Access control methods and devices
By dividing the permission settings interface of the terminal device into type areas and using multiple controls to control permissions, the problem of the inability to flexibly set application permissions in the existing technology is solved, and fast and flexible permission management and privacy protection are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- VIVO MOBILE COMM CO LTD
- Filing Date
- 2022-01-04
- Publication Date
- 2026-05-26
Smart Images

Figure CN114491440B_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of computer software, and specifically relates to an access control method and apparatus. Background Technology
[0002] With the increasing popularity of mobile phones and other terminal devices, mobile phones are becoming increasingly integrated into users' daily lives. More and more mobile device users are communicating and interacting through the internet, making their lives more colorful. The applications of terminal devices are also becoming more and more diversified, allowing users to browse the internet, shop, read, play games, chat, and so on via their mobile phones.
[0003] As a result, terminal devices accumulate more and more user information. However, some information on a terminal device, such as assets, chat logs, or personal interests, falls under the category of individual privacy, and users generally do not want others to see this information after the terminal device is lent out or unlocked.
[0004] Current locking solutions either control and lock permissions for the entire system or for individual applications or files. They lack the flexibility to set specific permissions for each application on the terminal, leading to inconvenience for some users and failing to meet their needs in certain scenarios. Summary of the Invention
[0005] The purpose of this application is to provide an access control method and apparatus that can solve the problem of insufficient flexibility in existing locking schemes.
[0006] In a first aspect, embodiments of this application provide an access control method, the method comprising:
[0007] If the first user's identity verification is successful, the first permission settings interface will be displayed;
[0008] Receive the first input from the first user on the first permission settings interface, and in response to the first input, determine the target visitor's usage permissions for the target application;
[0009] The first permission setting interface includes multiple first-type areas and a first control corresponding to each first-type area;
[0010] The first type of area includes an icon of at least one application and a second control corresponding to each application;
[0011] The first control is used to control the access permissions of different visitors to all applications in the first type area, and the second control is used to control the access permissions of different visitors to the applications in the first type area corresponding to the second control.
[0012] Secondly, embodiments of this application provide a terminal function authorization device, including:
[0013] The identity verification module is used to display the first permission settings interface when the first user's identity verification is successful.
[0014] The first permission determination module is used to receive the first input from the first user on the first permission setting interface, and in response to the first input, determine the target visitor's usage permission for the target application.
[0015] The first permission setting interface includes multiple first-type areas and a first control corresponding to each first-type area;
[0016] The first type of area includes an icon of at least one application and a second control corresponding to each application;
[0017] The first control is used to control the access permissions of different visitors to all applications in the first type area, and the second control is used to control the access permissions of different visitors to the applications in the first type area corresponding to the second control.
[0018] Thirdly, embodiments of this application provide an electronic device including a processor, a memory, and a program or instructions stored in the memory and executable on the processor, wherein the program or instructions, when executed by the processor, implement the steps of the method described in the first aspect.
[0019] Fourthly, embodiments of this application provide a readable storage medium on which a program or instructions are stored, which, when executed by a processor, implement the steps of the method described in the first aspect.
[0020] Fifthly, embodiments of this application provide a chip, the chip including a processor and a communication interface, the communication interface being coupled to the processor, the processor being used to run programs or instructions to implement the method as described in the first aspect.
[0021] In this embodiment, the second control is used to control the access permissions of different visitors to the applications corresponding to the second control in the first type area. The first control has an overall control effect on the applications in the area. Users can set permissions for multiple applications in one operation, which is faster and simpler. In addition, the second area controls the access permissions of each application, and users can set function authorization limits for each application, making function authorization limits more flexible. Attached Figure Description
[0022] Figure 1 This is a flowchart illustrating the access control method provided in an embodiment of this application;
[0023] Figure 2 One of the schematic diagrams of the first permission setting interface provided in the embodiments of this application;
[0024] Figure 3 A second schematic diagram of the first permission setting interface provided in an embodiment of this application;
[0025] Figure 4 A flowchart illustrating the process of determining the usage permissions of a target application, provided in an embodiment of this application;
[0026] Figure 5 A schematic diagram of the second permission setting interface provided in an embodiment of this application;
[0027] Figure 6 A schematic diagram illustrating the process of updating the target visitor's access rights to the target application, provided in an embodiment of this application;
[0028] Figure 7 This is a schematic diagram of the access control device provided in the embodiments of this application;
[0029] Figure 8 This is a schematic diagram of the structure of the electronic device provided in the embodiments of this application;
[0030] Figure 9 This is a schematic diagram of the hardware structure of the electronic device provided in the embodiments of this application. Detailed Implementation
[0031] The technical solutions of the embodiments of this application will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application are within the scope of protection of this application.
[0032] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such use of data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first," "second," etc., are generally of the same class and the number of objects is not limited; for example, a first object can be one or more. Furthermore, in the specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.
[0033] The permission control method and apparatus provided in this application will be described in detail below with reference to the accompanying drawings, through specific embodiments and application scenarios.
[0034] The access control method can be applied to a terminal, and can be executed by the terminal's hardware or software. The executing entity of this access control method can be the terminal itself, or the terminal's control device, etc.
[0035] The terminal includes, but is not limited to, mobile phones, tablets, watches, and other portable communication devices with touch-sensitive surfaces (e.g., touchscreen displays and / or touchpads). It should also be understood that, in some embodiments, the terminal may not be a portable communication device, but rather a desktop computer, smart screen, or car screen with a touch-sensitive surface (e.g., touchscreen displays and / or touchpads).
[0036] The following embodiments describe a terminal including a display and a touch-sensitive surface. However, it should be understood that the terminal may include one or more other physical user interface devices such as a touchpad, physical keyboard, mouse, and joystick.
[0037] This application provides an access control method, the executing entity of which can be a terminal, including but not limited to mobile terminals, non-mobile terminals, or terminal control devices. The following description uses a terminal as the executing entity to illustrate the access control method provided in this application.
[0038] Figure 1 This is a flowchart illustrating the access control method provided in an embodiment of this application, as shown below. Figure 1 As shown, the access control method includes steps 100 and 101.
[0039] Step 100: If the first user's identity verification is successful, the first permission settings interface will be displayed.
[0040] In this step, the terminal receives the identity verification information of the first user, which includes fingerprint information, password information, or facial information, etc. Then, it determines whether the verification passes based on the received identity verification information. For example, the received identity verification information is matched with information in the database. If the match is successful, the verification passes.
[0041] The first user is the owner of the electronic device. Understandably, the first permission settings interface is only visible to the first user.
[0042] Optionally, if the first user's identity verification is successful, and a request from the first user to perform permission settings is received, for example, if the first user clicks the system settings program icon and then clicks the permission settings icon, the first permission settings interface will be displayed.
[0043] The first permission setting interface includes multiple first-type areas and a first control corresponding to each first-type area;
[0044] The first type of area includes an icon of at least one application and a second control corresponding to each application;
[0045] The first control is used to control the access permissions of different visitors to all applications in the first type area, and the second control is used to control the access permissions of different visitors to the applications in the first type area corresponding to the second control.
[0046] Optionally, the first permission settings interface can be divided into first zones based on the type of application, and applications of the same type can be placed in the same first zone to facilitate unified permission management for applications of the same type. Each first zone has a different focus of control; for example, the first zone for financial applications focuses on assets, while the first zone for communication applications focuses on dialog boxes, and so on.
[0047] When an application enters the permission mode, it can automatically enter the corresponding area based on its type. For example, a wallet will automatically enter the financial category. The size, position, and number of items in the first area can all be adjusted based on user actions.
[0048] Figure 2 One of the schematic diagrams of the first permission setting interface provided in the embodiments of this application, such as Figure 2 As shown, the first permission settings interface is divided into four first areas according to the type of application: film and entertainment, finance, communication and public. The first control corresponding to the first area includes the plus sign icon in the upper right corner of the first area.
[0049] Figure 3 This is a second schematic diagram of the first permission setting interface provided in the embodiments of this application, as shown below. Figure 3 As shown, upon receiving a user's click on the plus icon, multiple target visitors and multiple authorized functions of all applications in the first area are displayed.
[0050] like Figure 2 As shown, the four first areas include the icon of at least one application, and the second control corresponding to the application includes the plus sign icon in the upper right corner of the application.
[0051] like Figure 3 As shown, when a user clicks the plus icon in the upper right corner of the application, multiple target visitors and multiple authorized functions of the application are displayed.
[0052] In addition, when the number of icons exceeds the number of icons that can be placed in the first area, some icons are hidden, and the hidden icons are displayed according to the received user operations, such as swipe operations and click operations.
[0053] The first control can be a master switch for permissions for all applications in the first type area. This master switch controls the permissions for all applications in the first type area, and the permissions set by this master switch apply to all applications in the first type area.
[0054] Step 101: Receive the first input from the first user on the first permission settings interface, and in response to the first input, determine the target visitor's usage permissions for the target application.
[0055] Optionally, the first permission setting interface includes a first control and a second control. Since the first control is used to control the access permissions of different visitors to all applications in the first type area, and the second control is used to control the access permissions of different visitors to the applications in the first type area corresponding to the second control, the access permissions of the target visitor to the target application can be determined based on the first input received from the first user to the first control or the second control in the first permission setting interface.
[0056] Among them, the target visitor refers to any user other than the first user who has access to the electronic device. Target visitors include limited users or visitors.
[0057] The target application refers to the application for which the first user can exercise access control.
[0058] The permission control method provided in this application embodiment includes a first permission setting interface comprising multiple first-type areas. Each first-type area includes an icon for at least one application. A first control is used to control the usage permissions of different visitors for all applications within the first-type areas. A second control is used to control the usage permissions of different visitors for the applications within the first-type areas corresponding to the second control. The first control has an overall control effect on the applications within the area. Users can set permissions for multiple applications in a single operation, making function authorization faster and simpler. In addition, the second area controls the usage permissions for each application, allowing users to set function authorization limits for each application, making function authorization limits more flexible.
[0059] Optionally, the first input includes at least one of the following:
[0060] The first operation on the first control corresponding to the first type area of the target in the first permission setting interface;
[0061] Apply the second operation of the corresponding second control to the target in the first type area of the first permission setting interface.
[0062] In one implementation, the first input is a first operation on the first control corresponding to the target first type area in the first permission setting interface.
[0063] In one implementation, the first input is a second operation on the second control corresponding to the target in the first type area of the first permission setting interface.
[0064] In one embodiment, the first input includes a first operation on a first control corresponding to a target first type area in the first permission setting interface, and a second operation on a second control corresponding to a target application in the target first type area in the first permission setting interface.
[0065] It should be noted that the authorizable functions in the first control corresponding to the first type area of the target may be the same as or different from the authorizable functions in the second control corresponding to the target application in the first type area of the target.
[0066] If the authorized functions in the first control corresponding to the first type area of the target are the same as the authorized functions in the second control corresponding to the target application in the first type area of the target, and if the first user enables the authorized functions in the first control corresponding to the first type area of the target through the first operation or the authorized functions in the first control corresponding to the first type area of the target are in the default enabled state, then the authorized functions in the second control corresponding to the target application in the first type area of the target are enabled by default. The first user can adjust the enabled state to the disabled state through the second operation.
[0067] If the first user disables the authorizable function in the first control corresponding to the first type area of the target through the first operation, or if the authorizable function in the first control corresponding to the first type area of the target is in the default disabled state, then the authorizable function in the second control corresponding to the target application in the target first type area is in the disabled state by default.
[0068] For example, the authorized functions in the first control corresponding to the first type area of the target are the same as the authorized functions in the second control corresponding to the target application in the first type area of the target, both including click, long press, login, uninstall, and share. If the first user closes the uninstall permission for user A in the first control corresponding to the first type area of the target through the first operation, the uninstall permission for user A in the second controls corresponding to all applications in the first type area of the target will be closed.
[0069] If the authorizable functions in the first control corresponding to the target first type area are different from the authorizable functions in the second control corresponding to the target application in the target first type area, for the overlapping parts of the authorizable functions in the first control and the second control, if the authorizable function in the first control corresponding to the target first type area is enabled, then the authorizable function in the second control corresponding to the target application in the target first type area is enabled by default, and the first user can adjust the enabled state to be disabled through the first input; if the authorizable function in the first control corresponding to the target first type area is disabled, then the authorizable function in the second control corresponding to the target application in the target first type area is disabled by default. For the non-overlapping parts of the authorizable functions in the first control and the second control, the state of the authorizable function in the second control is not affected by the state of the authorizable function in the first control.
[0070] The permission control method provided in this application embodiment includes at least one of a first operation on a first control and a second operation on a second control as the first input. Compared with the method that requires both a first operation on the first control and a second operation on the second control, the permission setting method in this application embodiment is more flexible.
[0071] Optionally, in response to the first input, determining the target visitor's access rights to the target application includes one of the following:
[0072] In response to the first operation, the first access permission of the target visitor to all applications in the target first type area is determined, and the access permission of the target visitor to the target application is determined based on the first access permission.
[0073] In response to the second operation, a second access permission of the target visitor to the target application in the target first type area is determined, and the access permission of the target visitor to the target application is determined based on the second access permission;
[0074] In response to the first operation, a first access permission of the target visitor to all applications in the target first type area is determined; in response to the second operation, a second access permission of the target visitor to the target application in the target first type area is determined; and based on the first and second access permissions, the access permission of the target visitor to the target application is determined.
[0075] Optionally, the first input received by the terminal may have three possibilities: the first input includes only the first operation, the first input includes only the second operation, or the first input includes both the first and second operations.
[0076] In the first scenario, the terminal receives a first operation from the first user on a first control corresponding to a target first type area in the first permission settings interface. This first operation may be a disabling or enabling operation of an authorized function within the target first type area. In response to the first operation, the terminal determines the target visitor's first usage permission for all applications in the target first type area. Based on the first usage permission, the terminal determines the target visitor's usage permission for the target application, or based on the first usage permission and a default second usage permission.
[0077] In the second scenario, the terminal receives a second operation from the first user on the second control corresponding to the target application in the first type area of the first permission settings interface. This second operation may be a disabling or enabling operation of the authorized functions of the target application. In response to the second operation, the terminal determines the target visitor's second usage permission for the target application in the first type area. The target visitor's usage permission for the target application is determined based on the second usage permission, or the target visitor's usage permission for the target application is determined based on the second usage permission and the default first usage permission.
[0078] In the third scenario, the terminal receives a first operation from the first user on a first control corresponding to a target first type area in the first permission settings interface. This first operation may be a disabling or enabling operation of the authorizable functions within the target first type area. In response to the first operation, the terminal determines the target visitor's first usage permission for all applications in the target first type area. The terminal then receives a second operation from the first user on a second control corresponding to a target application in the target first type area of the first permission settings interface. This second operation may be a disabling or enabling operation of the authorizable functions of the target application. In response to the second operation, the terminal determines the target visitor's second usage permission for the target application in the target first type area. Based on the first and second usage permissions, the terminal determines the target visitor's usage permission for the target application.
[0079] Optionally, if there is a conflict between the first and second usage permissions, the most recently set permission between the first and second usage permissions can be taken as the target visitor's usage permission for the target application. For example, if a first user first disables user A's payment permission for all applications in the first type area of the financial category, and then enables user A's payment permission for the first application in the first type area, then the most recently set permission between the first and second usage permissions will be taken as the target visitor's usage permission for the target application, meaning user A has payment permission for the first application.
[0080] The permission control method provided in this application determines the access permission of a target visitor to the target application based on at least one of a first access permission and a second access permission. Compared with the method that can only determine the access permission of a target visitor to the target application based on the first access permission and the second access permission, the permission determination method in this application is more flexible.
[0081] Optionally, the access control method further includes:
[0082] If the target visitor's identity is successfully verified, the display method of all applications on the desktop is adjusted according to the target visitor's usage permissions for all applications.
[0083] Optionally, the target visitors include restricted users and visitors. The terminal receives the identity verification information of the restricted users from the first user, such as fingerprints, passwords, or facial information of each restricted user. The entered identity verification information of the restricted users is stored in the terminal's local memory or in an identity database in the cloud. When the terminal receives the identity verification information input by the user, it compares the identity verification information with the information in the identity database to determine whether the identity recognition of the target visitor is successful. If no identity verification information is input or the input identity verification information does not match the restricted users in the identity database, the user's identity is determined to be a visitor.
[0084] Based on the target visitor's permissions for all applications, determine whether to display the icons of each application. For example, if the target visitor has all permissions for a certain application disabled, the icon of that application will not be displayed. Adjust the display method of all applications on the desktop according to the icons of the applications that are displayed and the number of applications that are displayed.
[0085] The permission control method provided in this application adjusts the display method of all applications on the desktop according to the target visitor's usage permissions for all applications. Compared with directly displaying all applications without considering the target visitor's usage permissions, it saves more desktop space and does not show icons of unusable applications to the visitor, thus improving security.
[0086] Optionally, the permission control method provided in this application embodiment further includes setting permissions for target visitors to use certain functions, icons, or operations of the target application. Figure 4 The flowchart illustrating the process for determining the usage permissions of the target application provided in this application is as follows: Figure 4 As shown, determining the usage permissions of the target application includes the following steps:
[0087] Step 400: Receive the second input from the first user regarding the target application in the first type area of the target, and in response to the second input, display the second permission settings interface.
[0088] The second permission setting interface includes multiple second-type areas and a third control corresponding to each second-type area;
[0089] The second type of area includes an icon for at least one functional item and a fourth control corresponding to each functional item;
[0090] The third control is used to control the access permissions of different visitors to all functional items in the second type area, and the fourth control is used to control the access permissions of different visitors to the corresponding functional items in the second type area.
[0091] The third control can serve as a master switch for all functional items in the second type area. This master switch controls the permissions of all functional items in the second type area, and the permissions set by this master switch apply to all functional items in the second type area.
[0092] Optionally, the second input is a click operation by the first user on the target application within the first type area. In response to the second input, a second permission setting interface is displayed. The second permission setting interface is derived from the internal interface of the target application, including the main interface and various sub-interfaces of the target application. A second type area is formed on the internal interface of the application, and the size of the second type area is adjustable.
[0093] Functional items refer to icons, functions, or operations in the second type area. The icons, functions, and operation permissions in the second type area are broken down, such as click, long press, pull up and down, swipe up, down, left and right, copy, forward, delete, etc., to form the icon of the functional item. It should be noted that the icon of the functional item can be an icon on the internal interface of the target application, or it can be an icon generated based on the icons, functions, and operation permissions in the second type area.
[0094] Figure 5 A schematic diagram of the second permission setting interface provided in the embodiments of this application, as shown below. Figure 5 As shown, the second permission settings interface includes icons for camera function items, input box function items, and sent message function items, etc.
[0095] The fourth control corresponding to the icon of the sent message function item is used to control the access permissions of different visitors to the corresponding function items in the second type area, including click permission, copy permission, quote permission, recall permission, and delete permission, etc.
[0096] Step 401: Receive the third input from the first user to the second permission settings interface, and in response to the third input, determine the target visitor's access permission to the target function item in the target application.
[0097] Optionally, the second permission setting interface includes a third control and a fourth control. The third control is used to control the access permissions of different visitors to all functional items in the second type area, and the fourth control is used to control the access permissions of different visitors to the corresponding functional items in the second type area. Therefore, based on the third input received from the first user to the third control or the fourth control in the second permission setting interface, the access permissions of the target visitor to the target functional items in the target application can be determined.
[0098] For example, in unrestricted use, long-pressing on a WeChat chat window can delete the chat window. The first user can restrict the target visitor's long-press operation. In the third control corresponding to the second area where the chat window is located, if the long-press permission of user B is disabled, user B cannot delete the chat window. In unrestricted use, pulling down on the WeChat main page will display recently used mini programs. The first user can also restrict the pull-down operation or restrict the display of the usage history after pulling down.
[0099] The permission control method provided in this application embodiment includes a second permission setting interface comprising multiple second-type areas, each second-type area including an icon for at least one functional item. A third control is used to control the access permissions of different visitors to all functional items in the second-type areas, and a fourth control is used to control the access permissions of different visitors to the corresponding functional items in the second-type areas. Corresponding to the internal functions, the method decomposes and authorizes them, enabling the first user to flexibly manage the functional permissions of local areas of the application, further improving the flexibility of authorization and restriction.
[0100] Optionally, the third input includes at least one of the following:
[0101] The third operation on the third control corresponding to the target second type area in the second permission setting interface;
[0102] The fourth operation of the fourth control corresponding to the target function item in the second type area of the second permission setting interface.
[0103] In one implementation, the third input is a third operation on the third control corresponding to the target second type area in the second permission setting interface.
[0104] In one implementation, the third input is a fourth operation on the fourth control corresponding to the target function item in the target second type area of the second permission setting interface.
[0105] In one embodiment, the third input is a third operation on a third control corresponding to a target second type area in the second permission setting interface, and a fourth operation on a fourth control corresponding to a target function item in the target second type area in the second permission setting interface.
[0106] It should be noted that the authorizable functions in the third control corresponding to the target second type area may be the same as or different from the authorizable functions in the fourth control corresponding to the target function item in the target second type area.
[0107] If the authorizable function in the third control corresponding to the target second type area is the same as the authorizable function in the fourth control corresponding to the target function item in the target second type area, and the user enables the authorizable function in the third control corresponding to the target second type area through a third operation or the authorizable function in the third control corresponding to the target second type area is in the default enabled state, then the authorizable function in the fourth control corresponding to the target function item in the target second type area is enabled by default, and the first user can change the enabled state to disabled state through a fourth operation; if the user disables the authorizable function in the third control corresponding to the target second type area through a third operation or the authorizable function in the third control corresponding to the target second type area is in the default disabled state, then the authorizable function in the fourth control corresponding to the target function item in the target second type area is disabled by default.
[0108] If the authorizable functions in the third control corresponding to the target second type area are different from the authorizable functions in the fourth control corresponding to the target function item in the target second type area, for the overlapping parts of the authorizable functions in the third control and the fourth control, if the authorizable function in the third control corresponding to the target second type area is enabled, then the corresponding authorizable function in the fourth control corresponding to the target function item in the target second type area is enabled by default, and the first user can adjust the enabled state to the disabled state through the third input; if the authorizable function in the third control corresponding to the target second type area is disabled, then the corresponding authorizable function in the fourth control corresponding to the target function item in the target second type area is disabled by default, and the first user can adjust the disabled state to the enabled state through the third input; for the non-overlapping parts of the authorizable functions in the third control and the fourth control, the state of the authorizable function in the fourth control is not affected by the state of the authorizable function in the third control.
[0109] The permission control method provided in this application embodiment includes at least one of a third operation on a third control and a fourth operation on a fourth control as the second input. Compared with the method that requires a third operation on the third control and a fourth operation on the fourth control, the permission setting method in this application embodiment is more flexible.
[0110] Optionally, in response to the third input, determining the target visitor's access rights to the target functional item in the target application includes one of the following:
[0111] In response to the third operation, a third access permission of the target visitor to all functional items in the target second type area is determined, and based on the third access permission, the access permission of the target visitor to the target functional items in the target application is determined;
[0112] In response to the fourth operation, a fourth access permission of the target visitor to the target functional item in the target second type area is determined, and based on the fourth access permission, the access permission of the target visitor to the target functional item in the target application is determined.
[0113] In response to the third operation, a third access permission for the target visitor to all functional items in the target second type area is determined. In response to the fourth operation, a fourth access permission for the target visitor to the target functional items in the target second type area is determined. Based on the third and fourth access permissions, the target visitor's access permission to the target functional items is determined.
[0114] Optionally, the third input received by the terminal may have three cases: the third input only includes the third operation, the third input only includes the fourth operation, and the third input includes both the third and fourth operations.
[0115] In the first scenario, the terminal receives a third operation from the first user on a third control corresponding to a target second-type area in the second permission settings interface. This third operation can be a closing or opening operation of the authorizable functions within the target second-type area. In response to the third operation, the terminal determines the target visitor's third access permission for all functional items in the target second-type area. Based on the third access permission, the terminal determines the target visitor's access permission for the target functional items in the target application. Alternatively, based on the third access permission and a default fourth access permission, the terminal determines the target visitor's access permission for the target functional items in the target application.
[0116] In the second scenario, the terminal receives a fourth operation from the first user on the fourth control corresponding to the target function item in the target second type area of the second permission setting interface. This fourth operation may be a deactivation or activation of the authorizable function of the target function item in the target second type area. In response to the fourth operation, the terminal determines the target visitor's fourth usage permission for the target function item. Based on the fourth usage permission, the terminal determines the target visitor's usage permission for the target function item in the target application. Alternatively, based on the fourth usage permission and the default third usage permission, the terminal determines the target visitor's usage permission for the target function item in the target application.
[0117] In the third scenario, the terminal receives a third operation from the first user on a third control corresponding to the target second-type area in the second permission settings interface. This third operation can be a deactivation or activation of an authorized function within the target second-type area. In response to the third operation, the terminal determines the target visitor's third access permission for all functional items in the target second-type area. The terminal also receives a fourth operation from the first user on a fourth control corresponding to the target functional item in the target second-type area of the second permission settings interface. This fourth operation can be a deactivation or activation of an authorized function for the target functional item in the target second-type area. In response to the fourth operation, the terminal determines the target visitor's fourth access permission for the target functional item. Based on the third and fourth access permissions, the terminal determines the target visitor's access permission for the target functional item. Optionally, if there is a conflict between the third and fourth access permissions, the most recently set permission between the third and fourth access permissions can be used as the target visitor's access permission for the target functional item.
[0118] The permission control method provided in this application determines the access permission of a target visitor to a target function item based on at least one of the third and fourth access permissions. Compared with the method that can only determine the access permission of a target visitor to a target function item based on the third and fourth access permissions, the permission determination method in this application is more flexible.
[0119] Optionally, the access control method further includes:
[0120] When the target visitor uses the target application, the layout of all functional items in the display interface of the target application is adjusted according to the target visitor's usage permissions for all functional items in the target application.
[0121] Optionally, if the target visitor's identity is successfully verified, an icon of the application visible to the target visitor is displayed on the desktop. If the target visitor uses the target application, for example, if the target visitor clicks on the target application, the internal interface of the target application is displayed. Since the target visitor may not have full access permissions to the target application, the layout of all functional items in the target application's display interface needs to be adjusted according to the target visitor's access permissions to all functional items in the target application before displaying them.
[0122] When the display area spans a certain distance, adjust the layout display method. For example, if there are ten dialog boxes in a chat application, and the first and fifth dialog boxes are authorized to be visible to the target visitor, then the positions of the dialog boxes need to be adjusted so that the two dialog boxes are adjacent.
[0123] In addition, application functions require clicking through layers of operations. Target visitors can log in to use the functions of the next level, but the previous level already contains private content. Therefore, it is necessary to adjust the display of the application function interface hierarchy. For example, the interface hierarchy in the target application is: Payment → Wallet → Help Center. Target visitors can use the Help Center, but at the "Wallet" level, the balance of funds has been exposed. In this case, the application function interface hierarchy should be adjusted to Payment → Help Center.
[0124] The permission control method provided in this application adjusts the layout of all functional items in the display interface of the target application when the target visitor uses the target application, so as to prevent the leakage of privacy information and make the displayed interface more beautiful.
[0125] Optionally, the access control method further includes updating the target visitor's usage permissions for the target application. Figure 6 The flowchart illustrating the process of updating the target visitor's access rights to the target application provided in this application is as follows: Figure 6 As shown, updating the target visitor's usage permissions for the target application includes the following steps:
[0126] Step 600: Receive the fourth input from the first user to move the target application in the source first type region to the destination first type region.
[0127] Optionally, the first user moves the target application from the source first type area to the destination first type area via the fourth input. For example, the first user drags the target application from the source first type area to the destination first type area, or adds the target application to the corresponding control in the destination first type area.
[0128] Step 601: In response to the fourth input, update the target visitor's usage permissions for the target application based on the target visitor's usage permissions for the target application and the target visitor's usage permissions for all applications in the first type of target area.
[0129] Optionally, in response to the fourth input, the target visitor's usage permissions for the target application and the target visitor's usage permissions for all applications in the first type of target area are superimposed, and the target visitor's usage permissions for the target application are updated.
[0130] Optionally, the first user can set new permissions for the target visitor's access to the target application in the first type area of the destination.
[0131] The permission control method provided in this application update the access permissions of the target user for the target application based on the fourth input of the user moving the target application from the source first type area to the destination first type area. This allows the access permissions of the target application to be quickly superimposed, improving the flexibility and efficiency of permission control.
[0132] It should be noted that the execution entity of the access control method provided in this application embodiment can be an access control device, or a control unit in the access control device for executing the access control method. This application embodiment uses the execution of the access control method by an access control device as an example to illustrate the access control device provided in this application embodiment.
[0133] Figure 7 This is a schematic diagram of the access control device provided in the embodiments of this application, such as... Figure 7 As shown, the access control device includes: an identity verification module 710 and a first access determination module 720.
[0134] The identity verification module 710 is used to display the first permission settings interface when the identity verification of the first user is successful.
[0135] The first permission determination module 720 is used to receive the first input from the first user to the first permission setting interface, and in response to the first input, determine the target visitor's usage permission for the target application.
[0136] The first permission setting interface includes multiple first-type areas and a first control corresponding to each first-type area;
[0137] The first type of area includes an icon of at least one application and a second control corresponding to each application;
[0138] The first control is used to control the access permissions of different visitors to all applications in the first type area, and the second control is used to control the access permissions of different visitors to the applications in the first type area corresponding to the second control.
[0139] Optionally, the first input includes at least one of the following:
[0140] The first operation on the first control corresponding to the first type area of the target in the first permission setting interface;
[0141] Apply the second operation of the corresponding second control to the target in the first type area of the first permission setting interface.
[0142] Optionally, in response to the first input, determining the target visitor's access rights to the target application includes one of the following:
[0143] In response to the first operation, the first access permission of the target visitor to all applications in the target first type area is determined, and the access permission of the target visitor to the target application is determined based on the first access permission.
[0144] In response to the second operation, a second access permission of the target visitor to the target application in the target first type area is determined, and the access permission of the target visitor to the target application is determined based on the second access permission;
[0145] In response to the first operation, a first access permission of the target visitor to all applications in the target first type area is determined; in response to the second operation, a second access permission of the target visitor to the target application in the target first type area is determined; and based on the first and second access permissions, the access permission of the target visitor to the target application is determined.
[0146] Optionally, the access control device further includes:
[0147] The first display module is configured to receive a second input from the first user to a target application in a first type area of the target, and in response to the second input, display a second permission setting interface;
[0148] The second permission determination module is used to receive the third input from the first user on the second permission setting interface, and in response to the third input, determine the target visitor's permission to use the target function item in the target application;
[0149] The second permission setting interface includes multiple second-type areas and a third control corresponding to each second-type area;
[0150] The second type of area includes an icon for at least one functional item and a fourth control corresponding to each functional item;
[0151] The third control is used to control the access permissions of different visitors to all functional items in the second type area, and the fourth control is used to control the access permissions of different visitors to the corresponding functional items in the second type area.
[0152] Optionally, the third input includes at least one of the following:
[0153] The third operation on the third control corresponding to the target second type area in the second permission setting interface;
[0154] The fourth operation of the fourth control corresponding to the target function item in the second type area of the second permission setting interface.
[0155] Optionally, in response to the third input, determining the target visitor's access rights to the target functional item in the target application includes one of the following:
[0156] In response to the third operation, a third access permission of the target visitor to all functional items in the target second type area is determined, and based on the third access permission, the access permission of the target visitor to the target functional items in the target application is determined;
[0157] In response to the fourth operation, a fourth access permission of the target visitor to the target functional item in the target second type area is determined, and based on the fourth access permission, the access permission of the target visitor to the target functional item in the target application is determined.
[0158] In response to the third operation, a third access permission for the target visitor to all functional items in the target second type area is determined. In response to the fourth operation, a fourth access permission for the target visitor to the target functional items in the target second type area is determined. Based on the third and fourth access permissions, the target visitor's access permission to the target functional items is determined.
[0159] Optionally, the access control device further includes:
[0160] The second display module is used to adjust the display mode of all applications on the desktop according to the target visitor's usage permissions for all applications, once the target visitor's identity is successfully identified.
[0161] Optionally, the access control device further includes:
[0162] The third display module is used to adjust the layout of all functional items in the display interface of the target application according to the target visitor's usage permissions for all functional items in the target application when the target visitor uses the target application.
[0163] Optionally, the access control device further includes:
[0164] The receiving module is configured to receive a fourth input from the first user, indicating that the target application in the source first type region is moved to the destination first type region;
[0165] The permission update module is used to update the target visitor's usage permissions for the target application in response to the fourth input, based on the target visitor's usage permissions for the target application and the target visitor's usage permissions for all applications in the first type of target area.
[0166] The access control device in this application embodiment can be a device, or a component, integrated circuit, or chip in a terminal. The device can be a mobile electronic device or a non-mobile electronic device. For example, mobile electronic devices can be mobile phones, tablets, laptops, PDAs, in-vehicle electronic devices, wearable devices, ultra-mobile personal computers (UMPCs), netbooks, or personal digital assistants (PDAs), etc., while non-mobile electronic devices can be servers, network-attached storage (NAS), personal computers (PCs), televisions (TVs), ATMs, or self-service machines, etc. This application embodiment does not impose specific limitations.
[0167] The access control device in this application embodiment can be a device with an operating system. This operating system can be Android, iOS, or other possible operating systems; this application embodiment does not specifically limit it.
[0168] The access control device provided in this application embodiment can achieve... Figures 1 to 6 The various processes implemented in the method implementation examples will not be described again here to avoid repetition.
[0169] Optionally, such as Figure 8As shown, this application embodiment also provides an electronic device 800, including a processor 801, a memory 802, and a program or instructions stored in the memory 802 and executable on the processor 801. When the program or instructions are executed by the processor 801, they implement the various processes of the above-described permission control method embodiment and achieve the same technical effect. To avoid repetition, they will not be described again here.
[0170] It should be noted that the electronic devices in the embodiments of this application include the mobile electronic devices and non-mobile electronic devices described above.
[0171] Figure 9 A schematic diagram of the hardware structure of an electronic device to implement an embodiment of this application.
[0172] The electronic device 900 includes, but is not limited to, components such as: radio frequency unit 901, network unit 902, audio output unit 903, input unit 904, sensor 905, display unit 906, user input unit 907, interface unit 908, memory 909, and processor 910.
[0173] Those skilled in the art will understand that the electronic device 900 may also include a power supply (such as a battery) for supplying power to various components. The power supply may be logically connected to the processor 910 through a power management system, thereby enabling functions such as managing charging, discharging, and power consumption through the power management system. Figure 9 The electronic device structure shown does not constitute a limitation on the electronic device. The electronic device may include more or fewer components than shown, or combine certain components, or have different component arrangements, which will not be elaborated here.
[0174] The processor 910 is used to display the first permission settings interface when the first user's identity verification is successful.
[0175] The user input unit 907 is used to receive the first input from the first user to the first permission setting interface, and the processor 910 is further used to: in response to the first input, determine the target visitor's usage permission for the target application;
[0176] The first permission setting interface includes multiple first-type areas and a first control corresponding to each first-type area;
[0177] The first type of area includes an icon of at least one application and a second control corresponding to each application;
[0178] The first control is used to control the access permissions of different visitors to all applications in the first type area, and the second control is used to control the access permissions of different visitors to the applications in the first type area corresponding to the second control.
[0179] In this embodiment, the first permission setting interface includes multiple first-type areas, each including an icon of at least one application. A first control controls the access permissions of different visitors to all applications within the first-type areas, and a second control controls the access permissions of different visitors to the applications within the first-type areas corresponding to the second control. The first control has an overall control effect on the applications within the area, allowing users to set permissions for multiple applications in a single operation, making function authorization faster and simpler. Furthermore, the second area controls the access permissions for each application, allowing users to set function authorization limits for each application, making function authorization limits more flexible.
[0180] Optionally, the first input includes at least one of the following:
[0181] The first operation on the first control corresponding to the first type area of the target in the first permission setting interface;
[0182] Apply the second operation of the corresponding second control to the target in the first type area of the first permission setting interface.
[0183] In this embodiment, the first input includes at least one of a first operation on the first control and a second operation on the second control. Compared to requiring a first operation on the first control and a second operation on the second control, the permission setting method in this embodiment is more flexible.
[0184] Optionally, in response to the first input, determining the target visitor's access rights to the target application includes one of the following:
[0185] In response to the first operation, the first access permission of the target visitor to all applications in the target first type area is determined, and the access permission of the target visitor to the target application is determined based on the first access permission.
[0186] In response to the second operation, a second access permission of the target visitor to the target application in the target first type area is determined, and the access permission of the target visitor to the target application is determined based on the second access permission;
[0187] In response to the first operation, a first access permission of the target visitor to all applications in the target first type area is determined; in response to the second operation, a second access permission of the target visitor to the target application in the target first type area is determined; and based on the first and second access permissions, the access permission of the target visitor to the target application is determined.
[0188] In this embodiment of the application, the user's access rights to the target application are determined based on at least one of the first access rights and the second access rights. Compared with the method that can only determine the user's access rights to the target application based on the first access rights and the second access rights, the access rights determination method in this embodiment of the application is more flexible.
[0189] Optionally, the user input unit 907 is further configured to: receive a second input from the first user to a target application in the first type area of the target, and the processor 910 is further configured to: display a second permission setting interface in response to the second input;
[0190] The user input unit 907 is further configured to: receive a third input from the first user to the second permission setting interface, and the processor 910 is further configured to: in response to the third input, determine the target visitor's permission to use the target function item in the target application;
[0191] The second permission setting interface includes multiple second-type areas and a third control corresponding to each second-type area;
[0192] The second type of area includes an icon for at least one functional item and a fourth control corresponding to each functional item;
[0193] The third control is used to control the access permissions of different visitors to all functional items in the second type area, and the fourth control is used to control the access permissions of different visitors to the corresponding functional items in the second type area.
[0194] In this embodiment, the second permission setting interface includes multiple second-type areas, each including an icon for at least one functional item. A third control controls the access permissions of different users to all functional items in the second-type areas, and a fourth control controls the access permissions of different users to the corresponding functional items in the second-type areas. This decomposes and authorizes the internal functions, allowing the first user to flexibly manage the functional permissions of local areas of the application, further improving the flexibility of authorization and restriction.
[0195] Optionally, the third input includes at least one of the following:
[0196] The third operation on the third control corresponding to the target second type area in the second permission setting interface;
[0197] The fourth operation of the fourth control corresponding to the target function item in the second type area of the second permission setting interface.
[0198] In this embodiment, the second input includes at least one of a third operation on the third control and a fourth operation on the fourth control. Compared to requiring a third operation on the third control and a fourth operation on the fourth control, the permission setting method in this embodiment is more flexible.
[0199] Optionally, in response to the third input, determining the target visitor's access rights to the target functional item in the target application includes one of the following:
[0200] In response to the third operation, a third access permission of the target visitor to all functional items in the target second type area is determined, and based on the third access permission, the access permission of the target visitor to the target functional items in the target application is determined;
[0201] In response to the fourth operation, a fourth access permission of the target visitor to the target functional item in the target second type area is determined, and based on the fourth access permission, the access permission of the target visitor to the target functional item in the target application is determined.
[0202] In response to the third operation, a third access permission for the target visitor to all functional items in the target second type area is determined. In response to the fourth operation, a fourth access permission for the target visitor to the target functional items in the target second type area is determined. Based on the third and fourth access permissions, the target visitor's access permission to the target functional items is determined.
[0203] In this embodiment, the access rights of the target visitor to the target function item are determined based on at least one of the third access rights and the fourth access rights. Compared with the access rights of the target visitor to the target function item can only be determined based on the third access rights and the fourth access rights, the access rights determination method in this embodiment is more flexible.
[0204] Optionally, the processor 910 is further configured to, upon successful identification of the target visitor, adjust the display mode of all applications on the desktop according to the target visitor's usage permissions for all applications.
[0205] Based on the target visitor's usage permissions for all applications, the display method of all applications on the desktop is adjusted. Compared with directly displaying all applications without considering the target visitor's usage permissions, this saves more desktop space and does not show the visitor the icons of unusable applications, thus improving security.
[0206] Optionally, the processor 910 is further configured to: when the target visitor uses the target application, adjust the layout of all functional items in the display interface of the target application according to the target visitor's usage permissions for all functional items in the target application.
[0207] When a target user uses the target application, the layout of all functional items in the target application's display interface is adjusted to prevent the leakage of privacy information and to make the displayed interface more aesthetically pleasing.
[0208] Optionally, the user input unit 907 is further configured to: receive a fourth input from the first user to move a target application in a source first type region to a destination first type region;
[0209] Processor 910 is further configured to: in response to the fourth input, update the target visitor's access rights to the target application based on the target visitor's access rights to the target application and the target visitor's access rights to all applications in the first type of destination area.
[0210] In this embodiment of the application, the user's access rights to the target application are updated based on the fourth input that the user moves the target application from the source first type area to the destination first type area. This allows the access rights of the target application to be quickly superimposed, improving the flexibility and efficiency of access control.
[0211] It should be understood that, in this embodiment, the input unit 904 may include a graphics processing unit (GPU) 9041 and a microphone 9042. The GPU 9041 processes image data of still images or videos obtained by an image capture device (such as a camera) in video capture mode or image capture mode. The display unit 906 may include a display panel 9061, which may be configured in the form of a liquid crystal display, an organic light-emitting diode, etc. The user input unit 907 includes a touch panel 9071 and other input devices 9072. The touch panel 9071 is also called a touch screen. The touch panel 9071 may include a touch detection device and a touch controller. Other input devices 9072 may include, but are not limited to, physical keyboards, function keys (such as volume control buttons, power buttons, etc.), trackballs, mice, joysticks, etc., which will not be described in detail here. The memory 909 can be used to store software programs and various data, including but not limited to applications and operating systems. The processor 910 may integrate an application processor and a modem processor, wherein the application processor mainly handles the operating system, user interface, and applications, and the modem processor mainly handles wireless communication. It is understandable that the aforementioned modem processor may not be integrated into the processor 910.
[0212] This application also provides a readable storage medium storing a program or instructions. When the program or instructions are executed by a processor, they implement the various processes of the above-described permission control method embodiments and achieve the same technical effect. To avoid repetition, they will not be described again here.
[0213] The processor is the processor in the electronic device described in the above embodiments. The readable storage medium includes computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk.
[0214] This application embodiment also provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement the various processes of the above-described permission control method embodiments and can achieve the same technical effect. To avoid repetition, it will not be described again here.
[0215] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.
[0216] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element. Furthermore, it should be noted that the scope of the methods and apparatuses in the embodiments of this application is not limited to performing functions in the order shown or discussed, but may also include performing functions substantially simultaneously or in the reverse order, depending on the functions involved. For example, the described methods may be performed in a different order than described, and various steps may be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.
[0217] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a computer software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of this application.
[0218] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of this application.
Claims
1. A method of controlling rights, characterized by, include: If the first user's identity verification is successful, the first permission settings interface will be displayed; Receive the first input from the first user on the first permission settings interface, and in response to the first input, determine the target visitor's usage permissions for the target application; The first permission setting interface includes multiple first-type areas and a first control corresponding to each first-type area; The first type of area includes an icon of at least one application and a second control corresponding to each application; The first control is used to control the access permissions of different visitors to all applications in the first type area, and the second control is used to control the access permissions of different visitors to the applications in the first type area corresponding to the second control. The method further includes: Receive the second input from the first user regarding the target application in the first type of target area, and display the second permission settings interface in response to the second input; Receive the third input from the first user on the second permission settings interface, and in response to the third input, determine the target visitor's access permission to the target function item in the target application; The second permission setting interface includes multiple second-type areas and a third control corresponding to each second-type area; The second type of area includes an icon for at least one functional item and a fourth control corresponding to each functional item; The third control is used to control the access permissions of different visitors to all functional items in the second type area, and the fourth control is used to control the access permissions of different visitors to the corresponding functional items in the second type area.
2. The rights control method according to claim 1, characterized by, The first input includes at least one of the following: The first operation on the first control corresponding to the first type area of the target in the first permission setting interface; Apply the second operation of the corresponding second control to the target in the first type area of the first permission setting interface.
3. The rights control method according to claim 2, characterized by, The response to the first input, determining the target visitor's access rights to the target application, includes one of the following: In response to the first operation, the first access permission of the target visitor to all applications in the target first type area is determined, and the access permission of the target visitor to the target application is determined based on the first access permission. In response to the second operation, a second access permission of the target visitor to the target application in the target first type area is determined, and the access permission of the target visitor to the target application is determined based on the second access permission; In response to the first operation, a first access permission of the target visitor to all applications in the target first type area is determined; in response to the second operation, a second access permission of the target visitor to the target application in the target first type area is determined; and based on the first and second access permissions, the access permission of the target visitor to the target application is determined.
4. The access control method according to claim 1, characterized in that, The third input includes at least one of the following: The third operation on the third control corresponding to the target second type area in the second permission setting interface; The fourth operation on the fourth control corresponding to the target function item in the second type area of the second permission setting interface; The response to the third input determines the target visitor's access rights to the target functional item in the target application, including one of the following: In response to the third operation, a third access permission of the target visitor to all functional items in the target second type area is determined, and based on the third access permission, the access permission of the target visitor to the target functional items in the target application is determined; In response to the fourth operation, a fourth access permission of the target visitor to the target functional item in the target second type area is determined, and based on the fourth access permission, the access permission of the target visitor to the target functional item in the target application is determined. In response to the third operation, a third access permission for the target visitor to all functional items in the target second type area is determined. In response to the fourth operation, a fourth access permission for the target visitor to the target functional items in the target second type area is determined. Based on the third and fourth access permissions, the target visitor's access permission to the target functional items is determined.
5. An access control device, characterized in that, include: The identity verification module is used to display the first permission settings interface when the first user's identity verification is successful. The first permission determination module is used to receive the first input from the first user on the first permission setting interface, and in response to the first input, determine the target visitor's usage permission for the target application. The first permission setting interface includes multiple first-type areas and a first control corresponding to each first-type area; The first type of area includes an icon of at least one application and a second control corresponding to each application; The first control is used to control the access permissions of different visitors to all applications in the first type area, and the second control is used to control the access permissions of different visitors to the applications in the first type area corresponding to the second control. The first display module is configured to receive a second input from the first user to a target application in a first type area of the target, and in response to the second input, display a second permission setting interface; The second permission determination module is used to receive the third input from the first user on the second permission setting interface, and in response to the third input, determine the target visitor's permission to use the target function item in the target application; The second permission setting interface includes multiple second-type areas and a third control corresponding to each second-type area; The second type of area includes an icon for at least one functional item and a fourth control corresponding to each functional item; The third control is used to control the access permissions of different visitors to all functional items in the second type area, and the fourth control is used to control the access permissions of different visitors to the corresponding functional items in the second type area.
6. The access control device according to claim 5, characterized in that, The first input includes at least one of the following: The first operation on the first control corresponding to the first type area of the target in the first permission setting interface; Apply the second operation of the corresponding second control to the target in the first type area of the first permission setting interface.
7. The access control device according to claim 6, characterized in that, The response to the first input, determining the target visitor's access rights to the target application, includes one of the following: In response to the first operation, the first access permission of the target visitor to all applications in the target first type area is determined, and the access permission of the target visitor to the target application is determined based on the first access permission. In response to the second operation, a second access permission of the target visitor to the target application in the target first type area is determined, and the access permission of the target visitor to the target application is determined based on the second access permission; In response to the first operation, a first access permission of the target visitor to all applications in the target first type area is determined; in response to the second operation, a second access permission of the target visitor to the target application in the target first type area is determined; and based on the first and second access permissions, the access permission of the target visitor to the target application is determined.
8. The access control device according to claim 5, characterized in that, The third input includes at least one of the following: The third operation on the third control corresponding to the target second type area in the second permission setting interface; The fourth operation on the fourth control corresponding to the target function item in the second type area of the second permission setting interface; The response to the third input determines the target visitor's access rights to the target functional item in the target application, including one of the following: In response to the third operation, a third access permission of the target visitor to all functional items in the target second type area is determined, and based on the third access permission, the access permission of the target visitor to the target functional items in the target application is determined; In response to the fourth operation, a fourth access permission of the target visitor to the target functional item in the target second type area is determined, and based on the fourth access permission, the access permission of the target visitor to the target functional item in the target application is determined. In response to the third operation, a third access permission for the target visitor to all functional items in the target second type area is determined. In response to the fourth operation, a fourth access permission for the target visitor to the target functional items in the target second type area is determined. Based on the third and fourth access permissions, the target visitor's access permission to the target functional items is determined.