An application management method and device
By generating user interaction pages, users can select the scope and policies for application control, which solves the problem of segmented control over different objects in the application and improves user privacy protection and experience.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-25
- Publication Date
- 2026-03-31
AI Technical Summary
In existing technologies, applications cannot effectively review dynamically loaded executable programs during the app store listing process, making it difficult to prevent the illegal theft of user privacy data, and there is a lack of detailed control mechanisms.
By generating user interaction pages, users can select the scope of application control on the first page and the control policy on the second page, enabling detailed control over different objects in the application, including the application, integrated SDK, and dynamically loaded executables.
It enables detailed control over different objects within the application, improves the ability to prevent illegal activities, protects user privacy data, and enhances the user experience.
Smart Images

Figure CN115017476B_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of communication technology, specifically relating to an application management method and apparatus. Background Technology
[0002] Currently, with the development of science and technology, smartphones have become widely popular. At the same time, the act of criminals stealing users' private data through smartphones and enticing users to download them is becoming increasingly rampant. The source of this illegal theft of user privacy data lies in the apps (Applications) installed on smartphones, the SDKs (Software Development Kits) integrated within those apps, and the executable programs dynamically loaded by the apps. Currently, security is mainly ensured by various software platforms and app stores reviewing apps and their integrated SDKs during the app listing process. However, during this process, criminals can evade security checks by using IP addresses, analyzing app usage time, and distributing malicious code from the cloud to achieve their goal of getting apps listed. Furthermore, there is currently no effective method to verify the security of dynamically loaded executable programs within apps.
[0003] Therefore, how to manage different objects within an application after it is installed on a terminal device has become a pressing technical problem that needs to be solved. Summary of the Invention
[0004] The purpose of this application is to provide an application management method and apparatus that can solve the technical problem of subdividing and controlling different objects in an application.
[0005] In a first aspect, embodiments of this application provide an application management method, the method comprising:
[0006] When a preset application control trigger event occurs, a first page and a second page are generated;
[0007] On the first page, in response to the user's first instruction, the control scope information of the application is determined, and the control scope information is used to determine the target program in the controlled application;
[0008] On the second page, in response to the user's second instruction, the control policy information of the application is determined;
[0009] The target operation is performed on the target program according to the control strategy information.
[0010] Secondly, embodiments of this application provide an application management device, including a page generation module, a control scope determination module, a control strategy determination module, and an application management module;
[0011] The page generation module is used to generate a first page and a second page when a preset application management trigger event occurs;
[0012] The control scope determination module is used to determine the control scope information of the application in response to the user's first instruction on the first page. The control scope information is used to determine the target program in the controlled application.
[0013] The control strategy determination module is used to determine the control strategy information of the application in response to the user's second instruction on the second page;
[0014] The application management module is used to perform target operations on the target program according to the control strategy information.
[0015] Thirdly, embodiments of this application provide an electronic device including a processor, a memory, and a program or instructions stored in the memory and executable on the processor, wherein the program or instructions, when executed by the processor, implement the steps of the method described in the first aspect.
[0016] Fourthly, embodiments of this application provide a readable storage medium on which a program or instructions are stored, which, when executed by a processor, implement the steps of the method described in the first aspect.
[0017] Fifthly, embodiments of this application provide a chip, the chip including a processor and a communication interface, the communication interface being coupled to the processor, the processor being used to run programs or instructions to implement the method as described in the first aspect.
[0018] In this embodiment, upon the occurrence of a preset application control trigger event, a first page and a second page are generated. Control scope information is determined based on the control scope selected by the user on the first page, and control policy information is determined based on the control policy selected by the user on the second page. Then, the target program requiring control within the application is determined based on the control scope information, and the target program is controlled according to the control policy information. This embodiment, when an application is being controlled, can determine the target program requiring control within the application based on the control scope information selected by the user, enabling segmented control over different target programs within the application and solving the technical problem in the prior art of being unable to segmentedly control different objects within an application. Attached Figure Description
[0019] Figure 1 This is a flowchart of an application management method provided in an embodiment of this application.
[0020] Figure 2 This is a schematic diagram of the first page provided in the embodiments of this application.
[0021] Figure 3 This is a schematic diagram of the third page provided in the embodiments of this application.
[0022] Figure 4 This is a schematic diagram of another third page provided in an embodiment of this application.
[0023] Figure 5 This is a schematic diagram of the fourth page provided in the embodiments of this application.
[0024] Figure 6 This is a schematic diagram of another fourth page provided in an embodiment of this application.
[0025] Figure 7 This is a schematic diagram of another first page provided in an embodiment of this application.
[0026] Figure 8 This is a schematic diagram of the second page provided in an embodiment of this application.
[0027] Figure 9 This is a flowchart of another application management method provided in the embodiments of this application.
[0028] Figure 10 This is a schematic diagram of another second page provided in an embodiment of this application.
[0029] Figure 11 This is a schematic diagram of the structure of the data control module provided in the embodiment of this application.
[0030] Figure 12 This is a schematic diagram of the access isolation module provided in an embodiment of this application.
[0031] Figure 13 This is a schematic diagram of the structure of the application management device provided in the embodiments of this application.
[0032] Figure 14 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.
[0033] Figure 15 This is a schematic diagram of the hardware structure of an electronic device according to an embodiment of this application. Detailed Implementation
[0034] The technical solutions of the embodiments of this application will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application are within the scope of protection of this application.
[0035] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such use of data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first," "second," etc., are generally of the same class and the number of objects is not limited; for example, a first object can be one or more. Furthermore, in the specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.
[0036] The following description, in conjunction with the accompanying drawings, details an application management method provided by this application through specific embodiments and application scenarios.
[0037] like Figure 1 As shown, Figure 1 This is a flowchart illustrating an application management method provided in an embodiment of this application. The application management method provided in this embodiment can be executed by an electronic device, which can consist of two or more physical entities, or it can consist of a single physical entity. For example, the electronic device can be a computer, mobile phone, tablet, or other smart device. The application management method includes:
[0038] Step 101: When a preset application control trigger event occurs, generate the first page and the second page.
[0039] An application is a computer program designed to perform one or more specific tasks. Generally, an application has a visual user interface through which it interacts with the user. For example, an application installed on a mobile phone displays a user interface on the phone screen, and the user can use different gestures on the screen to operate the user interface, thereby interacting with the application.
[0040] An application management trigger event can be an event that occurs when an application is managed or controlled. In one embodiment, an application management trigger event can be pre-set to be generated when any application on an electronic device is managed or controlled. For example, the electronic device is a mobile phone, which has an isolation system for managing applications. In one scenario, when a user adds an application installed on the phone to the isolation system for management, an application management trigger event is generated. In another scenario, when the phone's security system detects an application as an insecure application with malicious intent such as stealing user privacy, it adds the insecure application to the isolation system for management, also generating an application management trigger event.
[0041] In this embodiment, the electronic device includes a display screen, which can display different content according to the control of the electronic device. When an application management trigger event occurs, the electronic device generates a first page and a second page, and displays the first page and the second page on the display screen. The first page allows the user to select the management scope of the application being managed, and the second page allows the user to select the management strategy for the application being managed. In this embodiment, the display screen may or may not have touch functionality; this embodiment is not limited in this regard. In addition to displaying the first page and the second page, the display screen can also display other content such as videos played on the electronic device or web pages that are open.
[0042] Step 102: On the first page, in response to the user's first instruction, determine the control scope information of the application. The control scope information is used to determine the target program in the controlled application.
[0043] The scope of application control information can include information about the target programs that need to be controlled within the application. It should be noted that an application may contain multiple programs, such as third-party SDKs integrated into the application, or executable programs dynamically loaded by the application through a cloud server. Therefore, when controlling an application, the target programs to be controlled can be selected from the programs included in the application; that is, the scope of control for that application can be selected. For example, the target program can be an integrated SDK within the application, a dynamically loaded executable program, or the application itself.
[0044] In one embodiment, after the first page is generated, it displays control scope options for the user to select, such as integrating an SDK or an executable program. The user can determine the selected control scope option on the first page via a first instruction. When the application management device receives the first instruction from the user, it can determine the application's control scope information based on the user's instruction. For example, the first page may look like this: Figure 2 As shown, the first page offers four control scope options for the user: A1, B1, C1, and D1. The user selects the control scope option by issuing a first command. Upon receiving the user's first command, the system determines the application's control scope information based on the selected option, and then identifies the target program within the application that needs to be controlled. For example, when the user selects control scope option A1, the control scope information includes the control scope as A1. The electronic device can then select the program corresponding to the A1 control scope as the target program within the application based on this information.
[0045] It is understood that in this embodiment, the method by which the user generates the first instruction can be set according to actual needs. For example, the user can generate the first instruction by tapping the touch screen with their finger, clicking the mouse, or pressing a keyboard key. This embodiment does not specifically limit the method of generating the first instruction.
[0046] Step 103: On the second page, respond to the user's second instruction and determine the application's control policy information.
[0047] Control policy information may include control rules set for the behavior of the target program. For example, control policy information may include control rules set for the application's access to other applications, or control rules set for the SDK integrated into the application's access to user privacy data.
[0048] In one embodiment, after the second page is generated, it displays control policy options for the user to select. The user can determine the selected control policy option on the second page using a second command. When the application management device receives the second command from the user, it can determine the application's control policy information based on the user's command. For example, the second page includes three control policy options for the user to select: A2, B2, and C2. The user can select a control policy option using a second command. Upon receiving the second command from the user, the corresponding control policy information can be determined based on the selected control policy option.
[0049] It should be further noted that, in this embodiment, the display order of the first page and the second page is not important, and the first page and the second page can also be displayed simultaneously on the display screen of the electronic device. Similarly, the execution order of steps 102 and 103 is also not important, and step 103 can be executed before step 102.
[0050] Step 104: Perform the target operation on the target program according to the control strategy information.
[0051] Once the scope and policy information of the application to be controlled are determined, the target program within the application that needs to be controlled can be identified based on the scope information. During the execution of the target program, corresponding target operations are executed according to the control rules in the policy information, thereby controlling the behavior of the target program. For example, during the execution of the target program, actions such as accessing other applications, obtaining private data, or displaying pop-up advertising windows can be controlled.
[0052] In the embodiments described above, upon the occurrence of a preset application control trigger event, a first page and a second page are generated. Control scope information is determined based on the control scope selected by the user on the first page, and control policy information is determined based on the control policy selected by the user on the second page. Subsequently, the target program requiring control within the application is determined based on the control scope information, and the target program is controlled according to the control policy information. When an application is being controlled, this embodiment can determine the target program requiring control within the application based on the control scope information selected by the user, enabling segmented control over different target programs within the application and solving the technical problem in the prior art of being unable to segmentedly control different objects within an application.
[0053] It should be noted that in this embodiment, there are two scenarios in which the electronic device generates an application control trigger event. The first scenario is that after an insecure application is installed, the electronic device notifies the user. If the user confirms that they want to control the insecure application, an application control trigger event is generated. The second scenario is when the user actively controls an application already installed on the electronic device, which also generates an application control trigger event. An insecure application can be an application that exhibits malicious behavior, such as an application that steals user privacy or maliciously prompts users to download advertisements. Specifically, for the first scenario, the following steps are included:
[0054] Step 1001: If it is determined that an insecure application is installed, generate a third page.
[0055] In this embodiment, when the electronic device determines that an insecure application is installed, it generates a third page and displays it on the screen. This third page allows the user to choose whether to manage the insecure application. For example, when a user downloads and installs an application from an app store, a system broadcast for application installation is triggered. After installation, the electronic device performs a security check on the installed application. If the application is detected as a risky or unknown application (i.e., an application exhibiting malicious behavior), a third page is generated and displayed on the screen. This third page includes options for the user to choose whether to manage the installed insecure application, for example… Figure 3 As shown, users can choose whether to control insecure applications on the third page. In one embodiment, the first and third pages can be displayed simultaneously, as shown below. Figure 4 As shown, the third page displays the first page, meaning that when users choose whether to control insecure applications, they can also select the scope of control for insecure applications.
[0056] Step 1002: Respond to the user's third instruction on the third page.
[0057] Once a user has determined whether to control insecure applications, they can send a third command to the electronic device via a third page, causing the electronic device to respond to the third command and determine whether to control the insecure application based on the third command.
[0058] Step 1003: Determine if an application management trigger event has occurred.
[0059] When the third instruction is to control a non-secure application, the electronic device determines that an application control trigger event has occurred. For example, when a user clicks with a mouse or touches the screen... Figure 3 Clicking the "OK" option on the third page sends a third command to the electronic device. Upon receiving this command, the electronic device determines that an application control event has been triggered. It's understandable that if the user doesn't need to control insecure applications, they can simply select the "Cancel" option.
[0060] In another embodiment, for the second scenario, the following steps are included:
[0061] Step 1004: Generate the fourth page, which is used to respond to the user's fourth command.
[0062] In one embodiment, a fourth page is generated in the electronic device, which displays the applications already installed on the electronic device. The user can select whether to manage the installed applications on the fourth page using a fourth command. For example, in one embodiment, the content displayed on the fourth page is as follows: Figure 5 As shown, applications A, B, and C are installed applications, each with a toggle button displayed to the right. When the fourth instruction is a click instruction, the user can click the toggle button to determine whether to manage the application. For example, when an application is already managed, the toggle button is in the ON area. To de-manage the application, the user can click the toggle button again to switch it to the OFF area, indicating that the application is not yet managed. Similarly, if the user needs to manage an unmanaged application, they can simply switch the corresponding application's toggle button to the ON area.
[0063] Step 1005: If the fourth instruction specifies at least one application that has been installed, determine that an application management trigger event has occurred.
[0064] When a user selects at least one application from the installed applications via a fourth instruction, the electronic device identifies the selected applications as those requiring control and determines that an application control trigger event has occurred. For example, when a user clicks on an application... Figure 5 When at least one application's toggle button is switched to the ON area on the fourth page shown, the electronic device determines that an application control trigger event has occurred and generates the first page and the second page.
[0065] It should be noted that, in one embodiment, the user can also actively bring up the first page and the second page. For example, as shown below... Figure 6 As shown, the fourth page also displays "Control Scope Settings" and "Control Policy Settings" options. Users can trigger these options by clicking. When the "Control Scope Settings" option is triggered, the electronic device generates and displays the first page, allowing the user to select control scope options for different applications. When the "Control Policy Settings" option is triggered, the electronic device generates and displays the second page, allowing the user to select control policy options for different applications. In one embodiment, the control scope and control policy options can be globally set, meaning that when a user selects control scope and control policy options for one application, these options can be applied to all controlled applications. For example, as... Figure 7As shown, the first page also includes a "Global Application" option. When a user selects the control scope option for a specific application and clicks the "Global Application" option, the control scope of all controlled applications will be switched to the same control scope option as the currently selected control scope option. Similarly, the global setting process for control policy options is the same as the global setting process for control scope options, and will not be described again in this embodiment.
[0066] The above describes the process by which electronic devices generate application control trigger events under different circumstances.
[0067] It should be further explained that, in this embodiment, the scope of application control includes at least one of the application, the SDK integrated into the application, and dynamically loadable executable programs within the application; that is, the application, the integrated SDK within the application, or the dynamically loaded executable program can be used as the target program. For example, such as... Figure 8 As shown, the control scope options displayed on the first page include "Applications," "Integrated SDK," and "Executable Programs," and users can select at least one of these three options. When the user selects "Applications," the entire application is controlled. It should be further clarified that the control scope of the "Applications" option includes not only the application itself but also the SDK integrated within the application and any dynamically loadable executable programs within the application. That is, when the user selects the "Applications" option, the "Integrated SDK" and "Executable Program" options are also selected by default, meaning that in addition to the application itself, the SDK integrated within the application and any dynamically loadable executable programs within the application are also considered as target programs. When the user selects the "Integrated SDK" option, the SDK integrated within the application is used as the target program; when the user selects the "Executable Program" option, the dynamically loadable executable programs within the application are used as the target program. It can be understood that the user can select both the "Integrated SDK" and "Executable Program" options simultaneously, without selecting the "Applications" option; in this case, the SDK integrated within the application and any dynamically loadable executable programs within the application will be used as target programs.
[0068] It should be noted that in this embodiment, the electronic device is also equipped with a target program filtering module. This module is used to filter target programs from applications based on the control scope information. For example, when filtering applications, the target program filtering module can filter the corresponding applications based on their process IDs. A process is a running activity of a program on a certain data set in a computer, and it is the basic unit for system resource allocation and scheduling. When an application starts, the system allocates a corresponding process to each application to execute it, and each process has a unique identifier, i.e., a process ID. Since each application has a unique process ID, controlling the corresponding process based on the process ID allows for the control of the corresponding application. For example, the electronic device can send the application's process ID to an isolation system, which can then control the corresponding process based on the process ID.
[0069] When filtering SDKs integrated into an application, the target program filtering module can identify them because the SDK code and the application's code are compiled into the same package. Specifically, if the application's package name is com.tmall.wireless, after parsing this package, all executable programs except those in the com / tmall / wireless directory are integrated SDKs. Therefore, the program code corresponding to these executable programs can be filtered out as target programs.
[0070] Furthermore, when the target program filtering module filters executable programs, the application dynamically loads the corresponding dex / elf executable file, calling the Dexclassloader / runtime stub callback registered in the system to obtain the dex / elf executable file. Therefore, the electronic device can use the classloader to parse the class name of the dex / elf executable file, find the corresponding program code based on the executable file's class name, and manage the corresponding program code to achieve control over the executable program.
[0071] As described above, in this embodiment, the user can select the application to be controlled from the installed applications, or choose whether to control the application when the electronic device detects that the installed application is not a secure application. Furthermore, the user can select at least one of the application, the SDK integrated in the application, and a dynamically loadable executable program in the application as the target program, thereby achieving granular control over the application, the SDK in the application, and the executable program in the application, solving the technical problem in the prior art of not being able to granularly control different objects within an application.
[0072] like Figure 9 As shown, Figure 9 A flowchart illustrating another application management method provided in this application embodiment. Figure 9 The application management method shown is a concretization of the above-mentioned application management method, including:
[0073] Step 201: Obtain the user's age information when a preset application control trigger event occurs.
[0074] In this embodiment, when a preset application control trigger event occurs, the electronic device will further obtain the user's age information. For example, the electronic device can obtain the personal information filled in by the user on the electronic device and obtain the user's age information from the personal information. Alternatively, the electronic device can identify the user's age information through a local AI engine. For example, the local AI engine determines the user's age information based on the type of applications installed on the electronic device and the usage time of different applications; for example, if there are many games in the applications and the usage time of the games is long, the user's age can be determined to be younger. It is understood that the specific age value identified by the local AI engine needs to be determined based on the parameters of the local AI engine and the training set during the training process of the local AI engine, and no specific limitation is made in this embodiment.
[0075] Step 202: Determine the candidate control scope displayed on the first page based on the age information.
[0076] After obtaining the user's age information, the application management system can determine the candidate control scope displayed on the first page based on this information. The candidate control scope refers to the control scope that the user can choose. It's important to note that determining the candidate control scope displayed on the first page based on the user's age is to avoid confusion for older users who may not understand the specific meanings of the "Integrated SDK" and "Executable Program" options. For younger users, who have stronger learning abilities and a higher degree of individualization, they can quickly learn and grasp the meanings of the "Integrated SDK" and "Executable Program" options, allowing all available control scopes to be displayed on the first page.
[0077] Based on the above embodiments, step 202, which determines the candidate control range displayed on the first page according to age information, includes:
[0078] Step 2021: If the age information exceeds the preset age threshold, determine that the candidate control scope displayed on the first page includes applications.
[0079] After obtaining the user's age information, if the user's age exceeds a preset age threshold, the user is considered older, and the candidate control scope displayed on the first page is determined to include the application. That is, in... Figure 8 The control scope options displayed on the first page only include the "Application" option, eliminating the need for users to manually select a control scope option. In this embodiment, the preset age can be set according to actual needs, such as setting the age threshold to 55 or 60 years old; no specific limitation is made in this embodiment. In another embodiment, when the user's age exceeds the preset threshold, the first page may not be displayed, and the control scope option may be directly selected as the "Application" option by default, simplifying the user's operation.
[0080] Step 2022: If the age information is less than or equal to the preset age threshold, determine that the candidate control scope displayed on the first page includes applications, SDKs integrated in applications, and executable programs that can be dynamically loaded in applications.
[0081] When the age information is less than or equal to the preset age threshold, the user is considered younger. In this case, the first page will display all three control scope options: "Application", "Integrated SDK", and "Executable Program", allowing the user to select the appropriate control scope as needed.
[0082] Step 203: Generate the first page and the second page.
[0083] Step 204: On the first page, in response to the user's first instruction, determine the control scope information of the application. The control scope information is used to determine the target program in the controlled application.
[0084] Step 205: On the second page, respond to the user's second instruction and determine the application's control policy information.
[0085] Step 206: Perform the target operation on the target program according to the control strategy information.
[0086] As described above, in this embodiment, after generating the application control trigger event and before generating the first page, the user's age information is further obtained. When the user is older, the candidate control scope displayed on the first page is determined to be applications, thereby avoiding confusion for older users and improving their user experience. When the user is younger, the candidate control scope displayed on the first page is determined to include applications, SDKs integrated into applications, and dynamically loadable executable programs within applications, allowing younger users to select the control scope according to their needs. This embodiment considers the actual needs of different users and provides different candidate control scopes for users of different ages, further improving the user experience.
[0087] It should be further explained that, in this embodiment, the control strategy includes at least one of a data control strategy, an access control strategy, and a behavior control strategy. Specifically, the data control strategy can be a strategy for controlling the data acquisition operations of the target program, the access control strategy can be a strategy for controlling the access operations of the target program, and the behavior control strategy can be a strategy for controlling the risky actions of the target program. For example, in one embodiment, the content displayed on the second page is as follows... Figure 10 As shown, the control policy options displayed on the second page include "Data Control Policy", "Access Control Policy" and "Behavior Control Policy". Users can select at least one of these control policy options as the control policy for the target program through the second command.
[0088] In one embodiment, when the control policy includes a data control policy, performing a target operation on the target program based on the control policy information includes:
[0089] Based on the data control strategy, the data acquisition operations performed by the target program are controlled.
[0090] In this embodiment, the user can configure the data management policy to determine whether a target program is allowed to perform data acquisition operations that obtain user privacy data, and to set corresponding management rules for the data acquired by the target program. When the user selects a data management policy, the electronic device can manage the data acquisition operations performed by the target program according to the data management policy, and also manage the data acquired by the target program. For example, the electronic device is equipped with a data control module, which includes a data management unit and an operation management unit, such as... Figure 11 As shown. The data management unit is used to manage the data obtained by the target program through the interface according to the management policy. For example, for privacy data obtained by the target program, such as contacts, SMS messages, phone numbers, and user mobile phone numbers, custom data can be used to replace the data before sending it to the target program. Specifically, after managing the target program, the target program will request data access permissions. Since there are still situations in the existing technology where applications cannot be used without authorization, users will choose to grant permissions in order to use the application normally. After the target program obtains data access permissions, the data management unit can manage the data obtained by the target program through the interface through the application management system. For example, it can replace the data obtained by the target program with custom data or empty data before sending it to the target program. For example, the data management unit can replace the contact data obtained by the target program with specified contact data, or replace the SMS data obtained by the target program with empty data. It can be understood that the specific content of the data to be managed and the custom data to replace the managed data can be set in the data management policy.
[0091] Since the target program can acquire user privacy data not only through interfaces but also through system sensor data, the operation control unit in the data control module is used to control the data acquisition operations performed by the target program. Specifically, after controlling the target program, the permission data module parses the program code corresponding to the target program to determine the data acquisition operations within the program code. For example, the operation control unit parses the application's manifest file to filter out data acquisition operations in the application, such as location information acquisition operations, application usage time information acquisition operations, or user application usage behavior information acquisition operations. Then, the operation control unit controls different data acquisition operations according to the user's data control policy. For example, if the user sets the data control policy to disallow the application from acquiring location information, then the application is prohibited from performing location information acquisition operations. In one embodiment, the operation control unit can also display the target program's data acquisition operations in the interactive interface, allowing the user to choose whether to allow the target program to perform data acquisition operations. In another embodiment, the user can also allow the target program to perform data acquisition operations, but the data acquired by the data acquisition operations needs to be replaced with custom data.
[0092] In one embodiment, when the control policy includes an access control policy, performing a target operation on the target program based on the control policy information includes:
[0093] According to the access control policy, control is exercised over the target program's access operations to at least one other application.
[0094] In this embodiment, the user can configure whether a target program is allowed to access other applications in the access control policy. When the user selects an access control policy, the electronic device controls the target program's access to other applications according to the access control policy. For example, the electronic device includes an access isolation module, which includes an application access control unit and a data access control unit, such as... Figure 12As shown. The application access control unit is used to manage access operations of the target program to at least one other application. For example, a user can configure access control policies to allow access operations between the target program and other controlled applications, prohibit access operations between the target program and other uncontrolled applications, and allow access operations between other uncontrolled applications and the target program. The application access control unit can then manage access operations between the target program and other applications according to the access control policies. The data access control unit is used to manage files generated by the target program. For example, a user can configure access control policies to allow or deny access to files generated by the target program. The data access control unit can then use the Fuse system (Filesystem in Userspace) to mark and manage files generated during the target program's execution, thereby controlling whether data in the files can be accessed by other applications.
[0095] In one embodiment, when the control policy includes a behavior control policy, performing a target operation on the target program based on the control policy information includes:
[0096] Based on the behavior control strategy, risky actions performed by the target program are controlled. Risky actions include at least one of the following: pop-up ads, download inducement actions, and accessibility feature activation inducement actions.
[0097] In this embodiment, the user can set up behavior control strategies to manage risky actions performed by the target program. When the user selects a behavior control strategy, the electronic device can control at least one of the risky actions performed by the target program, including pop-up ads, download inducements, and accessibility feature activation inducements. A pop-up ad is an action where the target program displays an advertising window in the background; a download inducement is an action where the target program induces the user to download other applications; and an accessibility feature activation inducement is an action where the target program induces the user to activate accessibility features. Accessibility features can be services for special user groups with specific physical disabilities, such as motor, visual, or hearing impairments, providing functions like enlarged fonts, voice control, and on / off control. For example, the electronic device is equipped with a behavior control module, which manages the risky actions performed by the target program according to the behavior control strategy. Specifically, for a pop-up ad, the behavior control module can use a local AI engine to identify whether the content of the window popped up in the background is an advertisement; if so, the window is closed. For download inducements, since the act of downloading applications cannot be identified, the behavior control module can prevent the target program from installing other applications by identifying the installation source of the application. Specifically, during the application installation process, the installation source of the application can be matched. If the installation source is the target application, the application installation will be blocked. Similarly, for accessibility activation inducements from the target application, the behavior control module can determine whether the redirection to the accessibility page originates from the target application. If so, redirection to the accessibility page will be blocked. In one embodiment, records of risky actions performed by the target application can be saved in the interception log. Furthermore, each time a risky action is controlled, a corresponding notification or prompt can be displayed on the electronic device's screen to inform the user of the operation currently being performed by the target application.
[0098] As described above, the control strategy in this application embodiment includes at least one of data control strategy, access control strategy, and behavior control strategy, thereby enabling electronic devices to control the data acquisition operations performed by the target program, the access operations performed by other applications, and the risky actions performed. By controlling the target program in multiple aspects, different operations of the target program are restricted, the degree of harm to system security by the target program is reduced, and the user experience is improved.
[0099] It should be noted that the application management method provided in this application embodiment can be executed by an application management device or a control module within the application management device for executing the application management method. This application embodiment uses the execution of the application management method by an application management device as an example to illustrate the application management device provided in this application embodiment.
[0100] like Figure 13 As shown, Figure 13 A schematic diagram of the structure of an application management device provided in an embodiment of this application includes a page generation module 301, a control scope determination module 302, a control strategy determination module 303, and an application management module 304.
[0101] The page generation module 301 is used to generate a first page and a second page when a preset application control trigger event occurs;
[0102] The control scope determination module 302 is used to determine the control scope information of the application in response to the user's first instruction on the first page. The control scope information is used to determine the target program in the controlled application.
[0103] The control policy determination module 303 is used to determine the control policy information of the application in response to the user's second instruction on the second page;
[0104] Application management module 304 is used to perform target operations on the target program based on control strategy information.
[0105] Based on the above embodiments, the application management device further includes: a third page generation module, a third instruction response module, and an event determination module.
[0106] The third-page generation module is used to generate a third page when it is determined that an insecure application is installed.
[0107] The third instruction response module is used to respond to the user's third instruction on the third page;
[0108] The event determination module is used to determine when an application management-triggered event occurs.
[0109] Based on the above embodiments, the application management device further includes an age acquisition module and a candidate range determination module;
[0110] The age acquisition module is used to obtain the user's age information after a preset application control trigger event occurs and before the first page is generated;
[0111] The candidate scope determination module is used to determine the candidate control scope displayed on the first page based on age information.
[0112] Based on the above embodiments, the candidate range determination module includes a first determination unit and a second determination unit;
[0113] The first determining unit is used to determine that the candidate control scope displayed on the first page includes the application when the age information exceeds a preset age threshold;
[0114] The second determining unit is used to determine, when the age information is less than or equal to a preset age threshold, that the candidate control scope displayed on the first page includes applications, SDKs integrated in applications, and executable programs that can be dynamically loaded in applications.
[0115] Based on the above embodiments, the control policy includes at least one of data control policy, access control policy, and behavior control policy;
[0116] When the control strategy includes a data control strategy, the application management module 304 is specifically used to control the data acquisition operations performed by the target program according to the data control strategy.
[0117] Alternatively, when the control policy includes an access control policy, the application management module 304 is specifically used to control the target program's execution of at least one access operation of another application according to the access control policy;
[0118] Alternatively, when the control strategy includes a behavior control strategy, the application management module 304 is specifically used to control the risk actions performed by the target program according to the behavior control strategy. The risk actions include at least one of the following: pop-up advertising actions, download inducement actions, and accessibility function activation inducement actions.
[0119] In the embodiments described above, upon the occurrence of a preset application control trigger event, a first page and a second page are generated. Control scope information is determined based on the control scope selected by the user on the first page, and control policy information is determined based on the control policy selected by the user on the second page. Subsequently, the target program requiring control within the application is determined based on the control scope information, and the target program is controlled according to the control policy information. When an application is being controlled, this embodiment can determine the target program requiring control within the application based on the control scope information selected by the user, enabling segmented control over different target programs within the application and solving the technical problem in the prior art of being unable to segmentedly control different objects within an application.
[0120] The application management device in this application embodiment can be a device, or a component, integrated circuit, or chip in a terminal. The device can be a mobile electronic device or a non-mobile electronic device. For example, mobile electronic devices can be mobile phones, tablets, laptops, PDAs, in-vehicle electronic devices, wearable devices, ultra-mobile personal computers (UMPCs), netbooks, or personal digital assistants (PDAs), etc., while non-mobile electronic devices can be servers, network attached storage (NAS), personal computers (PCs), televisions (TVs), ATMs, or self-service machines, etc. This application embodiment does not impose specific limitations.
[0121] The application management in this embodiment can be a device with an operating system. This operating system can be Android, iOS, or other possible operating systems; this embodiment does not specifically limit the specific operating system.
[0122] The application management provided in this embodiment can achieve... Figures 1 to 12 The various processes implemented in the method implementation examples will not be described again here to avoid repetition.
[0123] Optionally, such as Figure 14 As shown, this application embodiment also provides an electronic device 400, including a processor 401, a memory 402, and a program or instructions stored in the memory 402 and executable on the processor 401. When the program or instructions are executed by the processor 401, they implement the various processes of the above-described application management method embodiment and achieve the same technical effect. To avoid repetition, they will not be described again here.
[0124] It should be noted that the electronic devices in the embodiments of this application include the mobile electronic devices and non-mobile electronic devices described above.
[0125] Figure 15 A schematic diagram of the hardware structure of an electronic device to implement an embodiment of this application.
[0126] The electronic device 500 includes, but is not limited to, components such as: radio frequency unit 501, network module 502, audio output unit 503, input unit 504, sensor 505, display unit 506, user input unit 507, interface unit 508, memory 509, and processor 510.
[0127] Those skilled in the art will understand that the electronic device 500 may also include a power supply (such as a battery) for supplying power to various components. The power supply may be logically connected to the processor 510 through a power management system, thereby enabling functions such as managing charging, discharging, and power consumption through the power management system. Figure 15 The electronic device structure shown does not constitute a limitation on the electronic device. The electronic device may include more or fewer components than shown, or combine certain components, or have different component arrangements, which will not be elaborated here.
[0128] The processor 510 is configured to generate a first page and a second page in response to a preset application control trigger event; on the first page, in response to a first instruction from the user, determine the control scope information of the application, which is used to determine the target program in the controlled application; on the second page, in response to a second instruction from the user, determine the control policy information of the application; and perform target operations on the target program according to the control policy information.
[0129] In the embodiments described above, upon the occurrence of a preset application control trigger event, a first page and a second page are generated. Control scope information is determined based on the control scope selected by the user on the first page, and control policy information is determined based on the control policy selected by the user on the second page. Subsequently, the target program requiring control within the application is determined based on the control scope information, and the target program is controlled according to the control policy information. When an application is being controlled, this embodiment can determine the target program requiring control within the application based on the control scope information selected by the user, enabling segmented control over different target programs within the application and solving the technical problem in the prior art of being unable to segmentedly control different objects within an application.
[0130] Optionally, the processor 510 is also configured to generate a third page if it is determined that an insecure application is installed; respond to a third instruction from the user on the third page; and determine that an application control trigger event has occurred.
[0131] Optionally, the processor 510 is also configured to obtain the user's age information after a preset application control trigger event occurs and before generating the first page; and determine the candidate control range displayed on the first page based on the age information.
[0132] Optionally, the processor 510 is specifically configured to determine that the candidate control scope displayed on the first page includes applications when the age information exceeds a preset age threshold; and to determine that the candidate control scope displayed on the first page includes applications, SDKs integrated in applications, and executable programs that can be dynamically loaded in applications when the age information is less than or equal to the preset age threshold.
[0133] Optionally, the control policy includes at least one of data control policy, access control policy, and behavior control policy;
[0134] When the control policy includes a data control policy, the processor 510 is specifically used to control the data acquisition operations performed by the target program according to the data control policy;
[0135] Alternatively, when the control policy includes an access control policy, the processor 510 is specifically used to control the target program's execution of at least one access operation of another application according to the access control policy;
[0136] Alternatively, when the control strategy includes a behavior control strategy, the processor 510 is specifically used to control the risky actions performed by the target program according to the behavior control strategy. The risky actions include at least one of the following: pop-up advertising actions, download inducement actions, and accessibility function activation inducement actions.
[0137] In the embodiments described above, upon the occurrence of a preset application control trigger event, a first page and a second page are generated. Control scope information is determined based on the control scope selected by the user on the first page, and control policy information is determined based on the control policy selected by the user on the second page. Subsequently, the target program requiring control within the application is determined based on the control scope information, and the target program is controlled according to the control policy information. When an application is being controlled, this embodiment can determine the target program requiring control within the application based on the control scope information selected by the user, enabling segmented control over different target programs within the application and solving the technical problem in the prior art of being unable to segmentedly control different objects within an application.
[0138] It should be understood that, in this embodiment, the input unit 504 may include a graphics processing unit (GPU) 5041 and a microphone 5042. The GPU 5041 processes image data of still images or videos obtained by an image capture device (such as a camera) in video capture mode or image capture mode. The display unit 506 may include a display panel 5061, which may be configured in the form of a liquid crystal display, an organic light-emitting diode, etc. The user input unit 507 includes a touch panel 5071 and other input devices 5072. The touch panel 5071 is also called a touch screen. The touch panel 5071 may include a touch detection device and a touch controller. Other input devices 5072 may include, but are not limited to, physical keyboards, function keys (such as volume control buttons, power buttons, etc.), trackballs, mice, joysticks, etc., which will not be described in detail here. The memory 509 can be used to store software programs and various data, including but not limited to applications and operating systems. The processor 510 may integrate an application processor and a modem processor, wherein the application processor mainly handles the operating system, user interface, and applications, and the modem processor mainly handles wireless communication. It is understandable that the aforementioned modem processor may not be integrated into processor 510.
[0139] This application also provides a readable storage medium storing a program or instructions. When the program or instructions are executed by a processor, they implement the various processes of the above-described application management method embodiments and achieve the same technical effects. To avoid repetition, they will not be described again here.
[0140] The processor is the processor in the electronic device described in the above embodiments. The readable storage medium includes computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk.
[0141] This application embodiment also provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement the various processes of the above application management method embodiments and can achieve the same technical effect. To avoid repetition, it will not be described again here.
[0142] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.
[0143] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element. Furthermore, it should be noted that the scope of the methods and apparatuses in the embodiments of this application is not limited to performing functions in the order shown or discussed, but may also include performing functions substantially simultaneously or in the reverse order, depending on the functions involved. For example, the described methods may be performed in a different order than described, and various steps may be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.
[0144] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a computer software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of this application.
[0145] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of this application.
Claims
1. An application management method characterized by comprising: The method comprises the following steps: generating a first page and a second page in the case of a preset application control trigger event; acquiring age information of a user before generating the first page after the preset application control trigger event occurs, determining that a candidate control range displayed in the first page includes the application in the case of the age information exceeding a preset age threshold, and determining that the candidate control range displayed in the first page includes the application, an SDK integrated in the application, and an executable program that can be dynamically loaded in the application in the case of the age information being less than or equal to the preset age threshold; determining control range information of the application in the first page in response to a first instruction of the user, the control range information being used to determine a target program in the application that is controlled; determining control policy information of the application in the second page in response to a second instruction of the user; performing a target operation on the target program according to the control policy information.
2. The application management method of claim 1, wherein, The method further comprises the following steps: generating a third page in the case of determining that a non-secure application is installed; responding to a third instruction of the user in the third page; determining that the application control trigger event occurs.
3. The application management method of claim 1, wherein, The control policy includes at least one of a data control policy, an access control policy, and a behavior control policy; when the control policy includes the data control policy, performing the target operation on the target program according to the control policy information includes: controlling a data acquisition operation of the target program according to the data control policy; or, when the control policy includes the access control policy, performing the target operation on the target program according to the control policy information includes: controlling an access operation of the target program to at least one other application according to the access control policy; or, when the control policy includes the behavior control policy, performing the target operation on the target program according to the control policy information includes: controlling a risk action of the target program according to the behavior control policy, the risk action including at least one of an advertisement pop-up action, a download inducement action, and an auxiliary function opening inducement action.
4. An application management apparatus characterized by comprising: The method comprises a page generation module, a control range determination module, a control policy determination module, an application management module, an age acquisition module, and a candidate range determination module; the page generation module is used to generate a first page and a second page in the case of a preset application control trigger event; the age acquisition module is used to acquire age information of a user before generating the first page after the preset application control trigger event occurs; the candidate range determination module comprises a first determination unit and a second determination unit; the first determination unit is used to determine that a candidate control range displayed in the first page includes the application in the case of the age information exceeding a preset age threshold. The second determining unit is configured to determine that the candidate management range displayed in the first page includes the application program, the SDK integrated in the application program, and the executable program that can be dynamically loaded in the application program, when the age information is less than or equal to a preset age threshold. The management range determining module is configured to determine management range information of the application program in response to a first instruction of a user on the first page, and the management range information is used to determine a target program in the application program that is managed. The management policy determining module is configured to determine management policy information of the application program in response to a second instruction of the user on the second page. The application management module is configured to perform a target operation on the target program according to the management policy information.
5. The application management apparatus according to claim 4, wherein Further comprising: a third page generating module, a third instruction responding module, and an event determining module: The third page generating module is configured to generate a third page when it is determined that the non-secure application program is installed. The third instruction responding module is configured to respond to a third instruction of the user on the third page. The event determining module is configured to determine that the application program management triggering event occurs.
6. The application management apparatus according to claim 4, wherein The management policy includes at least one of a data management policy, an access management policy, and a behavior management policy. When the management policy includes the data management policy, the application management module is specifically configured to manage a data acquisition operation of the target program according to the data management policy. Or, when the management policy includes the access management policy, the application management module is specifically configured to manage an access operation of at least one other application program of the target program according to the access management policy. Or, when the management policy includes the behavior management policy, the application management module is specifically configured to manage a risk action of the target program according to the behavior management policy, and the risk action includes at least one of an advertisement pop-up action, a download induction action, and an auxiliary function opening induction action.
Citation Information
Patent Citations
Application program control method and mobile terminal
CN108319833A
Application permission management method, device and equipment and storage medium
CN111523136A
Authority control method and device for application page
CN114547676A