Method and apparatus for application running control based on secure workspace

By acquiring and matching application information within a secure workspace and automatically running the target application, the problem of cumbersome application control in existing technologies is solved, achieving an efficient and simplified application running experience.

CN115756677BActive Publication Date: 2026-08-04QI-ANXIN LEGENDSEC INFORMATION TECH (BEIJING) INC +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
QI-ANXIN LEGENDSEC INFORMATION TECH (BEIJING) INC
Filing Date
2022-10-27
Publication Date
2026-08-04

AI Technical Summary

Technical Problem

In existing technologies, the method of controlling applications within a safe workspace requires users to drag and drop applications into the safe workspace themselves. This process is cumbersome, inefficient, and requires user instruction for first-time users.

Method used

By obtaining the application information of the target application and matching it with the file information in the system directory, the file storage location is determined, and the target application is run in a secure workspace. The application's automatic operation is achieved by embedding a link to the executable file using the application's display information.

Benefits of technology

It reduces user operation steps, improves user experience, simplifies the application's operation in a secure workspace, increases efficiency, and eliminates the need for user training upon first use.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115756677B_ABST
    Figure CN115756677B_ABST
Patent Text Reader

Abstract

The application provides a kind of based on safe workspace's application running control method and device, comprising: obtaining the application information of target application, the target application is the application needing to be placed in safe workspace and run;The application information of the target application is matched with the file information in system directory, to obtain the file information matched with the application information of the target application, wherein, the file storage location corresponding to the file information is stored in the system directory;The file storage location of target application is determined according to the obtained file information;The corresponding target application is run in the safe workspace using the determined file storage location.The application can reduce user operation link, improve user experience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security technology, and in particular to an application operation control method and apparatus based on a secure workspace. Background Technology

[0002] A secure workspace is a space that allows multiple programs to run while isolating the programs running outside the space from each other, thus preventing data leakage of processes within the space to the outside.

[0003] Currently, controlling applications within a safe workspace requires users to manually drag and drop the application from outside the safe workspace into it. This process is cumbersome, inefficient, and requires user training upon initial use. Therefore, improving the operational efficiency of applications within a safe workspace is a crucial issue that needs to be addressed. Summary of the Invention

[0004] This invention provides an application operation control method and apparatus based on a safe workspace to solve the above-mentioned problems.

[0005] This invention provides an application operation control method based on a safe workspace, comprising:

[0006] Obtain application information of the target application, wherein the target application is an application that needs to run in a secure workspace;

[0007] The application information of the target application is matched with the file information in the system directory to obtain the file information that matches the application information of the target application, wherein the system directory stores the file storage location corresponding to the file information;

[0008] Determine the file storage location of the target application based on the obtained file information;

[0009] The corresponding target application is run within the secure workspace using the determined file storage location.

[0010] According to the present invention, an application operation control method based on a secure workspace is provided, wherein the file information includes application display information and an executable file corresponding to the target application; the method further includes:

[0011] The application display information is displayed on the secure workspace interface, the executable file is stored in the database corresponding to the secure workspace, and a link pointing to the storage location of the executable file in the database is embedded in the application display information, so that the executable file is run based on the link through a first preset operation on the application display information.

[0012] According to the present invention, an application operation control method based on a secure workspace is provided, which acquires application information of a target application, including:

[0013] Obtain the configuration policy for the secure workspace from the console. The configuration policy includes application information for applications that need to run in the secure workspace.

[0014] The configuration policy is parsed to obtain application information for the target application.

[0015] According to the application operation control method based on a secure workspace provided by the present invention, the step of obtaining application information of the target application includes:

[0016] The application information of the target application is obtained based on the user's second preset operation, which includes selecting the target application and obtaining the path information of the target application.

[0017] According to the application operation control method based on a secure workspace provided by the present invention, the application information of the target application includes the application display name and / or the executable file name.

[0018] According to the present invention, an application operation control method based on a safe workspace is provided, the method further includes:

[0019] When launching the target application, determine whether the target application is in a secure workspace;

[0020] If the target application is in a secure workspace, the target application is run in the secure workspace based on the executable file;

[0021] If the target application is not in the secure workspace, perform the step of matching the application information of the target application with the file information in the system directory.

[0022] According to the present invention, an application operation control method based on a secure workspace is provided, wherein the secure workspace interface has a display list, and the application display information is displayed in the display list. When the target application is in the secure workspace, the method runs the target application in the secure workspace based on the executable file, including:

[0023] In response to a first preset operation on the application display information in the display list, the executable file is run based on the link embedded in the application display information to run the target application in the secure workspace.

[0024] According to the present invention, an application operation control method based on a safe workspace is provided, the method further includes:

[0025] If no file information matching the application information of the target application is obtained, the application display information of the target application is displayed in a preset color in the secure workspace. The application display information includes the target application display name and / or icon.

[0026] According to the present invention, an application operation control method based on a safe workspace is provided, wherein the safe workspace includes a sandbox.

[0027] The present invention also provides an application operation control device based on a safe workspace, comprising:

[0028] An application information acquisition unit is used to acquire application information of a target application, wherein the target application is an application that needs to be run in a secure workspace.

[0029] The file matching unit is used to match the application information of the target application with the file information in the system directory to obtain the file information that matches the application information of the target application, wherein the system directory stores the file storage location corresponding to the file information;

[0030] The storage location determination unit is used to determine the file storage location of the target application based on the acquired file information.

[0031] The secure workspace operation unit is used to run the corresponding target application within the secure workspace using the determined file storage location.

[0032] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement any of the above-described application operation control methods based on a secure workspace.

[0033] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements any of the above-described application operation control methods based on a secure workspace.

[0034] The application operation control method and device based on a secure workspace provided by this invention obtains application information related to applications that need to be placed in a secure workspace for data isolation, then obtains file information related to the target application in the system directory based on the application information, and then runs the target application directly in the secure workspace according to the file storage location corresponding to the file information. This eliminates the need for users to drag and drop the application into the secure workspace, and also eliminates the need for tutorials during initial use, reducing user operation steps and improving user experience. Attached Figure Description

[0035] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0036] Figure 1 This is a flowchart illustrating the application operation control method based on a safe workspace provided in an embodiment of the present invention;

[0037] Figure 2 A schematic diagram of the structure of an application operation control device based on a safe workspace provided in an embodiment of the present invention;

[0038] Figure 3 This is a schematic diagram of the physical structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation

[0039] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0040] Figure 1 This is a flowchart illustrating the application operation control method based on a safe workspace provided in an embodiment of the present invention; as shown below. Figure 1 As shown, the application operation control method based on a safe workspace includes:

[0041] S101, Obtain application information of the target application, wherein the target application is an application that needs to be run in a secure workspace.

[0042] S102, match the application information of the target application with the file information in the system directory to obtain the file information that matches the application information of the target application, wherein the system directory stores the file storage location corresponding to the file information.

[0043] S103, determine the file storage location of the target application based on the obtained file information.

[0044] S104, run the corresponding target application within the secure workspace using the determined file storage location.

[0045] In this embodiment, the application that needs to isolate the data generated during its operation from other applications is designated as the target application. Before controlling the target application to run within the secure workspace, the application information of the target application is obtained. This application information can be the name of the target application (Chinese, English abbreviation, English full name, etc.), or information such as the target application's identifier, code, or code, or the target application's MD5 value, etc. Any information that can uniquely identify the target application is acceptable.

[0046] After obtaining the application information, the system directory (i.e., Windows\Start Menu) is traversed based on the application's name, identifier, MD5 value, and other information to ensure that no application under the Windows\Start Menu is missed, and to obtain the file information that matches the application information.

[0047] The file information that matches the application information includes all application-related file information, such as the application's display name, executable file, application path information, etc.

[0048] It should be noted that applications can exist in the system directory as shortcuts or directly as executable files. If it is a shortcut, the application shortcut needs to be parsed to obtain the corresponding executable file name. Then, all executable file names are matched against the application information. If a match is found, the location of the executable file is obtained, and then all file information corresponding to the target application is retrieved based on that location.

[0049] After matching the file information corresponding to the target application, the file storage location corresponding to the target application is further determined based on the file storage location pre-stored in the system directory.

[0050] After determining the file storage location corresponding to the target application, the target application is run directly within the secure workspace using that file storage location.

[0051] The application operation control method based on a secure workspace provided in this invention obtains application information related to applications that need to be placed in a secure workspace for data isolation, then obtains file information related to the target application in the system directory based on the application information, and then runs the target application directly in the secure workspace according to the file storage location corresponding to the file information. This eliminates the need for users to drag and drop the application into the secure workspace, and also eliminates the need for tutorials during initial use, reducing user operation steps and improving user experience.

[0052] Furthermore, the file information includes application display information and executable files corresponding to the target application; the method further includes:

[0053] The application display information is displayed on the secure workspace interface, the executable file is stored in the database corresponding to the secure workspace, and a link pointing to the storage location of the executable file in the database is embedded in the application display information, so that the executable file is run based on the link through a first preset operation on the application display information.

[0054] In this embodiment, the file information matching the target application is specifically limited to application display information and executable files (e.g., the application's .exe file). The application display information enables the target application to be displayed within the secure workspace, while the executable file enables the target application to run within the secure workspace.

[0055] Specifically, after determining the file storage location of the target application, the application display information from the file information is displayed on the secure workspace interface based on the file storage location, and the executable file from the file information is stored in the database corresponding to the secure workspace. Additionally, a link pointing to the storage location of the executable file in the database needs to be embedded in the application display information. Based on this, after the user selects the application display information of the target application within the secure workspace, they can contact the corresponding executable file through the aforementioned link to run the executable file and achieve the purpose of running the target application.

[0056] It should be noted that the first preset operation is to run the target application. Specifically, this can be double-clicking the application to display information, or right-clicking to open the application after selecting the application to display information.

[0057] Furthermore, when the target application runs for the first time within the secure workspace, the aforementioned steps of application information acquisition, file information matching, and file storage location determination need to be performed. When the target application runs again, this can be accomplished directly based on the executable file stored in the database corresponding to the secure workspace and the application display information shown on the secure workspace interface. Unlike existing technologies, which require dragging the application into the secure space every time the application is launched, this invention's operation process is simpler and more efficient than existing technologies, whether running the software for the first time or running it again, thus improving the user experience. Moreover, it can load previously cached data from the target application during subsequent runs.

[0058] The application operation control method based on a secure workspace provided in this invention displays application display information in a secure workspace, stores executable files in a database corresponding to the secure workspace, and embeds links pointing to executable files in the application display information, thereby enabling the executable files to run within the secure workspace through the application display information.

[0059] Furthermore, obtain application information about the target application, including:

[0060] Obtain the configuration policy for the secure workspace from the console. The configuration policy includes application information for applications that need to run in the secure workspace.

[0061] The configuration policy is parsed to obtain application information for the target application.

[0062] The application information of the target application includes the application display name and / or the executable file name.

[0063] Specifically, the application information of the target application can be obtained based on a configuration policy. This configuration policy is issued by the console and includes information on multiple applications, enabling multiple applications to run simultaneously within the secure workspace. The configuration policy specifically includes the display name, .exe name, and MD5 value of all target applications that need to run. After obtaining the configuration policy, the application testing policy needs to be parsed to obtain the application name of the target application (including the display name and .exe name).

[0064] The application operation control method based on a secure workspace provided in this embodiment of the invention obtains information on all applications that need to run in a secure workspace through configuration policies issued by the console, enabling multiple applications to run simultaneously in the secure workspace.

[0065] Furthermore, obtaining the application information of the target application includes:

[0066] The application information of the target application is obtained based on the user's second preset operation, which includes selecting the target application and obtaining the path information of the target application.

[0067] The application information of the target application includes the application display name and / or the executable file name.

[0068] In this embodiment, the user can obtain the application information of the target application through a second preset operation (such as dragging). More specifically, when dragging the target application to the secure workspace, the user first selects the target application and then drags it into the secure workspace. When the target application is selected, the storage path information corresponding to the target application will be displayed, and then the application display name, executable file name, and other information corresponding to the target application will be obtained from the corresponding folder based on the path information.

[0069] Furthermore, the method also includes:

[0070] When launching the target application, determine whether the target application is in a secure workspace.

[0071] If the target application is in a secure workspace, the target application is run in the secure workspace based on the executable file.

[0072] If the target application is not in the secure workspace, perform the step of matching the application information of the target application with the file information in the system directory.

[0073] In this embodiment, the target application is launched within the secure workspace. If the target application is not running during the launch process, it means that the target application is not in the secure workspace. It is necessary to match the file information in the system directory based on the application information of the target application, and then run the target application within the secure workspace based on the determined file storage location.

[0074] If the target application is in a secure workspace, then the target application can be run directly in the secure workspace via the executable file.

[0075] Furthermore, the secure workspace interface has a display list, and the application display information is displayed in the display list. When the target application is in the secure workspace, running the target application in the secure workspace based on the executable file includes:

[0076] In response to a first preset operation on the application display information in the display list, the executable file is run based on the link embedded in the application display information to run the target application in the secure workspace.

[0077] In this embodiment, the secure workspace interface has a display list, in which application display information of all target applications is displayed. The user can perform a first preset operation (such as double-clicking) on ​​a certain application display information in the list. At this time, the link embedded in the application display information will directly run the executable file, realizing the running of the target application in the secure workspace. The data generated during the running of the target application will be stored in the database corresponding to the secure workspace, which is isolated from the application data outside.

[0078] The application operation control method based on a secure workspace provided in this invention achieves the purpose of running the target application in a secure workspace by linking the executable file with the application display information, thereby isolating the data during the operation from external data. It is also simple to operate and does not require additional instruction.

[0079] Furthermore, the method also includes:

[0080] If no file information matching the application information of the target application is obtained, the application display information of the target application is displayed in a preset color in the secure workspace. The application display information includes the target application display name and / or icon.

[0081] In this embodiment, there may be a situation where the application information is not matched in the system directory. In this case, the application display information (e.g., the application's display name, icon, etc.) is displayed in the secure workspace using a preset color (e.g., gray) to indicate that the target application is in an inoperable state in the secure workspace.

[0082] When the application display information is grayed out, users can manually obtain the corresponding path information of the target application. Specifically, users can right-click the grayed-out target application icon in the interface and manually specify the executable file to be matched in the pop-up file selection dialog box. The path information corresponding to this specified executable file is the path information of the target application.

[0083] The application operation control method based on a safe workspace provided in this embodiment of the invention indicates that the target application is currently in an inoperable state within the safe workspace by displaying the application display information of the target application in a preset color.

[0084] It should be noted that in this embodiment, the secure workspace is specifically limited to a sandbox, that is, a scenario in which the target application is tested. In other embodiments of the present invention, the secure workspace may also be...

[0085] Additionally, if you need to remove the target application from the secure workspace, you can delete the application from the list in the secure workspace. At this time, the application's display information will be deleted accordingly, the executable file will be deleted from the database corresponding to the secure workspace, and the cached data generated by the target application during its previous operation will also be deleted.

[0086] The application operation control device based on a safe workspace provided by the present invention is described below. The application operation control device based on a safe workspace described below can be referred to in correspondence with the application operation control method based on a safe workspace described above.

[0087] Figure 2 A schematic diagram of the application operation control device based on a safe workspace provided in an embodiment of the present invention is shown below. Figure 2 As shown, an application operation control device based on a safe workspace includes:

[0088] Application information acquisition unit 201 is used to acquire application information of a target application, wherein the target application is an application that needs to be run in a secure workspace.

[0089] The file matching unit 202 is used to match the application information of the target application with the file information in the system directory to obtain the file information that matches the application information of the target application, wherein the system directory stores the file storage location corresponding to the file information;

[0090] The storage location determination unit 203 is used to determine the file storage location of the target application based on the acquired file information.

[0091] The secure workspace operation unit 204 is used to run the corresponding target application within the secure workspace using the determined file storage location.

[0092] In this embodiment, the application that needs to isolate the data generated during its operation from other applications is designated as the target application. Before controlling the target application to run in the workspace, the application information of the target application is obtained. This application information can be the name of the target application (Chinese, English abbreviation, English full name, etc.), or information such as the target application's identifier, code, or code, or the target application's MD5 value.

[0093] After obtaining the application information, the system directory (i.e., Windows\Start Menu) is traversed based on the application's name, identifier, MD5 value, and other information to ensure that no application under the Windows\Start Menu is missed, and to obtain the file information that matches the application information.

[0094] The file information that matches the application information includes all application-related file information, such as the application's display name, executable file, application path information, etc.

[0095] It should be noted that applications can exist in the system directory as shortcuts or directly as executable files. If it is a shortcut, the application shortcut needs to be parsed to obtain the corresponding executable file name. Then, all executable file names are matched against the application information. If a match is found, the location of the executable file is obtained, and then all file information corresponding to the target application is retrieved based on that location.

[0096] After matching the file information corresponding to the target application, the file storage location corresponding to the target application is further determined based on the file storage location pre-stored in the system directory.

[0097] After determining the file storage location corresponding to the target application, the target application is run directly within the secure workspace using that file storage location.

[0098] The application operation control device based on a secure workspace provided in this embodiment of the invention obtains application information related to applications that need to be placed in a secure workspace for data isolation, then obtains file information related to the target application in the system directory based on the application information, and then runs the target application directly in the secure workspace according to the file storage location corresponding to the file information. This eliminates the need for users to drag and drop the application into the secure workspace, and also eliminates the need for instruction during initial use, reducing user operation steps and improving user experience.

[0099] Figure 3 This is a schematic diagram of the physical structure of an electronic device provided in an embodiment of the present invention, such as... Figure 3 As shown, the electronic device may include a processor 310, a communications interface 320, a memory 330, and a communication bus 340, wherein the processor 310, communications interface 320, and memory 330 communicate with each other via the communication bus 340. The processor 310 can call logical instructions in the memory 330 to execute an application execution control method based on a secure workspace. This secure workspace-based application execution control method includes: acquiring application information of a target application, wherein the target application is an application that needs to run in a secure workspace; matching the application information of the target application with file information in a system directory to obtain file information that matches the application information of the target application, wherein the system directory stores the file storage location corresponding to the file information; determining the file storage location of the target application based on the acquired file information; and running the corresponding target application within the secure workspace using the determined file storage location.

[0100] Furthermore, the logical instructions in the aforementioned memory 330 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0101] In another aspect, the present invention also provides a non-transitory computer-readable storage medium storing a computer program thereon. When executed by a processor, the computer program implements the application operation control method based on a secure workspace provided by the above-described methods. The application operation control method based on a secure workspace includes: acquiring application information of a target application, wherein the target application is an application that needs to be run in a secure workspace; matching the application information of the target application with file information in a system directory to acquire file information that matches the application information of the target application, wherein the system directory stores the file storage location corresponding to the file information; determining the file storage location of the target application based on the acquired file information; and running the corresponding target application in the secure workspace using the determined file storage location.

[0102] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0103] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., including several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods of various embodiments or some parts of embodiments.

[0104] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. An application operation control method based on a safe workspace, characterized in that, include: Obtain application information of the target application, wherein the target application is an application that needs to be run in a secure workspace, and the application is an application that is running in a secure workspace for the first time; The application information of the target application is matched with the file information in the system directory to obtain the file information that matches the application information of the target application, wherein the system directory stores the file storage location corresponding to the file information; The file storage location of the target application is determined based on the obtained file information; the file information includes application display information and executable files corresponding to the target application. The application display information is displayed on the secure workspace interface according to the file storage location; The executable file is stored in a database corresponding to the secure workspace, and a link pointing to the location of the executable file in the database is embedded in the application display information, so that the executable file is run based on the link through a first preset operation on the application display information.

2. The application operation control method based on a safe workspace according to claim 1, characterized in that, Obtain application information for the target application, including: Obtain the configuration policy for the secure workspace from the console. The configuration policy includes application information for applications that need to run in the secure workspace. The configuration policy is parsed to obtain application information for the target application.

3. The application operation control method based on a safe workspace according to claim 1, characterized in that, The acquisition of application information of the target application includes: The application information of the target application is obtained based on the user's second preset operation, which includes selecting the target application and obtaining the path information of the target application.

4. The application operation control method based on a safe workspace according to claim 2 or 3, characterized in that, The application information of the target application includes the application display name and / or the executable file name.

5. The application operation control method based on a safe workspace according to claim 1, characterized in that, The method also includes: When launching the target application, determine whether the target application is in a secure workspace; If the target application is in a secure workspace, the target application is run in the secure workspace based on the executable file; If the target application is not in the secure workspace, perform the step of matching the application information of the target application with the file information in the system directory.

6. The application operation control method based on a safe workspace according to claim 5, characterized in that, The secure workspace interface has a display list, and the application display information is displayed in the display list. When the target application is in the secure workspace, running the target application in the secure workspace based on the executable file includes: In response to a first preset operation on the application display information in the display list, the executable file is run based on the link embedded in the application display information to run the target application in the secure workspace.

7. The application operation control method based on a safe workspace according to claim 2 or 3, characterized in that, The method also includes: If no file information matching the application information of the target application is obtained, the application display information of the target application is displayed in a preset color in the secure workspace. The application display information includes the target application display name and / or icon.

8. The application operation control method based on a safe workspace according to claim 1, characterized in that, The safe workspace includes a sandbox.

9. An application start-up control device based on a safe workspace, characterized in that, The application operation control method based on a safe workspace as described in any one of claims 1-8 includes: An application information acquisition unit is used to acquire application information of a target application, wherein the target application is an application that needs to be run in a secure workspace, and the application is an application that is running in a secure workspace for the first time. The file matching unit is used to match the application information of the target application with the file information in the system directory to obtain the file information that matches the application information of the target application, wherein the system directory stores the file storage location corresponding to the file information; A storage location determination unit is used to determine the file storage location of the target application based on the acquired file information; the file information includes application display information and executable files corresponding to the target application. The secure workspace operation unit is used to display the application display information on the secure workspace interface according to the file storage location.

10. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the application operation control method based on a secure workspace as described in any one of claims 1 to 8.

11. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the application operation control method based on a secure workspace as described in any one of claims 1 to 8.