Permission Control Method and Device, Electronic Device, and Storage Medium in an Operating System
By introducing permission control methods in the operating system, querying the access status of device nodes and managing permissions, the problem of lack of device permission management in the prior art is solved, and the user experience and system security are improved.
Patent Information
- Application Number
- CN202111196972.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-10-14
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2041-10-14
AI Technical Summary
The lack of device permission management methods in existing operating systems has led to user privacy data leakage and poor experience.
The permission control method is introduced in the operating system, query the access status of the device node through device services and permission services, generate feedback information, and manage the access permissions of the device node based on the query results, set the default permission status and support user authorization.
It realizes permission management of device nodes, improves user experience, prevents privacy data leakage and improves system security.
Smart Images

Figure CN113987505B_ABST
Abstract
Description
1.1.1 Technical Field
[0002] The embodiments of the present application relate to the permission management technology for device nodes in an operating system, and in particular, to a permission control method and device, an electronic device, and a storage medium in an operating system. 1.1.2 Background Art
[0004] In some operating systems, no permission management method for accessing devices is set. In this way, all applications in the operating system can access devices, which will cause all device nodes in the operating system to be exposed, and the user's privacy data will be leaked and may be tampered with. For example, device nodes such as the camera and microphone of an electronic device can be opened at will, resulting in a poor user experience. 1.1.3 Summary of the Invention
[0006] In view of this, the embodiments of the present application provide a permission control method and device, an electronic device, and a storage medium in an operating system to at least solve the above technical problems existing in the prior art.
[0007] According to a first aspect of the embodiments of the present application, a permission control method in an operating system is provided, including:
[0008] In response to an access request of a first process to a first device node, a device service queries a first permission service for an access status of the first process to a first permission of the first device node;
[0009] The device service receives a first query result returned by the first permission service, generates first feedback information based on the first query result, and outputs the first feedback information to an application corresponding to the first process; or the device service receives a second query result returned by the first permission service, opens the first device node or outputs a first prompt message without permission to open the first device node to the application corresponding to the first process;
[0010] Wherein, the first query result and the second query result are obtained by the first permission service by searching in a set database based on information of the first device node and / or identification information of the first process; the access status of the first permission of one or more device nodes for one or more applications is pre-stored in the set database; the identification information of the first process is associated with the identification information of the application corresponding to the first process.
[0011] In one embodiment, the method further includes:
[0012] The device service receives second indication information of an application corresponding to the first process for the first feedback information, and based on the second indication information, enables the first device node; and triggers the first permission service to modify the access status of the first permission of the first device node for the application corresponding to the first process to allowed access in the set database.
[0013] In one embodiment, the method further includes:
[0014] The device service receives third indication information of the application corresponding to the first process for the first feedback information, and based on the third indication information, outputs a first prompt message indicating that there is no permission to enable the first device node to the application corresponding to the first process; and triggers the first permission service to modify the access status of the first permission of the first device node for the application corresponding to the first process to denied access in the set database.
[0015] In one embodiment, the method further includes:
[0016] In response to a query request for the first permission, the first permission service searches for all data items regarding the first permission, or data items of the first permission related to the application identification information in the query request, or data items of the first permission related to the device node identification information in the query request, or data items of the first permission related to the process identification in the query request in the set database, and outputs them.
[0017] In one embodiment, the method further includes:
[0018] In response to a modification request for a data item of the first permission, the first permission service modifies the corresponding data item of the first permission in the set database, and saves the modified data item of the first permission.
[0019] In one embodiment, the method further includes:
[0020] In response to the loading of the operating system, the first permission service and the set database are generated, and the first permission data item regarding the device node is set to a default value in the set database.
[0021] According to a second aspect of the embodiments of the present application, there is provided a permission control device in an operating system, including:
[0022] A query unit, configured to query the first permission service for the access status of the first permission of the first process to the first device node in response to an access request of the first process to the first device node;
[0023] A first receiving unit, configured to receive a first query result returned by the first permission service;
[0024] A first generation unit for generating first feedback information based on the first query result;
[0025] An output unit for outputting the first feedback information to the application corresponding to the first process;
[0026] A second receiving unit for receiving a second query result returned by the first permission service;
[0027] A processing unit for, in response to the second query result, enabling the first device node or outputting a first prompt message indicating no permission to enable the first device node to the application corresponding to the first process;
[0028] Wherein, the first query result and the second query result are obtained by the first permission service by searching in a set database based on the information of the first device node and / or the identification information of the first process; the access status of the first permissions of one or more device nodes for one or more applications is pre-stored in the set database; the identification information of the first process is associated with the identification information of the application corresponding to the first process.
[0029] In one embodiment, the device further includes:
[0030] A third receiving unit for receiving second indication information of the application corresponding to the first process for the first feedback information;
[0031] The processing unit is further configured to enable the first device node based on the second indication information; and trigger the first permission service to modify the access status of the first permission of the first device node for the application corresponding to the first process in the set database to allow access.
[0032] In one embodiment, the device further includes:
[0033] A fourth receiving unit for receiving third indication information of the application corresponding to the first process for the first feedback information;
[0034] The processing unit is further configured to output a first prompt message indicating no permission to enable the first device node to the application corresponding to the first process based on the third indication information; and trigger the first permission service to modify the access status of the first permission of the first device node for the application corresponding to the first process in the set database to deny access.
[0035] In one embodiment, the processing unit is further configured to:
[0036] In response to a query request for the first permission, trigger the first permission service to search for all data items related to the first permission in the set database, or data items related to the first permission associated with the application identification information in the query request, or data items related to the first permission associated with the device node identification information in the query request, or data items related to the first permission associated with the process identification in the query request, and output them.
[0037] In one embodiment, the processing unit is further configured to:
[0038] In response to a modification request for a data item of the first permission, the first permission service modifies the corresponding data item of the first permission in the set database and saves the modified data item of the first permission.
[0039] In one embodiment, the device further includes:
[0040] A second generation unit, configured to generate the first permission service and the set database in response to the loading of the operating system, and set the first permission data item regarding the device node to a default value in the set database.
[0041] According to a third aspect of the embodiments of the present application, there is provided an electronic device, including a processor, a memory, and an executable program stored on the memory and capable of being run by the processor. When the processor runs the executable program, it executes the steps of the permission control method in the operating system.
[0042] According to a fourth aspect of the embodiments of the present application, there is provided a storage medium, on which an executable program is stored. When the executable program is executed by a processor, it implements the steps of the permission control method in the operating system.
[0043] In the embodiments of the present application, when the operating system is loaded, corresponding permission services and databases are generated for all sensitive device nodes. The database is set with the permission management status regarding the sensitive device nodes, and by default, all applications need corresponding authorization to access the sensitive device nodes. After some applications obtain the access permissions to the device nodes, the access permissions to the device nodes are enabled for the applications subsequently. The embodiments of the present application also support the invocation of the access permissions to the device nodes, and can receive the modification of the permission status of the device nodes by the user according to the user's needs and store it in the corresponding database, facilitating the user to enable the relevant applications to access the device nodes. The embodiments of the present application set the permission access status of the device nodes for the operating system, facilitating the permission management for the device nodes and greatly improving the user experience of using the operating system. 1.1.4 Description of the Drawings
[0045] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0046] Figure 1 It is a schematic flowchart of the permission control method in the operating system of the embodiment of the present application;
[0047] Figure 2 It is a schematic architecture diagram of permission control in the operating system of the embodiment of the present application;
[0048] Figure 3 It is a schematic flowchart of the permission control method in the operating system of the embodiment of the present application;
[0049] Figure 4 It is a schematic architecture diagram of permission setting in the operating system of the embodiment of the present application;
[0050] Figure 5 It is a schematic composition structure diagram of the permission control device in the operating system of the embodiment of the present application;
[0051] Figure 6 It is a structure diagram of the electronic device of the embodiment of the present application. 1.1.5 Specific Embodiments
[0053] The following will elaborate on the essence of the technical solutions in the embodiments of the present application in conjunction with the accompanying drawings.
[0054] Figure 1 It is a schematic flowchart of the permission control method in the operating system of the embodiment of the present application. As Figure 1 shown, the permission control method in the operating system of the embodiment of the present application includes the following processing steps:
[0055] Step 101, in response to an access request from a first process to a first device node, the device service queries the first permission service about the access status of the first process to the first permission of the first device node.
[0056] In the embodiment of the present application, when the operating system is loaded, a first permission service and a setting database are generated, and a first permission data item regarding the device node is set to a default value in the setting database. Here, the operating system mainly includes the Linux system.
[0057] Those skilled in the art should understand that the technical solutions of the embodiments of the present application are applicable to all operating systems without corresponding permission management for device nodes. In the embodiments of the present application, the Linux system, also known as the GNU / Linux operating system, includes but is not limited to various distributions such as Ubuntu, Redhat, and Debian.
[0058] The first permission especially refers to sensitive permissions; it can also include general permissions, signature permissions, system signature permissions, etc. The access status includes a denied access status, a granted access status, and a default status, etc. In the embodiments of the present application, when the operating system is loaded on an electronic device, a default first permission access status is set for all sensitive device nodes in all operating systems, that is, the access status of the first permission is the default value, and all applications need user authorization for the first access to sensitive device nodes.
[0059] In the embodiments of the present application, when the user enables the corresponding application and the application needs to access the corresponding device after being enabled, an access process of the application is generated, and an access request for the first device node to be accessed is sent to the device service; the device service looks up the access status of the first permission of the first device node for the application corresponding to the first process in the set database. If it is in the default state, it is necessary to return relevant information about whether the user authorizes to the application corresponding to the first process, and enable or reject the enablement based on the user authorization situation; if the application corresponding to the first process has accessed the first device node before, it is determined whether to enable the first device node according to the corresponding authorization situation during the previous access.
[0060] Step 102, the device service receives the first query result returned by the first permission service, generates first feedback information based on the first query result, and outputs the first feedback information to the application corresponding to the first process.
[0061] Here, the first query result indicates that the access permission of the first device node for the application corresponding to the first process is the default setting, that is, the application corresponding to the first process accesses the first device node for the first time. At this time, the device service needs to send first feedback information to the application corresponding to the first process to ask the user whether to agree to access the first device node. In the embodiments of the present application, the first feedback information mainly includes information on whether to agree to access the first device node.
[0062] Step 103, the device service receives the second query result returned by the first permission service, enables the first device node or outputs a first prompt message without the permission to enable the first device node to the application corresponding to the first process.
[0063] In an embodiment of the present application, the second query result means that the application corresponding to the first process accesses the first device node not for the first time. The access status of the first permission when the application corresponding to the first process accessed the first device node last time is used as the current permission access status. If the previous setting was that the first device node allowed access to the application corresponding to the first process, the first device node is directly enabled. If the previous setting was that the first device node denied access to the application corresponding to the first process, the opening of the first device node is refused, and the device service sends a first prompt message for refusing to open the first device node to the application corresponding to the first process.
[0064] In an embodiment of the present application, the first query result and the second query result are obtained by the first permission service by searching in a set database based on the information of the first device node and / or the identification information of the first process; one or more access statuses of the first permissions of one or more device nodes for one or more applications are pre-stored in the set database; the identification information of the first process is associated with the identification information of the application corresponding to the first process. Here, that is, the identification information between the application and its own process is the same or closely associated. The corresponding application can be determined through the process identification, and the identification of the process corresponding to the application can be recognized based on the application. The set database mainly refers to an encrypted database, which is set for the first permission service and is mainly used to store the access status of the sensitive permissions of the device nodes to enable the corresponding sensitive permission access for different applications and protect the privacy of the device nodes.
[0065] In an embodiment of the present application, after step 102, the method further includes: the device service receives a second indication message from the application corresponding to the first process for the first feedback message, enables the first device node based on the second indication message; and triggers the first permission service to modify the access status of the first permission of the first device node for the application corresponding to the first process in the set database to allowed access.
[0066] Here, the second indication message means that the user selects to allow the first process to access the first device node based on the first feedback message and agrees to enable the first device node for the application corresponding to the first process. At this time, the device service triggers the first permission service to modify the access status of the first permission of the first device node for the application corresponding to the first process in the set database to allowed access. After that, when the application corresponding to the first process accesses the first device node again, the first device node can be directly enabled.
[0067] As an implementation, in the embodiments of the present application, after step 102, the method further includes: the device service receives third indication information of the application corresponding to the first process for the first feedback information, and outputs, based on the third indication information, a first prompt message indicating that the first device node permission is not enabled to the application corresponding to the first process; and triggers the first permission service to modify the access status of the first permission of the first device node for the application corresponding to the first process to denied access in the set database. Here, the third indication information means that the user has selected to reject the access of the first process to the first device node based on the first feedback information. At this time, the device service triggers the first permission service to modify the access status of the first permission of the first device node for the application corresponding to the first process to denied access in the set database. After that, when the application corresponding to the first process accesses the first device node again, an indication message of rejecting the opening is sent to the application corresponding to the first process, and the user is asked whether to enable the information allowing access to the first device node.
[0068] In the embodiments of the present application, the method further includes: in response to a query request for the first permission, the first permission service searches for all data items regarding the first permission, or data items of the first permission related to the application identification information in the query request, or data items of the first permission related to the device node identification information in the query request, or data items of the first permission related to the process identification in the query request in the set database, and outputs them. That is, the embodiments of the present application also support a query request for the first permission. The query request may be to default query all sensitive permission information, including both sensitive permission information of device nodes and sensitive permission information of applications, etc. Or, the query request is to query the sensitive permission information of a certain application for a device node, or to query the sensitive permission information of a certain process (based on the process identification (Process ID, PID)) for a device node, or to query the sensitive permission information of a certain device node for which applications. The embodiments of the present application support querying the first permission information and its access status at any time, and the supported query methods are more extensive.
[0069] In the embodiments of the present application, the method further includes: in response to a modification request for a data item of the first permission, the first permission service modifies the corresponding data item of the first permission in the setting database and saves the modified data item of the first permission. After querying the access status of the sensitive permissions of the relevant application for the device node or the access status of the sensitive permissions of the device node for the application or its process, the user can modify the access status of the sensitive permissions at any time based on the corresponding scenario, and the modified access status of the sensitive permissions will be recorded and saved in the setting database, i.e., the confidentiality database. The modifications here include modifying the relevant values of the access status of the original sensitive permissions, as well as adding or deleting the access status of the sensitive permissions.
[0070] The following further elaborates on the technical solutions of the embodiments of the present application with specific examples. Here, taking the Linux system as an example of the operating system, the technical solutions of the embodiments of the present application are also applicable to other operating systems.
[0071] In the embodiments of the present application, a service program for sensitive permissions (the first permission service) is created in the Linux system to save the information on the dynamic adjustment of the sensitive permissions of the application. In the embodiments of the present application, the main focus is on setting and managing the access status of the sensitive permissions of the device node (the first permission). In addition to sensitive permissions in the Linux system, there are also normal permissions, signature permissions, and system signature permissions, etc. Among them:
[0072] Normal permissions are also called normal rights. Even if a user has such permissions, there is still a relatively high risk of their private data being leaked or tampered with. For example, the permission to set the time zone is a normal permission. If an application declares that it requires a normal permission, the system will automatically grant this permission to the application.
[0073] Sensitive permissions are also called dangerous permissions. At runtime, their permission access status is the opposite of that of normal permissions. Once an application obtains such permissions, the user's private data is at risk of being leaked or tampered with. For example, the READ_CONTACTS permission belongs to dangerous permissions. If an application declares that it requires a dangerous permission, the user must explicitly grant this permission to the application.
[0074] Signature permission: This type of permission is only open to applications with the same signature. For example, Mobile QQ defines a permission and adds android:protectionLevel="signature" in the permission label. When accessing a certain data of it, the permission must be possessed. Then when WeChat and QQ are released with the same signature, WeChat can apply to access this permission in QQ and use the data controlled by the corresponding permission. Even if other programs know the interface of the open data and register the permission in the Manifest, they still cannot access the corresponding data due to different application signatures.
[0075] Signature or system permission: Similar to the signature permission, but it not only requires the same signature but also requires the same type of system-level application. This type of permission is generally used in the prefabricated scenarios developed by mobile phone manufacturers.
[0076] In the embodiments of the present application, the Linux device node refers to: In Linux, all devices are stored in the / dev directory in the form of files, and device nodes are all accessed through files. The device node is an abstraction of the device by the Linux kernel, and a device node is a file. The application program performs access to the device through a set of standardized calls, and these calls are independent of any specific driver. The driver is responsible for mapping these standard calls to the specific operations of the actual hardware. The file nodes in the / dev directory are called special device nodes. The so-called node refers to an entry, and through such an entry, the purpose of operating (reading, writing, etc.) a certain device can be achieved. The reason for uniformly setting the corresponding entry in / dev is that the Linux system provides a corresponding virtual file system, which can use consistent function interfaces (open(), read(), write(), close()...) to operate various different devices, which can greatly reduce the complexity of the application program accessing the Linux peripheral devices. The embodiments of the present application are precisely for the device nodes in the Linux system to set the management of the corresponding sensitive permission access status. That is, there is currently no method for managing the access permissions to devices in the Linux system, and the embodiments of the present application provide a corresponding method for dynamically managing the usage permissions of applications in the Linux system.
[0077] Figure 2 It is a schematic diagram of the permission control architecture in the operating system of the embodiments of the present application, as Figure 2As shown, in the embodiments of the present application, when a relevant application (App) in the operating system accesses a Linux device node, since the access status of the sensitive permissions of the Linux device node is managed and controlled, when the App calls the Linux device node, it needs to obtain the access status of the sensitive permissions of the Linux device node to be called through the device service. Specifically, the device service sends a query request to the sensitive permissions service, and the sensitive permissions service queries the corresponding encrypted database to obtain the access status of the current application to the sensitive permissions of the Linux device node to be accessed, and makes corresponding access management based on the corresponding access status.
[0078] That is, by creating a service program for sensitive permissions in the Linux system and setting a corresponding confidential database for the sensitive permissions service to store the information on the dynamic adjustment of the access status of the sensitive permissions of the application, it is convenient for the relevant application to access the corresponding device node based on the access status of the sensitive permissions.
[0079] For all applications installed on Linux, the default sensitive permission is to ask whether to allow access to the device node. When an application starts to access the sensitive permission of the device node, such as using the device microphone, the microphone service calls the sensitive permissions service to query whether the application is allowed to access the microphone. If access is allowed, the microphone function is enabled for the application; if access is not allowed, a prompt message indicating that the microphone cannot be opened is returned. In the scenario of the inquiry status, a system dialog box can be popped up for the user to choose whether to allow the relevant application to access the device node. After the user makes a choice on the sensitive permission, the access status of the sensitive permission selected by the user is saved to the encrypted database of the sensitive permissions service program.
[0080] Figure 3 It is a schematic flowchart of the permission control method in the operating system of the embodiments of the present application. As Figure 3 shown, the permission control method of the embodiments of the present application includes:
[0081] When the Linux system starts, the sensitive permissions service program runs, and the sensitive permissions service program generates an encrypted database to store the corresponding relationship between the application package name information and the sensitive permission information.
[0082] When the App accesses a device node with sensitive permissions, when the device-related service opens the Linux device node, it accesses the sensitive permissions service program to query the access status of the sensitive permissions of the application. That is, when the App needs to access a device node with sensitive permissions, the Linux device service obtains the process PID information of the current App.
[0083] When the application queries sensitive permission information through Inter-Process Communication (IPC), it sends the application PID and the specific sensitive information used as parameters to the sensitive permission service program at the same time. That is, the Linux device service sends the access status of the sensitive permissions of the device node to the sensitive permission service. At this time, the sensitive permission service queries the access status of the sensitive permissions of the device node for this PID according to the PID of the process, and makes corresponding management policies based on the queried access status of the sensitive permissions.
[0084] The sensitive permission service program can query information such as the application package name according to the PID. In the embodiments of the present application, the access status of the sensitive permissions includes at least three statuses: default status, denied status, and allowed status.
[0085] When the sensitive permission queries that the access permission of the application to the device node is in the default status, a system pop-up window is displayed, asking the user whether to agree or refuse to access the Linux device node function. And continue the following process according to the user's choice of running access or refusing access.
[0086] When the sensitive permission queries that the access permission of the application to the device node is in the denied status, relevant information for denying access to the device node is returned, and the function of the Linux device node is prohibited from being enabled.
[0087] When the sensitive permission queries that the access permission of the application to the device node is in the allowed status, the function of the Linux device node is normally enabled.
[0088] In the foregoing steps, after the user selects the status of the sensitive permission in the system pop-up window, the opening or refusal to open the device node is executed. At this time, the sensitive permission service program stores the information such as the application package name and the selected sensitive permission access status for the access to the device node in the encrypted database at the same time, so as to manage the sensitive permissions of the device node based on the selected sensitive permission access status when the application accesses next time.
[0089] In the embodiments of the present application, when an application requests to use sensitive devices such as cameras and microphones, the service program of the Linux device node reads the PID information of the requesting application in reverse through the local IPC communication mechanism and saves the PID information of the application. Before opening the Linux device node, the Linux device node service calls the sensitive permission service program through the local IPC communication mechanism to query the sensitive permission interface. The query parameters can include the application PID information and the information of the accessed device node. After receiving the query parameters, the sensitive permission service, based on the relevant data stored in its encrypted database, if it is the default value, pops up a system dialog box to ask the user whether to allow access to the device node. After the user makes a selection, the result is saved to its own encrypted database according to the user's selection. The next time this sensitive permission is accessed, the result is directly returned. If it is not the first access, the relevant device node is directly opened or refused to be opened based on the access status of the sensitive permission of the device node in the encrypted database.
[0090] Figure 4 It is a schematic diagram of the permission setting architecture in the operating system of the embodiments of the present application. As Figure 4 shown, in the embodiments of the present application, it also supports the function of querying and modifying the settings of the sensitive permission access status. Through the system settings function in the App, the access status of the sensitive permission of the application for the device node can be queried through the sensitive permission service in the encrypted database. That is, the embodiments of the present application can provide corresponding query interfaces for the App to query all sensitive permission information, such as querying the sensitive permission information of a certain application package, querying the sensitive permission information of a certain PID, setting the sensitive permission information of a certain application package, deleting the sensitive permission information of a certain application package, creating and storing sensitive permission information in the encrypted database, etc. The stored data in the encrypted database regarding the access status of sensitive permissions includes information such as the application package name, binary executable file name, sensitive permission name, and sensitive permission status. In the embodiments of the present application, the application process name is queried according to the PID, and the application package name information is queried according to the process name. The sensitive permission status specifically includes:
[0091] enum PermissionStatus {
[0092] Normal = 0, (default status)
[0093] Disagree, (deny access status)
[0094] Agree (allow access status)
[0095] };
[0096] Those skilled in the art should understand that the above access status of sensitive permissions is only for exemplary illustration, not for limiting the access status of sensitive permissions, and other status settings are also supported.
[0097] In the embodiments of the present application, the system settings in the App can call the sensitive permission service interface to query the application sensitive permission information and modify the relevant information of the sensitive permissions in the encrypted database.
[0098] Figure 5 It is a schematic structural diagram of the permission control device in the operating system according to the embodiments of the present application. As Figure 5 shown, the permission control device in the operating system according to the embodiments of the present application includes:
[0099] A query unit 50, configured to, in response to an access request of a first process to a first device node, query the access status of the first process to the first permission of the first device node from a first permission service;
[0100] A first receiving unit 51, configured to receive a first query result returned by the first permission service;
[0101] A first generating unit 52, configured to generate first feedback information based on the first query result;
[0102] An output unit 53, configured to output the first feedback information to the application corresponding to the first process;
[0103] A second receiving unit 54, configured to receive a second query result returned by the first permission service;
[0104] A processing unit 55, configured to, in response to the second query result, enable the first device node or output a first prompt message indicating that the first process corresponding application has no permission to enable the first device node;
[0105] Wherein, the first query result and the second query result are obtained by the first permission service by searching in a set database based on the information of the first device node and / or the identification information of the first process; the access status of the first permission of more than one device node for more than one application is pre-stored in the set database; the identification information of the first process is associated with the identification information of the application corresponding to the first process.
[0106] In one embodiment, on the basis of the permission control device in the Figure 5 operating system shown, the permission control device in the operating system according to the embodiments of the present application further includes:
[0107] A third receiving unit ( Figure 5 not shown in the figure), configured to receive second indication information of the application corresponding to the first process for the first feedback information;
[0108] The processing unit 55 is further configured to enable the first device node based on the second indication information; and trigger the first permission service to modify the access status of the first permission of the first device node for the application corresponding to the first process to allowed access in the set database.
[0109] In one embodiment, based on the permission control device in the Figure 5 operating system shown, the permission control device in the operating system of the embodiments of the present application further includes:
[0110] A fourth receiving unit ( Figure 5 not shown in the figure) for receiving third indication information of the application corresponding to the first process for the first feedback information;
[0111] The processing unit 55 is further configured to output a first prompt message without permission to enable the first device node to the application corresponding to the first process based on the third indication information; and trigger the first permission service to modify the access status of the first permission of the first device node for the application corresponding to the first process to denied access in the set database.
[0112] In one embodiment, the processing unit 55 is further configured to:
[0113] In response to a query request for the first permission, trigger the first permission service to search for all data items regarding the first permission, or data items of the first permission related to the application identification information in the query request, or data items of the first permission related to the device node identification information in the query request, or data items of the first permission related to the process identification in the set database, and output them.
[0114] In one embodiment, the processing unit 55 is further configured to:
[0115] In response to a modification request for a data item of the first permission, the first permission service modifies the corresponding data item of the first permission in the set database and saves the modified data item of the first permission.
[0116] In one embodiment, based on the permission control device in the Figure 5 operating system shown, the permission control device in the operating system of the embodiments of the present application further includes:
[0117] A second generating unit ( Figure 5 not shown in the figure) for generating the first permission service and the set database in response to the loading of the operating system, and setting the first permission data item regarding the device node to a default value in the set database.
[0118] In an exemplary embodiment, units such as the query unit 50, the first receiving unit 51, the first generating unit 52, the output unit 53, the second receiving unit 54, the third receiving unit, the fourth receiving unit, and the second generating unit can be implemented by one or more central processing units (CPUs), application specific integrated circuits (ASICs), digital signal processors (DSPs), programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontroller units (MCUs), microprocessors, or other electronic components, and are used to execute the steps of the privilege control method in the operating system of the foregoing embodiments.
[0119] In the embodiments of the present disclosure, Figure 5 The specific manners in which the respective units in the privilege control device in the illustrated operating system perform operations have been described in detail in the embodiments related to the method, and will not be elaborated herein.
[0120] Next, with reference to Figure 6 the electronic device 11 according to an embodiment of the present application will be described.
[0121] As Figure 6 shown, the electronic device 11 includes one or more processors 111 and a memory 112.
[0122] The processor 111 may be a central processing unit (CPU) or other form of processing unit having data processing capabilities and / or instruction execution capabilities, and may control other components in the electronic device 11 to perform desired functions.
[0123] The memory 112 may include one or more computer program products, and the computer program products may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory, etc. The non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage media, and the processor 111 may run the program instructions to implement the privilege control method in the operating system of various embodiments of the present application described above and / or other desired functions. Various contents such as input signals, signal components, noise components, etc. may also be stored in the computer-readable storage media.
[0124] In one example, the electronic device 11 may further include: an input device 113 and an output device 114, and these components are interconnected through a bus system and / or other forms of connection mechanisms ( Figure 6 not shown in the figure).
[0125] The input device 113 may include, for example, a keyboard, a mouse, and so on.
[0126] The output device 114 may output various information to the outside, including the determined distance information, direction information, etc. The output device 114 may include, for example, a display, a speaker, a printer, and a communication network and its connected remote output devices, and so on.
[0127] Of course, for simplicity, Figure 6 only some of the components related to the present application in the electronic device 11 are shown in the figure, and components such as buses, input / output interfaces, etc. are omitted. In addition, according to specific application scenarios, the electronic device 11 may further include any other appropriate components.
[0128] The embodiment of the present application also records a storage medium, on which an executable program is stored, and the executable program is executed by the processor to perform the steps of the privilege control method in the operating system of the foregoing embodiment.
[0129] In addition to the above methods and devices, the embodiments of the present application may also be a computer program product, which includes computer program instructions, and when the computer program instructions are run by the processor, the processor is caused to perform the steps in the methods according to various embodiments of the present application described in the "Exemplary Method" section of the present specification.
[0130] The computer program product may be written in any combination of one or more programming languages for executing the program code of the operations of the embodiments of the present application. The programming languages include object-oriented programming languages such as Java, C++, etc., and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computing device, partially on the user's device, executed as a stand-alone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.
[0131] In addition, an embodiment of the present application may also be a computer-readable storage medium storing computer program instructions, which when run by a processor cause the processor to execute the steps in the methods according to various embodiments of the present application described in the above "Exemplary Methods" section of this specification.
[0132] The computer-readable storage medium may adopt any combination of one or more readable media. The readable media may be a readable signal medium or a readable storage medium. The readable storage medium may include, for example, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of the readable storage medium include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0133] The basic principles of the present application have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, benefits, effects, etc. mentioned in the present application are only examples and not limitations, and it cannot be considered that these advantages, benefits, effects, etc. are essential for each embodiment of the present application. In addition, the above-disclosed specific details are only for the purposes of illustration and easy understanding, and not for limitation. The above details do not limit the present application to necessarily adopt the above specific details for implementation.
[0134] The block diagrams of the devices, apparatuses, equipment, and systems involved in this application are only illustrative examples and are not intended to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, equipment, and systems can be connected, arranged, and configured in any manner. Words such as "including", "comprising", "having", etc. are open-ended terms, meaning "including but not limited to", and can be used interchangeably with each other. The word "or" and "and" used herein refer to the phrase "and / or", and can be used interchangeably with it, unless the context clearly indicates otherwise. The phrase "such as" used herein refers to the phrase "such as but not limited to", and can be used interchangeably with it.
[0135] It should also be noted that in the devices, equipment, and methods of this application, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent solutions of this application.
[0136] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use this application. Various modifications to these aspects will be very obvious to those skilled in the art, and the general principles defined herein can be applied to other aspects without departing from the scope of this application. Therefore, this application is not intended to be limited to the aspects shown herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein.
[0137] The above description has been given for purposes of illustration and description. In addition, this description is not intended to limit the embodiments of this application to the forms disclosed herein. Although multiple example aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, changes, additions, and sub-combinations thereof.
Claims
1. A method for permission control in an operating system, characterized in that The method includes: In response to an access request of a first process to a first device node, a device service queries a first privilege service for an access status of the first process to a first privilege of the first device node; The device service receives a first query result returned by the first privilege service, where the first query result indicates that the application corresponding to the first process accesses the first device node for the first time. Based on the first query result, the device service generates first feedback information, outputs the first feedback information to the application corresponding to the first process, receives second indication information or third indication information of the application corresponding to the first process for the first feedback information, enables the first device node or outputs first prompt information indicating that there is no privilege to enable the first device node to the application corresponding to the first process, and triggers the first privilege service to modify the access status of the first privilege of the first device node for the application corresponding to the first process to allowed access or denied access in a set database; or the device service receives a second query result returned by the first privilege service, enables the first device node or outputs the first prompt information to the application corresponding to the first process; Wherein, the second query result is the access status of the first privilege in the case that the application corresponding to the first process accesses the first device node not for the first time, and the first query result and the second query result are obtained by the first privilege service by looking up in the set database based on information of the first device node and / or identification information of the first process; the access status of the first privilege of more than one device node for more than one application is pre-stored in the set database; the identification information of the first process is associated with the identification information of the application corresponding to the first process.
2. The method according to claim 1, wherein The method further includes: In response to a query request for a first privilege, the first privilege service looks up all data items regarding the first privilege, or data items of the first privilege related to the application identification information in the query request, or data items of the first privilege related to the device node identification information in the query request, or data items of the first privilege related to the process identification in the query request in the set database, and outputs them.
3. The method according to claim 2, wherein The method further includes: In response to a modification request for a data item of a first privilege, the first privilege service modifies the corresponding data item of the first privilege in the set database and saves the modified data item of the first privilege.
4. The method according to claim 1, wherein The method further includes: In response to the loading of the operating system, the first privilege service and the set database are generated, and the data item of the first privilege regarding the device node is set to a default value in the set database.
5. A privilege control device in an operating system, characterized in that, The apparatus includes: A query unit, configured to query a first privilege service for an access status of a first process to a first privilege of a first device node in response to an access request of the first process to the first device node; A first receiving unit, configured to receive a first query result returned by the first privilege service, where the first query result indicates that the application corresponding to the first process accesses the first device node for the first time; A first generation unit for generating first feedback information based on the first query result; An output unit for outputting the first feedback information to the application corresponding to the first process; A processing unit for receiving second indication information or third indication information of the application corresponding to the first process for the first feedback information, enabling the first device node or outputting a first prompt message without permission to enable the first device node to the application corresponding to the first process, and triggering the first permission service to modify the access status of the first permission of the first device node for the application corresponding to the first process to allowed access or denied access in the set database; A second receiving unit for receiving a second query result returned by the first permission service; The processing unit is further configured to, in response to the second query result, enable the first device node or output the first prompt message to the application corresponding to the first process; Wherein the second query result is the access status of the first permission when the application corresponding to the first process accesses the first device node for the non-first time, and the first query result and the second query result are obtained by the first permission service by searching in the set database based on the information of the first device node and / or the identification information of the first process; the access status of the first permission of more than one device node for more than one application is pre-stored in the set database; the identification information of the first process is associated with the identification information of the application corresponding to the first process.
6. The device according to claim 5, characterized in that The processing unit is further configured to: In response to a query request for the first permission, trigger the first permission service to search for all data items regarding the first permission in the set database, or data items of the first permission related to the application identification information in the query request, or data items of the first permission related to the device node identification information in the query request, or data items of the first permission related to the process identification in the query request, and output them.
7. The device according to claim 6, characterized in that, The processing unit is further configured to: In response to a modification request for the data item of the first permission, the first permission service modifies the corresponding data item of the first permission in the set database and saves the modified data item of the first permission.
8. The device according to claim 5, characterized in that The device further includes: A second generation unit for generating the first permission service and the set database in response to the loading of the operating system, and setting the first permission data item regarding the device node to a default value in the set database.
9. An electronic device, including a processor, a memory, and an executable program stored on the memory and capable of being run by the processor. When the processor runs the executable program, it executes the steps of the permission control method in the operating system according to any one of claims 1 to 4.
10. A storage medium, on which an executable program is stored. When the executable program is executed by a processor, it implements the steps of the permission control method in the operating system according to any one of claims 1 to 4.
Citation Information
Patent Citations
Application program authority dynamic control method and system
CN103617380A
Application starting method and device, mobile terminal and computer readable storage medium
CN110188534A