Permission configuration method, device and electronic device

By using signature information and functional module identification in the permission configuration method for verification, the problem of insufficient granularity of permission configuration in the prior art is solved, and more detailed permission management and verification of functional modules is achieved.

CN114579944BActive Publication Date: 2025-05-06GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210260471.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-03-16
Publication Date
2025-05-06
Estimated Expiration
2042-03-16

AI Technical Summary

Technical Problem

In the prior art, the permission configuration method is not fine-grained enough, making it difficult to effectively verify and manage application requests for permissions.

Method used

By introducing signature information and functional module identification into the permission configuration method, the information is obtained in response to the acquisition request for the target permission, and when the signature and identification match, the permission is configured to the requested functional module.

Benefits of technology

It realizes more fine-grained verification of functional modules that request permissions, improves fine-grainedness in the permission configuration process, and ensures the accuracy and security of permission management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114579944B_ABST
    Figure CN114579944B_ABST
Patent Text Reader

Abstract

The embodiments of the present application disclose a permission configuration method, device and electronic device. The method includes: in response to a request to obtain a target permission, obtaining the signature information and function module identification corresponding to the target permission; if the signature information of the function module requesting the target permission matches the signature information corresponding to the target permission, and the function module identification of the function module requesting the target permission matches the function module identification corresponding to the target permission, the target permission is configured to the function module requesting the target permission. Thus, through the above method, when the set permission corresponds to both the signature information and the function module identification, the electronic device can verify the function module requesting the permission in combination with the signature information and the function module identification, so that the electronic device can perform more fine-grained verification on the function module requesting the permission, thereby improving the fine-grainedness in the permission configuration process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and more specifically, to a permission configuration method, device and electronic device. Background Art

[0002] In an electronic device, the electronic device can manage the installed applications through the established permissions. In this case, when the application needs to implement some functions that can only be implemented after obtaining the corresponding permissions, it needs to apply for permissions from the electronic device. However, the relevant permission configuration method still has the problem of not being fine-grained enough. Summary of the invention

[0003] In view of the above problems, the present application proposes a permission configuration method, device and electronic device to improve the above problems.

[0004] In a first aspect, the present application provides a permission configuration method, which is applied to an electronic device, and the method comprises: in response to a request to obtain a target permission, obtaining signature information and a function module identifier corresponding to the target permission; if the signature information of the function module requesting the target permission matches the signature information corresponding to the target permission, and the function module identifier of the function module requesting the target permission matches the function module identifier corresponding to the target permission, configuring the target permission to the function module requesting the target permission.

[0005] In a second aspect, the present application provides a permission configuration device that runs on an electronic device, the device comprising: a permission information acquisition unit, for obtaining, in response to a request to obtain a target permission, signature information and a function module identifier corresponding to the target permission; a permission configuration unit, for configuring the target permission to the function module requesting the target permission if the signature information of the function module requesting the target permission matches the signature information corresponding to the target permission, and the function module identifier of the function module requesting the target permission matches the function module identifier corresponding to the target permission.

[0006] In a third aspect, the present application provides an electronic device comprising one or more processors and a memory; one or more programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs are configured to execute the above-mentioned method.

[0007] In a fourth aspect, the present application provides a computer-readable storage medium, in which program code is stored, wherein the above method is executed when the program code is run.

[0008] The present application provides a permission configuration method, device, and electronic device, which can respond to the request for obtaining the target permission after obtaining the request for obtaining the target permission, so as to obtain the signature information and function module identification corresponding to the target permission, and configure the target permission to the function module requesting the target permission when the signature information of the function module requesting the target permission matches the signature information corresponding to the target permission, and the function module identification of the function module requesting the target permission matches the function module identification corresponding to the target permission. Thus, through the above method, when the set permission corresponds to both the signature information and the function module identification, the electronic device can verify the function module requesting the permission in combination with the signature information and the function module identification, so that the electronic device can perform more fine-grained verification on the function module requesting the permission, thereby improving the fine-grainedness in the permission configuration process. BRIEF DESCRIPTION OF THE DRAWINGS

[0009] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.

[0010] Figure 1 A flowchart of a permission configuration method proposed in an embodiment of the present application is shown;

[0011] Figure 2 A flowchart of a permission configuration method proposed in another embodiment of the present application is shown;

[0012] Figure 3 A flowchart of a permission configuration method proposed in another embodiment of the present application is shown;

[0013] Figure 4 A structural block diagram of a permission configuration device proposed in an embodiment of the present application is shown;

[0014] Figure 5 A structural block diagram of an electronic device proposed in this application is shown;

[0015] Figure 6 It is a storage unit of an embodiment of the present application for storing or carrying program codes for implementing the permission configuration method according to an embodiment of the present application. DETAILED DESCRIPTION

[0016] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0017] In electronic devices, in order to facilitate the management of installed applications, some functions of installed applications may be restricted. For example, the functions that an application can implement or the data that can be obtained can be determined by allocating permissions. For example, the operating system of an electronic device can provide some functions for the installed application to use. Before the application needs to use some functions provided by the electronic device, the application can first apply for the corresponding permissions from the electronic device. After the electronic device determines to allocate the permissions applied by the application to the application, the application can use the functions provided by the electronic device.

[0018] For example, if an electronic device is equipped with a camera, if an application wants to call the camera of the electronic device for image acquisition, it is necessary to first obtain permission to use the camera from the electronic device. After the electronic device assigns the permission to use the camera to the application, the application can call the camera of the electronic device. In addition, in addition to defining permissions by the electronic device itself, permissions can also be defined by installed applications. For example, some applications have audio processing functions. If another application needs to use the audio processing function, it can apply for permission to call the relevant modules of the application with the audio processing function.

[0019] In the process of an application applying for permission, the electronic device will verify the application applying for permission to determine whether the requested permission can be configured for the application. However, the inventor found in the study that the relevant permission allocation method is relatively rough and not fine-grained enough.

[0020] In order to improve the above-mentioned problem, the inventor proposes a permission configuration method, device and electronic device in the present application, which can respond to the request for obtaining the target permission after obtaining the request for obtaining the target permission, so as to obtain the signature information and function module identification corresponding to the target permission, and configure the target permission to the function module requesting the target permission when the signature information of the function module requesting the target permission matches the signature information corresponding to the target permission, and the function module identification of the function module requesting the target permission matches the function module identification corresponding to the target permission. Thus, through the above-mentioned method, when the set permission corresponds to both the signature information and the function module identification, the electronic device can verify the function module requesting the permission in combination with the signature information and the function module identification, so that the electronic device can perform more fine-grained verification on the function module requesting the permission, thereby improving the fine-grainedness in the permission configuration process.

[0021] The following is an introduction to the embodiments of the present application in conjunction with the accompanying drawings.

[0022] See also Figure 1 , the present application provides a permission configuration method, the method comprising:

[0023] S110: In response to a request to obtain a target permission, obtain signature information and a functional module identifier corresponding to the target permission.

[0024] In the embodiment of the present application, the target permission is the permission currently requested. For example, permission A, permission B and permission C are configured in the electronic device. If a function module currently sends a request for permission B, permission B will be used as the target permission. Furthermore, in the embodiment of the present application, the signature information and function module identification corresponding to the permission represent the signature information and function module identification of the function module that allows the permission to be called. Correspondingly, the signature information and function module identification corresponding to the target permission also represent the signature information and function module identification of the function module that can call the target permission. Optionally, the signature information can be a signature certificate or a summary of a signature certificate. The function module identification can have different implementation methods according to the different function modules. For example, if the function module is the entire application, the function module identification can represent the package name of the application or the unique identification assigned to the application by the electronic device. For another example, if the function module is a module included in an application, the function module identification can represent the package name of the application to which the function module belongs, or the unique identification assigned to the application to which the function module belongs by the electronic device.

[0025] Among them, in the embodiment of the present application, there may be multiple permissions that can be called. For example, it may include the calling permission of a specified component, and it may also include the calling permission of a specified functional module. For example, taking the operating system of the electronic device as the Android system as an example, the specified components may include components such as Activity, Service, ContentProvider, BroadcastReceiver, etc. The specified functional module may be an application, or it may be a module included in an application.

[0026] S120: If the signature information of the function module requesting the target permission matches the signature information corresponding to the target permission, and the function module identifier of the function module requesting the target permission matches the function module identifier corresponding to the target permission, the target permission is configured to the function module requesting the target permission.

[0027] Among them, the signature information and function module identification corresponding to the permission are used to verify the function module requesting the corresponding permission. Then, after obtaining the signature information and function module identification of the function module requesting the target permission, the signature information of the function module requesting the target permission can be compared with the signature information of the target permission, and the function module identification of the function module requesting the target permission can be compared with the function module identification of the target permission, and when the signature information of the function module requesting the target permission matches the signature information corresponding to the target permission, and the function module identification of the function module requesting the target permission matches the function module identification corresponding to the target permission, the target permission is configured to the function module requesting the target permission. Furthermore, if the signature information of the function module requesting the target permission matches the signature information corresponding to the target permission, and the function module identification of the function module requesting the target permission does not match the function module identification corresponding to the target permission, the target permission is refused to be configured to the function module requesting the target permission.

[0028] In the embodiment of the present application, in the process of comparing two signature information, it can be understood that the contents included in the signature information are compared for consistency. If the contents included in the two signature information are completely consistent, it is determined that the two signature information match. If the contents included in the two signature information are not completely consistent, it is determined that the two signature information do not match. Correspondingly, in the process of comparing two function module identifiers, it can be understood that the contents included in the function module identifier are compared for consistency. If the contents included in the two function module identifiers are completely consistent, it is determined that the two function module identifiers match. If the contents included in the two function module identifiers are not completely consistent, it is determined that the function module identifiers do not match. Exemplarily, in the case where the signature information corresponding to the target permission is aabbcc and the function module identifier corresponding to the target permission is ddeeff, if the signature information of the function module requesting the target permission is aabbcc, and the function module identifier of the function module is ddeeff, it is determined that the signature information of the function module requesting the target permission matches the signature information of the target permission, and the function module identifier of the function module requesting the target permission matches the function module identifier of the target permission.

[0029] Furthermore, in an embodiment of the present application, there may be one or more function module identifiers corresponding to permissions. For example, in some cases, the permissions configured in the electronic device may be called by a function module. In this case, the function module identifier corresponding to the permission may include function module identifiers of multiple function modules that can all call the permission. Correspondingly, in the case where there are multiple function module identifiers corresponding to the target permission, if the function module identifier of the function module requesting the target permission matches any of the multiple function module identifiers corresponding to the target permission, it is determined that the function module identifier of the function module requesting the target permission matches the function module identifier corresponding to the target permission.

[0030] A permission configuration method provided in this embodiment can respond to the request for obtaining the target permission after obtaining the request for obtaining the target permission, so as to obtain the signature information and function module identification corresponding to the target permission, and configure the target permission to the function module requesting the target permission when the signature information of the function module requesting the target permission matches the signature information corresponding to the target permission, and the function module identification of the function module requesting the target permission matches the function module identification corresponding to the target permission. Thus, in the above manner, when the set permission corresponds to both the signature information and the function module identification, the electronic device can verify the function module requesting the permission in combination with the signature information and the function module identification, so that the electronic device can perform more fine-grained verification on the function module requesting the permission, thereby improving the fine-grainedness in the permission configuration process.

[0031] See also Figure 2 , the present application provides a permission configuration method, the method comprising:

[0032] S210: In response to a request to obtain a target permission, detecting whether the target permission corresponds to signature information and a function module identifier.

[0033] It should be noted that among the permissions configured for the electronic device, different permissions may involve different functions and data, so the levels (types) of different permissions may be different. As a way, in the embodiment of the present application, the level corresponding to the permission can be determined in advance by the developer according to the confidentiality of the data involved in the permission, or it can be configured by the user of the electronic device according to his or her own needs.

[0034] Furthermore, in the embodiment of the present application, different levels of permissions may have different ways of determining whether to allow configuration when requested. Optionally, some levels of permissions may be directly configured to the functional module that is applying for them when they are applied for, and further, some levels of permissions may be verified based only on the signature information corresponding to the permissions when they are applied for, and some levels of permissions may be verified based on both the signature information and the functional module identifier for the functional module that is applying for them.

[0035] As a method, in an embodiment of the present application, the target type of permission is a permission that, when applied for, requires verification of both the signature information and the functional module identification of the functional module being applied for. In this method, in response to a request to obtain the target permission, detecting whether the target permission corresponds to the signature information and the functional module identification includes: in response to a request to obtain the target permission, obtaining the type of the target permission, and if the type of the target permission is the target type, detecting whether the target permission corresponds to the signature information and the functional module identification.

[0036] Optionally, a list for classifying permissions may be stored in the electronic device. For example, multiple lists may be stored, and permissions for different verification methods are recorded in different lists. In this way, after the target permission is obtained, the target permission can be compared with the permissions in multiple lists. If the target permission is detected to be in the specified list, the type of the target permission can be determined to be the target type. Exemplarily, the list used to store permissions in the electronic device may include list 1, list 2, and list 3, where list 1 is the specified list. In addition, permissions A, B, and C are stored in list 1, permissions D, E, and F are stored in list 2, and permissions G, H, and I are stored in list 3. After the target permission is obtained, if the target permission is detected to be permission B, and permission B is compared with multiple lists, it can be determined that the target permission is in list 1, and then the type of the target permission is determined to be the target type.

[0037] It should be noted that in the embodiment of the present application, the permission with the specified flag added can be used as the target type permission. For example, taking the operating system of the electronic device as Android as an example, if the permission has the knownSigner flag added, the permission with the knownSigner flag added can be used as the target type permission.

[0038] As a mode, in response to the acquisition request for the target permission, detecting whether the target permission corresponds to the signature information and the function module identifier includes: in response to the acquisition request for the target permission, acquiring the attribute information of the target permission; if the format of the attribute information is the first specified format, determining that the target permission corresponds to the signature information and the function module identifier. It should be noted that in this mode, the signature information and the function module identifier corresponding to the permission can be recorded in the attribute information of the permission. In this case, if the content recorded in the attribute information is different, the format of the attribute information will also be different. For example, in the two cases where only the signature information corresponding to the permission is recorded in the attribute information and the signature information and the function module identifier corresponding to the permission are recorded in the attribute information at the same time, the format of the attribute information is different. Exemplarily, in the case where the signature information and the function module identifier are recorded in the attribute information of the permission, the signature information and the function module identifier can be separated by a specified symbol. Correspondingly, in the case where there are multiple function module identifiers recorded in the attribute information, the specified symbol can also be used for separation. Then in the embodiment of the present application, the attribute information of the first specified format indicates that the signature information and the function module identifier are recorded in the attribute information.

[0039] For example, taking the operating system of the electronic device as Android as an example, the attribute information of the permission may be the knownCerts attribute corresponding to the permission.

[0040] S220: If the target permission corresponds to signature information and a function module identifier, obtain the signature information and the function module identifier corresponding to the target permission.

[0041] S230: If the signature information of the function module requesting the target permission matches the signature information corresponding to the target permission, and the function module identifier of the function module requesting the target permission matches the function module identifier corresponding to the target permission, the target permission is configured to the function module requesting the target permission.

[0042] As a method, if the target permission corresponds to signature information but does not correspond to a functional module identifier, the signature information corresponding to the target permission is obtained; if the signature information of the functional module requesting the target permission matches the signature information corresponding to the target permission, the target permission is configured to the functional module requesting the target permission.

[0043] It should be noted that in an embodiment of the present application, the permissions configured in the electronic device may be permissions defined by a functional module. Among them, the permissions defined by the functional module can be understood as the content of the permission is to call the functional module that defines the permission, or to call a submodule included in the functional module that defines the permission. Correspondingly, if there is a permission defined in a functional module, then during the installation of the functional module with permission, the signature information and the functional module identifier corresponding to the functional module can be detected. If it is detected that the permission defined by the functional module only corresponds to the signature information, then only the signature information can be mapped and stored with the functional module. If it is detected that the permission defined by the functional module corresponds to the signature information and the functional module identifier, the signature information can be mapped and stored with the functional module identifier.

[0044] Optionally, during the installation of the functional module, it is also possible to first check whether the permissions defined by the installed functional module include permissions of the target type (for example, permissions with the knownSigner flag added). If permissions of the target type are defined, it is checked whether the permissions of the target type correspond to signature information and functional module identifiers; if both signature information and functional module identifiers are corresponding, the signature information and the functional module identifier are mapped and stored.

[0045] The present embodiment provides a method for configuring permissions, so that in the above manner, when the permissions set correspond to both signature information and function module identification, the electronic device can verify the function module requesting the permission in combination with the signature information and the function module identification, so that the electronic device can perform more fine-grained verification on the function module requesting the permission, thereby improving the fine-grainedness in the permission configuration process. Moreover, in the embodiment of the present application, after obtaining the request for the permission, at least one of the type of the requested permission itself and the type of the attribute of the requested permission can be detected first, thereby further improving the fine-grainedness and flexibility of permission management. Furthermore, in the present embodiment, when it is detected that the requested permission itself does not correspond to the function module identification, but only corresponds to the signature information, the application requesting the permission can be directly verified based on the signature information, thereby making the permission configuration method provided by the present embodiment have better adaptability.

[0046] See also Figure 3 , the present application provides a permission configuration method, the method comprising:

[0047] S310: In response to a request for obtaining a target permission sent during the installation of a function module, signature information corresponding to the target permission and a function module identifier are obtained, wherein the function module during the installation process is the function module requesting the target permission.

[0048] It should be noted that some functional modules need to obtain certain permissions after installation in order to implement the functions defined by themselves. For such functional modules, a request for obtaining permissions can be initiated during the installation process.

[0049] S320: If the signature information of the function module requesting the target permission matches the signature information corresponding to the target permission, and the function module identifier of the function module requesting the target permission matches the function module identifier corresponding to the target permission, after the function module in the installation process is successfully installed, the target permission is configured to the function module requesting the target permission.

[0050] It should be noted that during the installation of the functional module, the electronic device may perform some verification on the functional module. For example, verifying the signature certificate of the functional module itself and verifying the source of the functional module, etc., to avoid illegal functional modules causing security risks to the data of the electronic device after installation. Therefore, for the functional module that initiates permission acquisition during the installation process, the requested permissions can be configured to the functional module after detecting that the functional module has been successfully installed, so as to avoid invalid permission configuration operations and cause waste of resources, thereby also avoiding security risks caused by configuring permissions for functional modules that have not been successfully installed.

[0051] The present embodiment provides a permission configuration method, so that in the above manner, when the set permission corresponds to both signature information and function module identification, the electronic device can verify the function module requesting permission in combination with the signature information and the function module identification, so that the electronic device can perform more fine-grained verification on the function module requesting permission, thereby improving the fine-grainedness of the permission configuration process. Moreover, in the present embodiment, if a permission acquisition request is received from an application being installed, the requested permission will be configured to the application after the application is successfully installed, thereby avoiding invalid configuration of permissions and security issues in the use of permissions.

[0052] See also Figure 4 The present application provides a permission configuration device 400, which runs on an electronic device. The device 400 includes:

[0053] The permission information acquisition unit 410 is used to obtain the signature information and function module identification corresponding to the target permission in response to a request to obtain the target permission.

[0054] The permission configuration unit 420 is used to configure the target permission to the function module requesting the target permission if the signature information of the function module requesting the target permission matches the signature information corresponding to the target permission, and the function module identifier of the function module requesting the target permission matches the function module identifier corresponding to the target permission. The permission configuration unit 420 is also used to refuse to configure the target permission to the function module requesting the target permission if the signature information of the function module requesting the target permission matches the signature information corresponding to the target permission, and the function module identifier of the function module requesting the target permission does not match the function module identifier corresponding to the target permission.

[0055] As a method, the permission information acquisition unit 410 is specifically used to respond to a request to obtain the target permission, detect whether the target permission corresponds to signature information and a functional module identifier; if the target permission corresponds to signature information and a functional module identifier, obtain the signature information and functional module identifier corresponding to the target permission. Optionally, the permission information acquisition unit 410 is specifically used to respond to a request to obtain the target permission, obtain attribute information of the target permission; if the format of the attribute information is the first specified format, determine that the target permission corresponds to signature information and a functional module identifier.

[0056] As a method, the permission configuration unit 420 is also specifically used to obtain the signature information corresponding to the target permission if the target permission corresponds to signature information but does not correspond to a functional module identifier; if the signature information of the functional module requesting the target permission matches the signature information corresponding to the target permission, configure the target permission to the functional module requesting the target permission.

[0057] Optionally, the permission information acquisition unit 410 is specifically used to obtain the type of the target permission in response to a request to obtain the target permission; if the type of the target permission is a target type, detect whether the target permission corresponds to signature information and a function module identifier.

[0058] As a method, the permission information acquisition unit 410 is specifically used to respond to the acquisition request for the target permission sent during the installation process of the functional module, and obtain the signature information corresponding to the target permission and the functional module identification, wherein the functional module in the installation process is the functional module requesting the target permission. In this method, the permission configuration unit 420 is specifically used to configure the target permission to the functional module requesting the target permission after the functional module in the installation process is successfully installed.

[0059] The present embodiment provides a permission configuration device, which can respond to the request for obtaining the target permission after obtaining the request for obtaining the target permission, so as to obtain the signature information and function module identification corresponding to the target permission, and configure the target permission to the function module requesting the target permission when the signature information of the function module requesting the target permission matches the signature information corresponding to the target permission, and the function module identification of the function module requesting the target permission matches the function module identification corresponding to the target permission. Thus, through the above-mentioned permission configuration device, when the set permission corresponds to both the signature information and the function module identification, the electronic device can verify the function module requesting the permission in combination with the signature information and the function module identification, so that the electronic device can perform more fine-grained verification on the function module requesting the permission, thereby improving the fine-grainedness in the permission configuration process.

[0060] It should be noted that those skilled in the art can clearly understand that, for the convenience and simplicity of description, the specific working process of the above-described device and unit can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here. In several embodiments provided in the present application, the coupling between modules can be electrical. In addition, each functional module in each embodiment of the present application can be integrated in a processing module, or each module can exist physically separately, or two or more modules can be integrated in one module. The above-mentioned integrated module can be implemented in the form of hardware or in the form of software functional modules.

[0061] The following will be combined Figure 5 An electronic device provided by the present application is described.

[0062] See also Figure 5 Based on the above-mentioned permission configuration method and device, the embodiment of the present application also provides an electronic device 1000 that can execute the above-mentioned storage box positioning method. The electronic device 1000 includes one or more (only one is shown in the figure) processors 105, a memory 104, an audio playback module 106, and an audio acquisition device 108 that are coupled to each other. Among them, the memory 104 stores a program that can execute the content of the above-mentioned embodiment, and the processor 105 can execute the program stored in the memory 104.

[0063] Among them, the processor 105 may include one or more processing cores. The processor 105 uses various interfaces and lines to connect various parts of the entire electronic device 1000, and executes various functions and processes data of the electronic device 1000 by running or executing instructions, programs, code sets or instruction sets stored in the memory 104, and calling data stored in the memory 104. Optionally, the processor 105 can be implemented in at least one hardware form of digital signal processing (Digital Signal Processing, DSP), field programmable gate array (Field-Programmable Gate Array, FPGA), and programmable logic array (Programmable Logic Array, PLA). The processor 105 can integrate one or a combination of a central processing unit (Central Processing Unit, CPU), a graphics processing unit (Graphics Processing Unit, GPU) and a modem. Among them, the CPU mainly processes the operating system, user interface and application programs; the GPU is responsible for rendering and drawing display content; and the modem is used to process wireless communications. It can be understood that the above-mentioned modem may not be integrated into the processor 105, but may be implemented separately through a communication chip.

[0064] The memory 104 may include a random access memory (RAM) or a read-only memory (ROM). The memory 104 may be used to store instructions, programs, codes, code sets or instruction sets. The memory 104 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for implementing at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the following various method embodiments, etc.

[0065] Furthermore, in addition to the aforementioned components, the electronic device 1000 may further include a network module 110 and a sensor module 112 .

[0066] The network module 110 is used to realize information interaction between the electronic device 1000 and other devices. For example, a connection can be established with other audio playback devices or other electronic devices, and information interaction is performed based on the established connection. As a way, the network module 110 of the electronic device 1000 is a radio frequency module, which is used to receive and send electromagnetic waves, realize the mutual conversion of electromagnetic waves and electrical signals, and thus communicate with a communication network or other devices. The radio frequency module may include various existing circuit elements for performing these functions, such as antennas, radio frequency transceivers, digital signal processors, encryption / decryption chips, user identity modules (SIM) cards, memories, etc. For example, the radio frequency module can interact with external devices through electromagnetic waves sent or received.

[0067] The sensor module 112 may include at least one sensor. Specifically, the sensor module 112 may include but is not limited to: a pressure sensor, a motion sensor, an acceleration sensor, and other sensors.

[0068] Among them, the pressure sensor may be a sensor that detects the pressure generated by pressing on the electronic device 1000. That is, the pressure sensor detects the pressure generated by contact or pressing between the user and the electronic device 1000, for example, the pressure generated by contact or pressing between the user's ear and the electronic device 1000. Therefore, the pressure sensor can be used to determine whether contact or pressing occurs between the user and the electronic device 1000, and the magnitude of the pressure.

[0069] Among them, the acceleration sensor can detect the magnitude of acceleration in all directions (generally three axes), and can detect the magnitude and direction of gravity when stationary, and can be used for applications that recognize the posture of the electronic device 1000 (such as horizontal and vertical screen switching, related games, magnetometer posture calibration), vibration recognition related functions (such as pedometer, tapping), etc. In addition, the electronic device 1000 can also be equipped with other sensors such as gyroscopes, barometers, hygrometers, thermometers, etc., which will not be repeated here.

[0070] The audio collection device 110 is used to collect audio signals. Optionally, the audio collection device 110 includes a plurality of audio collection devices, which may be microphones.

[0071] Please refer to Figure 6, which shows a structural block diagram of a computer-readable storage medium provided in an embodiment of the present application. The computer-readable medium 1100 stores program codes, which can be called by a processor to execute the method described in the above method embodiment.

[0072] The computer readable storage medium 1100 may be an electronic memory such as a flash memory, an EEPROM (electrically erasable programmable read-only memory), an EPROM, a hard disk, or a ROM. Optionally, the computer readable storage medium 1100 includes a non-transitory computer-readable storage medium. The computer readable storage medium 1100 has storage space for program code 1110 that executes any method step in the above method. These program codes can be read from or written to one or more computer program products. The program code 1110 can be compressed, for example, in an appropriate form.

[0073] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine the different embodiments or examples described in this specification and the features of the different embodiments or examples, without contradiction.

[0074] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined as "first" and "second" may explicitly or implicitly include at least one of the features. In the description of this application, the meaning of "plurality" is at least two, such as two, three, etc., unless otherwise clearly and specifically defined.

[0075] Any process or method description in a flowchart or otherwise described herein may be understood to represent a module, segment or portion of code that includes one or more executable instructions for implementing the steps of a specific logical function or process, and the scope of the preferred embodiments of the present application includes alternative implementations in which functions may not be performed in the order shown or discussed, including performing functions in a substantially simultaneous manner or in the reverse order depending on the functions involved, which should be understood by technicians in the technical field to which the embodiments of the present application belong.

[0076] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing logical functions, which can be embodied in any computer-readable medium for use by an instruction execution system, apparatus or device (such as a computer-based system, a system including a processor or other system that can fetch instructions from an instruction execution system, apparatus or device and execute instructions), or used in combination with these instruction execution systems, apparatuses or devices.

[0077] It should be understood that the various parts of the present application can be implemented by hardware, software, firmware or a combination thereof. In the above-mentioned embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or their combination: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0078] In summary, the permission configuration method, device and electronic device provided by the present application can respond to the request for obtaining the target permission after obtaining the request for obtaining the target permission, so as to obtain the signature information and function module identification corresponding to the target permission, and configure the target permission to the function module requesting the target permission when the signature information of the function module requesting the target permission matches the signature information corresponding to the target permission, and the function module identification of the function module requesting the target permission matches the function module identification corresponding to the target permission. Thus, through the above-mentioned method, when the set permission corresponds to both the signature information and the function module identification, the electronic device can verify the function module requesting the permission in combination with the signature information and the function module identification, so that the electronic device can perform more fine-grained verification on the function module requesting the permission, thereby improving the fine-grainedness in the permission configuration process.

[0079] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit it. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical feature diagrams therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A permission configuration method, characterized in that: Applied to electronic equipment, the method comprises: In response to a request to obtain a target permission, detecting whether the target permission corresponds to signature information and a functional module identifier, wherein different levels of permissions have different ways of determining whether configuration is allowed when requested; If the target permission corresponds to signature information and a function module identifier, obtain the signature information and function module identifier corresponding to the target permission, wherein the target permission is the permission currently requested, and the signature information and function module identifier corresponding to the target permission represent the signature information and function module identifier of the function module that is allowed to call the target permission, wherein if the format of the attribute information of the target permission is the first specified format, it is determined that the target permission corresponds to the signature information and the function module identifier; If the signature information of the function module requesting the target permission matches the signature information corresponding to the target permission, and the function module identifier of the function module requesting the target permission matches the function module identifier corresponding to the target permission, the target permission is configured to the function module requesting the target permission; The method also includes: if the target permission corresponds to signature information but does not correspond to a functional module identifier, obtaining the signature information corresponding to the target permission; if the signature information of the functional module requesting the target permission matches the signature information corresponding to the target permission, configuring the target permission to the functional module requesting the target permission.

2. The method according to claim 1, characterized in that In response to the acquisition request for the target permission, detecting whether the target permission corresponds to signature information and a functional module identifier includes: In response to a request to obtain a target permission, obtain a type of the target permission; If the type of the target permission is a target type, it is detected whether the target permission corresponds to signature information and a function module identifier.

3. The method according to claim 1, characterized in that: The method further comprises: In response to a request for obtaining a target permission sent during the installation of a function module, obtaining signature information corresponding to the target permission and a function module identifier, wherein the function module during the installation process is the function module requesting the target permission; The configuring the target permission to the functional module requesting the target permission includes: After the functional module in the installation process is successfully installed, the target permission is configured to the functional module requesting the target permission.

4. The method according to any one of claims 1 to 3, characterized in that: The method further comprises: If the signature information of the function module requesting the target permission matches the signature information corresponding to the target permission, and the function module identifier of the function module requesting the target permission does not match the function module identifier corresponding to the target permission, refuse to configure the target permission to the function module requesting the target permission.

5. The method according to any one of claims 1 to 3, characterized in that: The target permissions include: Specify the calling permissions of the component; or Specify the calling permission of the function module.

6. A permission configuration device, characterized in that: Running on an electronic device, the device comprises: A permission information acquisition unit, configured to detect, in response to a request to acquire a target permission, whether the target permission corresponds to signature information and a function module identifier, wherein different levels of permissions have different ways of determining whether configuration is allowed when requested; if the target permission corresponds to signature information and a function module identifier, acquire the signature information and function module identifier corresponding to the target permission, wherein the target permission is the permission currently requested to be acquired, and the signature information and function module identifier corresponding to the target permission represent the signature information and function module identifier of the function module that is allowed to call the target permission, wherein if the format of the attribute information of the target permission is the first specified format, it is determined that the target permission corresponds to the signature information and the function module identifier; a permission configuration unit, configured to configure the target permission to the function module requesting the target permission if the signature information of the function module requesting the target permission matches the signature information corresponding to the target permission, and the function module identifier of the function module requesting the target permission matches the function module identifier corresponding to the target permission; The permission configuration unit is also used to obtain the signature information corresponding to the target permission if the target permission corresponds to signature information but does not correspond to a functional module identifier; if the signature information of the functional module requesting the target permission matches the signature information corresponding to the target permission, configure the target permission to the functional module requesting the target permission.

7. An electronic device, characterized in that: comprising one or more processors and memory; One or more programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs are configured to execute the method according to any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores program code, wherein when the program code is run, the method according to any one of claims 1 to 5 is executed.

Citation Information

Patent Citations

  • Method and device controlling terminal

    CN103678993A

  • Authority management method and device, electronic equipment and storage medium

    CN113541966A