Access control methods and related devices

By acquiring surrounding environmental data to determine the operating scenario and flexibly selecting the timing of permission granting, the issues of frequent single authorizations and runtime authorization security are resolved, thereby improving user experience and security.

CN115292730BActive Publication Date: 2026-01-30GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210917279.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-01
Publication Date
2026-01-30
Estimated Expiration
2042-08-01

AI Technical Summary

Technical Problem

Existing permission management methods lead to frequent user operations and reduce user experience when granting permissions only once, while runtime authorization poses a security risk of over-authorization.

Method used

By acquiring surrounding environmental data, determining the operating scenario based on the environmental data, and granting target permissions when they meet the preset scenario or risk level, the system can flexibly select permission management strategies.

Benefits of technology

While ensuring security, it improves the user experience and reduces the frequency of permission management operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115292730B_ABST
    Figure CN115292730B_ABST
Patent Text Reader

Abstract

This application provides a permission management method and related apparatus. First, when a target permission request for a target resource exists, surrounding environment data is acquired. Then, an operating scenario is determined based on the surrounding environment data. Finally, when the operating scenario matches a preset scenario or the risk level of the operating scenario is within a preset risk level, the target permission for the target resource is granted. This allows for flexible selection of the timing for granting target permissions based on the operating scenario, significantly improving user experience while ensuring security.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data processing, and particularly relates to a permission management method and related device. BACKGROUND

[0002] With the development of technology, when an application needs to call a related service of another application, authorization is generally needed, and the existing authorization mode generally adopts single-time authorization or runtime authorization.

[0003] Single-time authorization is, for example, when an application runs, the protected data can be accessed after the permission is granted, but the application needs to be authorized again when it is started again after being switched to the background or exited, that is, the permission can only be used once; runtime authorization is, for example, when an application runs, the protected data can be accessed after the permission is granted, and the protected data can still be accessed after the application is started again even if the application is switched to the background or exited.

[0004] It can be seen that the current permission management makes the user operation frequent and reduces the user experience in single-time authorization, and has the security problem of over-authorization in runtime authorization. SUMMARY

[0005] Therefore, the present application provides a permission management method and related device, which can determine a permission management strategy based on a perceived scene, improve the user experience while ensuring security.

[0006] In a first aspect, an embodiment of the present application provides a permission management method, and the method comprises the following steps:

[0007] When there is a target permission request for a target resource, acquiring surrounding environment data;

[0008] Determining a running scene according to the surrounding environment data;

[0009] When the running scene meets a preset scene or a risk level of the running scene belongs to a preset risk level, opening a target permission for the target resource.

[0010] In a second aspect, an embodiment of the present application provides a permission management device, and the device comprises:

[0011] An environment acquisition unit, configured to acquire surrounding environment data when there is a target permission request for a target resource;

[0012] A scene determination unit, configured to determine a running scene according to the surrounding environment data;

[0013] A permission management unit, configured to open a target permission for the target resource when the running scene meets a preset scene or a risk level of the running scene belongs to a preset risk level.

[0014] In a third aspect, an electronic device is provided, which includes a processor, a communication module, a memory, a communication interface, and one or more programs. The one or more programs are stored in the memory and configured to be executed by the processor. The programs include instructions for performing the steps in any method of the first aspect.

[0015] In a fourth aspect, a computer-readable storage medium is provided, which stores a computer program for electronic data exchange. The computer program causes a computer to perform some or all of the steps described in any method of the first aspect.

[0016] In a fifth aspect, a computer program product is provided, which includes a non-transitory computer-readable storage medium storing a computer program. The computer program is operable to cause a computer to perform some or all of the steps described in any method of the first aspect. The computer program product can be a software installation package.

[0017] It can be seen that, by the above permission management method and related device, first, when there is a target permission request for a target resource, surrounding environment data is acquired; then, a running scenario is determined according to the surrounding environment data; finally, when the running scenario meets a preset scenario or a risk level of the running scenario belongs to a preset risk level, a target permission for the target resource is opened. The timing of opening the target permission can be flexibly selected based on the running scenario, which greatly improves user experience while ensuring security. BRIEF DESCRIPTION OF DRAWINGS

[0018] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiment description. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can also be obtained by those skilled in the art without creative labor.

[0019] Figure 1 A system architecture diagram of a permission management method provided by the embodiments of the present application;

[0020] Figure 2 A flowchart of a permission management method provided by the embodiments of the present application;

[0021] Figure 3 A schematic diagram of setting a scenario white list provided by the embodiments of the present application;

[0022] Figure 4Another flowchart of a permission management method provided by an embodiment of the present application is shown in FIG. 2.

[0023] Figure 5 A structural diagram of an electronic device provided by an embodiment of the present application is shown in FIG. 3.

[0024] Figure 6 A functional unit composition block diagram of a permission management device provided by an embodiment of the present application is shown in FIG. 4.

[0025] Figure 7 A functional unit composition block diagram of another permission management device provided by an embodiment of the present application is shown in FIG. 5. DETAILED DESCRIPTION

[0026] In order to make the personnel in the art better understand the present application, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of the present application.

[0027] The terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish different objects, and are not used to describe a specific order. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units is not limited to the listed steps or units, but can optionally include steps or units not listed or can optionally include other steps or units inherent to the process, method, product or device.

[0028] It should be understood that the term "and / or" herein is only used to describe the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B can mean that A exists alone, A and B exist together, and B exists alone. In addition, the character " / " in this paper represents that the front and rear associated objects are a "or" relationship. "Multiple" appearing in the embodiments of the present application means two or more.

[0029] The "connection" appearing in the embodiments of the present application means direct connection or indirect connection and various connection modes to realize communication between devices, which is not limited by the embodiments of the present application.

[0030] Reference to "an embodiment" or "the embodiment" means that a particular feature, structure, or characteristic described in connection with the embodiment can be included in at least one embodiment of the application. The appearances of the phrase "in an embodiment" or "in the embodiment" in various places in the specification are not necessarily all referring to the same embodiment, nor are they necessarily all referring to a common set of embodiments. It is expressly understood that the embodiments described herein are merely examples from a

[0031] The background and related terms of the application are described below.

[0032] Background related:

[0033] The so-called permission management refers to that according to a preset security rule or security policy, a user can access and can only access the resources authorized by the user. One possible permission management manner is single-time authorization, that is, when an Activity component of an application is visible, the application can access the authorized related data, and when the application is switched to the background or exited, the application needs to request authorization again when started again, otherwise the application cannot access the related data. Another possible permission management manner is runtime authorization, that is, when an Activity component of an application is visible, the application can access the authorized related data, and when the application is switched to the background or exited, the application can still access the authorized related data when started again, and does not need to request authorization again.

[0034] However, when the called service is frequently switched between the foreground and the background, the single-time authorization needs to request authorization multiple times, which greatly affects the user experience, and the runtime authorization may over-authorize, affecting the security and privacy.

[0035] To solve the above problems, the embodiments of the application provide a permission management method and related apparatus, which can determine a permission management policy based on a perceived scene, thereby improving the user experience while ensuring the security.

[0036] The embodiments of the application are described below in combination with Figure 1 The system architecture of the permission management method in the embodiments of the application is described below, Figure 1 The system architecture 100 of the permission management method provided by the embodiments of the application includes a user control 110, a provider control 120, and an environment collection unit 130.

[0037] The user control 110 can be a consumer service, the provider control 120 can be a provider service, and the environment collection unit 130 can be an image sensor, an audio sensor, a speed sensor, a positioning unit, etc. The user control 110 is connected to the provider control 120 and the environment collection unit 130. The provider control 120 is configured to provide a service for the user control 110 in response to a request of the user control 110. The service can be a network, a file, a location, etc. It can be understood that the user control 110 and the provider control 120 can be deployed on the same device or can be deployed on different devices.

[0038] The user control 110 can call an interface of the provider control 120 to obtain the service provided by the provider control 120. The provider control 120 can call the interface to determine whether the user control 110 is authorized and whether the service is bound to a corresponding scenario condition. If the service is not bound to the corresponding scenario condition, the provider control 120 returns an authorization result to the user control 110. If the service is bound to the corresponding scenario, the provider control 120 determines a running scenario of the user control 110. If the running scenario meets the corresponding scenario condition bound by the service, the provider control 120 returns the authorization result. If the running scenario does not meet the corresponding scenario condition bound by the service, the provider control 120 returns a refusal authorization result.

[0039] In one possible embodiment, the user control 110 can receive surrounding environment data collected by the environment collection unit 130, determine a running scenario based on the surrounding environment data, and send the running scenario to the provider control 120.

[0040] In one possible embodiment, the user control 110 can receive surrounding environment data collected by the environment collection unit 130, send the surrounding environment data to the provider control 120, and the provider control 120 can determine a running scenario based on the surrounding environment data.

[0041] It can be seen that, by using the above system architecture, the timing of opening the target permission can be flexibly selected based on the running scenario, which greatly improves the user experience while ensuring security.

[0042] After introducing the software and hardware architecture of the embodiments of the present application, the following describes the embodiments of the present application with reference to the accompanying drawings. Figure 2 The embodiments of the present application provide a permission management method, which specifically includes the following steps. Figure 2 The permission management method provided by the embodiments of the present application specifically includes the following steps.

[0043] In step 201, surrounding environment data is obtained when there is a target permission request for a target resource.

[0044] The target resource can be a target service or a target file. For example, the target service can be a network service, a positioning service, etc., and the target file can be an encrypted file, etc. Here, no specific limitation is made, and all services or files that need to be authorized to use can be used as target resources.

[0045] The target permission request can be sent by the user control to the provider control. The target permission request can be an access request, and no specific limitation is made herein.

[0046] The surrounding environment data collected by the surrounding devices connected to the same IoT within a preset period can be obtained when there is a target permission request for the target resource. The surrounding environment data includes at least one of image data, audio data, speed data, and location data. The preset period can be set by the user. The surrounding devices are connected to the same IoT as the electronic device, so that the surrounding devices can transmit the collected surrounding environment data to the electronic device, and the electronic device itself can also obtain the surrounding environment data. For example, the electronic device can collect images and audio of the current space, and can also collect its own speed and location, etc. The electronic device can also receive image data, audio data, speed data, and location data collected by the surrounding devices connected to the same IoT (such as the same Bluetooth network or the same WiFi network). It can be understood that the user control is responsible for collecting the surrounding environment data and providing it to the provider control.

[0047] It can be seen that by obtaining the surrounding environment data when there is a target permission request for the target resource, reliable data reference can be provided for subsequent determination of the running scenario.

[0048] In step 202, the running scenario is determined according to the surrounding environment data.

[0049] The scene key information can be determined according to the surrounding environment data. The scene key information includes at least one of key image information corresponding to the image data, key audio information corresponding to the audio data, key speed information corresponding to the speed data, key location information corresponding to the location data, and key physical information corresponding to the user physical data. Then, the running scenario is determined according to the scene key information.

[0050] Specifically, for example, key image information reflecting the current scene can be determined from the image data, the key image information can be text in the image, part of the image area including landmarks, etc.; key audio information reflecting the current scene can be determined from the audio data, the key audio information can be an audio paragraph related to the scene description; key speed information reflecting the current scene can be determined from the speed data, the key speed information can be speed change; key location information reflecting the current scene can be determined from the position data, the key location information can be landmark information; key motion information reflecting the current scene can be determined from the user's vital sign data, the key motion information can be heartbeat information, pulse information, breathing rate, etc. The running scene can be determined by at least one of the key image information, the key audio information, the key speed information, the key location information, and the key vital sign information. The running scene can be an in-car, in-company, commuting, in-motion, in-meeting, etc. scene, which is not limited here. It can be understood that the scene key information and the running scene can be determined by machine learning, deep learning, etc., which is not limited here.

[0051] It can be seen that the running scene is determined according to the surrounding environment data, which can provide a reference for the subsequent permission management strategy, and improve the flexibility and accuracy of permission management.

[0052] Step 203, when the running scene meets the preset scene or the risk level of the running scene belongs to the preset risk level, the target permission of the target resource is opened.

[0053] Among them, the scene white list of the target permission or the preset risk level of the target permission can be set in advance, when the running scene belongs to the scene white list corresponding to the target permission, or the risk level of the running scene belongs to the preset risk level corresponding to the target permission, the target permission of the target resource is opened.

[0054] In one possible embodiment, a to-be-permitted scene list or a to-be-permitted risk level list can be displayed, the to-be-permitted scene list includes the running scene, and the to-be-permitted risk level list includes the risk level of the running scene; then the final permission list is determined according to the user's feedback to the to-be-permitted scene list or the to-be-permitted risk level list, the permission list includes the preset scene or the preset risk level; finally, when the running scene meets the preset scene or the risk level of the running scene belongs to the preset risk level, the target permission of the target resource is opened.

[0055] For example, the permission list or the permission risk level can be set by the user himself, such as Figure 3As shown, when "xx needs to use the location information permission", and the detected running scenario at this time is "commuting", then "commuting" can be added to the list of to-be-permitted scenarios and displayed to the user, and the user can set the final permission list as "commuting", that is, when the running scenario is "commuting", the location information permission can be automatically opened to xx, and the user can also add other scenarios to open the location information permission when entering the other scenarios, which will not be described herein. In a possible embodiment, the permission list can also include a preset risk level, which is not limited herein.

[0056] In a possible embodiment, the risk coefficient of the target permission can be determined first, and the higher the safety coefficient is, the higher the corresponding preset risk level is. The target permission can be divided into high-risk services, medium-risk services and low-risk services according to the risk coefficient, and the running scenario can also be pre-corresponded to a low-risk level, a medium-risk level and a high-risk level. As shown in the following table:

[0057]

[0058]

[0059] It can be understood that the high-risk service is only allowed to access when the running scenario is at a low-risk level, and the medium-risk service is not allowed to access when the running scenario is at a high-risk level, and the low-risk service is allowed to access in all running scenarios.

[0060] In a possible embodiment, for example, the a file needs to be accessed at this time, and the access permission of the a file corresponds to a scenario white list "in the office", so the access permission of the a file is opened only when it is determined that the current running scenario is "in the office", and the access permission of the a file is not opened when it is determined that the current running scenario is "in a public place" or "at home". When no scenario white list is set, the risk coefficient of the a file can be determined as high, and the a file is a "high-risk service". When it is determined that the running scenario is "in the office", and the running scenario "in the office" is at a low-risk level, it is determined that the access permission of the a file can be opened. It can be understood that the running scenario "in a public place" is at a high-risk level, and the running scenario "at home" is at a medium-risk level, that is, the access permission of the "high-risk service" a file cannot be opened when "in a public place" or "at home".

[0061] It can be seen that when the running scenario meets the preset scenario or the risk level of the running scenario belongs to the preset risk level, the target permission of the target resource is opened, the timing of opening the target permission can be flexibly selected based on the running scenario, the user experience is greatly improved while the security is ensured.

[0062] The following will be described in combination with Figure 4Another permission management method in the embodiments of the present application is described, Figure 4 A flowchart of another permission management method provided by the embodiments of the present application is shown, and specifically includes the following steps:

[0063] Step 401, when there is a target permission request for a target resource, determine the scene binding state of the target permission.

[0064] The target permission can be an access permission, a use permission, etc. When the target permission does not have a bound preset scene, step 402 is executed; when the target resource has a bound preset scene, step 403 is executed.

[0065] Step 402, when the target permission does not have a bound preset scene, open the target permission.

[0066] As can be seen, when the target permission does not have a bound preset scene, the authorization result can be directly returned, avoiding subsequent steps and saving power consumption.

[0067] Step 403, when the target resource has a bound preset scene, obtain surrounding environment data.

[0068] Step 404, determine a running scene according to the surrounding environment data.

[0069] Step 405, when the running scene meets a preset scene or the risk level of the running scene belongs to a preset risk level, open the target permission for the target resource.

[0070] Step 406, when the running scene does not meet the preset scene or the risk level of the running scene does not belong to the preset risk level, do not open the target permission for the target resource.

[0071] Step 407, when it is detected that the running scene does not meet the preset scene or the risk level of the running scene does not belong to the preset risk level within the next period of the preset period, display prompt information.

[0072] The prompt information is used to prompt the user whether to maintain the opening of the target permission. It can be understood that the form of the prompt information can be text, voice, image, interactive button, etc.

[0073] For example, when the running scene is "driving", when the speed is reduced to 0 within the next period of the preset period, it can be determined that the user is in a parking state at this time, and the user can be prompted with prompt information to confirm whether the permission permission needs to be maintained.

[0074] It can be seen that the current running scene can be detected in real time, and the permission is closed in time when the running scene does not meet the requirements, thereby improving the security.

[0075] In step 408, the permission management of the target resource is performed according to the feedback instruction of the user for the prompt information.

[0076] The feedback instruction can be maintaining the permission or closing the permission.

[0077] Through the above method, the permission management strategy can be determined based on the perceived scene, the security is ensured, and the user experience is improved.

[0078] The steps not described in detail above can refer to the description of the steps of the method in Figure 2 , and will not be described here.

[0079] The following will be described with reference to Figure 5 An electronic device in an embodiment of the present application is described, Figure 5 The structure schematic diagram of another electronic device provided by the embodiment of the present application is shown in Figure 5 , which includes a processor 501, a communication module 502 and a memory 503, and the processor 501, the communication module 502 and the memory 503 are connected with each other. The electronic device 500 can further include a bus 504, and the processor 501, the communication module 502 and the memory 503 can be connected with each other through the bus 504. The bus 504 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus 504 can be divided into an address bus, a data bus, a control bus, etc. For the convenience of representation, Figure 5 only one thick line is used in the figure, but it does not mean that there is only one bus or only one type of bus. The memory 503 is used to store a computer program, the computer program includes program instructions, and the processor is configured to invoke the program instructions to execute all or part of the method described in the above Figure 2 、 Figure 4 .

[0080] The above describes the scheme of the embodiments of the present application mainly from the perspective of the process of executing the method. It can be understood that, in order to implement the above functions, the electronic device comprises a hardware structure and / or a software module corresponding to the execution of each function. Those skilled in the art should easily realize that, in combination with the unit and algorithm steps of each example described in the embodiments provided herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is implemented in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. The skilled person can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0081] The embodiments of the present application can divide the functional units of the electronic device according to the above method examples. For example, each functional unit can be divided according to each function, or two or more functions can be integrated in one processing unit. The integrated unit can be implemented in the form of hardware or software functional unit. It should be noted that the division of units in the embodiments of the present application is illustrative and is only a logical function division. Actual implementation can have another division method.

[0082] In the case of dividing each functional module according to each function, the following will be described in combination with Figure 6 A detailed description will be given of a kind of permission management device in the embodiments of the present application, Figure 6 The functional unit composition block diagram of a kind of permission management device provided in the embodiments of the present application, the permission management device 600 includes:

[0083] The environmental acquisition unit 610 is used to acquire surrounding environment data when there is a target permission request for target resource;

[0084] The scene determination unit 620 is used to determine the running scene according to the surrounding environment data;

[0085] The permission management unit 630 is used to open the target permission of the target resource when the running scene meets the preset scene or the risk level of the running scene belongs to the preset risk level.

[0086] It can be seen that, through the above permission management method and related device, first, when there is a target permission request for target resource, surrounding environment data is acquired;Then, the running scene is determined according to the surrounding environment data;Finally, when the running scene meets the preset scene or the risk level of the running scene belongs to the preset risk level, the target permission of the target resource is opened. The timing of opening the target permission can be flexibly selected based on the running scene, which greatly improves the user experience while ensuring security.

[0087] In the case of using the integrated unit, the following is combined with Figure 7 Another kind of permission management apparatus 700 in the embodiment of the application is described in detail, the permission management apparatus 700 includes a processing unit 701 and a communication unit 702, wherein the processing unit 701 is used for executing any step in the above method embodiment, and when executing data transmission such as sending, the communication unit 702 can be selectively called to complete the corresponding operation.

[0088] The permission management apparatus 700 can further include a storage unit 703 for storing program codes and data. The processing unit 701 can be a processor, the communication unit 702 can be a wireless communication module, and the storage unit 703 can be a memory.

[0089] The processing unit 701 is specifically used for:

[0090] When there is a target permission request for a target resource, surrounding environment data is acquired;

[0091] A running scenario is determined according to the surrounding environment data;

[0092] When the running scenario meets a preset scenario or a risk level of the running scenario belongs to a preset risk level, a target permission for the target resource is opened.

[0093] It can be seen that through the above permission management method and related apparatus, first, when there is a target permission request for a target resource, surrounding environment data is acquired; then, a running scenario is determined according to the surrounding environment data; finally, when the running scenario meets a preset scenario or a risk level of the running scenario belongs to a preset risk level, a target permission for the target resource is opened. The timing of opening the target permission can be flexibly selected based on the running scenario, which greatly improves the user experience while ensuring the security.

[0094] The embodiment of the application further provides a computer storage medium, wherein the computer storage medium stores a computer program for electronic data exchange, and the computer program causes a computer to execute part or all steps of any method described in the above method embodiment.

[0095] The embodiment of the application further provides a computer program product, and the above computer program product includes a non-transitory computer readable storage medium storing a computer program, and the computer program is operable to cause a computer to execute part or all steps of any method described in the above method embodiment. The computer program product can be a software installation package, and the computer includes an electronic device.

[0096] It should be noted that, for the foregoing method embodiments, the sequences of the described actions can be changed, and the actions can be performed in other sequences or concurrently. Additionally, it should be understood that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily required by the present application.

[0097] In the above embodiments, the description of each embodiment is focused on, and the parts not described in detail in a certain embodiment can be referred to the relevant description of other embodiments.

[0098] In the several embodiments provided by the present application, it should be understood that the disclosed apparatus can be implemented in other manners. For example, the apparatus embodiments described above are merely schematic; the division of the units is only a logical function division; there can be another division manner for the actual implementation, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between different units, or the among different units, can be indirect couplings or communication connections through some interfaces, devices or units, and can be in electrical, mechanical or other forms.

[0099] The units described as separate components can or can not be physically separate, and the components displayed as units can or can not be physical units, i.e., can be located in one place or distributed on multiple network units. Some or all of the units can be selected according to actual needs to achieve the purposes of the embodiments.

[0100] In addition, each functional unit in the embodiments of the present application can be integrated in one processing unit, or each unit can exist physically as a separate unit, or two or more units can be integrated in one unit. The integrated unit can be implemented in the form of hardware or software functional units.

[0101] If the above integrated unit is realized in the form of a software function unit and sold or used as an independent product, it can be stored in a computer readable memory. Based on this understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a memory and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the above-mentioned method of each embodiment of the present application. The aforementioned memory includes: a U disk, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store program codes.

[0102] A person of ordinary skill in the art can understand that all or part of the steps in the above-mentioned embodiments can be completed by instructing the relevant hardware through a program, which can be stored in a computer readable memory. The memory can include: a flash disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.

[0103] The embodiments of the present application are described in detail above, and the principles and implementation manners of the present application are described by applying specific examples. The above description of the embodiments is only used to help understand the method of the present application and its core idea; at the same time, for those skilled in the art, according to the idea of the present application, the specific implementation manner and application range will be changed, and the above description of the embodiments should not be understood as a limitation of the present application.

Claims

1. A rights management method, characterized by, The method comprises: acquiring surrounding environment data when a target permission request for a target resource exists; determining a running scene according to the surrounding environment data; opening a target permission for the target resource when the running scene meets a preset scene or a risk level of the running scene belongs to a preset risk level, wherein a to-be-permitted scene list or a to-be-permitted risk level list is displayed, the to-be-permitted scene list comprises the running scene, and the to-be-permitted risk level list comprises a risk level of the running scene; a final permission list is determined according to feedback of a user for the to-be-permitted scene list or the to-be-permitted risk level list, the permission list comprises the preset scene or the preset risk level; and the target permission for the target resource is opened when the running scene meets the preset scene or the risk level of the running scene belongs to the preset risk level.

2. The method of claim 1, wherein, The acquiring surrounding environment data when a target permission request for a target resource exists comprises: acquiring surrounding environment data collected by surrounding devices connected to the same Internet of Things in a preset period when a target permission request for a target resource exists, the surrounding environment data comprising at least one of image data, audio data, speed data, position data, and user physical sign data.

3. The method of claim 2, wherein, The determining a running scene according to the surrounding environment data comprises: determining scene key information according to the surrounding environment data, the scene key information comprising at least one of key image information corresponding to the image data, key audio information corresponding to the audio data, key speed information corresponding to the speed data, key position information corresponding to the position data, and key physical sign information corresponding to the user physical sign data; determining the running scene according to the scene key information.

4. The method of claim 1, wherein, The opening a target permission for the target resource when the running scene meets a preset scene or a risk level of the running scene belongs to a preset risk level comprises: opening the target permission for the target resource when the running scene belongs to a scene white list corresponding to the target permission or a risk level of the running scene belongs to a preset risk level corresponding to the target permission.

5. The method of claim 1, wherein, Before the acquiring surrounding environment data, the method further comprises: determining a scene binding state of the target permission; opening the target permission when the target permission does not have a bound preset scene; executing the step of acquiring surrounding environment data when the target resource has a bound preset scene.

6. The method of claim 2, wherein, After the opening a target permission for the target resource, the method further comprises: displaying prompt information when it is detected that the running scene does not meet the preset scene or the risk level of the running scene does not belong to the preset risk level in a next period of the preset period, the prompt information being used to prompt a user whether to maintain the target permission being opened; performing permission management of the target resource according to a feedback instruction of the user for the prompt information.

7. A rights management apparatus characterized by comprising: The device comprises: an environment acquisition unit configured to acquire surrounding environment data when a target permission request for a target resource exists; A scene determining unit is configured to determine an operation scene according to the surrounding environment data; The permission management unit is configured to open a target permission to the target resource when the operation scene meets a preset scene or a risk level of the operation scene belongs to a preset risk level, wherein a to-be-permitted scene list or a to-be-permitted risk level list is displayed, the to-be-permitted scene list includes the operation scene, and the to-be-permitted risk level list includes the risk level of the operation scene; a final permission list is determined according to feedback of a user to the to-be-permitted scene list or the to-be-permitted risk level list, the permission list includes the preset scene or the preset risk level; and the target permission to the target resource is opened when the operation scene meets the preset scene or the risk level of the operation scene belongs to the preset risk level.

8. An electronic device, comprising: A computer program product comprising a computer readable medium storing instructions executable by a processor to perform the steps of the method of any one of claims 1-6.

9. A computer storage medium, characterized in that The computer storage medium stores a computer program, and the computer program includes program instructions. When the program instructions are executed by a processor, the processor executes the method of any one of claims 1-6.

Citation Information

Patent Citations

  • Data processing method and device

    CN114419664A