Permission Control Method, Device, Equipment and Storage Medium
By determining the status of the protocol information before the application is started and obtaining the necessary permission authorization, the problem of infringing on user privacy during application startup is solved, and more standardized and secure permission control is achieved.
Patent Information
- Application Number
- CN202011055150.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-09-29
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2040-09-29
AI Technical Summary
In the prior art, applications are prone to perform operations that infringe upon user privacy without authorization at startup, and the authority control is poor in standardization and effectiveness, and insufficient security.
Before the application is started, by determining the processing status of the protocol information, displaying the protocol information and obtaining the authorization results of the necessary permissions, it will only jump to the start main page after all necessary permissions are authorized, and integrate the protocol information confirmation process to standardize permission control.
It effectively avoids the phenomenon of infringing on user privacy when the application is started, improves the standardization and security of permission control, and enhances the protection of user privacy.
Smart Images

Figure CN112131556B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of computer technology, and in particular, to a permission control method, apparatus, device, and storage medium. Background Art
[0002] With the development of computer technology, the types of application programs are increasing. Usually, when some permissions of an application program are not authorized by the user, the terminal cannot execute operations that require resources corresponding to these permissions, thereby achieving the effect of protecting user privacy based on permission control.
[0003] In the related art, after the application program is successfully started, it is determined whether the to-be-executed operation corresponding to the application program depends on resources corresponding to a certain permission. When it is determined that the to-be-executed operation corresponding to the application program depends on resources corresponding to a certain permission, the permission control process for this permission is then executed. Based on this permission control method, it is easy to have the phenomenon of performing operations that violate user privacy when the application program starts, and the limitations of permission control are relatively large, the standardization and effectiveness of permission control are poor, and the security is poor. Summary of the Invention
[0004] The embodiments of the present application provide a permission control method, apparatus, device, and storage medium, which can be used to improve security. The technical solutions are as follows:
[0005] On the one hand, the embodiments of the present application provide a permission control method, and the method includes:
[0006] Based on the start instruction of the application program, determine the processing status of the protocol information corresponding to the application program;
[0007] In response to the processing status of the protocol information being that the protocol information has not been confirmed, display the protocol information;
[0008] Based on the confirmation instruction of the protocol information, display the permission description information corresponding to the application program, and the permission description information is used to prompt and explain at least one necessary permission corresponding to the application program;
[0009] Based on the confirmation instruction of the permission description information, obtain the authorization result of the at least one necessary permission in a polling manner;
[0010] In response to the authorization results of the at least one necessary permission all being authorized, jump to the start main page corresponding to the application program.
[0011] In a possible implementation manner, the selection control further includes an exit control. After the selection control is displayed, the method further includes:
[0012] Exit the application based on the trigger operation of the exit control.
[0013] On the other hand, a permission control device is provided, and the device includes:
[0014] A determination module, configured to determine the processing status of protocol information corresponding to the application based on a startup instruction of the application;
[0015] A display module, configured to display the protocol information in response to the processing status of the protocol information being that the protocol information has not been confirmed;
[0016] The display module is further configured to display permission description information corresponding to the application based on a confirmation instruction of the protocol information, where the permission description information is used to prompt and explain at least one necessary permission corresponding to the application;
[0017] An acquisition module, configured to obtain an authorization result of the at least one necessary permission in a polling manner based on a confirmation instruction of the permission description information;
[0018] A jump module, configured to jump to a startup main page corresponding to the application in response to the authorization results of the at least one necessary permission all being authorized.
[0019] In a possible implementation manner, the display module is further configured to display a selection control in response to at least one target permission among the at least one necessary permission having an authorization result of unauthorized, where the selection control includes a re-authorization control and a setting control;
[0020] The acquisition module is further configured to obtain an authorization result of at least one first permission in a polling manner based on a trigger operation of the re-authorization control, where the at least one first permission is a target permission among the at least one target permission that meets a condition, and the target permission that meets the condition is a target permission that allows obtaining an authorization result again in a polling manner; and obtain an authorization result of at least one second permission by jumping to a system settings page based on a trigger operation of the setting control, where the at least one second permission is each target permission among the at least one target permission except the at least one first permission;
[0021] The jump module is further configured to jump to a startup main page corresponding to the application in response to the authorization results of the at least one first permission and the at least one second permission all being authorized.
[0022] In a possible implementation manner, the selection control further includes an exit control, and the device further includes:
[0023] An exit module, configured to exit the application based on a trigger operation of the exit control.
[0024] In a possible implementation, before obtaining the authorization result, the at least one necessary permission is in the necessary permission list; the apparatus further includes:
[0025] An elimination module, configured to eliminate the necessary permissions with the authorization result being authorized from the necessary permission list;
[0026] The determining module is further configured to, in response to the necessary permission list after the elimination process not being an empty list, determine that there is at least one target permission among the at least one necessary permission with the authorization result being unauthorized.
[0027] In a possible implementation, the apparatus further includes:
[0028] A detection module, configured to, in response to the processing status of the protocol information being that the protocol information has been confirmed, detect the processing status of at least one necessary permission corresponding to the application program;
[0029] The display module is further configured to, in response to the processing status of the at least one necessary permission indicating that there is at least one reference permission among the at least one necessary permission that has not been authorized, display the permission description information;
[0030] The obtaining module is further configured to, based on the confirmation instruction of the permission description information, obtain the authorization result of the at least one reference permission in a polling manner;
[0031] The jump module is further configured to, in response to the authorization results of the at least one reference permission all being authorized, jump to the startup main page corresponding to the application program.
[0032] In a possible implementation, the determining module is further configured to, in response to the confirmation mark information of the protocol information being included in the first local storage information of the application program, determine that the processing status of the protocol information is that the protocol information has been confirmed; or, in response to the login information of the application program being included in the second local storage information of the application program, determine that the processing status of the protocol information is that the protocol information has been confirmed.
[0033] In a possible implementation, the obtaining module is further configured to, in response to the operation to be executed corresponding to the application program depending on the resource corresponding to any non-necessary permission, obtain the authorization result of the any non-necessary permission;
[0034] The apparatus further includes:
[0035] An execution module, configured to, in response to the authorization result of the any non-necessary permission being authorized, execute the operation to be executed.
[0036] In a possible implementation manner, the application program is configured with target permission control information for indicating the permission control manner of the application program, and the target permission control information is obtained by customizing the template configuration information in the directly called general permission control information.
[0037] On the other hand, a computer device is provided, which includes a processor and a memory. At least one program code is stored in the memory, and the at least one program code is loaded and executed by the processor to implement the permission control method described in any one of the above.
[0038] On the other hand, a computer-readable storage medium is further provided. At least one program code is stored in the computer-readable storage medium, and the at least one program code is loaded and executed by a processor to implement the permission control method described in any one of the above.
[0039] On the other hand, a computer program product or a computer program is further provided. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the permission control method described in any one of the above.
[0040] The technical solutions provided by the embodiments of the present application at least bring the following beneficial effects:
[0041] In the embodiments of the present application, permission control is performed during the startup process of the application program, and the confirmation process of the protocol information is incorporated into the permission control process. After the protocol information is confirmed, the authorization result of the necessary permissions is obtained. After all the necessary permissions are authorized, the application jumps to the startup main page of the application program. Based on this process, permission control is performed before the application program is successfully started, which can avoid the phenomenon of performing operations that violate user privacy when the application program is started. The permission control is more standardized and effective, which is conducive to improving the protection of user privacy and has higher security. Description of the Drawings
[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0043] Figure 1 It is a schematic diagram of the implementation environment of a permission control method provided by the embodiments of the present application;
[0044] Figure 2 It is a flowchart of a permission control method provided by an embodiment of the present application;
[0045] Figure 3 It is a schematic diagram of a process for displaying protocol information provided by an embodiment of the present application;
[0046] Figure 4 It is a schematic diagram of a process for displaying permission description information provided by an embodiment of the present application;
[0047] Figure 5 It is a schematic diagram of a process for displaying an authorization request text box for the first necessary permission provided by an embodiment of the present application;
[0048] Figure 6 It is a schematic diagram of the display of a selection control provided by an embodiment of the present application;
[0049] Figure 7 It is a flowchart of a permission control method provided by an embodiment of the present application;
[0050] Figure 8 It is a schematic diagram of a permission control process provided by an embodiment of the present application;
[0051] Figure 9 It is a schematic diagram of a permission control device provided by an embodiment of the present application;
[0052] Figure 10 It is a schematic diagram of a permission control device provided by an embodiment of the present application;
[0053] Figure 11 It is a schematic structural diagram of a permission control device provided by an embodiment of the present application. Specific embodiments
[0054] To make the objectives, technical solutions, and advantages of the present application clearer, the following will further describe the embodiments of the present application in detail with reference to the accompanying drawings.
[0055] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order different from those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.
[0056] An embodiment of the present application provides a permission control method. Please refer to Figure 1 ,Figure 1 The figure shows a schematic diagram of the implementation environment of the permission control method provided by an embodiment of the present application. The implementation environment includes: a terminal 101.
[0057] The terminal 101 is installed with an application program that requires permission control. When the application program needs to perform permission control, the method provided by the embodiment of the present application can be applied for control. The process of permission control refers to the process of obtaining the authorization result of the permission and then performing an operation that matches the authorization result of the permission. The terminal 101 can generally refer to one of multiple terminals. Those skilled in the art can know that the number of the above-mentioned terminals 101 can be more or less. For example, the above-mentioned terminal 101 can be only one, or the above-mentioned terminal 101 can be dozens or hundreds, or a larger number. The embodiment of the present application does not limit the number and device type of the terminals.
[0058] In a possible implementation manner, the terminal 101 can be any electronic product that can perform human-computer interaction with the user through one or more ways such as a keyboard, a touchpad, a touch screen, a remote control, voice interaction, or a handwriting device. For example, a PC (Personal Computer), a mobile phone, a smart phone, a PDA (Personal Digital Assistant), a wearable device, a palm computer PPC (Pocket PC), a tablet computer, a smart vehicle machine, a smart TV, a smart speaker, etc. In an exemplary embodiment, the terminal 101 can interact with the background server of the application program. The terminal 101 and the background server of the application program establish a communication connection through a wired or wireless network.
[0059] Those skilled in the art should understand that the above-mentioned terminal 101 is only an example, and other existing or future terminals that can be applied to the present application should also be included within the protection scope of the present application and are hereby incorporated herein by reference.
[0060] Based on the above Figure 1 shown implementation environment, the embodiment of the present application provides a permission control method, taking this method applied to the terminal 101 as an example. As Figure 2 shown, the method provided by the embodiment of the present application includes the following steps:
[0061] In step 201, based on the start instruction of the application program, determine the processing status of the protocol information corresponding to the application program.
[0062] One or more applications are installed in the terminal. When an interaction object triggers the icon of a certain application on the terminal home screen, the terminal obtains the start instruction of the application. The start instruction of the application is used to indicate that the interaction object needs to use the application. In the embodiment of the present application, after obtaining the start instruction of the application and before successfully starting the application, permission control is performed to avoid operations that violate the privacy of the interaction object as soon as the application starts, and the security is relatively high.
[0063] In a possible implementation manner, the application is configured with target permission control information for indicating the permission control manner of the application. The target permission control information is obtained by customizing the template configuration information in the directly called general permission control information. The target permission control information is used to indicate the correspondence between conditions and permission control operations. That is to say, in the target permission control information, it is stipulated under what conditions what kind of permission control operations are performed, so that the terminal can implement the permission control process according to the target permission control information. In an exemplary embodiment, the form of the target permission control information is code.
[0064] The target permission control information is obtained by customizing the template configuration information in the directly called general permission control information. The general permission control information is used to provide general permission control information for multiple applications. Exemplarily, the multiple applications applicable to the general permission control information are applications running under a certain same system. For example, the general permission control information is applicable to applications running under the Android system.
[0065] The general permission control information is preset and directly called by the developers of the applications. In a possible implementation manner, the general permission control information includes template configuration information for the developers of the applications to customize display information or UI (User Interface) display effects to meet the different needs of different applications. In the embodiment of the present application, the type and quantity of the template configuration information in the general permission control information are not limited, which can be flexibly set by the developers of the general permission control information. By customizing the template configuration information in the directly called general permission control information, the target permission control information can be obtained. That is to say, the target permission control information refers to the control information obtained by customizing the template configuration information in the directly called general permission control information.
[0066] In an exemplary embodiment, any template configuration information may include default information or may not include any information. The embodiment of the present application does not limit this.
[0067] In a possible implementation manner, the template configuration information in the general permission control information at least includes protocol configuration information, permission description configuration information, necessary permission list configuration information, and startup main page configuration information. The protocol configuration information is used for the developer of the application to customize and configure the protocol information corresponding to the application. The permission description configuration information is used for the developer of the application to customize and configure the permission description information corresponding to the application. The necessary permission list configuration information is used for the developer of the application to customize and configure the necessary permission list corresponding to the application. The startup main page configuration information is used for the developer of the application to customize and configure the startup main page corresponding to the application. Based on this, by customizing and configuring the protocol configuration information, permission description configuration information, necessary permission list configuration information, and startup main page configuration information in the general control information, the target permission control information can be obtained. It should be noted that the protocol information corresponding to the application, the permission description information corresponding to the application, the necessary permission list corresponding to the application, and the startup main page corresponding to the application will be introduced in detail in the subsequent content and will not be elaborated here for the time being.
[0068] It should be noted that the above template configuration information is only an example. In the exemplary embodiment, other types of template configuration information may also be included to meet more customization requirements of the developer of the application. For example, UI configuration information may also be included for the developer of the application to flexibly set the UI display style.
[0069] The process of obtaining the target permission control information is carried out on the development terminal of the application. After obtaining the target permission control information, the developer of the application configures the target permission control information to be called when the application starts, and then obtains the application configured with the target permission control information. After obtaining the application configured with the target permission control information, the development terminal of the application publishes the application configured with the target permission control information to the application market, and then the terminal of the interaction object can download and install the application configured with the target permission control information in the application market. Based on this, the terminal of the interaction object can implement the permission control process of the application based on the target permission control information.
[0070] In the embodiment of the present application, the developer of the application only needs to customize and configure the protocol information, permission description information, and necessary permission list on the basis of directly calling the general permission control information, and specify the startup main page to jump to after startup to obtain the target permission control information. When the target permission control information is configured to be called when the application starts, the permission control process can be implemented without caring about the specific logical details in the middle, and the access of the permission control information is convenient and efficient. In addition, for applications with their own custom UI display requirements, the UI display style suitable for their own applications can also be easily customized by modifying the page style, icon style, etc.
[0071] After receiving the startup instruction of the application, the terminal of the interaction object can perform the permission control process based on the permission control method indicated by the target permission control information. During the permission control process, it is first necessary to determine the processing status of the protocol information corresponding to the application.
[0072] In a possible implementation manner, the processing status of the protocol information corresponding to the application includes two types, namely, the protocol information has not been confirmed and the protocol information has been confirmed. If the processing status of the protocol information of the application is that the protocol information has not been confirmed, it means that the interaction object has not agreed to the protocol information of the application before triggering the application this time. If the processing status of the protocol information of the application is that the protocol information has been confirmed, it means that the interaction object has agreed to the protocol information of the application before triggering the application this time.
[0073] In an exemplary embodiment, when receiving the startup instruction of the application, it is impossible to determine whether the interaction object has authorized the network permission, and it is impossible to determine the processing status of the protocol information corresponding to the application through the network data stored remotely. In a possible implementation manner, the methods for determining the processing status of the protocol information corresponding to the application include but are not limited to the following three:
[0074] Method 1: Determine the processing status of the protocol information corresponding to the application according to whether the first local storage information of the application includes the confirmation mark information of the protocol information.
[0075] The first local storage information of the application is used to store information of the type of the confirmation mark information of the protocol information. The confirmation mark information of the protocol information will be recorded in the first local storage information of the application after the protocol information is confirmed. Exemplarily, the first local storage information of the application refers to the SharePreference (sharing preference) information of the application locally.
[0076] Based on this Method 1, in response to the first local storage information of the application including the confirmation mark information of the protocol information, determine that the processing status of the protocol information corresponding to the application is that the protocol information has been confirmed; in response to the first local storage information of the application not including the confirmation mark information of the protocol information, determine that the processing status of the protocol information corresponding to the application is that the protocol information has not been confirmed. The embodiments of the present application do not limit the form of the confirmation mark information of the protocol information. For example, the form of the confirmation mark information of the protocol information is a flag bit.
[0077] Method 2: Determine the processing status of the protocol information corresponding to the application according to whether the second local storage information of the application includes the login information of the application.
[0078] The second local storage information of the application is used to store information of the login information type of the application. The login information of the application will be recorded in the second local storage information after the interaction object successfully logs in to the application. The embodiments of the present application do not limit the storage method of the login information of the application. For example, the login information of the application is stored in the form of a file. When the second local storage information of the application includes the mark of the file corresponding to the login information of the application, it is considered that the second local storage information of the application includes the login information of the application.
[0079] It should be noted that since the login information of the application will be recorded in the second local storage information after the interaction object successfully logs in to the application, if the second local storage information of the application includes the login information of the application, it means that the interaction object has successfully logged in to the application. Since logging in is only allowed after the application is successfully started and successful startup is only allowed after the protocol information is confirmed, when the second local storage information of the application includes the login information of the application, it means that the protocol information has been confirmed.
[0080] Based on this method 2, in response to the second local storage information of the application including the login information of the application, it is determined that the processing status of the protocol information corresponding to the application is that the protocol information has been confirmed; in response to the second local storage information of the application not including the login information of the application, it is determined that the processing status of the protocol information corresponding to the application is that the protocol information has not been confirmed. This method 2 can be compatible with old versions of the application.
[0081] Method 3: Determine the processing status of the protocol information corresponding to the application according to whether the first local storage information of the application includes the confirmation mark information of the protocol information and whether the second local storage information of the application includes the login information of the application.
[0082] Under this method 3, by comprehensively considering whether the first local storage information of the application includes the confirmation mark information of the protocol information and whether the second local storage information of the application includes the login information of the application to determine the processing status of the protocol information corresponding to the application, it is beneficial to improve the determination accuracy of the processing status of the protocol information corresponding to the application.
[0083] Based on this method 3, in response to the confirmation flag information of the protocol information being included in the first local storage information of the application, or in response to the login information of the application being included in the second local storage information of the application, determine that the processing status of the protocol information corresponding to the application is that the protocol information has been confirmed. In response to the confirmation flag information of the protocol information not being included in the first local storage information of the application and the login information of the application not being included in the second local storage information of the application, determine that the processing status of the protocol information corresponding to the application is that the protocol information has not been confirmed.
[0084] After determining the processing status of the protocol information corresponding to the application, process the subsequent permission control process according to the processing status of the protocol information. In different processing statuses of the protocol information, there are specific different processing processes. When the processing status of the protocol information is that the protocol information has not been confirmed, execute step 202 below; when the processing status of the protocol information is that the protocol information has been confirmed, see the Figure 7 illustrated embodiment, which will not be elaborated here for the time being.
[0085] In step 202, in response to the processing status of the protocol information being that the protocol information has not been confirmed, display the protocol information.
[0086] If it is determined that the processing status of the protocol information corresponding to the application is that the protocol information has not been confirmed, then display the protocol information corresponding to the application. In an exemplary embodiment, the protocol information is displayed in the form of a pop-up window. The protocol information corresponding to the application is used to indicate the protocol that the application follows during operation, and the protocol that the application follows during operation is used to indicate the processing rules for the personal information of the interaction object during the operation of the application.
[0087] The protocol information corresponding to the application is used to prompt the interaction object of one or more protocols that the application follows during operation, such as a license agreement, a privacy data protocol, etc. In an exemplary embodiment, the names of each protocol are included in the displayed protocol information, and the names of each protocol are in a triggerable mode. When the name of any protocol is triggered, the terminal displays the specific content of the protocol. When a close instruction for the specific content of the protocol is detected, return to the page for displaying the protocol information. Exemplarily, the close instruction for the specific content of the protocol may refer to the interaction object triggering a close control, or may refer to the terminal detecting that the specific content of the protocol has been completely displayed, etc. The embodiments of the present application do not limit this.
[0088] In an exemplary embodiment, the protocol information corresponding to the application is configured in the target permission control information. The general permission control information includes protocol configuration information for the developer of the application to customize and configure the protocol information, so as to meet the needs of customizing and configuring the protocol information. After obtaining the general permission control information by means of direct call, the developer of the application can customize and configure in the protocol configuration information the protocol information corresponding to this application that needs to be displayed for the interaction object to view. Exemplarily, the protocol configuration information is marked as "msdk_policy_content.html". The protocol information customized and configured by the developer of the application will be displayed for the interaction object to view. Exemplarily, the display manner of the protocol information is: displaying the protocol information in a TextView (text view) control on the protocol information display page. Exemplarily, displaying the protocol information in a WebView (web view) control on the protocol information display page.
[0089] It should be noted that the protocol information corresponding to different applications may be the same or different, and the embodiments of the present application do not limit this.
[0090] In a possible implementation manner, on the page for displaying the protocol information, a confirmation control and a rejection control are also displayed, so that the interaction object can make a choice of whether to agree to the protocol information by triggering the control. The embodiments of the present application do not limit the display manner of the confirmation control and the rejection control. Exemplarily, the display manner of the confirmation control and the rejection control may refer to the default display manner indicated by the general startup control information. In an exemplary embodiment, if the information in the general startup control information for indicating the display manner of the confirmation control and the rejection control is information that can be customized and configured, the display manner of the confirmation control and the rejection control can also be the display manner customized and configured by the developer. In an exemplary embodiment, the confirmation control is displayed using a button marked with the word "Agree", and the rejection control is displayed using a button marked with the word "Disagree".
[0091] For example, the process of displaying the protocol information is as Figure 3 shown. When a trigger operation of the application named APP5 in (1) in Figure 3 is detected, the startup instruction of the application named APP5 is obtained. If, when obtaining the startup instruction of the application named APP5, it is determined that the protocol information corresponding to the application named APP5 has not been confirmed, then the protocol information display page shown in (2) in Figure 3 is displayed. On the protocol information display page, the protocol information, a confirmation control 301 displayed using a button marked with the word "Agree", and a rejection control 302 displayed using a button marked with the word "Disagree" are displayed.
[0092] In Figure 3Among the protocol information shown in (2), it includes the name "Game User Agreement and Privacy Policy" and the description "Before you use our services, please carefully read and fully understand each clause of the Game License and Service Agreement and the Game Privacy Protection Guidelines to understand our rules for processing your personal information. If you have carefully read and agreed to the Game License and Service Agreement and the Game Privacy Protection Guidelines, please click 'Agree' to start using our services." In the description, the underlined content "Game License and Service Agreement" and "Game Privacy Protection Guidelines" are the names of the protocols, and the names of the protocols are in a triggerable state.
[0093] After presenting the protocol information, the confirmation control, and the rejection control, the interaction object can select whether to agree to the protocol information by triggering the confirmation control or the rejection control. In response to detecting a trigger instruction for the confirmation control, a confirmation instruction for the protocol information is obtained. In this case, step 203 is executed. In response to a trigger instruction for the rejection control, a rejection instruction for the protocol information is obtained. In this case, the subsequent permission control process is not executed, and the application is directly exited. That is, based on the rejection instruction of the protocol information, the application is exited. This method can effectively avoid the phenomenon of performing some non-compliant operations when the application starts. Only when the interaction object agrees to the protocol information can the permission control process continue to ensure compliance.
[0094] In step 203, based on the confirmation instruction of the protocol information, the permission description information corresponding to the application is presented. The permission description information is used to provide a prompt description of at least one necessary permission corresponding to the application.
[0095] When obtaining the confirmation instruction of the protocol information, it is explained that the interaction object permits the content described in the protocol in the protocol information, and the permission description information is presented. The permission description information is used to provide a prompt description of at least one necessary permission corresponding to the application. A necessary permission refers to a permission that must be required to start the application. The type and quantity of the necessary permissions corresponding to the application are related to the application itself. The types and quantities of the necessary permissions corresponding to different applications may be the same or different, and this application embodiment does not limit this.
[0096] In a possible implementation, in addition to being used to provide a prompt description of at least one necessary permission corresponding to the application, the permission description information is also used to provide a prompt description of all non-necessary information corresponding to the application. In this case, the permission description information is used to provide a prompt description of all the permissions required during the operation of the application, so that the interaction object is aware of all the permissions required during the operation of the application. In an exemplary embodiment, in the permission description information, the description information of the necessary permissions and the description information of the non-necessary permissions are marked differently for easy visual distinction.
[0097] In a possible implementation manner, in the permission description information, the function of prompting and explaining any permission is realized by displaying the type of any permission and the purpose of the any permission.
[0098] In a possible implementation manner, the permission description information corresponding to the application is configured in the target permission control information. The general permission control information includes permission description configuration information for the developer of the application to customize and configure the permission description information, so as to meet the different requirements of different applications for the permission description information. After obtaining the general permission control information by directly calling, the developer of the application can customize and configure the permission description information corresponding to the application that needs to be displayed to the interaction object in the permission description configuration information. Exemplarily, the permission description configuration information is marked as "msdk_permission_content.html". The permission description information customized and configured by the developer of the application will be displayed to the interaction object for viewing. Exemplarily, the display manner of the permission description information is: displaying the permission description information in the TextView (text view) control on the permission description information display page. Exemplarily, displaying the permission description information in the WebView (web view) control on the permission description information display page.
[0099] In an exemplary embodiment, on the page for displaying the permission description information, a determination control is also displayed. The determination control is used for the interaction object to trigger to execute the subsequent process. Exemplarily, the display process of the permission description information is as Figure 4 shown. When a trigger operation of the confirmation control 401 marked with the word "agree" is detected in (1) in Figure 4 , a confirmation instruction for the protocol information is obtained. After obtaining the confirmation instruction for the protocol information, based on the confirmation instruction for the protocol information, the permission description information and the determination control 402 shown in (2) in Figure 4 are displayed. In (2) in Figure 4 , the displayed permission description information includes the name "Permission Request", the related description content "To ensure your game experience, we will apply for the following permissions during your use of our service", and the names and purposes of each permission, etc. For example, the purpose of the storage permission is to cache pictures / videos. In (2) in Figure 4 , the necessary permissions are marked with the word "required". For example, according to the permission description information shown in (2) in Figure 4 , both the storage permission and the phone / call permission are necessary permissions.
[0100] In step 204, based on the confirmation instruction for the permission description information, the authorization results of at least one necessary permission are obtained by means of polling.
[0101] When a trigger operation on the OK control in the page showing the permission description information is detected for the interaction object, obtain the confirmation instruction for the permission description information, and then enter the necessary permission authorization process based on the confirmation instruction for the permission description information. In the necessary permission authorization process, first obtain the authorization results of at least one necessary permission in a polling manner.
[0102] In a possible implementation, the process of obtaining the authorization results of at least one necessary permission in a polling manner means obtaining the authorization results of at least one necessary permission in sequence in the page showing the permission description information. That is, after obtaining the authorization result of the previous necessary permission, obtain the authorization result of the next necessary permission.
[0103] In a possible implementation, in the process of obtaining the authorization results of at least one necessary permission in a polling manner, the implementation of obtaining the authorization result of any necessary permission is as follows: Pop up a window to display the authorization request text box for the any necessary permission, and obtain the authorization result of the any necessary permission based on the trigger operation of the interaction object on the candidate control in the authorization request text box for the any necessary permission. The authorization request text box for any necessary permission is used to request the authorization result of the any necessary permission.
[0104] In an exemplary embodiment, the candidate controls include a first control for indicating prohibited authorization and a second control for indicating permitted authorization. The process of obtaining the authorization result of any necessary permission based on the trigger operation of the interaction object on the candidate control in the authorization request text box for the any necessary permission is as follows: In response to detecting the trigger operation of the interaction object on the first control in the authorization request text box for the any necessary permission, take unauthorized as the authorization result of the any necessary permission; in response to detecting the trigger operation of the interaction object on the second control in the authorization request text box for the any necessary permission, take authorized as the authorization result of the any necessary permission.
[0105] In a possible implementation, in addition to candidate controls, the authorization request text box for any necessary permission further includes candidate options, which are used to indicate that it is not allowed to obtain the authorization result of un-authorized permissions by means of polling again. If it is detected that the interaction object selects this option, it indicates that the interaction object does not want to display the authorization request text box for un-authorized permissions again. It should be noted that since the candidate options are used to limit un-authorized permissions, the selection operation of the candidate options is effective only when the interaction object triggers the second control. In an exemplary embodiment, for any necessary permission, during the process of obtaining the authorization result of any necessary permission by means of polling, for the case where the interaction object triggers the second control, if the interaction object selects the candidate option, it indicates that the authorization result of any necessary permission is un-authorized and it is not allowed to obtain the authorization result of any necessary permission by means of polling again; if the interaction object does not select the candidate option, it indicates that the authorization result of any necessary permission is un-authorized and it is allowed to obtain the authorization result of any necessary permission by means of polling again.
[0106] In an exemplary embodiment, the authorization request text box for any necessary permission further includes the arrangement order information of any necessary permission among at least one necessary permission and the authorization request text corresponding to any necessary permission. In a possible implementation, the arrangement order information of any necessary permission among at least one necessary permission is directly determined according to the total number of items of at least one necessary permission and the arrangement order of any necessary permission among at least one necessary permission. The authorization request text corresponding to any necessary permission can be determined based on the correspondence between the permission type and the authorization request text. The correspondence between the permission type and the authorization request text records the authorization request texts corresponding to various types of permissions, and thus the authorization request text corresponding to any necessary permission can be directly determined.
[0107] Exemplarily, the process of displaying the authorization request text box for the first necessary permission is as Figure 5 shown. When a trigger operation of the determination control 501 is detected in (1) in Figure 5 , a confirmation instruction for obtaining the permission description information is obtained. After obtaining the confirmation instruction for the permission description information, based on the confirmation instruction for the permission description information, display as Figure 5The authorization request text box 502 of the first necessary permission shown in (2) in []. In the authorization request text box 502 of the first necessary permission, it includes the arrangement order information of the first necessary permission among at least one necessary permission, "Permission Item 1 (total 2 items)", the authorization request text corresponding to the first necessary permission, "Whether to allow XX to access the photos, media content and files on your device", the first control 503 for indicating prohibited authorization, the second control 504 for indicating permitted authorization, and the candidate option 505 for indicating that it is not allowed to obtain the authorization result of unauthorized permissions by polling again.
[0108] In a possible implementation manner, a necessary permission list is configured in the target permission control information. The general permission control information includes necessary permission list configuration information for the developer of the application to customize and configure the necessary permission list to meet the different requirements of different applications for the necessary permission list. After obtaining the general permission control information by directly calling, the developer of the application can customize the necessary permission list in the necessary permission list configuration information. Exemplarily, the necessary permission list configuration information is in the form of a list and is marked as "msdk_permission_list.xml".
[0109] The necessary permission list corresponding to the application is set by the developer of the application according to the actual situation of the application. It should be noted that the necessary permission list corresponding to the application includes all the necessary permissions required for the startup process of the application, that is, the necessary permission list corresponding to the application includes all the necessary permissions shown in the permission description information to avoid the situation where the application cannot be started.
[0110] After configuring the necessary permission list, the terminal will read the necessary permission list based on the confirmation instruction of the permission description information to further determine the necessary permissions for which the authorization result needs to be obtained according to the read necessary permission list.
[0111] In a possible implementation, the process by which the terminal further determines the necessary permissions for which authorization results need to be obtained based on the read necessary permission list is as follows: The terminal filters each necessary permission in the necessary permission list based on the permission configuration file local to the application, retains the necessary permissions that meet the retention conditions, and uses the retained necessary permissions as the necessary permissions for which authorization results need to be obtained. The permission configuration file local to the application is used to declare all the permissions corresponding to the application and the processing status of each permission. The processing status of any permission is used to indicate whether the permission is authorized. Exemplarily, the necessary permissions that meet the retention conditions refer to the necessary permissions declared in the permission configuration file local to the application that are not authorized. In an exemplary embodiment, not being authorized includes two cases: not having an authorization result, or having an authorization result but the authorization result being unauthorized. In an exemplary embodiment, the permission configuration file local to the application is the AndroidManifest.xml configuration file.
[0112] In an exemplary embodiment, for the case where the protocol information has not been confirmed, none of the necessary permissions corresponding to the application have obtained authorization results (i.e., none of them are authorized). Therefore, each necessary permission in the necessary permission list is a necessary permission that meets the retention conditions, and all the necessary permissions will be retained in the necessary permission list. That is to say, at least one necessary permission corresponding to the application is in the necessary permission list before obtaining the authorization result. In a possible implementation, during the process of polling to obtain the authorization results of at least one necessary permission, if the authorization result of a certain necessary permission is authorized, then that necessary permission is removed from the necessary permission list. That is to say, during the process of polling to obtain the authorization results of at least one necessary permission, the necessary permissions with an authorization result of authorized are removed from the necessary permission list.
[0113] In a possible implementation, after obtaining the authorization results of at least one necessary permission by means of polling, the authorization results of at least one necessary permission include the following two cases:
[0114] Case 1: The authorization results of all of the at least one necessary permissions are authorized.
[0115] In this Case 1, step 205 is executed.
[0116] Case 2: The authorization results of the at least one necessary permissions are not all authorized. That is to say, there is at least one target permission among the at least one necessary permissions for which the authorization result is unauthorized.
[0117] In a possible implementation, corresponding to the case where the necessary permissions with an authorization result of authorized are removed from the necessary permission list, in response to the necessary permission list after the removal process not being an empty list, it is determined that there is at least one target permission among the at least one necessary permissions for which the authorization result is unauthorized.
[0118] In this case 2, a selection control is presented. The selection control includes a re-authorization control and a settings control. In one possible implementation, the selection control is presented in the following way: presenting the selection control on the page where the permission description information is presented. In an exemplary embodiment, in addition to the re-authorization control and the settings control, the selection control further includes an exit control. For example, the schematic diagram of the presentation of the selection control is shown in FIG. 6. In Figure 6 the presented selection control, there are included a re-authorization control 601, a settings control 602, and an exit control 603.
[0119] The different controls in the selection control have different functions. The re-authorization control is used to control obtaining the authorization result of at least one first permission in a polling manner; the settings control is used to control obtaining the authorization result of at least one second permission by jumping to the system settings page; the exit control is used to control exiting the application. Among them, at least one first permission is the target permission that meets the conditions among at least one target permission, and at least one second permission is each of the target permissions among at least one target permission except at least one first permission; the target permission that meets the conditions is the target permission that allows obtaining the authorization result again in a polling manner.
[0120] By presenting the selection control, it can provide a reference for the selection of the interaction object. The interaction object can choose to re-authorize the necessary permissions, can also choose to authorize the necessary permissions in the system settings page, and can also choose to exit the current application. The terminal will perform corresponding operations according to the selection of the interaction object.
[0121] In one possible implementation, after presenting the selection control, it includes: based on the triggering operation of the re-authorization control, obtaining the authorization result of at least one first permission in a polling manner; based on the triggering operation of the settings control, obtaining the authorization result of at least one second permission by jumping to the system settings page; in response to the authorization results of at least one first permission and at least one second permission both being authorized, jumping to the corresponding startup main page of the application.
[0122] In one possible implementation, the process of obtaining the authorization result of at least one second permission by jumping to the system settings page is: jumping to the system settings page, and obtaining the authorization result of at least one second permission according to the settings of at least one second permission by the interaction object on the system settings page.
[0123] It should be noted that the above is the case where at least one target permission includes both a first permission and a second permission. In an exemplary embodiment, at least one target permission may only include a first permission, and at least one target permission may also only include a second permission.
[0124] In a possible implementation manner, for the case where at least one target permission only includes the second permission, since the second permission is a target permission that does not allow obtaining the authorization result again by means of polling, after detecting the trigger operation of the interaction object on the re-authorization control, the process of obtaining the authorization result by means of polling will not be executed. In this case, prompt text is displayed to inform the interaction object that it is necessary to trigger the setting control to go to the system settings page for authorization.
[0125] In a possible implementation manner, for the case where at least one target permission includes at least one first permission and at least one second permission, in response to the authorization results of at least one first permission and at least one second permission both being authorization, it jumps to the corresponding startup main page of the application. For the case where at least one target permission only includes at least one first permission, in response to the authorization results of at least one first permission all being authorization, it jumps to the corresponding startup main page of the application. For the case where at least one target permission only includes at least one second permission, in response to the authorization results of at least one second permission all being authorization, it jumps to the corresponding startup main page of the application. That is to say, in response to the authorization results of at least one target permission all being authorization, it jumps to the corresponding startup main page of the application.
[0126] The corresponding startup main page of the application refers to the page that needs to be displayed after the application is successfully started. In an exemplary embodiment, the corresponding startup main page of the application is configured in the target permission control information. The general permission control information includes startup main page configuration information for the developer of the application to customize the startup main page, so as to meet the different requirements of different applications for the startup main page. After the developer of the application obtains the general permission control information by means of direct call, the developer can customize and configure the startup main page in the startup main page configuration information. After jumping to the corresponding startup main page of the application, the entire process loop of permission control is completed.
[0127] In a possible implementation manner, for the case where the selection control includes, in addition to the re-selection control and the setting control, an exit control, after the selection control is displayed, it further includes: based on the trigger operation of the exit control, exiting the application.
[0128] In a possible implementation, if, after obtaining the authorization results of at least one target permission again, there are still un-authorized permissions among the at least one target permission, the selection control is displayed again until the interaction object actively triggers the exit control, or all necessary permissions are authorized, or the number of times the selection control is displayed reaches the threshold. When the interaction object actively triggers the exit control, the application is exited; if all necessary permissions are authorized, the application jumps to the startup main page; if the number of times the selection control is displayed reaches the threshold, the application is exited. The threshold is set according to experience or flexibly adjusted according to the application scenario, and the embodiments of the present application do not limit this.
[0129] In step 205, in response to the authorization results of all at least one necessary permission being authorized, the application jumps to the startup main page corresponding to the application.
[0130] If, after obtaining the authorization results of at least one necessary permission by polling, the authorization results of the at least one necessary permission are all authorized, the application directly jumps to the startup main page corresponding to the application. Thus, the permission control process loop is completed.
[0131] In a possible implementation, after jumping to the startup main page corresponding to the application, it further includes: in response to the operation to be executed corresponding to the application depending on the resources corresponding to any non-necessary permission, obtaining the authorization result of any non-necessary permission; in response to the authorization result of any non-necessary permission being authorized, executing the operation to be executed. Since only necessary permissions are authorized during the startup process of the application, the non-necessary permissions corresponding to the application may affect some execution operations. During the running process of the application, if the operation to be executed corresponding to the application depends on the resources corresponding to a certain non-necessary permission, the authorization result of the non-necessary permission is obtained, so as to determine whether to execute the operation to be executed according to the authorization result of the non-necessary permission. Based on this method, the authorization result of the non-necessary permission can be dynamically obtained when the resources corresponding to the non-necessary permission are needed.
[0132] In a possible implementation, the method for obtaining the authorization result of any non-necessary permission can be set by the developer of the application, and the embodiments of the present application do not limit this. Exemplarily, the method for obtaining the authorization result of any non-necessary permission is: a pop-up window displays the authorization request text box of the any non-necessary permission, and based on the triggering operation of the interaction object on the candidate control in the authorization request text box of the any non-necessary permission, the authorization result of the any non-necessary permission is obtained.
[0133] In an exemplary embodiment, the process of determining whether to perform the operation to be performed according to the authorization result of the non-essential permission is as follows: If the authorization result of the non-essential permission is obtained as authorized, the operation to be performed is executed; if the authorization result of the non-essential permission is not authorized, the operation to be performed is carried out. In a possible implementation manner, the process of executing the operation to be performed is: calling the resource corresponding to the non-essential permission and executing the operation to be performed based on the resource corresponding to the non-essential permission.
[0134] In the embodiments of the present application, the protocol information confirmation process and the essential permission authorization process are integrated to obtain a set of compliance processes for permission control. It is necessary to first display the protocol information for confirmation by the interaction object, and then apply for authorization of the essential permissions, which solves the problem of non-compliance such as the application starting to report data without the permission of the interaction object when it is launched. By guiding the interaction object through a concise application interface process and informing the protocol information corresponding to this application program and the permissions required to run this application program, the permission control process becomes more standardized and transparent, meeting the current policy trend.
[0135] In the embodiments of the present application, permission control is performed during the startup process of the application program, and the protocol information confirmation process is incorporated into the permission control process. After the protocol information is confirmed, the authorization result of the essential permissions is obtained. After all the essential permissions are authorized, the application jumps to the main startup page of the application program. Based on this process, permission control is performed before the application program is successfully started, which can avoid the phenomenon of performing operations that violate user privacy when the application program is launched. The permission control is more standardized and effective, which is beneficial to improving the protection of user privacy and has a higher security level.
[0136] Based on the above Figure 1 shown implementation environment, the embodiments of the present application provide a permission control method, taking this method applied to the terminal 101 as an example. As Figure 7 shown, the method provided by the embodiments of the present application includes the following steps:
[0137] In step 701, based on the startup instruction of the application program, determine the processing status of the protocol information corresponding to the application program.
[0138] For the implementation process of this step 701, refer to step 201, which will not be elaborated here.
[0139] In step 702, in response to the processing status of the protocol information being confirmed, detect the processing status of at least one essential permission corresponding to the application program.
[0140] When the processing status of the protocol information is that the protocol information is confirmed to be outdated, it indicates that the interaction object has confirmed the protocol information before. In a possible implementation manner, the method for determining that the processing status of the protocol information is that the protocol information has been confirmed is as follows: in response to the confirmation marker information of the protocol information being included in the first local storage information of the application, determining that the processing status of the protocol information is that the protocol information has been confirmed; or, in response to the login information of the application being included in the second local storage information of the application, determining that the processing status of the protocol information is that the protocol information has been confirmed.
[0141] When the processing status of the protocol information is that the protocol information has been confirmed, detect the processing status of at least one necessary permission corresponding to the application. The processing status of any necessary permission is used to indicate whether the any necessary permission is authorized.
[0142] In a possible implementation manner, the processing status of at least one necessary permission corresponding to the application is declared in the permission configuration file local to the application. By detecting the processing status of each necessary permission declared in the permission configuration file local to the application, the processing status of at least one necessary permission corresponding to the application can be obtained.
[0143] The processing status of at least one necessary permission includes the following two cases:
[0144] Case 1: The processing status of at least one necessary permission indicates that all of the at least one necessary permissions are authorized.
[0145] In this Case 1, directly jump to the startup main page of the application.
[0146] Case 2: The processing status of at least one necessary permission indicates that there is at least one reference permission among the at least one necessary permissions that is not authorized.
[0147] In this Case 2, execute step 703.
[0148] In a possible implementation manner, the occurrence conditions for the case where the processing status of at least one necessary permission indicates that there is at least one reference permission among the at least one necessary permissions that is not authorized include, but are not limited to, the following two:
[0149] Occurrence condition 1: Before obtaining the startup instruction of the application, no version of the application has been successfully started.
[0150] Under this occurrence condition 1, since the protocol information has been confirmed, the reason for the failure to start successfully is that there is at least one necessary permission that is not authorized among the necessary permissions. In an exemplary embodiment, during a permission control process, if the application program fails to start successfully, the authorization result obtained during this permission control process will not be saved. Based on this, if any version of this application program fails to start successfully, it means that each necessary permission does not have an authorization result. That is to say, each necessary permission is an unauthorized reference permission, and the number of reference permissions is the same as the number of necessary permissions.
[0151] Occurrence condition 2: The application program that the start instruction needs to start is a new version of the application program obtained by overwriting the old version of the application program. Among the at least one necessary permission corresponding to the new version of the application program, in addition to including all the necessary permissions corresponding to the old version of the application program, it also includes new necessary permissions. In addition, before obtaining the start instruction of the new version of the application program, the old version of the application program has been successfully started but the new version of the application program has not been successfully started.
[0152] Since the application program to be started is the application program obtained by overwriting the old version of the application program and the old version of the application program has been successfully started, all the necessary permissions corresponding to the old version of the application program are authorized. Since among the at least one necessary permission corresponding to the new version of the application program, in addition to including all the necessary permissions corresponding to the old version of the application program, it also includes new necessary permissions. Therefore, if the new version of the application program fails to start successfully, it means that there is at least one necessary permission that is not authorized among the new necessary permissions.
[0153] In an exemplary embodiment, for the situation where during a permission control process, if the application program fails to start successfully, the authorization result obtained during this permission control process will not be saved, none of the new necessary permissions among the at least one necessary permission corresponding to the new version of the application program have an authorization result. In this case, each new necessary permission is an unauthorized reference permission. The number of reference permissions is the same as the number of new necessary permissions.
[0154] In step 703, in response to the processing status of at least one necessary permission indicating that there is at least one unauthorized reference permission among the at least one necessary permission, permission description information is displayed.
[0155] When the processing status of at least one necessary permission indicates that there is at least one unauthorized reference permission among the at least one necessary permission, permission description information is displayed to prompt the interaction object to enter the permission authorization process next.
[0156] The process of displaying the permission description information can refer to Step 203 and will not be elaborated here. In an exemplary embodiment, the permission description information displayed here is still used to prompt and explain all the permissions corresponding to the application.
[0157] In Step 704, based on the confirmation instruction of the permission description information, the authorization results of at least one reference permission are obtained by means of polling.
[0158] For the implementation process of this Step 704, refer to Step 204 and will not be elaborated here. It should be noted that compared with obtaining the authorization results of at least one necessary permission by means of polling in Step 204, since only at least one reference permission is not authorized at this time, only the authorization results of at least one reference permission need to be obtained by means of polling.
[0159] In an exemplary embodiment, the at least one reference permission is in the reference permission list before obtaining the authorization result. Exemplarily, the reference permission list refers to the permission list composed of the necessary permissions retained after filtering each necessary permission in the necessary permission list based on the local permission configuration file of the application.
[0160] In a possible implementation manner, when there is a permission with an unauthorized authorization result among the at least one reference permission, a selection control is displayed. For the implementation manner of this process, refer to the relevant process of Step 204 and will not be elaborated here.
[0161] In Step 705, in response to the authorization results of all the at least one reference permission being authorized, it jumps to the startup main page corresponding to the application.
[0162] When the authorization results of all the at least one reference permission are authorized, it indicates that all the at least one necessary permissions corresponding to the application are authorized. At this time, it jumps to the startup main page corresponding to the application.
[0163] In the embodiments of the present application, permission control is performed during the startup process of the application, and the confirmation process of the protocol information is incorporated into the permission control process. After the protocol information is confirmed, the authorization results of the necessary permissions are obtained. After all the necessary permissions are authorized, it jumps to the startup main page of the application. Based on this process, permission control is performed before the application is successfully started, which can avoid the phenomenon of performing operations that violate user privacy when the application starts. The permission control is more standardized and effective, which is beneficial to improving the protection of user privacy and has higher security.
[0164] In an exemplary embodiment, the permission control process is as Figure 8As shown in the figure. After obtaining the startup instruction of the application, it is determined whether the protocol information has been confirmed. When the protocol information has not been confirmed, the protocol information is displayed. It is determined whether the protocol information has been confirmed. When the protocol information has not been confirmed, the application is exited. When the protocol information has been confirmed, the permission description information is displayed, and then the authorization results of all necessary permissions are obtained. It is determined whether the authorization results of all necessary permissions are all authorized. If the authorization results of all necessary permissions are all authorized, it jumps to the startup main page; if the authorization results of all necessary permissions are not all authorized, it returns to the step of displaying the permission description information, and a selection control is displayed on the page where the permission description information is displayed. If a trigger operation of the re-authorization control or the setting control is detected, the authorization results of the necessary permissions are continuously obtained; if a trigger operation in the exit control is detected, the application is exited.
[0165] When the protocol information has not been confirmed and there are unauthorized reference permissions in at least one necessary permission, the step of displaying the permission description information is executed. Then the authorization results of all reference permissions are obtained. It is determined whether the authorization results of all necessary permissions are all authorized. If the authorization results of all necessary permissions are all authorized, it jumps to the startup main page; if the authorization results of all necessary permissions are not all authorized, it returns to the step of displaying the permission description information, and a selection control is displayed on the page where the permission description information is displayed. If a trigger operation of the re-authorization control or the setting control is detected, the authorization results of the reference permissions are continuously obtained; if a trigger operation in the exit control is detected, the application is exited.
[0166] See Figure 9 , an embodiment of the present application provides a permission control device, and the device includes:
[0167] A determination module 901, configured to determine the processing status of the protocol information corresponding to the application based on the startup instruction of the application;
[0168] A display module 902, configured to display the protocol information in response to the processing status of the protocol information being that the protocol information has not been confirmed;
[0169] The display module 902 is further configured to display the permission description information corresponding to the application based on the confirmation instruction of the protocol information, and the permission description information is used to prompt and explain at least one necessary permission corresponding to the application;
[0170] An acquisition module 903, configured to obtain the authorization results of at least one necessary permission in a polling manner based on the confirmation instruction of the permission description information;
[0171] A jump module 904, configured to jump to the startup main page corresponding to the application in response to the authorization results of at least one necessary permission all being authorized.
[0172] In a possible implementation manner, the display module 902 is further configured to display a selection control in response to at least one target permission among at least one necessary permission having an unauthorized authorization result. The selection control includes a re-authorization control and a settings control;
[0173] The acquisition module 903 is further configured to, based on a trigger operation of the re-authorization control, obtain the authorization results of at least one first permission by means of polling. The at least one first permission is the target permission among the at least one target permission that meets the condition. The target permission that meets the condition is the target permission that allows obtaining the authorization result again by means of polling; based on a trigger operation of the settings control, obtain the authorization results of at least one second permission by means of jumping to the system settings page. The at least one second permission is each target permission among the at least one target permission except the at least one first permission;
[0174] The jump module 904 is further configured to jump to the corresponding startup main page of the application in response to the authorization results of at least one first permission and at least one second permission both being authorized.
[0175] In a possible implementation manner, the selection control further includes an exit control. Refer to Figure 10 and the device further includes:
[0176] The exit module 905 is configured to exit the application based on a trigger operation of the exit control.
[0177] In a possible implementation manner, all of the at least one necessary permissions are in the necessary permission list before obtaining the authorization results; refer to Figure 10 and the device further includes:
[0178] The elimination module 906 is configured to eliminate the necessary permissions with an authorized authorization result from the necessary permission list;
[0179] The determination module 901 is further configured to determine that at least one target permission among at least one necessary permission has an unauthorized authorization result in response to the necessary permission list after the elimination process not being an empty list.
[0180] In a possible implementation manner, refer to Figure 10 and the device further includes:
[0181] The detection module 907 is configured to detect the processing status of at least one necessary permission corresponding to the application in response to the processing status of the protocol information being confirmed;
[0182] The display module 902 is further configured to display permission description information in response to the processing status of at least one necessary permission indicating that at least one reference permission among at least one necessary permission is not authorized;
[0183] The obtaining module 903 is further configured to obtain the authorization results of at least one reference permission in a polling manner based on the confirmation instruction of the permission description information;
[0184] The jumping module 904 is further configured to jump to the startup main page corresponding to the application in response to the authorization results of at least one reference permission all being authorized.
[0185] In a possible implementation manner, the determining module 901 is further configured to determine that the processing status of the protocol information is that the protocol information has been confirmed in response to the confirmation flag information of the protocol information being included in the first local storage information of the application; or, determine that the processing status of the protocol information is that the protocol information has been confirmed in response to the login information of the application being included in the second local storage information of the application.
[0186] In a possible implementation manner, the obtaining module 903 is further configured to obtain the authorization result of any non-essential permission in response to the resource corresponding to any non-essential permission being required for the to-be-executed operation corresponding to the application.
[0187] See Figure 10 , the apparatus further includes:
[0188] The execution module 908 is configured to execute the to-be-executed operation in response to the authorization result of any non-essential permission being authorized.
[0189] In a possible implementation manner, the application is configured with target permission control information for indicating the permission control mode of the application, and the target permission control information is obtained by customizing the template configuration information in the directly called general permission control information.
[0190] In the embodiments of the present application, permission control is performed during the startup process of the application, and the confirmation process of the protocol information is incorporated during the permission control process. After the protocol information is confirmed, the authorization results of the necessary permissions are obtained. After all the necessary permissions are authorized, the startup main page of the application is jumped to. Based on this process, permission control is performed before the application is successfully started, which can avoid the phenomenon of performing operations that violate user privacy when the application starts. The permission control is more standardized and effective, which is beneficial to improving the protection of user privacy and has higher security.
[0191] It should be noted that when the apparatus provided in the above embodiments implements its functions, only the above-mentioned division of each functional module is used for illustration. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the apparatus provided in the above embodiments and the method embodiments belong to the same concept, and the specific implementation process is detailed in the method embodiments and will not be repeated here.
[0192] Figure 11 It is a schematic structural diagram of a permission control device provided by an embodiment of the present application. The device can be a terminal, for example, it can be: a smart phone, a tablet computer, a notebook computer or a desktop computer. The terminal may also be referred to by other names such as user equipment, portable terminal, laptop terminal, desktop terminal, etc.
[0193] Generally, the terminal includes: a processor 1101 and a memory 1102.
[0194] The processor 1101 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 1101 can be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), and PLA (Programmable Logic Array). The processor 1101 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the wake state, also known as the CPU (Central Processing Unit); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 1101 may be integrated with a GPU (Graphics Processing Unit), and the GPU is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 1101 may also include an AI (Artificial Intelligence) processor, and the AI processor is used to process computational operations related to machine learning.
[0195] The memory 1102 may include one or more computer-readable storage media, and the computer-readable storage media may be non-transitory. The memory 1102 may also include high-speed random access memory and non-volatile memory, such as one or more disk storage devices and flash storage devices. In some embodiments, the non-transitory computer-readable storage medium in the memory 1102 is used to store at least one instruction, and the at least one instruction is used to be executed by the processor 1101 to implement the permission control method provided by the method embodiment of the present application.
[0196] In some embodiments, the terminal may further optionally include: a peripheral device interface 1103 and at least one peripheral device. The processor 1101, the memory 1102, and the peripheral device interface 1103 may be connected via a bus or signal lines. Each peripheral device may be connected to the peripheral device interface 1103 via a bus, signal lines, or a circuit board. Specifically, the peripheral device includes at least one of: a radio frequency circuit 1104, a display screen 1105, a camera assembly 1106, an audio circuit 1107, and a power supply 1109.
[0197] The peripheral device interface 1103 can be used to connect at least one peripheral device related to I / O (Input / Output) to the processor 1101 and the memory 1102. In some embodiments, the processor 1101, the memory 1102, and the peripheral device interface 1103 are integrated on the same chip or circuit board; in some other embodiments, any one or two of the processor 1101, the memory 1102, and the peripheral device interface 1103 can be implemented on a separate chip or circuit board, and this embodiment does not limit this.
[0198] The radio frequency circuit 1104 is used to receive and transmit RF (Radio Frequency) signals, also known as electromagnetic signals. The radio frequency circuit 1104 communicates with a communication network and other communication devices via electromagnetic signals. The radio frequency circuit 1104 converts an electrical signal into an electromagnetic signal for transmission, or converts the received electromagnetic signal into an electrical signal. Optionally, the radio frequency circuit 1104 includes: an antenna system, an RF transceiver, one or more amplifiers, a tuner, an oscillator, a digital signal processor, a codec chipset, a user identity module card, and so on. The radio frequency circuit 1104 can communicate with other terminals via at least one wireless communication protocol. The wireless communication protocol includes but is not limited to: a metropolitan area network, each generation of mobile communication networks (2G, 3G, 4G, and 5G), a wireless local area network, and / or a WiFi (Wireless Fidelity) network. In some embodiments, the radio frequency circuit 1104 may further include a circuit related to NFC (Near Field Communication), and this application does not limit this.
[0199] The display screen 1105 is used to display the UI (User Interface). The UI may include graphics, text, icons, videos, and any combination thereof. When the display screen 1105 is a touch display screen, the display screen 1105 also has the ability to collect touch signals on or above the surface of the display screen 1105. The touch signals can be input to the processor 1101 as control signals for processing. At this time, the display screen 1105 can also be used to provide virtual buttons and / or virtual keyboards, also known as soft buttons and / or soft keyboards. In some embodiments, there may be one display screen 1105, which is disposed on the front panel of the terminal; in other embodiments, there may be at least two display screens 1105, which are respectively disposed on different surfaces of the terminal or are in a folded design; in still other embodiments, the display screen 1105 may be a flexible display screen, which is disposed on the curved surface or the folding surface of the terminal. Even further, the display screen 1105 can be set to an irregular non-rectangular shape, that is, a special-shaped screen. The display screen 1105 can be prepared using materials such as LCD (Liquid Crystal Display) and OLED (Organic Light-Emitting Diode).
[0200] The camera module 1106 is used to capture images or videos. Optionally, the camera module 1106 includes a front camera and a rear camera. Generally, the front camera is disposed on the front panel of the terminal, and the rear camera is disposed on the back of the terminal. In some embodiments, there are at least two rear cameras, which are any one of a main camera, a depth camera, a wide-angle camera, and a telephoto camera, to implement functions such as background blurring by fusing the main camera and the depth camera, panoramic shooting by fusing the main camera and the wide-angle camera, and VR (Virtual Reality) shooting functions or other fused shooting functions. In some embodiments, the camera module 1106 may further include a flash. The flash can be a single-color temperature flash or a two-color temperature flash. A two-color temperature flash refers to a combination of a warm light flash and a cold light flash, which can be used for light compensation under different color temperatures.
[0201] The audio circuit 1107 may include a microphone and a speaker. The microphone is used to collect sound waves of the user and the environment, and convert the sound waves into electrical signals for input to the processor 1101 for processing, or input to the radio frequency circuit 1104 to achieve voice communication. For the purpose of stereo collection or noise reduction, there may be multiple microphones, which are respectively arranged at different parts of the terminal. The microphone may also be an array microphone or an omnidirectional collection microphone. The speaker is used to convert the electrical signal from the processor 1101 or the radio frequency circuit 1104 into sound waves. The speaker may be a traditional thin film speaker or a piezoelectric ceramic speaker. When the speaker is a piezoelectric ceramic speaker, it can not only convert the electrical signal into sound waves audible to humans, but also convert the electrical signal into sound waves inaudible to humans for uses such as ranging. In some embodiments, the audio circuit 1107 may further include a headphone jack.
[0202] The power supply 1109 is used to supply power to each component in the terminal. The power supply 1109 may be alternating current, direct current, a disposable battery or a rechargeable battery. When the power supply 1109 includes a rechargeable battery, the rechargeable battery may support wired charging or wireless charging. The rechargeable battery may also be used to support fast charging technology.
[0203] In some embodiments, the terminal further includes one or more sensors 1110. The one or more sensors 1110 include but are not limited to: an acceleration sensor 1111, a gyroscope sensor 1112, a pressure sensor 1113, an optical sensor 1115, and a proximity sensor 1116.
[0204] The acceleration sensor 1111 can detect the magnitude of acceleration on the three coordinate axes of the coordinate system established by the terminal. For example, the acceleration sensor 1111 can be used to detect the components of the gravitational acceleration on the three coordinate axes. The processor 1101 can control the display screen 1105 to display the user interface in a landscape view or a portrait view according to the gravitational acceleration signal collected by the acceleration sensor 1111. The acceleration sensor 1111 can also be used for collecting game or user movement data.
[0205] The gyroscope sensor 1112 can detect the body direction and rotation angle of the terminal. The gyroscope sensor 1112 can cooperate with the acceleration sensor 1111 to collect the 3D actions of the user on the terminal. According to the data collected by the gyroscope sensor 1112, the processor 1101 can achieve the following functions: motion sensing (such as changing the UI according to the user's tilting operation), image stabilization during shooting, game control, and inertial navigation.
[0206] The pressure sensor 1113 can be disposed on the side frame of the terminal and / or the lower layer of the display screen 1105. When the pressure sensor 1113 is disposed on the side frame of the terminal, it can detect the holding signal of the user on the terminal, and the processor 1101 can perform left / right hand recognition or quick operation according to the holding signal collected by the pressure sensor 1113. When the pressure sensor 1113 is disposed on the lower layer of the display screen 1105, the processor 1101 can control the operable controls on the UI interface according to the pressure operation of the user on the display screen 1105. The operable controls include at least one of button controls, scroll bar controls, icon controls, and menu controls.
[0207] The optical sensor 1115 is used to collect the ambient light intensity. In one embodiment, the processor 1101 can control the display brightness of the display screen 1105 according to the ambient light intensity collected by the optical sensor 1115. Specifically, when the ambient light intensity is high, the display brightness of the display screen 1105 is increased; when the ambient light intensity is low, the display brightness of the display screen 1105 is decreased. In another embodiment, the processor 1101 can also dynamically adjust the shooting parameters of the camera module 1106 according to the ambient light intensity collected by the optical sensor 1115.
[0208] The proximity sensor 1116, also known as the distance sensor, is usually disposed on the front panel of the terminal. The proximity sensor 1116 is used to collect the distance between the user and the front of the terminal. In one embodiment, when the proximity sensor 1116 detects that the distance between the user and the front of the terminal is gradually decreasing, the processor 1101 controls the display screen 1105 to switch from the lit state to the off state; when the proximity sensor 1116 detects that the distance between the user and the front of the terminal is gradually increasing, the processor 1101 controls the display screen 1105 to switch from the off state to the lit state.
[0209] Those skilled in the art can understand that Figure 11 the structure shown in does not constitute a limitation on the terminal, and it may include more or fewer components than shown in the figure, or combine certain components, or adopt different component arrangements.
[0210] In an exemplary embodiment, a computer device is further provided. The computer device includes a processor and a memory, and at least one program code is stored in the memory. The at least one program code is loaded and executed by one or more processors to implement any one of the above permission control methods.
[0211] In an exemplary embodiment, a computer-readable storage medium is further provided. At least one program code is stored in the computer-readable storage medium, and the at least one program code is loaded and executed by the processor of the computer device to implement any one of the above permission control methods.
[0212] In one possible implementation, the above-mentioned computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a compact disc read-only memory (CD-ROM), magnetic tape, floppy disk, optical data storage device, etc.
[0213] In an exemplary embodiment, there is also provided a computer program product or a computer program. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes any one of the above-mentioned permission control methods.
[0214] It should be understood that the "plurality" mentioned herein refers to two or more. "And / or" describes the association relationship of associated objects and indicates that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after.
[0215] The above are only exemplary embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A permission control method, characterized in that, The method includes: Based on the startup instruction of the application, determining the processing status of the protocol information corresponding to the application; In response to the processing status of the protocol information being that the protocol information has been confirmed, detecting the processing status of at least one necessary permission corresponding to the application, where the processing status of any necessary permission is used to indicate whether the any necessary permission is authorized, and the necessary permission refers to the permission required to start the application; In response to the processing status of the at least one necessary permission indicating that there is at least one reference permission among the at least one necessary permission that is not authorized, presenting the permission description information corresponding to the application, where the permission description information is used to prompt and explain the at least one necessary permission corresponding to the application; Based on the confirmation instruction of the permission description information, obtaining the authorization result of the at least one reference permission by means of polling; In response to the authorization results of the at least one reference permission all being authorized, jumping to the startup main page corresponding to the application; Wherein, the application to be started by the startup instruction is a new version of the application obtained by overwriting the old version of the application, the reference permission is the necessary permission among the newly added necessary permissions that is not authorized, and the newly added necessary permissions are the necessary permissions corresponding to the new version of the application except for the necessary permissions corresponding to the old version of the application.
2. The method according to claim 1, characterized in that, Before the step of detecting the processing status of at least one necessary permission corresponding to the application in response to the processing status of the protocol information being that the protocol information has been confirmed, the method further includes: In response to the first local storage information of the application including the confirmation mark information of the protocol information, determining that the processing status of the protocol information is that the protocol information has been confirmed; or, In response to the second local storage information of the application including the login information of the application, determining that the processing status of the protocol information is that the protocol information has been confirmed.
3. The method according to claim 1 or 2, characterized in that, After the step of jumping to the startup main page corresponding to the application, the method further includes: In response to the operation to be executed corresponding to the application depending on the resources corresponding to any non-necessary permission, obtaining the authorization result of the any non-necessary permission; In response to the authorization result of the any non-necessary permission being authorized, executing the operation to be executed.
4. The method according to claim 1 or 2, characterized in that, The application is configured with target permission control information for indicating the permission control method of the application, and the target permission control information is obtained by customizing the template configuration information in the directly called general permission control information.
5. A permission control device, characterized in that, The device includes: A determination module, configured to determine the processing status of the protocol information corresponding to the application based on the startup instruction of the application; A detection module, configured to, in response to the processing status of the protocol information being that the protocol information has been confirmed, detect the processing status of at least one necessary permission corresponding to the application, where the processing status of any necessary permission is used to indicate whether the any necessary permission is authorized, and the necessary permission refers to the permission required to start the application; A display module, configured to respond to a processing status of the at least one necessary permission to indicate that there is at least one reference permission among the at least one necessary permissions that is not authorized, and display permission description information corresponding to the application, where the permission description information is used to prompt and explain the at least one necessary permission corresponding to the application; An acquisition module, configured to obtain an authorization result of the at least one reference permission in a polling manner based on a confirmation instruction of the permission description information; A jump module, configured to jump to a startup main page corresponding to the application in response to that the authorization results of the at least one reference permission are all authorized; Wherein, the application to be started by the startup instruction is a new version of the application obtained by overwriting an old version of the application, the reference permission is a necessary permission among the newly added necessary permissions that is not authorized, and the newly added necessary permissions are necessary permissions corresponding to the new version of the application except for the necessary permissions corresponding to the old version of the application.
6. The device according to claim 5, wherein The determination module is further configured to, in response to that a confirmation flag information of the protocol information is included in the first local storage information of the application, determine that the processing status of the protocol information is that the protocol information has been confirmed; or, In response to that login information of the application is included in the second local storage information of the application, determine that the processing status of the protocol information is that the protocol information has been confirmed.
7. The device according to claim 5 or 6, characterized in that The acquisition module is further configured to, in response to that an operation to be executed corresponding to the application depends on a resource corresponding to any non-necessary permission, obtain an authorization result of the any non-necessary permission; The apparatus further includes: An execution module, configured to execute the operation to be executed in response to that the authorization result of the any non-necessary permission is authorized.
8. The device according to claim 5 or 6, characterized in that, The application is configured with target permission control information for indicating a permission control manner of the application, and the target permission control information is obtained by customizing template configuration information in the directly called general permission control information.
9. A computer device, characterized in that, The computer device includes a processor and a memory, and at least one program code is stored in the memory, and the at least one program code is loaded and executed by the processor to implement the permission control method according to any one of claims 1 to 4.
10. A computer-readable storage medium, characterized in that, At least one program code is stored in the computer-readable storage medium, and the at least one program code is loaded and executed by a processor to implement the permission control method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Method, system, client and server for installing software
CN101256500A
Method and device for installing application program on basis of intelligent terminal equipment
CN103870306A
Method and device for acquiring system authority for application program
CN108133124A