Method for controlling permission of application and electronic device supporting the same

KR103005291B1Active Publication Date: 2026-08-14SAMSUNG ELECTRONICS CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
KR1020210038136
Authority / Receiving Office
KR · KR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-03-24
Publication Date
2026-08-14
Estimated Expiration
2041-03-24

Smart Images

  • Figure 112021034690492-PAT00002_ABST
    Figure 112021034690492-PAT00002_ABST
Patent Text Reader

Abstract

An electronic device according to one embodiment disclosed in this document comprises a display, a communication module, a memory, and a processor. The processor, using the communication module, receives first authority evaluation information from a server, generates second authority evaluation information based on authority usage information of at least one application obtained within the electronic device, determines an evaluation result regarding the permission of at least one authority associated with the at least one application based on the first authority evaluation information or the second authority evaluation information, and can display a user notification regarding the at least one authority on the display based on the evaluation result. In addition to this, various other embodiments identified through the specification are possible.
Need to check novelty before this filing date? Find Prior Art

Description

Technology Field

[0001] Various embodiments of this document relate to a method for controlling the rights of an application and an electronic device supporting the same. Background Technology

[0002] Electronic devices such as smartphones and tablet PCs can run various applications. An electronic device can install an application by receiving and executing an application installation file from an external server. Alternatively, the electronic device may have an application installed at the time of manufacture.

[0003] When an application is executed, the application may generate a request (hereinafter referred to as a permission request) to allow permission to use designated functions, modules, internal devices, or hardware resources of an electronic device, or to access and use specific data. For example, when an application is installed, a permission request regarding location information, camera usage, or file data access may be generated. Different permissions may be required depending on the type of device or data that the application intends to use.

[0004] An electronic device may receive user input by displaying a user interface or user notification that prompts the user to confirm whether to allow the permission in response to a request for permission usage. In response to the user input, the electronic device may allow or deny the permission to the application. The problem to be solved

[0005] When applications are installed or run on electronic devices, they often possess more permissions than necessary, and there is a problem in that it is difficult to block permissions once they have been granted. Furthermore, if an application holds more permissions than required, personal information may be leaked or illegal information may be collected, so it is necessary to restrict such permissions.

[0006] Embodiments according to various embodiments of this document can provide an electronic device capable of evaluating the permissions of an application through various criteria and notifying the user of the appropriateness of permission granting. means of solving the problem

[0007] The electronic device includes a display, a communication module, a memory, and a processor, and the processor can use the communication module to receive first authority evaluation information from a server, generate second authority evaluation information based on authority usage information of at least one application obtained within the electronic device, determine an evaluation result regarding the permission of at least one authority related to the at least one application based on the first authority evaluation information or the second authority evaluation information, and display a user notification regarding the at least one authority on the display based on the evaluation result. Effects of the invention

[0008] An electronic device according to the various embodiments disclosed in this document can notify a user of the appropriateness of application setting permissions based on category evaluation, user evaluation, and usability evaluation.

[0009] An electronic device according to the various embodiments disclosed in this document can evaluate whether the permission is appropriate in the first instance through external data learning and in the second instance through internal data learning.

[0010] The electronic device according to the various embodiments disclosed in this document can increase the reliability of evaluation criteria by updating the application's category evaluation, user evaluation, or usability evaluation based on the results of the user's permission grant. Brief explanation of the drawing

[0011] FIG. 1 is a block diagram of an electronic device in a network environment according to various embodiments. FIG. 2 shows an authorization evaluation system according to various embodiments. FIG. 3 illustrates a method for controlling the rights of an application according to various embodiments. FIG. 4 illustrates a permission control method when a permission usage request occurs in an application according to various embodiments. FIG. 5 is an example diagram showing a first type of user notification according to various embodiments. FIG. 6 illustrates a permission control method for changing permission permission after permission has been granted to an application according to various embodiments. FIG. 7 is an example of a first type of user notification after permission has been granted according to various embodiments. FIG. 8 illustrates the automatic change of authority based on the authority evaluation results according to various embodiments. In relation to the description of the drawings, the same or similar reference numerals may be used for identical or similar components. Specific details for implementing the invention

[0012] Hereinafter, various embodiments of this document are described with reference to the accompanying drawings. However, this is not intended to limit the technology described in this document to specific embodiments and should be understood to include various modifications, equivalents, and / or alternatives to the embodiments of this document. In relation to the description of the drawings, similar reference numerals may be used for similar components.

[0013] FIG. 1 is a block diagram of an electronic device (101) in a network environment (100) according to various embodiments. The electronic device according to the various embodiments disclosed in this document may be a device of various forms. The electronic device may include, for example, at least one of a portable communication device (e.g., a smartphone), a computer device (e.g., a personal digital assistant (PDA), a tablet PC, a laptop PC (desktop PC, workstation, or server), a portable multimedia device (e.g., an e-book reader or MP3 player), a portable medical device (e.g., a heart rate, blood glucose, blood pressure, or body temperature monitor), a camera, or a wearable device. The wearable device may include at least one of an accessory type (e.g., a watch, ring, bracelet, anklet, necklace, glasses, contact lens, or head-mounted device (HMD)), a fabric or clothing integrated type (e.g., electronic clothing), a body-attached type (e.g., a skin pad or tattoo), or a bio-implantable circuit. In some embodiments, the electronic device may include, for example, a television, a DVD (digital video disk) player, an audio device, an audio accessory device (e.g., a speaker, headphones, or a headset), a refrigerator, an air conditioner, a vacuum cleaner, an oven, a microwave oven, a washing machine, an air purifier, a set-top box, or a home automation control. It may include at least one of a panel, a security control panel, a game console, an electronic dictionary, an electronic key, a camcorder, or an electronic photo frame.

[0014] In other embodiments, the electronic device may include at least one of a navigation device, a satellite navigation system (GNSS (global navigation satellite system)), an event data recorder (EDR) (e.g., a black box for a vehicle / ship / aircraft), an automotive infotainment device (e.g., a head-up display for a vehicle), an industrial or domestic robot, a drone, an automated teller machine (ATM), a point of sales (POS) device, a measuring device (e.g., a water, electricity, or gas meter), or an Internet of Things device (e.g., a light bulb, a sprinkler system, a fire alarm, a thermostat, or a street light). The electronic device according to the embodiments of this document is not limited to the aforementioned devices and may also provide a combination of the functions of multiple devices, such as in the case of a smartphone equipped with a function to measure personal biometric information (e.g., heart rate or blood glucose). In this document, the term "user" may refer to a person using the electronic device or a device using the electronic device (e.g., an artificial intelligence electronic device).

[0015] In a network environment (100), an electronic device (101) may communicate with an electronic device (102) through a first network (198) (e.g., a short-range wireless communication network) or with an electronic device (104) or a server (108) through a second network (199) (e.g., a long-range wireless communication network). According to one embodiment, the electronic device (101) may communicate with an electronic device (104) through a server (108). According to one embodiment, the electronic device (101) may include a processor (120), memory (130), input device (150), sound output device (155), display device (160), audio module (170), sensor module (176), interface (177), connection terminal (178), haptic module (179), camera module (180), power management module (188), battery (189), communication module (190), subscriber identification module (196), or antenna module (197). In some embodiments, at least one of these components (e.g., connection terminal (178)) may be omitted from the electronic device (101), or one or more other components may be added. In some embodiments, some of these components (e.g., sensor module (176), camera module (180), or antenna module (197)) may be integrated into a single component (e.g., display device (160)).

[0016] The processor (120) can control at least one other component (e.g., a hardware or software component) of the electronic device (101) connected to the processor (120) by executing software (e.g., a program (140)), for example, and can perform various data processing or operations. According to one embodiment, as at least part of the data processing or operations, the processor (120) can store commands or data received from other components (e.g., a sensor module (176) or a communication module (190)) in volatile memory (132), process the commands or data stored in volatile memory (132), and store the resulting data in non-volatile memory (134). According to one embodiment, the processor (120) may include a main processor (121) (e.g., a central processing unit or an application processor) or an auxiliary processor (123) that can operate independently or together with it (e.g., a graphics processing unit, an image signal processor, a sensor hub processor, or a communication processor). For example, if the electronic device (101) includes a main processor (121) and an auxiliary processor (123), the auxiliary processor (123) may be configured to use lower power than the main processor (121) or to be specialized for a designated function. The auxiliary processor (123) may be implemented separately from the main processor (121) or as part thereof.

[0017] The auxiliary processor (123) can control at least some of the functions or states associated with at least one component of the electronic device (101) (e.g., display device (160), sensor module (176), or communication module (190)) on behalf of the main processor (121) while the main processor (121) is in an inactive (e.g., sleep) state, or together with the main processor (121) while the main processor (121) is in an active (e.g., application execution) state. According to one embodiment, the auxiliary processor (123) (e.g., image signal processor or communication processor) may be implemented as part of another functionally related component (e.g., camera module (180) or communication module (190)).

[0018] The memory (130) can store various data used by at least one component of the electronic device (101) (e.g., processor (120) or sensor module (176)). The data may include, for example, software (e.g., program (140)) and input data or output data for related commands. The memory (130) may include volatile memory (132) or non-volatile memory (134).

[0019] The program (140) may be stored as software in memory (130) and may include, for example, an operating system (142), middleware (144), or an application (146).

[0020] The input device (150) can receive commands or data to be used for a component of the electronic device (101) (e.g., processor (120)) from outside the electronic device (101) (e.g., user). The input device (150) may include, for example, a microphone, a mouse, a keyboard, or a digital pen (e.g., a stylus pen).

[0021] The sound output device (155) can output a sound signal to the outside of the electronic device (101). The sound output device (155) may include, for example, a speaker or a receiver. The speaker may be used for general purposes, such as multimedia playback or recording playback. The receiver may be used to receive incoming calls. According to one embodiment, the receiver may be implemented separately from the speaker or as part thereof.

[0022] The display device (160) can visually provide information to an external (e.g., user) of the electronic device (101). The display device (160) may include, for example, a display, a holographic device, or a projector and a control circuit for controlling said device. According to one embodiment, the display device (160) may include a touch sensor configured to detect a touch, or a pressure sensor configured to measure the intensity of the force generated by said touch.

[0023] The audio module (170) can convert sound into an electrical signal or, conversely, convert an electrical signal into sound. According to one embodiment, the audio module (170) can acquire sound through an input device (150) or output sound through an audio output device (155) or an external electronic device (e.g., electronic device (102)) (e.g., speaker or headphones) that is directly or wirelessly connected to the electronic device (101).

[0024] The sensor module (176) can detect the operating state of the electronic device (101) (e.g., power or temperature) or the external environmental state (e.g., user state) and generate an electrical signal or data value corresponding to the detected state. According to one embodiment, the sensor module (176) may include, for example, a gesture sensor, a gyroscope sensor, a barometric pressure sensor, a magnetic sensor, an accelerometer sensor, a grip sensor, a proximity sensor, a color sensor, an IR (infrared) sensor, a biosensor, a temperature sensor, a humidity sensor, or an illuminance sensor.

[0025] The interface (177) may support one or more specified protocols that can be used for the electronic device (101) to be connected directly or wirelessly to an external electronic device (e.g., electronic device (102)). According to one embodiment, the interface (177) may include, for example, a high definition multimedia interface (HDMI), a universal serial bus (USB) interface, an SD card interface, or an audio interface.

[0026] The connection terminal (178) may include a connector through which the electronic device (101) can be physically connected to an external electronic device (e.g., electronic device (102)). According to one embodiment, the connection terminal (178) may include, for example, an HDMI connector, a USB connector, an SD card connector, or an audio connector (e.g., a headphone connector).

[0027] The haptic module (179) can convert an electrical signal into a mechanical stimulus (e.g., vibration or movement) or an electrical stimulus that the user can perceive through tactile or kinesthetic senses. According to one embodiment, the haptic module (179) may include, for example, a motor, a piezoelectric element, or an electric stimulation device.

[0028] The camera module (180) can capture still images and video. According to one embodiment, the camera module (180) may include one or more lenses, image sensors, image signal processors, or flashes.

[0029] The power management module (188) can manage the power supplied to the electronic device (101). According to one embodiment, the power management module (188) can be implemented, for example, as at least part of a power management integrated circuit (PMIC).

[0030] The battery (189) can supply power to at least one component of the electronic device (101). According to one embodiment, the battery (189) may include, for example, a non-rechargeable primary battery, a rechargeable secondary battery, or a fuel cell.

[0031] The communication module (190) can support the establishment of a direct (e.g., wired) communication channel or a wireless communication channel between an electronic device (101) and an external electronic device (e.g., electronic device (102), electronic device (104), or server (108)), and the performance of communication through the established communication channel. The communication module (190) may include one or more communication processors that operate independently of the processor (120) (e.g., application processor) and support direct (e.g., wired) communication or wireless communication. According to one embodiment, the communication module (190) may include a wireless communication module (192) (e.g., cellular communication module, short-range wireless communication module, or GNSS (global navigation satellite system) communication module) or a wired communication module (194) (e.g., LAN (local area network) communication module, or power line communication module). The corresponding communication module among these communication modules can communicate with an external electronic device (104) through a first network (198) (e.g., a short-range communication network such as Bluetooth, WiFi (wireless fidelity) direct, or IrDA (infrared data association)) or a second network (199) (e.g., a legacy cellular network, a 5G network, a next-generation communication network, the Internet, or a computer network (e.g., a LAN or WAN)). These various types of communication modules may be integrated into a single component (e.g., a single chip) or implemented as multiple separate components (e.g., multiple chips). The wireless communication module (192) can identify or authenticate the electronic device (101) within a communication network such as the first network (198) or the second network (199) using subscriber information (e.g., International Mobile Subscriber Identifier (IMSI)) stored in the subscriber identification module (196).

[0032] An antenna module (197) can transmit a signal or power to or from an external source (e.g., an external electronic device). According to one embodiment, the antenna module (197) may include an antenna comprising a radiator made of a conductor or a conductive pattern formed on a substrate (e.g., a PCB). According to one embodiment, the antenna module (197) may include a plurality of antennas (e.g., an array antenna). In this case, at least one antenna suitable for a communication method used in a communication network, such as a first network (198) or a second network (199), may be selected from the plurality of antennas, for example, by a communication module (190). A signal or power may be transmitted or received between the communication module (190) and an external electronic device through the selected at least one antenna. According to some embodiments, in addition to the radiator, other components (e.g., a radio frequency integrated circuit (RFIC)) may be additionally formed as part of the antenna module (197).

[0033] At least some of the above components can be connected to each other via a communication method between peripheral devices (e.g., bus, GPIO (general purpose input and output), SPI (serial peripheral interface), or MIPI (mobile industry processor interface)) and exchange signals (e.g., commands or data) with each other.

[0034] According to one embodiment, commands or data may be transmitted or received between the electronic device (101) and an external electronic device (104) through a server (108) connected to a second network (199). Each of the external electronic devices (102, or 104) may be the same or different type of device as the electronic device (101). According to one embodiment, all or part of the operations performed on the electronic device (101) may be performed on one or more of the external electronic devices (102, 104, or 108). For example, if the electronic device (101) needs to perform a function or service automatically or in response to a request from a user or another device, the electronic device (101) may request one or more external electronic devices to perform at least part of the function or service instead of performing the function or service itself or additionally. One or more external electronic devices that receive the above request may execute at least part of the requested function or service, or additional function or service related to the request, and transmit the result of the execution to the electronic device (101). The electronic device (101) may provide the result as is or additionally processed as at least part of the response to the request. For this purpose, for example, cloud computing, distributed computing, mobile edge computing (MEC), or client-server computing technology may be used.

[0035] The electronic device according to the various embodiments disclosed in this document may be of various forms. The electronic device may include, for example, a portable communication device (e.g., a smartphone), a computer device, a portable multimedia device, a portable medical device, a camera, a wearable device, or a consumer electronics device. The electronic device according to the embodiments of this document is not limited to the devices described above.

[0036] FIG. 2 shows an authorization evaluation system according to various embodiments.

[0037] Referring to FIG. 2, the authorization evaluation system (200) may include a server (108) (e.g., the server (108) of FIG. 1) and an electronic device (101) (e.g., the electronic device (101) of FIG. 1).

[0038] The server (108) may include an external data learning unit (205). The external data learning unit (205) may primarily evaluate the permissions required by the application based on various criteria. For example, the server (108) may be a server that operates an app market (e.g., Android - Play Store, iOS - App Store).

[0039] According to one embodiment, the external data learning unit (205) can generate first authority evaluation information including at least one of first evaluation information regarding the category of the application, second evaluation information regarding the user using the application, or third evaluation information regarding the usage pattern of the application.

[0040] In the following discussion, the focus is on cases where the server (108) determines one of positive evaluations or negative evaluations regarding the permission requested by the application, but it is not limited thereto. For example, the server (108) may determine one of "positive evaluation / neutral evaluation / negative evaluation" or "one of very positive evaluation / positive evaluation / negative evaluation / very negative evaluation" for a plurality of reference values, or may calculate and use an evaluation score. Alternatively, the server (108) may determine at least one reference value that can be evaluated regarding the permission requested by the application and transmit it to the electronic device (101).

[0041] According to one embodiment, a server (108) may generate first evaluation information (hereinafter referred to as external category evaluation) regarding a category of an application (e.g., finance, game, health, education, social, map, or shopping). The category of the application may be the same as the classification of applications applied in an app market (e.g., Android - Play Store, iOS - App Store). The server (108) may check the permissions requested by each of the applications included in the same category. The server (108) may determine the permissions requested by applications that are above (or exceed) a reference ratio within the category as positive evaluations, and the permissions requested by applications that are below (or less than) the reference ratio as negative evaluations. The following discussion focuses on the 'finance' category, but is not limited thereto.

[0042] For example, if the threshold value for a positive or negative evaluation is 90%, and more than 90% of the apps in the 'finance' category request 'phone usage' permission, the server (108) may determine the 'phone usage' permission for the apps in the 'finance' category as a positive evaluation. Or, if less than 90% of the apps in the 'finance' category request 'location information' permission, the server (108) may determine the 'location information' permission for the apps in the 'finance' category as a negative evaluation.

[0043] According to one embodiment, the server (108) may generate second evaluation information (hereinafter, external user evaluation) regarding a user using an application. The server (108) may evaluate the permissions requested by applications by obtaining results of permission being granted on the terminals of multiple users for a specified application. The server (108) may determine the permission granted on the terminals of users above (or exceeding) the threshold ratio among all users or a group according to a specific criterion (e.g., a specific country, a specific region, a specific age group, or users who have installed five or more applications of the same category) as a positive evaluation, and determine the permission not granted on the terminals of users below (or below) the threshold ratio as a negative evaluation.

[0044] For example, if the threshold value for a positive or negative evaluation is 90%, and 90% or more of all users (an unspecified number) have allowed the 'phone usage' permission in the Bank A application, the 'phone usage' permission for the Bank A application can be determined as a positive evaluation. Or, if 90% or more of all users in a designated country have allowed the 'location usage' permission in the Bank A application, the 'phone usage' permission for the Bank A application can be determined as an permission that can be allowed.

[0045] As another example, if 90% of users selected based on specific criteria allow the 'phone usage' permission in Bank A's application, the 'phone usage' permission for Bank A's application can be determined as a positive evaluation. The specific criteria may be criteria such as users who have installed five or more bank apps, users who have completed identity verification, or users registered with specific users via SNS / address book.

[0046] According to one embodiment, the server (108) may generate third evaluation information (hereinafter referred to as external usability evaluation) regarding the usage pattern of the application. The server (108) may collect the number of times or time that the permission requested by the application is used at each terminal. If the permission requested by the application is used at each terminal more than (or exceeds) a reference number of times or is used for more than (or exceeds) a specified time, the server (108) may determine the permission as a positive evaluation. Conversely, if the permission requested by the application is used at each terminal less than (or less than) the reference number of times or for less than (or less than) a specified time, the server (108) may determine the permission as a negative evaluation.

[0047] For example, if the navigation application continuously accesses the 'location usage' permission while running, the server (108) may decide to positively evaluate the use of the 'location usage' permission in the navigation application.

[0048] As another example, if the 'location usage' permission in the A bank application is accessed less than 5 times within 10 minutes, the server (108) may determine that the 'location usage' permission in the A bank application is accessed less than 5 times within 5 minutes as a positive evaluation.

[0049] According to one embodiment, the external usability evaluation may include a threshold value related to the frequency of use or usage time of the permission, rather than an evaluation result such as a positive or negative evaluation.

[0050] According to various embodiments, the server (108) may receive and reflect the results of permissions allowed or denied on each user's terminal in order to analyze numerous apps and collect and reflect evaluation results from multiple users. The server (108) may update external category evaluations, external user evaluations, or external usability evaluations through statistical methods or AI learning.

[0051] According to various embodiments, the server (108) may generate first authority evaluation information by giving weight to an external category evaluation, an external usability evaluation, or an external user evaluation. For example, the server (108) may generate first authority evaluation information by giving more weight to the external user evaluation than to the external category evaluation or the external usability evaluation.

[0052] According to various embodiments, the electronic device (101) can evaluate the application's permissions through various criteria and notify the user of the appropriateness of the permission settings. At least some of the operations of the configuration inside the electronic device (101) may be the operations of the processor (120) in FIG. 1.

[0053] According to various embodiments, the electronic device (101) may include a data transmission / reception unit (210), an internal data learning unit (220), an authority determination unit (230), a user notification unit (240), and an authority control unit (250). FIG. 2 is classified according to functions related to authority control, but is not limited thereto. At least some operations of the data transmission / reception unit (210), the internal data learning unit (220), the authority determination unit (230), the user notification unit (240), and the authority control unit (250) may be operations of the processor (120) of FIG. 1.

[0054] The data transmission / reception unit (210) can receive first authority evaluation information generated by the server (108). The data transmission / reception unit (210) can transmit the first authority evaluation information to the internal data learning unit (220).

[0055] The first authorization evaluation information may include at least one of an external category evaluation regarding the category of the application, an external user evaluation regarding the user utilizing the application, or an external usability evaluation regarding the usage pattern of the application.

[0056] According to one embodiment, the first permission evaluation information may include an evaluation result for a permission required by an application. For example, the first permission evaluation information may include a result of evaluating the application's permission as "one of positive evaluation / negative evaluation," "one of positive evaluation / neutral evaluation / negative evaluation," or "one of very positive evaluation / positive evaluation / negative evaluation / very negative evaluation."

[0057] According to another embodiment, the first permission evaluation information may include evaluation criteria for the permission required by the application. For example, the first permission evaluation information may include a criterion value for determining the use of the permission less than 5 times within 10 minutes as a positive evaluation.

[0058] According to various embodiments, the data transmission and reception unit (210) can transmit at least one of the allowed or denied permission information of an application, user identification information, terminal identification information, and internal evaluation information within the electronic device (101) to the server (108).

[0059] The internal data learning unit (220) can generate second authority evaluation information based on information regarding the authority of an application obtained within the electronic device (101) (hereinafter, authority usage information). For example, the authority usage information may include first history information regarding the installation, execution, or deletion of the application, or second history information regarding the authority required by the application, whether the authority is allowed, the number of uses, or the time of use.

[0060] The second authority evaluation information may include at least one of the fourth evaluation information regarding the category of the application (hereinafter, internal category evaluation), the fifth evaluation information regarding the user associated with the electronic device (101) (hereinafter, internal user evaluation), or the sixth evaluation information regarding the usage pattern of the application installed on the electronic device (101) (hereinafter, internal usability evaluation).

[0061] According to various embodiments, the internal data learning unit (220) can identify the categories of applications installed on the electronic device (101). The internal data learning unit (220) can obtain statistical information regarding the required permissions, allowed permissions, and disallowed permissions for each category within the electronic device (101). The internal data learning unit (220) can generate an internal category evaluation based on the statistical information.

[0062] According to various embodiments, the internal data learning unit (220) may obtain first history information regarding the installation, execution, or deletion of an application. The internal data learning unit (220) may generate an internal user evaluation based on the first history information of the application. For example, when the application is installed for the first time, the internal data learning unit (220) may generate an internal user evaluation without reflecting a separate weight. On the other hand, when an application that has a history of past installation is reinstalled, the internal data learning unit (220) may generate an internal user evaluation by reflecting a weight to the permissions allowed by the user in the previous installation.

[0063] According to various embodiments, the internal data learning unit (220) can extract second history information regarding whether permission is allowed, the number of uses, or the time of use during the execution of the application. The internal data learning unit (220) can generate an internal usability evaluation based on the second history information.

[0064] For example, if the internal data learning unit (220) has never used the "location usage" permission during the execution of the A bank application on the electronic device (101), it can generate an internal usability evaluation by reflecting the weight of the "location usage" permission of the A bank application as an unnecessary permission.

[0065] According to various embodiments, permission usage information used in the internal data learning unit (220) may be transmitted to a server (108) or a separate server as an individual profile. In the case of deleting and reinstalling the application, resetting the terminal, or replacing the user's terminal, the internal data learning unit (220) may accumulate learning data by reusing stored data, thereby increasing the reliability of permission-related user notifications.

[0066] According to various embodiments, when the electronic device (101) includes a neural processing unit (NPU), the analysis and learning of the internal data learning unit (220) can be performed through AI learning.

[0067] According to various embodiments, the authority determination unit (230) can determine the evaluation result of the authority required by the application by applying the first authority evaluation information and the second authority evaluation information determined by the internal data learning unit (220) in combination.

[0068] According to one embodiment, the authority determination unit (230) can determine the final evaluation result for the authority by applying category evaluation (external category evaluation and internal category evaluation), user evaluation (external user evaluation and internal user evaluation), and usability evaluation (external usability evaluation or internal usability evaluation) with various priorities or weights.

[0069] For example, when an application is first installed or a specific permission is used for the first time, the permission determination unit (230) can determine a positive or negative evaluation of the permission based on a category evaluation or a user evaluation.

[0070] As another example, the authority determination unit (230) can determine a positive or negative evaluation of the authority based on usability evaluation or user evaluation when the application is running and using a specific authority.

[0071] The user notification unit (240) can display a user notification based on the evaluation result of the permission determination unit (230). For example, if the permission of the application is determined to be negative, the user notification unit (240) can display a user notification on the display. The user notification can be output in the form of a pop-up message or a status bar message.

[0072] According to various embodiments, the user notification unit (240) may display a list of applications and provide the user with evaluation results regarding the permissions required by each application included in the list in various ways.

[0073] The permission control unit (250) receives user input through a user notification or user interface output from the user notification unit (240), and can allow or deny the permission of the application in response to the user input.

[0074] According to various embodiments, the authority control unit (250) can transmit the result of the authority setting based on user input to the internal data learning unit (220) to learn.

[0075] According to various embodiments, the authorization control unit (250) may transmit the authorization setting result based on user input to the data transmission / reception unit (210) so that it is transmitted to the server (108). The server (108) may update the first authorization evaluation information based on the received information.

[0076] According to various embodiments, when a user changes the application's permissions in the settings menu of the electronic device (101), the permission control unit (250) can transmit the result of the change to the internal data learning unit (220) or to the data transmission and reception unit (210).

[0077] FIG. 3 illustrates a method for controlling the rights of an application according to various embodiments.

[0078] Referring to FIG. 3, in operation 310, the processor (120) may receive first authorization evaluation information regarding at least one application from the server (108). The at least one application may be installed on the electronic device (101) or may be an installed application.

[0079] The first authority evaluation information may include at least one of an external category evaluation regarding a category of at least one application, an external user evaluation regarding a user utilizing at least one application, or an external usability evaluation regarding a usage pattern of at least one application.

[0080] According to one embodiment, the processor (120) may receive first permission evaluation information when installing an application. According to another embodiment, the processor (120) may receive first permission evaluation information when running the application after installation. According to yet another embodiment, the processor (120) may receive first permission evaluation information when using a specific permission for the first time after running the application.

[0081] In operation 320, the processor (120) may obtain permission usage information of at least one application within the electronic device (101). The permission usage information may include first history information regarding the installation, execution, or deletion of the application, or second history information regarding the permission required by the application, whether the permission is allowed, the number of uses, or the time of use.

[0082] In operation 330, the processor (120) may generate second authority evaluation information based on authority usage information. The second authority evaluation information may include at least one of an internal category evaluation, an internal user evaluation, or an internal usability evaluation.

[0083] In operation 340, the processor (120) can determine the evaluation result regarding the permission of the application based on the first permission evaluation information or the second permission evaluation information.

[0084] For example, when the application is first run after installation, the processor (120) may apply a user evaluation (external user evaluation or internal user evaluation) first, and if there is no user evaluation, apply a category evaluation (external category evaluation or internal category evaluation) to determine a positive or negative evaluation of the authority.

[0085] As another example, the processor (120) can determine a positive or negative evaluation of the authority by comparing the score calculated by assigning different weights to each of the category evaluation (external category evaluation or internal category evaluation), user evaluation (external user evaluation or internal user evaluation), or usability evaluation (external usability evaluation or internal usability evaluation) with a preset threshold value. The weights may vary depending on the application or may be set differently depending on the category of the application.

[0086] As another example, the processor (120) can determine a positive or negative evaluation of authority by comparing a score calculated by assigning different weights to the first authority evaluation information and the second authority evaluation information with a preset reference value (e.g., a weight of 60% for the first authority evaluation information and a weight of 40% for the second authority evaluation information).

[0087] According to various embodiments, the processor (120) can manage the evaluation history of authority based on the first authority evaluation information or the second authority evaluation information.

[0088] In operation 350, the processor (120) may display a user notification regarding the application's permissions based on the evaluation result. For example, if the evaluation result is a negative evaluation, a popup window to allow the user to set or change the permissions may be displayed with a message indicating the negative evaluation (e.g., "Most people do not allow this permission.").

[0089] As another example, if the number of times a specified permission is used exceeds a threshold value while the application is running, a pop-up window may be displayed containing a notification message regarding the negative evaluation (e.g., "Location information" is being used excessively) and a button to change the permission.

[0090] FIG. 4 illustrates a permission control method when a permission usage request occurs in an application according to various embodiments.

[0091] Referring to FIG. 4, in operation 410, the processor (120) can run an application. The processor (120) can download, install, and run an installation file (e.g., an APK file). Alternatively, the processor (120) can run an already installed application.

[0092] In operation 420, the processor (120) can determine whether a permission usage request occurs in the application. A permission usage request may be a request to use a designated function, module, internal device, or hardware resource of the electronic device (101), or to access and use specific data. A permission usage request may occur simultaneously with the execution of the application. Alternatively, a permission usage request may occur when a specific permission is used for the first time after the application has been executed.

[0093] In operation 430, when a request for permission usage occurs, the processor (120) can check whether a user evaluation is stored. The user evaluation may include an external user evaluation or an internal user evaluation.

[0094] In operation 440, if a user evaluation is stored, the processor (120) can check the evaluation results based on the user evaluation. The user evaluation may include an external user evaluation or an internal user evaluation.

[0095] In operation 450, if user evaluations are not saved, the processor (120) can check evaluation results based on category evaluations. Category evaluations may include external category evaluations or internal category evaluations.

[0096] In operation 460, the processor (120) can determine whether the evaluation result by user evaluation or category evaluation is a negative evaluation.

[0097] For example, if less than 90% of users who have installed the application have denied the permission, the evaluation result of the permission may be negative based on external user evaluation. Alternatively, even if the evaluation result of the permission is positive based on external user evaluation, it may be changed to a negative evaluation based on internal user evaluation.

[0098] As another example, if less than 30% of the applications in the category to which the application belongs are requesting the permission, the evaluation result of the permission may be negative by the external category evaluation.

[0099] In operation 470, if the evaluation result by user evaluation or category evaluation is a negative evaluation, the processor (120) may output a first type of user notification including a guidance message regarding the evaluation result. For example, the first type of user notification may include a guidance message such as "Most users do not allow this permission" or "This permission seems excessive in a financial application."

[0100] In operation 480, if the evaluation result by user evaluation or category evaluation is a positive evaluation, the processor (120) may output a second type of user notification regarding permission setting. The second type of user notification may not include a guidance message regarding the evaluation result and may include a button for permission setting.

[0101] According to various embodiments, the processor (120) may receive user input for permission setting through a first type of user notification or a second type of user notification. The processor (120) may allow or deny permission in response to the user input. The processor (120) may transmit the permission setting result to the server (108) to be used as first permission evaluation information or utilize it as internal second permission evaluation information.

[0102] FIG. 4 illustrates an exemplary case where user evaluation is given more weight than category evaluation, but is not limited thereto. For example, the processor (120) may display results based on user evaluation and category evaluation simultaneously.

[0103] FIG. 5 is an exemplary diagram illustrating a first type of user notification according to various embodiments. FIG. 5 is exemplary and is not limited thereto.

[0104] Referring to FIG. 5, when an application is first executed after installation or when a designated authority is first used, the processor (120) can determine the evaluation result of the authority based on the first authority evaluation information or the second authority evaluation information.

[0105] The processor (120) may display a first type of user interface (510, 520) containing the evaluation result when the evaluation result is a negative evaluation. The first type of user interface (510, 520) may include a first part (511, 521) that displays whether the permission is allowed by including an identifier of the application and an identifier of the permission, a second part (512, 522) that displays the evaluation result for the permission, and a third part (513, 523) that receives user input regarding the setting (allow / deny) of the permission.

[0106] For example, if the evaluation result by user evaluation is a negative evaluation, the processor (120) may display a second part (512) such as "This is an authority that users judged to be excessive."

[0107] As another example, if the evaluation result of the permission by category evaluation is negative, the processor (120) may display a second part (522) such as “The operation in the financial app seems excessive.”

[0108] FIG. 5 illustrates an example where the evaluation results are simply displayed in the second part (512, 522), but is not limited thereto. For example, the processor (120) may display specific numbers in the second part (512, 522) (e.g., "90% of users judged this to be excessive authority") or display a button for displaying additional information in the second part (512, 522).

[0109] According to one embodiment, if the evaluation result for the authority is a positive evaluation, the processor (120) may display a second type of user interface (not shown) comprising a first part indicating whether the authority is allowed and a third part receiving user input regarding the setting (allow / deny) of the authority. The second user interface may not include the evaluation result for the authority.

[0110] According to various embodiments, the processor (120) may receive user input for permission setting through the third part (513, 523). The processor (120) may allow or deny permission in response to the user input. The processor (120) may transmit application information, permission information, or permission setting results regarding permission status to the server (108) to be used as first permission evaluation information. Through this, the server (108) may refer to the accumulated first permission evaluation information when another user sets the permission of an application. This may be useful for setting permissions for applications that have low usage rates or are unfamiliar to users.

[0111] According to various embodiments, the processor (120) can protect personal information by transmitting the permission setting result, excluding personal information that can identify the user, to the server (108). Additionally, the processor (120) can store the permission setting result in internal memory (130) and use it as second permission evaluation information.

[0112] FIG. 6 illustrates a permission control method for changing permission permission after permission has been granted to an application according to various embodiments. FIG. 6 is exemplary and is not limited thereto.

[0113] Referring to FIG. 6, in operation 610, the processor (120) can execute an application after at least one permission has been granted. The application may be in use or available after at least one permission has been granted.

[0114] In operation 620, the processor (120) can monitor the number of times or the duration of use of permissions allowed to an application. The processor (120) can record the number of times or the duration of use of permissions allowed to each application for a specified period (e.g., during one execution of the application, or for 10 minutes). The processor (120) may also assign weights to data from a recent period (e.g., within 5 or 10 days).

[0115] In operation 630, the processor (120) can check whether the number of uses or the usage time exceeds a first threshold value based on a usability evaluation. The first threshold value may be determined through an external usability evaluation or an internal usability evaluation. For example, in the case of the Bank A app, the first threshold value regarding 'location information' may be three or fewer uses within 10 minutes.

[0116] According to one embodiment, the processor (120) can continue monitoring if the number of uses or the usage time does not exceed a first reference value (630-NO).

[0117] In operation 640, if the number of uses or the usage time exceeds the first threshold value, the processor (120) can check whether the user evaluation is stored.

[0118] In operation 650, if the processor (120) has stored a user evaluation, the processor (120) can check whether the number of uses or the usage time exceeds a second threshold value based on the user evaluation.

[0119] The second threshold value may be determined through external user evaluation or internal user evaluation. For example, in the case of the Bank A app, the second threshold value regarding 'location information' may be five times or less within 10 minutes.

[0120] According to one embodiment, the processor (120) can continue monitoring if the number of uses or the usage time does not exceed a second reference value (650-NO).

[0121] In operation 660, if the user evaluation is not saved (640-NO) or if the number of uses or the usage time exceeds a second threshold value (650-YES), the processor (120) may output a first type of user notification including a guidance message regarding the evaluation result. For example, the first type of user notification may include a guidance message such as "Location information access appears excessive."

[0122] According to various embodiments, the processor (120) may receive user input for permission setting through a first type of user notification. The processor (120) may continuously allow or deny permission in response to user input. The processor (120) may transmit the permission setting result to the server (108) to be used as first permission evaluation information or utilize it as internal second permission evaluation information.

[0123] FIG. 6 illustrates an example in which priority is given to usability evaluation over user evaluation, but it is not limited thereto. For example, the processor (120) may display evaluation results based on user evaluation and usability evaluation simultaneously.

[0124] FIG. 7 is an example of a first type of user notification after authorization has been granted according to various embodiments. FIG. 7 is exemplary and is not limited thereto.

[0125] Referring to FIG. 7, after permission is granted to an application, the processor (120) can monitor the number of times or the time of use of the permission granted to the application. The processor (120) can compare the number of times or the time of use with a threshold value set according to a category evaluation, user evaluation, or usability evaluation, and if the threshold value is exceeded, it can display a first type of user notification (710, 720).

[0126] A first type of user interface (710, 720) may include a first part (711, 721) that displays the permission usage status including an identifier of an application and an identifier of a permission, a second part (712, 722) that displays the evaluation result of the permission usage status, and a third part (713, 723) that receives user input regarding the setting (allow / deny) of the permission.

[0127] For example, the processor (120) can display a first part (711, 721) such as "A bank app is continuously accessing my location."

[0128] For example, if the number of uses or usage time exceeds a first threshold value based on usability evaluation and a second threshold value based on user evaluation, the processor (120) may display a second part (712) such as "This is an authority that users have deemed excessive."

[0129] As another example, if the number of uses or usage time exceeds a first threshold value based on usability evaluation and the user evaluation is not saved, the processor (120) may display a second part (722) such as "The operation in the financial app appears excessive."

[0130] FIG. 7 illustrates an exemplary case where the evaluation results are simply displayed in the second part (712, 722), but is not limited thereto. For example, the processor (120) may display specific numerical values ​​in the second part (712, 722) (e.g., "90% of users judged this to be excessive authority") or display a button for displaying additional information in the second part (712, 722).

[0131] According to various embodiments, the processor (120) may receive user input for permission setting through the third part (713, 723). The processor (120) may allow or deny permission in response to the user input. The processor (120) may transmit application information, permission information, or permission setting results regarding permission status to the server (108) to be used as first permission evaluation information.

[0132] FIG. 8 illustrates the automatic change of authority based on the result of an authority evaluation according to various embodiments. FIG. 8 is exemplary and is not limited thereto.

[0133] Referring to FIG. 8, operations 810 to 830 may be the same or similar to operations 610 to 630 in FIG. 6.

[0134] In operation 840, if the number of uses or the usage time exceeds the first threshold value, the processor (120) can determine whether it is a designated type of permission. For example, the designated type may be a permission closely related to personal information (e.g., "location information").

[0135] In operation 850, if the specified type of permission is used, the processor (120) may change to automatically deny the permission without separate user input. The processor (120) may not output a separate notification. Alternatively, the processor (120) may output a separate user notification to allow the user to return the permission to an allowed state.

[0136] In operation 860, if the specified type of permission is not present, a first type of user interface may be displayed. The processor (120) may output a first type of user notification containing information regarding the evaluation result. For example, the first type of user notification may include a guidance message such as "Location information access appears excessive."

[0137] FIG. 8 illustrates an example of using usability evaluation, but is not limited thereto. The processor (120) can evaluate authority by applying a combination of category evaluation, usability evaluation, and user evaluation.

[0138] An electronic device according to various embodiments (e.g., the electronic device (101) of FIG. 1) comprises a display (e.g., the display device (160) of FIG. 1), a communication module (e.g., the communication module (190) of FIG. 1), a memory (e.g., the memory (130) of FIG. 1), and a processor (e.g., the processor (120) of FIG. 1) receives first authorization evaluation information from a server (e.g., the server (108) of FIG. 1) using the communication module (e.g., the communication module (190) of FIG. 1), generates second authorization evaluation information based on authorization usage information of at least one application obtained within the electronic device (e.g., the electronic device (101) of FIG. 1), determines an evaluation result regarding the permission of at least one authorization associated with at least one application based on the first authorization evaluation information or the second authorization evaluation information, and based on the evaluation result, provides a user notification regarding the at least one authorization to the display (e.g., the display of FIG. 1). It can be displayed on the device (160).

[0139] According to various embodiments, the first authority evaluation information may include at least one of first evaluation information regarding a category of at least one application, second evaluation information regarding a user utilizing at least one application, or third evaluation information regarding a usage pattern of at least one application.

[0140] According to various embodiments, the second authority evaluation information may include at least one of a fourth evaluation information regarding an application installed on the electronic device (e.g., the electronic device (101) of FIG. 1), a fifth evaluation information regarding a user of the electronic device (e.g., the electronic device (101) of FIG. 1), or a sixth evaluation information regarding a usage pattern of the at least one application within the electronic device (e.g., the electronic device (101) of FIG. 1).

[0141] According to various embodiments, the processor (e.g., processor (120) of FIG. 1) may determine the evaluation result based on the second evaluation information or the fifth evaluation information when the at least one application is installed and executed for the first time, or when the at least one authority is used for the first time, and when the second evaluation information or the fifth evaluation information is stored in the memory (e.g., memory (130) of FIG. 1).

[0142] According to various embodiments, the processor (e.g., processor (120) of FIG. 1) may determine the evaluation result based on the first evaluation information or the fourth evaluation information when the second evaluation information or the fifth evaluation information is not stored in the memory (e.g., memory (130) of FIG. 1).

[0143] According to various embodiments, the processor (e.g., processor (120) of FIG. 1) may monitor the number of uses or usage time of the at least one authority after the at least one authority is set on the at least one application, and determine the evaluation result based on the first reference value regarding the third evaluation information or the sixth evaluation information.

[0144] According to various embodiments, the processor (e.g., processor (120) of FIG. 1) may determine the evaluation result based on the second evaluation information or the fifth evaluation information when the number of uses or the usage time exceeds the first reference value and the second evaluation information or the fifth evaluation information is stored in the memory (e.g., memory (130) of FIG. 1).

[0145] According to various embodiments, the permission usage information may include first history information regarding the installation, execution, or deletion of at least one application, or second history information regarding whether the at least one permission is allowed, the number of uses, or the time of use.

[0146] According to various embodiments, the user notification may include a first part comprising an identifier of at least one application and an identifier of at least one authority, a second part comprising an evaluation result, and a third part receiving user input for controlling the setting of at least one authority.

[0147] According to various embodiments, the processor (e.g., processor (120) of FIG. 1) receives the user input in the third part, allows or denies the at least one authority in response to the user input, and transmits the result of setting the at least one authority to the server (e.g., server (108) of FIG. 1) or stores the second authority control information in the memory (e.g., memory (130) of FIG. 1).

[0148] According to various embodiments, the evaluation result is either a positive evaluation or a negative evaluation, and the processor (e.g., the processor (120) of FIG. 1) may display the user notification if the evaluation result is a negative evaluation.

[0149] According to various embodiments, the processor (e.g., the processor (120) of FIG. 1) may display a separate user notification distinct from the user notification when the evaluation result is a positive evaluation.

[0150] According to various embodiments, the processor (e.g., the processor (120) of FIG. 1) may determine a plurality of reference values ​​based on the first authority evaluation information or the second authority evaluation information, and determine the evaluation result based on the plurality of reference values.

[0151] According to various embodiments, the first authority evaluation information may include a reference value related to the evaluation of at least one authority.

[0152] A permission control method according to various embodiments may include: an operation of receiving a first permission evaluation information from a server (e.g., a server (108) of FIG. 1) which is performed in an electronic device (e.g., an electronic device (101) of FIG. 1); an operation of generating a second permission evaluation information based on permission usage information of at least one application obtained within the electronic device (e.g., an electronic device (101) of FIG. 1); an operation of determining an evaluation result regarding the permission of at least one permission associated with the at least one application based on the first permission evaluation information or the second permission evaluation information; and an operation of displaying a user notification regarding the at least one permission on a display (e.g., a display device (160) of FIG. 1) of the electronic device (e.g., an electronic device (101) of FIG. 1) based on the evaluation result.

[0153] According to various embodiments, the first authority evaluation information may include at least one of first evaluation information regarding a category of at least one application, second evaluation information regarding a user utilizing at least one application, or third evaluation information regarding a usage pattern of at least one application.

[0154] According to various embodiments, the second authority evaluation information may include at least one of a fourth evaluation information regarding an application installed on the electronic device (e.g., the electronic device (101) of FIG. 1), a fifth evaluation information regarding a user of the electronic device (e.g., the electronic device (101) of FIG. 1), or a sixth evaluation information regarding a usage pattern of the at least one application within the electronic device (e.g., the electronic device (101) of FIG. 1).

[0155] According to various embodiments, the operation of determining the evaluation result may include the operation of determining the evaluation result based on the second evaluation information or the fifth evaluation information when the at least one application is installed and executed for the first time, or when the at least one authority is used for the first time, and the second evaluation information or the fifth evaluation information is stored in the memory (e.g., memory (130) of FIG. 1).

[0156] According to various embodiments, the operation of determining the evaluation result may include the operation of determining the evaluation result based on the first evaluation information or the fourth evaluation information when the second evaluation information or the fifth evaluation information is not stored in the memory (e.g., memory (130) of FIG. 1).

[0157] According to various embodiments, the permission usage information may include first history information regarding the installation, execution, or deletion of at least one application, or second history information regarding whether the at least one permission is allowed, the number of uses, or the time of use.

[0158] The electronic device according to the various embodiments disclosed in this document may be of various forms. The electronic device may include, for example, a portable communication device (e.g., a smartphone), a computer device, a portable multimedia device, a portable medical device, a camera, a wearable device, or a consumer electronics device. The electronic device according to the embodiments of this document is not limited to the devices described above.

[0159] The various embodiments of this document and the terms used therein are not intended to limit the technical features described in this document to specific embodiments, and should be understood to include various modifications, equivalents, or substitutions of said embodiments. In connection with the description of the drawings, similar reference numerals may be used for similar or related components. The singular form of a noun corresponding to an item may include one or more of said items unless the relevant context clearly indicates otherwise. In this document, phrases such as “A or B,” “at least one of A and B,” “at least one of A or B,” “A, B or C,” “at least one of A, B and C,” and “at least one of A, B, or C” each may include any one of the items listed together in the corresponding phrase, or all possible combinations thereof. Terms such as “first,” “second,” or “first” or “second” may be used simply to distinguish said components from other said components and do not limit said components in any other aspect (e.g., importance or order). Where any (e.g., 1st) component is referred to as “coupled” or “connected” to another (e.g., 2nd) component, with or without the terms “functionally” or “communicationly,” it means that said any component may be connected to said other component directly (e.g., via a wire), wirelessly, or through a third component.

[0160] As used herein, the term "module" may include a unit implemented in hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit. A module may be a component formed integrally, or a minimum unit of said component or a part thereof that performs one or more functions. For example, according to one embodiment, a module may be implemented in the form of an application-specific integrated circuit (ASIC).

[0161] Various embodiments of the present document may be implemented as software (e.g., program (740)) comprising one or more instructions stored in a storage medium (e.g., internal memory (736) or external memory (738)) readable by a machine (e.g., electronic device (701)). For example, a processor (e.g., processor (720)) of the machine (e.g., electronic device (701)) may call at least one of the one or more instructions stored from the storage medium and execute it. This enables the machine to be operated to perform at least one function according to the at least one called instruction. The one or more instructions may include code generated by a compiler or code that can be executed by an interpreter. The storage medium readable by the machine may be provided in the form of a non-transitory storage medium. Here, 'non-temporary' simply means that the storage medium is a tangible device and does not contain a signal (e.g., electromagnetic waves), and the term does not distinguish between cases where data is stored semi-permanently and cases where it is stored temporarily.

[0162] According to one embodiment, the method according to the various embodiments disclosed herein may be provided by being included in a computer program product. The computer program product may be traded between a seller and a buyer as a product. The computer program product may be distributed in the form of a device-readable storage medium (e.g., compact disc read-only memory (CD-ROM)) or an application store (e.g., Play Store). TM It can be distributed online (e.g., downloaded or uploaded) through ) or directly between two user devices (e.g., smartphones). In the case of online distribution, at least a portion of the computer program product may be temporarily stored or temporarily created on a device-readable storage medium, such as the memory of a manufacturer's server, an application store's server, or a relay server.

[0163] According to various embodiments, each component (e.g., module or program) of the components described above may include a singular or multiple entities. According to various embodiments, one or more of the components or operations of the aforementioned components may be omitted, or one or more other components or operations may be added. Generally or additionally, multiple components (e.g., module or program) may be integrated into a single component. In this case, the integrated component may perform one or more functions of each of the components of the multiple components in the same or similar manner as those performed by the corresponding component among the multiple components prior to the integration. According to various embodiments, operations performed by the module, program, or other components may be executed sequentially, in parallel, iteratively, or heuristically, or one or more of the operations may be executed in a different order, omitted, or one or more other operations may be added.

Claims

Claim 1 An electronic device comprising: a display; a communication module; a memory; and a processor; wherein the processor receives first authority evaluation information from a server using the communication module, generates second authority evaluation information based on authority usage information of at least one application obtained within the electronic device, determines an evaluation result regarding the permission of at least one authority associated with the at least one application based on the first authority evaluation information or the second authority evaluation information, displays a user notification regarding the at least one authority on the display based on the evaluation result, and wherein the at least one authority is an authority that can execute a designated function in the electronic device, use configurations or hardware resources within the electronic device, or access and use specific data. Claim 2 An electronic device according to claim 1, wherein the first authority evaluation information comprises at least one of first evaluation information regarding a category of at least one application, second evaluation information regarding a user utilizing at least one application, or third evaluation information regarding a usage pattern of at least one application. Claim 3 An electronic device according to paragraph 2, wherein the second authority evaluation information comprises at least one of fourth evaluation information regarding a category of an application installed on the electronic device, fifth evaluation information regarding a user of the electronic device, or sixth evaluation information regarding a usage pattern of at least one application within the electronic device. Claim 4 In paragraph 3, the electronic device wherein the processor determines the evaluation result based on the second evaluation information or the fifth evaluation information when the at least one application is installed and executed for the first time, or when the at least one authority is used for the first time, and when the second evaluation information or the fifth evaluation information is stored in the memory. Claim 5 In paragraph 4, the electronic device wherein the processor determines the evaluation result based on the first evaluation information or the fourth evaluation information when the second evaluation information or the fifth evaluation information is not stored in the memory. Claim 6 An electronic device according to paragraph 3, wherein the processor monitors the number of uses or usage time of the at least one authority after the at least one authority is set in the at least one application, and determines the evaluation result based on a first reference value regarding the third evaluation information or the sixth evaluation information. Claim 7 An electronic device according to claim 6, wherein the processor determines the evaluation result based on the second evaluation information or the fifth evaluation information when the number of uses or the usage time exceeds the first reference value and the second evaluation information or the fifth evaluation information is stored in the memory. Claim 8 An electronic device according to claim 1, wherein the permission usage information comprises: first history information regarding the installation, execution, or deletion of at least one application; or second history information regarding whether the at least one permission is allowed, the number of uses, or the time of use. Claim 9 An electronic device according to claim 1, wherein the user notification comprises: a first part including an identifier of at least one application and an identifier of at least one authority; a second part including an evaluation result; and a third part receiving user input for controlling the setting of at least one authority. Claim 10 An electronic device according to claim 9, wherein the processor receives the user input in the third part, allows or denies the at least one authority in response to the user input, transmits the result of setting the at least one authority to the server, or stores the second authority control information in the memory. Claim 11 In claim 1, the evaluation result is one of a positive evaluation or a negative evaluation, and the processor is an electronic device that displays the user notification when the evaluation result is a negative evaluation. Claim 12 In paragraph 11, the processor is an electronic device that displays a separate user notification distinct from the user notification when the evaluation result is a positive evaluation. Claim 13 An electronic device according to claim 1, wherein the processor determines a plurality of reference values ​​based on the first authority evaluation information or the second authority evaluation information, and determines the evaluation result based on the plurality of reference values. Claim 14 In claim 1, the electronic device comprising the first authority evaluation information including a reference value related to the evaluation of at least one authority. Claim 15 A method for controlling rights performed in an electronic device comprises: receiving a first right evaluation information from a server; generating a second right evaluation information based on right usage information of at least one application obtained within the electronic device; determining an evaluation result regarding the permission of at least one right associated with the at least one application based on the first right evaluation information or the second right evaluation information; and displaying a user notification regarding the at least one right on a display of the electronic device based on the evaluation result; wherein the at least one right is a right to execute a designated function in the electronic device, use a configuration or hardware resources within the electronic device, or access and use specific data. Claim 16 A method according to claim 15, wherein the first authority evaluation information comprises at least one of first evaluation information regarding the category of at least one application, second evaluation information regarding a user utilizing at least one application, or third evaluation information regarding the usage pattern of at least one application. Claim 17 A method according to claim 16, wherein the second authority evaluation information comprises at least one of a fourth evaluation information regarding a category of an application installed on the electronic device, a fifth evaluation information regarding a user of the electronic device, or a sixth evaluation information regarding a usage pattern of at least one application within the electronic device. Claim 18 In claim 17, the operation of determining the evaluation result comprises: an operation of determining the evaluation result based on the second evaluation information or the fifth evaluation information when the at least one application is installed and executed for the first time, or when the at least one authority is used for the first time, and when the second evaluation information or the fifth evaluation information is stored in the memory of the electronic device. Claim 19 A method according to claim 18, wherein the operation of determining the evaluation result comprises, when the second evaluation information or the fifth evaluation information is not stored in the memory, the operation of determining the evaluation result based on the first evaluation information or the fourth evaluation information. Claim 20 A method according to claim 15, wherein the permission usage information comprises: first history information regarding the installation, execution, or deletion of at least one application; or second history information regarding whether the at least one permission is allowed, the number of uses, or the time of use.

Citation Information

Patent Citations

  • Method for controlling the permission of application program and electronic device

    KR1020190021559A

  • Application licensing authentication

    US20130144755A1