Screen capture control method and device, computer readable medium and electronic device

By monitoring and processing screenshot operations, and by adding account information or watermarks based on application blacklists, the inconvenience and information security issues caused by screenshot permission settings in existing technologies are resolved, achieving a balance between information security and traceability.

CN112149104BActive Publication Date: 2026-01-02TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202011061496.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-09-30
Publication Date
2026-01-02
Estimated Expiration
2041-01-11

AI Technical Summary

Technical Problem

While existing technologies can prevent information leakage by disabling screenshot permissions, this leads to user inconvenience, fails to meet the screenshot needs of specific interfaces, and still poses information security risks.

Method used

By monitoring screenshot operations on the target application's display interface, it determines whether the application is on the screenshot blacklist. If it is on the blacklist, the image is deleted; otherwise, account information or an invisible watermark is added to the image, and a second image is generated.

Benefits of technology

It enables reasonable screenshot operations while ensuring information security, preventing the leakage of important information, and supporting information traceability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112149104B_ABST
    Figure CN112149104B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a screenshot control method and device, a computer readable medium and an electronic device. The screenshot control method comprises: monitoring a screenshot operation on a display interface of a target application, the target application being logged in with account information; after a first picture is obtained through the screenshot operation, determining whether the target application is in a screenshot application blacklist; if the target application is in the screenshot application blacklist, deleting the first picture; and if the target application is not in the screenshot application blacklist, adding the account information in the first picture to generate a second picture. The technical solution of the embodiments of the present application can not only guarantee the security of information, but also realize tracing of the information.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of computer and communication, in particular, to a screenshot control method and device, computer readable medium and electronic equipment. BACKGROUND

[0002] At present, when a user browses information by using a mobile terminal, the user usually saves information of interest or information of value by means of a screenshot (referred to as screenshot) in order to view the information or share the information with friends or family members.

[0003] However, if all screenshots are allowed, there may be information security risks for some important information. Therefore, in the prior art, a screenshot permission can be disabled to prohibit all screenshot behaviors. For example, when a user terminal identifies an input environment of confidential information, a secure input keyboard is started and a security protection function is started, and an interface for calling a screenshot and / or a screen recording is prohibited, so as to achieve the purpose of prohibiting screenshots. However, this results in extremely inconvenient user operation and cannot meet the screenshot requirements of a specific interface. For example, if screenshots are directly prohibited in a government WeChat or an enterprise WeChat, the chat record cannot be shared to the government WeChat or the enterprise WeChat, resulting in high communication costs. SUMMARY

[0004] Embodiments of the present application provide a screenshot control method, device, computer readable medium and electronic equipment, so as to at least ensure the security of information and trace the information to a certain extent.

[0005] Other characteristics and advantages of the present application will become apparent from the following detailed description, or will be learned by practice of the present application.

[0006] According to an aspect of an embodiment of the present application, a screenshot control method is provided, comprising: monitoring a screenshot operation on a display interface of a target application, the target application being logged in with account information; after a first picture is obtained through the screenshot operation, determining whether the target application is in a screenshot application blacklist; if the target application is in the screenshot application blacklist, deleting the first picture; and if the target application is not in the screenshot application blacklist, adding the account information to the first picture to generate a second picture.

[0007] According to an aspect of some embodiments of the present application, a screenshot control apparatus is provided, comprising: a monitoring unit configured to monitor a screenshot operation on a display interface of a target application, the target application being logged in with account information; a judging unit configured to, after the first picture is obtained through the screenshot operation, judge whether the target application is in a screenshot application blacklist; a first deleting unit configured to, if the target application is in the screenshot application blacklist, delete the first picture; and a generating unit configured to, if the target application is not in the screenshot application blacklist, add the account information in the first picture to generate a second picture.

[0008] In some embodiments of the present application, based on the foregoing scheme, the generating unit is configured to: synthesize the account information into invisible watermark information; and embed the invisible watermark information into the first picture to generate the second picture.

[0009] In some embodiments of the present application, based on the foregoing scheme, the apparatus further comprises: a detecting unit configured to detect whether the second picture contains sensitive information; and a second deleting unit configured to, if it is detected that the second picture contains the sensitive information, delete the second picture from a first storage space, the first storage space storing the second picture.

[0010] In some embodiments of the present application, based on the foregoing scheme, the apparatus further comprises: the detecting unit configured to detect whether the second picture contains sensitive information; and a first determining unit configured to, if it is detected that the second picture contains the sensitive information, determine a target processing mode for the second picture according to a security level corresponding to the sensitive information and a corresponding relationship between security levels and processing modes.

[0011] In some embodiments of the present application, based on the foregoing scheme, the first determining unit is configured to: if the security level of the sensitive information is a first security level, take a first processing mode corresponding to the first security level as the target processing mode for the second picture, the first processing mode being moving the second picture from a first storage space to a second storage space and generating a screenshot record according to the second picture, the screenshot record containing the account information; and if the security level of the sensitive information is a second security level lower than the first security level, take a second processing mode corresponding to the second security level as the target processing mode for the second picture, the second processing mode being generating the screenshot record according to the second picture, the screenshot record containing the account information.

[0012] In some embodiments of the present application, based on the foregoing scheme, the apparatus further comprises: an acquisition unit configured to acquire a second picture to be processed, the second picture to be processed being a source of leakage of the target sensitive information; an analysis unit configured to analyze the second picture to be processed to obtain target account information added to the second picture to be processed; and a second determination unit configured to determine that an owner of the target account information is a leakage party of the target sensitive information if a target screenshot record is found according to the target account information.

[0013] In some embodiments of the present application, based on the foregoing scheme, the detection unit is configured to: acquire text information in the second picture; and determine that the second picture contains sensitive information if the text information contains a keyword matching a sensitive word included in a preset sensitive information set.

[0014] According to an aspect of some embodiments of the present application, a computer readable medium having a computer program stored thereon is provided, the computer program being executed by a processor to implement the screenshot control method as described in the above embodiments.

[0015] According to an aspect of some embodiments of the present application, an electronic device is provided, comprising: one or more processors; and a storage device configured to store one or more programs, the one or more programs being executed by the one or more processors to cause the one or more processors to implement the screenshot control method as described in the above embodiments.

[0016] According to an aspect of some embodiments of the present application, a computer program product or computer program is provided, the computer program product or computer program comprising computer instructions stored in a computer readable storage medium. A processor of a computer device reads the computer instructions from the computer readable storage medium, and the processor executes the computer instructions to cause the computer device to perform the screenshot control method provided in the various optional embodiments described above.

[0017] In the technical scheme provided in some embodiments of the present application, by monitoring the screenshot operation on the display interface of the target application, after the first picture obtained by the screenshot operation is monitored, it is further judged whether the target application is in the screenshot blacklist, if the target application is in the screenshot application blacklist, the first picture is deleted; if the target application is not in the screenshot application blacklist, account information is added in the first picture to generate a second picture. Unlike the prior art which disables all screenshot behaviors by setting the screenshot permission, the technical scheme of the embodiments of the present application determines different screenshot control modes through the screenshot application blacklist and the added account information, which not only prevents the problem of important information being leaked and ensures the safety of important information, but also facilitates the tracing of information.

[0018] It should be understood that the foregoing general description and the following detailed description are only examples and explanatory, and are not restrictive of the application. BRIEF DESCRIPTION OF DRAWINGS

[0019] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the application and serve to explain the principles of the application. It is readily apparent to one skilled in the art that the following described embodiments are only exemplary and that other embodiments can be realized based on these drawings without paying creative labor. In the drawings:

[0020] Figure 1 An application scenario diagram of a screenshot control method according to an embodiment of the application is shown;

[0021] Figure 2 A flowchart of a screenshot control method according to an embodiment of the application is shown;

[0022] Figure 3 A flowchart of a screenshot control method according to an embodiment of the application is shown;

[0023] Figure 4 A flowchart of a screenshot control method according to an embodiment of the application is shown;

[0024] Figure 5 A flowchart of a screenshot control method according to an embodiment of the application is shown;

[0025] Figure 6 A flowchart of a screenshot control method according to an embodiment of the application is shown;

[0026] Figure 7 A logic judgment diagram of a screenshot control method according to an embodiment of the application is shown;

[0027] Figure 8 A logic judgment diagram of a method for determining a leakage side of target sensitive information according to an embodiment of the application is shown;

[0028] Figure 9 A block diagram of a screenshot control device according to an embodiment of the application is shown;

[0029] Figure 10 A structural schematic diagram of a computer system of an electronic device suitable for implementing embodiments of the application is shown. DETAILED DESCRIPTION

[0030] Example implementations are now described with reference to the drawings. Example implementations can, however, be implemented in many different forms and should not be construed as limited to the examples set forth herein; rather, these implementations are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the example implementations to those skilled in the art.

[0031] Moreover, the described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of embodiments of the application. One skilled in the relevant art will recognize, however, that the

[0032] It should be noted that the foregoing description has been directed to specific embodiments of the application. It is understood that other variations and modifications can be made to the procedures described and illustrated, and such variations and modifications can be made without departing from the spirit and scope of the application. It is, therefore, to be understood that this application is not limited to the particular examples described herein but includes all such as can fall within the scope of the application. Accordingly, the specification and drawings are to be regarded in an illustrative, rather than a restrictive, sense.

[0033] It will be further understood that, although the terms "first", "second", "third", etc. can be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, a first element could later be termed a second element without departing from the scope of the present application. Similarly, the terms "comprise", "comprising", "include", "including", and the like, are synonymous with the term "contain" and are used herein to indicate the presence of stated elements or integers or groups thereof, but not to the exclusion of any other elements or integers or groups thereof. It is noted that, as used in this specification and the appended claims, the singular forms "a", "an" and "the" include plural referents unless expressly and unequivocally limited by the context.

[0034] The block diagrams in the drawings show only the functionality of the example implementations and do not imply any particular physical or software

[0035] The flow diagrams depicted herein are merely examples and that numerous variations and modifications can be made to these diagrams without departing from the spirit and scope of the application. For instance, the operations can be performed in a differing order, or additional operations can be added, or others deleted without departing from the spirit or scope of the application. Further, terms such as "first", "second", "third", etc. are used herein not to denote absolute sequence, but to denote different features.

[0036] It should be understood that in the present application, "at least one" refers to one or more, and "multiple" refers to two or more.

[0037] At present, with the rapid development of Internet technology and mobile communication network technology, mobile terminals such as mobile phones, tablet computers, smart watches have become essential personal items for the public. Users can share content of their interest through mobile terminals, for example, when a user browses a microblog of his interest through a mobile phone, he can control the mobile phone to capture the current screen display interface and share it.

[0038] However, for some important information, if all screen captures are allowed, there may be information security risks. Therefore, in the prior art, the screen capture permission can be disabled to prohibit all screen capture behaviors. For example, when the user terminal identifies the input environment of sensitive information, a secure input keyboard is started and a security protection function is started, and the interface for calling screen capture and / or screen recording is prohibited, so as to achieve the purpose of prohibiting screen capture. However, this will also cause the user to be extremely inconvenient to operate, and cannot meet the screen capture requirements of specific interfaces. For example, if screen capture is directly prohibited in the government WeChat and enterprise WeChat, it will not be possible to share the chat record screenshot to the government WeChat and enterprise WeChat, resulting in high communication cost.

[0039] To this end, the present application provides a screen capture control method. By monitoring the screen capture operation on the display interface of the target application, the target application logs in with account information, after the first picture is obtained through the screen capture operation, it is further judged whether the target application is in the screen capture blacklist, if the target application is in the screen capture application blacklist, the first picture can be deleted; if the target application is not in the screen capture application blacklist, the account information can be added in the first picture to generate a second picture. In this way, different screen capture control methods are determined by the screen capture application blacklist and the addition of account information, which not only prevents important information from being leaked, but also ensures the security of important information, and facilitates the tracing of information.

[0040] Reference Figure 1 As shown in FIG. 1, an exemplary system architecture 100 that can apply the embodiments of the screen capture control method of the present application.

[0041] As Figure 1 As shown in FIG. 1, the system architecture 100 can include a terminal device 102, a network and a server 104. The network is a medium for providing a communication link between the terminal device 102 and the server 104. The network can include various connection types, such as wired, wireless communication links or optical fiber cables, etc.

[0042] The terminal device 102 can be various electronic devices with a display screen, including but not limited to a smart phone, a tablet computer, a laptop computer, a desktop computer, and the like. Various client applications can be installed on the terminal device 102, such as voice recognition applications, image processing applications, social applications, data processing applications, e-commerce applications, search applications, and the like. The server 104 can be a server providing various services, such as a background server providing support for the applications installed on the terminal device 102.

[0043] The screenshot control method of the embodiments of the present application can be executed by the terminal device 102 or the server 104.

[0044] When the screenshot control method is executed by the terminal device 102, the method process is as follows: the target application is running on the terminal device 102, the target application is logged in with account information, the terminal device 102 can monitor the screenshot operation on the display interface, after monitoring the first picture obtained by the screenshot operation, the terminal device 102 further judges whether the target application is in the screenshot application blacklist, if the target application is in the screenshot application blacklist, the terminal device 102 can delete the first picture obtained by the screenshot operation; if the target application is not in the screenshot application blacklist, the terminal device 102 can add account information in the first picture to generate a second picture.

[0045] When the screenshot control method is executed by the server 104, the method process is as follows: the server 104 monitors the screenshot operation on the display interface of the target application running on the terminal device 102, after monitoring the first picture obtained by the screenshot operation, the server 104 can further judge whether the target application is in the screenshot application blacklist, if the target application is in the screenshot application blacklist, the server 104 can delete the first picture sent by the terminal device 102; if the target application is not in the screenshot application blacklist, the server 104 can add account information in the first picture sent by the terminal device 102 to generate a second picture, and send the second picture to the terminal device 102.

[0046] It should be understood that Figure 1 The number of terminal devices, networks, and servers in the above description is only illustrative. According to the needs of implementation, there can be any number of terminal devices, networks, and servers.

[0047] The implementation details of the technical solutions of the embodiments of the present application are described in detail as follows:

[0048] Figure 2 A flowchart of a screenshot control method according to an embodiment of the present application is shown, referring to Figure 2 As shown in the screenshot control method includes:

[0049] Step S210, monitoring the screenshot operation on the display interface of the target application which is logged in with the account information;

[0050] Step S220, after monitoring the first picture obtained through the screenshot operation, judging whether the target application is in the screenshot application blacklist;

[0051] Step S230, if the target application is in the screenshot application blacklist, deleting the first picture;

[0052] Step S240, if the target application is not in the screenshot application blacklist, adding the account information in the first picture to generate a second picture.

[0053] The steps are described in detail as follows.

[0054] In step S210, the screenshot operation on the display interface of the target application which is logged in with the account information is monitored.

[0055] In the embodiment, the user logs in the target application with the account information, which can include the user identifier and the password, wherein the user identifier can be the account number or the user name. After the user logs in the target application with the account information, the user can enter the display interface of the target application, for example, if the target application is a chat application, the display interface can be a chat interface; if the target application is a video playing application, the display interface can be a video playing interface.

[0056] The terminal device can monitor the screenshot operation on the display interface, and in the specific implementation, the terminal device can monitor the screenshot operation on the display interface through the preset application program calling interface, such as Javascript. The screenshot operation can be the screenshot operation of the user through the shortcut key of the display interface or the shake-to-screenshot operation.

[0057] In step S220, after monitoring the first picture obtained through the screenshot operation, judging whether the target application is in the screenshot application blacklist.

[0058] The picture obtained through the screenshot in the traditional sense can be directly used for sharing and viewing, however, this way has information security risks. In the embodiment, after the first picture is obtained through the screenshot operation, different processing can be performed on the first picture to limit the sharing of the first picture. In the specific implementation, after the terminal device monitors the first picture obtained through the screenshot operation, the terminal device can judge whether the target application is in the screenshot application blacklist to obtain a judgment result, and process the first picture according to the judgment result.

[0059] It should be noted that the screenshot application blacklist refers to a list of applications that are prohibited from being screenshot, that is, the applications in the screenshot application blacklist are not allowed to be screenshot by the user. The screenshot application blacklist can be formed in advance according to the nature of the application, for example, for applications with high security requirements, they can be listed in the screenshot application blacklist, such as bank APP (Application, application program).

[0060] In step S230, if the target application is in the screenshot application blacklist, the first picture is deleted.

[0061] If the terminal device judges that the target application is in the screenshot application blacklist, that is, the target application is not allowed to be screenshot, in other words, the first picture obtained by the screenshot operation contains important information to a large extent, therefore, after the terminal device judges that the target application is in the screenshot application blacklist, the first picture can be directly deleted, so as to avoid the important information in the first picture being leaked.

[0062] In addition, for the target application, the terminal device can also call the system application programming interface (API) to prohibit the screenshot. In this way, the subsequent screenshot operation on the display interface of the target application cannot be completed.

[0063] In step S240, if the target application is not in the screenshot application blacklist, the account information is added to the first picture to generate a second picture.

[0064] On the contrary, if the terminal device judges that the target application is not in the screenshot application blacklist, that is, the target application is an application that is allowed to be screenshot, the terminal device can add the account information to the first picture to generate a second picture.

[0065] In some embodiments, adding the account information to the first picture can be text editing on the first picture, setting a layer above the first picture, calling a predetermined input box body in the layer, the input box body can be various shapes such as rectangle, rounded rectangle, circle, etc., the input box body includes a display area of editable characters, and the account information is added to the display area, so as to synthesize the account information and the first picture to obtain the second picture.

[0066] In other embodiments, adding the account information to the first picture can also be embedding the account information as a watermark in the first picture by using a watermark technology, which specifically includes: synthesizing the account information into watermark information, and adding the watermark information to the first picture to generate a watermark picture, and encoding the watermark picture to generate a second picture. The watermark can be a visible watermark or an invisible watermark.

[0067] Based on the technical solutions of the above embodiments, by monitoring the screenshot operation on the display interface of the target application, after the first picture obtained through the screenshot operation is monitored, it is further judged whether the target application is in the screenshot blacklist. If the target application is in the screenshot application blacklist, the first picture can be deleted. If the target application is not in the screenshot application blacklist, the account information can be added in the first picture to generate the second picture. Unlike the prior art which disables the screenshot permission to prohibit all screenshot behaviors, the technical solutions of the embodiments of the present application determine different screenshot control modes through the screenshot application blacklist and the addition of account information, which not only prevents the problem of important information being leaked and ensures the safety of important information, but also facilitates the tracing of information.

[0068] In an embodiment of the present application, in order to keep the account information secret, the account information can be synthesized into invisible watermark information. For invisible watermark, imperceptibility and robustness are two important characteristics. Imperceptibility means that after a series of hiding processes, the target data has no obvious degradation phenomenon, and the hidden data cannot be perceived by people. Robustness means the ability not to cause hidden information loss due to some changes of the image file. After the account information is synthesized into invisible watermark information, the invisible watermark information can be embedded into the first picture to generate the second picture containing the account information, so that the account information is hidden, thereby achieving the purpose of keeping secret.

[0069] In an embodiment of the present application, the leakage of sensitive information will cause great harm to the user. Therefore, after adding the account information in the first picture obtained by screenshot to generate the second picture, it can be further detected whether the second picture contains sensitive information to prevent sensitive information leakage when the second picture is shared or viewed, such as Figure 3 As shown, it includes steps S310-S320, which are described in detail as follows:

[0070] Step S310, detecting whether the second picture contains sensitive information.

[0071] Sensitive information refers to information that has a key impact on the subject and the loss or improper use of which will cause the loss of the subject's interests, such as identity card information, passport information, credit card information, security card information, account information and payment information, etc.

[0072] In some embodiments, the terminal device detecting whether the second picture contains sensitive information can be sending the second picture to the server, determining whether the second picture contains sensitive information according to a detection result sent by the server, the detection result being obtained by the server by extracting feature information of the second picture, detecting whether information similar to the feature information exists in the sensitive information database. If information similar to the feature information exists in the sensitive information database, it is determined that the second picture contains sensitive information; if information similar to the feature information does not exist in the sensitive information database, it is determined that the second picture does not contain sensitive information. The information similar to the feature information of the second picture can be information with a difference from the feature information of the second picture less than a preset threshold.

[0073] Further, the terminal device needs to consume a lot of traffic to send the second picture to the server, therefore, the terminal device can extract feature information of the second picture, and send the feature information to the server for detection. Of course, the terminal device can also directly compare the extracted feature information with information in the sensitive database to determine whether the second picture contains sensitive information.

[0074] In other embodiments, the terminal device detecting whether the second picture contains sensitive information can also be the terminal device detecting the second picture by using a classifier, if a classifier to which the second picture belongs is detected to exist, it is determined that the second picture contains sensitive information; if a classifier to which the second picture belongs is detected to not exist, it is determined that the second picture does not contain sensitive information.

[0075] The server pre-collects sensitive pictures to obtain a sensitive picture database, classifies the sensitive pictures in the sensitive picture database, such as identity card information, credit card information, etc., for each type of sensitive picture, the server trains the sensitive pictures of the type to obtain a classifier corresponding to the type of sensitive pictures only, and the server sends the classifier corresponding to each type of sensitive picture to the terminal. The classifier is used to detect whether the second picture belongs to the classification. For example, the classifier corresponding to the identity card information is used to detect whether the second picture belongs to the identity card information.

[0076] After the terminal device receives the at least one classifier, the terminal device detects the second picture using the classifiers one by one, if a classifier to which the second picture belongs is detected to exist, it is determined that the second picture contains sensitive information; if a classifier to which the second picture belongs is detected to not exist, it is determined that the second picture does not contain sensitive information.

[0077] Step S320, if it is detected that the second picture contains the sensitive information, the second picture is deleted from the first storage space, and the first storage space stores the second picture.

[0078] In this embodiment, if it is detected that the second picture contains sensitive information, the second picture can be deleted from the first storage space, and the first storage space stores the second picture. The first storage space can be an external storage space of the terminal device, such as an SD card or a hard disk.

[0079] Based on the technical solution of this embodiment, for the case that the second picture contains sensitive information, the second picture can be directly deleted from the storage space, thereby effectively ensuring the security of the sensitive information in the second picture and preventing the sensitive information from being leaked.

[0080] In actual application, some sensitive information can be information that a user wants to view. For example, a friend of a user asks the user to pay money, and the user has confirmed the authenticity of the information by other means. After the friend sends the user a bank card number, the user actually needs the bank card number of the friend. Obviously, directly deleting the second picture cannot meet the user's viewing requirement.

[0081] In an embodiment of the present application, if the second picture contains sensitive information, the different processing manners for the second picture can be further determined in combination with the security level of the sensitive information, instead of deleting the second picture. As shown in FIG. 4B, the specific operations can include the following steps. Figure 4

[0082] Step S410: detecting whether the second picture contains sensitive information.

[0083] Step S420: if it is detected that the second picture contains the sensitive information, determining a target processing manner for the second picture according to the security level corresponding to the sensitive information and the correspondence between the security level and the processing manner.

[0084] In this embodiment, the terminal device can first detect whether the second picture contains sensitive information. The specific detection manner is the same as that described in step S310, and will not be described here.

[0085] After detecting that the second picture contains sensitive information, the terminal device can determine the security level of the sensitive information to obtain a determination result. The higher the security level, the higher the security of the sensitive information and the smaller the security threat to the user. The lower the security level, the lower the security of the sensitive information and the greater the security threat to the user.

[0086] After determining the security level of the sensitive information, the terminal device can determine the target processing manner for the second picture according to the determination result and the correspondence between the security level and the processing manner.

[0087] ​It can be understood that the terminal device has a correspondence between the security level and the processing mode pre-stored therein, and the processing mode for the second picture can be an encryption processing on the second picture, can be displaying prompt content in the second picture, or can be any other reasonable processing mode, which is not limited herein by the embodiments of the present application. Therefore, after determining the security level of the sensitive information contained in the second picture, the terminal device can directly determine the target processing mode for the second picture from the correspondence.

[0088] In an embodiment of the present application, the sensitive information can be divided into malicious information and safe information according to security, the security level of the malicious information is very low, and the malicious information is a great threat to the security of the user. Therefore, the second picture containing the malicious information can be directly deleted, and the second picture containing the safe information can be processed according to different security levels of the safe information to determine different processing modes. The different security levels can include a first security level and a second security level, wherein the second security level is lower than the first security level.

[0089] In this embodiment, if the security level of the sensitive information is the first security level, a first processing mode corresponding to the first security level can be used as the target processing mode for the target picture, wherein the first processing mode is to move the second picture from the first storage space to the second storage space, and to generate a screenshot record according to the second picture, and the screenshot record contains the account information for logging into the target application.

[0090] It should be noted that the first storage space and the second storage space are different in that the first storage space can be an external storage space of the terminal device, such as an SD card or a hard disk, and the second storage space can be an internal storage space of the terminal device, such as a memory. Since the data in the external storage space is more likely to be shared and leaked than the data in the internal storage space, when the first storage space stores the second picture and the second picture contains sensitive information with a high security level and is not suitable for being leaked and shared, the second picture can be moved from the first storage space to the second storage space to prevent the second picture from being leaked.

[0091] If the security level of the sensitive information is the second security level, it means that the security level of the sensitive information is relatively low. At this time, a second processing mode corresponding to the second security level can be used as the target processing mode for the target picture, wherein the second processing mode is to generate a screenshot record according to the second picture, and the screenshot record contains the account information for logging into the target application.

[0092] In the technical solutions of the above embodiments, when the security level of the sensitive information is a first security level which is relatively high, the second picture can be moved in the storage space to prevent the second picture from being leaked out, and when the security level of the sensitive information is a second security level which is relatively low, neither the second picture needs to be deleted from the first storage space nor the second picture needs to be moved from the first storage space to the second storage space. In this embodiment, different processing manners for the second picture are determined according to different security levels, the specific needs of various application scenarios are met, the information safety in the second picture is ensured, and the actual need that the second picture can be shared is ensured. In addition, by generating the screenshot record, it is beneficial to subsequent tracing.

[0093] In an embodiment of the present application, since the second pictures that are not deleted can all generate corresponding screenshot records, if a sensitive information leakage event occurs through a second picture, the leakage party can be traced according to the second picture. In this embodiment, steps S510-S530 can be specifically included, which are described in detail as follows:

[0094] Step S510, obtaining a second picture to be processed, the second picture to be processed being a leakage source of target sensitive information.

[0095] In the specific implementation of this embodiment, if a leakage event of target sensitive information occurs, the second picture to be processed as the leakage source can be obtained first. It can be understood that the second picture to be processed is the leakage source of target sensitive information, that is, the second picture to be processed contains target sensitive information.

[0096] Step S520, analyzing the second picture to be processed to obtain target account information added to the second picture to be processed.

[0097] After obtaining the second picture to be processed, the second picture to be processed can be analyzed to obtain target account information added to the second picture to be processed.

[0098] Since the target account information can be embedded into the picture to be processed through watermark technology, when the target account information needs to be obtained, the target account information can be obtained through the de-watermarking manner.

[0099] Specifically, the second picture to be processed can be subjected to Fourier transform to obtain a frequency domain picture first; then an overlapping area in which the target account information watermark is superimposed is intercepted from the frequency domain picture as a watermark restoration image; and then the watermark restoration image is decoded to restore the target account information.

[0100] Step S530, if the target screenshot record is found according to the target account information, it is determined that the owner of the target account information is the leakage party of the target sensitive information.

[0101] In this step, after the target account information is obtained by analyzing the second picture to be processed, it cannot be determined that the owner of the target account information is the leakage party of the target sensitive information, because the second picture to be processed may not be obtained by the screenshot operation, but may be forged by an illegal user.

[0102] Therefore, in order to further determine whether the second picture to be processed is obtained by the screenshot operation, that is, to determine whether the owner of the target account information is the leakage party of the target sensitive information, the target account information can be further used to search for a screenshot record. If the target screenshot record exists, the target screenshot record refers to a screenshot record containing the target account information, it is indicated that the target account information has the screenshot operation, the second picture to be processed is obtained by the target account information through the screenshot operation, and therefore, the owner of the target account information is the leakage party of the target sensitive information. On the contrary, if the target screenshot record cannot be found according to the target account information, it is indicated that the second picture to be processed is not obtained by the target account information through the screenshot operation, and therefore, the owner of the target account information is not the leakage party of the target sensitive information.

[0103] In an embodiment of the present application, in the case that the second picture contains text information, the manner of detecting whether the second picture contains sensitive information can be matching the text information with a preset sensitive information set, as shown in the following. Figure 6 As shown in the embodiment, specifically, it includes steps S610-S620, which will be described in detail as follows.

[0104] Step S610, obtaining text information in the second picture.

[0105] The terminal device can extract the text information in the second picture, and specifically, the optical character recognition (Optical Character Recognition, OCR) can be used to obtain the text information in the second picture.

[0106] Optical character recognition is the electronic device (for example, scanner or digital camera) to check the characters printed on paper, by detecting dark, light pattern to determine its shape, and then use character recognition method to translate the shape into computer text process is the extraction of text string. Based on the above features, in practical application, there are a variety of different ways to extract text string using optical character recognition technology, the following describes one of the ways: according to the projection of the gray histogram in the line area, the single word area is cut, and then the gray image normalization, gradient feature extraction, multi template matching and minimum classification error classification are carried out for the single word area, so as to obtain the text string in the second picture.

[0107] Step S620, if the keyword in the text information matches the sensitive word contained in the preset sensitive information set, it is determined that the second picture contains sensitive information.

[0108] After obtaining the text information in the second picture, the text information can be compared with the preset sensitive information set, that is, it is determined whether there is a keyword in the text information that matches the sensitive word contained in the preset sensitive information set. If there is, it can be determined that the second picture contains sensitive information, otherwise, it can be determined that the second picture does not contain sensitive information.

[0109] It should be noted that the preset sensitive information set is established in advance, and the preset sensitive information set contains a set of sensitive words. The sensitive word can be an uncivilized word, a word related to national security, a word related to personal privacy information, or a self-defined keyword.

[0110] Figure 7 The logic judgment diagram of the screenshot control method according to an embodiment of the application is shown. As shown in Figure 7 The screenshot control method can specifically include the following steps:

[0111] Step S710, monitoring the screenshot operation on the display interface of the target application.

[0112] It should be noted that before the terminal device executes the screenshot control method, the terminal device can download the screenshot application blacklist from the cloud server side, and at the same time, the terminal device needs to be granted the stack top permission. In this way, the terminal device can obtain the relevant information of the target application through the stack top permission, so as to subsequently determine whether the target application is in the screenshot application blacklist.

[0113] Step S720, monitoring the first picture obtained by the screenshot operation.

[0114] Step S730, determining whether the target application is in the screenshot application blacklist. If yes, step S740 is executed, if no, step S750 is executed.

[0115] Step S740, deleting the first picture.

[0116] Step S750, adding the account information in the first picture to generate a second picture.

[0117] Step S760, detecting whether there is sensitive information in the second picture, if yes, executing step S770, if not, ending.

[0118] Step S770, determining the security level of the sensitive information, if the security level of the sensitive information is a first security level, executing step S780, if the security level of the sensitive information is a second security level, the second security level is lower than the first security level, executing step S790.

[0119] Step S780, moving the second picture from the first storage space to the second storage space, and generating a screenshot record according to the second picture, the screenshot record containing the account information.

[0120] Step S790, generating a screenshot record according to the second picture, the screenshot record containing the account information.

[0121] Figure 8 A logic determination diagram of a method for determining a leakage party of target sensitive information according to an embodiment of the present application is shown, which specifically includes the following steps: Figure 8

[0122] Step S810, obtaining a second picture to be processed.

[0123] The second picture to be processed is a leakage source of the target sensitive information, that is, the second picture to be processed contains the target sensitive information.

[0124] Step S820, analyzing the second picture to be processed to obtain target account information added to the second picture to be processed.

[0125] Step S830, searching for a target screenshot record according to the target account information.

[0126] If the target screenshot record is found, it is determined that the owner of the target account information is the leakage party of the target sensitive information, if the target screenshot record cannot be found, it is determined that the owner of the target account information is not the leakage party of the target sensitive information.

[0127] The device embodiment of the present application is introduced below, which can be used to execute the screenshot control method in the above embodiments of the present application. For details not disclosed in the device embodiment of the present application, please refer to the above embodiments of the screenshot control method of the present application.

[0128] Figure 9 A block diagram of a screenshot control device according to an embodiment of the present application is shown, which is described with reference to​Figure 9 As shown, the screenshot control apparatus 900 according to one embodiment of the present application comprises a monitoring unit 902, a judging unit 904, a first deleting unit 906 and a generating unit 908.

[0129] The monitoring unit 902 is configured to monitor a screenshot operation on a display interface of a target application, the target application being logged in with account information; the judging unit 904 is configured to, after monitoring the first picture obtained through the screenshot operation, judge whether the target application is in a screenshot application blacklist; the first deleting unit 906 is configured to, if the target application is in the screenshot application blacklist, delete the first picture; and the generating unit 908 is configured to, if the target application is not in the screenshot application blacklist, add the account information in the first picture to generate a second picture.

[0130] In some embodiments of the present application, the generating unit 908 is configured to: synthesize the account information into invisible watermark information; and embed the invisible watermark information into the first picture to generate the second picture.

[0131] In some embodiments of the present application, the apparatus further comprises a detecting unit configured to detect whether the second picture contains sensitive information; and a second deleting unit configured to, if it is detected that the second picture contains the sensitive information, delete the second picture from a first storage space, the first storage space storing the second picture.

[0132] In some embodiments of the present application, the apparatus further comprises the detecting unit configured to detect whether the second picture contains sensitive information; and a first determining unit configured to, if it is detected that the second picture contains the sensitive information, determine a target processing mode for the second picture according to a security level corresponding to the sensitive information and a corresponding relationship between security levels and processing modes.

[0133] In some embodiments of the present application, the first determining unit is configured to: if the security level of the sensitive information is a first security level, take a first processing mode corresponding to the first security level as the target processing mode for the second picture, the first processing mode being moving the second picture from a first storage space to a second storage space and generating a screenshot record according to the second picture, the screenshot record containing the account information; and if the security level of the sensitive information is a second security level lower than the first security level, take a second processing mode corresponding to the second security level as the target processing mode for the second picture, the second processing mode being generating the screenshot record according to the second picture, the screenshot record containing the account information.

[0134] In some embodiments of the present application, the apparatus further comprises: an acquisition unit configured to acquire a second picture to be processed, the second picture to be processed being a source of leakage of the target sensitive information; an analysis unit configured to analyze the second picture to be processed to obtain target account information added to the second picture to be processed; and a second determination unit configured to determine that an owner of the target account information is a leakage party of the target sensitive information if a target screenshot record is found according to the target account information.

[0135] In some embodiments of the present application, the detection unit is configured to: acquire text information in the second picture; and determine that the second picture contains sensitive information if there is a keyword in the text information that matches a sensitive word included in a preset sensitive information set.

[0136] Figure 10 A structural schematic diagram of a computer system of an electronic device suitable for implementing embodiments of the present application is shown.

[0137] It should be noted that, Figure 10 The computer system 1000 of the electronic device shown is only an example and should not impose any limitation on the functions and use range of embodiments of the present application.

[0138] As Figure 10 shown, the computer system 1000 includes a central processing unit (CPU) 1001, which can perform various appropriate actions and processes according to programs stored in a read-only memory (ROM) 1002 or programs loaded from a storage portion 1008 into a random access memory (RAM) 1003, such as performing the methods described in the above embodiments. In the RAM 1003, various programs and data required for system operation are also stored. The CPU 1001, the ROM 1002, and the RAM 1003 are connected to each other through a bus 1004. An input / output (I / O) interface 1005 is also connected to the bus 1004.

[0139] The following components are connected to the I / O interface 1005: an input section 1006 including input devices such as a keyboard and mouse; an output section 1007 including output devices such as a Cathode Ray Tube (CRT), a Liquid Crystal Display (LCD), and a speaker; a storage section 1008 including a hard disk; and a communication section 1009 including a network interface card such as a LAN (Local Area Network) card, a modem, and the like. The communication section 1009 performs communication processing via a network such as the Internet. A drive 1010 is also connected to the I / O interface 1005 as necessary. A removable media 1011 such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, and the like is attached to the drive 1010 as necessary, so that a computer program read therefrom is installed in the storage section 1008 as necessary.

[0140] In particular, the processes described above with reference to the flowcharts can be implemented as a computer software program according to embodiments of the present application. For example, embodiments of the present application include a computer program product comprising a computer program carried on a computer readable medium, the computer program containing a computer program for executing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via the communication section 1009, and / or installed from the removable media 1011. When the computer program is executed by the Central Processing Unit (CPU) 1001, various functions defined in the system of the present application are executed.

[0141] It should be noted that the computer-readable medium in the embodiments of the present application can be a computer-readable signal medium or a computer-readable storage medium or any combination thereof. The computer-readable storage medium may, for example, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or apparatus, or any combination thereof. More specific examples of the computer-readable storage medium can include, but are not limited to, an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disk read-only memory (Compact Disc Read-Only Memory, CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present application, the computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device or apparatus. In the present application, the computer-readable signal medium can include a data signal carrying computer-readable computer programs in a baseband or as a part of a carrier wave. Such a propagated data signal can take various forms, including but not limited to an electromagnetic signal, an optical signal, or any suitable combination thereof. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, which can send, propagate or transmit programs for use by or in conjunction with an instruction execution system, device or apparatus. The computer programs contained in the computer-readable medium can be transmitted by any suitable medium, including but not limited to wireless, wired, or the like, or any suitable combination thereof.

[0142] The flowcharts and block diagrams in the drawings illustrate the possible implementation architectures, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. In the flowcharts or block diagrams, each block can represent a module, a program segment or a part of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions noted in the blocks can occur in different orders than that shown in the drawings. For example, two blocks represented in succession can actually be executed substantially in parallel, and sometimes in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams or flowcharts, and the combination of blocks in the block diagrams or flowcharts, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of special-purpose hardware and computer instructions.

[0143] The units described in the embodiments of the present application can be implemented by software, or by hardware, or by a combination of software and hardware. The units described can also be located in a single processor. In some cases, the names of the units do not limit the units themselves.

[0144] As another aspect, the present application provides a computer readable medium, which can be included in the electronic device described in the above embodiments, or can exist separately without being assembled into the electronic device. The computer readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to implement the method described in the above embodiments.

[0145] It should be noted that although several modules or units for performing actions are mentioned in the above detailed description, the division into the modules or units is not mandatory. In fact, according to the embodiments of the present application, features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, features and functions of one module or unit described above can be further divided into a plurality of modules or units.

[0146] From the above description of the embodiments, those skilled in the art will readily appreciate that the example embodiments described herein can be implemented by software and / or by hardware coupled with software. Accordingly, the technical solutions of the embodiments of the present application can be embodied in the form of a software product. The software product can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, or the like) or on a network, and includes a number of instructions for causing a computing device (which can be a personal computer, a server, a touch terminal, or a network device, etc.) to perform the methods according to the embodiments of the present application.

[0147] Other embodiments of the present application will be apparent to those skilled in the art from consideration of the specification and practice of the embodiments disclosed herein. The present application is intended to cover any variations, uses, or adaptations of the application following, in general, the principles of the application and including such

[0148] It should be understood that the present application is not limited to the precise construction that has been described above and illustrated in the accompanying drawings, and that various modifications and changes can be made by those skilled in the art without departing from the scope of the present application. The scope of the present application is limited only by the appended claims.

Claims

1. A screenshot control method, characterized by, The method comprises: monitoring a screenshot operation on a display interface of a target application, the target application being logged in with account information; after monitoring that a first picture is obtained through the screenshot operation, judging whether the target application is in a screenshot application blacklist according to relevant information of the target application, wherein the relevant information of the target application is obtained through a granted top-of-stack permission; if the target application is in the screenshot application blacklist, deleting the first picture; if the target application is not in the screenshot application blacklist, synthesizing the account information into invisible watermark information; embedding the invisible watermark information into the first picture to generate a watermarked picture, encoding the watermarked picture to generate a second picture, and storing the second picture in a first storage space; if it is detected that the second picture contains sensitive information and the security level of the sensitive information is a first security level, moving the second picture from the first storage space to a second storage space, generating a screenshot record according to the second picture, the screenshot record containing the account information, and the data in the second storage space being more difficult to share than the data in the first storage space; if it is detected that the second picture contains the sensitive information and the security level of the sensitive information is a second security level lower than the first security level, not moving the second picture, and generating the screenshot record according to the second picture, the screenshot record containing the account information; obtaining a second picture to be processed, the second picture to be processed being a source of leakage of target sensitive information; analyzing the second picture to be processed to obtain target account information added to the second picture to be processed; if a target screenshot record is found according to the target account information, determining that an owner of the target account information is a leakage party of the target sensitive information.

2. The method of claim 1, wherein, The method further comprises: obtaining text information in the second picture; if there is a keyword matching a sensitive word contained in a preset sensitive information set in the text information, it is determined that the second picture contains sensitive information.

3. A screen capturing control apparatus, characterized by comprising: The device comprises: a monitoring unit configured to monitor a screenshot operation on a display interface of a target application, the target application being logged in with account information; a judging unit configured to, after monitoring that a first picture is obtained through the screenshot operation, judge whether the target application is in a screenshot application blacklist according to relevant information of the target application, wherein the relevant information of the target application is obtained through a granted top-of-stack permission; a first deleting unit configured to, if the target application is in the screenshot application blacklist, delete the first picture; a generating unit configured to, if the target application is not in the screenshot application blacklist, add the account information in the first picture to generate a second picture, and store the second picture in a first storage space; The first determining unit is configured to move the second picture from the first storage space to a second storage space and generate a screenshot record according to the second picture if it is detected that the second picture contains sensitive information and the security level of the sensitive information is a first security level, wherein the screenshot record contains the account information, and the data in the second storage space is more difficult to be shared than the data in the first storage space. The first determining unit is further configured to not move the second picture in storage space and generate the screenshot record according to the second picture if it is detected that the second picture contains the sensitive information and the security level of the sensitive information is a second security level, wherein the second security level is lower than the first security level, and the screenshot record contains the account information. The generating unit is configured to synthesize the account information into invisible watermark information, embed the invisible watermark information into the first picture to generate a watermarked picture, and encode the watermarked picture to generate a second picture. The obtaining unit is configured to obtain a second picture to be processed, wherein the second picture to be processed is a source of leakage of target sensitive information. The analyzing unit is configured to analyze the second picture to be processed to obtain target account information added to the second picture to be processed. The second determining unit is configured to determine that an owner of the target account information is a leakage party of the target sensitive information if a target screenshot record is found according to the target account information.

4. A computer readable medium having stored thereon a computer program, characterized in that, The computer program is executed by a processor to implement the screenshot control method in any one of claims 1-2.

5. An electronic device, comprising: Comprise: One or more processors; Storage device for storing one or more programs, when the one or more programs are executed by the one or more processors, so that the one or more processors implement the screenshot control method in any one of claims 1-2.

6. A computer program product, characterised in that, The computer program product comprises a computer program stored in a computer readable storage medium, and a processor of a computer device reads and executes the computer program from the computer readable storage medium, so that the computer device executes the screenshot control method in any one of claims 1-2.

Citation Information

Patent Citations

  • Mobile terminal information protecting method and device and mobile terminal

    CN106791168A

  • Picture processing method, mobile terminal and computer readable storage medium

    CN108038827A

  • Screen-captured picture processing method and device, terminal and computer storage medium

    CN109033850A