实施例中,第一终端41可以根据周边设备40发送的广播回复进行初筛,确定周边设备40中是否包括与第一终端41的第一用户的联系人关联的设备,以及是否与第一终端41进行过数据分享的设备。
在本申请实施例中,第一终端41根据广播回复进行初筛,可以是指第一终端41将接收到的其他设备(例如第二终端42)发送的广播回复进行处理和识别,确定是否满足筛选条件。其中,筛选条件包括:其他设备关联的用户为第一终端41的联系人,和/或,其他设备为与第一终端41分享过数据的设备。
第一终端41中可以包括本地哈希数据库,本地哈希数据库包括联系人数据库和历史分享数据库。其中,联系人数据库中可以包括第一终端41关联的第一用户的各个联系人的相关信息,历史分享数据库中可以包括与第一终端进行过数据分享的设备的相关信息。例如,联系人数据库中包括各个联系人的关系链标识,历史分享数据库中包括进行过数据分享的设备的设备哈希。
可选的,联系人数据库中也可以包括各个联系人关联的设备的相关信息。历史分享数据库中也可以包括进行过数据分享的设备关联的用户的相关信息。
可以理解的是,联系人数据库中的各数据可以采用表格存储,且,联系人数据库中存储的联系人的关系链标识是根据联系人的账号进行哈希运算得到的。因此,联系人数据库也可以描述为联系人列表、或联系人哈希数据表等。历史分享数据库中的各数据也可以采用表格存储,且,历史分享数据库中存储的设备的设备哈希是根据设备标识进行哈希运算得到的。因此,历史分享数据库也可以描述为历史分享列表、最近分享列表或历史分享设备哈希数据表等。本申请对此不做限制。
第一终端41可以根据广播回复在上述本地哈希数据库中进行匹配,以确定是否满足筛选条件。
例如,以第一终端41接收到第二终端42的广播回复为例,该广播回复中包括第二用户的关系链标识和/或第二终端的设备哈希。第一终端41根据广播回复中的第二用户的关系链标识和/或第二终端的设备哈希在第一终端41的本地哈希数据库中进行匹配,以确定是否满足筛选条件。在确定第二用户为第一用户的联系人,和/或,第二终端42为与第一终端41分享过数据的设备的情况下,确定满足筛选条件。
其中,第二终端42与第一终端41分享过数据包括第一终端41向第二终端42分享过数据,或者第二终端42向第一终端41分享过数据。
在本申请实施例的一种可能的实现方式中,第一终端41进行初筛,可以根据第一终端41的联系人数据库和/或历史分享数据库进行。
在一些示例中,第一终端41根据回复广播中的第二用户的关系链标识和第一终端41的联系人数据库,确定第二用户是否为第一用户的联系人。若联系人数据库包括第二用户的关系链标识,则确定第二用户是第一用户的联系人,满足筛选条件。若联系人数据库不包括第二用户的关系链标识,则第一终端41根据回复广播中的第二终端的设备哈希和第一终端41的历史分享数据库,确定第二终端42是否为与第一终端41分享过数据的设备。若历史分享数据库包括第二终端的设备哈希,则确定第二终端42是与第一终端41分享过数据的设备,满足筛选条件。否则,确定第二用户不是第一用户的联系人,且第二终端42是与第一终端41分享过数据的设备,不满足筛选条件。
在另一些示例中,第一终端41根据回复广播中的第二终端的设备哈希和第一终端41的历史分享数据库,确定第二终端42是否为与第一终端41分享过数据的设备。若历史分享数据库包括第二终端的设备哈希,则确定第二终端42是与第一终端41分享过数据的设备,满足筛选条件。否则,第一终端41根据回复广播中的第二用户的关系链标识和第一终端41的联系人数据库,确定第二用户是否为第一用户的联系人。若联系人数据库包括第二用户的关系链标识,则确定第二用户是第一用户的联系人,满足筛选条件。否则,确定第二用户不是第一用户的联系人,且第二终端42是与第一终端41分享过数据的设备,不满足筛选条件。
可以理解的是,本申请实施例不限定第一终端41进行初筛的具体实现方式。
在本申请实施例中,第一终端41获取满足筛选条件的信息,以便后续进行显示。
在本申请实施例的一种可能的实现方式中,为了实现初筛过程中快速识别身份,对广播回复中进行预处理,基于预处理后的数据进行初筛。其中,预处理为截断处理。例如,广播回复中包括第二用户的关系链标识和第二设备的设备哈希,对第二用户的关系链标识和第二设备的设备哈希分别进行截断处理,基于截断处理后的第二用户的关系链标识和截断处理后的第二设备的设备哈希进行初筛。示例性的,第一终端41根据第二终端42回复的广播报文进行初筛的过程,以及第二终端42根据第一终端41发起的广播报文进行初筛的过程,均可以对广播中的数据进行预处理,再基于预处理后的数据进行初筛。
如图14所示,是本申请实施例提供的一种根据预处理后的数据进行联系人初筛的示意图。以第一终端41根据第二终端42回复的广播报文进行初筛为例,图14中示出的哈希值12345678可以是第二用户的关系链标识或第二终端的设备哈希。在对上述哈希值进行预处理时,可以选取N个字符进行截断,例如,选取前N个字符进行截断;或者,选取后N个字符截断;或者,截取第a个字符到第b个字符之间的字符等。其中,N、a、b为正整数,a<b。例如,选择前4个字符进行截断,截断后的哈希值为1234。第一终端41可以采用截断后的哈希值在本地哈希数据库中进行匹配,根据本地哈希数据库是否包含截断后的哈希值以确定是否满足筛选条件。
如图14所示,示出了本地哈希数据库中的一个哈希值12345115,该哈希值可以是第一终端41的联系人数据库中某一联系人的关系链标识,或者,历史分享数据库中某一设备的设备哈希。以前述哈希值12345678为第二用户的关系链标识,前述哈希值12345115为第一终端41的联系人数据库中某一联系人的关系链标识。在采用截断后的哈希值进行匹配时,第一终端41可以使用截断后的哈希值1234在本地哈希数据库中进行匹配。根据截断方式确定联系人数据库中的“哈希值12345115”截断后的哈希值也为1234,则确定截断后的哈希值1234能够命中联系人数据库中的哈希值12345115,即哈希值12345115中存在与截断后的哈希值相同的字符串。也就表示,截断后的哈希值1234对应的第二用户命中第一终端41的联系人数据库,第二用户为第一用户的联系人。
可以理解的是,上述示例中第一终端在接收到第二终端的广播回复后,对广播回复中的数据进行截断处理,基于截断处理后的数据进行初筛。在另一种实施例中,终端可以先对关系链标识和/或设备哈希进行截断处理。在发送广播或回复广播时,广播中可以携带截断处理后的关系链标识和/或设备哈希。对端设备可以基于截断处理后的关系链标识和/或设备哈希进行初筛,可以加快处理流程。
在本申请实施例的一种可能的实现方式中,终端的本地哈希数据库中的联系人数据库可以包括该终端关联的用户的多个联系人的关系链标识。
基于上文所述的实施例,终端可以基于系统登录的账号确定该终端的用户的关系链标识,从服务器获取终端用户的联系人的关系链标识。可以理解的是,终端获取联系人的关系链标识的具体实现方式参见上文所述,终端可以将获取的联系人的关系链标识存储至本地哈希数据库中的联系人数据库。
在本申请实施例的另一种可能的实现方式中,终端的本地哈希数据库中的历史分享数据库可以包括多个与终端分享过数据的设备的设备哈希。在终端与其他设备分享数据后,终端可以与该设备交互获取该设备的设备哈希。或者,终端可以获取该设备的设备标识,对该设备标识进行哈希运算得到该设备的设备哈希。终端可以将分享过数据的设备的设备哈希存储至本地哈希数据库中的历史分享数据库。
在本申请实施例的一种可能的实现方式中,历史分享数据库中的各个设备哈希可以具有各自的老化周期(也可以描述为预设时长),不同的设备哈希的老化周期不同。设备哈希在老化周期内是有效的。当设备哈希的保存时长超过老化周期时,该设备哈希将会成为无效的设备哈希。终端可以删除该无效的设备哈希。其中,保存时长从获取到设备哈希开始计时。
在本申请实施例的另一种可能的实现方式中,历史分享数据库中的各个设备哈希可以具有相同的老化周期。在一种示例中,当历史分享数据库中的某一设备哈希的保存时长达到该老化周期对应的时间时,该设备哈希可以成为无效的设备哈希,而其他未到达老化周期的设备哈希可以维持有效的状态。在另一种示例中,历史分享数据库中的各个设备哈希也可以同时失效。
在本申请实施例的又一种可能的实现方式中,该老化周期可以是历史分享数据库的老化周期。也即,当历史分享数据库的生成时间达到老化周期对应的时间时,该历史分享数据库失效。相应地,该历史分享数据库中的全部设备哈希均失效。
S404、第一终端显示第一界面,该第一界面包括初筛得到的联系人的信息和/或分享过的设备的信息。
对于初筛得到的联系人和/或分享过的设备(也即,该联系人和/或分享过的设备满足筛选条件),第一终端41可以按照图12中的(b)或(c)所示,将联系人的信息和/或分享过的设备的信息显示在第一界面的相应区域中。这样,用户可以选择连接某一联系人或设备,以进行数据分享。
在本申请实施例的一种可能的实现方式中,对于相同的联系人,第一终端41可以显示同一个头像,以此来表示多个联系人为同一人。
在本申请实施例的一种可能的实现方式中,一个账号可以登录多个设备,例如,用户A使用账号A分别登陆设备a、设备b和设备c。如此,设备a、设备b和设备c相关的用户均为用户A,每一设备基于账号A生成的关系链标识相同,均为关系链标识a。设备a、设备b和设备c分别基于各自的UDID生成设备哈希,设备a生成设备哈希a、设备b生成设备哈希b、设备c生成设备哈希c。如此,关系链标识a对应的设备哈希包括设备哈希a、设备哈希b和设备哈希c。可以根据关系链标识确定联系人是否相同,对于同一联系人,可以采用相同的信息表示该联系人。
S405、第一终端对初筛得到的联系人和/或分享过的设备进行认证。
在本申请实施例中,第一终端41对联系人的信息和/或分享过的设备的信息进行认证可以是在初筛完成之后进行的。在初筛完成后,第一终端41可以将筛选出的联系人的信息和/或分享过的设备的信息显示在第一界面中。
可以理解的是,由于初筛的过程并非严格的认证过程,初筛过程中根据部分信息进行匹配,且并未确定用户的账号、设备等是否安全。例如,用户的账号是否是通过官方渠道注册完成的,账号的使用者使用拥有该账号的使用权等。设备是否是正规生产的等。因此第一终端41需要对该联系人或分享过的设备作进一步的认证,通过再次验证以提升身份认证准确性以及安全性。
在本申请实施例的一种可能的实现方式中,第一终端响应于用户触控目标对象的操作,对目标对象进行认证。其中,目标对象可以是联系人的信息,或者,目标对象也可以是分享过的设备的信息。其中,第一终端响应于用户触控目标对象的操作,用于触发第一终端向目标对象对应的终端发起通信连接,可以理解成上文实施例中的第一操作。例如,目标对象包括第二用户的头像。第一设备响应于用户触控第二用户的头像的操作,对第二用户进行认证。
可以理解的是,上述实施例中,第一终端在接收到广播回复后,先基于广播回复进行初筛,再显示初筛后的数据,最后对初筛后的数据进行认证。在另一种实施例中,第一终端也可以在接收到广播后,先基于广播数据进行初筛,再对该初筛后的数据进行认证,最后显示认证通过的数据。
在一些实施例中,第一终端包括第一列表和第二列表,第一列表包括可信设备的设备标识,第二列表包括可信账号的信息。其中,可信设备为被平台或服务商认定为安全的设备,可信账号为被平台或服务商认定为安全的账号。可信设备和可信账号可以通过身份认证和信任评估后确定的。第一终端与第二用户对应的第二终端交互,获取第二终端的设备标识和第二用户的账号。根据第二终端的设备标识和第一列表认证第二终端,在第一列表包括第二终端的设备标识的情况下,第一终端根据获取到的第二用户的账号和第二列表认证第二用户。在第二列表包括第二用户的账号的情况下,根据第二用户的账号进行哈希运算得到第一认证凭证,若第一认证凭证与第二用户的关系链标识相同,则确定第二用户通过认证。和/或,根据第二终端的设备标识进行哈希运算得到第二认证凭证,若第一认证凭证与第二终端的设备哈希相同,则确定第二终端通过认证。通过上述方式,对初筛得到的联系人和/或分享过的设备进行认证。
如图15所示,是本申请实施例提供的一种认证账号的方法流程示意图,图15中示出的是在第一终端41与第二终端42完成联系人初筛后,相互间进行的进一步认证的流程。在完成图15所示的认证流程后,第一终端41与第二终端42可以进行数据分享。
如图15所示,第一终端41与第二终端42在进行认证时,需要相互告知对端设备自身的账号ID,即第一终端41将自身的账号ID告知第二终端42,第二终端42将自身的账号ID告知第一终端41。为了实现上述目标,第一终端41与第二终端42在进行认证之前,第一终端41与第二终端42需要获取对方的账号ID以生成各自的第二列表。第一终端41与第二终端42均需要完成一系列相同的操作。如图15所示,第一终端41与第二终端42首先需要登录账号并注册凭证,然后双方交换账号ID(账号ID也可以描述为用户身份证明(user identification,UID))以及交换账号设备认证凭据,认证账号。也即确定账号ID是否可信。其中,账号ID用于标识用户。此外,第一终端41与第二终端42还需要利用本端私钥及对端公钥进行协商。该过程可以基于密码的密钥交换协议(simple password exponential key exchange)SPEKE协议实现。这样,第一终端41与第二终端42可以获取到对端的账号ID,并存储到自身的第二列表中,以便后续进行账号认证,以验证账号ID的真实性。
第一终端与第二终端交互,获取第二用户的账号,根据第二列表和第二用户的账号认证第二用户的账号是否可信。在第二列表包括第二用户的账号的情况下,确定第二终端可信。
如图15所示,第二终端42登录的账号ID可以是联系人的手机号码。在认证时,第一终端41与第二终端42分别告知对端自身的账号ID。第一终端41可以查询对端的可信账号ID,以及账号ID与联系人映射关系表,确认对端登录的手机号码对应的联系人。然后,第一终端41可以指定一账号ID,并认证对端设备即第二终端42是否归属于该账号ID。如果第二终端42归属于被指定的账号ID,可以认为第二终端认证通过,设备属于该账号。第二终端42也可以查询对端可信账号ID,以及账号ID与联系人映射关系表,确认对端登录的手机号码对应的联系人。另一方面,第二终端42可以认证对端设备即第一终端41是否归属于数据分享业务指定的可信账号列表。如果第一终端41归属于数据分享业务指定的可信账号列表,则表示第一终端41认证通过。第二终端42对可信账号列表的查询,可以通过业务注册回调的方式进行。
可以理解的是,第一终端可以通过服务器获取第一列表。例如,服务器获取多个终端的设备标识,确定可信设备,生成第一列表。第一终端与服务器交互获取第一列表。第一终端获取第二终端的设备标识,根据第一列表和第二终端的设备标识认证第二终端是否可信。在第一列表包括第二终端的设备标识的情况下,确定第二终端可信。
可选的,还可以将账号和设备标识关联起来,建立账号和设备的关联关系,以便认证账号或设备。
在完成认证后,第一终端41的第一界面中可以更新显示认证通过后的联系人的信息或分享过的设备的信息。
S406、向认证通过的联系人或分享过的设备分享数据。
在一些实施例中,第一终端可以向认证通过的联系人对应的终端或分享过的设备分享数据。
如图16所示,是本申请实施例提供的又一种联系人认证方法流程示意图。图16示出了在区分发送方和接收方的情况下,对联系人认证过程中发送方与接收方不同的处理过程的示意图。图16中的发送方可以是前述各个实施例中的第一终端41,接收方可以是前述各个实施例中的第二终端42。
发送方的第一终端41可以对外广播,搜索周边设备中联系人的设备或分享过的设备。第二终端42可以作为接收方回复第一终端41发起的广播,二者可以通过前述各个实施例介绍的初筛及认证流程,完成对端设备的账号的认证。
在本申请实施例中,上述实施例中第二终端42的可见性为“联系人和分享过的设备可见”。如图16所示,发送方的第一终端41与接收方的第二终端42可以针对不同的场景采用不同的初筛和认证策略。
场景一:发送方有联系人和/或分享过的设备,接收方所有人可见。
即,作为发送方的第一终端41中存储有联系人的相关信息,和/或分享过的设备的相关信息,接收方的第二终端42开启了数据分享功能下“所有人可见”选项。因此,作为发送方的第一终端41可以在第二终端42开启上述“所有人可见”选项后的一定时间内发现或搜索到第二终端42。例如,10分钟内。
此时,联系人的初筛和认证策略为单向的,也即发送方的第一终端41对接收方的第二终端42进行鉴权,判断第二终端42是否可信。若是,第一终端41可以显示第二终端42或第二终端42的第二用户的信息。否则,第一终端可以不显示第二终端42或第二终端42的第二用户信息。
场景二:发送方无联系人和分享过的设备,接收方联系人和分享过的设备可见。
即,作为发送方的第一终端41中没有联系人和分享过的设备的相关信息,接收方的第二终端42开启了数据分享功能下“仅联系人和分享过的设备可见”选项。因此,作为发送方的第一终端41只有在属于第二终端42的第二用户的联系人的设备或分享过的设备的情况下,第一终端41才能够发现或搜索到第二终端42。
此时,联系人的初筛和认证策略也是单向的,也即接收方的第二终端42对发送方的第一终端41进行鉴权,判断第一终端41是否是第二用户的联系人的设备或分享过的设备。
场景三:发送方有联系人和/或分享过的设备,接收方联系人和分享过的设备可见。
即,作为发送方的第一终端41中存储有联系人的相关信息,和/或分享过的设备的相关信息。接收方的第二终端42开启了数据分享功能下“仅联系人和分享过的设备可见”选项。因此,作为发送方的第一终端41只有在属于第二终端42的第二用户的联系人的设备或分享过的设备的情况下,第一终端41才能够发现或搜索到第二终端42。
此时,联系人的初筛和认证策略可以是双向的,也即发送方的第一终端41对接收方的第二终端42进行鉴权,判断第二终端42是否可信。同时,接收方的第二终端42也对发送方的第一终端41进行鉴权,判断第一终端41是否是第二用户的联系人的设备或分享过的设备。
场景四:发送方无联系人和分享过的设备,接收方所有人可见。
即,作为发送方的第一终端41中没有联系人和分享过的设备的相关信息,接收方的第二终端42开启了数据分享功能下“所有人可见”选项。作为发送方的第一终端41可以在第二终端42开启上述“所有人可见”选项后的一定时间内发现或搜索到第二终端42。例如,10分钟内。
此时,第一终端41与第二终端42无需进行相互间的鉴权,可以按照现有技术中的方式进行数据的分享。
基于图12至图16所示的各个实施例,如图17所示,示出了本申请实施例提供的另一种通信方法的示意图,该方法可以包括如下步骤S1701-S1703:
S1701、第一终端接收用于触发第一终端搜索设备的操作。
在本申请实施例中,第一终端的系统登录第一用户的账号,第一终端存储有第一用户的关系链标识和第一终端的设备哈希,关系链标识基于终端的系统登录的用户的账号生成,设备哈希基于终端的设备标识生成。
其中,第一用户的关系链标识基于第一用户在第一终端的系统登录的账号进行哈希运算得到。例如,基于第一用户的账号ID进行哈希运算得到第一用户的关系链标识。第一终端的哈希值基于第一终端的设备标识进行哈希运算得到。例如,基于第一终端的唯一设备标识符(unique device identifier,UDID)进行哈希运算得到第一终端的设备哈希。
本申请中,关系链标识用于标识用户,不需要通过手机号、邮箱号等隐私信息标识用户,减少了用户隐私信息泄露的风险。设备哈希用于标识设备,以便快速筛选设备。
例如,触发第一终端搜索设备的操作可以是用户启动“华为分享”功能的操作,第一终端响应于该操作,搜索周边设备。
在一些实施例中,第一终端还可以响应于触发第一终端搜索设备的操作,发送第二广播,第二广播包括第一用户的关系链标识和第一终端的设备哈希。
例如,第一终端响应触发第一终端搜索设备的操作,作为发起设备,通过广播的形式,对外发送第二广播,以搜索第一终端附近的周边设备。其中,周边设备的数量可以是一个或多个,周边设备中各个设备的设备类型可以相同或不同。周边设备与第一终端的设备类型也可以相同或不同。
S1702、第一终端接收来自第二终端的第一广播,第一广播包括第二终端的第二用户的关系链标识和/或第二终端的设备哈希。
在本申请实施例中,第二终端为启动数据分享功能,且被设置为“联系人和分享过的设备可见”的终端。
可以理解的是,由于第二终端被设置为“联系人和分享过的设备可见”,因此,第二终端在接收到其他设备发送的广播后,需要根据该广播确定发送该广播的设备是否为符合“联系人和分享过的设备可见”这一条件的终端。若符合,则回复广播,以便后续连接、分享数据;否则,不回复广播。
例如,第二终端位于第一终端附近,第二终端接收到第一终端发送的第二广播,根据第二广播中的第一用户的关系链标识和第一终端的设备哈希,确定是否满足以下条件:第一用户为第二终端的联系人,和/或,第一终端为与第二终端分享过数据的设备。若满足上述任意一个条件,则第二终端生成第一广播,并将第一广播发送至第一终端,第一广播包括第二终端的第二用户的关系链标识和/或第二终端的设备哈希。
其中,第二用户的关系链标识基于第二用户在第二终端的系统登录的账号进行哈希运算得到。第二终端的哈希值基于第二终端的设备标识进行哈希运算得到。
可以理解的是,第二终端确定第一用户是否为第二用户的联系人或,第一终端是否为与第二终端分享过数据的设备的实现方式,与第一终端确定第二用户是否为第一用户的联系人,或第二终端是否为与第一终端分享过数据的设备的实现方式相同,具体实现过程可以参见S403或S1703的部分。
S1703、在满足第一条件的情况下,第一终端显示第一界面;第一条件包括根据第二用户的关系链标识确定第二用户为第一用户的联系人,和/或,根据第二终端的设备哈希确定第二终端为第一终端分享过数据的设备;第一界面包括第一对象,第一对象包括第二用户的信息,和/或,第二终端的信息。
在一些实施例中,第一终端包括联系人数据库,联系人数据库包括第一用户的联系人对应的关系链标识,该方法还包括:在联系人数据库包括至少第二用户的关系链标识的部分字节情况下,确定第二用户为第一用户的联系人。
在一些示例中,第一广播中包括第二用户的关系链标识。第一终端根据该第二用户的关系链标识在联系人数据库中进行匹配,在联系人数据库包括第二用户的关系链标识的情况下,确定第二用户为第一用户的联系人。
在另一些示例中,第一广播中包括第二用户的关系链标识。第一终端对第二用户的关系链标识进行截断处理,得到第二用户的关系链标识的部分字节。根据第二用户的关系链标识的部分字节在联系人数据库中进行匹配,在联系人数据库包括第二用户的关系链标识的部分字节的情况下,确定第二用户为第一用户的联系人。
在另一些示例中,第一广播中包括第二用户的关系链标识的部分字节。也即,第二终端对第二用户的关系链标识进行截断处理,在发送第一广播时,广播中携带第二用户的关系链标识的部分字节。第一终端在接收到第一广播后,根据第一广播中的第二用户的关系链标识的部分字节,在联系人数据库中进行匹配,在联系人数据库包括第二用户的关系链标识的部分字节的情况下,确定第二用户为第一用户的联系人。
在一些实施例中,第一终端包括历史分享数据库,历史分享数据库包括与第一终端分享过数据的设备对应的设备哈希,该方法还包括:在历史分享数据库包括至少第二终端的设备哈希的部分字节情况下,确定第二终端为与第一终端分享过数据的设备。
在一些示例中,第一广播中包括第二终端的设备哈希。第一终端根据该第二终端的设备哈希在历史分享数据库中进行匹配,在历史分享数据库包括第二终端的设备哈希的情况下,确定第二终端为与第一终端分享过数据的设备。
在另一些示例中,第一广播中包括第二终端的设备哈希。第一终端对第二终端的设备哈希进行截断处理,得到第二终端的设备哈希的部分字节。根据第二终端的设备哈希的部分字节在历史分享数据库中进行匹配,在历史分享数据库包括第二终端的设备哈希的部分字节的情况下,确定第二终端为与第一终端分享过数据的设备。
在另一些示例中,第一广播中包括第二终端的设备哈希的部分字节。也即,第二终端对第二终端的设备哈希进行截断处理,在发送第一广播时,广播中携带第二终端的设备哈希的部分字节。第一终端在接收到第一广播后,根据第一广播中的第二终端的设备哈希的部分字节,在历史分享数据库中进行匹配,在历史分享数据库包括第二终端的设备哈希的部分字节的情况下,确定第二终端为与第一终端分享过数据的设备。
在一些实施例中,在与所述第一终端分享过数据的设备的设备哈希的保存时长超过预设时长的情况下,删除与第一终端分享过数据的设备的设备哈希;预设时长为预设的历史分享数据库中与第一终端分享过数据的设备的设备哈希的保存时长。
第一终端的历史分享数据库中保存的是与第一终端进行过数据分享的设备的设备哈希。为了保证数据的实时性和准确性,避免信息冗余,可以仅存储最近与第一终端进行过数据分析的设备的设备哈希。因此,可以设置预设时长,根据预设时长保存与第一终端进行过数据分享的设备的设备哈希。预设时长为上文的老化周期。
在一些示例中,历史分享数据库中的每一设备哈希可以具有各自的预设时长,不同的设备哈希的预设时长不同。
在另一些示例中,历史分享数据库中的每一设备哈希可以具有相同的预设时长,设备哈希仅在预设时长内有效。
在一些示例中,第一广播包括第二用户的关系链标识和第二终端的设备哈希。第一终端根据该第二用户的关系链标识在联系人数据库中进行匹配,并根据该第二终端的设备哈希在历史分享数据库中进行匹配。在联系人数据库包括第二用户的关系链标识,和/或,历史分享数据库包括第二终端的设备哈希的情况,确定满足第一条件。
在另一些示例中,第一广播包括第二用户的关系链标识和第二终端的设备哈希。第一终端对第二用户的关系链标识和第二终端的设备哈希进行截断处理,分别得到第二用户的关系链标识的部分字节、第二终端的设备哈希的部分字节。根据第二用户的关系链标识的部分字节在联系人数据库中进行匹配,以及,根据第二终端的设备哈希的部分字节在历史分享数据库中进行匹配。在联系人数据库包括第二用户的关系链标识的部分字节,和/或,历史分享数据库包括第二终端的设备哈希的部分字节的情况,确定满足第一条件。
在另一些示例中,第一广播包括第二用户的关系链标识的部分字节和第二终端的设备哈希的部分字节。也即,第二终端对第二用户的关系链标识和第二终端的设备哈希进行截断处理,在发送第一广播时,广播中携带第二用户的关系链标识的部分字节和第二终端的设备哈希的部分字节第一终端根据第二用户的关系链标识的部分字节在联系人数据库中进行匹配,以及,根据第二终端的设备哈希的部分字节在历史分享数据库中进行匹配。在联系人数据库包括第二用户的关系链标识的部分字节,和/或,历史分享数据库包括第二终端的设备哈希的部分字节的情况,确定满足第一条件。
本申请中,第一终端基于联系人数据库和历史分享数据库可以快速筛选,快速确定是否满足第一条件,有助于提高认证效率。
可以理解的是,上述示例,是第一终端基于第二终端回复的第一广播进行初筛的具体实现方式。
在一些实施例中,第二用户为第一用户的联系人包括:第一终端获取到的第二用户的关系链标识与第一终端确定的第一认证标识相同,第一认证标识基于第一终端获取到的第二用户的账号确定。
在一些示例中,在第一终端确定联系人数据库包括第二用户的关系链标识之后,显示第一界面,第一界面中包括第一对象。第一终端响应于用户对第一对象的第一操作,与第二终端交互,获取第二用户的账号。根据第二用户的账号进行哈希运算得到第一认证标识,在第一终端获取到的第二用户的关系链标识与第一终端确定的第一认证标识相同的情况下,确定认证通过。与第二用户对应的第二终端建立连接,以发送数据。也即,在该示例中,先进行初筛,显示初筛结果。然后认证用户选定的对象,与认证通过的对象建立连接。
在另一些示例中,在第一终端确定联系人数据库包括第二用户的关系链标识之后,第一终端与第二终端交互,获取第二用户的账号。根据第二用户的账号进行哈希运算得到第一认证标识,在第一终端获取到的第二用户的关系链标识与第一终端确定的第一认证标识相同的情况下,确定认证通过,显示第一界面。第一界面中包括第一对象,第一对象为认证通过后的第二用户的信息,和/或,第二终端的信息。也即,在该示例中,先进行初筛,再对初筛结果进行认证,显示认证通过的初筛结果。
在一些实施例中,第二终端为第一终端分享过数据的设备包括:第一终端获取到的第二终端的设备哈希与第一终端确定的第二认证标识相同,第二认证标识基于第一终端获取到的第二终端的设备标识确定。
在一些示例中,在第一终端确定历史分享数据库包括第二终端的设备哈希之后,显示第一界面,第一界面中包括第一对象。第一终端响应于用户对第一对象的第一操作,与第二终端交互,获取第二终端的设备标识。根据第二终端的设备标识进行哈希运算得到第二认证标识,在第一终端获取到的第二终端的设备哈希与第一终端确定的第二认证标识相同的情况下,确定认证通过。与第二用户对应的第二终端建立连接,以发送数据。
在另一些示例中,在第一终端确定历史分享数据库包括第二终端的设备哈希之后,第一终端与第二终端交互,获取第二终端的设备标识。根据第二终端的设备标识进行哈希运算得到第二认证标识,在第一终端获取到的第二终端的设备哈希与第一终端确定的第二认证标识相同的情况下,确定认证通过,显示第一界面。第一界面中包括第一对象,第一对象为认证通过后的第二终端的信息,和/或,第二用户的信息。
可以理解的是,第一认证标识和第二认证标识可以是进行哈希计算后得到的完整的数据,第一认证标识和第二认证标识也可以是先进行哈希运算,再进行截断处理后得到的部分字节。
本申请中,通过认证确保设备、账号的合法性,防止虚假账号等行为,可以提高安全性,增强数据保护,防止信息泄露。而且,终端联系其他终端时,可以验证对端的合法性,可能增强通信过程的安全性,增强用户对通信的信任度,提升用户体验。
在一些实施例中,该方法还包括:接收来自第三终端的第二广播,第二广播包括第三终端的第二用户关系链标识和第三终端的设备哈希;在满足第二条件的情况下,显示第二界面,第二条件包括根据第二用户的关系链标识确定第二用户为第一用户的联系人,和/或,根据第三终端的设备哈希确定第三终端为第一终端分享过的设备,第二界面包括第一对象和第二对象,第二对象包括第二用户的信息,和/或,第三终端的信息。
可以理解的是,同一用户可以有多个终端,
可以理解的是,上述示例中一个用户拥有多个终端,如手机和平板,且登录同一账号,如账号1。当手机和平台启动数据分享功能,且设置为“联系人和分享过的设备可见”时,接收到电脑发送的广播。手机和电脑最近分享过数据,电脑和平板最近也分享过手机。因此,手机和平板分别向电脑返回广播,手机发送的广播1中携带基于账号1生成的关系链标识1,和手机的设备标识生成的设备哈希1。平板发送的广播2中携带基于账号1生成的关系链标识1,和平板的设备标识生成的设备哈希2。电脑确定手机和平板为最近分享过的设备,且手机和平台发送的广播中的关系链标识相同,均为关系链标识1。当电脑显示手机的用户的信息和平板的用户的信息时,手机的用户的信息和平板的用户的信息相同。例如,手机的用户的头像信息和平板的用户的头像信息相同。
本申请中,第一终端和第二终端进行通信时,可以基于关系链标识和设备哈希进行身份认证,而不需要通过手机号、邮箱号等隐私信息进行身份认证,减少了用户的隐私信息泄露的风险,增加了通信的安全性和效率。而且,基于关系链标识和设备哈希进行身份认证,简化了身份认证的操作流程,提高了身份认证的效率。
上述主要是从方法的角度对本申请实施例提供的方案进行了介绍。可以理解的是,电子设备为了实现上述功能,其包含了执行各个功能相应的硬件结构和/或软件模块。结合本申请中所公开的实施例描述的各示例的单元及算法步骤,本申请实施例能够以硬件或硬件和计算机软件的结合形式来实现。某个功能究竟以硬件还是计算机驱动硬件的方式来执行,取决于技术方案的特定应用和设计约束条件。本领域技术人员可以对每个特定的应用来使用不同的方法来实现所描述的功能,但是这种实现不应认为超过本申请实施例的技术方案的范围。
本申请是实施例可以根据上述方法示例对电子设备进行功能模块的划分,例如,可以对应各个功能划分各个功能模块,也可以将两个或两个以上的功能集成在一个处理单元中。上述集成的单元既可以采用硬件的形式,也可以采用软件功能模块的形式实现。需要说明的是,本申请实施例中对单元的划分是示意性的,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式。
对应于上述图11-图17的各个实施例,参照图18,示出了本申请实施例提供的一种通信装置的结构框图,该装置可以应用于前述各个实施例中的终端,例如第一终端,该装置具体可以包括如下模块:处理模块1801、显示模块1802。
其中,处理模块1801用于支持通信装置执行图1至图9或图11-图17中的任一项的处理功能。显示模块1802用于支持通信装置执行图1至图9或图11-图17中的任一项的显示功能。
图18所示的通信装置的技术效果可以参考上述方法实施例所述方法的技术效果,此处不再赘述。图18所示的通信装置中涉及的处理模块1801可以由处理器或处理器相关电路组件实现,可以为处理器或处理模块。显示模块1802可以由显示屏相关组件实现。
可选的,通信装置可以包括至少一个处理器,处理器用于执行上述实施例中的任意一种处理功能。通信装置。通信装置还可以包括通信接口,通信接口用于接收和/或发送信号。
如图19所示,为本申请实施例提供的一种电子设备的结构示意图,该电子设备2200可用于实现以上各个方法实施例中记载的方法。如执行第一终端在各个方法实施例中记载的方法。再如,执行服务器在各个方法实施例中记载的方法。示例性的,该电子设备2200具体可以包括:处理单元2201和显示单元2202。
其中,处理单元2201用于支持电子设备2200执行图1至图9或图11-图17中任一项的处理功能。
显示单元2202为可选的,显示单元2202用于支持电子设备2200执行图1至图9或图11-图17中任一项的显示功能。
可选的,图19所示的电子设备2200还可以包括通信单元(图19中未示出),该通信单元,用于支持电子设备2200执行本申请实施例中电子设备与其他电子设备之间通信的步骤。
可选的,图19所示的电子设备2200还可以包括存储单元2203,该存储单元2203存储有程序或指令。当处理单元2201执行该程序或指令时,使得图19所示的电子设备2200可以执行上述方法实施例所示的方法。
图19所示的电子设备2200的技术效果可以参考上述方法实施例所示方法的技术效果,此处不再赘述。图19所示的电子设备2200中涉及的处理单元2201可以由处理器或处理器相关电路组件实现,可以为处理器或处理模块。通信单元可以由收发器或收发器相关电路组件实现,可以为收发器或收发模块。显示单元2202可以由显示屏相关组件实现。
本申请实施例还提供一种芯片系统,如图20所示,该芯片系统包括至少一个处理器2301和至少一个接口电路2302。处理器2301和接口电路2302可通过线路互联。例如,接口电路2302可用于从其它装置接收信号。又例如,接口电路2302可用于向其它装置(例如处理器2301)发送信号。示例性的,接口电路2302可读取存储器中存储的指令,并将该指令发送给处理器2301。当指令被处理器2301执行时,可使得电子设备执行上述实施例中的电子设备执行的各个步骤。当然,该芯片系统还可以包含其他分立器件,本申请实施例对此不作具体限定。
可选地,该芯片系统中的处理器可以为一个或多个。该处理器可以通过硬件实现也可以通过软件实现。当通过硬件实现时,该处理器可以是逻辑电路、集成电路等。当通过软件实现时,该处理器可以是一个通用处理器,通过读取存储器中存储的软件代码来实现。
可选地,该芯片系统中的存储器也可以为一个或多个。该存储器可以与处理器集成在一起,也可以和处理器分离设置,本申请并不限定。示例性的,存储器可以是非瞬时性处理器,例如只读存储器ROM,其可以与处理器集成在同一块芯片上,也可以分别设置在不同的芯片上,本申请对存储器的类型,以及存储器与处理器的设置方式不作具体限定。
示例性的,该芯片系统可以是现场可编程门阵列(field programmable gate array,FPGA),可以是专用集成芯片(application specific integrated circuit,ASIC),还可以是系统芯片(system on chip,SoC),还可以是中央处理器(central processor unit,CPU),还可以是网络处理器(network processor,NP),还可以是数字信号处理电路(digital signal processor,DSP),还可以是微控制器(micro controller unit,MCU),还可以是可编程控制器(programmable logic device,PLD)或其他集成芯片。
应理解,上述方法实施例中的各步骤可以通过处理器中的硬件的集成逻辑电路或者软件形式的指令完成。结合本申请实施例所公开的方法步骤可以直接体现为硬件处理器执行完成,或者用处理器中的硬件及软件模块组合执行完成。
本申请实施例还提供一种计算机存储介质,该计算机存储介质中存储有计算机指令,当该计算机指令在电子设备上运行时,使得电子设备执行上述方法实施例所述的方法。
本申请实施例提供一种计算机程序产品,该计算机程序产品包括:计算机程序或指令,当计算机程序或指令在计算机上运行时,使得该计算机执行上述方法实施例所述的方法。
另外,本申请实施例还提供一种装置,这个装置具体可以是芯片,组件或模块,该装置可包括相连的处理器和存储器;其中,存储器用于存储计算机执行指令,当装置运行时,处理器可执行存储器存储的计算机执行指令,以使装置执行上述各方法实施例中的方法。
其中,本实施例提供的电子设备、计算机存储介质、计算机程序产品或芯片均用于执行上文所提供的对应的方法,因此,其所能达到的有益效果可参考上文所提供的对应的方法中的有益效果,此处不再赘述。
通过以上实施方式的描述,所属领域的技术人员可以了解到,为描述的方便和简洁,仅以上述各功能模块的划分进行举例说明,实际应用中,可以根据需要而将上述功能分配由不同的功能模块完成,即将装置的内部结构划分成不同的功能模块,以完成以上描述的全部或者部分功能。
在本申请所提供的几个实施例中,应该理解到,所揭露的装置和方法,可以通过其它的方式实现。各实施例在不冲突的情况下可以相互结合或相互参考。以上所描述的装置实施例仅仅是示意性的,例如,模块或单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个装置,或一些特征可以忽略,或不执行。另一点,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口,装置或单元的间接耦合或通信连接,可以是电性,机械或其它的形式。
作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是一个物理单元或多个物理单元,即可以位于一个地方,或者也可以分布到多个不同地方。可以根据实际的需要选择其中的部分或者全部单元来实现本实施例方案的目的。
另外,在本申请各个实施例中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用软件功能单元的形式实现。
集成的单元如果以软件功能单元的形式实现并作为独立的产品销售或使用时,可以存储在一个可读取存储介质中。基于这样的理解,本申请实施例的技术方案本质上或者说对现有技术做出贡献的部分或者该技术方案的全部或部分可以以软件产品的形式体现出来,该软件产品存储在一个存储介质中,包括若干指令用以使得一个设备(可以是单片机,芯片等)或处理器(processor)执行本申请各个实施例方法的全部或部分步骤。而前述的存储介质包括:U盘、移动硬盘、只读存储器(read only memory,ROM)、随机存取存储器(random access memory,RAM)、磁碟或者光盘等各种可以存储程序代码的介质。
以上内容,仅为本申请的具体实施方式,但本申请的保护范围并不局限于此,任何熟悉本技术领域的技术人员在本申请揭露的技术范围内,可轻易想到变化或替换,都应涵盖在本申请的保护范围之内。因此,本申请的保护范围应以权利要求的保护范围为准。

Claims (27)

  1. 一种通信方法,其特征在于,应用于第一终端,所述第一终端的系统登录第一用户的账号,所述第一终端存储有所述第一用户的关系链标识,和第二用户的关系链标识,所述第二用户是所述第一用户的联系人,所述关系链标识基于终端的系统登录的用户的账号生成;
    所述方法包括:
    接收向所述第二用户发起通信连接的第一操作;
    响应于所述第一操作,基于所述第二用户的关系链标识获取所述第二用户的第二终端的通信标识;
    基于所述通信标识,向所述第二终端发送通信连接请求。
  2. 根据权利要求1所述的方法,其特征在于,所述方法还包括:
    向服务器发送所述第一用户的联系方式和所述第一用户的关系链标识。
  3. 根据权利要求1-2中任一项所述的方法,其特征在于,所述方法还包括:
    接收添加第三用户为联系人的第三操作;
    响应于所述第三操作,向服务器发送所述第三用户的联系方式;
    接收并存储所述服务器发送的所述第三用户的关系链标识。
  4. 根据权利要求1-3中任一项所述的方法,其特征在于,所述方法还包括:
    接收删除第四用户为联系人的第四操作;
    响应于所述第四操作,删除存储的所述第四用户的关系链标识。
  5. 根据权利要求4所述的方法,其特征在于,所述方法还包括:
    响应于所述第四操作,向所述服务器发送所述第四用户的联系方式。
  6. 根据权利要求1-5中任一项所述的方法,其特征在于,所述第一终端还存储有第五用户的联系方式和所述第五用户的关系链标识,所述第五用户是所述第一用户的联系人;
    所述方法还包括:
    接收将所述第五用户的联系方式由第一联系方式更新为第二联系方式的第五操作;
    响应于所述第五操作,将与所述第五用户的关系链标识的对应的联系方式由所述第一联系方式更新为所述第二联系方式。
  7. 根据权利要求6所述的方法,其特征在于,所述方法还包括:
    响应于所述第五操作,向所述服务器发送所述第五用户的所述第一联系方式和所述第二联系方式。
  8. 根据权利要求1-7中任一项所述的方法,其特征在于,所述第一终端还存储有所述第一用户的至少一个联系人的联系方式,所述联系人的联系方式与所述联系人的关系链标识一一对应;
    所述方法还包括:
    接收服务器发送的通知消息,所述通知消息用于通知所述第一终端修改存储的联系方式与关系链标识的关联关系;
    其中,所述修改存储的联系方式与关系链标识的关联关系包括以下一个或多个:
    删除所述第一用户的至少一个联系人中第六用户的联系方式与关系链标识的关联关系;
    更新所述第一用户的至少一个联系人中第七用户的关系链标识对应的联系方式;
    增加第八用户的联系方式与关系链标识的关联关系。
  9. 根据权利要求1-8中任一项所述的方法,其特征在于,所述通信连接请求用于发起音视频通信;
    所述第一终端还存储有所述第一用户的至少一个联系人的能力信息,所述联系人的能力信息与所述联系人的关系链标识一一对应,所述能力信息用于指示对应联系人是否具备音视频通信能力;
    所述第二用户的所述能力信息用于指示所述第二用户具备音视频通信能力。
  10. 根据权利要求9所述的方法,其特征在于,所述方法还包括:
    向服务器发送所述第一用户的所述能力信息。
  11. 一种通信方法,其特征在于,应用于服务器,所述方法包括:
    接收来自第一终端的第一用户的至少一个联系人的联系方式;
    向所述第一终端发送所述第一用户的至少一个联系人的关系链标识。
  12. 根据权利要求11所述的方法,其特征在于,所述至少一个联系人包括第二用户;
    在向所述第一终端发送所述第一用户的至少一个联系人的关系链标识之前,所述方法还包括:
    接收所述第二用户的第二终端发送的所述第二用户的联系方式和所述第二用户的关系链标识。
  13. 根据权利要求11或12所述的方法,其特征在于,所述方法还包括:
    接收所述第一终端发送的修改的所述第一用户的联系方式;所述修改包括以下一个或多个,添加联系方式,将删除联系方式,更新联系方式;
    向第三终端发送第一通知消息,所述第一通知消息用于通知所述第三终端修改所述第一用户的联系方式和所述第一用户的关系链标识的关联关系;所述第三终端的用户的联系人的联系方式包括添加的所述第一用户的联系方式。
  14. 根据权利要求11-13中任一项所述的方法,其特征在于,所述方法还包括:
    接收来自所述第一终端的修改的第三用户的联系方式;所述修改包括以下一个或多个,添加所述第三用户为联系人,将从联系人中删除所述第三用户,更新所述第三用户的联系方式;
    向第四终端发送第二通知消息,所述第二通知消息用于通知所述第四终端修改存储的联系方式与关系链标识的关联关系,所述第四终端登录的账号与所述第一终端登录的账号相同。
  15. 一种通信方法,其特征在于,应用于第一终端,所述第一终端的系统登录第一用户的账号,所述第一终端存储有所述第一用户的关系链标识和所述第一终端的设备哈希,所述关系链标识基于终端的系统登录的用户的账号生成,所述设备哈希基于终端的设备标识生成;所述方法包括:
    接收用于触发所述第一终端搜索设备的操作;
    接收来自第二终端的第一广播,所述第一广播包括所述第二终端的第二用户的关系链标识和/或所述第二终端的设备哈希;
    在满足第一条件的情况下,显示第一界面;所述第一条件包括根据第二用户的关系链标识确定所述第二用户为所述第一用户的联系人,和/或,根据所述第二终端的设备哈希确定所述第二终端为所述第一终端分享过数据的设备;所述第一界面包括第一对象,所述第一对象包括所述第二用户的信息,和/或,第二终端的信息。
  16. 根据权利要求15所述的方法,其特征在于,所述第一终端包括联系人数据库,所述联系人数据库包括所述第一用户的联系人对应的关系链标识,所述方法还包括:
    在所述联系人数据库包括至少所述第二用户的关系链标识的部分字节情况下,确定所述第二用户为所述第一用户的联系人。
  17. 根据权利要求15所述的方法,其特征在于,所述第一终端包括历史分享数据库,所述历史分享数据库包括与所述第一终端分享过数据的设备对应的设备哈希,所述方法还包括:
    在所述历史分享数据库包括至少所述第二终端的设备哈希的部分字节情况下,确定所述第二终端为与所述第一终端分享过数据的设备。
  18. 根据权利要求15或16所述的方法,其特征在于,所述第二用户为所述第一用户的联系人包括:所述第一终端获取到的所述第二用户的关系链标识与所述第一终端确定的第一认证标识相同,所述第一认证标识基于所述第一终端获取到的所述第二用户的账号确定。
  19. 根据权利要求15或17所述的方法,其特征在于,所述第二终端为所述第一终端分享过数据的设备包括:所述第一终端获取到的所述第二终端的设备哈希与所述第一终端确定的第二认证标识相同,所述第二认证标识基于所述第一终端获取到的所述第二终端的设备标识确定。
  20. 根据权利要求15-19中任一项所述的方法,其特征在于,所述方法还包括:
    接收来自第三终端的第二广播,所述第二广播包括所述第三终端的第二用户关系链标识和所述第三终端的设备哈希;
    在满足第二条件的情况下,显示所述第二界面,所述第二条件包括根据所述第二用户的关系链标识确定所述第二用户为所述第一用户的联系人,和/或,根据所述第三终端的设备哈希确定所述第三终端为所述第一终端分享过的设备,所述第二界面包括所述第一对象和第二对象,所述第二对象包括所述第二用户的信息,和/或,所述第三终端的信息。
  21. 根据权利要求17所述的方法,其特征在于,所述方法还包括:
    在所述与所述第一终端分享过数据的设备的设备哈希的保存时长超过预设时长的情况下,删除所述与所述第一终端分享过数据的设备的设备哈希;所述预设时长为预设的所述历史分享数据库中所述与所述第一终端分享过数据的设备的设备哈希的保存时长。
  22. 一种通信装置,其特征在于,包括:至少一个处理器,所述处理器被配置执行如权利要求1-14或15-21中任一项所述的方法。
  23. 根据权利要求22所述的通信装置,其特征在于,所述通信装置还包括:通信接口,所述通信接口用于接收和/或发送信号。
  24. 一种电子设备,其特征在于,包括:处理器和存储器,所述存储器与所述处理器耦合,所述存储器用于存储程序代码,所述程序代码包括指令,所述处理器从所述存储器中读取所述指令,以使得所述电子设备执行如权利要求1-14或15-21中任一项所述的方法。
  25. 一种计算机可读存储介质,其特征在于,所述计算机可读存储介质包括计算机程序,当所述计算机程序在电子设备上运行时,使得所述电子设备执行如权利要求1-14或15-21中任一项所述的方法。
  26. 一种计算机程序产品,其特征在于,所述计算机程序产品包括:计算机程序或指令,当所述计算机程序或指令在计算机上运行时,使得所述计算机执行如权利要求1-14或15-21中任一项所述的方法。
  27. 一种通信系统,其特征在于,包括第一终端以及服务器,所述第一终端用于执行如权利要求1-10或15-21中任一项所述的方法,所述服务器用于执行如权利要求11-14中任一项所述的方法。
PCT/CN2024/140071 2024-06-20 2024-12-17 一种通信方法及装置 Pending WO2025260656A1 (zh)

Applications Claiming Priority (8)

Application Number Priority Date Filing Date Title
CN202410808178.2 2024-06-20
CN202410808194 2024-06-20
CN202410808178 2024-06-20
CN202410808194.1 2024-06-20
CN202411109200 2024-08-12
CN202411109200.0 2024-08-12
CN202411507240.0A CN121193707A (zh) 2024-06-20 2024-10-25 一种通信方法及装置
CN202411507240.0 2024-10-25

Publications (1)

Publication Number Publication Date
WO2025260656A1 true WO2025260656A1 (zh) 2025-12-26

Family

ID=95447477

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2024/140071 Pending WO2025260656A1 (zh) 2024-06-20 2024-12-17 一种通信方法及装置

Country Status (2)

Country Link
CN (1) CN119892789A (zh)
WO (1) WO2025260656A1 (zh)

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR20100088861A (ko) * 2009-02-02 2010-08-11 주식회사 유섹 컨택센터 고객의 개인정보 보호 방법 및 그 시스템
CN105376733A (zh) * 2015-09-30 2016-03-02 联想(北京)有限公司 信息处理方法及电子设备
CN106533917A (zh) * 2016-11-24 2017-03-22 腾讯科技(深圳)有限公司 关系链处理方法、装置及系统
CN113051605A (zh) * 2021-03-08 2021-06-29 西南林业大学 一种基于区块链的个人隐私信息使用管理系统及方法
CN114244954A (zh) * 2021-12-19 2022-03-25 王恩惠 一种查找通讯录联系人是否为通讯录好友的方法及系统

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
FR2983023A1 (fr) * 2011-11-21 2013-05-24 France Telecom Procede de gestion de la mise en relation numerique.
WO2018133853A1 (zh) * 2017-01-22 2018-07-26 华为技术有限公司 一种通信方法及设备
CN114895991B (zh) * 2021-02-05 2024-06-25 华为技术有限公司 内容分享方法和电子设备

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR20100088861A (ko) * 2009-02-02 2010-08-11 주식회사 유섹 컨택센터 고객의 개인정보 보호 방법 및 그 시스템
CN105376733A (zh) * 2015-09-30 2016-03-02 联想(北京)有限公司 信息处理方法及电子设备
CN106533917A (zh) * 2016-11-24 2017-03-22 腾讯科技(深圳)有限公司 关系链处理方法、装置及系统
CN113051605A (zh) * 2021-03-08 2021-06-29 西南林业大学 一种基于区块链的个人隐私信息使用管理系统及方法
CN114244954A (zh) * 2021-12-19 2022-03-25 王恩惠 一种查找通讯录联系人是否为通讯录好友的方法及系统

Also Published As

Publication number Publication date
CN119892789A (zh) 2025-04-25

Similar Documents

Publication Publication Date Title
CN112205019B (zh) 用于使计算设备能够识别何时彼此接近的技术
US20220038458A1 (en) Multifactor Authentication for Internet-of-Things Devices
CN102497635B (zh) 服务器、终端和账户密码获取方法
CA2823983C (en) Constructing a contact sharing history
TWI654534B (zh) 身份認證方法、裝置及伺服器
KR101130405B1 (ko) 아이덴티티 인식 방법 및 시스템
US12177768B2 (en) Maintaining access to services via SIM card
JP2011120213A (ja) 発呼者の位置、プロファイル及び信頼関係のリアルタイム表示の方法及びシステム
CN103647785A (zh) 一种移动终端安全的控制方法、装置及系统
CN101589569A (zh) 至网络中的客户端设备的安全口令分发
JP2017532926A (ja) マルチナンバーサービス提供方法
CN104079659A (zh) 一种基于随机代理的位置服务匿名查询系统及其使用方法
CN105991717A (zh) 文件分享方法及系统
CN116962114A (zh) 基于分布式软总线的设备互联方法、装置、设备及介质
CN107113320A (zh) 一种下载签约文件的方法、相关设备及系统
CN115694847A (zh) 一种设备管理方法、系统以及装置
WO2019185709A1 (en) Electronic device management
CN114554567A (zh) 通信的方法及通信装置
CN114553440B (zh) 基于区块链和属性签名的跨数据中心身份认证方法及系统
CN110168550A (zh) 基于随机数的数据消息认证
WO2017210914A1 (zh) 传输信息的方法和装置
WO2025260656A1 (zh) 一种通信方法及装置
CN113946739B (zh) 敏感数据查询方法、装置、设备及存储介质
CN113055254B (zh) 一种地址配置方法、装置、接入服务器及存储介质
CN108985765A (zh) 企业用户信息处理方法、设备及存储介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 24945381

Country of ref document: EP

Kind code of ref document: A1