Application program rights management method and electronic device

By implementing the application permission management method on electronic devices, allowing one device to automatically propagate user operations to other connected devices, solving the problem of users repeatedly setting permissions on multiple devices and improving the user experience.

CN114692094BActive Publication Date: 2025-05-06HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202011562436.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-12-25
Publication Date
2025-05-06
Estimated Expiration
2040-12-25

AI Technical Summary

Technical Problem

In the scenarios associated with multiple electronic devices, users need to set the permissions of the application on each device separately, resulting in cumbersome user operations and reducing the user experience.

Method used

Through an application permission management method, an electronic device allows an electronic device to automatically propagate the operation to other connected electronic devices after detecting a user's operation, thereby setting the permissions of multiple devices to the same application.

Benefits of technology

This enables users to change the permissions of applications on multiple devices by simply operating on one device once, reducing user operations and improving user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114692094B_ABST
    Figure CN114692094B_ABST
Patent Text Reader

Abstract

A method for managing application permissions and an electronic device relate to the field of terminal technology. Specifically, a first electronic device has a first application and a second application installed, a second electronic device has the first application installed but the second application is not installed, and the first electronic device and the second electronic device are in a connected state. The method includes: the first electronic device detects a first operation, and in response to the first operation, the first electronic device sets the permission of the first application to allow access to the user data of the second application, and sends permission change information to the second electronic device. After the first electronic device receives the user data acquisition request sent by the second electronic device after changing the permission of the first application according to the permission change information, the request to obtain the user data of the second application is sent, and the user data of the second application is sent to the second electronic device. This technical solution helps to realize the sharing of application permissions of different electronic devices.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of terminal technology, and in particular to an application permission management method and an electronic device. Background Art

[0002] At present, electronic devices such as mobile phones and tablet computers provide users with functions such as making calls, surfing the Internet, taking photos, and recording audio through applications. Usually, electronic devices manage the user data of applications based on a sandbox mechanism. Although this method helps to enhance the security of user data, it will result in the inability to share user data between applications. Therefore, application permission management is introduced. For example, take application 1 accessing the user data of application 2 as an example. When application 1 of the electronic device accesses the user data of application 2, it is necessary to first determine whether the permissions of application 1 allow application 1 to access the user data of application 2. If the permissions of application 1 allow application 1 to access the user data of application 2, the electronic device can execute the step of application 1 accessing the user data of application 2. If the permissions of application 1 prohibit application 1 from accessing the user data of application 2, the electronic device cannot execute the step of application 1 accessing the user data of application 2.

[0003] Specifically, the permissions of applications are set by users on electronic devices according to their own needs. Although this method helps to achieve data sharing between different applications on the basis of ensuring user data security, for scenarios where multiple electronic devices are associated, such as multiple electronic devices logging into the same user account, or an electronic device being bound to one or more electronic devices, for the same application, users need to set the permissions of the application on multiple electronic devices separately, which is inconvenient for users and reduces user experience. Summary of the invention

[0004] The embodiments of the present application provide an application permission management method and an electronic device, so that the user only needs to operate once to change the permissions of multiple electronic devices for the same application, which helps to reduce user operations and improve user experience.

[0005] A first aspect provides an application permission management method. Specifically, a first electronic device has a first application and a second application installed, a second electronic device has the first application installed, and the second electronic device does not have the second application installed, and the first electronic device and the second electronic device are in a connected state. In this case, the method includes:

[0006] The first electronic device detects a first operation, and the first operation is used to change the permission of the first application from prohibiting access to the user data of the second application to allowing access to the user data of the second application. In response to the first operation, the first electronic device sets the permission of the first application to allow access to the user data of the second application, and sends permission change information to the second electronic device, and the permission change information is used to instruct the second electronic device to set the permission of the first application to allow access to the user data of the second application. Then, the first electronic device receives the user data acquisition request sent by the second electronic device after the permission of the first application is set to allow access to the user data of the second application according to the permission change information, and the user data acquisition request includes a first file identifier, and the first file identifier is used to identify the user data of the second application. Then, in response to the user data acquisition request, the first electronic device sends the user data identified by the first file identifier to the second electronic device.

[0007] In the embodiment of the present application, since the first electronic device changes the permission of the first application from prohibiting access to the user data of the second application to allowing access to the user data of the second application in response to the first operation, it can send permission change information to the second electronic device, so that the second electronic device can directly change the permission of the first application from prohibiting access to the user data of the second application to allowing access to the user data of the second application according to the permission change information without user operation, thereby helping to reduce user operations. Moreover, in the case where the second electronic device has the first application installed but the second application not installed, when the user uses the first application installed on the second electronic device to access the user data of the second application, the second electronic device can obtain the user data of the second application from the first electronic device, thereby achieving cross-device access.

[0008] In a possible design, the first electronic device may respond to the user data acquisition request and send the user data identified by the first file identifier to the second electronic device in the following manner:

[0009] The first electronic device displays a prompt box in response to the user data acquisition request, the prompt box being used to prompt the user whether to agree to send the user data identified by the first file identifier to the second electronic device, including an agree option and a reject option;

[0010] In response to the user selecting the consent option, the first electronic device sends the user data identified by the first file identifier to the second electronic device, thereby helping to improve the security of user data interaction between different electronic devices.

[0011] In a possible design, the first electronic device may set the permission of the first application to allow access to user data of the second application based on the following method:

[0012] The first electronic device adds the second application identifier to the application group that the first application is allowed to access, and the second application identifier is used to identify the second application. This helps to simplify the implementation. Or,

[0013] The first electronic device adds the target group identifier to the permission group list of the first application according to the first application identifier, the first application identifier is used to identify the first application, and the target group identifier is used to identify the application group that is allowed to access the user data of the second application, which is the application group identifier to which the application with the user data access permission of the second application belongs. The permission group list of the first application includes the first application identifier and the application group identifier to which the application allowed to access by the first application belongs.

[0014] In a possible design, the first application identifier is generated by the first electronic device according to the package name of the first application. The above technical solution helps to achieve that the application identifiers obtained by different electronic devices for the same application are the same.

[0015] In one possible design, the first electronic device detects a second operation, the second operation is used to open a user data view of a second application through the first application, the user data view of the second application includes a second file identifier, and the second file identifier is used to identify user data of the second application;

[0016] In response to the second operation, the first electronic device displays a user data view of the second application;

[0017] In response to the operation on the second file identifier, the first electronic device triggers the first application to access the user data identified by the second file identifier.

[0018] In one possible design, in response to an operation on a second file identifier, a first electronic device first determines, based on file metadata of the user data identified by the second file identifier, that the user data identified by the second file identifier is located on the first electronic device, the file metadata including the second file identifier and a first device identifier, the first device identifier being used to identify the first electronic device; then, the first electronic device triggers a first application to access the user data identified by the second file identifier.

[0019] A second aspect provides an application permission management method. Specifically, a first electronic device has a first application and a second application installed, a second electronic device has the first application installed, and the second electronic device does not have the second application installed, and the first electronic device and the second electronic device are in a connected state. The method includes:

[0020] The second electronic device receives permission change information sent by the first electronic device, and the permission change information is used to instruct the second electronic device to set the permission of the first application to allow access to the user data of the second electronic device; then, the second electronic device sets the permission of the first application to allow access to the user data of the second application according to the permission change information. When the second electronic device receives the first operation, the first operation is used for the first application to access the user data of the second application identified by the first file identifier; in response to the first operation, the second electronic device sends a user data acquisition request to the first electronic device, and the user data acquisition request includes the first file identifier; the second electronic device receives the user data identified by the first file identifier sent by the first electronic device in response to the user data acquisition request.

[0021] In the embodiment of the present application, since the second electronic device does not require user operation, it can directly change the permission of the first application from prohibiting access to the user data of the second application to allowing access to the user data of the second application based on the permission change information from the first electronic device, thereby helping to reduce user operations. Moreover, when the second electronic device has the first application installed but the second application not installed, when the user uses the first application installed on the second electronic device to access the user data of the second application, the second electronic device can obtain the user data of the second application from the first electronic device, thereby achieving cross-device access.

[0022] In a possible design, the second electronic device may send a user data acquisition request to the first electronic device in response to the first operation in the following manner, including:

[0023] In response to the first operation, the second electronic device determines that the user data identified by the first file identifier is located on the first electronic device based on the file metadata of the user data identified by the first file identifier, and then sends a user data acquisition request to the first electronic device, where the file metadata includes the first file identifier and the first device identifier, and the first device identifier is used to identify the first electronic device. By adding the device identifier to the file metadata, when the permissions of the application are shared between electronic devices, the electronic device where the user data is located can be determined based on the file metadata.

[0024] In a possible design, after the second electronic device sets the permission of the first application to allow access to the user data of the second electronic device according to the permission change information, it receives a second operation, the second operation is for the first application to open the user data view of the second application, the user data view of the second application includes the first file identifier; in response to the second operation, the second electronic device displays the user data view of the second application. In this case, the first operation can be an operation on the first file identifier.

[0025] In a possible design, the permission change information includes a first application identifier and a target group identifier, the first application identifier is used to identify the first application, and the target group identifier is used to identify an application group that is allowed to access user data of the second application; specifically, the second electronic device may set the permission of the first application to allow access to user data of the second application based on the permission change information in the following manner:

[0026] The second electronic device adds the target group identifier to the permission group list of the first application according to the first application identifier. The permission group list of the first application includes the first application identifier and the application group identifier that the first application is allowed to access, thereby facilitating implementation.

[0027] In a possible design, the permission change information includes a first application identifier and a second application identifier. The second electronic device adds the second application identifier to the application group that the first application is allowed to access based on the first application identifier. The first application identifier is used to identify the first application, and the second application identifier is used to identify the second application. This facilitates implementation.

[0028] In a possible design, the first application identifier is generated by the second electronic device according to the package name of the first application. The above technical solution helps to achieve that the application identifiers obtained by different electronic devices for the same application are the same.

[0029] The third aspect provides an electronic device, which includes modules / units for executing the above-mentioned first aspect or any possible design method of the first aspect; these modules / units can be implemented by hardware, or corresponding software can be implemented by hardware.

[0030] The fourth aspect provides an electronic device, which includes modules / units for executing the method of the second aspect or any possible design of the second aspect; these modules / units can be implemented by hardware, or the corresponding software can be implemented by hardware.

[0031] The fifth aspect provides a device, which includes a memory, a processor, and a computer program, wherein the computer program is stored in the memory. When the computer program is executed, the device executes the first aspect of the embodiment of the present application and any possible design of the technical solution of the first aspect, or executes the second aspect of the embodiment of the present application and any possible design of the technical solution of the second aspect.

[0032] The device includes a chip system, a chip, an integrated circuit, etc., or the device is an electronic device.

[0033] The sixth aspect is a device of an embodiment of the present application, comprising a memory, a processor, and a computer program, wherein the computer program is stored in the memory. When the computer program is executed, the device executes the first aspect of the embodiment of the present application and any possible technical solution of the first aspect, or executes the second aspect of the embodiment of the present application and any possible technical solution of the second aspect.

[0034] The device includes a chip system, a chip, an integrated circuit, etc., or the device is an electronic device.

[0035] The seventh aspect is a computer-readable storage medium of an embodiment of the present application, wherein the computer-readable storage medium includes a computer program. When the computer program runs on an electronic device, the electronic device executes a technical solution such as the first aspect mentioned above and any possible design of the first aspect thereof.

[0036] The eighth aspect is a computer-readable storage medium of an embodiment of the present application, wherein the computer-readable storage medium includes a computer program. When the computer program runs on an electronic device, the electronic device executes a technical solution such as the second aspect above and any possible design of the second aspect thereof.

[0037] The ninth aspect is a computer program product of an embodiment of the present application. When it runs on a computer, it enables the computer to execute the technical solution as described in the first aspect and any possible design of the first aspect.

[0038] The tenth aspect is a computer program product of an embodiment of the present application. When it runs on a computer, it enables the computer to execute the technical solution as described in the second aspect and any possible design of the second aspect.

[0039] The eleventh aspect is a communication system of an embodiment of the present application, comprising a first electronic device and a second electronic device, wherein the first electronic device is used to execute a technical solution such as the first aspect above and any possible design of the first aspect, and the second electronic device is used to execute a technical solution such as the second aspect above and any possible design of the second aspect.

[0040] Among them, for the beneficial effects of the third to tenth aspects, please refer to the beneficial effects of the method part and will not be repeated. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] Figure 1 A schematic diagram of a multi-device connection scenario in an embodiment of the present application;

[0042] Figure 2A A schematic diagram of the hardware structure of an electronic device according to an embodiment of the present application;

[0043] Figure 2B A schematic diagram of the software structure of an electronic device according to an embodiment of the present application;

[0044] Figure 2C A schematic diagram of a user data sandbox according to an embodiment of the present application;

[0045] Figure 3 A flowchart of an application program permission management method according to an embodiment of the present application;

[0046] Figure 4A A schematic diagram of a setting interface for permissions of an application program according to an embodiment of the present application;

[0047] Figure 4B A schematic diagram of a permission setting interface of another application program according to an embodiment of the present application;

[0048] Figure 4C A schematic diagram of a permission setting interface of another application program according to an embodiment of the present application;

[0049] Figure 5 A schematic diagram of an interface of an embodiment of the present application;

[0050] Fig. 6A A schematic diagram of an identity authentication interface according to an embodiment of the present application;

[0051] Figure 6B A schematic diagram of an interface for user data authorization according to an embodiment of the present application;

[0052] Figure 7 A flowchart of another application permission management method according to an embodiment of the present application;

[0053] Figure 8 A schematic diagram of the structure of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION

[0054] In response to the problems involved in the background technology, an embodiment of the present application provides an application permission management method, so that when the permissions of an application are changed on an electronic device, one or more electronic devices associated with the electronic device (such as one or more electronic devices that are logged in to the same user account as the electronic device, or one or more electronic devices bound to the electronic device through an application, or one or more electronic devices that maintain connection with the electronic device) can be notified to change the permissions of the corresponding application, so that the user only needs to operate once to change the permissions of multiple electronic devices for the application, which helps to reduce user operations and improve user experience.

[0055] Among them, the permissions of the applications in the embodiments of the present application may include the permission of the application to access the user data of other applications, and / or the permission of the application to access other applications. For example, take the example of application 1 allowing access to the user data of application 2. Application 1 allowing access to the user data of application 2 can be understood as application 1 can perform file operations on the user data of application 2, such as read and / or write operations, without launching application 2, such as accessing pictures in the gallery via email. For another example, take the example of application 1 allowing access to application 2, application 1 allowing access to application 2 can be understood as application 2 can be launched through application 1, such as through Launch the Camera app.

[0056] In the embodiment of the present application, the user data of the application can be stored in the form of files, such as pictures, videos, audios, chat records, etc. For an application, it can include one or more files, which is not limited. Specifically, each file corresponds to a file metadata, which is information used to describe the file, and can include file name, size, creation time information, application identification (such as UID, used to identify the application that created the file), application group identification (such as GID, used to identify the application group that allows the application to create the file to access), etc. For example, the electronic device can obtain the user data of the corresponding application based on the file metadata. In some embodiments, the application identification (such as UID) is generated by the electronic device based on the information used to describe the application (such as the package name of the application, or other information used to uniquely identify the application). Thereby, different electronic devices can have the same application identification for the same application, which helps to synchronize the permissions of applications on different electronic devices. For example, the electronic device can obtain the application identification based on the hash algorithm according to the package name of the application. Thereby helping to simplify the calculation method. Further, in some embodiments, the file metadata also includes the device identification of the electronic device used to create the file, so that other electronic devices can identify it.

[0057] It should be understood that in the embodiments of the present application, "at least one" refers to one or more. "Multiple" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent three situations: A exists alone, A and B exist at the same time, and B exists alone. Among them, A and B can be singular or plural. The character " / " generally indicates that the objects associated before and after are in an "or" relationship. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b or c can represent: a, b, c, a and b, a and c, b and c, or a, b and c. Each of a, b, and c can be an element itself, or a set containing one or more elements.

[0058] In this application, "exemplary", "in some embodiments", "in other embodiments", etc. are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as "exemplary" in this application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Rather, the use of the word "exemplary" is intended to present concepts in a concrete way.

[0059] It should be pointed out that the words "first", "second", etc. involved in the embodiments of the present application are only used for the purpose of distinguishing the description, and cannot be understood as indicating or implying relative importance, nor can they be understood as indicating or implying an order.

[0060] The embodiments of the present application are applicable to application scenarios where multiple devices are connected. For example, Figure 1 As shown, an application scenario of a multi-device connection in an embodiment of the present application includes electronic device 01, electronic device 02 and electronic device 03. It should be noted that: Figure 1 The application scenario of multiple device connections shown is only an example. The embodiment of the present application does not limit the number of electronic devices in the application scenario of multiple device connections.

[0061] Take the electronic device 01 and the electronic device 02 as an example. For example, the electronic device 01 and the electronic device 02 can communicate through the Wi-Fi network. Alternatively, the electronic device 01 and the electronic device 2 can also communicate through Bluetooth. Alternatively, the electronic device 01 and the electronic device 02 can also communicate through the mobile data network. For example, when the Bluetooth, Wi-Fi and mobile data of the electronic device 01 and the electronic device 02 are all turned on, in the embodiment of the present application, the communication method of the electronic device 01 and the electronic device 02 can be selected based on the distance between the electronic device 01 and the electronic device 02. For example, when the distance between the electronic device 01 and the electronic device 02 is close, the electronic device 01 and the electronic device 02 can give priority to Bluetooth for communication. For example, when the electronic device 01 and the electronic device 02 are beyond the communication range of Bluetooth, the Wi-Fi network can be given priority for communication. Further, in some embodiments, when the network signal strength of the Wi-Fi network is poor, the electronic device 01 and the electronic device 02 can choose the mobile data network for communication. The above is only an example of a communication method between an electronic device 01 and an electronic device 02, and does not constitute a limitation on the embodiment of the present application. In the embodiment of the present application, the electronic device 01 and the electronic device 02 may also communicate in other ways, such as Wi-Fi direct connection, etc. Optionally, the electronic device 01 and the electronic device 02 may also be connected via a connection line.

[0062] The electronic device of the embodiment of the present application may be a portable terminal, such as a mobile phone, a tablet computer, a laptop computer, a wearable electronic device (such as a smart watch), etc. For example, the portable terminal includes but is not limited to a device equipped with Hongmeng Or other operating systems. In addition, the electronic device in the embodiment of the present application may not be a portable terminal, such as a desktop computer, etc., which is not limited to this.

[0063] For example, Figure 2AAs shown, it is a hardware structure diagram of an electronic device of an embodiment of the present application. Specifically, as shown in the figure, the electronic device includes a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, an earphone interface 170D, a sensor module 180, a button 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and a subscriber identification module (SIM) card interface 195, etc. Among them, the sensor module 180 may include a pressure sensor, a gyroscope sensor, an air pressure sensor, a magnetic sensor, an acceleration sensor, a distance sensor, a proximity light sensor, a fingerprint sensor, a temperature sensor, a touch sensor, an ambient light sensor, a bone conduction sensor, etc.

[0064] The processor 110 may include one or more processing units. For example, the processor 110 may include an application processor (AP), a modem, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU). Different processing units may be independent devices, or two or more different processing units may be integrated into one device.

[0065] The processor 110 may also be provided with a memory for storing computer programs and / or data. In some embodiments, the memory in the processor 110 is a cache memory. The memory may store computer programs and / or data that have just been used or are cyclically used by the processor 110. If the processor 110 needs to use the computer program and / or data again, it may be directly called from the memory. This avoids repeated access, reduces the waiting time of the processor 110, and thus improves the efficiency of the system.

[0066] In some embodiments, the processor 110 may include one or more interfaces. For example, the processor 110 includes a universal serial bus (USB) interface 130 and a subscriber identity module (SIM) interface 195. For another example, the processor 110 may also include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), and / or a general-purpose input / output (GPIO) interface, etc.

[0067] It is understandable that the interface connection relationship between the modules illustrated in the embodiments of the present application is only a schematic illustration and does not constitute a structural limitation on the electronic device. In other embodiments of the present application, the electronic device may also adopt different interface connection methods in the above embodiments, or a combination of multiple interface connection methods.

[0068] The USB interface 130 is an interface that complies with the USB standard specification, and specifically can be a Mini USB interface, a Micro USB interface, a USB Type C interface, etc. The USB interface 130 can be used to connect a charger to charge an electronic device, and can also be used to transfer data between an electronic device and a peripheral device. It can also be used to connect headphones to play audio through the headphones. The interface can also be used to connect other electronic devices, such as augmented reality (AR) devices, etc.

[0069] The SIM card interface 195 is used to connect a SIM card. The SIM card can be connected to and separated from the electronic device by inserting it into the SIM card interface 195 or pulling it out from the SIM card interface 195. The electronic device can support 2 or N SIM card interfaces, where N is a positive integer greater than 2. The SIM card interface 195 can support Nano SIM cards, Micro SIM cards, SIM cards, and the like. Multiple cards can be inserted into the same SIM card interface 195 at the same time. The types of the multiple cards can be the same or different. The SIM card interface 195 can also be compatible with different types of SIM cards. The SIM card interface 195 can also be compatible with external memory cards. The electronic device interacts with the network through the SIM card to implement functions such as calls and data communications. In some embodiments, the electronic device uses an eSIM, i.e., an embedded SIM card. The eSIM card can be embedded in the electronic device and cannot be separated from the electronic device.

[0070] The charging management module 140 is used to receive charging input from a charger. The charger may be a wireless charger or a wired charger. In some wired charging embodiments, the charging management module 140 may receive charging input from a wired charger through the USB interface 130. In some wireless charging embodiments, the charging management module 140 may receive wireless charging input through a wireless charging coil of an electronic device. While the charging management module 140 is charging the battery 142, it may also power the electronic device through the power management module 141.

[0071] The power management module 141 is used to connect the battery 142, the charging management module 140 and the processor 110. The power management module 141 receives input from the battery 142 and / or the charging management module 140, and supplies power to the processor 110, the internal memory 121, the external memory, the display screen 194, the camera 193 and the wireless communication module 160. The power management module 141 can also be used to monitor parameters such as battery capacity, battery cycle number, battery health status (leakage, impedance), etc. In some other embodiments, the power management module 141 can also be set in the processor 110. In other embodiments, the power management module 141 and the charging management module 140 can also be set in the same device.

[0072] The wireless communication function of the electronic device can be implemented through the antenna 1, the antenna 2, the mobile communication module 150, the wireless communication module 160, the modem, and the baseband processor.

[0073] Antenna 1 and antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in the electronic device can be used to cover a single or multiple communication frequency bands. Different antennas can also be reused to improve the utilization of the antennas. For example, antenna 1 can be reused as a diversity antenna for a wireless local area network. In some other embodiments, the antenna can be used in combination with a tuning switch.

[0074] The mobile communication module 150 can provide wireless communication solutions for electronic devices including 2G / 3G / 4G / 5G, etc. The mobile communication module 150 can include at least one filter, a switch, a power amplifier, a low noise amplifier (LNA), etc.

[0075] The wireless communication module 160 includes wireless communication solutions that can be applied to electronic devices, including wireless local area networks (WLAN) (such as Wi-Fi networks), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication technology (NFC), infrared technology (IR), etc.

[0076] In some embodiments, the antenna 1 of the electronic device is coupled to the mobile communication module 150, and the antenna 2 is coupled to the wireless communication module 160, so that the electronic device can communicate with the network and other devices through wireless communication technology. The wireless communication technology may include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time division code division multiple access (TD-SCDMA), long term evolution (LTE), BT, GNSS, WLAN, NFC, FM and / or IR technology, etc. The GNSS may include global positioning system (GPS), global navigation satellite system (GLONASS), Beidou navigation satellite system (BDS), quasi-zenith satellite system (QZSS) and / or satellite based augmentation system (SBAS).

[0077] The electronic device realizes the display function through the GPU, the display screen 194 and the application processor. The display screen 194 is used to display images, videos and the like. The display screen 194 includes a display panel. The display panel can be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode or an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), Miniled, MicroLed, Micro-oLed, a quantum dot light emitting diode (QLED), and the like. In some embodiments, the electronic device may include 1 or N display screens 194, where N is a positive integer greater than 1.

[0078] The electronic device can realize the shooting function through ISP, camera 193, video codec, GPU, display screen 194 and application processor. ISP is used to process the data fed back by camera 193. For example, when taking a photo, the shutter is opened, and the light is transmitted to the camera photosensitive element through the lens. The light signal is converted into an electrical signal, and the camera photosensitive element transmits the electrical signal to the ISP for processing and converts it into an image visible to the naked eye. ISP can also perform algorithm optimization on the noise, brightness and skin color of the image. ISP can also optimize the exposure, color temperature and other parameters of the shooting scene. In some embodiments, ISP can be set in camera 193.

[0079] The camera 193 is used to capture still images or videos. The object generates an optical image through the lens and projects it onto the photosensitive element. The photosensitive element can be a charge coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the optical signal into an electrical signal, and then passes the electrical signal to the ISP to be converted into a digital image signal. The ISP outputs the digital image signal to the DSP for processing. The DSP converts the digital image signal into an image signal in a standard RGB, YUV or other format. In some embodiments, the electronic device may include 1 or N cameras 193, where N is a positive integer greater than 1.

[0080] The external memory interface 120 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the electronic device. The external memory card communicates with the processor 110 through the external memory interface 120 to implement a data storage function. For example, audio, video and other files are stored in the external memory card.

[0081] The internal memory 121 includes a running memory and a built-in memory. Among them, the running memory can be used to store computer programs and / or data, etc. The processor 110 executes various functional applications and data processing of the electronic device by running the computer programs stored in the running memory. For example, the running memory may include a high-speed random access memory. The built-in memory can also be referred to as a built-in external memory, etc., which can be used to store computer programs and / or data. For example, the built-in memory can store operating systems, applications, etc. Electronic devices usually load computer programs and / or data in the built-in memory into the running memory, so that the processor 110 runs the corresponding computer programs and / or data to achieve corresponding functions. In addition, the internal memory 121 may include a non-volatile memory, such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), etc.

[0082] The electronic device can implement audio functions such as music playing and recording through the audio module 170, the speaker 170A, the receiver 170B, the microphone 170C, the earphone interface 170D, and the application processor.

[0083] The key 190 includes a power key, a volume key, etc. The key 190 may be a mechanical key or a touch key. The electronic device may receive key input and generate key signal input related to user settings and function control of the electronic device.

[0084] Motor 191 can generate vibration prompts. Motor 191 can be used for incoming call vibration prompts, and can also be used for touch vibration feedback. For example, touch operations acting on different applications (such as taking pictures, audio playback, etc.) can correspond to different vibration feedback effects. For touch operations acting on different areas of the display screen 194, motor 191 can also correspond to different vibration feedback effects. Different application scenarios (for example: time reminders, receiving messages, alarm clocks, games, etc.) can also correspond to different vibration feedback effects. The touch vibration feedback effect can also support customization.

[0085] The indicator 192 may be an indicator light, which may be used to indicate the charging status, power changes, messages, missed calls, notifications, etc.

[0086] It is to be understood that the structure illustrated in the embodiments of the present application does not constitute a specific limitation on the electronic device. In other embodiments of the present application, the electronic device may include more or fewer components than shown in the figure, or combine certain components, or split certain components, or arrange the components differently. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware.

[0087] For example, Figure 2B , which is a schematic diagram of the software structure of an electronic device according to an embodiment of the present application, specifically includes a data management module 201, a permission management module 202 and a communication component 203.

[0088] Among them, the data management module 201 is used to manage the user data of the application. For example, the data management module 201 includes a user data sandbox. The user data sandbox is a storage space for storing the user data of the application. For example, the user data sandbox may include the user data of the application of at least one electronic device. For example, the user data sandbox includes local files and remote files. Local files refer to files created by the application on the electronic device where the data management module 201 is located, and remote files refer to files created by the application on the electronic device associated with the electronic device where the data management module 201 is located. Specifically, in an embodiment of the present application, different electronic devices can be associated by logging into the same user account, or by accessing the same local area network (such as a Wi-Fi network), or different electronic devices can establish a binding relationship through an application. For another example, a short-distance connection (such as a Bluetooth connection) can also be established between different electronic devices to achieve association between different electronic devices. Taking two electronic devices as an example, when the other party's phone number is stored in the address book of the two electronic devices, a short-distance connection is established. Of course, in an embodiment of the present application, even if the other party's phone number is not stored in the address book of the two electronic devices, a short-distance connection can be established. The embodiment of the present application does not limit the electronic device association method.

[0089] Furthermore, in some embodiments, the user data sandbox can be divided into two parts, namely a first storage space and a second storage space. Among them, the user data of the application stored in the first storage space can be shared between electronic devices, that is, the electronic device can send the user data in the first storage space to other electronic devices. The user data of the application stored in the second storage space is not shared with other electronic devices, that is, the electronic device cannot send the user data in the second storage space to other electronic devices. Alternatively, the user data sandbox in the embodiment of the present application may not distinguish between different storage spaces, and this is not limited.

[0090] For example, the data management module 201 is used to perform file operations (such as read operations, write operations, etc.) on the user data in the user data sandbox. For example, the data management module 201 can be used to trigger the permission management module 202 to check the permissions of application 1 when application 1 requests to access the user data of application 2, and after the permission check of application 1 passes, perform corresponding file operations on the user data of application 2, thereby enabling application 1 to access the user data of application 2. In addition, in the case where the user data of application 1 and application 2 are located on different electronic devices, the data management module 201 is used to call the communication component to send a user data acquisition request after the permission check of application 1 passes, and receive the user data of application 2 sent in response to the user data request.

[0091] It should be understood that if the permission check of application 1 passes, it can be understood that the permission of application 1 allows application 1 to access the user data of application 2. If the permission check of application 1 fails, it can be understood that the permission of application 1 prohibits application 1 from accessing the user data of application 2. In the case that the permission check of application 1 fails, application 1 can call the system to prompt the user whether to set the permission of application 1 to allow application 1 to access the user data of application 2.

[0092] In addition, for electronic devices that support multiple users, one user account corresponds to one user data sandbox, and the user data sandbox is used to store user data of the application on the corresponding user account. And the user data sandboxes of different user accounts are different. The data management module 201 may include a user data sandbox of at least one user account. For example, the data management module 201 includes a user data sandbox of the currently used user account and a user data sandbox of the user account authorized to the currently used user account. The user data sandbox that is not authorized to the currently used user account is invisible to the data management module 201. For example, the electronic device logs in to user account 1 and user account 2 at the same time. When the user account currently used by the electronic device is user account 1, if the identity authentication of user account 2 is passed, user account 2 authorizes user account 1. In this case, the user data sandbox of user account 2 is visible to the data management module 201, that is, the data management module 201 may include the user data sandbox of user account 1 and the user data sandbox of user account 2.

[0093] For example, taking the example that application 1 and application 2 are installed on user account 1, and application 2 and application 3 are installed on user account 2, if the electronic device logs in user account 1 and user account 2 at the same time, and the user account currently used by the electronic device is user account 1, and user account 2 authorizes user account 1, the data management module 201 includes the user data sandbox of user account 1 and the user data sandbox of user account 2, that is, the user data sandbox of user account 1 and the user data sandbox of user account 2 are visible to the data management module 201. Among them, the user data sandbox of user account 1 includes the user data of application 1 and the user data of application 2, and the user data sandbox of user account 2 includes the user data of application 2 and the user data of application 3, such as Figure 2C shown.

[0094] It should be noted that in the embodiments of the present application, for electronic devices that support multiple users, the applications installed on the electronic devices under different user accounts may be partially the same or partially different, may be all the same, or may be all different, and may be installed according to user needs without limitation.

[0095] In other embodiments, the data management module 202 may also be used to synchronize file metadata between different electronic devices and / or user accounts. For example, when user data of an application changes, the data management module 202 synchronizes corresponding file metadata between different electronic devices and / or user accounts.

[0096] The permission management module 202 is responsible for managing the permissions of the application. For example, the permission management module 202 is used to check the permissions of the application. For another example, the permission management module 202 can also be used to synchronize the permissions of the application between different electronic devices and / or user accounts. For another example, the permission management module 202 can also be used to set the permissions of the application. For example, the permission management module 202 can set the permissions of a certain application to allow access or prohibit access to the user data of another application by calling the system.

[0097] The communication component 203 is responsible for information transmission between electronic devices. For example, the communication component 203 can be used to transmit file metadata. For another example, the communication component 203 can also be used to transmit permission synchronization information to achieve permission synchronization of applications.

[0098] Understandably, Figure 2B The software structure shown is only a logical division and does not constitute a specific limitation on the electronic device.

[0099] With Figure 2A and Figure 2BTaking the electronic device with the structure shown as an example, the method of the embodiment of the present application is introduced in detail in combination with different scenarios.

[0100] Scenario 1: Application 1 and Application 2 are installed on electronic device 1, and electronic device 1 is associated with electronic device 2. It should be noted that electronic device 1 and electronic device 2 are associated, including: electronic device 1 and electronic device 2 are in a connected state. For example, electronic device 1 and electronic device 2 can be located in the same local area network, or electronic device 1 and electronic device 2 are logged in to user account 1 at the same time, or electronic device 1 and electronic device 2 are bound through a certain application (for example, a mobile phone and a TV are bound through Binding), or electronic device 1 and electronic device 2 are connected via Bluetooth, etc.

[0101] like Figure 3 FIG. 1 is a flowchart of a permission management method according to an embodiment of the present application, which specifically includes the following steps:

[0102] 301. Electronic device 1 detects that the user sets the permission of application 1 to allow access to user data operations of application 2.

[0103] For example, after installing application 1 on electronic device 1, the user can set the permissions of application 1 when opening application 1 for the first time. Figure 4A As shown, electronic device 1 displays interface 400, and interface 400 includes icon 401 of application 1 and icon 402 of application 2. In response to the operation of clicking icon 401, electronic device 1 pops up prompt box 410, and prompt window 410 includes virtual control 411. Virtual control 411 is used to control whether application 1 is allowed to access user data of application 2 or not. For example, when virtual control 411 is turned on, application 1 is allowed to access user data of application 2; when virtual control 411 is turned off, application 1 is prohibited from accessing user data of application 2. The user can operate virtual control 411 to turn on virtual control 411 and set the permission of application 1 to allow access to user data of application 2.

[0104] Alternatively, the user can set the permissions of application 1 on the permission management setting interface of application 1. For example, the permission management setting interface of application 1 can be Figure 4BThe interface 420 shown includes multiple permission setting options, such as location information, microphone, etc. It should be noted that the permission setting options included in the permission management setting interface for application 1 are related to the application or user data required to run application 1. For example, running application 1 may require the use of location information, microphone, user data of application 2, and user data of application 3. In this case, the permission management setting interface for application 1 may be Figure 4B . As shown in the figure, interface 420 includes option 421, and option 421 is used to set the permission of application 1 to access the user data of application 2. In response to the user clicking option 421, electronic device 1 displays interface 430, and interface 430 includes virtual control 431 and virtual control 432. When virtual control 431 is selected, application 1 is allowed to access the user data of application 2; when virtual control 432 is selected, application 1 is prohibited from accessing the user data of application 2. In this case, electronic device 1 can set the permission of application 1 to allow application 1 to access the user data of application 2 in response to the user selecting virtual control 431.

[0105] Alternatively, the user can set permissions for application 1 when triggering application 1 to access user data for application 2. For example, Figure 4C As shown, electronic device 1 displays interface 440 of application 1, and interface 440 of application 1 includes virtual control 441, which is an interface for application 1 to access user data of application 2. In response to the user clicking virtual control 441, if electronic device 1 checks that the permission of application 1 prohibits access to user data of application 2, a prompt box 450 pops up, and prompt box 450 includes virtual control 451, and virtual control 451 is used to set the permission of application 1. In this case, the user turns on virtual control 451, so that electronic device 1 can set the permission of application 1 to allow application 1 to access user data of application 2 in response to the user's operation of turning on virtual control 451.

[0106] The above is only an example of the operation of users setting permissions for application 1, and does not constitute a specific limitation on the operation of users setting permissions for application 1 in the embodiment of the present application. The operation of users setting permissions for application 1 is not limited in the embodiment of the present application, such as quick gesture operations, voice commands, etc., and is not limited to this.

[0107] 302 . In response to the user setting the permission of application 1 to allow access to user data of application 2 , electronic device 1 sets the permission of application 1 to allow access to user data of application 2 .

[0108] In some embodiments, application 1 in electronic device 1 receives an operation of setting the permission of application 1 to allow access to user data of application 2, and in response to the operation of setting the permission of application 1 to allow access to user data of application 2, applies to the permission management module in electronic device 1 to change the permission of application 1. The permission management module in electronic device 1 sets the permission of application 1 to allow access to user data of application 2. For example, the permission management module in electronic device 1 can add the target group identifier to the permission group list of application 1 by calling the system, thereby setting the permission of application 1 to allow access to user data of application 2. The target group identifier is used to identify the application group to which the application with access rights to user data of application 2 belongs. For example, the target group identifier can be application identifier 2, and application identifier 2 can be used to uniquely identify application 2, such as the UID of application 2, and application identifier 2 can be generated based on information used to identify application 2 (such as the identifier of application 2, or other information). The permission group list of application 1 includes application identifier 1 and at least one group identifier. Application identifier 1 can be used to uniquely identify application 1, and can be generated based on information used to identify application 1 (such as the identifier of application 1, or other information).

[0109] It is understandable that the number of group identifiers included in the permission group list of application 1 is related to the applications that are allowed to be accessed by application 1. For example, there are 3 applications that are allowed to be accessed by application 1, and the permission group list of application 1 may include 3 group identifiers. In this case, the permission group list of application 1 may be as shown in Table 1.

[0110] Table 1

[0111]

[0112] Alternatively, in some embodiments, electronic device 1 may set the permission of application 1 to allow access to user data of application 2 based on the following method:

[0113] Electronic device 1 adds application identifier 2 to the application group that the first application is allowed to access, where application identifier 2 is used to identify application 2. The application group that the first application is allowed to access includes the first application identifier and at least one application identifier that the first application is allowed to access.

[0114] Furthermore, in some other embodiments, the data management module in the electronic device 1 generates a user data view of the application 2 after detecting that the permission management module changes the permission setting of the application 1 to allow access to the user data of the application 2.

[0115] 303. Electronic device 1 sends permission change information to electronic device 2. The permission change information is used to indicate that the permission of application 1 is set to allow access to user data of application 2. For example, the permission change information includes application ID 1 and target group ID.

[0116] In some embodiments, when the permissions of application 1 are changed, electronic device 1 detects whether there is an electronic device associated with itself, and if there is an electronic device associated with itself, it sends permission change information to the electronic device. Take the example of electronic device 1 and electronic device 2 being associated by logging into the same user account. For example, electronic device 1 can detect whether the device list of the user account logged in by itself includes device information of other electronic devices other than the device information of electronic device 1. When the device list of the user account logged in by electronic device 1 includes device information of other electronic devices other than the device information of electronic device 1, electronic device 1 confirms that there is an electronic device associated with itself. Of course, other methods can be used for detection for other association methods, and this is not limited to this.

[0117] For example, after the permission changing module in electronic device 1 changes the permission of application 1 , it calls the communication component in electronic device 1 to send permission changing information to electronic device 2 .

[0118] 304 . Electronic device 2 receives permission change information from electronic device 1 , and sets permission of application 1 to allow access to user data of application 2 according to the permission change information.

[0119] In some embodiments, the permission change module in the electronic device 2 detects that the communication component in the electronic device 2 receives permission change information from the electronic device 1, and sets the permission of the application 1 according to the permission change information. For example, the permission change module in the electronic device 2 calls the system to set the permission of the application 1 according to the permission change information.

[0120] 305. Electronic device 2 generates a user data view of application 2 according to the file metadata of application 2. The user data view includes one or more file identifiers of application 2, and the file identifier of application 2 is used to identify the user data of application 2, which may be a file name, icon, and / or thumbnail, etc., and is not limited to this.

[0121] For example, after the permission change module in electronic device 2 sets the permission of application 1, it triggers the data management module in electronic device 2 to generate a user data view of application 2 according to the file metadata of application 2.

[0122] It should be noted that the electronic device 2 may be installed with the application 1 and the application 2, or may not be installed with the application 1 or the application 2, and this is not limited.

[0123] Furthermore, when the application 1 is installed on the electronic device 2, Figure 3 The method shown also includes the following steps:

[0124] 306 . Electronic device 2 detects a first trigger event, where the first trigger event is used to trigger a user to use application 1 to open a user data view of application 2 .

[0125] 307 . In response to the first triggering event, electronic device 2 checks the permissions of application 1 .

[0126] For example, application 1 of electronic device 2 detects a first trigger event. In response to the first trigger event, a data management module in electronic device 2 triggers a permission management module in electronic device 2 to detect permissions of application 1.

[0127] 308 . If the permission of application 1 allows access to user data of application 2 , electronic device 2 displays a user data view of application 2 .

[0128] If the permission of application 1 is to allow access to the user data of application 2, application 1 calls the data management module to display the user data view of application 2.

[0129] In the following, it is taken that the user data view of application 2 includes a target file identifier as an example. The target file identifier is used to identify the target user data of application 2.

[0130] In other embodiments, if the permissions of application 1 are to prohibit access to user data of application 2, electronic device 2 can prompt the user whether to modify the permissions of application 1 to allow access to user data of application 2, so that the user can modify the permissions of application 1 according to his or her own needs.

[0131] For example, it is taken that the electronic device 2 stores the user data of the application 1, the user data of the application 2 and the user data of the application 3, and the file identifier for identifying the user data of the application 2 stored in the electronic device 2 includes the file identifier 1 and the file identifier 2. Figure 5As shown, electronic device 2 displays interface 500 of application 1. Interface 500 includes application name 1, application name 2 and application name 3. Application name 1 is used to identify application 1, application name 2 is used to identify application 2, and application name 3 is used to identify application 3. In response to the user clicking on application name 2, electronic device 2 checks the permissions of application 1. If the permissions of application 1 allow access to application 2, electronic device 2 displays interface 510, which is a user data view of application 2, including file identifier 1 and file identifier 2. For example, the user can click on file identifier 1 to enable electronic device 2 to access the user data identified by file identifier 1 on electronic device 1.

[0132] It should be noted that the application name in the interface 500 may also be replaced by other application identifiers, such as an application icon, etc., and this is not limited.

[0133] 309. The electronic device 2 detects the user's operation on the target file identifier, wherein the user's operation on the target file identifier refers to the operation of the user using the application 1 to access the user data of the application 2 identified by the target file identifier.

[0134] For example, the application 1 in the electronic device 2 receives the user's operation on the target file identifier. For example, the target file identifier can be Figure 5 File ID 1 or file ID 2 in the interface shown.

[0135] 310. In response to the user's operation on the target file identifier, the electronic device 2 sends a user data acquisition request to the electronic device 1. The user data acquisition request includes the target file identifier.

[0136] For example, in response to the user's operation on the target file identifier, the application 1 triggers the data management module in the electronic device 2 to request the electronic device 1 to obtain the user data identified by the target file identifier. The data management module in the electronic device 2 calls the communication component in the electronic device 2 to send a user data acquisition request to the electronic device.

[0137] In some embodiments, in response to the user's operation on the target file identifier, electronic device 2 determines that the user data identified by the target file identifier is located on electronic device 2 based on the file metadata of the user data identified by the target file identifier, and then sends a user data acquisition request to electronic device 1.

[0138] Further, in some other embodiments, in response to the user's operation on the target file identifier, the electronic device 2 detects that the user data of the file identified by the target file identifier is located on the electronic device 1, and then displays the identity authentication interface. The identity authentication interface is used to input the identity authentication information of the electronic device 1. For example, the identity authentication information of the electronic device 1 may include the unlock password, unlock fingerprint, facial data, etc. of the electronic device 1. In response to the user completing the input of the identity authentication information, the electronic device 2 sends an identity authentication request to the electronic device 1, and the identity authentication request includes the identity authentication information input on the identity authentication interface. The electronic device 1 receives the identity authentication request from the electronic device 2, determines whether the identity authentication information included in the identity authentication request is consistent with the identity authentication information stored by itself, and if consistent, sends a successful identity authentication notification to the electronic device 2. After receiving the successful identity authentication notification, the electronic device 2 sends a user data acquisition request to the electronic device 1. This helps to improve the security of user data.

[0139] Additionally, the authentication interface can include a skip authentication option, such as Fig. 6A As shown. When this option is selected by the user, after the current identity authentication is successful, the electronic device 2 can skip the identity authentication step and directly send a user data acquisition request to the electronic device 1 if it subsequently receives an operation on a file identifier for identifying user data on the electronic device 1. If the user does not select the option to skip identity authentication, the electronic device 2 will need to perform identity authentication each time it subsequently receives an operation on a file identifier for identifying user data on the electronic device 1.

[0140] 311. Electronic device 1 receives the user data acquisition request sent by electronic device 2, and sends the user data identified by the target file identifier to electronic device 2. Thus, after electronic device 2 receives the user data identified by the target file identifier sent by electronic device 1, application 1 in electronic device 2 accesses the user data of application 2.

[0141] For example, the data management module in electronic device 2 detects that the communication component receives the user data identified by the target file identifier, and stores the user data in its own user data sandbox, so that the data management module can perform file operations on the user data, thereby enabling application 1 in electronic device 2 to access the user data of application 2.

[0142] Further, in some embodiments, after receiving the user data acquisition request sent by the electronic device 2, the electronic device 1 pops up a prompt box to the user, and the prompt box is used to prompt the user whether to agree to send the user data to the electronic device 2. In response to the user agreeing to send the user data to the electronic device 2, the electronic device 1 sends the user data identified by the target file identifier to the electronic device 2. For example, the prompt box can be as follows: Figure 6B As shown, it includes prompt information, an agree option, and a reject option for whether the user agrees to send user data to the electronic device 2. In response to the user clicking the agree option, the electronic device 1 sends the user data identified by the target file identifier to the electronic device 2. In other embodiments, if the user clicks the reject option, then in response to the user clicking the reject option, the electronic device 1 does not send the user data identified by the target file identifier to the electronic device 2. Alternatively, in some embodiments, if the user does not operate the electronic device 1 for more than a set time, the electronic device 1 may assume that the user refuses to send user data to the electronic device 2. The set time can be 10s, 15s, etc., and there is no limitation on this. It should be understood that if the user does not operate the electronic device 1 for more than a set time, the electronic device 1 may also assume that the user agrees to send user data to the electronic device 2, and there is no limitation on this.

[0143] It should be noted that in the embodiment of the present application, electronic device 1 prompts the user whether to agree to send user data to electronic device 2, and electronic device 2 performs device identity authentication on electronic device 1 can be performed simultaneously, or only one of them can be performed, and there is no limitation on this.

[0144] In other embodiments of the present application, after changing the permissions of the application 1, the electronic device 1 may further perform the following steps:

[0145] 304 ′: Electronic device 1 detects a second trigger event, where the second trigger event is used to trigger the user to use application 1 to open the user data view of application 2 .

[0146] 305 ′: In response to the second triggering event, the electronic device 1 checks the permission of the application 1 .

[0147] 306 ′: If the permission of application 1 allows access to user data of application 2 , electronic device 1 displays a user data view of application 2 .

[0148] 307', the electronic device 1 receives the user's operation on the target file identifier, wherein the user's operation on the target file identifier refers to the operation of the user using the application 1 to access the user data of the application 2 identified by the target file identifier.

[0149] 308': In response to the user's operation on the target file identifier, the electronic device 1 performs an operation of accessing the user data identified by the target file identifier.

[0150] In some embodiments, in response to a user's operation on a target file identifier, electronic device 1 determines that the user data identified by the target file identifier is located on electronic device 1 based on the file metadata of the user data identified by the target file identifier, and then performs an operation to access the user data identified by the target file identifier.

[0151] Of course, when the user sets the permission of application 1 to prohibit access to application 2, the permission synchronization method of the application can be found in Figure 3 The method described above will not be described in detail here. The difference between the user setting the permission of application 1 to allow access to application 2 is that when the user sets the permission of application 1 on electronic device 1 to prohibit access to application 2, electronic device 1 deletes the target group list in the permission group list of application 1. Further, for electronic device 2, electronic device 2 can delete the target group list in the permission group list of application 1 and delete the file metadata of application 2 in response to setting the permission of application 1 to prohibit access to application 2.

[0152] Scenario 2: Electronic device 1 supports multiple users. User account 1 and user account 2 are logged in at the same time. Application 1 and application 2 are installed on user account 1. The user account currently used on electronic device 1 is user account 1.

[0153] like Figure 7 FIG. 1 is a flowchart of a permission management method according to an embodiment of the present application, which specifically includes the following steps:

[0154] 701. Electronic device 1 detects that a user sets the permission of application 1 to allow access to application 2.

[0155] It should be noted that, for the relevant introduction about the user setting the permission of application 1 to allow access to application 2, please refer to the relevant introduction in the above step 301, which will not be repeated here.

[0156] 702 . In response to the user setting the permission of application 1 to allow access to application 2 , electronic device 1 sets the permission of application 1 in user account 1 to allow access to application 2 .

[0157] For an introduction to the implementation method of electronic device 1 setting the permission of application 1 to allow access to application 2, please refer to the relevant introduction in the above step 302, which will not be repeated here.

[0158] 703 , the electronic device 1 identifies whether there are other user accounts logged in. If the electronic device 1 identifies that the electronic device 1 is also logged in to the user account 2 , step 704 is executed.

[0159] For example, electronic device 1 can identify whether other user accounts are logged in by electronic device 1 by whether the user account login list includes other user accounts except user account 1. If user account 2 is included in the user account login list, then user account 2 is also logged in by electronic device 1.

[0160] 704. The electronic device displays an identity authentication interface, where the identity authentication interface is used for the user to input the identity authentication information of user account 2, such as an unlock password, an unlock fingerprint, or facial data.

[0161] 705. In response to the user completing the input of the identity authentication information, the electronic device 1 verifies whether the identity authentication information input by the user is consistent with the identity authentication information of the pre-stored user account 2. If they are consistent, the identity authentication is successful, the user account 2 is authorized to the user account 1, and step 706 is executed. Otherwise, the identity authentication fails, and the electronic device 1 prompts the user that the identity authentication information input is incorrect.

[0162] In addition, in some other embodiments, the identity authentication interface may further include a skip identity authentication option. When this option is selected by the user, the electronic device 1 can skip the identity authentication step if the electronic device 1 needs to access the user account 2 when using the user account 1 in the future after the identity authentication is successful. If the user does not select the skip identity authentication option, the electronic device needs to perform identity authentication each time it needs to access the user account 2 when using the user account 1 in the future.

[0163] It should be noted that steps 704 and 705 are optional steps.

[0164] 706 . Electronic device 1 sets the permission of application 1 in user account 2 to allow access to application 2 .

[0165] Furthermore, after the user switches the user account currently used by the electronic device 1 from the user account 1 to the user account 2, the following steps may also be included:

[0166] 707. When using user account 2, electronic device 1 receives a third trigger event, where the third trigger event is used to trigger the user to use application 1 to open the user data view of application 2.

[0167] For example, user account 2 stores user data of application 1, user data of application 2, and user data of application 3, and the file identifier used to identify the user data of application 2 stored in user account 2 includes file identifier 1 and file identifier 2. Figure 5 As shown, electronic device 1 displays interface 500 of application 1 when using user account 2. Interface 500 includes application name 1, application name 2 and application name 3. The third trigger event may be an operation of application name 2 by the user.

[0168] 708 . In response to the third triggering event, electronic device 1 uses user account 2 to check the permissions of application 1 .

[0169] 709 . If the permission of application 1 allows access to user data of application 2 , electronic device 2 displays a user data view of application 2 .

[0170] In the following, it is taken that the user data view of application 2 includes a target file identifier as an example. The target file identifier is used to identify the target user data of application 2.

[0171] 710. The electronic device 1 detects a user's operation on a target file identifier.

[0172] 711. In response to the user's operation on the target file identifier, the electronic device 1 obtains the user data identified by the target file identifier from the user account 1, thereby realizing the sharing of application programs in different user accounts.

[0173] Further, in some embodiments, in response to the user's operation on the target file identifier, the electronic device 2 detects that the user data of the file identified by the target file identifier is located on the user account 1, and then displays the identity authentication interface. The identity authentication interface is used to input the identity authentication information of the user account 1. For example, the identity authentication information of the user account 1 may include the unlock password, unlock fingerprint, facial data, etc. of the electronic device 1. In response to the user completing the input of the identity authentication information, the electronic device 1 determines whether the identity authentication information included in the identity authentication request is consistent with the identity authentication information of the user account 1 stored in itself. If they are consistent, the user account 1 is authorized to the user account 2, and then the electronic device 1 obtains the user data identified by the target file identifier from the user account 1. This helps to improve the security of user data.

[0174] In addition, the identity authentication interface may also include a skip identity authentication option. When this option is selected by the user, after the current identity authentication is successful, if the electronic device 1 subsequently receives an operation on a file identifier used to identify user data on the user account 1, it can skip the identity authentication step and directly obtain the corresponding user data from the user account 1. If the user does not select the skip identity authentication option, the electronic device 1 needs to perform identity authentication each time it subsequently receives an operation on a file identifier used to identify user data on the user account 1.

[0175] It should be noted that the above is based on the example of a user setting the permission of application 1 to allow access to application 2. When a user sets the permission of application 1 to prohibit access to application 2, the method for synchronizing the permissions of applications between different user accounts can also be found in Figure 7 The method described is not repeated here. The difference between the method described above and the method in which the user sets the permission of application 1 to allow access to application 2 is that when the user sets the permission of application 1 on electronic device 1 to prohibit access to application 2, electronic device 1 deletes the target group list in the permission group list of application 1.

[0176] It should be noted that Figure 3 and Figure 7 The method shown is also applicable to the sharing of other permissions, such as location permission, microphone usage permission, etc., without limitation.

[0177] The above embodiments may be used alone or in combination with each other to achieve different technical effects.

[0178] In the embodiments provided by the present application, the method provided by the embodiments of the present application is introduced from the perspective of the electronic device as the execution subject. In order to implement the functions in the methods provided by the embodiments of the present application, the electronic device may include a hardware structure and / or a software module, and implement the above functions in the form of a hardware structure, a software module, or a hardware structure plus a software module. Whether a function of the above functions is executed in the form of a hardware structure, a software module, or a hardware structure plus a software module depends on the specific application and design constraints of the technical solution.

[0179] The present application also provides a device, such as Figure 8 As shown, it includes one or more processors 801 and one or more memories 802. The memory 802 stores one or more computer programs, and when the one or more computer programs are executed by the processor 801, the device executes the application program permission management method provided in the embodiment of the present application.

[0180] In some embodiments, the device may be an electronic device, or the device may include a chip system, a chip or an integrated circuit, etc.

[0181] Further, in some embodiments, the apparatus may further include a transceiver 803 for communicating with other devices via a transmission medium, so that the apparatus can communicate with other devices. Exemplarily, the transceiver 803 may be a communication interface, a circuit, a bus, a module, etc., and the other device may be other electronic devices, such as a terminal or a server, etc. Exemplarily, the transceiver 803 may be used to send or receive permission change information, etc.

[0182] In other embodiments, the device may also include a display, a touch sensor, etc., which is not limited to this.

[0183] In the embodiment of the present application, the connection medium between the processor 801, the memory 802 and the transceiver 803 is not limited. For example, in the embodiment of the present application, the processor 801, the memory 802 and the transceiver 803 can be connected through a bus, which can be divided into an address bus, a data bus, a control bus, etc.

[0184] In the embodiments of the present application, the processor may be a general-purpose processor, a digital signal processor, an application-specific integrated circuit, a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component, and may implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the method disclosed in the embodiments of the present application may be directly embodied as being executed by a hardware processor, or may be executed by a combination of hardware and software modules in the processor.

[0185] In the embodiment of the present application, the memory may be a non-volatile memory, such as a hard disk drive (HDD) or a solid-state drive (SSD), etc., or a volatile memory (volatile memory), such as a random access memory (RAM). The memory is any other medium that can be used to carry or store a desired program code in the form of an instruction or data structure and can be accessed by a computer, but is not limited thereto. The memory in the embodiment of the present application may also be a circuit or any other device that can implement a storage function, for storing program instructions and / or data.

[0186] As used in the above embodiments, the term "when..." or "after..." may be interpreted to mean "if..." or "after..." or "in response to determining..." or "in response to detecting...", depending on the context. Similarly, the phrase "upon determining..." or "if (the stated condition or event) is detected" may be interpreted to mean "if determining..." or "in response to determining..." or "upon detecting (the stated condition or event)" or "in response to detecting (the stated condition or event)", depending on the context.

[0187] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented by software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present invention is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website site, computer, server or data center to another website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrated. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state hard disk Solid State Disk (SSD)), etc. In the absence of conflict, the solutions of the above embodiments can be used in combination.

[0188] Note: A portion of this patent application document contains material which is subject to copyright protection. The copyright owner reserves all rights reserved except for the production of copies of the material in the patent file or patent record in the Patent Office.

Claims

1. A method for managing application permissions, characterized in that: A first electronic device has a first application and a second application installed, a second electronic device has the first application installed, and the second electronic device has not installed the second application, and the first electronic device and the second electronic device are in a connected state, and the method includes: The first electronic device detects a first operation, where the first operation is used to change the permission of the first application from prohibiting access to user data of the second application to allowing access to user data of the second application; In response to the first operation, the first electronic device sets the permission of the first application to allow access to user data of the second application, and sends permission change information to the second electronic device, where the permission change information is used to instruct the second electronic device to set the permission of the first application to allow access to user data of the second application; The first electronic device receives a user data acquisition request sent by the second electronic device after the second electronic device sets the permission of the first application to allow access to the user data of the second application according to the permission change information, the user data acquisition request including a first file identifier, and the first file identifier is used to identify the user data of the second application; The first electronic device sends the user data identified by the first file identifier to the second electronic device in response to the user data acquisition request.

2. The method according to claim 1, characterized in that The first electronic device sends the user data identified by the first file identifier to the second electronic device in response to the user data acquisition request, including: The first electronic device displays a prompt box in response to the user data acquisition request, the prompt box being used to prompt the user whether to agree to send the user data identified by the first file identifier to the second electronic device, including an agree option and a reject option; In response to the user selecting an approval option, the first electronic device sends the user data identified by the first file identifier to the second electronic device.

3. The method according to claim 1 or 2, characterized in that The first electronic device sets the permission of the first application to allow access to user data of the second application, including: The first electronic device adds a second application identifier to the application group that the first application is allowed to access, and the second application identifier is used to identify the second application.

4. The method according to any one of claims 1 to 3, characterized in that: The method further comprises: The first electronic device detects a second operation, where the second operation is used to open a user data view of the second application through the first application, where the user data view of the second application includes a second file identifier, and the second file identifier is used to identify user data of the second application; In response to the second operation, the first electronic device displays a user data view of the second application; In response to the operation on the second file identifier, the first electronic device triggers the first application to access the user data identified by the second file identifier.

5. A method for managing application permissions, characterized in that: A first electronic device has a first application and a second application installed, a second electronic device has the first application installed, and the second electronic device has not installed the second application, and the first electronic device and the second electronic device are in a connected state, and the method includes: The second electronic device receives permission change information sent by the first electronic device, where the permission change information is used to instruct the second electronic device to set the permission of the first application to allow access to user data of the second application; The second electronic device sets the permission of the first application to allow access to user data of the second application according to the permission change information; The second electronic device detects a first operation, where the first operation is used for the first application to access user data of the second application identified by the first file identifier; In response to the first operation, the second electronic device sends a user data acquisition request to the first electronic device, where the user data acquisition request includes the first file identifier; The second electronic device receives the user data identified by the first file identifier sent by the first electronic device in response to the user data acquisition request.

6. The method according to claim 5, characterized in that After the second electronic device sets the permission of the first application to allow access to user data of the second electronic device according to the permission change information, the method further includes: The second electronic device detects a second operation, where the second operation is used by the first application to open a user data view of the second application, where the user data view of the second application includes the first file identifier; In response to the second operation, the second electronic device displays a user data view of the second application.

7. The method according to claim 5 or 6, characterized in that The permission change information includes a first application identifier and a second application identifier, wherein the first application identifier is used to identify the first application, and the second application identifier is used to identify the second application; The second electronic device sets the permission of the first application program to allow access to the user data of the second application program according to the permission change information, including: The second electronic device adds the second application identifier to the application group that the first application is allowed to access based on the first application identifier, where the second application identifier is used to identify the second application.

8. An electronic device, characterized in that: include: processor; Memory; And a computer program, which is stored in the memory, and when the computer program is executed by the processor, enables the electronic device to execute the method as claimed in any one of claims 1 to 4, or execute the method as claimed in any one of claims 5 to 7.

9. A device, characterized in that: include: processor; Memory; and a computer program, wherein the computer program is stored in the memory, and when the computer program is executed by the processor, the apparatus executes the method according to any one of claims 1 to 4, or the method according to any one of claims 5 to 7.

10. A computer-readable storage medium, characterized in that: The method comprises a computer program, which, when executed on an electronic device, enables the electronic device to execute the method as claimed in any one of claims 1 to 4, or the method as claimed in any one of claims 5 to 7.

11. A computer program product, characterized in that When the method is executed on a computer, the computer is enabled to execute the method according to any one of claims 1 to 4, or the method according to any one of claims 5 to 7.