Resource access control method, terminal device and computer readable storage medium
By passing the web page URL requested by JsBridge call in the Browser module of the WebView component, the problem of insufficient accuracy and real-time resource access control in the prior art is solved, and higher security and accuracy are achieved.
Patent Information
- Application Number
- CN202010848944.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-08-21
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2040-08-21
AI Technical Summary
The existing resource access control methods are insufficient in terms of accuracy and real-timeness, especially in hybrid mode mobile applications. The JsBridge mechanism may cause malicious network resources to uncontrolled access and operate local resources of terminal devices.
By passing the webpage URL that initiates the JsBridge call request in the Browser module of the WebView component, ensuring that the application can accurately identify the true source of the request, thereby improving the accuracy and real-timeness of resource access control. The specific implementation method includes adding new parameters to receive URLs in the JavaObject interface, or passing URLs through the setUrl interface.
Improve the accuracy and real-time nature of resource access control, ensure that malicious network resources cannot access and operate the local resources of terminal devices without authorization, and enhance security.
Smart Images

Figure CN114077732B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of terminal technology, and in particular to a resource access control method, a terminal device, and a computer-readable storage medium. Background Art
[0002] WebView is an operating system component that can be used to provide web page display and web page interaction capabilities for applications. Based on the WebView component, hybrid mobile applications (Hybrid App) can be developed. The WebView component in the hybrid mobile application, like a normal browser, can execute remote HTML / JavaScript code on the network side. In addition, the hybrid mobile application can provide local resource access and operation capabilities for the remote code through some mechanisms (for example, the JsBridge mechanism), that is, the network side can access and operate the local resources of the terminal device installed with the hybrid mobile application through mechanisms such as JsBridge.
[0003] Mechanisms such as JsBridge may introduce security issues. For example, untrusted or malicious network resources can arbitrarily access and operate local resources of terminal devices without restrictions, which may cause local resources to be tampered with or abused. For this reason, some access control technologies have emerged to control the interactive behavior of the network end, and prevent malicious network sources from tampering with or abusing local resources while ensuring the integrity of business capabilities.
[0004] Existing access control methods generally focus on whitelist control strategies. However, these access control methods have poor accuracy and real-time performance. Summary of the invention
[0005] The embodiments of the present application provide a resource access control method, a terminal device, and a computer-readable storage medium, which can improve the accuracy and real-time performance of resource access control.
[0006] In the first aspect, the embodiment of the present application provides a resource access control method, which is applied to a terminal device, the terminal device includes an application and a WebView component of the application, and the WebView component includes a Render module and a Browser module. The method may include: the terminal device obtains a web link through the WebView component through the application, loads and displays a web page related to the web link; the terminal device receives a JsBridge call request of the web page through the WebView component, and sends the JsBridge call request to the Browser module through the Render module; the terminal device sends a Uniform Resource Locator (URL) and a JsBridge call request to the application through the Browser module, the URL being the URL of the web page that initiates the JsBridge call request; the terminal device instructs the application to perform resource access control according to the URL and the JsBridge call request.
[0007] In an embodiment of the present application, when a JsBridge call request is passed to an application through the Browser module in the WebView component, the URL of the web page that initiated the JsBridge call request is also passed, that is, the URL of the requesting party's web page is passed. That is, through the WebView framework, the URL of the requesting party page of each JsBridge call request is passed to the application, so that the authenticity and real-time nature of the URL received by the application are higher, thereby improving the accuracy and real-time nature of resource access control.
[0008] In specific applications, there are many ways to implement the Browser module passing the requesting page URL and the JsBridge call request to the application.
[0009] In one implementation, a new parameter is added to the original JavaObject interface to receive the URL of the page that initiates the JsBridge call request. Based on this, when the Browser module forwards the JsBridge call request, it adds the URL of the requesting page as a parameter to the JsBridge call request, so that the JsBridge call request carries the URL of the requesting page and is passed to the application.
[0010] That is, in some possible implementations of the first aspect, the process of a terminal device sending a uniform resource locator URL and a JsBridge call request to an application through a Browser module may include: the terminal device calls the JavaObeject interface of the application through the Browser module, and sends the URL and the JsBridge call request to the application; wherein the JavaObeject interface is provided with parameters for receiving the URL.
[0011] In another implementation, a setUrl interface can be added to the application to receive the URL of the requesting page. Based on this, before the Browser module forwards the JsBridge call request, the WebView component will make an additional local Jsbridge call to call the setUrl interface through the Browser module to pass the URL of the requesting page to the application. Then, the Browser module calls the JavaObeject interface to send the Jsbridge call request to the application.
[0012] That is, in some other possible implementations of the first aspect, the process of the terminal device sending a uniform resource locator URL and a JsBridge call request to an application through a Browser module may include: the terminal device calls the setUrl interface of the application through the Browser module, and sends the URL to the application through the setUrl interface; the terminal device calls the JavaObeject interface of the application through the Browser module, and sends the JsBridge call request to the application through the JavaObeject interface.
[0013] In some possible implementations of the first aspect, before the terminal device calls the setUrl interface of the application through the Browser module and sends the URL to the application through the setUrl interface, the method may also include: the terminal device determines through the Browser module whether the application has set the setUrl interface; if the setUrl interface has been set, the terminal device executes the step of calling the setUrl interface of the application through the Browser module and sending the URL to the application through the setUrl interface.
[0014] In some possible implementations of the first aspect, the webpage includes a top-level page, or includes a top-level page and an embedded page; the JsBridge call request includes a JsBridge call request initiated by the top-level page, and / or a JsBridge call request initiated by the embedded page. That is, the JsBridge call request can be initiated by the top-level page or by the embedded page.
[0015] In some possible implementations of the first aspect, a process in which a terminal device instructs an application to perform resource access control according to a URL and a JsBridge call request may include:
[0016] The terminal device instructs the application to determine whether the URL is in the whitelist based on the URL, or to determine whether the URL is in the whitelist based on the URL and the type of resource requested for access; when the URL is not in the whitelist, the terminal device instructs the application to interrupt the JsBridge call request to deny the web page from accessing the local resources of the terminal device; when the URL is in the whitelist, the terminal device instructs the application to accept the JsBridge call request to allow the web page to access the local resources of the terminal device.
[0017] In a second aspect, an embodiment of the present application provides a terminal device, including an application and a WebView component of the application, wherein the WebView component includes a Render module and a Browser module;
[0018] The application is used to obtain a web link through the WebView component, and load and display the web page related to the web link;
[0019] The WebView component is used to receive the JsBridge call request from the web page and send the JsBridge call request to the Browser module through the Render module;
[0020] The Browser module is used to send a uniform resource locator URL and a JsBridge call request to the application. The URL is the URL of the web page that initiates the JsBridge call request.
[0021] The application is also used to perform resource access control based on URL and JsBridge call requests.
[0022] In some possible implementations of the second aspect, the Browser is specifically used to: call the JavaObeject interface of the application, and send a URL and a JsBridge call request to the application; wherein the JavaObeject interface is provided with parameters for receiving the URL.
[0023] In some possible implementations of the second aspect, the above-mentioned Browser is specifically used to: call the setUrl interface of the application and send a URL to the application through the setUrl interface; call the JavaObeject interface of the application and send a JsBridge call request to the application through the JavaObeject interface.
[0024] In some possible implementations of the second aspect, the above-mentioned Browser is also specifically used to: determine whether the application has set the setUrl interface; if the setUrl interface has been set, execute the steps of calling the setUrl interface of the application and sending the URL to the application through the setUrl interface.
[0025] In some possible implementations of the second aspect, the web page includes a top-level page, or includes a top-level page and an embedded page; the JsBridge call request includes a JsBridge call request initiated by the top-level page, and / or a JsBridge call request initiated by the embedded page.
[0026] In some possible implementations of the second aspect, the above-mentioned application is specifically used to: determine whether the URL is in the whitelist based on the URL, or determine whether the URL is in the whitelist based on the URL and the type of resource requested to be accessed; when the URL is not in the whitelist, interrupt the JsBridge call request to deny the web page from accessing the local resources of the terminal device; when the URL is in the whitelist, accept the JsBridge call request to allow the web page to access the local resources of the terminal device.
[0027] In a third aspect, an embodiment of the present application provides a terminal device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements any method of the first aspect when executing the computer program.
[0028] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method of any one of the above-mentioned first aspects is implemented.
[0029] In a fifth aspect, an embodiment of the present application provides a chip system, the chip system includes a processor, the processor is coupled to a memory, and the processor executes a computer program stored in the memory to implement any method as described in any one of the first aspects above. The chip system can be a single chip, or a chip module composed of multiple chips.
[0030] In a sixth aspect, an embodiment of the present application provides a computer program product, which, when executed on a terminal device, enables the terminal device to execute any of the methods described in the first aspect above.
[0031] It can be understood that the beneficial effects of the second to sixth aspects mentioned above can be found in the relevant description of the first aspect mentioned above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Figure 1 A schematic flow chart of a resource access control method provided in an embodiment of the present application;
[0033] Figure 2 A schematic diagram of a resource access control system framework provided in an embodiment of the present application;
[0034] Figure 3 Another schematic block diagram of the resource access control method provided in the embodiment of the present application;
[0035] Figure 4 A schematic diagram comparing resource access control methods provided in an embodiment of the present application;
[0036] Figure 5 A schematic diagram of a resource access control process provided in an embodiment of the present application;
[0037] Figure 6 A schematic block diagram of another process of the resource access control method provided in the embodiment of the present application;
[0038] Figure 7 A schematic diagram for comparing another resource access control method provided in an embodiment of the present application;
[0039] Figure 8 A schematic diagram of another resource access control process provided in an embodiment of the present application;
[0040] Fig. 9 A schematic diagram of the interaction process provided in the embodiment of the present application;
[0041] Fig.10 A schematic diagram of the hardware structure of the terminal device 1000 provided in an embodiment of the present application. DETAILED DESCRIPTION
[0042] In the following description, for the purpose of explanation rather than limitation, specific details such as specific system structures and technologies are provided to facilitate a thorough understanding of the embodiments of the present application.
[0043] See also Figure 1 , which is a schematic flowchart of a resource access control method provided in an embodiment of the present application.
[0044] like Figure 1 As shown, after the WebView component receives the web link, it uses the LoadUrl method to load the web page corresponding to the web link.
[0045] First, before executing the LoadUrl method, obtain the URL of the web link. Based on the URL and the pre-configured whitelist policy, determine whether the web link is allowed to be loaded. Specifically, determine whether the URL is in the whitelist; when the URL is in the whitelist, the web link is allowed to be loaded, and the initialization and life cycle function calling (for example, OnPageStarted, ShouldOverrideUrl) and other processes are entered. When the URL is not in the whitelist, the web link is not allowed to be loaded, the web page loading process is interrupted, or a prompt message can be displayed to prompt the user that the current web link is not trustworthy.
[0046] In the process of calling the life cycle function, the WebView component can also perform whitelist access control on the web link to determine whether to allow the web link to load. Specifically, the WebView component calls the built-in function getUrl method to obtain the URL currently being loaded; determine whether the URL is in the whitelist. If the URL is in the whitelist, the web link can be loaded, the network resources can be rendered, and the web page can be displayed. If the URL is not in the whitelist, the operation is interrupted.
[0047] Moreover, after the WebView component calls the lifecycle function and obtains the currently loaded URL through the getUrl method, the WebView component can call the SetUrl method to save the currently obtained URL in a variable. In the subsequent process, when the WebView component receives a JsBride call request, it can obtain the URL from the variable and perform whitelist access control based on the URL.
[0048] After the WebView component is initialized and the life cycle function is called, it can load the web page corresponding to the web link. At this time, the terminal device displays the corresponding web page, and the user can also see the web page corresponding to the web link.
[0049] After loading the web page, the network end can access the local resources of the terminal device through the JsBridge mechanism. Specifically, the network end sends an interaction request, and after the WebView component receives the interaction request, it calls the getUrl method to obtain the URL previously saved in the variable. The URL is obtained and saved by calling the getUrl method during the process of the WebView component calling the life cycle function.
[0050] The WebView component determines whether to allow the network resource to access the local resource based on the acquired URL. Specifically, the WebView component determines whether the acquired URL is in the whitelist. If it is in the whitelist, the network resource is allowed to access the local resource. If it is not in the whitelist, the network resource is not allowed to access the local resource.
[0051] The interactive request is a resource access request initiated by the network resource calling the JsBridge mechanism. The interactive request can be specifically a JsBridge call request. The JsBridge mechanism is a mechanism that provides an interface for calling functions to web pages. The network resource can refer to a network terminal or a web page, that is, the web page or the network terminal initiates the JsBridge call.
[0052] As can be seen above, after receiving the JsBridge call request, the WebView component actively obtains the previously saved URL through the getUrl method. The obtained URL is not real-time, that is, it does not re-obtain the URL of the web page that initiated the JsBridge call request after receiving the JsBridge call request, resulting in poor real-time resource access control.
[0053] In addition, the URL obtained by the built-in getUrl method when the WebView component calls the lifecycle function is the URL of the top-level page, and the URL of the embedded iframe page cannot be obtained. Therefore, when the WebView component performs whitelist access control on the JsBridge call request, the source page of the JsBridge call request is regarded as the top-level page, resulting in poor accuracy of resource access control.
[0054] For example, a JsBridge call request is initiated by an embedded page of a top-level page. The URL of the embedded page is untrusted, that is, the URL of the embedded page is not in the whitelist. The URL of the top-level page is trusted, that is, the URL of the top-level page is in the whitelist. However, the WebView component regards the requesting page of the JsBridge call request as the top-level page. The WebView component determines whether to allow the current JsBridge call request based on the URL of the top-level page. Since the URL of the top-level page is trusted, the final judgment result is to allow the current JsBridge call request. In this way, untrusted web pages can access local resources, which poses a high security risk.
[0055] The above article about Figure 1In the description, the WebView component is used as the execution subject. In actual applications, the subject of resource access control is the application (Application, APP), that is, the application can call the WebView component to implement resource access control.
[0056] against Figure 1 In order to solve the problem of poor real-time performance and accuracy in the resource access control method, an embodiment of the present application provides a resource access control solution to improve the real-time performance and accuracy.
[0057] The resource access control solution provided in the embodiment of the present application improves the JsBridge mechanism of the WebView component so as to pass the URL of the actual request page of the JsBridge call request to the application through the framework of the WebView component.
[0058] Let's first combine Figure 2 The resource access control system framework schematic diagram shown introduces the resource access control solution provided in the embodiment of the present application.
[0059] like Figure 2 As shown, it includes an application 21, an application framework layer 22, and a WebView component 23. The application 21 refers to an application using the WebView component, and the application 21 may include a JavaObject 211. The JavaObject 211 is the final local resource provider.
[0060] The application framework layer 22 can provide an application programming interface (API) and a programming framework for the application. JsBridge is between the application 21 and the application framework layer 22.
[0061] The WebView component 23 may include a Browser module 231, a Render module 232, a V8 module 233, a Gin layer 234, and a Glue layer 235. The Browser module 231 includes a GinJavaBoundObject 236, the Render module 232 includes a GinJavaBridgeObject 237, and the V8 module 233 includes a V8 Object 238.
[0062] Among them, GinJavaBoundObject236, GinJavaBridgeObject237 and V8 Object238 are reference forms of JavaObject211 in different modules.
[0063] The Browser module 231 is a window management module in the browser, and the Render module 232 is a page rendering module in the browser. The Gin layer 234 and the Glue layer 235 are both link layers, the Gin layer 234 is the link layer between the Javascript engine and the browser, and the Glue layer 235 is the connection layer between the WebView component and the Android system.
[0064] Typically, the JsBridge call request is initiated by the V8 module 233, that is, the V8 module 233 passes the JsBridge call request to the Render module 232, and the Render module 232 sends the JsBridge call request to the Browser module 231. The Browser module 231 forwards the JsBridge call request to the application 21. In this process, when the Browser module 231 forwards the JsBridge call request, it only includes a simple request and does not include the URL of the web page that initiates the JsBridge call request. In this way, the application 21 cannot distinguish the real web page source of the JsBridge call request.
[0065] The embodiment of the present application improves the JsBridge call mechanism so that when the Browser module 231 forwards the JsBridge call request, it not only includes a simple request, but also sends the render url to the application 21. The render url represents the URL of the requesting page that initiates the JsBridge call request. In this way, the URL of the requesting page that initiates the JsBridge call request can be passed to the application through the framework of the WebView component.
[0066] like Figure 2 As shown, the V8 module 233 and the Render module 232 can interact through injection and query. The Render module 232 and the Browser module 231 can use the MOJO communication protocol to perform IPC communication. The Browser module 231 can invoke the JavaObject 211 in the application 21 to pass the render url to the application 21.
[0067] That is to say, Figure 1 In the resource access control method shown, the Browser module 231 only sends a simple JsBridge call request to the application 21. The application 21 needs to obtain the webpage URL by an untrusted asynchronous method of obtaining the request source. That is, the application 21 calls the getUrl method to actively obtain the URL previously stored in the variable.
[0068] The resource access control scheme of the embodiment of the present application is different from Figure 1 The asynchronous way of obtaining the request source is to pass the URL of the real request page to the application 21 through the Browser module 231 in the WebView framework.
[0069] In comparison, Figure 1 In the resource access control method shown, the requesting party web page URL obtained by the application is saved during the life cycle function call process, and the real-time performance is poor. However, in the embodiment of the present application, the requesting party web page URL is passed to the application through the Browser module 231 during the process of transmitting the JsBridge call request, and the real-time performance is higher. In addition, since the Browser module 231 transmits the real web page URL that initiates the JsBridge call request, even if the request is initiated by an embedded page, whitelist access control can be performed based on the URL of the embedded page, and the accuracy is higher.
[0070] That is to say, the resource access control scheme provided in the embodiment of the present application can improve the real-time and authenticity of the requesting party page URL obtained by the application 21.
[0071] In a specific application, the way in which the Browser module 231 transmits the render url parameter to the application program 21 is arbitrary. By way of example, two possible implementations are introduced below.
[0072] First method
[0073] In this method, a new parameter is added to the specific interface of the application, and the new parameter is used to receive the render url parameter.
[0074] In specific applications, it is necessary to modify the logic of the Jsbridge registration part and the interaction part in the application package (APK) of the WebView component. In this way, during the resource access process, the application 21 can obtain the URL of the web page that initiates the JsBridge call request from the newly added parameters, which does not affect business continuity and can improve the accuracy and real-time performance of resource access control.
[0075] For example, first, a parameter is added to the JavaObject211 of the application 21 to receive the render url parameter sent by the Browser module 231. Then, when registering the JavaObject object interface, the Browser module 231 can ignore the newly added parameter, so that the web end can still use the previous call logic when calling the JavaObject interface. Finally, when the Browser module 231 sends the JsBridge call request to the application 21, the newly added parameter in the JavaObject interface is explicitly set to the render url (i.e., the URL of the current requester), that is, the Browser module 231 adds the render url to the JsBridge call request, so that the JsBridge call request carries the render url. Alternatively, it can also be understood that the Browser module 231 receives the JsBridge call request sent by the Render module 232, adds the renderurl to the JsBridge call request, generates a new request, and sends the generated request to the application 21. Alternatively, the Browser module 231 may also determine whether the JsBridge object applies the first solution. If the first solution is applied, the URL of the network requester is added to the parameter list of the JsBridge call.
[0076] The application 21 can read the render url in the JavaObject interface to obtain the URL to the real requester.
[0077] In this implementation, the resource access control process of the WebView component can be as follows: Figure 3 shown. Figure 3 Another schematic block diagram of the process of the resource access control method provided in the embodiment of the present application.
[0078] like Figure 3 As shown, Figure 1 Similarly, after the WebView component obtains the web link, before LoadUrl, it determines whether the URL of the web link is in the whitelist based on the pre-configured whitelist strategy; if the URL is in the whitelist, it enters the initialization and lifecycle function calling process. If the URL is not in the whitelist, the web link is not allowed to load.
[0079] and Figure 1Similarly, the WebView component calls the lifecycle function, obtains the currently loaded URL through the getUrl method, and then determines whether the URL is in the whitelist. If the URL is in the whitelist, the web link is loaded and the network resources are rendered. If the URL is not in the whitelist, the operation is interrupted.
[0080] and Figure 1 Differently, after the WebView component calls the lifecycle function and obtains the currently loaded URL through the getUrl method, the WebView component does not call the SetUrl method to save the currently obtained URL in a variable. That is, the obtained URL does not need to be saved.
[0081] In addition, after loading the web page, when the network end accesses the local resources of the terminal device through the JsBridge mechanism, the JsBridge call request will carry a render url parameter, which is used to identify the initiator of the JsBridge call request. Figure 1 Differently, after the WebView component receives an interaction request, it does not need to call the getUrl method to obtain the URL previously saved in the variable.
[0082] After receiving the JsBridge call request, the application can perform a whitelist comparison based on the render url parameter carried in the JsBridge call request and the resource type requested to be accessed. After the verification passes, the network end is allowed to access and operate local resources.
[0083] Among them, when the resource type requested for access is a type that does not allow access and operation, even if the render url is in the whitelist, the resource access request may not be allowed. For example, local resources include two resource types: username and user password. When the local resource requested by the network end is the username and the requesting party's webpage URL is in the whitelist, the network end's access request is allowed. However, when the local resource requested by the network end is the user password, the network end's access request is not allowed.
[0084] The following will be Figure 4 and Figure 5 , for the first method and Figure 1 The differences between the resource access control methods shown are introduced. Figure 4 A schematic diagram comparing resource access control methods provided in the embodiments of the present application. Figure 5 A schematic diagram of a resource access control process provided in an embodiment of the present application.
[0085] like Figure 4As shown, the application 41 includes a whitelist access control module 411, a JavascriptObject 412, a whitelist policy 413, and a local resource 414. The application is an application that uses the WebView component. The WebView component 42 includes a whitelist trusted page (Trust page) 421 and a malicious web page (Untrust iframe) 422. The malicious page 422 is an embedded web page of the whitelist trusted page 421, and the whitelist trusted page 421 is a top-level page. The malicious page 422 can be a third-party advertising page, which is an untrusted page.
[0086] Figure 4 (a) in Figure 1 The corresponding resource access control method, Figure 4 (b) is the resource access control method corresponding to the first method mentioned above.
[0087] Depend on Figure 4 As can be seen from (a), the whitelist trusted page 421 and the malicious web page 422 initiate Jscall, which represents a JsBridge call request initiated from the network end. The application 41 receives the JsBridge call requests of the whitelist trusted page 421 and the malicious web page 422 through JavascriptObject412. The whitelist access control module (White List checker) 411 actively obtains the URL of the whitelist trusted page 421 previously saved in the variable through the getUrl method. Whitelist access control is performed based on the URL of the whitelist trusted page 421.
[0088] Specifically, for the JsBridge call request initiated by the whitelist trusted page 421, the whitelist access control module 411 determines that the URL of the whitelist trusted page 421 is in the whitelist, then allows the JsBridge call request to be initiated from the whitelist trusted page 421, allowing the network end to access and control the local resource 414.
[0089] For the JsBridge call request initiated from the malicious web page 422, the whitelist access control module 411 regards the source of the JsBridge call request as the whitelist trusted page 421, that is, according to the URL of the whitelist trusted page 421, it determines whether to allow the JsBridge call request initiated from the malicious web page 422. Since the URL of the whitelist trusted page 421 is in the whitelist, the request initiated from the malicious page is allowed.
[0090] It is understandable that JsBridge call requests initiated from trusted pages should be allowed, while JsBridge call requests initiated from untrusted pages should be blocked. Figure 4 In the resource access control method corresponding to (a), when there is an untrusted iframe page in a trusted page, the application cannot distinguish the real source page of the JsBridge call request, and thus processes the JsBridge call request initiated from the untrusted page as the JsBridge call request initiated from the trusted page, which poses a security risk.
[0091] like Figure 4 As shown in (b), the Jscall initiated by the whitelist trusted page 421 and the malicious web page 422 carries the render url. That is, the JsBridge call request initiated from the whitelist trusted page 421 carries the URL of the whitelist trusted page 421, and the JsBridge call request initiated from the malicious web page 422 carries the URL of the malicious web page 422.
[0092] The application 41 receives the JsBridge call requests of the whitelist trusted page 421 and the malicious web page 422 through the JavascriptObject 412. The whitelist access control module 411 performs whitelist access control according to the URL carried in each JsBridge call request.
[0093] Specifically, for the JsBridge call request initiated by the whitelist trusted page 421, the whitelist access control module 411 determines that the URL of the whitelist trusted page 421 is in the whitelist, then allows the JsBridge call request to be initiated from the whitelist trusted page 421, allowing the network end to access and control the local resource 414.
[0094] For the JsBridge call request initiated from the malicious web page 422 , the whitelist access control module 411 determines that the URL carried by the JsBridge call request is not in the whitelist, and then does not allow the JsBridge call request, that is, does not allow resource access requests initiated from the malicious web page 422 .
[0095] By comparison, we can see that Figure 4 In the resource access control method corresponding to (b), through the render url parameter carried by each JsBridge call request, the application 41 can accurately identify the true source of the request, and the JsBridge call request initiated from the trusted page and the JsBridge call request initiated from the untrusted page are accurately distinguished, thereby improving the accuracy of resource access control.
[0096] Figure 5 (a) is the above Figure 4 (a) in FIG. 1 shows a schematic diagram of the effect of the resource access control method. Figure 5As shown in (a), a top-level page 511 and an embedded iframe page 512 are displayed on the terminal device 51. The top-level page 511 is a trusted page, and the embedded iframe page 512 is an untrusted page, which is generally a third-party advertising page. The JsBridge call request initiated from the top-level page 511 is passed to the JavaObject 513 of the application, and then passed to the whitelist access control module 514 of the application. The whitelist access control module 514 calls the getUrl method to obtain the previously saved URL of the top-level page 511. After determining that the URL of the top-level page 511 is in the whitelist, the JsBridge call request initiated by the top-level page 511 is allowed, that is, the resource access request initiated by the top-level page 511 is allowed, and the network end can access and operate the local resource 515.
[0097] For the JsBridge call request initiated from the embedded iframe page 512, the whitelist access control module 514 calls the getUrl method to obtain the URL of the previously saved top-level page 511. After determining that the URL of the top-level page 511 is in the whitelist, the JsBridge call request initiated by the embedded iframe page 512 is allowed, that is, the resource access request initiated by the top-level page 511 is allowed.
[0098] Figure 5 (b) is the above Figure 4 (b) in FIG. 1 shows a schematic diagram of the effect of the resource access control method. Figure 5 As shown in (b) in FIG. 5 , the JsBridge call request initiated from the top-level page 511 carries the URL of the top-level page, and the JsBridge call request initiated from the embedded iframe page 512 carries the URL of the embedded iframe page 512.
[0099] The whitelist access control module 514 of the application determines whether to allow the JsBridge call request based on the URL carried by each JsBridge call request. Since the URL of the top-level page 511 is in the whitelist, the JsBridge call request initiated from the top-level page 511 is allowed. However, the URL of the embedded iframe page 512 is not in the whitelist, so the JsBridge call request initiated from the embedded iframe page 512 is not allowed, that is, the JsBridge call request initiated from the embedded iframe page 512 is interrupted. Specifically, Figure 5 The “X” in (b) of FIG.
[0100] Second method
[0101] In this implementation, a new interface is added to the application to receive the render url parameter.
[0102] In specific applications, modify the logic of the interactive request part in the WebView component. After receiving the JsBridge call request from the network, WebView will make an additional local Jsbridge call to call the newly added interface and pass the render url parameter to the application.
[0103] For example, JavaObject211 of application 21 adds a new interface, setUrl interface, for receiving the URL of the requesting party. Browser module 231 receives the JsBridge call request from Render module 232. Before sending the JsBridge call request to application 21, it can first determine whether JavaObject211 has registered the setUrl method. If it has been registered, Browser module 231 calls the setUrl interface and passes the render url parameter of the current JsBridge call request to application 21. Then, JavaObject211 is called to send the JsBridge call request to application 21.
[0104] The JavaObject 211 of the application 21 saves the renderurl parameter passed in by the Browser module 231 in a variable through the setUrl interface. When performing resource access control, the application can read the renderurl parameter saved in the variable and perform whitelist access control based on the renderurl parameter and the resource type requested for access. Only after passing the whitelist check can the local resources be accessed and operated.
[0105] In this implementation, the resource access control process of the WebView component can be as follows: Figure 6 shown. Figure 6 A schematic block diagram of another process of the resource access control method provided in an embodiment of the present application.
[0106] like Figure 6 As shown, Figure 3The difference is that after the WebView component loads the web page, renders network resources, and displays the web page, it can receive an interaction request initiated from the web page, which is a JsBridge call request. Before passing the JsBridge call request to the application, the Browser module in the WebView component first determines whether there is a setUrl interface, that is, whether to register the setUrl method. If the setUrl interface exists, the Browser module calls the setUrl interface to pass the render url to the application. The application determines whether to allow this call based on the renderurl passed in through the setUrl interface and the JsBridge call request. If the render url is in the whitelist, the call is allowed.
[0107] It should be noted that the process description before the WebView component loads a web page can be found in Figure 3 The corresponding content in will not be repeated here.
[0108] It can be seen that Figure 3 same, Figure 6 After the WebView component calls the lifecycle function and obtains the currently loaded URL through the getUrl method, the WebView component does not call the SetUrl method to save the currently obtained URL in a variable. In other words, the obtained URL does not need to be saved. In addition, after the WebView component receives an interaction request, it does not need to call the getUrl method to obtain the URL previously saved in the variable.
[0109] The following will be Figure 7 and Figure 8 , for the second method and Figure 1 The differences between the resource access control methods shown are introduced. Figure 7 A schematic diagram for comparing another resource access control method provided in an embodiment of the present application. Figure 8 A schematic diagram of another resource access control process provided in an embodiment of the present application.
[0110] like Figure 7 As shown, the application 71 includes a whitelist access control module 711, a JavascriptObject 712, a whitelist policy 713, and a local resource 714. The application is an application that uses the WebView component. The WebView component 72 includes a whitelist trusted page (Trust page) 721 and a malicious web page (Untrust iframe) 722. The malicious page 722 is an embedded web page of the whitelist trusted page 721, and the whitelist trusted page 721 is a top-level page. The malicious page 722 can be a third-party advertising page, which is an untrusted page.
[0111] Figure 7 (a) in Figure 1 The corresponding resource access control method, Figure 7 (b) is the resource access control method corresponding to the second method mentioned above.
[0112] Depend on Figure 7 As can be seen from (a) in the figure, the whitelist trusted page 721 and the malicious web page 722 initiate Jscall. The application 71 receives the JsBridge call requests of the whitelist trusted page 721 and the malicious web page 722 through JavascriptObject712. The whitelist access control module (White List checker) 711 actively obtains the URL of the whitelist trusted page 721 previously saved in the variable through the getUrl method. Whitelist access control is performed based on the URL of the whitelist trusted page 721.
[0113] Specifically, for the JsBridge call request initiated by the whitelist trusted page 721, the whitelist access control module 711 determines that the URL of the whitelist trusted page 721 is in the whitelist, and then allows the JsBridge call request to be initiated from the whitelist trusted page 721, allowing the network end to access and control the local resource 714.
[0114] For the JsBridge call request initiated from the malicious web page 722, the whitelist access control module 711 regards the source of the JsBridge call request as the whitelist trusted page 721, that is, according to the URL of the whitelist trusted page 721, it determines whether to allow the JsBridge call request initiated from the malicious web page 722. Since the URL of the whitelist trusted page 721 is in the whitelist, the request initiated from the malicious page is allowed.
[0115] Understandably, Figure 7 In the resource access control method corresponding to (a), when there is an untrusted iframe page in a trusted page, the application cannot distinguish the real source page of the JsBridge call request, and thus processes the JsBridge call request initiated from the untrusted page as the JsBridge call request initiated from the trusted page, which poses a security risk.
[0116] like Figure 7As shown in (b), the whitelist trusted page 721 and the malicious web page 722 initiate Jscall. For the JsBridge call request initiated from the whitelist trusted page 721, the Browser module calls the setUrl interface 715 to pass the render url parameter of the request to the application, and passes the JsBridge call request to the application by calling JavascriptObject712.
[0117] In response to the JsBridge call request initiated from the malicious web page 722, the Browser module calls the setUrl interface 715 to pass the render url parameter of the request to the application, and passes the JsBridge call request to the application by calling JavascriptObject712.
[0118] The whitelist access control module 711 of the application 71 performs whitelist access control according to the URL of each JsBridge call request.
[0119] Specifically, for the JsBridge call request initiated by the whitelist trusted page 721, the whitelist access control module 711 reads the URL saved in the setUrl interface 715, and determines that the URL of the whitelist trusted page 721 is in the whitelist, then allows the JsBridge call request to be initiated from the whitelist trusted page 721, allowing the network end to access and control the local resource 714.
[0120] For the JsBridge call request initiated from the malicious webpage 722, the whitelist access control module 711 reads the URL of the request from the seturl interface 715. Then, if it is determined that the URL of the JsBridge call request is not in the whitelist, the JsBridge call request is not allowed, that is, the resource access request initiated from the malicious webpage 422 is not allowed.
[0121] By comparison, we can see that Figure 7 The resource access control method corresponding to (b) in FIG. 4A passes the render url parameter of each JsBridge call request to the application by calling the newly added setUrl interface 715. The application 41 can accurately identify the real source of the request, and the JsBridge call request initiated from the trusted page and the JsBridge call request initiated from the untrusted page are accurately distinguished, thereby improving the accuracy of resource access control.
[0122] Figure 8 For the above Figure 7 (b) in FIG. 1 shows a schematic diagram of the effect of the resource access control method. Figure 7The effect diagram corresponding to (a) in the figure can be found in the above Figure 5 (a) in the above will not be described in detail here. Figure 8 As shown, the terminal device 81 displays a top-level page 811 and an embedded iframe page 812. The top-level page 811 is a trusted page, and the embedded iframe page 812 is an untrusted page.
[0123] After the JsBridge call request initiated from the top-level page 811 is passed to the Browser module in the WebView component, the Browser module can call the setUrl interface to pass the URL of the top-level page 811 to the application's whitelist access control module 814. The Browser module calls JavascriptObject 813 to pass the JsBridge call request to the application.
[0124] Similarly, after the JsBridge call request initiated from the embedded iframe page 812 is passed to the Browser module in the WebView component, the Browser module can call the setUrl interface to pass the URL of the embedded iframe page 812 to the application's whitelist access control module 814. The Browser module calls JavascriptObject 813 to pass the JsBridge call request to the application.
[0125] The whitelist access control module 814 of the application determines whether to allow the JsBridge call request based on the URL of each JsBridge call request. Since the URL of the top-level page 811 is in the whitelist, the JsBridge call request initiated from the top-level page 811 is allowed to access the local resource 815. However, the URL of the embedded iframe page 812 is not in the whitelist, so the JsBridge call request initiated from the embedded iframe page 812 is not allowed, that is, the JsBridge call request initiated from the embedded iframe page 812 is interrupted. Figure 8 The "X" in the
[0126] The first and second methods are described above respectively, but in actual applications, the specific implementation methods are not limited to the first and second methods described above.
[0127] In the first method, a new parameter is added to the existing JavascriptObject interface to pass the requester's URL, which is a hidden parameter. In other words, this method can implicitly pass the requester's URL through the hidden parameter during the JsBridge call process through the WebView framework.
[0128] In the second method, a new setUrl interface is added to pass the requester's URL. In this implementation, each time the WebView framework makes a JsBridge call, it makes an additional local JsBridge call to call the setUrl interface and pass the requester's URL. The newly added interface type is not limited to the setUrl interface.
[0129] As can be seen from the above, the embodiment of the present application can pass the accurate requester URL to the application through the WebView framework, thereby improving the real-time and accuracy of resource access control. In addition, the embodiment of the present application is that the WebView framework actively pushes the real requester URL to the application, without the need for the application to actively obtain it by calling the getUrl method.
[0130] It should be noted that, although the descriptions of the first and second methods above are both based on a request in which a trusted page has an embedded untrusted page, the solution provided in the embodiment of the present application can also be applied when there is no embedded page or the embedded page is a trusted page.
[0131] The resource scheme control scheme provided in the embodiment of the present application can be applied to a terminal device, which may include a WebView component and an application using the WebView component. The WebView component may include a Broswer module and a Render module, etc. In order to better introduce the resource access control scheme provided in the embodiment of the present application, the following will be combined with Fig. 9 The interactive process diagram shown introduces the process of each module in the terminal device.
[0132] After the application in the terminal device calls the WebView component and loads and displays the web page related to the web link, the web page can initiate a resource access request by calling the JsBridge mechanism. The V8 module in the WebView component can receive the JsBridge call request, and then pass the JsBridge call request and the URL of the requesting page to the application through the framework of the WebView component. Fig. 9 As shown, the interaction process may include the following steps:
[0133] Step S901: The V8 module in the WebView component sends a JsBridge call request to the Render module.
[0134] It is understandable that the JsBridge call request may be initiated from a web page, and the web page may be a top-level page or an embedded iframe page.
[0135] Step S902: The Render module sends the JsBridge call request to the Broswer module.
[0136] Step S903: The Broswer module sends the JsBridge call request and the renderurl parameter of the JsBridge call request to the application.
[0137] In a specific application, when the JavaObject interface of the application is set with parameters for receiving the URL, the Broswer module calls the JavaObject interface, adds the rendder URL of the JsBridge call request to the JsBridge call request, and sends it to the application together.
[0138] When the application adds a new setUrl interface, the Broswer module first calls the setUrl interface to send the rendder url of the JsBridge call request to the application. Then, it calls the JavaObeject interface to send the JsBridge call request to the application.
[0139] Step S904: The application performs resource access control according to the JsBridge call request and the render url parameter of the request.
[0140] Specifically, the application is pre-configured with a whitelist strategy. The application determines whether the render url is in the whitelist, that is, whether the URL of the web page that initiates the JsBridge call request is in the whitelist. If it is, the network terminal is allowed to access local resources. If not, the call is interrupted and the network terminal is not allowed to access local resources.
[0141] More specifically, resource access control can also be performed based on the resource type requested for access. The resource type requested for access can be obtained from the JsBridge call request. By classifying local resources in advance, various resource types can be obtained. For example, local resources include user names and user passwords. When the local resource requested for access is a user password, due to the privacy and security of the user password, that is, the URL of the requesting party's web page is in the whitelist, it cannot be determined that the call is not allowed, that is, the network end is not allowed to access the local user password. At this time, the application performs resource access control based on the URL and the resource type requested for access. In this implementation method, local resources can be graded, and web links verified by the whitelist cannot access all local resources, which further improves the accuracy of resource access control and further improves the security of local resources.
[0142] from Fig. 9It can be learned that the application in the terminal device can be used to obtain web links through the WebView component, load and display web pages related to the web links; the WebView component is used to receive JsBridge call requests for web pages, and send JsBridge call requests to the Browser module through the Render module; the Browser module is used to send a uniform resource locator URL and a JsBridge call request to the application, where the URL is the URL of the web page that initiates the JsBridge call request; the application is also used to perform resource access control based on the URL and the JsBridge call request.
[0143] In some embodiments, the Browser module can be specifically used to: call the JavaObeject interface of the application, and send a URL and a JsBridge call request to the application; wherein the JavaObeject interface is provided with parameters for receiving the URL.
[0144] In another embodiment, the Browser can be specifically used for: making a local Jsbridge call to call the setUrl interface of the application to send a URL to the application; calling the JavaObeject interface of the application to send a JsBridge call request to the application.
[0145] In some embodiments, the above-mentioned Browser can also be specifically used to: determine whether the application has registered the setUrl method or set the setUrl interface; if the setUrl method has been registered, execute the step of calling the setUrl interface of the application through the local Jsbridge call and sending the URL to the application. If it has not been registered, the subsequent steps are not executed.
[0146] In some embodiments, the web page includes a top-level page, or includes a top-level page and an embedded page; the JsBridge call request includes a JsBridge call request initiated by the top-level page, and / or a JsBridge call request initiated by the embedded page.
[0147] In some embodiments, the above application can be specifically used to: determine whether the URL is in the whitelist based on the URL, or determine whether the URL is in the whitelist based on the URL and the type of resource requested to be accessed; when the URL is not in the whitelist, interrupt the JsBridge call request to deny the web page from accessing the local resources of the terminal device; when the URL is in the whitelist, allow the JsBridge call request to allow the web page to access the local resources of the terminal device.
[0148] The type of terminal device provided in the embodiment of the present application can be any. For example, the terminal device can be a portable terminal device such as a mobile phone or a tablet computer, and the specific structure of the terminal device is also arbitrary. Fig.10 As shown, the terminal device 1000 may include a processor 1010, an external memory interface 1020, an internal memory 1021, a universal serial bus (USB) interface 1030, a charging management module 1040, a power management module 1041, a battery 1042, an antenna 1, an antenna 2, a mobile communication module 1050, a wireless communication module 1060, an audio module 1070, a speaker 1070A, a receiver 1070B, a microphone 1070C, an earphone interface 1070D, a sensor module 1080, a button 1090, a motor 1091, an indicator 1092, a camera 1093, a display screen 1094, and a subscriber identification module (SIM) card interface 1095, etc. The sensor module 1080 may include a pressure sensor 1080A, a gyroscope sensor 1080B, an air pressure sensor 1080C, a magnetic sensor 1080D, an acceleration sensor 1080E, a distance sensor 1080F, a proximity light sensor 1080G, a fingerprint sensor 1080H, a temperature sensor 1080J, a touch sensor 1080K, an ambient light sensor 1080L, a bone conduction sensor 1080M, etc.
[0149] It is understood that the structure illustrated in the embodiment of the present application does not constitute a specific limitation on the terminal device 1000. In other embodiments of the present application, the terminal device 1000 may include more or fewer components than shown in the figure, or combine some components, or split some components, or arrange the components differently. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware.
[0150] The processor 1010 may include one or more processing units, for example, the processor 1010 may include an application processor (AP), a modem processor, a graphics processor (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Different processing units may be independent devices or integrated into one or more processors.
[0151] The controller may be the nerve center and command center of the terminal device 1000. The controller may generate an operation control signal according to the instruction operation code and the timing signal to complete the control of fetching and executing instructions.
[0152] The processor 1010 may also be provided with a memory for storing instructions and data. In some embodiments, the memory in the processor 1010 is a cache memory. The memory may store instructions or data that the processor 1010 has just used or cyclically used. If the processor 1010 needs to use the instruction or data again, it may be directly called from the memory. This avoids repeated access, reduces the waiting time of the processor 1010, and thus improves the efficiency of the system.
[0153] In some embodiments, the processor 1010 may include one or more interfaces. The interface may include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface, etc.
[0154] The I2C interface is a bidirectional synchronous serial bus, including a serial data line (SDA) and a serial clock line (SCL). In some embodiments, the processor 1010 may include multiple groups of I2C buses. The processor 1010 may be coupled to the touch sensor 1080K, the charger, the flash, the camera 1093, etc. through different I2C bus interfaces. For example: the processor 1010 may be coupled to the touch sensor 1080K through the I2C interface, so that the processor 1010 communicates with the touch sensor 1080K through the I2C bus interface, thereby realizing the touch function of the terminal device 1000.
[0155] The I2S interface can be used for audio communication. In some embodiments, the processor 1010 can include multiple I2S buses. The processor 1010 can be coupled to the audio module 1070 via the I2S bus to achieve communication between the processor 1010 and the audio module 1070.
[0156] The PCM interface can also be used for audio communication, sampling, quantizing and encoding analog signals. In some embodiments, the audio module 1070 and the wireless communication module 1060 can be coupled via a PCM bus interface. Both the I2S interface and the PCM interface can be used for audio communication.
[0157] The UART interface is a universal serial data bus for asynchronous communication. The bus can be a bidirectional communication bus. It converts the data to be transmitted between serial communication and parallel communication. In some embodiments, the UART interface is generally used to connect the processor 1010 and the wireless communication module 1060. For example, the processor 1010 communicates with the Bluetooth module in the wireless communication module 1060 through the UART interface to implement the Bluetooth function.
[0158] The MIPI interface can be used to connect the processor 1010 with peripheral devices such as the display screen 1094 and the camera 1093. The MIPI interface includes a camera serial interface (CSI), a display serial interface (DSI), etc. In some embodiments, the processor 1010 and the camera 1093 communicate via the CSI interface to implement the shooting function of the terminal device 1000. The processor 1010 and the display screen 1094 communicate via the DSI interface to implement the display function of the terminal device 1000.
[0159] The GPIO interface can be configured by software. The GPIO interface can be configured as a control signal or as a data signal. In some embodiments, the GPIO interface can be used to connect the processor 1010 with the camera 1093, the display 1094, the wireless communication module 1060, the audio module 1070, the sensor module 1080, etc. The GPIO interface can also be configured as an I2C interface, an I2S interface, a UART interface, a MIPI interface, etc.
[0160] The USB interface 1030 is an interface that complies with the USB standard specification, and specifically can be a Mini USB interface, a Micro USB interface, a USB Type C interface, etc. The USB interface 1030 can be used to connect a charger to charge the terminal device 1000, and can also be used to transmit data between the terminal device 1000 and peripheral devices. It can also be used to connect headphones to play audio through the headphones. The interface can also be used to connect other terminal devices, such as AR devices, etc.
[0161] It is understandable that the interface connection relationship between the modules illustrated in the embodiment of the present application is only a schematic illustration and does not constitute a structural limitation on the terminal device 1000. In other embodiments of the present application, the terminal device 1000 may also adopt different interface connection methods in the above embodiments, or a combination of multiple interface connection methods.
[0162] The charging management module 1040 is used to receive charging input from a charger. The charger may be a wireless charger or a wired charger. In some wired charging embodiments, the charging management module 1040 may receive charging input from a wired charger through the USB interface 1030. In some wireless charging embodiments, the charging management module 140 may receive wireless charging input through a wireless charging coil of the terminal device 1000. While the charging management module 1040 is charging the battery 1042, it may also power the terminal device through the power management module 1041.
[0163] The power management module 1041 is used to connect the battery 1042, the charging management module 1040 and the processor 1010. The power management module 1041 receives input from the battery 1042 and / or the charging management module 1040, and supplies power to the processor 1010, the internal memory 1021, the external memory, the display screen 1094, the camera 1093, and the wireless communication module 1060. The power management module 1041 can also be used to monitor parameters such as battery capacity, battery cycle number, battery health status (leakage, impedance), etc. In some other embodiments, the power management module 1041 can also be set in the processor 1010. In other embodiments, the power management module 1041 and the charging management module 1040 can also be set in the same device.
[0164] The wireless communication function of the terminal device 1000 can be implemented through antenna 1, antenna 2, mobile communication module 1050, wireless communication module 1060, modem processor and baseband processor.
[0165] Antenna 1 and antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in terminal device 1000 can be used to cover a single or multiple communication frequency bands. Different antennas can also be reused to improve the utilization of antennas. For example, antenna 1 can be reused as a diversity antenna for a wireless local area network. In some other embodiments, the antenna can be used in combination with a tuning switch.
[0166] The mobile communication module 1050 can provide solutions for wireless communications including 2G / 3G / 4G / 5G applied to the terminal device 1000. The mobile communication module 1050 may include at least one filter, a switch, a power amplifier, a low noise amplifier (LNA), etc. The mobile communication module 1050 can receive electromagnetic waves from the antenna 1, and filter, amplify, and process the received electromagnetic waves, and transmit them to the modulation and demodulation processor for demodulation. The mobile communication module 1050 can also amplify the signal modulated by the modulation and demodulation processor, and convert it into electromagnetic waves for radiation through the antenna 1. In some embodiments, at least some of the functional modules of the mobile communication module 1050 can be set in the processor 1010. In some embodiments, at least some of the functional modules of the mobile communication module 1050 can be set in the same device as at least some of the modules of the processor 1010.
[0167] The modem processor may include a modulator and a demodulator. Among them, the modulator is used to modulate the low-frequency baseband signal to be sent into a medium-high frequency signal. The demodulator is used to demodulate the received electromagnetic wave signal into a low-frequency baseband signal. The demodulator then transmits the demodulated low-frequency baseband signal to the baseband processor for processing. After the low-frequency baseband signal is processed by the baseband processor, it is passed to the application processor. The application processor outputs a sound signal through an audio device (not limited to a speaker 1070A, a receiver 1070B, etc.), or displays an image or video through a display screen 1094. In some embodiments, the modem processor may be an independent device. In other embodiments, the modem processor may be independent of the processor 1010 and be set in the same device as the mobile communication module 1050 or other functional modules.
[0168] The wireless communication module 1060 can provide wireless communication solutions including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks), bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared (IR), etc., which are applied to the terminal device 1000. The wireless communication module 1060 can be one or more devices integrating at least one communication processing module. The wireless communication module 1060 receives electromagnetic waves via the antenna 2, modulates the frequency of the electromagnetic wave signal and performs filtering, and sends the processed signal to the processor 110. The wireless communication module 1060 can also receive the signal to be sent from the processor 1010, modulate the frequency of it, amplify it, and convert it into electromagnetic waves for radiation through the antenna 2.
[0169] In some embodiments, the antenna 1 of the terminal device 1000 is coupled to the mobile communication module 1050, and the antenna 2 is coupled to the wireless communication module 1060, so that the terminal device 1000 can communicate with the network and other devices through wireless communication technology. The wireless communication technology may include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technology. GNSS may include the global positioning system (GPS), the global navigation satellite system (GLONASS), the Beidou navigation satellite system (BDS), the quasi-zenith satellite system (QZSS) and / or the satellite based augmentation system (SBAS).
[0170] The terminal device 1000 implements the display function through a GPU, a display screen 1094, and an application processor. The GPU is a microprocessor for image processing, which connects the display screen 1094 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. The processor 1010 may include one or more GPUs, which execute program instructions to generate or change display information.
[0171] The display screen 1094 is used to display images, videos, etc. The display screen 1094 includes a display panel. The display panel can be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode or an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), Miniled, MicroLed, Micro-oLed, a quantum dot light-emitting diode (QLED), etc. In some embodiments, the terminal device 1000 may include 1 or N display screens 1094, where N is a positive integer greater than 1.
[0172] The terminal device 1000 can realize the shooting function through ISP, camera 1093, video codec, GPU, display screen 1094 and application processor.
[0173] The ISP is used to process the data fed back by the camera 1093. For example, when taking a photo, the shutter is opened, and the light is transmitted to the camera photosensitive element through the lens. The light signal is converted into an electrical signal, and the camera photosensitive element transmits the electrical signal to the ISP for processing and converts it into an image visible to the naked eye. The ISP can also perform algorithm optimization on the noise, brightness, and skin color of the image. The ISP can also optimize the exposure, color temperature and other parameters of the shooting scene. In some embodiments, the ISP can be set in the camera 1093.
[0174] The camera 1093 is used to capture still images or videos. The object generates an optical image through the lens and projects it onto the photosensitive element. The photosensitive element can be a charge coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the optical signal into an electrical signal, and then passes the electrical signal to the ISP to be converted into a digital image signal. The ISP outputs the digital image signal to the DSP for processing. The DSP converts the digital image signal into an image signal in a standard RGB, YUV or other format. In some embodiments, the terminal device 1000 may include 1 or N cameras 1093, where N is a positive integer greater than 1.
[0175] The digital signal processor is used to process digital signals. In addition to processing digital image signals, it can also process other digital signals. For example, when the terminal device 1000 is selecting a frequency point, the digital signal processor is used to perform Fourier transform on the frequency point energy.
[0176] Video codecs are used to compress or decompress digital videos. The terminal device 1000 may support one or more video codecs. Thus, the terminal device 1000 may play or record videos in various coding formats, such as Moving Picture Experts Group (MPEG) 1, MPEG2, MPEG3, MPEG4, etc.
[0177] NPU is a neural network (NN) computing processor. By drawing on the structure of biological neural networks, such as the transmission mode between neurons in the human brain, it can quickly process input information and can also continuously self-learn. Through NPU, applications such as intelligent cognition of the terminal device 1000 can be realized, such as image recognition, face recognition, voice recognition, text understanding, etc.
[0178] The external memory interface 1020 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the terminal device 1000. The external memory card communicates with the processor 1010 through the external memory interface 1020 to implement a data storage function, such as storing music, video and other files in the external memory card.
[0179] The internal memory 1021 can be used to store computer executable program codes, and the executable program codes include instructions. The processor 1010 executes various functional applications and data processing of the terminal device 1000 by running the instructions stored in the internal memory 1021. The internal memory 1021 may include a program storage area and a data storage area. Among them, the program storage area may store an operating system, an application required for at least one function (such as a sound playback function, an image playback function, etc.), etc. The data storage area may store data created during the use of the terminal device 1000 (such as audio data, a phone book, etc.), etc. In addition, the internal memory 1021 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), etc.
[0180] The terminal device 1000 can implement audio functions such as music playing and recording through the audio module 1070, the speaker 1070A, the receiver 1070B, the microphone 1070C, the headphone interface 1070D, and the application processor.
[0181] The audio module 1070 is used to convert digital audio information into analog audio signal output, and is also used to convert analog audio input into digital audio signals. The audio module 1070 can also be used to encode and decode audio signals. In some embodiments, the audio module 1070 can be arranged in the processor 1010, or some functional modules of the audio module 1070 can be arranged in the processor 1010.
[0182] The speaker 1070A, also called a "speaker", is used to convert an audio electrical signal into a sound signal. The terminal device 100 can listen to music or listen to a hands-free call through the speaker 1070A.
[0183] The receiver 1070B, also called a "handset", is used to convert audio electrical signals into sound signals. When the terminal device 100 receives a call or voice message, the voice can be received by placing the receiver 1070B close to the human ear.
[0184] Microphone 1070C, also called "microphone" or "microphone", is used to convert sound signals into electrical signals. When making a call or sending a voice message, the user can make a sound by putting their mouth close to the microphone 1070C to input the sound signal into the microphone 1070C. The terminal device 1000 can be provided with at least one microphone 1070C. In other embodiments, the terminal device 1000 can be provided with two microphones 1070C, which can not only collect sound signals but also realize noise reduction function. In other embodiments, the terminal device 1000 can also be provided with three, four or more microphones 1070C to collect sound signals, reduce noise, identify the source of sound, realize directional recording function, etc.
[0185] The earphone interface 1070D is used to connect a wired earphone and can be a USB interface 1030 or a 3.5 mm open mobile terminal platform (OMTP) standard interface or a cellular telecommunications industry association of the USA (CTIA) standard interface.
[0186] The pressure sensor 1080A is used to sense the pressure signal and can convert the pressure signal into an electrical signal. In some embodiments, the pressure sensor 1080A can be set on the display screen 1094. There are many types of pressure sensors 1080A, such as resistive pressure sensors, inductive pressure sensors, capacitive pressure sensors, etc. A capacitive pressure sensor can be a parallel plate including at least two conductive materials. When a force acts on the pressure sensor 180A, the capacitance between the electrodes changes. The terminal device 1000 determines the intensity of the pressure based on the change in capacitance. When a touch operation acts on the display screen 1094, the terminal device 1000 detects the touch operation intensity according to the pressure sensor 1080A. The terminal device 1000 can also calculate the touch position according to the detection signal of the pressure sensor 1080A. In some embodiments, touch operations acting on the same touch position but with different touch operation intensities can correspond to different operation instructions. For example: when a touch operation with a touch operation intensity less than the first pressure threshold acts on the short message application icon, an instruction to view the short message is executed. When a touch operation with a touch operation intensity greater than or equal to a first pressure threshold acts on the short message application icon, an instruction to create a new short message is executed.
[0187] The gyroscope sensor 1080B can be used to determine the motion posture of the terminal device 1000. In some embodiments, the angular velocity of the terminal device 1000 around three axes (i.e., x, y, and z axes) can be determined by the gyroscope sensor 1080B. The gyroscope sensor 1080B can be used for anti-shake shooting. Exemplarily, when the shutter is pressed, the gyroscope sensor 180B detects the angle of the terminal device 1000 shaking, calculates the distance that the lens module needs to compensate based on the angle, and allows the lens to offset the shaking of the terminal device 1000 through reverse movement to achieve anti-shake. The gyroscope sensor 1080B can also be used for navigation and somatosensory game scenes.
[0188] The air pressure sensor 1080C is used to measure air pressure. In some embodiments, the terminal device 1000 calculates the altitude through the air pressure value measured by the air pressure sensor 180C to assist positioning and navigation.
[0189] The magnetic sensor 1080D includes a Hall sensor. The terminal device 1000 can use the magnetic sensor 1080D to detect the opening and closing of the flip leather case. In some embodiments, when the terminal device 1000 is a flip phone, the terminal device 1000 can detect the opening and closing of the flip cover according to the magnetic sensor 1080D. Then, according to the detected opening and closing state of the leather case or the opening and closing state of the flip cover, the flip cover automatic unlocking and other features are set.
[0190] The acceleration sensor 1080E can detect the magnitude of the acceleration of the terminal device 1000 in various directions (generally three axes). When the terminal device 1000 is stationary, the magnitude and direction of gravity can be detected. It can also be used to identify the posture of the terminal device and applied to applications such as horizontal and vertical screen switching and pedometers.
[0191] The distance sensor 1080F is used to measure the distance. The terminal device 1000 can measure the distance by infrared or laser. In some embodiments, when shooting a scene, the terminal device 1000 can use the distance sensor 1080F to measure the distance to achieve fast focusing.
[0192] The proximity light sensor 1080G may include, for example, a light emitting diode (LED) and a light detector, such as a photodiode. The light emitting diode may be an infrared light emitting diode. The terminal device 1000 emits infrared light outward through the light emitting diode. The terminal device 1000 uses a photodiode to detect infrared reflected light from nearby objects. When sufficient reflected light is detected, it can be determined that there is an object near the terminal device 1000. When insufficient reflected light is detected, the terminal device 1000 can determine that there is no object near the terminal device 1000. The terminal device 1000 can use the proximity light sensor 1080G to detect that the user holds the terminal device 1000 close to the ear to talk, so as to automatically turn off the screen to save power. The proximity light sensor 1080G can also be used in leather case mode, and pocket mode automatically unlocks and locks the screen.
[0193] The ambient light sensor 1080L is used to sense the ambient light brightness. The terminal device 1000 can adaptively adjust the brightness of the display screen 1094 according to the perceived ambient light brightness. The ambient light sensor 1080L can also be used to automatically adjust the white balance when taking pictures. The ambient light sensor 1080L can also cooperate with the proximity light sensor 1080G to detect whether the terminal device 1000 is in a pocket to prevent accidental touch.
[0194] The fingerprint sensor 1080H is used to collect fingerprints. The terminal device 1000 can use the collected fingerprint characteristics to achieve fingerprint unlocking, access application locks, fingerprint photography, fingerprint call answering, etc.
[0195] The temperature sensor 1080J is used to detect temperature. In some embodiments, the terminal device 1000 uses the temperature detected by the temperature sensor 1080J to execute a temperature processing strategy. For example, when the temperature reported by the temperature sensor 1080J exceeds a threshold, the terminal device 1000 reduces the performance of the processor located near the temperature sensor 1080J to reduce power consumption and implement thermal protection. In other embodiments, when the temperature is lower than another threshold, the terminal device 1000 heats the battery 1042 to avoid abnormal shutdown of the terminal device 1000 due to low temperature. In some other embodiments, when the temperature is lower than another threshold, the terminal device 1000 performs a boost on the output voltage of the battery 1042 to avoid abnormal shutdown caused by low temperature.
[0196] The touch sensor 1080K is also called a "touch panel". The touch sensor 1080K can be set on the display screen 1094, and the touch sensor 1080K and the display screen 1094 form a touch screen, also called a "touch screen". The touch sensor 1080K is used to detect touch operations acting on or near it. The touch sensor can pass the detected touch operation to the application processor to determine the type of touch event. Visual output related to the touch operation can be provided through the display screen 1094. In other embodiments, the touch sensor 1080K can also be set on the surface of the terminal device 1000, which is different from the position of the display screen 1094.
[0197] The bone conduction sensor 1080M can obtain a vibration signal. In some embodiments, the bone conduction sensor 1080M can obtain a vibration signal of a vibrating bone block of the vocal part of the human body. The bone conduction sensor 1080M can also contact the human pulse to receive a blood pressure beat signal. In some embodiments, the bone conduction sensor 1080M can also be set in an earphone and combined into a bone conduction earphone. The audio module 1070 can parse out a voice signal based on the vibration signal of the vibrating bone block of the vocal part obtained by the bone conduction sensor 1080M to realize a voice function. The application processor can parse the heart rate information based on the blood pressure beat signal obtained by the bone conduction sensor 1080M to realize a heart rate detection function.
[0198] The key 1090 includes a power key, a volume key, etc. The key 1090 may be a mechanical key or a touch key. The terminal device 1000 may receive key input and generate key signal input related to user settings and function control of the terminal device 1000.
[0199] Motor 1091 can generate vibration prompts. Motor 1091 can be used for incoming call vibration prompts, and can also be used for touch vibration feedback. For example, touch operations acting on different applications (such as taking pictures, audio playback, etc.) can correspond to different vibration feedback effects. For touch operations acting on different areas of the display screen 1094, motor 1091 can also correspond to different vibration feedback effects. Different application scenarios (for example: time reminders, receiving messages, alarm clocks, games, etc.) can also correspond to different vibration feedback effects. The touch vibration feedback effect can also support customization.
[0200] Indicator 1092 may be an indicator light, which may be used to indicate charging status, power changes, messages, missed calls, notifications, etc.
[0201] The SIM card interface 1095 is used to connect a SIM card. The SIM card can be connected to and separated from the terminal device 1000 by inserting it into the SIM card interface 1095 or pulling it out from the SIM card interface 1095. The terminal device 1000 can support 1 or N SIM card interfaces, where N is a positive integer greater than 1. The SIM card interface 1095 can support Nano SIM cards, Micro SIM cards, SIM cards, and the like. Multiple cards can be inserted into the same SIM card interface 1095 at the same time. The types of the multiple cards can be the same or different. The SIM card interface 1095 can also be compatible with different types of SIM cards. The SIM card interface 1095 can also be compatible with external memory cards. The terminal device 1000 interacts with the network through the SIM card to implement functions such as calls and data communications. In some embodiments, the terminal device 1000 uses an eSIM, i.e., an embedded SIM card. The eSIM card can be embedded in the terminal device 1000 and cannot be separated from the terminal device 1000.
[0202] The terminal device provided in the embodiment of the present application may include a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, a method such as any one of the above-mentioned resource access control method embodiments is implemented.
[0203] The embodiment of the present application further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments can be implemented.
[0204] An embodiment of the present application provides a computer program product. When the computer program product runs on a terminal device, the terminal device can implement the steps in the above-mentioned method embodiments when executing the computer program product.
[0205] The present application also provides a chip system, which includes a processor coupled to a memory, and the processor executes a computer program stored in the memory to implement the methods described in the above method embodiments. The chip system can be a single chip or a chip module composed of multiple chips.
[0206] In the above-mentioned embodiments, the description of each embodiment has its own emphasis. For the part that is not described or recorded in detail in a certain embodiment, please refer to the relevant description of other embodiments. It should be understood that the size of the sequence number of each step in the above-mentioned embodiment does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiment of the present application. In addition, in the description of the present application specification and the attached claims, the terms "first", "second", "third", etc. are only used to distinguish the description, and cannot be understood as indicating or implying relative importance. The reference "one embodiment" or "some embodiments" described in the present application specification means that one or more embodiments of the present application include specific features, structures or characteristics described in combination with the embodiment. Therefore, the statements "in one embodiment", "in some embodiments", "in some other embodiments", "in some other embodiments", etc. that appear in the different places in this specification are not necessarily all referring to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways.
[0207] Finally, it should be noted that the above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions within the technical scope disclosed in the present application should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
Claims
1. A resource access control method, characterized in that: Applied to a terminal device, the terminal device includes an application and a WebView component of the application, the method includes: The terminal device obtains a web link through the WebView component of the application, and loads and displays a web page related to the web link; The terminal device receives the JsBridge call request of the web page through the WebView component, and sends the JsBridge call request to the Browser module of the WebView component through the Render module of the WebView component; The terminal device sends a uniform resource locator URL and the JsBridge call request to the application through the Browser module, where the URL is the URL of the web page that initiates the JsBridge call request; If the application determines that the web page that initiates the JsBridge call request is a trusted page based on the URL, the JsBridge call request is responded to; if the application determines that the web page that initiates the JsBridge call request is an untrusted page based on the URL, the JsBridge call request is intercepted.
2. The method according to claim 1, characterized in that The terminal device sends a uniform resource locator URL and the JsBridge call request to the application through the Browser module, including: The terminal device calls the JavaObject interface of the application through the Browser module, and sends the URL and the JsBridge calling request to the application; The JavaObject interface is provided with parameters for receiving the URL.
3. The method according to claim 1, characterized in that The terminal device sends a uniform resource locator URL and the JsBridge call request to the application through the Browser module, including: The terminal device calls the setUrl interface of the application through the Browser module, and sends the URL to the application through the setUrl interface; The terminal device calls the JavaObeject interface of the application program through the Browser module, and sends the JsBridge calling request to the application program through the JavaObeject interface.
4. The method according to claim 3, characterized in that Before the terminal device calls the setUrl interface of the application through the Browser module and sends the URL to the application through the setUrl interface, the method further includes: The terminal device determines whether the application has set the setUrl interface through the Browser module; If the setUrl interface has been set, the terminal device executes the steps of calling the setUrl interface of the application through the Browser module and sending the URL to the application through the setUrl interface.
5. The method according to claim 1, characterized in that The web page includes a top-level page, or includes a top-level page and an embedded page; The JsBridge call request includes a JsBridge call request initiated by the top-level page and / or a JsBridge call request initiated by the embedded page.
6. The method according to any one of claims 1 to 5, characterized in that: If the application determines, according to the URL, that the web page that initiates the JsBridge call request is a trusted page, then responding to the JsBridge call request; if the application determines, according to the URL, that the web page that initiates the JsBridge call request is an untrusted page, then intercepting the JsBridge call request, including: The application determines whether the URL is in the whitelist according to the URL, or determines whether the URL is in the whitelist according to the URL and the type of resource requested for access; When the URL is not in the whitelist, the web page is an untrusted page, and the application program interrupts the JsBridge call request to deny the web page from accessing the local resources of the terminal device; When the URL is in the whitelist, the web page is a trusted page, and the application accepts the JsBridge call request to allow the web page to access the local resources of the terminal device.
7. A terminal device, characterized in that: It includes an application and a WebView component of the application, wherein the WebView component includes a Render module and a Browser module; The application is used to obtain a web link through a WebView component, and load and display a web page related to the web link; The WebView component is used to receive the JsBridge call request of the web page, and send the JsBridge call request to the Browser module through the Render module; The Browser module is used to send a uniform resource locator URL and the JsBridge call request to the application, where the URL is the URL of the web page that initiates the JsBridge call request; The application is also used to respond to the JsBridge call request if it is determined according to the URL that the web page initiating the JsBridge call request is a trusted page, and to intercept the JsBridge call request if it is determined according to the URL that the web page initiating the JsBridge call request is an untrusted page.
8. The terminal device according to claim 7, characterized in that: The Browser module is specifically used for: Calling the JavaObeject interface of the application, and sending the URL and the JsBridge calling request to the application; The JavaObject interface is provided with parameters for receiving the URL.
9. The terminal device according to claim 7, characterized in that: The Browser module is specifically used for: Calling the setUrl interface of the application, and sending the URL to the application through the setUrl interface; The JavaObject interface of the application is called, and the JsBridge calling request is sent to the application through the JavaObject interface.
10. The terminal device according to claim 9, characterized in that: The Browser module is also specifically used for: Determine whether the application has set the setUrl interface; If the setUrl interface has been set, the step of calling the setUrl interface of the application and sending the URL to the application through the setUrl interface is performed.
11. The terminal device according to claim 7, characterized in that: The web page includes a top-level page, or includes a top-level page and an embedded page; The JsBridge call request includes a JsBridge call request initiated by the top-level page and / or a JsBridge call request initiated by the embedded page.
12. The terminal device according to any one of claims 7 to 11, characterized in that: The application is specifically used to: Determine whether the URL is in the whitelist according to the URL, or determine whether the URL is in the whitelist according to the URL and the type of resource requested for access; When the URL is not in the whitelist, the web page is an untrusted page, and the JsBridge call request is interrupted to deny the web page from accessing the local resources of the terminal device; When the URL is in the whitelist, the web page is a trusted page and the JsBridge call request is accepted to allow the web page to access the local resources of the terminal device.
13. A terminal device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the method according to any one of claims 1 to 6 is implemented.
14. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Advertisement processing method and electronic equipment
CN110751503A
Bridge for Communicating Data Outside of a Mobile Application
US20180240118A1