Electronic device control method, apparatus, and electronic device
By implementing permission controls based on application type and file tags in electronic devices, the problem of applications lacking control over user data storage operations is solved, achieving more secure data management.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BEIJING YOUZHUJU NETWORK TECH CO LTD
- Filing Date
- 2021-03-26
- Publication Date
- 2026-04-14
AI Technical Summary
In the prior art, applications on electronic devices lack effective access control when performing operations on user data storage areas, which may lead to damage to user data, such as accidental deletion.
By determining whether an application has the necessary permissions based on its application type and file tags, and allowing it to perform the target operation if it does, the system employs a storage directory partitioning and tag management mechanism to restrict or allow applications to read and write files.
It enables more targeted control over application file operations on user data storage areas, reducing the risk of file damage and improving data storage security.
Smart Images

Figure CN113032830B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of this disclosure relate to the field of computer technology, and more particularly to an electronic device control method, apparatus, and electronic device. Background Technology
[0002] In practical applications, electronic devices can store user data. User data can be files such as pictures and documents.
[0003] Typically, electronic devices can have applications (APPs) installed to perform various functions. When performing certain functions, these APPs may manipulate user data stored on the electronic device. Summary of the Invention
[0004] This disclosure is provided to briefly introduce the concepts, which will be described in detail in the subsequent Detailed Description section. This disclosure is not intended to identify key or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.
[0005] Embodiments of this disclosure provide an electronic device control method, apparatus, and electronic device that can reduce the possibility that applications installed on terminal devices may damage locally stored user data.
[0006] In a first aspect, embodiments of this disclosure provide an electronic device control method, the method comprising: in response to receiving an operation request from an application to perform a target operation on a target file in a user data storage area, determining whether the application has operation permission based on the type of the application and the tag of the target file; and in response to the application having operation permission, agreeing to allow the application to perform the target operation on the target file.
[0007] Secondly, embodiments of this disclosure provide an electronic device control apparatus, the apparatus comprising: a determining unit, configured to, in response to receiving an operation request from an application to perform a target operation on a target file in a user data storage area, determine whether the application has operation permissions based on the type of the application and the tag of the target file; and an approving unit, configured to, in response to the application having operation permissions, approve the application to perform the target operation on the target file.
[0008] Thirdly, embodiments of this disclosure provide an electronic device, including: one or more processors; and a storage device for storing one or more programs, which, when executed by the one or more processors, cause the one or more processors to implement the electronic device control method as described in the first aspect.
[0009] Fourthly, embodiments of this disclosure provide a computer-readable medium having a computer program stored thereon that, when executed by a processor, implements the steps of the electronic device control method as described in the first aspect.
[0010] The electronic device control method, apparatus, and electronic device provided in the embodiments of this disclosure, when receiving an operation request from an application to perform a target operation on a target file in a user data storage area, can determine whether the application has operation permissions based on the type of the application and the tag of the target file. Furthermore, if the application has operation permissions, the application can be allowed to perform the target operation on the target file. Therefore, when an application requests to perform a target operation on a target file, the application's type and the target file's tag are combined to determine whether the application has operation permissions. On the one hand, this allows for more targeted implementation of application operations on files in the user data storage area. On the other hand, it can more effectively reduce damage caused by applications to files in the user data storage area. Attached Figure Description
[0011] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and the originals and elements are not necessarily drawn to scale.
[0012] Figure 1 This is a flowchart of some embodiments of the electronic device control method according to the present disclosure;
[0013] Figure 2 This is a flowchart of some embodiments of the electronic device control method according to the present disclosure;
[0014] Figure 3 This is a flowchart of some embodiments of the electronic device control method according to the present disclosure;
[0015] Figure 4A , Figure 4B This is a flowchart of some embodiments of the electronic device control method according to the present disclosure;
[0016] Figure 5 This is a schematic diagram of the structure of some embodiments of the electronic device control device according to the present disclosure;
[0017] Figure 6 These are exemplary system architectures to which the electronic device control methods of some embodiments of this disclosure can be applied;
[0018] Figure 7 This is a schematic diagram of the basic structure of an electronic device provided according to some embodiments of the present disclosure. Detailed Implementation
[0019] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.
[0020] It should be understood that the steps described in the method embodiments of this disclosure may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this disclosure is not limited in this respect.
[0021] The term "comprising" and its variations as used herein are open-ended inclusions, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the description below.
[0022] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.
[0023] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".
[0024] The names of messages or information exchanged between multiple devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of such messages or information.
[0025] Please refer to Figure 1 This illustrates the flow of some embodiments of the electronic device control method according to the present disclosure. For example... Figure 1 As shown, the electronic device control method includes the following steps:
[0026] Step 101: In response to receiving an operation request from an application to perform a target operation on a target file in the user data storage area, determine whether the application has operation permissions based on the type of the application and the tag of the target file.
[0027] In this embodiment, the execution subject of the electronic device control method (e.g. Figure 6The terminal device 601 shown can receive an operation request from an application to perform a target operation on a target file in the user data storage area.
[0028] The aforementioned application can be any application (Application, App) installed by the execution process described above.
[0029] The user data storage area can be a storage area used to store user data. In practical applications, the user data storage area can be provided by various storage media. For example, it can be provided by storage media such as UFS (Universal Flash Storage), eMMC (Embedded Multi Media Card), and SD card (Secure Digital Memory Card). It should be noted that the user data storage area can store various files such as user pictures, videos, audio, and text.
[0030] The target file can be any file from which the application requests the execution of the target operation. The target operation can include read and / or write operations.
[0031] In this embodiment, in response to receiving the above-mentioned operation request, the executing entity can determine whether the application has operation permissions based on the type of the application and the tag of the target file.
[0032] Applications can be categorized based on specific needs.
[0033] Files stored in the user data storage area can all have tags. File tags are used to describe some attributes of the file.
[0034] In some scenarios, the aforementioned executing entity can determine the number of times an application of the aforementioned type performs operations on a file with the aforementioned tag within a predetermined time period. If the determined number is less than a preset number, the executing entity can determine that the application has the necessary operating permissions. Conversely, if the determined number is greater than or equal to the preset number, the executing entity can determine that the application does not have the necessary operating permissions.
[0035] Step 102: In response to the fact that the above application has operating permissions, consent is given to the above application to perform the target operation on the target file.
[0036] In this embodiment, in response to the application having operating permissions, the executing entity may agree to allow the application to perform the target operation on the target file. Furthermore, the application may perform the target operation on the target file.
[0037] In related technologies, when an application performs operations on user data, it directly consents to those operations. This may result in the application modifying or accidentally deleting user data, causing harm.
[0038] In this embodiment, when an application requests to perform a target operation on a target file in the user's data storage area, the application's type and the target file's tag are considered to determine whether the application has the necessary permissions. Furthermore, if the application has the required permissions, permission is granted to allow the application to perform the target operation on the target file. This approach allows for more targeted execution of operations on files in the user's data storage area. It also more effectively reduces the damage caused by applications to files in the user's data storage area.
[0039] In some embodiments, the user data storage area is pre-divided into a first storage directory, a second storage directory, and a third storage directory. The first storage directory is configured with read / write permission tags to restrict read and / or write operations of the application, and the second storage directory is configured with write permission tags to restrict write operations of the application.
[0040] Read / write permission tags can be used to describe restrictions on read and write operations. Write permission tags can be used to describe restrictions on write operations.
[0041] In practical applications, read and write permission tags can be used to restrict an application's read and / or write operations on files in the first storage directory. Write permission tags can be used to restrict an application's write operations on files in the second storage directory.
[0042] In some embodiments, the aforementioned execution entity may perform Figure 2 The steps in the process shown include step 201.
[0043] Step 201: For each file in the third storage directory, in response to a locking operation on that file, perform the first tag update step. The first tag update step includes steps 2011 and 2012.
[0044] Step 2011: Move the file from the third storage directory to the target storage directory.
[0045] The target storage directory is either the first storage directory or the second storage directory.
[0046] Locking operations are various actions used to lock files, and can be configured according to actual needs. In some scenarios, locking operations can be triggered by user actions on the locking control. The locking control can respond to pre-defined user actions on the file (such as long press, double-click, etc.) and be displayed accordingly.
[0047] In practical applications, moving a file to the first or second storage directory can be determined based on the locking operation performed by the user. In some scenarios, if the locking control triggered by the user's operation is used to lock both read and write operations on the file, the file will be moved to the first storage directory. If the locking control triggered by the user's operation is used to lock only write operations on the file, the file will be moved to the second storage directory.
[0048] Step 2012: Update the file's label to the permission label set for the target storage directory.
[0049] In some scenarios, after a file in the user data storage area is moved, its tag remains the same as the tag set for its original storage directory. Therefore, after moving a file in the user data storage area, its tag needs to be updated to reflect the tag set for its new storage directory.
[0050] Therefore, when a user performs a locking operation on a file in the third storage directory, moving the file to the first storage directory can restrict the application's read and / or write operations on that file. Similarly, moving the file to the second storage directory can restrict the application's write operations on that file.
[0051] In some embodiments, the aforementioned executing entity may perform step 2011 in the following manner.
[0052] The first step is to prompt the user to enter a verification password.
[0053] The second step is to move the file from the third storage directory to the target storage directory in response to the user's input verification password matching the preset verification password.
[0054] Therefore, when a user attempts to lock a file in the third storage directory, the system needs to verify the user's entered password. Furthermore, only if the entered password is correct can the file be moved to the first or second storage directory. This allows for more secure restrictions on application read and / or write operations on files.
[0055] In some embodiments, the aforementioned executing entity may perform step 2012 in the following manner.
[0056] Specifically, in response to the fulfillment of the tag update conditions, the tag of the file is updated to the permission tag set for the target storage directory.
[0057] Therefore, after a file is moved from the third storage directory to the first or second storage directory, its tag can be updated to the tag set for the first or second storage directory when the tag update conditions are met. This allows the system to adapt to scenarios where file tags need to be updated at various times.
[0058] In some embodiments, the aforementioned execution entity may also perform Figure 3 The steps in the process shown include step 301.
[0059] Step 301: For each file in the target storage directory, in response to the file's unlock operation, perform a second tag update step. The second tag update step includes steps 3011 and 3012.
[0060] Step 3011: Move the file from the target storage directory to the third storage directory.
[0061] Unlock operations are various actions used to unlock files. In some scenarios, the unlock operation can be a trigger action performed by the user on the unlock control. The unlock control can be displayed in response to a pre-defined action performed by the user on the file (e.g., long press, double-click, etc.).
[0062] Step 3012: Update the file's label to the label set for the third storage directory.
[0063] Therefore, when a user performs an unlock operation on a file in the first or second storage directory, the application's restrictions on reading and / or writing operations on that file are lifted by moving the file to the third storage directory and updating the file's tag.
[0064] In some embodiments, the aforementioned executing entity may perform step 3011 in the following manner.
[0065] The first step is to prompt the user to enter a verification password.
[0066] The second step is to move the file from the target storage directory to the third storage directory in response to the user's input verification password matching the preset verification password.
[0067] Therefore, when a user attempts to unlock a file in the target storage directory, the system needs to verify the accuracy of the entered password. Furthermore, only if the entered password is correct can the file be moved to the third-party storage directory. This allows for more secure removal of restrictions on application read and / or write operations on files.
[0068] In some embodiments, the aforementioned executing entity may perform step 3012 in the following manner.
[0069] Specifically, in response to the fulfillment of the tag update conditions, the permission tag of the file is updated to the tag set for the third storage directory.
[0070] Therefore, after a file is moved from the target storage directory to the third storage directory, its tag can be updated to the tag set for the third storage directory when the tag update conditions are met. This allows the system to adapt to scenarios where file tags need to be updated at various times.
[0071] Optionally, the tag update conditions include at least one of the following: detecting the execution of a tag refresh command; detecting an operating system restart.
[0072] Tag refresh commands are commands used to refresh the tags of a file. Typically, tag refresh commands are provided by the operating system. For example, a tag refresh command could be the "restorecon" command.
[0073] Therefore, after a file is moved in the user data storage area, the file's label is updated by executing a label refresh command or restarting the operating system.
[0074] In some embodiments, the user data storage area is a sub-storage area of the system data storage area. The system data storage area may be a storage area used to store data required by the operating system.
[0075] At this point, the aforementioned executing entity can set the permission tags for the first and second storage directories in the following ways.
[0076] Specifically, for the storage path of the first storage directory under the system data storage area, a permission label is set for the first storage directory; for the storage path of the second storage directory under the system data storage area, a permission label is set for the second storage directory.
[0077] For example, the first storage directory might have a storage path of " / sdcard / aaa / xxx" in the user data storage area and " / data / media / 0 / aaa / xxx" in the system data storage area. In this case, you can set the tag information for the first storage directory " / data / media / 0 / aaa / xxx".
[0078] Similarly, permission tags for the second storage directory can be set for its storage path within the system data storage area in a similar manner; no further examples will be provided here.
[0079] Therefore, when the user data storage area is a sub-storage area of the system data storage area, permission tags for the target storage directory can be set based on its storage path within the system data storage area. This allows for more flexible settings for the permission tags of the target storage directory.
[0080] In some embodiments, the aforementioned implementing entity may, in accordance with Figure 4A The process shown executes step 101 above, which includes step 401.
[0081] Step 401: In response to the fact that the target file's label is not a read / write permission label or a write permission label, it is determined that the above application has operation permissions.
[0082] Therefore, when the target file's tag is not a permission tag (read / write permission tag or write permission tag), after receiving the operation request from the aforementioned application, the application is allowed to perform the target operation on the target file.
[0083] In some scenarios, files in the third-party storage directory may not have permission tags (read / write permission tags or write permission tags). In such cases, when the target file is located in the third-party storage directory, upon receiving the operation request from the aforementioned application, the application is permitted to perform the target operation on the target file.
[0084] In some embodiments, the aforementioned implementing entity may, in accordance with Figure 4B The process shown executes step 101 above, which includes steps 402 and 403.
[0085] Step 402: In response to the target file's label being a read / write permission label or a write permission label, based on the type of the application, determine at least one operation that the application has permission to perform on the file with the aforementioned label.
[0086] In some scenarios, depending on the application type, the application is pre-configured to have at least one operation that grants permissions to files with different tags. Therefore, the executing entity can determine, based on the pre-configuration, that the application has at least one operation that grants permissions to files with the aforementioned tags (i.e., the tags of the target file).
[0087] Step 403: In response to at least one of the above operations including the target operation, determine that the application has operation permissions.
[0088] In some embodiments, Figure 4B The process shown may also include step 404.
[0089] Step 404: In response to the fact that at least one of the above operations does not include the target operation, it is determined that the above application does not have the operation permission.
[0090] Therefore, when the target file is labeled with a permission tag, it is necessary to determine whether the target operation falls under the category of operations that the aforementioned application has permission to perform on the target file, rather than directly granting permission for the aforementioned application to execute the target operation on the target file. Furthermore, if the target operation is an operation that the aforementioned application has permission to perform on the target file, then permission is granted for the aforementioned application to execute the target operation on the target file. If the target operation is not an operation that the aforementioned application has permission to perform on the target file, then permission is denied for the aforementioned application to execute the target operation on the target file.
[0091] In some scenarios, files in the first or second storage directory may have permission tags. In this case, when the target file is a file in the first or second storage directory, the decision is made based on whether the target operation falls under the category of operations that the aforementioned application has permission to perform on the target file.
[0092] In some embodiments, the aforementioned executing entity may also perform the following steps.
[0093] Specifically, in response to the fact that the aforementioned application does not have the necessary permissions, a permission denied message is returned to the aforementioned application.
[0094] A permission-not-permit message can be used to indicate that an application does not have the necessary permissions.
[0095] In some scenarios, the aforementioned applications may display a permission denied message. In this case, the user can understand that the application does not have permission to perform the desired operation on the target file.
[0096] Therefore, when the aforementioned application does not have the necessary permissions, a permission-only message will be displayed to inform the user that the application does not have the required permissions.
[0097] In some embodiments, the application types include a first type, a second type, and a third type. The first type of application has a system signature and system permissions, the second type of application has a system signature but no system permissions, and the third type of application has neither a system signature nor system permissions.
[0098] A system signature is a signature provided by the operating system to an application. System permissions are permissions granted to an application by the operating system.
[0099] In practical applications, applications with system permissions and / or system signatures are pre-verified and possess a certain degree of trustworthiness. Furthermore, system permissions have a higher priority than system signatures. Therefore, the trustworthiness decreases sequentially for the first type of application, the second type, and the third type.
[0100] Therefore, based on the trustworthiness of the applications, they are categorized into three types: Type 1, Type 2, and Type 3. It is evident that when an application requests to perform a target operation on a target file, its trustworthiness can be used to determine whether the application has the necessary permissions. This further enhances the security of applications operating on files in the user data storage area. In some embodiments, Type 1 applications have read and write permissions for files with any tag in the user data storage area; Type 2 applications have read permissions for files with read / write permission tags and write permission tags, and read and write permissions for files with other tags in the user data storage area; Type 3 applications have read permissions for files with write permission tags, and read and write permissions for files with other tags.
[0101] Other tags can be any tags that are distinct from the aforementioned permission tags. That is, other tags are any tags that are not used to characterize read and / or write permissions.
[0102] In some scenarios, if the application mentioned above belongs to the first type, the operations that the application has permission to perform on the target file include read operations and write operations.
[0103] In some scenarios, if the application belongs to the second type and the target file has read / write permission tags or a write permission tag, the operations that the application has permission to perform on the target file include read operations. If the application belongs to the second type and the target file has other tags, the operations that the application has permission to perform on the target file include both read and write operations.
[0104] In some scenarios, if the application belongs to the third type and the target file has a write permission tag, the operations that the application has permission to perform on the target file include read operations. If the application belongs to the third type and the target file has other tags, the operations that the application has permission to perform on the target file include both read and write operations.
[0105] Further reference Figure 5 As an implementation of the methods shown in the above figures, this disclosure provides some embodiments of an electronic device control device, which are similar to... Figure 1 Corresponding to the method embodiments shown, this device can be specifically applied to various electronic devices.
[0106] like Figure 5As shown, the electronic device control device of this embodiment includes a determining unit 501 and an approving unit 502. The determining unit 501 is configured to: in response to receiving an operation request from an application to perform a target operation on a target file in a user data storage area, determine whether the application has operation permissions based on the type of the application and the tag of the target file. The approving unit 502 is configured to: in response to the application having operation permissions, approve the application to perform the target operation on the target file.
[0107] In this embodiment, the specific processing of the determining unit 501 and the agreeing unit 502 of the electronic device control device and the resulting technical effects can be referred to respectively. Figure 1 The relevant descriptions of steps 101 and 102 in the corresponding embodiments will not be repeated here.
[0108] In some embodiments, the user data storage area is pre-divided into a first storage directory, a second storage directory, and a third storage directory. The first storage directory is provided with read and write permission labels for restricting read and / or write operations of the application, and the second storage directory is provided with write permission labels for restricting write operations of the application.
[0109] In some embodiments, the electronic device control device further includes a first execution unit (not shown in the figures). The first execution unit is configured to: for each file in the third storage directory, in response to a locking operation on the file, perform a first tag update step: move the file from the third storage directory to a target storage directory, wherein the target storage directory is either the first storage directory or the second storage directory; update the tag of the file to a permission tag set for the target storage directory.
[0110] In some embodiments, the user data storage area is a sub-storage area of the system data storage area. The electronic device control device further includes a setting unit (not shown in the figure). The setting unit is configured to: set permission labels for the first storage directory in the system data storage area for the storage path of the first storage directory; and set permission labels for the second storage directory in the system data storage area for the storage path of the second storage directory.
[0111] In some embodiments, the determining unit 501 is further configured to: determine that the application has operation permissions in response to the fact that the label of the target file is not a read / write permission label and a write permission label.
[0112] In some embodiments, the determining unit 501 is further configured to: in response to the target file's tag being a read / write permission tag or a write permission tag, determine, based on the type to which the application belongs, at least one operation that the application has permission to perform on the file with the tag; and in response to the at least one operation including the target operation, determine that the application has operation permission.
[0113] In some embodiments, the determining unit 501 is further configured to: determine that the application does not have operation permission in response to the fact that at least one of the above operations does not include the target operation.
[0114] In some embodiments, the electronic device control device further includes a return unit (not shown). The return unit is configured to: in response to the application not having operating permissions, return a permission-unauthorized prompt message to the application.
[0115] In some embodiments, the application types include a first type, a second type, and a third type, wherein the first type of application has a system signature and system permissions, the second type of application has a system signature but no system permissions, and the third type of application has neither a system signature nor system permissions.
[0116] In some embodiments, a first type of application has read and write permissions for files with any tag in the user data storage area; a second type of application has read permissions for files with read / write permission tags and write permission tags in the user data storage area, and read and write permissions for files with other tags in the user data storage area; a third type of application has read permissions for files with write permission tags, and read and write permissions for files with other tags.
[0117] In some embodiments, the electronic device control device further includes a second execution unit (not shown). The second execution unit is configured to: for each file in the target storage directory, in response to an unlocking operation of the file, perform a second tag update step: move the file from the target storage directory to a third storage directory, wherein the target storage directory is either the first storage directory or the second storage directory; and update the tag of the file to a tag set for the third storage directory.
[0118] In some embodiments, the second execution unit is further configured to: prompt the user to enter a verification password; and, in response to the user entering a verification password that is the same as a preset verification password, move the file from the target storage directory to a third storage directory.
[0119] In some embodiments, the second execution unit is further configured to: update the permission label of the file to the label set for the third storage directory in response to the fulfillment of the label update condition.
[0120] In some embodiments, the first execution unit is further configured to: prompt the user to enter a verification password; and, in response to the user entering a verification password that is the same as a preset verification password, move the file from the third storage directory to the target storage directory.
[0121] In some embodiments, the first execution unit is further configured to: update the label of the file to the permission label set for the target storage directory in response to the fulfillment of the label update condition.
[0122] In some embodiments, the tag update conditions include at least one of the following: detecting the execution of a tag refresh command; detecting a restart of the operating system.
[0123] Further reference Figure 6 , Figure 6 The present disclosure illustrates an exemplary system architecture in which electronic device control methods, representing some embodiments, can be applied.
[0124] like Figure 6 As shown, the system architecture may include an electronic device 601, wherein an application 602 is installed on the electronic device 601 and a user data storage area 603 is provided.
[0125] Application 602 can be an application used to implement various functions. For example, application 602 can be a shopping application, a search application, a social application, and so on. In some scenarios, application 602 can operate on files in the user data storage area 603. Files in the user data storage area 603 can be, for example, text, video, audio, images, and so on.
[0126] It should be noted that electronic device 601 can be a terminal device or a server.
[0127] If electronic device 601 is a terminal device, it can be either hardware or software. When the terminal device is hardware, it can be various electronic devices with a display screen and supporting information interaction, including but not limited to smartphones, tablets, laptops, and desktop computers. When the terminal device is software, it can be installed in the electronic devices listed above. It can be implemented as multiple software programs or software modules, or as a single software program or software module. No specific limitations are made here.
[0128] If electronic device 601 is a server, it can be either hardware or software. When the server is hardware, it can be implemented as a distributed server cluster consisting of multiple servers, or as a single server. When the server is software, it can be implemented as multiple software programs or software modules (e.g., multiple software programs or software modules used to provide distributed services), or as a single software program or software module. No specific limitations are made here.
[0129] In some scenarios, in response to receiving an operation request from application 602 to perform a target operation on a target file in user data storage area 603, electronic device 601 can determine whether application 602 has operation permissions based on the type of application 602 and the tag of the target file. Furthermore, in response to application 602 having operation permissions, electronic device 601 can grant application 602 permission to perform the target operation on the target file. Thus, application 602, with the necessary operation permissions, can perform the target operation on the target file in user data storage area 603.
[0130] It should be noted that the electronic device control method provided in the embodiments of this disclosure can be executed by the electronic device 601, and correspondingly, the electronic device control device can be disposed in the electronic device 601.
[0131] It should be understood that Figure 6 The number of electronic devices, applications, and user data storage areas shown is merely illustrative. Any number of electronic devices, applications, and user data storage areas can be included depending on implementation needs.
[0132] The following is for reference. Figure 7 It illustrates electronic devices suitable for implementing some embodiments of this disclosure (e.g., Figure 6 The diagram shows the structure of the terminal device. In some embodiments of this disclosure, the terminal device may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), and in-vehicle terminals (e.g., in-vehicle navigation terminals), as well as fixed terminals such as digital TVs and desktop computers. Figure 7 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein. Figure 7 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments of this disclosure.
[0133] like Figure 7 As shown, the electronic device may include a processing unit (e.g., a central processing unit, a graphics processor, etc.) 701, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 702 or a program loaded from a storage device 708 into a random access memory (RAM) 703. The RAM 703 also stores various programs and data required for the operation of the electronic device. The processing unit 701, ROM 702, and RAM 703 are interconnected via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.
[0134] Typically, the following devices can be connected to I / O interface 705: input devices 706 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 707 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 708 including, for example, magnetic tapes, hard disks, etc.; and communication devices 709. Communication device 709 allows electronic devices to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 7 Electronic devices with various devices are shown, but it should be understood that it is not required to implement or have all of the devices shown. More or fewer devices may be implemented or have alternatively. Figure 7 Each box shown can represent a device or multiple devices as needed.
[0135] In particular, according to some embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, some embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication device 709, or installed from storage device 708, or installed from ROM 702. When the computer program is executed by processing device 701, it performs the functions defined in the methods of the embodiments of this disclosure.
[0136] It should be noted that the computer-readable medium described in some embodiments of this disclosure may be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium may be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In some embodiments of this disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In some embodiments of this disclosure, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.
[0137] In some implementations, clients and servers can communicate using any currently known or future-developed network protocol, such as HTTP (Hypertext Transfer Protocol), and can interconnect with digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include local area networks (“LANs”), wide area networks (“WANs”), the Internet (e.g., the Internet of Things), and peer-to-peer networks (e.g., ad hoc peer-to-peer networks), as well as any currently known or future-developed networks.
[0138] The aforementioned computer-readable medium may be included in the aforementioned electronic device or may exist independently without being assembled into the electronic device. The aforementioned computer-readable medium carries one or more programs that, when executed by the electronic device, cause the electronic device to: upon receiving an operation request from an application to perform a target operation on a target file in a user data storage area, determine whether the application has operation permissions based on the type of the application and the tag of the target file; and, upon confirming that the application has operation permissions, agree to allow the application to perform the target operation on the target file.
[0139] Computer program code for performing operations of some embodiments of this disclosure can be written in one or more programming languages or a combination thereof, including but not limited to object-oriented programming languages such as Java, Smalltalk, and C++, as well as conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0140] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0141] The units described in some embodiments of this disclosure can be implemented in software or in hardware. The names of these units do not necessarily limit the unit itself; for example, a consent unit can also be described as a unit that "in response to the application having operating permissions, consents to the application performing target operations on the target file."
[0142] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: Field Programmable Gate Arrays (FPGAs), Application-Specific Integrated Circuits (ASICs), Application Standard Products (ASSPs), System-on-Chip (SoCs), Complex Programmable Logic Devices (CPLDs), and so on.
[0143] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0144] The above description is merely a selection of preferred embodiments of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of disclosure in the embodiments of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described concept. For example, technical solutions formed by substituting the above-described features with (but not limited to) technical features with similar functions disclosed in this disclosure.
[0145] Furthermore, while the operations are described in a specific order, this should not be construed as requiring these operations to be performed in the specific order shown or in a sequential order. In certain environments, multitasking and parallel processing may be advantageous. Similarly, while several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of this disclosure. Certain features described in the context of individual embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.
[0146] Although the subject matter has been described using language specific to structural features and / or methodological logic, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are merely illustrative examples of implementing the claims.
Claims
1. A method for controlling an electronic device, characterized in that, The method further includes: In response to receiving an operation request from an application to perform a target operation on a target file in the user data storage area, the system determines whether the application has the operation permission based on the type of the application and the tag of the target file. In response to the application having operating permissions, consent is granted for the application to perform the target operation on the target file; The user data storage area is pre-divided into a first storage directory, a second storage directory, and a third storage directory. The first storage directory is equipped with read / write permission tags to restrict read and / or write operations of the application, and the second storage directory is equipped with write permission tags to restrict write operations of the application. The method further includes: For each file in the third storage directory, in response to the locking operation on that file, the first tag update step is performed: Move the file from the third storage directory to the target storage directory, wherein the target storage directory is either the first storage directory or the second storage directory; Update the file's tag to the permission tag set for the target storage directory; The step of determining whether the application has operation permissions based on the type of the application and the tag of the target file includes: in response to the tag of the target file being the read-write permission tag or the write permission tag, determining, based on the type of the application, that the application has permission to perform at least one operation on the file with the tag. In response to the fact that the at least one operation includes the target operation, it is determined that the application has operation permissions; The method further includes: for each file in the target storage directory, in response to the file's unlocking operation, performing a second tag update step: moving the file from the target storage directory to the third storage directory, wherein the target storage directory is either the first storage directory or the second storage directory; updating the file's tag to a tag set for the third storage directory; The step of moving the file from the target storage directory to the third storage directory includes: prompting the user to enter a verification password; and moving the file from the target storage directory to the third storage directory in response to the user entering a verification password that is the same as the set verification password.
2. The method according to claim 1, characterized in that, The user data storage area is a sub-storage area of the system data storage area; The permission tags for the first storage directory and the second storage directory are set in the following manner: For the storage path of the first storage directory under the system data storage area, set the permission label of the first storage directory; Set permission tags for the second storage directory in the system data storage area.
3. The method according to claim 1, characterized in that, The step of determining whether the application has operation permissions based on the type of the application and the tags of the target file includes: If the target file's tag is not the read / write permission tag or the write permission tag, it is determined that the application has the necessary permissions.
4. The method according to claim 3, characterized in that, The step of determining whether the application has operation permissions based on the type of the application and the tag of the target file further includes: In response to the fact that the at least one operation does not include the target operation, it is determined that the application does not have the operation permission.
5. The method according to claim 1, characterized in that, The method further includes: In response to the application not having the necessary permissions, a permission denied message is returned to the application.
6. The method according to claim 1, characterized in that, The application types include a first type, a second type, and a third type. The first type of application has a system signature and system permissions, the second type of application has the system signature but does not have the system permissions, and the third type of application does not have the system signature and system permissions.
7. The method according to claim 6, characterized in that, The first type of application has read and write permissions for files with any tags in the user data storage area; The second type of application has read permission for files with read / write permission tags and write permission tags in the user data storage area, and read and write permission for files with other tags in the user data storage area. The third type of application has read permission for files with the write permission tag, and read and write permissions for files with other tags.
8. The method according to claim 1, characterized in that, The step of updating the file's tag to the tag set for the third storage directory includes: In response to the fulfillment of the tag update condition, the permission tag of the file is updated to the tag set for the third storage directory.
9. The method according to claim 1, characterized in that, Moving the file from the third storage directory to the target storage directory includes: The user is prompted to enter a verification password. In response to the user's input verification password being the same as the preset verification password, the file is moved from the third storage directory to the target storage directory.
10. The method according to claim 1, characterized in that, The step of updating the file's tag to the permission tag set for the target storage directory includes: In response to the fulfillment of the tag update conditions, the tag of the file is updated to the permission tag set for the target storage directory.
11. The method according to claim 1 or 10, characterized in that, The label update conditions include at least one of the following: The execution of the tag refresh command has been detected; Operating system restart detected.
12. An electronic device control device, characterized in that, include: The determining unit is configured to, in response to receiving an operation request from an application to perform a target operation on a target file in a user data storage area, determine whether the application has operation permissions based on the type of the application and the tag of the target file; A consent unit is configured to, in response to the application having operating permissions, consent to the application performing the target operation on the target file; The user data storage area is pre-divided into a first storage directory, a second storage directory, and a third storage directory. The first storage directory is equipped with read / write permission tags to restrict read and / or write operations of the application, and the second storage directory is equipped with write permission tags to restrict write operations of the application. The update unit is configured to, in response to a locking operation on a file in the third storage directory, perform a first tag update step: move the file from the third storage directory to a target storage directory, wherein the target storage directory is either the first storage directory or the second storage directory; and update the tag of the file to a permission tag set for the target storage directory. The step of determining whether the application has operation permissions based on the type of the application and the tags of the target file includes: In response to the target file being labeled with either the read / write permission label or the write permission label, based on the type of the application, it is determined that the application has permission to perform at least one operation on the file with the label. In response to the fact that the at least one operation includes the target operation, it is determined that the application has operation permissions; The apparatus is further configured to: for each file in the target storage directory, in response to an unlocking operation of the file, perform a second tag update step: move the file from the target storage directory to the third storage directory, wherein the target storage directory is either the first storage directory or the second storage directory; update the tag of the file to a tag set for the third storage directory; The step of moving the file from the target storage directory to the third storage directory includes: prompting the user to enter a verification password; and moving the file from the target storage directory to the third storage directory in response to the user entering a verification password that is the same as the set verification password.
13. An electronic device, characterized in that, include: One or more processors; Storage device for storing one or more programs. When the one or more programs are executed by the one or more processors, the one or more processors implement the method as described in any one of claims 1-11.
14. A computer-readable medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the method as described in any one of claims 1-11.
Citation Information
Patent Citations
Rapid search and recovery method based on file attribute
CN101324898A
Data dumping method and data dumping device
CN101763318A
Computer storage device having separate read-only space and read-write space, removable media component, system management interface, and network interface
CN101952809A
Method and device for application program to operate file
CN106203159A
File management method and device of subscriber identity module
CN106354718A