Permission Prompting Method, Device, Computer Equipment and Medium

By detecting the data acquisition request of the target application and obtaining relevant information, determining the risk level and maximum risk event of the target data, it solves the problem that users are not sure about their security when granting application permissions, and improves the security of the application.

CN114386018BActive Publication Date: 2025-06-10PING AN TECH (SHENZHEN) CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210057712.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-19
Publication Date
2025-06-10
Estimated Expiration
2042-01-19

AI Technical Summary

Technical Problem

The existing Android operating system pops up the permission application interface when the application is installed, and users are prone to uncertainty about the permission security, resulting in malicious applications obtaining user privacy data and causing privacy data leakage.

Method used

By detecting the data acquisition request of the target application, if the target application has the permission to obtain the target data, the usage information set and reference information set are obtained, and the risk level and maximum risk event of the target application obtaining the target data is determined based on this information, and the corresponding prompt information is displayed.

Benefits of technology

Remind users to protect privacy data, improve the security of using applications, and prevent malicious applications from obtaining user privacy data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114386018B_ABST
    Figure CN114386018B_ABST
Patent Text Reader

Abstract

This application relates to the field of data analysis technology, and provides a permission prompt method, device, computer device and medium. The method includes: detecting a data acquisition request of a target application, where the data acquisition request is used to acquire target data; if the target application has the acquisition permission for the target data, acquiring a usage information set of the target data and a reference information set of the target application; determining a risk level and a maximum risk event for the target application to acquire the target data based on the reference information set and the usage information set; and displaying a prompt information corresponding to the risk level and the maximum risk event. By adopting this application, data leakage can be protected and the security of using application programs can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data analysis technology, and mainly relates to a permission prompt method, device, computer device and medium. Background Art

[0002] With the development of computer technology, electronic devices such as mobile phones and tablets have become necessities in people's lives and store a large amount of personal sensitive information, such as address books, locations, personal files, photos, etc. While various application programs installed in electronic devices provide us with conveniences such as communication, social networking, office work, payment, and games, these application programs may request to obtain sensitive permissions such as files, address books, and locations during installation / operation, resulting in the leakage of users' privacy.

[0003] In the existing Android operating system, when an application program is installed, a permission application interface will pop up on the display interface. Only when the user accepts the permission application can the application program be allowed to be installed. And when the user is unsure whether the applied permissions are safe, they habitually choose to accept the permission application, which easily leads to malicious application programs obtaining the user's privacy data and causing the leakage of privacy data. Summary of the Invention

[0004] The embodiments of this application provide a permission prompt method, device, computer device and medium, which can remind users to protect privacy data and improve the security of using application programs.

[0005] In a first aspect, the embodiments of this application provide a permission prompt method, where:

[0006] Detect a data acquisition request of a target application, where the data acquisition request is used to acquire target data;

[0007] If the target application has the acquisition permission for the target data, obtain the usage information set of the target data and the reference information set of the target application;

[0008] Based on the reference information set and the usage information set, determine the risk level and the maximum risk event for the target application to acquire the target data;

[0009] Display prompt information corresponding to the risk level and the maximum risk event.

[0010] In a second aspect, the embodiments of this application provide a permission prompt device, where:

[0011] A detection unit, configured to detect a data acquisition request of a target application, where the data acquisition request is used to acquire target data;

[0012] An acquisition unit, configured to acquire a usage information set of the target data and a reference information set of the target application if the target application has the permission to acquire the target data;

[0013] A determination unit, configured to determine a risk level and a maximum risk event of the target application for acquiring the target data based on the reference information set and the usage information set;

[0014] A display unit, configured to display a prompt message corresponding to the risk level and the maximum risk event.

[0015] In a third aspect, an embodiment of the present application provides a computer device, including a processor, a memory, a communication interface, and a computer program, wherein the computer program is stored in the memory and configured to be executed by the processor, and the computer program includes instructions for performing some or all of the steps described in the first aspect.

[0016] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and the computer program causes a computer to execute to implement some or all of the steps described in the first aspect.

[0017] Implementing the embodiments of the present application will have the following beneficial effects:

[0018] After adopting the above-mentioned permission prompt method, device, computer device, and medium, after detecting a data acquisition request of a target application for acquiring target data, first determine whether the target application has the permission to acquire the target data. If so, acquire a usage information set of the target data and a reference information set of the target application. Then determine a risk level and a maximum risk event of the target application for acquiring the target data based on the usage scenario and the reference information set. Then display a prompt message corresponding to the risk level and the maximum risk event. In this way, it is possible to remind the user to protect privacy data and improve the security of using application programs. Description of the Drawings

[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0020] Among them:

[0021] Figure 1 is a schematic flowchart of a permission prompt method provided by an embodiment of the present application;

[0022] Figure 2 A structural schematic diagram of a permission prompt device provided by an embodiment of the present application;

[0023] Figure 3 A structural schematic diagram of a computer device provided by an embodiment of the present application. Specific embodiments

[0024] In order to enable those skilled in the art to better understand the solutions of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. According to the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0025] The terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally further include steps or units not listed, or may optionally further include other steps or units inherent to these processes, methods, products or devices.

[0026] Referring to "embodiment" in this article means that a specific feature, structure or characteristic described in combination with the embodiment may be included in at least one embodiment of the present application. The phrase appears in various positions in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will explicitly and implicitly understand that the embodiments described herein may be combined with other embodiments.

[0027] The network architecture applied in the embodiments of the present application includes a server and electronic devices. The embodiments of the present application do not limit the number of electronic devices and servers. The server can provide services for multiple electronic devices at the same time. The server can be an independent server or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery network (CDN), and big data and artificial intelligence platforms. The server can also be implemented by a server cluster composed of multiple servers.

[0028] The electronic device can be a personal computer (PC), a laptop, or a smartphone, and can also be an all-in-one computer, a handheld computer, a tablet (pad), a smart TV playback terminal, a vehicle-mounted terminal, or a portable device, etc. For the electronic device on the PC side, such as an all-in-one computer, its operating system can include, but is not limited to, Linux system, Unix system, Windows series systems (such as Windows xp, Windows 7, etc.), Mac OS X system (the operating system of Apple computers), etc. For the electronic device on the mobile side, such as a smartphone, its operating system can include, but is not limited to, Android system, IOS (the operating system of Apple mobile phones), Window system, etc.

[0029] The electronic device can install and run application programs. The server can be the server corresponding to the application programs installed on the electronic device, providing application services for the application programs. Among them, the application programs can be standalone integrated application software, or small programs embedded in other applications, or systems on web pages, etc., which are not limited here.

[0030] An embodiment of this application proposes a permission prompt method, which can be executed by a permission prompt device. This device can be implemented by software and / or hardware, and is generally integrated in an electronic device or a server, capable of reminding users to protect privacy data and improving the security of using application programs.

[0031] Please refer to Figure 1 , Figure 1 which is a schematic flowchart of a permission prompt method provided by this application. Taking the application of this method in the server as an example for illustration, it includes the following steps S101 to S104, where:

[0032] S101. Detect the data acquisition request of the target application.

[0033] In the embodiment of this application, the data acquisition request is used to acquire target data. The data acquisition request includes at least the identification information of the target data. For example, the class name of the target data, or the encoded field of the class name, etc., which are not limited here.

[0034] This application does not limit the method for obtaining detection data. It can be achieved by replacing the process program of the target application in the system (for example, the / system / bin / app_process program) to control the process of the target application (for example, the Zygote process), so that the process program of the target application will load a monitoring function (for example, XposedBridge.jar) during the startup process. When this monitoring function is called, the virtual machine (for example, the Dalvik virtual machine) determines that the target application has triggered a data acquisition request for the target data based on the path of the calling function. Or a monitoring function for the target data can be set, and when this monitoring function is called, it is further determined whether the target application requests to obtain the target data based on the calling function of this monitoring function.

[0035] This application does not limit the target application and the target data. The target application can be any installed application in the electronic device or a third-party application added to the application. The target data can be data that requires permission application to obtain in the target application. That is to say, when the target application has the permission to obtain the target data, the electronic device can obtain the target data based on this data acquisition request. When the target application does not have the permission to obtain the target data, the electronic device cannot directly obtain the target data.

[0036] In the embodiments of this application, the data type of the target data can be a privacy type. For example, the target data can be stored data such as address book, images, files, historical records, etc., and can also include real-time generated data such as location information, call records, sensor data, etc., which are not limited here. Among them, the sensor data can include physiological data such as heart rate, blood pressure, and walking steps collected by motion sensors, and can also include fingerprint data collected by fingerprint sensors, iris data collected by iris sensors, and brain wave data collected by brain wave sensors. It can be understood that different types of target data can generate different usage information. For example, the usage information of the address book is to obtain the user's relationship graph or search for potential online friends who may be known. Another example is that the usage information of the image is to generate a portrait of the user or generate a memory video.

[0037] It should be noted that the number of target data can be one or more, and the data types of the target data can exist in multiple categories according to different classifications. This application does not limit the number of target data and the number of data types of the target data.

[0038] S102. If the target application has the permission to obtain the target data, obtain the usage information set of the target data and the reference information set of the target application.

[0039] Since some applications require permission requests to be approved before they can be installed. And when users habitually accept permission requests without being sure whether the requested permissions are secure, when the target application has the permission to obtain the target data, it is also necessary to determine whether there are security risks in opening the permission to obtain the target data to the target application. Therefore, it is possible to obtain the usage data of the target data and the reference information set of the target application. In the scenario where the target application does not have the permission to obtain the target data, the data acquisition request can be directly rejected, or the risk level and the maximum risk event of the target application obtaining the target data can be determined based on the reference information set of the target application, so as to remind the user based on the risk level and the maximum risk event. For example, when the risk level is low and the risk level corresponding to the maximum risk event is low, the user can be reminded to enable the permission to obtain the target data. When the risk level is high or the risk level corresponding to the maximum risk event is high, the user can be reminded to pay attention to privacy protection during the use of the target application.

[0040] In the embodiment of the present application, the usage information set of the target data may include the usage information of the target application obtaining the target data. For example, the number of times, frequency, time, usage scenarios, etc. of the target application using the target data. The usage information set of the target data may also include the usage information obtained by the associated data associated with the target application for the target data, etc., which is not limited here.

[0041] The reference information set of the target application may include the basic information of the target application. For example, application name, version number, developer, application type, launch time, whether it is launched in each application store (or application market), etc., and may also include the download volume, access volume, evaluation information, etc. of the target application. Among them, the download volume refers to the download volume of the target application downloaded in the application store or other web pages, etc. The access volume may include the number of views of the target application in the application store or web page, or the average usage frequency of the target application statistically, etc. The evaluation information may include score values, comments, complaints, etc. The reference information set of the target application may alternatively include the event information of the target application. For example, information on various events such as public opinion, products, raw materials, business, spokespersons, etc. The event information may include event parameters such as event name, event cause, event type, event result, impact node, etc.

[0042] The present application does not limit the usage information set of the target data, the reference information set of the target application, and the method for obtaining the usage information set and the reference information set. In one possible example, it may include the following steps A1 to A5, where:

[0043] A1. Obtain the historical usage record of the target data.

[0044] A2. Obtain the usage information set of the target data based on the historical usage record.

[0045] In the embodiments of the present application, the historical usage records of the target data may include the historical usage records of the target application obtaining the target data. For example, the record information of processing types such as storing, editing, and transmitting the target data through the target application. Or it may include the historical usage records of the associated application associated with the target application obtaining the target data, etc. It can be understood that obtaining the usage information set of the target data based on the historical usage records of the target data can improve the comprehensiveness of obtaining the usage information set and is beneficial to improving the accuracy of determining the risk level.

[0046] A3. Determine the associated application associated with the target application.

[0047] In the embodiments of the present application, the associated application may be an application belonging to the same development company as the target application. For example, different versions of the same application, or different applications of the same company, etc. The associated application may also be an application of the same application type as the target application. For example, if the target application is of the instant messaging type, the associated application may be an instant messaging type application installed in the electronic device other than the target application. The associated application may also be an application having data interaction with the target application. For example, an application to which the target application can jump pages, an application corresponding to the microservices added in the target application, etc.

[0048] In a possible example, step A3 may include the following steps: Determine the transmission path of the target data based on the historical usage records; Determine the associated application associated with the target application based on the transmission path.

[0049] Among them, the transmission path refers to the transmission link information of the target data. Any application in the transmission path can be called an associated application. It can be understood that the associated application associated with the target application is determined based on the transmission path of the target data determined based on the historical usage records. In this way, the target data is transmitted between the associated application and the target application, which is beneficial to improving the accuracy of determining the risk level of the target application obtaining the target data.

[0050] It should be noted that step A3 may be executed before step A1, or may be executed before step A1, and may be executed simultaneously with step A1.

[0051] A4. Search the basic information and event information of the target application and the associated application respectively.

[0052] A5. Obtain the reference information set of the target application based on the basic information and event information.

[0053] Among them, the basic information and event information can be referred to the foregoing, and will not be elaborated here. This application does not limit the method for searching the basic information and event information, and web crawler technology can be used to search the target page. The target page can be a web page or an introduction page of an application store, etc., which is not limited here. In this way, obtaining the reference information set of the target application based on the basic information and event information of the target application, as well as the basic information and event information of the associated application, is beneficial to determining the accuracy rate of the risk level and the maximum risk event.

[0054] In a possible example, step A5 may include the following steps: determining a relationship graph between the target application and the associated application based on the basic information of the target application and the basic information of the associated application; adjusting the association value between the target node and other nodes in the relationship graph based on the event information of the target application and the event information of the associated application to obtain a target relationship graph; obtaining a reference information set of the target application based on the association values between each node and other nodes in the target relationship graph.

[0055] Among them, the relationship graph is used to describe the association relationship between relevant nodes of the target application and the associated application. This association relationship can be reflected in the relationship graph through the association value. The relationship graph between the target application and the associated application can be determined by the association relationship between sub-information of each dimension in the basic information, that is, when the sub-information is the same, the target application and the associated application can be connected through the node corresponding to the sub-information. Then, based on the connection of relevant sub-information, a relationship graph between the target application and the associated application is formed.

[0056] It can be understood that the occurrence events of the application more or less have a certain impact on the application. In this example, the association value in the relationship graph between the target application and the associated application is adjusted based on the event information of the target application and the event information of the associated application. Specifically, the nodes corresponding to the event parameters such as the event name, event reason, event type, event result, and affected node in the event information in the relationship graph can be determined first, and then the new association value can be obtained by analyzing the association relationship between this node and the node connected to this node based on the above event parameters. Then, the reference information set of the target application is obtained based on the target relationship graph obtained after adjustment, which can improve the reference value and is beneficial to improving the accuracy rate of risk identification.

[0057] It can be understood that in steps A1 to A5, the usage information set of the target data is obtained based on the historical usage record of the target data, and the reference information set of the target application is obtained based on the basic information and event information of the target application, as well as the basic information and event information of the associated application associated with the target application. In this way, the comprehensiveness of obtaining the usage information set of the target data and the reference information set of the target application can be improved, which is beneficial to improving the accuracy rate of risk identification.

[0058] S103. Determine the risk level and the maximum risk event of the target application for obtaining the target data based on the reference information set and the usage information set.

[0059] In the embodiments of the present application, the risk level is used to describe the risk level of data leakage, which can be understood as the size of the security risk caused by data leakage. The maximum risk event refers to the event with the maximum risk that the risk information can generate. It should be noted that the maximum risk event can be one or more. For example, the first three risk events with relatively large risk values, or the risk event corresponding to the maximum risk level, etc.

[0060] In a possible example, step S103 may include the following steps B1 to B5, where:

[0061] B1. Select the potential risk information of the target application from the reference information set.

[0062] In the embodiments of the present application, the potential risk information refers to the information that may have security risks in the reference information set of the target application. For example, the target application is not launched on any application store, the download volume of the target application is less than 100, the rating of the target application is lower than 40 points, the operating company corresponding to the target application is on the blacklist, 80% of the users have complained about the target application obtaining the target data, etc.

[0063] In a possible example, step B1 may include the following steps B11 to B14, where:

[0064] B11. Classify the reference information in the reference information set to obtain a reference information subset corresponding to each feature dimension in at least two feature dimensions.

[0065] In the embodiments of the present application, the feature dimension refers to the category for measuring the risk level of the target application, which can be measured from aspects such as the normativity and public opinion of the target application. Among them, the normativity can be evaluated through information such as the application source of the target application, the launch situation and download volume on major application stores, and the evaluation value of the developer of the target application. The public opinion can be evaluated through information such as the download volume of the target application, the activity of customers, the evaluation value, and the complaint ratio.

[0066] Classification can be performed through the inclusion relationship or association relationship between the feature dimension and various reference information, and the reference information corresponding to the feature dimension is classified into one category to obtain the reference information subset corresponding to the feature dimension. Exemplarily, if the feature dimension is normativity, the reference information subset corresponding to normativity may include the application source of the target application, the launch situation and download volume on major application stores, and the evaluation value of the developer of the target application.

[0067] B12. Determine the risk index corresponding to the feature dimension based on the reference information subset corresponding to the feature dimension.

[0068] In the embodiments of the present application, a risk indicator refers to a value related to privacy risks. The risk indicator corresponding to a feature dimension can be obtained by weighting the sub-risk indicators corresponding to each piece of reference information in the reference information subset corresponding to the feature dimension.

[0069] Exemplarily, the reference information subset corresponding to normativity includes the application source of the target application, its online status and download volume in major application stores, and the evaluation value of the developer of the target application. Among them, if the target application is not available on any application store and the application source is unclear, the sub-risk indicator corresponding to the application source of the target application is 90 points, the sub-risk indicator corresponding to its online status in major application stores is 100 points. If the download volume is less than 100, the corresponding sub-risk value is 95 points. The evaluation value of the developer of the target application is 65 points, and the corresponding sub-risk value is 65 points. If the preset weights of each piece of reference information are equal, the preset weight is 0.25, and the calculation formula for the risk indicator corresponding to normativity is 0.25 * 90 + 0.25 * 100 + 0.25 * 95 + 0.25 * 65 = 87.5.

[0070] B13. If the risk indicator corresponding to a feature dimension is greater than a preset threshold, determine the reference information subset corresponding to the feature dimension as the target information subset.

[0071] In the embodiments of the present application, the risk indicator corresponding to the feature dimension corresponding to the target information subset is greater than the preset threshold. Exemplarily, the reference information set can be divided into the reference information subset corresponding to the first feature dimension, the reference information subset corresponding to the second feature dimension, and the reference information subset corresponding to the third feature dimension. Among them, the risk indicator corresponding to the first feature dimension is 88, the risk indicator corresponding to the second feature dimension is 80, and the risk indicator corresponding to the third feature dimension is 90. If the preset threshold is 85, both the reference information subset corresponding to the first feature dimension and the reference information subset corresponding to the third feature dimension are target information subsets.

[0072] The present application does not limit the preset threshold, and the preset threshold can be a specific value or can be determined based on the data type of the target data. For example, when the target data is the data that the target application needs to use, the preset threshold can be 60. While when the target data is not the data that the target application needs to use, the preset threshold can be 80.

[0073] B14. Determine the potential risk information of the target application based on the target information subset.

[0074] The potential risk information of the target application can include all the reference information in the target information subset, or can include the reference information whose sub-risk indicator is greater than another preset threshold, etc., which is not limited herein.

[0075] It can be understood that in steps B11 to B14, the reference information set of the target application is classified according to the type of feature dimension, and a reference information subset corresponding to each type of feature dimension is obtained. Then, based on the reference information subsets corresponding to each type of feature dimension, the risk indicators corresponding to each type of feature dimension are determined, which can improve the evaluation efficiency and accuracy of obtaining the risk indicators corresponding to each type of feature dimension. When the risk indicator corresponding to a feature dimension is greater than a preset threshold, the reference information subset corresponding to the feature dimension is determined as the target information subset. Then, based on the target information subset, the potential hazard information of the target application is determined, which can improve the accuracy of determining the potential hazard information.

[0076] B2. Determine at least two potential hazard events for the target application to obtain the target data based on the usage information set.

[0077] In the embodiments of the present application, a potential hazard event refers to an event that may or has caused a security hazard. For example, determining the health status of a user based on the obtained sensor data of the user; pushing advertisements to the user based on the obtained browsing records of the user, etc.

[0078] In a possible example, step B2 may include the following steps B21 to B23, where:

[0079] B21. Determine the event information of each occurrence event in at least two occurrence events for the target application to obtain the target data based on the usage information set.

[0080] B22. Determine the potential hazard level of the occurrence event based on the event information of the occurrence event.

[0081] B23. Select the occurrence events whose potential hazard levels are greater than the preset level from the occurrence events as the potential hazard events for the target application to obtain the target data.

[0082] In the embodiments of the present application, the event information of the occurrence event may include the above-mentioned event parameters, and may also include the occurrence time and usage information of the occurrence event, the data volume of the target data used, etc., which are not limited herein. The potential hazard level of the occurrence event can be understood as the risk hazard caused by the occurrence event for data leakage. This potential hazard level can be obtained by weighted calculation based on various event information such as the data volume of the target data used in the occurrence event, the usage information of the target data, and the event result. The present application does not limit the preset level, and this preset level can be less than the preset threshold for selecting the target information subset mentioned above.

[0083] It can be understood that in steps B21 to B23, first, based on the usage information set, the event information of the occurrence event of the target application obtaining the target data is determined. Then, based on the event information of the occurrence event, the potential risk level of the occurrence event is determined. When the potential risk level of the occurrence event is greater than the preset level, it is determined that the occurrence event is a potential risk event for the target application to obtain the target data. In this way, selecting potential risk events through the event type of the occurrence event is beneficial to improving the accuracy of risk identification.

[0084] B3. Determine the sub-risk value of the potential risk event based on the potential risk information.

[0085] In the embodiments of the present application, the sub-risk value of the potential risk event is used to describe the security risk caused by the potential risk event to data leakage. In a possible example, step B3 may include the following steps B31 and B32, where:

[0086] B31. Determine the correlation value between the event information of the potential risk event and the potential risk information.

[0087] In the embodiments of the present application, the correlation value between the event information of the potential risk event and the potential risk information is used to describe whether the potential risk information will lead to the occurrence of the potential risk event. The correlation value can be determined based on a pre-set knowledge graph. The knowledge graph can be constructed based on the relationship graph of the target application and the associated application, or can be constructed based on various information in the knowledge domain of the target data, etc., which is not limited here. After obtaining the knowledge graph, the nodes corresponding to the event information and the potential risk information can be searched, and then the correlation value between the event information and the potential risk information can be calculated based on the number of connection nodes between the node and another node and the correlation relationship between the connection nodes.

[0088] B32. Determine the sub-risk level of the potential risk event based on the correlation value and the potential risk level of the potential risk event.

[0089] In the embodiments of the present application, the potential risk level of the potential risk event can be determined based on the potential risk level of the occurrence event determined in step B22. The sub-risk level of the potential risk event can be determined as the product of the correlation value and the value corresponding to the potential risk level. Exemplarily, if the correlation value is 0.8 and the value range corresponding to the potential risk level belongs to (60, 80), then the multiplied value range is (48, 64). Assuming that (48, 60) belongs to the value range of the first sub-risk level and (60, 64) belongs to the value range of the second sub-risk level, then the sub-risk level of the potential risk event can be the first sub-risk level that mostly falls into, or can be the second sub-risk level with a greater risk level.

[0090] It can be understood that in step B31 and step B32, determining the sub-risk level of the potential risk event based on the correlation value between the event information and the potential risk information of the potential risk event, and the potential risk level of the potential risk event is beneficial to improving the accuracy of risk identification.

[0091] B4. Perform weighted calculation on the sub-risk values of the potential risk events to obtain the risk level for the target application to obtain the target data.

[0092] In the embodiment of the present application, the risk level for the target application to obtain the target data can be determined by performing weighted calculation on the numerical values of the sub-risk values of each potential risk event. For example, there are two potential risk events, the sub-risk value of one potential risk event is 60, and the sub-risk value of the other potential risk event is 80. If the preset weights of the two potential risk events are equal, the numerical value obtained by weighted calculation is 70. Assuming that the risk level corresponding to 70 is the second risk level, then it is determined that the risk level for the target application to obtain the target data is the second risk level.

[0093] B5. Use the potential risk event corresponding to the maximum value of the sub-risk value as the maximum risk event for the target application to obtain the target data.

[0094] It can be understood that in steps B1 to B5, first determine the potential risk information of the target data based on the reference information set of the target application, and determine the potential risk events for the target application to obtain the target data based on the usage information set of the target data. Then determine the sub-risk values of the potential risk events based on the potential risk information, perform weighted calculation on the sub-risk values of the potential risk events to obtain the risk level for the target application to obtain the target data, and use the potential risk event corresponding to the maximum value of the sub-risk value as the maximum risk event for the target application to obtain the target data. In this way, by determining the risk level and the maximum risk event for the target application to obtain the target data through the potential risk information and potential risk events determined by the reference information set of the target application and the usage information set of the target data, the accuracy of determining the risk level and the maximum risk event can be improved.

[0095] S104. Display prompt information corresponding to the risk level and the maximum risk event.

[0096] In the embodiment of the present application, the prompt information corresponding to the risk level and the maximum risk event at least includes the risk level and the maximum risk event, and is used to prompt the user that the acquisition permission of the target data authorized by the target application is subject to a relatively large risk, so as to prompt the user whether to continue to open the acquisition permission of the target data, thereby protecting the user's privacy and improving the security of using the application program.

[0097] The prompt message may further include a suggestion message. For example, a suggestion to uninstall the target application, a suggestion to close the permission for the target data, a suggestion to stop detecting the permission for the target data, etc. Exemplarily, if the risk level is greater than a preset threshold, the suggestion message in the prompt message may be a suggestion to uninstall. If the risk level is less than the preset threshold, the suggestion message in the prompt message may include a suggestion to stop detecting the permission for the target data.

[0098] The prompt message may further include a permission application box for the user to confirm whether to restrict the acquisition permission of the target data. The present application does not limit the display manner of the prompt message, and the prompt message may be displayed in the form of a pop-up window or in the form of a banner, etc.

[0099] In one possible example, after step S103, the following steps may further be included: determining whether the risk level is greater than a preset threshold, and if so, executing step S104.

[0100] The present application does not limit the preset threshold, and the preset threshold may be related to the data type of the target data. For example, the preset threshold corresponding to the data type of motion data is greater than the preset threshold corresponding to the data type of image data. In one possible example, if the number of data types of the target data is greater than 1, the preset levels corresponding to each data type are weighted and calculated to obtain the preset threshold. In this way, the accuracy of setting the preset threshold can be further improved.

[0101] In Figure 1 the method shown, after detecting a data acquisition request of a target application for acquiring target data, first determine whether the target application has the permission to acquire the target data. If so, obtain the usage information set of the target data and the reference information set of the target application. Then, based on the usage scenario and the reference information set, determine the risk level and the maximum risk event of the target application for acquiring the target data. Then display the prompt message corresponding to the risk level and the maximum risk event. In this way, the user can be reminded to protect privacy data, and the security of using the application program is improved.

[0102] The method of the embodiment of the present application is elaborated in detail above, and the device of the embodiment of the present application is provided below.

[0103] Consistent with Figure 1 the embodiment shown, please refer to Figure 2 , Figure 2 which is a schematic structural diagram of a permission prompt device proposed by the present application. As Figure 2 shown, the above permission prompt device 200 includes:

[0104] A detection unit 201 is configured to detect a data acquisition request of a target application, where the data acquisition request is used to acquire target data;

[0105] The obtaining unit 202 is configured to obtain the usage information set of the target data and the reference information set of the target application if the target application has the obtaining permission for the target data;

[0106] The determining unit 203 is configured to determine the risk level and the maximum risk event of the target application for obtaining the target data based on the reference information set and the usage information set;

[0107] The display unit 204 is configured to display prompt information corresponding to the risk level and the maximum risk event.

[0108] In a possible example, the determining unit 203 is specifically configured to select the hidden trouble information of the target application from the reference information set; determine at least two hidden trouble events of the target application for obtaining the target data based on the usage information set; determine the sub-risk value of the hidden trouble event based on the hidden trouble information; perform weighted calculation on the sub-risk value to obtain the risk level of the target application for obtaining the target data; and use the hidden trouble event corresponding to the maximum value of the sub-risk value as the maximum risk event of the target application for obtaining the target data.

[0109] In a possible example, the determining unit 203 is specifically configured to classify the reference information in the reference information set to obtain a reference information subset corresponding to each feature dimension in at least two feature dimensions; determine the risk index corresponding to the feature dimension based on the reference information subset corresponding to the feature dimension; if the risk index corresponding to the feature dimension is greater than a preset threshold, determine the reference information subset corresponding to the feature dimension as the target information subset; and determine the hidden trouble information of the target application based on the target information subset.

[0110] In a possible example, the determining unit 203 is specifically configured to determine the event information of each occurrence event in at least two occurrence events of the target application for obtaining the target data based on the usage information set; determine the hidden trouble level of the occurrence event based on the event information of the occurrence event; and select the occurrence event with the hidden trouble level greater than the preset level from the occurrence events as the hidden trouble event of the target application for obtaining the target data.

[0111] In a possible example, the determining unit 203 is specifically configured to determine the correlation value between the event information of the hidden trouble event and the hidden trouble information; and determine the sub-risk level of the hidden trouble event based on the correlation value and the hidden trouble level of the hidden trouble event.

[0112] In a possible example, the obtaining unit 202 is specifically configured to obtain the historical usage record of the target application for obtaining the target data; obtain a usage information set of the target application for obtaining the target data based on the historical usage record; determine an associated application associated with the target application; separately search for basic information and event information of the target application and the associated application; and obtain a reference information set of the target application based on the basic information and the event information.

[0113] In a possible example, the obtaining unit 202 is specifically configured to determine the transmission path of the target data based on the historical usage record; and determine an associated application associated with the target application based on the transmission path.

[0114] For the detailed processes executed by each unit in the permission prompt device 200, reference may be made to the execution steps in the foregoing method embodiments, which will not be elaborated here.

[0115] Consistent with Figure 1 the embodiments of Figure 3 , Figure 3 FIG. is a schematic structural diagram of a computer device provided in an embodiment of the present application. As Figure 3 shown, the computer device 300 includes a processor 310, a memory 320, and a communication interface 330. The processor 310, the memory 320, and the communication interface 330 are interconnected with each other through a bus 350. Figure 2 The related functions implemented by the detection unit 201 shown in Figure 2 can be implemented through the communication interface 330, and the related functions implemented by the detection unit 201, the obtaining unit 202, the determining unit 203, and the display unit 204 shown in

[0116] can be implemented through the processor 310. The above-mentioned memory 320 stores a computer program 340, and the computer program 340 is configured to be executed by the above-mentioned processor 310. The computer program 340 includes instructions for performing the following steps:

[0117] Detect a data acquisition request of a target application, where the data acquisition request is used to acquire target data;

[0118] If the target application has the acquisition permission for the target data, obtain a usage information set of the target data and a reference information set of the target application;

[0119] Based on the reference information set and the usage information set, determine the risk level and the maximum risk event of the target application for acquiring the target data;

[0120] Display a prompt message corresponding to the risk level and the maximum risk event.

[0121] In a possible example, in determining the risk level and the maximum risk event of the target application for obtaining the target data based on the reference information set and the usage information set, the computer program 340 specifically includes instructions for performing the following steps:

[0122] Select the potential problem information of the target application from the reference information set;

[0123] Based on the usage information set, determine at least two potential problem events for the target application to obtain the target data;

[0124] Based on the potential problem information, determine the sub-risk value of the potential problem event;

[0125] Perform weighted calculation on the sub-risk value to obtain the risk level of the target application for obtaining the target data;

[0126] Use the potential problem event corresponding to the maximum value of the sub-risk value as the maximum risk event for the target application to obtain the target data.

[0127] In a possible example, in selecting the potential problem information of the target application from the reference information set, the computer program 340 specifically includes instructions for performing the following steps:

[0128] Classify the reference information in the reference information set to obtain a reference information subset corresponding to each feature dimension in at least two feature dimensions;

[0129] Based on the reference information subset corresponding to the feature dimension, determine the risk index corresponding to the feature dimension;

[0130] If the risk index corresponding to the feature dimension is greater than a preset threshold, determine the reference information subset corresponding to the feature dimension as the target information subset;

[0131] Based on the target information subset, determine the potential problem information of the target application.

[0132] In a possible example, in determining each potential problem event for the target application to obtain the target data based on the usage information set, the computer program 340 specifically includes instructions for performing the following steps:

[0133] Based on the usage information set, determine the event information of each occurrence event in at least two occurrence events for the target application to obtain the target data;

[0134] Based on the event information of the occurrence event, determine the potential problem level of the occurrence event;

[0135] Select the occurrence events with the hidden danger level greater than the preset level from the occurrence events as the hidden danger events for the target application to obtain the target data.

[0136] In a possible example, in terms of determining the sub-risk value of the hidden danger event based on the hidden danger information, the computer program 340 specifically includes instructions for performing the following steps:

[0137] Determine the correlation value between the event information of the hidden danger event and the hidden danger information;

[0138] Determine the sub-risk level of the hidden danger event based on the correlation value and the hidden danger level of the hidden danger event.

[0139] In a possible example, in terms of obtaining the usage information set for the target application to obtain the target data and the reference information set of the target application, the computer program 340 specifically includes instructions for performing the following steps:

[0140] Obtain the historical usage record of the target application to obtain the target data;

[0141] Obtain the usage information set for the target application to obtain the target data based on the historical usage record;

[0142] Determine the associated application associated with the target application;

[0143] Search for the basic information and event information of the target application and the associated application respectively;

[0144] Obtain the reference information set of the target application based on the basic information and the event information.

[0145] In a possible example, in terms of determining the associated application associated with the target application, the computer program 340 specifically includes instructions for performing the following steps:

[0146] Determine the transmission path of the target data based on the historical usage record;

[0147] Determine the associated application associated with the target application based on the transmission path.

[0148] An embodiment of the present application also provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program for storing, and the computer program enables a computer to execute to implement part or all of the steps of any method recorded in the method embodiment, and the computer includes an electronic device or a server.

[0149] An embodiment of the present application also provides a computer program product. The computer program product includes a non-transitory computer-readable storage medium storing a computer program. The computer program is operable to cause a computer to execute part or all of the steps of any method described in the method embodiments. The computer program product can be a software installation package, and the computer includes an electronic device or a server.

[0150] In the above embodiment, the computer-readable storage medium may mainly include a program storage area and a data storage area. Among them, the program storage area may store an operating system, application programs required for at least one function, etc.; the data storage area may store data created according to the use of the blockchain node, etc. For example, the usage information set of the target data, the reference information set of the target application, preset thresholds, preset levels, the historical usage records of the target data, etc. may be stored in the blockchain, which is not limited herein.

[0151] The blockchain referred to in the embodiments of the present application is a new application mode of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanism, and encryption algorithms. Blockchain, in essence, is a decentralized database, a string of data blocks generated by using cryptographic methods. Each data block contains information about a batch of network transactions, which is used to verify the validity (anti-counterfeiting) of the information and generate the next block. The blockchain may include a blockchain underlying platform, a platform product service layer, an application service layer, etc.

[0152] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present application is not limited by the described action sequence, because according to the present application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modes involved are not necessarily essential to the present application.

[0153] In the above embodiment, the descriptions of the various embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0154] In several embodiments provided by the present application, it should be understood that the disclosed device can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods. For example, at least one unit or component can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed mutual coupling or direct coupling or communication connection can be through some interfaces. The indirect coupling or communication connection of the device or unit can be in an electrical or other form.

[0155] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to at least one network unit. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0156] In addition, the functional units in each embodiment of this application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of a software program mode.

[0157] If the integrated unit is implemented in the form of a software program mode and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions for causing a computer (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in each embodiment of this application. The aforementioned memory includes: various media such as USB flash drives, read-only memory (ROM), random access memory (RAM), mobile hard disks, magnetic disks, or optical discs that can store program codes.

[0158] The above has introduced the embodiments of this application in detail. Specific examples are used in this article to elaborate on the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to this application.

Claims

1. A permission prompt method, characterized in that, it includes: Detect a data acquisition request of a target application, where the data acquisition request is used to acquire target data; If the target application has the acquisition permission for the target data, obtain the usage information set of the target data and the reference information set of the target application; Classify the reference information in the reference information set to obtain a reference information subset corresponding to each feature dimension in at least two feature dimensions; Determine the risk index corresponding to the feature dimension based on the reference information subset corresponding to the feature dimension; If the risk index corresponding to the feature dimension is greater than a preset threshold, determine the reference information subset corresponding to the feature dimension as the target information subset; Determine the potential risk information of the target application based on the target information subset; Determine at least two potential risk events for the target application to acquire the target data based on the usage information set; Determine the sub-risk value of the potential risk event based on the potential risk information; Perform weighted calculation on the sub-risk value to obtain the risk level for the target application to acquire the target data; Use the potential risk event corresponding to the maximum value of the sub-risk value as the maximum risk event for the target application to acquire the target data; Display the prompt information corresponding to the risk level and the maximum risk event.

2. The method according to claim 1, characterized in that, The determining at least two potential risk events for the target application to acquire the target data based on the usage information set includes: Determine the event information of each occurrence event in at least two occurrence events for the target application to acquire the target data based on the usage information set; Determine the potential risk level of the occurrence event based on the event information of the occurrence event; Select the occurrence events with a potential risk level greater than a preset level from the occurrence events as the potential risk events for the target application to acquire the target data.

3. The method according to claim 2, characterized in that, The determining the sub-risk value of the potential risk event based on the potential risk information includes: Determine the correlation value between the event information of the potential risk event and the potential risk information; Determine the sub-risk level of the potential risk event based on the correlation value and the potential risk level of the potential risk event.

4. The method according to any one of claims 1-3, characterized in that, The obtaining the usage information set of the target data and the reference information set of the target application includes: Obtain the historical usage record of the target data; Obtain the usage information set of the target data based on the historical usage record; Determine the associated application associated with the target application; Search for the basic information and event information of the target application and the associated application respectively; Obtain the reference information set of the target application based on the basic information and the event information.

5. The method according to claim 4, characterized in that, The determining the associated application associated with the target application includes: Determine the transmission path of the target data based on the historical usage record; Determine the associated application associated with the target application based on the transmission path.

6. A permission prompt device, characterized in that, it includes: A detection unit for detecting a data acquisition request of a target application, where the data acquisition request is used to acquire target data; An acquisition unit for acquiring a usage information set of the target data and a reference information set of the target application if the target application has the acquisition permission for the target data; A determination unit for classifying the reference information in the reference information set to obtain a reference information subset corresponding to each feature dimension in at least two feature dimensions; Determining a risk index corresponding to the feature dimension based on the reference information subset corresponding to the feature dimension; if the risk index corresponding to the feature dimension is greater than a preset threshold, determining the reference information subset corresponding to the feature dimension as a target information subset; Determining potential problem information of the target application based on the target information subset; Determining at least two potential problem events for the target application to acquire the target data based on the usage information set; Determining a sub-risk value of the potential problem event based on the potential problem information; Performing a weighted calculation on the sub-risk value to obtain a risk level for the target application to acquire the target data; Regarding the potential problem event corresponding to the maximum value of the sub-risk value as the maximum risk event for the target application to acquire the target data; A display unit for displaying a prompt message corresponding to the risk level and the maximum risk event.

7. A computer device characterized in that it includes a processor, a memory, and a communication interface, where the memory stores a computer program, the computer program is configured to be executed by the processor, and the computer program includes instructions for executing the steps in any one of the methods of claims 1-5.

8. A computer-readable storage medium characterized in that the computer-readable storage medium stores a computer program, and the computer program enables a computer to execute to implement the method described in any one of claims 1-5.

Citation Information

Patent Citations

  • Application permission processing method, terminal and server

    CN108537011A