Method and related device for managing rights
By performing global authorization status management and database synchronization among interconnected electronic devices, the problem of low efficiency in cross-device access permission management is solved, and a simplified user authorization process and improved user experience are achieved.
Patent Information
- Application Number
- CN202110379733.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-04-08
- Publication Date
- 2026-02-03
- Estimated Expiration
- 2041-04-08
AI Technical Summary
When accessing resources across devices, existing technologies suffer from low access permission management efficiency, cumbersome user authorization processes, and negatively impact user experience.
By managing the global authorization status among interconnected electronic devices, synchronizing and merging data using the permission databases of the first and second electronic devices, the authorization status of the same application is managed in a unified manner, avoiding duplicate authorizations, and displaying a processing interface for user confirmation in case of conflicts.
It improves the efficiency of cross-device access control, reduces user authorization operations, and enhances the user experience.
Smart Images

Figure CN115202559B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of this application relate to the field of information security technology, and in particular to a permission management method and related equipment. Background Technology
[0002] With the widespread use of electronic devices (such as smartphones, tablets, etc.) and the promotion of communication technologies, electronic devices can access resources across devices.
[0003] When electronic devices access resources across devices, access permissions need to be managed. However, low access permission management and cumbersome user authorization processes are problems that need to be solved. Summary of the Invention
[0004] This application discloses a permission management method and related equipment, which can improve the efficiency of permission management between electronic devices in a distributed system.
[0005] The first aspect of this application discloses a permission management method applied in a first electronic device. The permission management method includes: a first application of the first electronic device requesting access to a second system resource of a second electronic device; receiving the authorization status of the second system resource for the first application returned by the second electronic device; and storing the authorization status of the second system resource for the first application in a first permission database of the first electronic device.
[0006] By adopting this technical solution, the first electronic device can apply the authorization status returned by the second electronic device, thus avoiding the user from granting authorization multiple times.
[0007] In some alternative implementations, the first electronic device and the second electronic device are mutually trusted and connected.
[0008] By adopting this technical solution, global authorization status management can be performed on multiple trusted connected electronic devices.
[0009] In some alternative implementations, the application identifier of the second application of the second electronic device is consistent with the application identifier of the first application of the first electronic device.
[0010] By adopting this technical solution, the same application in the first electronic device and the second electronic device has the same application identifier, which facilitates unified permission management.
[0011] In some optional implementations, the permission management method further includes: synchronizing the first permission database with the second permission database of the second electronic device.
[0012] This technical solution enables the synchronization of authorization status between two electronic devices. For example, it allows for data synchronization between an electronic device that stores authorization status and an electronic device that does not.
[0013] In some optional implementations, the permission management method further includes merging the authorization status in the first permission database based on the application identifier of the first application and the application identifier of the second application of the second electronic device.
[0014] By adopting this technical solution, the authorization status can be merged to make the authorization status of two electronic devices consistent.
[0015] In some optional implementations, if a conflict occurs in the authorization status merging in the first permission database, the permission management method further includes: displaying a conflict resolution interface; determining the conflicting authorization status in the first permission database based on the user's conflict resolution operation in the conflict resolution interface; and synchronizing the determined conflicting authorization status to the second permission database of the second electronic device.
[0016] By adopting this technical solution, the problem of conflicting authorization statuses that occur during the merging of multiple electronic devices can be resolved.
[0017] In some optional implementations, after the first permission database of the first electronic device stores the authorization status of the second system resources for the first application, the permission management method further includes: the first application of the first electronic device requests access to the first system resources of the first electronic device, the first system resources being consistent with the second system resources; and obtaining the authorization status of the first system resources for the first application from the first permission database.
[0018] By adopting this technical solution, the authorization status can be directly obtained from the first permission database without needing to obtain authorization from the user again. The authorization status of the first system resource for the first application comes from the second electronic device.
[0019] In some optional implementations, after the first electronic device obtains the authorization status of the first system resources for the first application from the first permission database, the permission management method further includes: controlling the first application's access to the first system resources based on the authorization status of the first system resources for the first application.
[0020] By adopting this technical solution, access control of system resources by applications can be implemented based on the authorization status.
[0021] In some optional implementations, after the first permission database of the first electronic device stores the authorization status of the second system resource for the first application, the permission management method further includes: receiving an access request from the second application of the second electronic device to the first system resource of the first electronic device, wherein the first system resource is consistent with the second system resource and the application identifier of the first application is consistent with the application identifier of the second application; obtaining the authorization status of the first system resource for the second application from the first permission database; and controlling the access of the second application to the first system resource according to the authorization status of the first system resource for the second application.
[0022] By adopting this technical solution, access to the resources of the first system by the second application can be controlled based on the authorization status in the first permission database without obtaining authorization from the user.
[0023] In some optional implementations, the permission management method further includes: if the first application does not exist in the first electronic device and the second application does not exist in the second electronic device, deleting the authorization status corresponding to the first application in the first permission database.
[0024] By adopting this technical solution, the authorization status of a given application can be deleted after a user deletes it in a distributed system.
[0025] In some alternative implementations, the authorization status includes an application identifier field, a resource identifier field, a permission field, and / or an authorization status field.
[0026] The second aspect of this application discloses a permission management method applied to a second electronic device. The permission management method includes: receiving an access request from a first application of a first electronic device to a second system resource of the second electronic device; obtaining the authorization status of the second system resource to the first application from a second permission database of the second electronic device; determining the authorization status of the second system resource to the first application; and sending the authorization status of the second system resource to the first application to the first electronic device.
[0027] By adopting this technical solution, the authorization status of the second system resource to the first application can be sent to the first electronic device, so that the first electronic device can control the second application to access the first system resource or the second system resource according to the authorization status of the second system resource to the first application, wherein the first system resource and the second system resource are the same system resource.
[0028] In some alternative implementations, the first electronic device and the second electronic device are mutually trusted and connected.
[0029] By adopting this technical solution, global authorization status management can be performed on multiple trusted connected electronic devices.
[0030] In some alternative implementations, the application identifier of the second application of the second electronic device is consistent with the application identifier of the first application of the first electronic device.
[0031] By adopting this technical solution, the same application in the first electronic device and the second electronic device has the same application identifier, which facilitates unified permission management.
[0032] In some optional implementations, the permission management method further includes: synchronizing the second permission database with the first permission database of the first electronic device.
[0033] In some optional implementations, the permission management method further includes merging the authorization status in the second permission database based on the application identifier of the first application and the application identifier of the second application.
[0034] In some optional implementations, if a conflict occurs in the merging of authorization states in the second permission database, the permission management method further includes: displaying a conflict resolution interface; determining the conflicting authorization states in the second permission database based on the user's conflict resolution operation on the conflict resolution interface; and synchronizing the determined conflicting authorization states to the first permission database of the first electronic device.
[0035] By adopting this technical solution, the problem of conflicting authorization statuses that occur during the merging of multiple electronic devices can be resolved.
[0036] In some optional implementations, determining the authorization status of the second system resource to the first application includes: displaying the permission interaction interface of the first application to the second system resource; and determining the authorization status of the second system resource to the first application in the second permission database based on the user's permission determination operation in the permission interaction interface.
[0037] By adopting this technical solution, the authorization status of system resources for applications can be determined as either allowed or revoked based on user operations. The revoked status indicates that applications are not allowed to access system resources.
[0038] In some optional implementations, the access control method further includes: a second application of a second electronic device requests access to a second system resource, wherein the application identifier of the first application is consistent with the application identifier of the second application; obtaining the authorization status of the second system resource for the second application from a second access control database; and controlling the access of the second application to the second system resource based on the authorization status of the second system resource for the second application.
[0039] In some optional implementations, the permission management method further includes: if the second application does not exist in the second electronic device and the first application does not exist in the first electronic device, deleting the authorization status corresponding to the second application in the second permission database.
[0040] In some alternative implementations, the authorization status includes an application identifier field, a resource identifier field, a permission field, and / or an authorization status field.
[0041] A third aspect of this application discloses an electronic device, including a processor and a memory; the memory is used to store instructions; the processor is used to invoke the instructions in the memory to cause the electronic device to execute an access control method.
[0042] The fourth aspect of this application discloses a computer-readable storage medium storing at least one instruction, which, when executed by a processor, implements a permission management method.
[0043] The technical effects brought about by the second to fourth aspects can be found in the descriptions of the methods involved in the above-mentioned methods section, and will not be repeated here. Attached Figure Description
[0044] Figure 1 This is a schematic diagram illustrating an application scenario of a permission management method.
[0045] Figure 2 This is a system framework diagram of a permission management method provided in an embodiment of this application.
[0046] Figure 3 This is a schematic diagram illustrating an application scenario of a permission management method provided in an embodiment of this application.
[0047] Figure 4 This is a flowchart of a permission management method provided in an embodiment of this application.
[0048] Figure 5 This is a schematic diagram of an application provided in an embodiment of this application.
[0049] Figure 6 This is a schematic diagram of permission management provided in an embodiment of this application.
[0050] Figure 7 This is another permission management diagram provided in the embodiments of this application.
[0051] Figure 8 This is another permission management diagram provided in the embodiments of this application.
[0052] Figure 9 This is a flowchart of a permission management method provided in an embodiment of this application.
[0053] Figure 10 This is a flowchart of another permission management method provided in the embodiments of this application.
[0054] Figure 11 This is a schematic diagram of the structure of the electronic device provided in the embodiments of this application.
[0055] Figure 12 This is a software structure block diagram of the electronic device provided in the embodiments of this application. Detailed Implementation
[0056] It should be noted that in the embodiments of this application, "at least one" refers to one or more, and "more than one" refers to two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone, where A and B can be singular or plural. The terms "first," "second," "third," "fourth," etc. (if present) in the specification, claims, and drawings of this application are used to distinguish similar objects, not to describe a specific order or sequence.
[0057] Typically, an operating system (OS) manages resources based on independent physical devices. With a distributed operating system, users can access resources across devices. Because electronic devices store personal data, such as private information, a distributed operating system needs to perform permission verification and control when accessing resources across devices. If permission control is cumbersome, it can lead to a poor user experience and inefficient permission management.
[0058] Figure 1 This is a schematic diagram illustrating an application scenario of a permission management method.
[0059] like Figure 1 As shown, a first electronic device (Device 1) and a second electronic device (Device 2) constitute a distributed management system. Each electronic device includes a database storing authorization status (e.g., authorization records). Each electronic device's database stores the authorization status of applications accessing system resources (such as software services, hardware services, etc.) within those electronic devices. The distributed system synchronizes authorization status across databases; for example, authorization records on the first electronic device can be synchronized to the second electronic device. Software services include decoding services, encoding services, compression services, etc.; hardware services include camera services, sensor services, gyroscope services, etc.
[0060] like Figure 1The first and second electronic devices each have a communication application (APP) and a camera service. When a user uses the communication app on the first electronic device and needs to access the camera service on the second electronic device, the user needs to confirm through a user pop-up on both the first and second electronic devices to authorize the application to access the camera service.
[0061] To facilitate understanding, the problems in the above application scenarios will be explained.
[0062] In a distributed system with multiple electronic devices, application access permissions between devices are independent of each other. When an application on one electronic device accesses system resources on another electronic device, both devices require user confirmation via separate pop-up windows.
[0063] Once the communication application in the first electronic device has permission to access the Camera service in the second electronic device, the communication application in the first electronic device no longer has permission to access the Camera service in the first electronic device. If the communication application in the first electronic device needs to access the Camera service in the first electronic device, a user confirmation pop-up is required again.
[0064] Once the communication application on the first electronic device has permission to access the Camera service on the second electronic device, the communication application on the second electronic device cannot access the Camera service on the first electronic device. If the communication application on the second electronic device needs to access the Camera service on the first electronic device, a user confirmation prompt will be required again.
[0065] If a user needs to revoke authorization, a large amount of information needs to be retrieved and then revoked one by one.
[0066] When users use the same application on multiple devices, repeated authorizations can occur, affecting user experience and the efficiency of permission management.
[0067] Figure 2 This is a system framework diagram of a permission management method provided in an embodiment of this application.
[0068] like Figure 2As shown, the first electronic device (Device1) and the second electronic device (Device2) communicate through the distributed system communication layer and transmit data via this connection. The distributed system security layer manages user accounts and controls the security of user accounts on multiple electronic devices within the distributed system, allowing login to multiple electronic devices using a single user account. The first and second electronic devices can synchronize data through the distributed system database management layer. The databases of each electronic device can include application package databases and permission authorization databases. The data corresponding to the distributed system application package management service is stored in the application package database, and this service manages application packages within the distributed system.
[0069] In a distributed system, multiple electronic devices log into the same user account to form a mutual trust network. These devices all have the same application installed, such as a communication application. The application's vendor, application name, application signature, and application package name are identical on each device. An application identifier, generated from one or more of these identifiers, serves as the application's unique identifier. The same application has the same identifier on every electronic device in the distributed system, and the management mechanism for the same application is consistent across all devices. The distributed system permission management service stores data in a permission authorization database. This service controls and authorizes applications' access to system resources (such as application programming interfaces, APIs, etc.). For example, an application can access system resources when it has the necessary permissions, and is prevented from doing so when it lacks the required permissions. Electronic devices can display a user interface (UI) for user authorization interaction. The distributed application runtime management service manages the execution and requests of applications across multiple electronic devices in the distributed system, including remote method calls, remote data transmission, interface authentication, and triggering.
[0070] Figure 3 This is a schematic diagram illustrating an application scenario of a permission management method provided in an embodiment of this application.
[0071] like Figure 3As shown, a first electronic device (Device1) and a second electronic device (Device2) establish a mutual trust connection, forming a distributed management system. Each electronic device includes a database storing authorization status (authorization records). Each database stores the authorization status of applications accessing system resources on the electronic device. The distributed system synchronizes authorization status across databases; authorization records on the first electronic device can be synchronized to the second electronic device. When an application on the first electronic device first accesses system resources in the distributed system (including system resources in the electronic device to which the application belongs and system resources in electronic devices with the same user account as the application's electronic device), the distributed system confirms authorization through the user. The user decides whether to grant authorization for a given application to access a given system resource. After the user grants authorization for a given application to access a given system resource, the given application in the distributed system can access the given system resource without requiring multiple user confirmation prompts.
[0072] like Figure 3 As shown, when a communication application on a first electronic device first accesses the Camera service in a second electronic device within a distributed system, the second electronic device displays a permission interaction interface for the user to determine whether to authorize the communication application to access the Camera service. After the user grants authorization, the communication application in the distributed system can access the Camera service within the distributed system without requiring multiple authorizations. For example, when a communication application on a first electronic device first accesses the Camera service in a first electronic device within a distributed system, the first electronic device displays a permission interaction interface for the user to determine whether to authorize the communication application to access the Camera service. After the user grants authorization, the communication application in the first electronic device can access the Camera service in the second electronic device; the communication application in the second electronic device can also access the Camera service in the first electronic device, and vice versa, without requiring multiple authorizations.
[0073] If a user does not authorize a communication application to access the Camera service, the communication applications of various electronic devices in the distributed system cannot access the Camera service in the distributed system.
[0074] Figure 4 This is a flowchart of a permission management method provided in an embodiment of this application. The permission management method is applied to a distributed system. Specifically, the permission management method includes:
[0075] S401, A first application of a first electronic device requests access to a second system resource of a second electronic device.
[0076] In one embodiment of this application, the first electronic device and the second electronic device are mutually trusted and connected.
[0077] In one embodiment of this application, the mutual trust connection between the first electronic device and the second electronic device includes: the first electronic device and the second electronic device are connected in communication, and the user account of the first electronic device is the same as the user account of the second electronic device; and / or the first electronic device and the second electronic device are connected in communication in a local area network.
[0078] Specifically, multiple electronic devices in a distributed system can mutually trust and identify user accounts. These devices can connect via wired or wireless networks, and user account verification is required when they access the network. Each electronic device broadcasts its locally logged-in user account to other devices in the network. Upon receiving the broadcast user account, other devices match it with the logged-in user accounts of other devices. Electronic devices with matching user accounts belong to the same mutual trust network space. This constitutes a mutual trust connection between multiple electronic devices within the mutual trust network space.
[0079] Alternatively, the communication connection between multiple electronic devices on the same local area network can also be a mutual trust connection.
[0080] In one embodiment of this application, the application identifier of the second application of the second electronic device is consistent with the application identifier of the first application of the first electronic device.
[0081] The distributed system application package management service (i.e., the package management service) manages application identifiers, such as unique application identification codes (IDs), for applications across multiple electronic devices in a distributed system. The same application across multiple electronic devices in a distributed system will have the same application identifier in the application package management service. Figure 5 This is a schematic diagram of an application provided as an embodiment of this application. For example... Figure 5 As shown, both the first and second electronic devices have application A installed. The application identifier of application A in the first electronic device is consistent with the application identifier of application A in the second electronic device. Application A can be a communication application or an audio-visual application, etc. A distributed application package database (i.e., application package database) can be synchronized among multiple electronic devices. The record data for each application in the application package database can include the manufacturer, application name (e.g., ...). Figure 5 Application attributes of database records), application signatures (such as...) Figure 5 The signature attribute of the database record), and the application package name (e.g. Figure 5The first or second electronic device can generate an application identifier for the application based on one or more of the application's vendor, application name, application signature, and application package name, which serves as the application's unique identifier. That is, the application identifier may include, but is not limited to: vendor, application name, application signature, and / or application package name.
[0082] Application package management services can identify the application identifier of an application when it is installed on an electronic device.
[0083] The first application of the first electronic device can request to call the system application programming interface (API) of the first electronic device, and remotely call the second system resources of the second electronic device through the system API of the first electronic device.
[0084] S402, based on the second permission database of the second electronic device, the second electronic device determines the authorization status of the second system resources for the first application.
[0085] The authorization status of the second system resource to the first application indicates the permission of the first application to access the second system resource.
[0086] (1) The second electronic device obtains the authorization status of the second system resources for the first application from the second permission database of the second electronic device.
[0087] The second permission database may include the permission authorization database of the second electronic device or the distributed application permission database of the second electronic device. For example, the first electronic device includes a first permission database, which may include the permission authorization database of the first electronic device or the distributed application permission database of the first electronic device.
[0088] In one embodiment of this application, the authorization status includes an application identifier field, a resource identifier field, a permission field, and / or an authorization status field.
[0089] In one embodiment of this application, the permission management method further includes: synchronizing the first permission database of the first electronic device with the second permission database of the second electronic device. The first and second electronic devices can store authorization status and synchronization authorization status through a distributed application permission database of the two electronic devices, and can store application identifiers and synchronization application identifiers through a distributed application package database of the two electronic devices.
[0090] Optionally, the distributed system may also include a cloud server, and data synchronization can be performed between the first electronic device, the second electronic device, and the cloud server. For example, the first electronic device can synchronize its authorization status to the cloud server, and the second electronic device can synchronize its authorization status from the cloud server.
[0091] In one embodiment of this application, the permission management method further includes: a first electronic device merging the authorization status in a first permission database based on the application identifier of a first application and the application identifier of a second application; and / or a second electronic device merging the authorization status in a second permission database based on the application identifier of the first application and the application identifier of the second application. For example, if the authorization status of Perm1 corresponding to the second application in the second permission database is allowed, and the authorization status of Perm1 corresponding to the second application in the first permission database is empty, merging the two authorization statuses will result in the authorization status of Perm1 corresponding to the second application in the first permission database being allowed.
[0092] For example, a second electronic device receives the authorization status of one or more applications from a first electronic device. The second electronic device matches the received application authorization status with the authorization status of locally available applications, merging the authorization statuses of applications with the same application identifier. The second electronic device can then synchronize the merged application authorization status to other electronic devices in the distributed system, enabling the distributed electronic devices to control the applications' access to system resources based on the merged application authorization status.
[0093] In one embodiment of this application, if a conflict occurs in the authorization status of the first authorization database or the second authorization database, the authorization management method further includes: displaying a conflict resolution interface on either the first electronic device or the second electronic device; receiving a conflict resolution operation from the user on the conflict resolution interface; determining the conflicting authorization status in the corresponding authorization database based on the conflict resolution operation; and synchronizing the determined conflicting authorization status to the authorization databases of each electronic device in the distributed system.
[0094] The second electronic device can determine the permissions required for the first application to access the second system resources, and retrieve the authorization status field of the second system resources for the first application from the second permission database of the second electronic device based on the application identifier field, permission field, and / or resource identifier field of the first application. The authorization status field can include an allowed status or a revoked status; an allowed status indicates that the first application is allowed to access the second system resources; a revoked status indicates that the first application is not allowed to access the second system resources. The default value of the authorization status field is a revoked status.
[0095] (2) The second electronic device determines the authorization status of the second system resources for the first application.
[0096] In one embodiment of this application, the second electronic device determines the authorization status of the second system resource for the first application by: the second electronic device displaying an interactive interface for the first application's permissions to the second system resource; the second electronic device receiving a permission confirmation operation from the user on the permission interactive interface; and the second electronic device determining the authorization status of the second system resource for the first application in the second permission database based on the permission confirmation operation.
[0097] Specifically, the second electronic device can determine the authorization status of the second system resource for the first application; if the authorization status of the second system resource for the first application is revoked, the second electronic device displays the permission interaction interface of the first application for the second system resource; the user can perform permission confirmation operations on the permission interaction interface, such as changing the authorization status to allowed, confirming the authorization status to allowed, etc., and the second electronic device receives the permission confirmation operation from the user on the permission interaction interface; based on the permission confirmation operation, the second electronic device determines in the second permission database that the authorization status of the second system resource for the first application is allowed.
[0098] Optionally, users can determine the authorization status as either allowed or revoked through the authorization interaction interface. The authorization status may also include other statuses, such as the default status.
[0099] Optionally, the second electronic device can directly display the permission interaction interface of the first application to the second system resources; the user can perform permission confirmation operations on the permission interaction interface, such as determining the authorization status as an allowed state or a revoked state, and the second electronic device receives the permission confirmation operation from the user on the permission interaction interface; the second electronic device determines the authorization status of the second system resources to the first application as an allowed state or a revoked state in the second permission database according to the permission confirmation operation.
[0100] When the first application of the first electronic device accesses the second system resource API of the second electronic device, the second system resource API needs to perform a permission check. Since the authorization status of the first application to access the second system resource is revoked, user interaction will be performed to authorize the application, update the authorization status to allowed, and write the authorization status to the second permission database.
[0101] S403, the second electronic device sends the authorization status of the second system resources for the first application to the first electronic device.
[0102] After the second electronic device determines the authorization status of the second system resources for the first application, or after the user determines the authorization status of the second system resources for the first application, the second electronic device stores the determined authorization status of the second system resources for the first application in the second permission database, and sends the authorization status of the second system resources for the first application to the first electronic device through data synchronization between the second permission database and the first permission database.
[0103] The second electronic device can send the authorization status of the second system resources for the first application to other electronic devices in the distributed system.
[0104] In one embodiment of this application, the permission management method further includes: a first application requesting access to a first system resource of a first electronic device, wherein the first system resource is consistent with a second system resource; the first electronic device obtaining the authorization status of the first system resource for the first application from a first permission database; and the first electronic device controlling the first application's access to the first system resource based on the authorization status of the first system resource for the first application.
[0105] Understandably, the application identifiers of the first application and the second application are identical, the first system resource is identical to the second system resource, and the access permissions of the first application to the second system resource are the same as the access permissions of the first application to the first system resource. The first permission database stores the authorization status of the first system resource to the first application (data synchronized with the second permission database), and the authorization status of the first system resource to the first application is "allowed".
[0106] In one embodiment of this application, the permission management method further includes: a second application requesting access to a first system resource of a first electronic device, wherein the first system resource is consistent with the second system resource; the first electronic device obtaining the authorization status of the first system resource for the second application from a first permission database; and the first electronic device controlling the first application's access to the first system resource based on the authorization status of the first system resource for the second application.
[0107] Understandably, the application identifiers of the first application and the second application are identical, the first system resource is identical to the second system resource, and the access permissions of the first application to the second system resource are the same as the access permissions of the second application to the first system resource. The first permission database stores the authorization status of the first system resource to the second application (data synchronized with the second permission database), and the authorization status of the first system resource to the second application is "allowed".
[0108] In one embodiment of this application, the permission management method further includes: if a first application does not exist in a first electronic device and a second application does not exist in a second electronic device, the first electronic device deletes the authorization status corresponding to the first application from the first permission database, and the second electronic device deletes the authorization status corresponding to the second application from the second permission database. The first application and the second application can be applications with the same application identifier, that is, the first application and the second application are the same application.
[0109] Alternatively, the permission management method may also include: for any application in the distributed system, if no application exists in any of the various electronic devices in the distributed system, deleting the authorization status corresponding to any application in the permission database of each electronic device.
[0110] Alternatively, any electronic device in the distributed system can determine the authorization status to be revoked and synchronize the redefined authorization status to other electronic devices in the distributed system.
[0111] like Figure 6 The diagram shown is a permission management illustration provided in an embodiment of this application.
[0112] like Figure 6A first electronic device (Device1) and a second electronic device (Device2) are connected with mutual trust. Application A (the first application) on the first electronic device needs to access the Camera service (a second system resource) on the second electronic device via an API call. Application A makes a remote API call through the system API, requesting the second electronic device to call the Camera service API. The second electronic device checks the permission of Application A's request, determining the Perm1 permission required for Application A to access the Camera service on the second electronic device. The second electronic device reads the authorization status of Perm1 from its distributed application permission database based on the application identifier. If the authorization status of Perm1 is unauthorized (revoked), an authorization pop-up is displayed. Based on the user's authorization action in the authorization pop-up, the authorization status is redefined as allowed. The second electronic device writes the redefined authorization status into its distributed application permission database and synchronizes the authorization status in its distributed application permission database to the first electronic device's distributed application permission database. If the authorization status of Perm1 is allowed, the second electronic device allows Application A to call the Camera service API.
[0113] like Figure 7 The diagram shown illustrates another permission management method provided in this application embodiment. After the second electronic device synchronizes its authorization status to the distributed application permission database of the first electronic device, the first electronic device can control the access of the first application to the first system resources based on the authorization status in the distributed application permission database of the first electronic device.
[0114] Application A (first application) in the first electronic device makes local API calls through the system API to access the Camera service (first system resource) on the first electronic device. The first electronic device reads the authorization status of the permission (Perm1) for application A to access the Camera service on the first electronic device from the distributed application permission database of the first electronic device. If the permission Perm1 is authorized, application A is allowed to call the Camera service API on the first electronic device, and application A can access the Camera service on the first electronic device.
[0115] like Figure 8 The diagram shown illustrates another permission management method provided in this application embodiment. When the authorization status in the first permission database of the first electronic device is modified or changed, the first electronic device writes the modified or changed authorization status into the first permission database and synchronizes the authorization status in the first permission database to the second permission database of the second electronic device.
[0116] If the first electronic device or the user changes the authorization status to the revocation status, the first electronic device writes the modified authorization status into its distributed application permission database and synchronizes the first electronic device's distributed application permission database to the second electronic device's distributed application permission database.
[0117] Figure 9 This is a flowchart of a permission management method provided in an embodiment of this application. The permission management method is applied in a first electronic device. Specifically, the permission management method includes:
[0118] S901, the first application of the first electronic device requests access to the second system resource of the second electronic device.
[0119] The first electronic device and the second electronic device are mutually trusted and connected. Specifically, the first electronic device and the second electronic device are communicatively connected, and the user account of the first electronic device is the same as that of the second electronic device; and / or the first electronic device and the second electronic device are communicatively connected in a local area network; and / or the user account of the first electronic device is associated with the user account of the second electronic device.
[0120] For example, the first electronic device is a smartphone, and the second electronic device is a tablet computer. The user account logged in on the smartphone is the same as the user account logged in on the tablet computer, and there is a mutual trust connection between the smartphone and the tablet computer.
[0121] For example, if a smartphone and a tablet are on the same local area network, a trusted connection between them can be established.
[0122] The first application can remotely call the second system resource API of the second electronic device through the system API of the first electronic device to access the second system resource.
[0123] S902, receive the authorization status of the second system resources for the first application returned by the second electronic device.
[0124] The authorization status includes an application identifier field, a resource identifier field, a permission field, and / or an authorization status field. For example, the authorization status is "Communication Application: Camera = grant", where "Communication Application" is the application identifier field; "Camera" is the resource identifier field; "grant" is the authorization status, indicating an allowed status; the authorization status can also include "denied", indicating a revoked status. Another example is the authorization status "Application A: Perm1 = Allow", where "Application A" is the application identifier field, "Perm1" is the permission field, indicating application A's access rights to system resources, and "allow" is the authorization status field.
[0125] The second electronic device can synchronize the authorization status determined by the user to the first electronic device through the second permission database of the second electronic device and the first permission database of the first electronic device.
[0126] S903, the first permission database of the first electronic device stores the authorization status of the second system resources for the first application.
[0127] In one embodiment of this application, the permission management method further includes: synchronizing data between the first permission database and the second permission database of the second electronic device.
[0128] For example, the first electronic device synchronizes the authorization status in the second permission database of the second electronic device to the first permission database.
[0129] Optionally, the first electronic device, the second electronic device, and the cloud server establish a mutual trust connection, and the first electronic device and the cloud server synchronize data (such as authorization status).
[0130] The application identifier of the second application on the second electronic device is consistent with the application identifier of the first application on the first electronic device. Understandably, the first application and the second application are the same application on different electronic devices.
[0131] The permission management method also includes merging the authorization status in the first permission database based on the application identifier of the first application and the application identifier of the second application of the second electronic device.
[0132] For example, if the first application and the second application are the same application, and the application identifier of the first application matches the application identifier of the second application, the authorization status of the applications with the same application identifier in the first permission database and the second permission database can be merged. For example, if the authorization status of the second application corresponding to Perm1 in the second permission database is "allowed," while the authorization status of the second application corresponding to Perm1 in the first permission database is "empty," merging the two authorization statuses will result in the authorization status of the second application corresponding to Perm1 in the first permission database being "allowed."
[0133] If a conflict occurs in the authorization status merging in the first permission database, the permission management method further includes: displaying a conflict resolution interface; receiving a user's conflict resolution operation on the conflict resolution interface; determining the conflicting authorization status in the first permission database based on the conflict resolution operation; and synchronizing the determined conflicting authorization status to the second permission database of the second electronic device.
[0134] For example, if the authorization status in the first permission database is "Application A: Perm1 = Allowed", and the authorization status in the second permission database is "Application A: Perm1 = Revoked", then the authorization status of Application A for permission Perm1 in the two permission databases will conflict. The first electronic device displays a conflict resolution interface to the user; the user selects an allow authorization status in the conflict resolution interface, and the first electronic device receives the user's conflict resolution operation in the conflict resolution interface; based on the user's selection of the allow authorization status, the first electronic device re-determines the conflicting authorization status as an allow status; and synchronizes the authorization status of Application A for permission Perm1 to the second permission database of the second electronic device.
[0135] In one embodiment of this application, after the first permission database of the first electronic device stores the authorization status of the second system resources for the first application, the permission management method further includes: the first application of the first electronic device requests access to the first system resources of the first electronic device, the first system resources being consistent with the second system resources; and obtaining the authorization status of the first system resources for the first application from the first permission database.
[0136] After the first electronic device obtains the authorization status of the first system resources for the first application from the first permission database, the permission management method further includes: controlling the first application's access to the first system resources based on the authorization status of the first system resources for the first application.
[0137] For example, application A of a first electronic device requests access to the Camera service of the first electronic device, which is the same as the Camera service of a second electronic device; the first electronic device obtains the authorization status of application A of the first electronic device for the Camera service of the first electronic device from a first permission database; the first electronic device allows or prohibits application A of the first electronic device from accessing the Camera service of the first electronic device according to the authorization status of application A of the first electronic device for the Camera service of the first electronic device.
[0138] In one embodiment of this application, after the first permission database of the first electronic device stores the authorization status of the second system resource to the first application, the permission management method further includes: receiving an access request from the second application of the second electronic device to the first system resource of the first electronic device, wherein the first system resource is consistent with the second system resource and the application identifier of the first application is consistent with the application identifier of the second application; obtaining the authorization status of the first system resource to the second application from the first permission database; and controlling the access of the second application to the first system resource according to the authorization status of the first system resource to the second application.
[0139] For example, a first electronic device receives an access request from application A of a second electronic device to the camera service of the first electronic device. The camera service of the first electronic device is the same as that of the second electronic device, and application A of the first electronic device is the same as that of the second electronic device, that is, the application identifier of application A of the first electronic device is consistent with that of application A of the second electronic device. The first electronic device reads the authorization status of application A of the second electronic device to the camera service of the first electronic device from a first permission database. The first electronic device allows or prohibits application A of the second electronic device from accessing the camera service of the first electronic device according to application A of the second electronic device.
[0140] In one embodiment of this application, the permission management method further includes: if the first electronic device does not have a first application and the second electronic device does not have a second application that is the same as the first application, deleting the authorization status corresponding to the first application from the first permission database.
[0141] For example, if a user deletes application A on both a first electronic device and a second electronic device, the first electronic device deletes the authorization status corresponding to application A from the first permission database; the second electronic device deletes the authorization status corresponding to application A from the second permission database.
[0142] Figure 10 This is a flowchart of another permission management method provided in an embodiment of this application. The permission management method is applied to a second electronic device. Specifically, the permission management method includes:
[0143] S1001, Receive a request from the first application of the first electronic device to access the second system resources of the second electronic device.
[0144] The first electronic device and the second electronic device are mutually trusted and connected. Specifically, the first electronic device and the second electronic device are communicatively connected, and the user account of the first electronic device is the same as that of the second electronic device; and / or the first electronic device and the second electronic device are communicatively connected in a local area network.
[0145] Specifically, multiple electronic devices in a distributed system can perform mutual trust identification of user accounts. A second electronic device can connect to a first electronic device via a wired or wireless network. When the second electronic device accesses the network, user account verification is required. The second electronic device broadcasts its locally logged-in user account to the first electronic device in the network. After receiving the broadcast user account, the first electronic device matches the second electronic device with the logged-in user account. Two electronic devices with matching logged-in user accounts belong to the same mutually trusted network space.
[0146] Alternatively, the communication connection between multiple electronic devices on the same local area network can also be a mutual trust connection.
[0147] S1002, obtain the authorization status of the second system resources for the first application from the second permission database of the second electronic device.
[0148] The authorization status includes the application identifier field, resource identifier field, permission field, and / or authorization status field.
[0149] For example, the second electronic device can obtain the authorization status of the first electronic device's application A (first application) for the Camera service (second system resource) in the second electronic device from the second permission database. If the authorization status is "Application A: Perm1 = Revoked", it means that the first electronic device's application A does not have permission to access the Camera service in the second electronic device.
[0150] S1003, Determine the authorization status of the second system resources for the first application.
[0151] As in the example above, if application A of the first electronic device does not have permission to access the Camera service on the second electronic device, the second electronic device needs to re-determine the authorization status of application A of the first electronic device for the Camera service on the second electronic device. For example, the authorization status of application A of the first electronic device for the Camera service on the second electronic device can be re-determined to an allowed status.
[0152] Determining the authorization status of the second system resource for the first application includes: displaying the permission interaction interface of the first application for the second system resource; receiving the user's permission confirmation operation on the permission interaction interface; and determining the authorization status of the second system resource for the first application in the second permission database based on the permission confirmation operation.
[0153] For example, the second electronic device displays an interactive interface to the user showing the permission of application A of the first electronic device to the Camera service in the second electronic device; the user determines the authorization status of application A of the first electronic device to the Camera service in the second electronic device to be allowed in the permission interactive interface, and the second electronic device receives the permission determination operation from the user in the permission interactive interface; based on the user's determination of the allowed authorization status, the second electronic device re-determines the authorization status of application A of the first electronic device to the Camera service in the second electronic device to be allowed in the second permission database.
[0154] S1004, the authorization status of the second system resources for the first application is sent to the first electronic device.
[0155] Specifically, the second electronic device can send the authorization status of the second system resources for the first application to the first electronic device through data synchronization between the second permission database and the second permission database.
[0156] In one embodiment of this application, the permission management method further includes: synchronizing the second permission database with the first permission database of the first electronic device.
[0157] Optionally, the distributed system may also include a cloud server, and data synchronization can be performed between the first electronic device, the second electronic device, and the cloud server. For example, the second electronic device can synchronize its authorization status to the cloud server, and the second electronic device can also synchronize its authorization status from the cloud server.
[0158] The application identifier of the second application of the second electronic device is consistent with the application identifier of the first application of the first electronic device.
[0159] In one embodiment of this application, the permission management method further includes: merging the authorization status in the second permission database according to the application identifier of the first application and the application identifier of the second application.
[0160] If a conflict occurs in the merging of authorization states in the second permission database, the permission management method further includes: displaying a conflict resolution interface; receiving a user's conflict resolution operation on the conflict resolution interface; determining the conflicting authorization state in the second permission database based on the conflict resolution operation; and synchronizing the determined conflicting authorization state to the first permission database of the first electronic device.
[0161] In one embodiment of this application, the permission management method further includes: a second application of a second electronic device requests access to a second system resource, wherein the application identifier of the first application is consistent with the application identifier of the second application; obtaining the authorization status of the first system resource for the first application from a second permission database; and controlling the access of the second application to the second system resource according to the authorization status of the second system resource for the second application.
[0162] For example, application A of the second electronic device requests access to the Camera service of the second electronic device. The Camera service of the first electronic device is the same as the Camera service of the second electronic device, and application A of the second electronic device is the same as application A of the first electronic device, that is, the application identifier of application A of the second electronic device is consistent with the application identifier of application A of the first electronic device. The second electronic device obtains the authorization status of application A of the second electronic device for the Camera service of the second electronic device from the second permission database. The second electronic device allows or prohibits application A of the second electronic device from accessing the Camera service of the second electronic device according to the authorization status of application A of the second electronic device for the Camera service of the second electronic device.
[0163] In one embodiment of this application, the permission management method further includes: if the second electronic device does not have a second application and the first electronic device does not have a first application that is the same as the second application, deleting the authorization status corresponding to the second application from the second permission database.
[0164] Figure 11 This is a schematic diagram of the structure of the electronic device 100 provided in the embodiments of this application. The electronic device 100 may include a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, a headphone jack 170D, a sensor module 180, buttons 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and a subscriber identification module (SIM) card interface 195, etc. The sensor module 180 may include a pressure sensor 180A, a gyroscope sensor 180B, a barometric pressure sensor 180C, a magnetic sensor 180D, an accelerometer sensor 180E, a distance sensor 180F, a proximity sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, etc.
[0165] It is understood that the structures illustrated in the embodiments of this application do not constitute a specific limitation on the electronic device 100. In other embodiments of this application, the electronic device 100 may include more or fewer components than illustrated, or combine some components, or split some components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.
[0166] Processor 110 may include one or more processing units, such as: application processor (AP), modem processor, graphics processing unit (GPU), image signal processor (ISP), controller, memory, video codec, digital signal processor (DSP), baseband processor, and / or neural network processing unit (NPU), etc. Different processing units may be independent devices or integrated into one or more processors.
[0167] The controller can be the nerve center and command center of the electronic device 100. The controller can generate operation control signals according to the instruction opcode and timing signals to complete the control of fetching and executing instructions.
[0168] The processor 110 may also include a memory for storing instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. This memory can store instructions or data that the processor 110 has just used or that are used repeatedly. If the processor 110 needs to use the instruction or data again, it can retrieve it directly from the memory. This avoids repeated accesses, reduces the waiting time of the processor 110, and thus improves the efficiency of the system.
[0169] In some embodiments, the processor 110 may include one or more interfaces. Interfaces may include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface, etc.
[0170] The I2C interface is a bidirectional synchronous serial bus, including a serial data line (SDA) and a serial clock line (SCL). In some embodiments, the processor 110 may include multiple I2C buses. The processor 110 can couple to the touch sensor 180K, charger, flash, camera 193, etc., through different I2C bus interfaces. For example, the processor 110 can couple to the touch sensor 180K through the I2C interface, enabling the processor 110 and the touch sensor 180K to communicate through the I2C bus interface, thereby realizing the touch function of the electronic device 100.
[0171] The I2S interface can be used for audio communication. In some embodiments, the processor 110 may include multiple I2S buses. The processor 110 can be coupled to the audio module 170 via the I2S bus to enable communication between the processor 110 and the audio module 170. In some embodiments, the audio module 170 can transmit audio signals to the wireless communication module 160 via the I2S interface to enable the function of answering phone calls through a Bluetooth headset.
[0172] The PCM interface can also be used for audio communication, sampling, quantizing, and encoding analog signals. In some embodiments, the audio module 170 and the wireless communication module 160 can be coupled via the PCM bus interface. In some embodiments, the audio module 170 can also transmit audio signals to the wireless communication module 160 via the PCM interface, enabling the function of answering phone calls through a Bluetooth headset. Both the I2S interface and the PCM interface can be used for audio communication.
[0173] The UART interface is a universal serial data bus used for asynchronous communication. This bus can be a bidirectional communication bus. It converts the data to be transmitted between serial and parallel communication. In some embodiments, the UART interface is typically used to connect the processor 110 and the wireless communication module 160. For example, the processor 110 communicates with the Bluetooth module in the wireless communication module 160 via the UART interface to implement Bluetooth functionality. In some embodiments, the audio module 170 can transmit audio signals to the wireless communication module 160 via the UART interface to enable music playback through Bluetooth headphones.
[0174] The MIPI interface can be used to connect the processor 110 to peripheral devices such as the display screen 194 and the camera 193. The MIPI interface includes a camera serial interface (CSI) and a display serial interface (DSI). In some embodiments, the processor 110 and the camera 193 communicate via the CSI interface to enable the electronic device 100 to capture images. The processor 110 and the display screen 194 communicate via the DSI interface to enable the electronic device 100 to display images.
[0175] The GPIO interface can be configured via software. It can be configured as a control signal or a data signal. In some embodiments, the GPIO interface can be used to connect the processor 110 to a camera 193, a display screen 194, a wireless communication module 160, an audio module 170, a sensor module 180, etc. The GPIO interface can also be configured as an I2C interface, an I2S interface, a UART interface, a MIPI interface, etc.
[0176] USB port 130 is a USB standard compliant interface, specifically a Mini USB port, Micro USB port, USB Type-C port, etc. USB port 130 can be used to connect a charger to charge electronic device 100, and can also be used for data transfer between electronic device 100 and peripheral devices. It can also be used to connect headphones for audio playback. This interface can also be used to connect other electronic devices, such as AR devices.
[0177] It is understood that the interface connection relationships between the modules illustrated in the embodiments of this application are merely illustrative and do not constitute a structural limitation on the electronic device 100. In other embodiments of this application, the electronic device 100 may also employ different interface connection methods or combinations of multiple interface connection methods as described in the above embodiments.
[0178] The charging management module 140 receives charging input from a charger. The charger can be a wireless charger or a wired charger. In some wired charging embodiments, the charging management module 140 receives charging input from the wired charger via the USB interface 130. In some wireless charging embodiments, the charging management module 140 receives wireless charging input via the wireless charging coil of the electronic device 100. While charging the battery 142, the charging management module 140 can also supply power to the electronic device via the power management module 141.
[0179] The power management module 141 connects the battery 142, the charging management module 140, and the processor 110. The power management module 141 receives input from the battery 142 and / or the charging management module 140, providing power to the processor 110, internal memory 121, external memory, display screen 194, camera 193, and wireless communication module 160, etc. The power management module 141 can also monitor parameters such as battery capacity, battery cycle count, and battery health status (leakage current, impedance). In some other embodiments, the power management module 141 may also be located within the processor 110. In other embodiments, the power management module 141 and the charging management module 140 may be located in the same device.
[0180] The wireless communication function of electronic device 100 can be realized through antenna 1, antenna 2, mobile communication module 150, wireless communication module 160, modem processor and baseband processor, etc.
[0181] Antenna 1 and antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in electronic device 100 can be used to cover one or more communication frequency bands. Different antennas can also be multiplexed to improve antenna utilization. For example, antenna 1 can be multiplexed as a diversity antenna for a wireless local area network. In some other embodiments, the antennas can be used in conjunction with tuning switches.
[0182] The mobile communication module 150 can provide solutions for wireless communication, including 2G / 3G / 4G / 5G, applied to the electronic device 100. The mobile communication module 150 may include at least one filter, switch, power amplifier, low noise amplifier (LNA), etc. The mobile communication module 150 can receive electromagnetic waves via antenna 1, and perform filtering, amplification, and other processing on the received electromagnetic waves before transmitting them to a modem processor for demodulation. The mobile communication module 150 can also amplify the signal modulated by the modem processor and convert it into electromagnetic waves for radiation via antenna 1. In some embodiments, at least some functional modules of the mobile communication module 150 may be housed in the processor 110. In some embodiments, at least some functional modules of the mobile communication module 150 and at least some modules of the processor 110 may be housed in the same device.
[0183] The modem processor may include a modulator and a demodulator. The modulator modulates the low-frequency baseband signal to be transmitted into a mid-to-high frequency signal. The demodulator demodulates the received electromagnetic wave signal into a low-frequency baseband signal. The demodulator then transmits the demodulated low-frequency baseband signal to the baseband processor for processing. After processing by the baseband processor, the low-frequency baseband signal is transmitted to the application processor. The application processor outputs sound signals through an audio device (not limited to speaker 170A, receiver 170B, etc.) or displays images or videos through the display screen 194. In some embodiments, the modem processor may be a separate device. In other embodiments, the modem processor may be independent of the processor 110 and may be housed in the same device as the mobile communication module 150 or other functional modules.
[0184] The wireless communication module 160 can provide solutions for wireless communication applications on the electronic device 100, including wireless local area networks (WLANs) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), and infrared (IR) technologies. The wireless communication module 160 can be one or more devices integrating at least one communication processing module. The wireless communication module 160 receives electromagnetic waves via antenna 2, performs frequency modulation and filtering of the electromagnetic wave signals, and sends the processed signal to processor 110. The wireless communication module 160 can also receive signals to be transmitted from processor 110, perform frequency modulation and amplification, and convert them into electromagnetic waves for radiation via antenna 2.
[0185] In some embodiments, antenna 1 of electronic device 100 is coupled to mobile communication module 150, and antenna 2 is coupled to wireless communication module 160, enabling electronic device 100 to communicate with networks and other devices via wireless communication technology. The wireless communication technology may include Global System for Mobile Communications (GSM), General Packet Radio Service (GPRS), Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), Time-Division Code Division Multiple Access (TD-SCDMA), Long Term Evolution (LTE), 5G (the 5th Generation of wireless communication system), BT, GNSS, WLAN, NFC, FM, and / or IR technologies, etc. The GNSS may include the Global Positioning System (GPS), the Global Navigation Satellite System (GLONASS), the BeiDou Navigation Satellite System (BDS), the Quasi-Zenith Satellite System (QZSS), and / or satellite-based augmentation systems (SBAS).
[0186] Electronic device 100 implements display functions through a GPU, a display screen 194, and an application processor. The GPU is a microprocessor for image processing, connected to the display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations and for graphics rendering. Processor 110 may include one or more GPUs, which execute program instructions to generate or modify display information.
[0187] Display screen 194 is used to display images, videos, etc. Display screen 194 includes a display panel. The display panel may be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a miniature LED, a microLED, a quantum dot light-emitting diode (QLED), etc. In some embodiments, electronic device 100 may include one or N displays 194, where N is a positive integer greater than 1.
[0188] Electronic device 100 can perform shooting functions through ISP, camera 193, video codec, GPU, display 194 and application processor.
[0189] The ISP (Image Signal Processor) is used to process data fed back from the camera 193. For example, when taking a picture, the shutter is opened, and light is transmitted through the lens to the camera's photosensitive element. The light signal is converted into an electrical signal, and the camera's photosensitive element transmits the electrical signal to the ISP for processing, transforming it into an image visible to the naked eye. The ISP can also perform algorithmic optimization of image noise, brightness, and skin tone. The ISP can also optimize parameters such as exposure and color temperature of the shooting scene. In some embodiments, the ISP can be set in the camera 193.
[0190] Camera 193 is used to capture still images or videos. An object is projected onto a photosensitive element by generating an optical image through the lens. The photosensitive element can be a charge-coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the light signal into an electrical signal, which is then passed to an ISP for conversion into a digital image signal. The ISP outputs the digital image signal to a DSP for processing. The DSP converts the digital image signal into image signals in standard RGB, YUV, or other formats. In some embodiments, the electronic device 100 may include one or N cameras 193, where N is a positive integer greater than 1.
[0191] Digital signal processors (DSPs) are used to process digital signals. Besides digital image signals, they can also process other digital signals. For example, when electronic device 100 selects a frequency, the DSP can perform Fourier transforms on the frequency energy.
[0192] Video codecs are used to compress or decompress digital video. Electronic device 100 may support one or more video codecs. Thus, electronic device 100 can play or record videos in various encoding formats, such as Moving Picture Experts Group (MPEG) 1, MPEG2, MPEG3, MPEG4, etc.
[0193] An NPU (Neural Processing Unit) is a computational processor for neural networks (NNs). By borrowing the structure of biological neural networks, such as the transmission patterns between neurons in the human brain, it can rapidly process input information and continuously learn on its own. NPUs enable intelligent cognitive applications in electronic devices, such as image recognition, facial recognition, speech recognition, and text understanding.
[0194] The external storage interface 120 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the electronic device 100. The external memory card communicates with the processor 110 through the external storage interface 120 to perform data storage functions. For example, music, video, and other files can be saved on the external memory card.
[0195] Internal memory 121 can be used to store computer executable program code, which includes instructions. Processor 110 executes various functional applications and data processing of electronic device 100 by running the instructions stored in internal memory 121. Internal memory 121 may include a program storage area and a data storage area. The program storage area may store the operating system, at least one application program required for a function (such as sound playback, image playback, etc.), etc. The data storage area may store data created during the use of electronic device 100 (such as audio data, phonebook, etc.). Furthermore, internal memory 121 may include high-speed random access memory and may also include non-volatile memory, such as at least one disk storage device, flash memory device, universal flash storage (UFS), etc.
[0196] Electronic device 100 can implement audio functions, such as music playback and recording, through audio module 170, speaker 170A, receiver 170B, microphone 170C, headphone jack 170D, and application processor.
[0197] The audio module 170 is used to convert digital audio information into analog audio signals for output, and also to convert analog audio input into digital audio signals. The audio module 170 can also be used for encoding and decoding audio signals. In some embodiments, the audio module 170 may be located in the processor 110, or some functional modules of the audio module 170 may be located in the processor 110.
[0198] The speaker 170A, also known as a "loudspeaker," is used to convert audio electrical signals into sound signals. The electronic device 100 can listen to music or make hands-free calls through the speaker 170A.
[0199] The receiver 170B, also known as the "earpiece," is used to convert audio electrical signals into sound signals. When the electronic device 100 answers a telephone call or voice message, the receiver 170B can be brought close to the ear to listen to the voice.
[0200] Microphone 170C, also known as a "microphone" or "voice transducer," is used to convert sound signals into electrical signals. When making a phone call or sending a voice message, the user can speak by bringing their mouth close to microphone 170C, inputting the sound signal into microphone 170C. Electronic device 100 may have at least one microphone 170C. In some embodiments, electronic device 100 may have two microphones 170C, which, in addition to collecting sound signals, can also perform noise reduction. In other embodiments, electronic device 100 may also have three, four, or more microphones 170C, which can collect sound signals, reduce noise, identify the sound source, and perform directional recording, etc.
[0201] The 170D headphone jack is used to connect wired headphones. The 170D headphone jack can be a USB 130 interface or a 3.5mm Open Mobile Terminal Platform (OMTP) standard interface, a CTIA (Cellular Telecommunications Industry Association of the USA) standard interface.
[0202] Pressure sensor 180A is used to sense pressure signals and convert them into electrical signals. In some embodiments, pressure sensor 180A can be disposed on display screen 194. There are many types of pressure sensors 180A, such as resistive pressure sensors, inductive pressure sensors, and capacitive pressure sensors. A capacitive pressure sensor may include at least two parallel plates with conductive material. When force is applied to pressure sensor 180A, the capacitance between the electrodes changes. Electronic device 100 determines the pressure intensity based on the change in capacitance. When a touch operation is applied to display screen 194, electronic device 100 detects the intensity of the touch operation based on pressure sensor 180A. Electronic device 100 can also calculate the touch position based on the detection signal from pressure sensor 180A. In some embodiments, touch operations applied to the same touch position but with different touch operation intensities can correspond to different operation commands. For example, when a touch operation with an intensity less than a first pressure threshold is applied to the SMS application icon, a command to view an SMS is executed. When a touch operation with an intensity greater than or equal to the first pressure threshold is applied to the SMS application icon, a command to create a new SMS is executed.
[0203] The gyroscope sensor 180B can be used to determine the motion attitude of the electronic device 100. In some embodiments, the gyroscope sensor 180B can determine the angular velocity of the electronic device 100 about three axes (i.e., the x, y, and z axes). The gyroscope sensor 180B can be used for image stabilization. For example, when the shutter is pressed, the gyroscope sensor 180B detects the angle of the shake of the electronic device 100, calculates the distance that the lens module needs to compensate based on the angle, and allows the lens to counteract the shake of the electronic device 100 by moving in the opposite direction, thus achieving image stabilization. The gyroscope sensor 180B can also be used in navigation and motion-sensing game scenarios.
[0204] The barometric pressure sensor 180C is used to measure air pressure. In some embodiments, the electronic device 100 calculates altitude using the air pressure value measured by the barometric pressure sensor 180C to assist in positioning and navigation.
[0205] The magnetic sensor 180D includes a Hall sensor. The electronic device 100 can use the magnetic sensor 180D to detect the opening and closing of the flip cover. In some embodiments, when the electronic device 100 is a flip phone, the electronic device 100 can detect the opening and closing of the flip cover using the magnetic sensor 180D. Then, based on the detected opening and closing state of the cover or the flip cover, features such as automatic flip unlocking can be set.
[0206] The 180E accelerometer can detect the magnitude of acceleration of electronic device 100 in various directions (typically three axes). When electronic device 100 is stationary, it can detect the magnitude and direction of gravity. It can also be used to identify the posture of electronic devices and applied to applications such as screen orientation switching and pedometers.
[0207] A distance sensor 180F is used to measure distance. Electronic device 100 can measure distance via infrared or laser. In some embodiments, during a shooting scene, electronic device 100 can utilize the distance sensor 180F to measure distance for rapid focusing.
[0208] The proximity sensor 180G may include, for example, a light-emitting diode (LED) and a light detector, such as a photodiode. The LED may be an infrared LED. The electronic device 100 emits infrared light outward through the LED. The electronic device 100 uses the photodiode to detect infrared reflected light from nearby objects. When sufficient reflected light is detected, it can be determined that there is an object near the electronic device 100. When insufficient reflected light is detected, the electronic device 100 can determine that there is no object near the electronic device 100. The electronic device 100 may use the proximity sensor 180G to detect when a user holds the electronic device 100 close to their ear for a call, so as to automatically turn off the screen to save power. The proximity sensor 180G can also be used in holster mode and pocket mode for automatic unlocking and locking of the screen.
[0209] The ambient light sensor 180L is used to sense the brightness of ambient light. The electronic device 100 can adaptively adjust the brightness of the display screen 194 based on the sensed ambient light brightness. The ambient light sensor 180L can also be used to automatically adjust the white balance when taking pictures. The ambient light sensor 180L can also work with the proximity sensor 180G to detect whether the electronic device 100 is in a pocket to prevent accidental touches.
[0210] The fingerprint sensor 180H is used to collect fingerprints. The electronic device 100 can utilize the characteristics of the collected fingerprints to achieve fingerprint unlocking, accessing application locks, taking photos with fingerprints, answering calls with fingerprints, etc.
[0211] Temperature sensor 180J is used to detect temperature. In some embodiments, electronic device 100 uses the temperature detected by temperature sensor 180J to execute a temperature handling strategy. For example, when the temperature reported by temperature sensor 180J exceeds a threshold, electronic device 100 performs thermal protection by reducing the performance of a processor located near temperature sensor 180J to reduce power consumption. In other embodiments, when the temperature is below another threshold, electronic device 100 heats battery 142 to prevent abnormal shutdown of electronic device 100 due to low temperature. In still other embodiments, when the temperature is below yet another threshold, electronic device 100 boosts the output voltage of battery 142 to prevent abnormal shutdown due to low temperature.
[0212] Touch sensor 180K, also known as a "touch panel," can be located on display screen 194. The touch sensor 180K and display screen 194 together form a touchscreen, also known as a "touch screen." Touch sensor 180K detects touch operations applied to or near it. The touch sensor can transmit the detected touch operation to the application processor to determine the type of touch event. Visual output related to the touch operation can be provided through display screen 194. In other embodiments, touch sensor 180K may also be located on the surface of electronic device 100, in a different position than display screen 194.
[0213] The bone conduction sensor 180M can acquire vibration signals. In some embodiments, the bone conduction sensor 180M can acquire vibration signals from the vibrating bone segments of the human vocal cords. The bone conduction sensor 180M can also contact the human pulse to receive blood pressure signals. In some embodiments, the bone conduction sensor 180M can also be incorporated into headphones to form bone conduction headphones. The audio module 170 can parse the voice signals from the vibrating bone segments of the vocal cords acquired by the bone conduction sensor 180M to realize voice functionality. The application processor can parse heart rate information from the blood pressure signals acquired by the bone conduction sensor 180M to realize heart rate detection functionality.
[0214] Buttons 190 include a power button, volume buttons, etc. Buttons 190 can be mechanical buttons or touch-sensitive buttons. Electronic device 100 can receive button input and generate key signal inputs related to user settings and function control of electronic device 100.
[0215] Motor 191 can generate vibration alerts. Motor 191 can be used for incoming call vibration alerts or for touch vibration feedback. For example, different vibration feedback effects can correspond to touch operations performed on different applications (such as taking photos, playing audio, etc.). Motor 191 can also correspond to different vibration feedback effects for touch operations performed on different areas of the display screen 194. Different application scenarios (such as time reminders, receiving messages, alarm clocks, games, etc.) can also correspond to different vibration feedback effects. The touch vibration feedback effect can also be customized.
[0216] Indicator 192 can be an indicator light, used to indicate charging status, power changes, or to indicate messages, missed calls, notifications, etc.
[0217] The SIM card interface 195 is used to connect a SIM card. The SIM card can be inserted into or removed from the SIM card interface 195 to make contact with and separate from the electronic device 100. The electronic device 100 can support one or N SIM card interfaces, where N is a positive integer greater than 1. The SIM card interface 195 can support Nano SIM cards, Micro SIM cards, SIM cards, etc. Multiple cards can be inserted into the same SIM card interface 195 simultaneously. The multiple cards can be of the same or different types. The SIM card interface 195 is also compatible with different types of SIM cards. The SIM card interface 195 is also compatible with external memory cards. The electronic device 100 interacts with the network through the SIM card to realize functions such as calls and data communication. In some embodiments, the electronic device 100 uses an eSIM, i.e., an embedded SIM card. The eSIM card can be embedded in the electronic device 100 and cannot be separated from the electronic device 100.
[0218] The software system of electronic device 100 can adopt a layered architecture, event-driven architecture, microkernel architecture, microservice architecture, or cloud architecture. This application embodiment uses the layered architecture Android system as an example to exemplify the software structure of electronic device 100.
[0219] Figure 12 This is a software structure block diagram of the electronic device 100 provided in this application embodiment. The layered architecture divides the software into several layers, each with a clear role and division of labor. Layers communicate with each other through software interfaces. In some embodiments, the Android system is divided into four layers, from top to bottom: the application layer, the application framework layer, the Android runtime and system libraries, and the kernel layer. The application layer may include a series of application packages.
[0220] like Figure 12 As shown, the application package may include applications such as camera, gallery, calendar, call, map, navigation, WLAN, Bluetooth, music, video, and SMS.
[0221] The application framework layer provides application programming interfaces (APIs) and a programming framework for applications in the application layer. The application framework layer includes some predefined functions.
[0222] like Figure 12 As shown, the application framework layer may include a window manager, content provider, view system, phone manager, resource manager, notification manager, etc.
[0223] The window manager is used to manage windowed applications. It can retrieve screen size, determine the presence of a status bar, lock the screen, and capture screenshots, among other things.
[0224] Content providers store and retrieve data, making that data accessible to applications. This data may include videos, images, audio, made and received phone calls, browsing history and bookmarks, phone books, etc.
[0225] A view system includes visual controls, such as controls for displaying text and controls for displaying images. View systems can be used to build applications. A display interface can consist of one or more views. For example, a display interface including a text notification icon could include views for displaying text and views for displaying images.
[0226] The phone manager is used to provide communication functions for electronic device 100. For example, it manages call status (including connection and disconnection).
[0227] The file explorer provides applications with various resources, such as localized strings, icons, images, layout files, video files, and more.
[0228] The notification manager allows applications to display notifications in the status bar. These notifications can be used to deliver informational messages and can disappear automatically after a short pause, requiring no user interaction. For example, the notification manager can be used to notify users of completed downloads or message alerts. The notification manager can also display notifications as icons or scrolling text in the top status bar, such as notifications from background applications, or as dialog boxes on the screen. Examples include displaying text messages in the status bar, emitting sounds, vibrating electronic devices, and flashing indicator lights.
[0229] The Android Runtime consists of core libraries and a virtual machine. The Android runtime is responsible for the scheduling and management of the Android system.
[0230] The core library consists of two parts: one part is the functionalities that need to be called by the Java language, and the other part is the Android core library.
[0231] The application layer and application framework layer run in a virtual machine. The virtual machine executes the Java files of the application layer and application framework layer as binary files. The virtual machine is used to perform functions such as object lifecycle management, stack management, thread management, security and exception management, and garbage collection.
[0232] System libraries can include multiple functional modules. For example: surface manager, media libraries, 3D graphics processing libraries (e.g., OpenGL ES), 2D graphics engines (e.g., SGL), etc.
[0233] The Surface Manager is used to manage the display subsystem and provides the blending of 2D and 3D layers for multiple applications.
[0234] The media library supports playback and recording of various common audio and video formats, as well as still image files. It supports multiple audio and video encoding formats, such as MPEG4, H.264, MP3, AAC, AMR, JPG, and PNG.
[0235] The 3D graphics processing library is used to implement 3D graphics drawing, image rendering, compositing, and layer processing.
[0236] A 2D graphics engine is a graphics engine for 2D drawing.
[0237] The kernel layer is the layer between hardware and software. The kernel layer contains at least the display driver, camera driver, audio driver, and sensor driver.
[0238] If the modules integrated in the electronic device 100 are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments can also be implemented by instructing related hardware through computer-readable instructions. These computer-readable instructions can be stored in a computer-readable storage medium, and when executed by a processor, they can implement the steps of the various method embodiments described above. The computer-readable instructions include computer-readable instruction code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include any entity or device capable of carrying the computer-readable instruction code, a recording medium, a USB flash drive, a portable hard drive, a magnetic disk, an optical disk, a computer memory, a read-only memory (ROM), a random access memory (RAM), etc.
[0239] This embodiment also provides a computer storage medium storing computer instructions. When the computer instructions are executed on an electronic device, the electronic device performs the aforementioned related method steps to implement the permission management method in the above embodiment.
[0240] This embodiment also provides a computer program product that, when run on an electronic device, causes the electronic device to perform the aforementioned related steps to implement the permission management method described in the above embodiment.
[0241] In addition, embodiments of this application also provide an apparatus, which may specifically be a chip, component, or module. The apparatus may include a connected processor and a memory; wherein the memory is used to store computer execution instructions, and when the apparatus is running, the processor may execute the computer execution instructions stored in the memory to cause the chip to execute the permission management methods in the above-described method embodiments.
[0242] In this embodiment, the electronic device, computer storage medium, computer program product or chip are all used to execute the corresponding method provided above. Therefore, the beneficial effects that can be achieved can be referred to the beneficial effects of the corresponding method provided above, and will not be repeated here.
[0243] Through the above description of the embodiments, those skilled in the art can clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0244] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another device, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.
[0245] The unit described as a separate component may or may not be physically separate. The component shown as a unit can be one physical unit or multiple physical units, that is, it can be located in one place or distributed in multiple different places. Some or all of the units can be selected to achieve the purpose of the solution in this embodiment according to actual needs.
[0246] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0247] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solutions of the embodiments of this application, essentially or in other words, the parts that contribute to the prior art, or all or part of the technical solutions, can be embodied in the form of a software product. This software product is stored in a storage medium and includes several instructions to cause a device (which may be a microcontroller, chip, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0248] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A permission management method, applied to a first electronic device, characterized in that, The permission management method includes: The first application of the first electronic device requests access to the second system resource of the second electronic device; Receive the authorization status of the second system resources for the first application returned by the second electronic device; The first permission database of the first electronic device stores the authorization status of the second system resources for the first application; Merging the authorization status of applications with the same application identifier in the first permission database and the second permission database of the second electronic device includes: if the authorization status of the second application in the second permission database is allowed and the authorization status of the second application in the first permission database is empty, the authorization status of the second application in the first permission database after merging the two authorization statuses is allowed.
2. The access control method as described in claim 1, characterized in that, The first electronic device and the second electronic device are mutually trusted and connected.
3. The access control method as described in any one of claims 1 to 2, characterized in that, The application identifier of the second application of the second electronic device is the same as the application identifier of the first application of the first electronic device.
4. The access control method as described in any one of claims 1 to 3, characterized in that, The access control method also includes: The first permission database is synchronized with the second permission database of the second electronic device.
5. The access control method as described in claim 1, characterized in that, If a conflict occurs during the merging of authorization states in the first permission database, the permission management method further includes: Display the conflict resolution interface; Based on the user's conflict handling operation on the conflict handling interface, determine the authorization status of the conflict in the first permission database; The determined conflicting authorization status is synchronized to the second permission database of the second electronic device.
6. The access control method as described in any one of claims 1 to 5, characterized in that, After storing the authorization status of the second system resources for the first application in the first permission database of the first electronic device, the permission management method further includes: The first application of the first electronic device requests access to the first system resource of the first electronic device, and the first system resource is the same as the second system resource; Obtain the authorization status of the first system resources for the first application from the first permission database.
7. The access control method as described in claim 6, characterized in that, After the first electronic device obtains the authorization status of the first system resources for the first application from the first permission database, the permission management method further includes: The access of the first application to the first system resources is controlled based on the authorization status of the first system resources for the first application.
8. The access control method as described in any one of claims 1 to 5, characterized in that, After storing the authorization status of the second system resources for the first application in the first permission database of the first electronic device, the permission management method further includes: The system receives a request from a second application of the second electronic device to access a first system resource of the first electronic device. The first system resource is identical to the second system resource, and the application identifier of the first application is identical to the application identifier of the second application. Obtain the authorization status of the first system resources for the second application from the first permission database; The access of the second application to the first system resources is controlled based on the authorization status of the first system resources.
9. The access control method as described in any one of claims 1 to 5, characterized in that, The access control method also includes: If the first application does not exist in the first electronic device and the second application does not exist in the second electronic device, the authorization status corresponding to the first application is deleted from the first permission database.
10. The access control method as described in claim 1, characterized in that, The authorization status includes an application identifier field, a resource identifier field, a permission field, and / or an authorization status field.
11. A permission management method applied to a second electronic device, characterized in that, The permission management method includes: Receive a request from a first application of a first electronic device to access a second system resource of the second electronic device; Obtain the authorization status of the second system resources for the first application from the second permission database of the second electronic device; Determine the authorization status of the second system resources for the first application; Send the authorization status of the second system resources for the first application to the first electronic device; Merging the authorization status of applications with the same application identifier in the first permission database and the second permission database of the first electronic device includes: if the authorization status of the second application in the second permission database is allowed and the authorization status of the second application in the first permission database is empty, the authorization status of the second application in the first permission database after merging the two authorization statuses is allowed.
12. The access control method as described in claim 11, characterized in that, The first electronic device and the second electronic device are mutually trusted and connected.
13. The access control method as described in any one of claims 11 to 12, characterized in that, The application identifier of the second application of the second electronic device is the same as the application identifier of the first application of the first electronic device.
14. The access control method as described in any one of claims 11 to 13, characterized in that, The access control method also includes: The second permission database is synchronized with the first permission database of the first electronic device.
15. The access control method as described in any one of claims 11 to 14, characterized in that, The access control method also includes: The authorization status in the second permission database is merged based on the application identifier of the first application and the application identifier of the second application.
16. The access control method as described in claim 15, characterized in that, If a conflict occurs during the merging of authorization states in the second permission database, the permission management method further includes: Display the conflict resolution interface; Based on the user's conflict handling operation on the conflict handling interface, determine the authorization status of the conflict in the second permission database; The determined conflicting authorization status is synchronized to the first permission database of the first electronic device.
17. The access control method as described in claim 11, characterized in that, Determining the authorization status of the second system resource for the first application includes: Displays the permission interaction interface of the first application to the second system resources; Based on the user's permission confirmation operation in the permission interaction interface, the authorization status of the second system resource for the first application is determined in the second permission database.
18. The access control method as described in claim 11, characterized in that, The access control method also includes: The second application of the second electronic device requests access to the second system resources, and the application identifier of the first application is consistent with the application identifier of the second application. Obtain the authorization status of the second system resources for the second application from the second permission database; The access of the second application to the second system resources is controlled based on the authorization status of the second system resources for the second application.
19. The access control method as described in any one of claims 11 to 15, characterized in that, The access control method also includes: If the second application does not exist in the second electronic device and the first application does not exist in the first electronic device, delete the authorization status corresponding to the second application in the second permission database.
20. The access control method as described in any one of claims 11 to 15, characterized in that, The authorization status includes an application identifier field, a resource identifier field, a permission field, and / or an authorization status field.
21. An electronic device, characterized in that, It includes a processor and a memory; the memory is used to store instructions; the processor is used to invoke the instructions in the memory to cause the electronic device to perform the permission management method as described in any one of claims 1 to 10, or to cause the electronic device to perform the permission management method as described in any one of claims 11 to 20.
22. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores at least one instruction, which, when executed by a processor, implements the permission management method as described in any one of claims 1 to 10, or when executed by a processor, implements the permission management method as described in any one of claims 11 to 20.
Citation Information
Patent Citations
Authorization method and device of application program
CN106022091A
Atomic energy force calling method and terminal equipment
CN111859418A