Data calling method and electronic device
By creating isolated spaces within electronic devices to store the data of malicious applications, the security risks caused by users' inability to identify malicious applications are solved. This achieves isolation between the storage and running spaces of applications, preventing malicious applications from tampering with the data.
Patent Information
- Application Number
- CN202310359257.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2023-03-23
- Filing Date
- 2023-03-31
- Publication Date
- 2026-01-09
- Estimated Expiration
- 2043-03-31
AI Technical Summary
Users are unable to identify malicious applications, which can lead to security risks on electronic devices after installation, such as the tampering with sensitive data.
By creating isolated spaces within electronic devices to store data from malicious applications, it ensures that malicious applications can only access data within their own isolated spaces, while normal applications can only access public storage spaces, thus achieving isolation between the application's storage and runtime spaces.
It effectively reduces the security risks of malicious applications to electronic devices and prevents malicious applications from tampering with the data of other applications.
Smart Images

Figure CN118690352B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Embodiments of the present application relate to the technical field of electronic devices, and in particular, to a data calling method and an electronic device. BACKGROUND
[0002] A user may install various application programs on an electronic device. When the user cannot distinguish whether a to-be-installed application program is a malicious application program, the user may install the malicious application program on the electronic device. After the malicious application program is installed on the electronic device by the user by mistake, the malicious application program may bring some security risks to the electronic device. For example, the malicious application program may obtain sensitive information on the electronic device. SUMMARY
[0003] The data calling method and the electronic device provided by the embodiments of the present application reduce the security risks brought by the application program.
[0004] To achieve the above object, the embodiments of the present application adopt the following technical solutions.
[0005] In a first aspect, the embodiments of the present application provide a data calling method. The execution subject of the method can be an electronic device or a component (for example, a chip, a chip system or a processor, etc.) in the electronic device. Hereinafter, the execution subject is taken as an example to be described, and the method comprises: displaying, by the electronic device, a first interface, and the first interface displays a first control for triggering isolation of a first application. In response to receiving a first operation on the first control, the electronic device determines that the first application is an isolated application. The electronic device stores data of the first application in a first isolated space when it is determined that the first application is an isolated application, and the first isolated space is used only for storing the data of the first application. The electronic device receives a first request of the first application, and the first request is used for calling data. The electronic device calls only the data in the first isolated space according to the first request when it is determined that the first application is an isolated application.
[0006] The isolation can be understood as separation or isolation. The isolation of the first application can be understood as separate storage or running of the first application from other applications. That is, the data of the first application is stored separately from the data of other applications, or the running space of the first application is different from the running space of other applications.
[0007] The isolated application can be understood as an application program with lower security, and the normal application can be understood as an application program with higher security. The first isolated space can be understood as a dedicated space of the first application when the first application is an isolated application, and no data of other application programs is stored in the first isolated space. The public storage space can be understood as a public storage space.
[0008] In the embodiments of this application, when the first application is an isolated application, the data of the first application is stored in the first isolated space of the electronic device. When the second application is a normal application, the data of the second application is stored in the common storage space of the electronic device, which is a common storage space of data on the electronic device. The first application can only call the data in the first isolated space when calling data, and cannot access the data in the common storage space. The second application can only call the data in the common storage space when calling data, and cannot access the data in the first isolated space. Further, the storage space and the running space of the first application and the second application are isolated, so that the first application cannot access the data of other applications, thereby reducing the security risks caused by the first application.
[0009] In a design scheme, the data calling method provided by the embodiments of the present application further includes: the electronic device receives a second request of a second application, the second request being used to call data. The electronic device calls the data in a target space according to the second request, when determining that the second application is a normal application, wherein the target space does not include an isolated space, and the isolated space includes a first isolated space. The calling of the data can include at least one of viewing the data, modifying the data and deleting the data.
[0010] In a design scheme, the data calling method provided by the embodiments of the present application further includes: the electronic device receives a third request of a first application, the third request being used to add data. The electronic device adds the data only in a first isolated space according to the third request, when determining that the first application is an isolated application.
[0011] In a design scheme, the data calling method provided by the embodiments of the present application further includes: the electronic device receives a fourth request of a fourth application, the fourth request being used to call data. The electronic device calls the data in a target space according to the fourth request, when determining that the fourth application is an isolated application, wherein the target space includes an isolated space, and the isolated space includes a fourth isolated space.
[0012] In a design scheme, the data calling method provided by the embodiments of the present application further includes: the electronic device receives a fifth request of a second application, the fifth request being used to add data. The electronic device adds the data only in a target space according to the fifth request, when determining that the second application is a normal application.
[0013] In a design scheme, the first interface is an installation interface of the first application, and the first control is an isolated installation control. Alternatively, the first interface is a setting interface, and the first control is an isolated setting control. That is, when the first application is installed, the first application can be set as an isolated application, or after the first application is installed on the electronic device, the first application can be set as an isolated application by operating the setting application of the electronic device.
[0014] In an example, the first interface is a setting interface, and the first control is an isolation setting control. In response to determining that the first application is an isolated application, the electronic device stores data of the first application in the first isolated space. For example, in response to determining that the first application is an isolated application, the electronic device migrates data of the first application stored in the common storage space to the first isolated space.
[0015] In an example, in response to the first operation on the first control, the electronic device determines that the first application is an isolated application. For example, in response to the first operation on the first control, the electronic device configures the first application with first marking information, and the first marking information is used to mark the first application as an isolated application. In this way, the electronic device can store data of the first application in the first isolated space according to the marking information.
[0016] In this way, by marking the first application as an isolated application, the storage space of the isolated application is independent of the storage space of a normal application, and the running space of the isolated application is independent of the running space of the normal application, so as to achieve the isolation purpose of the isolated application and the normal application, and improve the security.
[0017] In an example, the method further includes: in response to detecting an operation of triggering the first application to be unisolated, the electronic device migrates data of the first application in the first isolated space to the common storage space.
[0018] In an example, the first interface is a setting interface, and the first control is further used to trigger the first application to be unisolated. The method further includes: in response to a second operation on the first control on the setting interface, the electronic device configures the first application with second marking information, and the second marking information is used to mark the first application as a normal application. The electronic device migrates data of the first application in the first isolated space to the common storage space.
[0019] In an example, the isolated space further includes a second isolated space, and the second isolated space is used to store data of a third application in an isolated case.
[0020] In an example, the first interface is a setting interface, and the first interface further displays a second control used to trigger unisolation. The method further includes: in response to an operation on the second control, the electronic device clears the marking information of the first application. The electronic device migrates data of the first application in the first isolated space to the common storage space.
[0021] In this way, by operating the setting application of the electronic device, the first application is marked as an isolated application, so that the storage space of the isolated application is independent of the storage space of a normal application, and the running space of the isolated application is independent of the running space of the normal application, so as to achieve the isolation purpose of the isolated application and the normal application, and improve the security.
[0022] In this way, by operating the setting application of the electronic device, the first application can be converted between the isolated application and the normal application, and the user can flexibly adjust according to the needs, which is high in practicability while ensuring security.
[0023] In an example, the first isolated space and the common storage space can belong to the same user account. Of course, the first isolated space and the common storage space can also belong to different user accounts.
[0024] In an example, the electronic device displays the first interface, specifically, the electronic device displays the first interface when it is determined that the first application does not satisfy the trusted condition.
[0025] In an example, the first application not satisfying the trusted condition includes that a download source of the first application does not belong to a download source white list, or the download source of the first application belongs to a download source black list. The download source white list can be understood as a list of allowed download sources, for example, a list of specified stores, such as Huawei Store. The download source black list can be understood as a list of disallowed download sources, for example, a website or other storage devices (such as a U disk, a mobile hard disk, etc.).
[0026] In an example, the first application not satisfying the trusted condition includes that a trustworthiness of the first application is less than or equal to a first threshold, where the trustworthiness of the first application is used to represent the security of the first application.
[0027] In a second aspect, an example of the present application provides an electronic device, which includes a display module, a determination module, a storage module, a receiving module and a calling module. The display module is configured to display a first interface, and the first interface displays a first control for triggering isolation of a first application. The determination module is configured to determine that the first application is an isolated application in response to receiving a first operation on the first control. The storage module is configured to store data of the first application in a first isolated space when it is determined that the first application is an isolated application, and the first isolated space is only used to store the data of the first application. The receiving module is configured to receive a first request of the first application, and the first request is used to call data. The calling module is configured to call only the data in the first isolated space according to the first request when it is determined that the first application is an isolated application.
[0028] In an example, isolation can be understood as separation or partition. Isolating the first application can be understood as storing or running the first application separately from other applications. That is, the data of the first application is stored separately from the data of other applications, or the running space of the first application is different from the running space of other applications.
[0029] The isolated application can be understood as an application with lower security, and the normal application can be understood as an application with higher security. The first isolated space can be understood as a dedicated space of the first application when the first application is an isolated application, and no data of other applications is stored in the first isolated space. The common storage space can be understood as a common storage space.
[0030] In the embodiments of the application, when the first application is an isolated application, data of the first application is stored in a first isolated space of the electronic device. When the second application is a normal application, data of the second application is stored in a common storage space of the electronic device, which is a common storage space of data on the electronic device. The first application can only call data in the first isolated space when calling data, and cannot access data in the common storage space. The second application can only call data in the common storage space when calling data, and cannot access data in the first isolated space. Further, the storage space and the running space of the first application and the second application are isolated, so that the first application cannot access data of other applications, thereby reducing the security risks caused by the first application.
[0031] In a design scheme, the first interface is an installation interface of the first application, and the first control is an isolated installation control. Alternatively, the first interface is a setting interface, and the first control is an isolated setting control. That is, when the first application is installed, the first application can be set as an isolated application, or after the first application is installed on the electronic device, the first application can be set as an isolated application by operating a setting application of the electronic device.
[0032] In a design scheme, the receiving module is configured to receive a second request of the second application, and the second request is configured to call data. The calling module is configured to call data in a target space according to the second request, when it is determined that the second application is a normal application, wherein the target space does not include an isolated space, and the isolated space includes the first isolated space.
[0033] In a design scheme, the electronic device further includes an adding module. The receiving module is configured to receive a third request of the first application, and the third request is configured to add data. The adding module is configured to add data only in the first isolated space according to the third request, when it is determined that the first application is an isolated application.
[0034] In a design scheme, the first interface is an installation interface of the first application, and the first control is an isolated installation control. Alternatively, the first interface is a setting interface, and the first control is an isolated setting control.
[0035] In a design scheme, the first interface is a setting interface, and the first control is an isolated setting control. The storage module is configured to: when it is determined that the first application is an isolated application, migrate data of the first application stored in the common storage space to the first isolated space.
[0036] In one design, the determining module is configured to: in response to the first operation on the first control, configure the first application with first marking information, the first marking information being used to mark the first application as an isolated application.
[0037] In this way, by marking the first application as an isolated application, the storage space of the isolated application is independent of the storage space of normal applications, and the running space of the isolated application is independent of the running space of normal applications, so as to achieve the isolation purpose of the isolated application and the normal application, and improve the security.
[0038] In one design, the electronic device further includes a migration module, the migration module being configured to: in response to detecting an operation that triggers un-isolation of the first application, migrate data of the first application in the first isolated space to the common storage space.
[0039] In one design, the storage module is configured to: in response to a second operation on the first control on the setting interface, configure the first application with second marking information, the second marking information being used to mark the first application as a normal application; and migrate data of the first application in the first isolated space to the common storage space.
[0040] In this way, by operating the setting application of the electronic device, the first application can be converted between an isolated application and a normal application, and the user can flexibly adjust according to the requirement, which is of high practicability while ensuring the security.
[0041] In one design, the first isolated space and the common storage space can belong to the same user account. Of course, the first isolated space and the common storage space can also belong to different user accounts.
[0042] In one design, the isolated space further includes a second isolated space, the second isolated space being used to store data of a third application in an isolated case.
[0043] In one design, the display module is configured to: display the first interface when it is determined that the first application does not satisfy the trusted condition.
[0044] In one design, the first application not satisfying the trusted condition includes that a download source of the first application does not belong to a download source white list, or the download source of the first application belongs to a download source black list. The download source white list can be understood as a list of allowed download sources, for example, a list of specified stores, such as Huawei Store. The download source black list can be understood as a list of disallowed download sources, for example, a website or other storage devices (such as a U disk, a mobile hard disk, etc.).
[0045] In an example, the first application not satisfying the trust condition includes that a trust level of the first application is less than or equal to a first threshold, where the trust level of the first application is used to represent security of the first application.
[0046] In a third aspect, an electronic device is provided. The electronic device includes one or more processors and memory storing computer instructions. When the computer instructions are executed by the processor, the electronic device performs the method of the first aspect.
[0047] In a fourth aspect, a computer readable storage medium is provided. The computer readable storage medium includes computer instructions. When the computer instructions are executed by an electronic device, the electronic device performs the method of the first aspect.
[0048] The specific implementation and corresponding technical effects of each embodiment of the second aspect to the fourth aspect can refer to the specific implementation and technical effects of the first aspect. BRIEF DESCRIPTION OF DRAWINGS
[0049] Figure 1 An interface diagram for installing an XX application on an electronic device;
[0050] Figure 2 An interface diagram for installing an XX application on an electronic device in an embodiment of the present application;
[0051] Figure 3 An interface diagram for installing an XX application on an electronic device in an embodiment of the present application;
[0052] Figure 4 An interface diagram for installing an XX application on an electronic device in an embodiment of the present application;
[0053] Figure 5 An interface diagram for installing an XX application on an electronic device in an embodiment of the present application;
[0054] Figure 6 An interface diagram for installing an XX application on an electronic device in an embodiment of the present application;
[0055] Figure 7-1 A flowchart of a data calling method provided in an embodiment of the present application;
[0056] Figure 7-2 A flowchart of a data calling method provided in an embodiment of the present application;
[0057] Figure 8 A scene diagram of installing an application on an electronic device provided in an embodiment of the present application;
[0058] Figure 9This application provides a schematic diagram of a data retrieval method in one scenario.
[0059] Figure 10 A schematic diagram of the application management list provided in an embodiment of this application;
[0060] Figure 11 A schematic diagram of an external system directory in an electronic device provided in an embodiment of this application;
[0061] Figure 12 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0062] People need to install various applications on their electronic devices. These application installation packages can come from app stores, be downloaded from websites, or be transferred via other storage devices (such as USB drives). Therefore, these applications may be malicious (such as applications carrying viruses). Even when users cannot distinguish whether an application to be installed is malicious, they may still install malicious applications on their electronic devices through methods such as application prompts. Once installed, malicious applications may pose security risks to the electronic device; for example, they may tamper with sensitive data on the device.
[0063] For example, the electronic device can be a mobile phone. Figure 1 This is a schematic diagram of the interface for installing the XX application on a mobile phone. For example... Figure 1 As shown, the display on mobile phone 100 is as follows Figure 1 The interface 101 shown displays a control 102 for canceling the installation and a control 103 for continuing the installation. Interface 101 also displays a security warning message for the application, which may read, "Security reminder: The source of this application has not disclosed whether the application complies with the 'Huawei Terminal Quality Inspection and Security Review Standards'." The user can determine whether to continue the installation based on the warning message. If the user chooses to continue installing the application, they can click as follows... Figure 1 The control 103 on the interface 101 shown. At this time, the mobile phone 100 performs the operation of installing the XX application. If the user does not want to continue installing the application, the user clicks as shown. Figure 1 Control 102 on the interface 101 shown. At this time, the mobile phone 100 does not perform the operation of installing the XX application.
[0064] It is evident that users cannot distinguish whether the aforementioned XX applications are malicious applications, or if the aforementioned XX applications are malicious applications but the user insists on installing them, once these applications are installed on electronic devices, they will bring some security risks to the electronic devices, such as the application may tamper with the sensitive data of the electronic devices.
[0065] To solve the above problems, an embodiment of the present application provides a data calling method, which comprises: when a first application is an isolated application, an electronic device stores data of the first application in a first isolated space of the electronic device; and when a second application is a normal application, the electronic device stores data of the second application in a common storage space of the electronic device. The first application can only call data in the first isolated space and cannot call data in the common storage space when calling data. The second application can only call data in the common storage space and cannot call data in the first isolated space when calling data. Thus, the storage space and running space of the first application and the second application are isolated, so that the first application cannot access data of other applications, thereby reducing the security risks caused by the first application.
[0066] In some examples, when a third application is an isolated application, the electronic device stores data of the third application in a second isolated space of the electronic device. The second isolated space and the first isolated space belong to the isolated space. The second isolated space is isolated from the first isolated space. The first application can only call data in the first isolated space and cannot call data in the second isolated space when calling data. The third application can only call data in the second isolated space and cannot call data in the first isolated space when calling data. Thus, the storage space and running space of the first application and the third application are isolated, so that the first application cannot access data of other applications, thereby reducing the security risks caused by the first application.
[0067] The first isolated space can be understood as a dedicated space of the first application, and no data of other applications is stored in the first isolated space. The space can be understood as a storage space and / or a running space. The second isolated space can be understood as a dedicated space of the third application, and no data of other applications is stored in the second isolated space. The common storage space is used to store data of normal applications on the electronic device. The normal application can be understood as an application with high security. The isolated application can be understood as an application with low security. In the embodiment of the present application, no specific limitation is made, and the specific implementation needs to be determined according to the actual situation.
[0068] In some examples, the electronic device sets the first application as an isolated application. Specifically, the electronic device displays a first interface, and the first interface displays a first control for triggering the isolation of the first application. In response to receiving an operation on the first control, the electronic device sets the first application as an isolated application and stores data of the isolated application in the first isolated space. The first interface can be an installation interface or a setting interface, and the details are as follows:
[0069] In some examples, the first interface can be an installation interface of the first application, and the first isolated space can be an isolated installation control. Specifically, the data calling method provided by the embodiments of the present application can include: an electronic device displays an installation interface, and the interface displays an isolated installation control. In response to receiving an operation on the isolated installation control, the electronic device stores data of the first application in a first isolated space. Exemplarily, Figure 2 An interface diagram of an electronic device is provided for the embodiments of the present application. As shown in Figure 2 , it is assumed that the first application is an XX application. The electronic device 100 displays an installation interface 201 of the XX application, and the interface 201 displays an isolated installation control 204. When the user clicks the control 204, the electronic device 100 receives the click operation of the user. In response to the click operation, the electronic device 100 installs the XX application, and stores data of the XX application in a first isolated space of the electronic device 100. Figure 2
[0070] In some examples, the electronic device installs the first application on the electronic device in isolation, which can be specifically implemented as: the electronic device marks the first application as an isolated application, and stores data of the isolated application in a first isolated space. Optionally, the first isolated space and the common storage space belong to the same user account. Of course, the first isolated space and the common storage space can also belong to different user accounts. In other examples, the electronic device installs the first application on the electronic device in isolation, which can be specifically implemented as: the electronic device installs the first application as an isolated application under a specified account, the specified account being different from other accounts, and installs a non-isolated application under the other accounts, and installs the isolated application under the specified account.
[0071] In some examples, the first interface can be a settings interface, and the first control can be an isolated settings control. Specifically, the data calling method provided by the embodiments of the present application can include: an electronic device displays a settings interface, and the interface displays an isolated settings control. In response to receiving an operation on the isolated settings control, the electronic device stores data of the first application in a first isolated space. Exemplarily, Figure 3 An interface diagram of an electronic device is provided for the embodiments of the present application. As shown in Figure 3 , it is assumed that the first application is an XX application. The electronic device 100 displays a settings interface 301 of the XX application, and the interface 301 is an application management interface. The interface 301 displays various applications installed on the electronic device, such as the XX application, the MM application, the YY application, the ZZ application, the SS application, and the KK application. When the user clicks the option 302 corresponding to the XX application, the interface of the electronic device jumps from the interface 301 shown in Figure 3 Figure 3 Figure 4 The interface 401 shown is an application information interface of the XX application. The isolation setting option 402 is displayed on the interface 401, and the isolation setting control is displayed in an unselected state. When the user clicks Figure 4 the option 402, the electronic device 100 displays the interface 401 shown, in which the isolation setting control is displayed in a selected state. The electronic device 100 receives the click operation of the user. In response to the click operation, the electronic device 100 marks the XX application as an isolated application, and migrates the data of the XX application from the common storage space of the electronic device to the first isolated space of the electronic device 100. Figure 5
[0072] It can be seen that by operating the interface of the electronic device, the first application is marked as an isolated application, and the data of the first application in the isolated case and the non-isolated case is stored in different spaces. If the application is a malicious application, the security risks brought by the application can be reduced.
[0073] The electronic device can be a mobile phone, a tablet computer, a laptop computer, a notebook computer, an ultra-mobile personal computer (UMPC), a handheld computer, a netbook, a personal digital assistant (PDA), a wearable electronic device, or the like. The specific form of the electronic device is not specially limited in the embodiments of the present application.
[0074] Figure 6 The electronic device is a structural diagram.
[0075] As shown in Figure 6 , the electronic device 100 can include a processor 210, an external memory interface 220, a universal serial bus (USB) interface 230, a charge management module 240, a power management module 241, a battery 242, a memory 250, an antenna 1, a wireless communication module 260, a display screen 270, and a sensor module 280, etc. The sensor module 280 can include a pressure sensor 280A, an acceleration sensor 280B, a touch sensor 280C, etc.
[0076] It can be understood that the structure shown in the embodiments of the present application does not constitute a specific limitation on the electronic device. In other embodiments of the present application, the electronic device can include more or fewer components than shown, or combine certain components, or split certain components, or different component arrangements. The components shown can be implemented in hardware, software, or a combination of software and hardware.
[0077] The processor 210 can include one or more processing units, for example: the processor 210 can include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Among them, different processing units can be independent devices, or can be integrated in one or more processors.
[0078] The controller can generate operation control signals according to the instruction operation code and the timing signal, complete the control of fetching and executing instructions.
[0079] The processor 210 can also be provided with a memory for storing instructions and data. In some embodiments, the memory in the processor 210 is a cache memory. The memory can save instructions or data that the processor 210 has just used or repeatedly uses. If the processor 210 needs to use the instructions or data again, it can be directly called from the memory. This avoids repeated access and reduces the waiting time of the processor 210, thereby improving the efficiency of the system.
[0080] The charging management module 240 is used to receive charging input from a charger. The charger can be a wireless charger or a wired charger. In some wired charging embodiments, the charging management module 240 can receive the charging input of the wired charger through the USB interface 230. In some wireless charging embodiments, the charging management module 240 can receive the wireless charging input through the wireless charging coil of the electronic device. The charging management module 240 can charge the battery 242 while also supplying power to the electronic device through the power management module 241.
[0081] The power management module 241 is used to connect the battery 242, the charging management module 240, and the processor 210. The power management module 241 receives the input of the battery 242 and / or the charging management module 240, and supplies power to the processor 210, the memory 220, the display screen 270, and the wireless communication module 260, etc. The power management module 241 can also be used to monitor parameters such as battery capacity, battery cycle number, battery health state (leakage, impedance), etc. In other embodiments, the power management module 241 can also be arranged in the processor 210. In other embodiments, the power management module 241 and the charging management module 240 can also be arranged in the same device.
[0082] The wireless communication function of the electronic device can be implemented by the antenna 1, the wireless communication module 260, the modem processor, and the baseband processor, etc.
[0083] The antenna 1 is used for transmitting and receiving electromagnetic wave signals. Each antenna in the electronic device can be used to cover a single or multiple communication frequency bands. Different antennas can also be multiplexed to improve the utilization of the antennas. For example, the antenna 1 can be multiplexed as a diversity antenna of a wireless local area network. In some other embodiments, the antenna can be used in combination with a tuning switch.
[0084] The wireless communication module 260 can provide a wireless communication solution applied to the electronic device, including wireless local area networks (WLAN) (such as a wireless fidelity (Wi-Fi) network), Bluetooth (BT), a global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared technology (IR), etc. The wireless communication module 260 can be one or more devices integrating at least one communication processing module. The wireless communication module 260 receives electromagnetic waves via the antenna 1, performs frequency modulation and filtering processing on the electromagnetic wave signals, and sends the processed signals to the processor 210. The wireless communication module 260 can also receive signals to be sent from the processor 210, perform frequency modulation and amplification, and convert the signals into electromagnetic wave radiation via the antenna 1. In some embodiments, the wireless communication module 260 receives application information sent by a server.
[0085] The electronic device implements a display function by a GPU, a display screen 270, and an application processor, etc. The GPU is a microprocessor for image processing, connected to the display screen 270 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. The processor 210 can include one or more GPUs that execute program instructions to generate or change display information.
[0086] The display screen 270 is configured to display images, videos, and the like. The display screen 270 includes a display panel. The display panel can be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flex light-emitting diode (FLED), a Miniled, a Micro Led, a Micro-oLed, a quantum dot light emitting diode (QLED), or the like. In some embodiments, the electronic device can include one or N display screens 270, where N is a positive integer greater than 1.
[0087] In some embodiments, the display screen 270 displays an interface 201 as shown in Figure 2 In some embodiments, the display screen 270 displays an interface 301 as shown in Figure 3 In some embodiments, the display screen 270 displays an interface 401 as shown in Figure 4 In some embodiments, the display screen 270 displays an interface 401 as shown in
[0088] The external memory interface 220 can be configured to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the electronic device. The external memory card communicates with the processor 210 through the external memory interface 220 to implement a data storage function. For example, music, video, and the like files are saved in the external memory card. In some embodiments, the external storage device is connected through the memory interface 220 to copy the installation package of the application to be installed from the external storage device.
[0089] The memory 250 can be used to store computer-executable program codes including instructions. The memory 250 can include a program storage area and a data storage area. The program storage area can store an operating system, application programs (such as a sound play application, an image play application, etc.) required by at least one function, etc. The data storage area can store data (such as audio data, a phone book, etc.) created during use of the electronic device, etc. In addition, the memory 250 can include a high-speed random access memory, and can further include a nonvolatile memory such as at least one of a magnetic disk storage device, a flash memory device, a universal flash storage (UFS), etc. The processor 210 executes various function applications and data processing of the electronic device by running the instructions stored in the memory 250 and / or the instructions stored in the memory disposed in the processor.
[0090] The pressure sensor 280A is used to sense a pressure signal and can convert the pressure signal into an electrical signal. In some embodiments, the pressure sensor 280A can be disposed in the display screen 270. There are many types of pressure sensors 280A, such as a resistive pressure sensor, an inductive pressure sensor, a capacitive pressure sensor, etc. The capacitive pressure sensor can include at least two parallel plates with conductive material. When a force is applied to the pressure sensor 280A, the capacitance between the electrodes changes. The electronic device determines the intensity of the pressure according to the change in capacitance. When a touch operation is applied to the display screen 270, the electronic device detects the intensity of the touch operation according to the pressure sensor 280A. The electronic device can also calculate the position of the touch according to the detection signal of the pressure sensor 280A. In some embodiments, touch operations applied to the same touch position but with different touch operation intensities can correspond to different operation instructions. For example, when a touch operation with an intensity less than a first pressure threshold is applied to a short message application icon, an instruction to view a short message is executed. When a touch operation with an intensity greater than or equal to the first pressure threshold is applied to the short message application icon, an instruction to create a new short message is executed.
[0091] The acceleration sensor 280B can detect the magnitude of acceleration of the electronic device in each direction (generally three axes). When the electronic device is stationary, the magnitude and direction of gravity can be detected. It can also be used to identify the posture of the electronic device and applied to landscape / portrait switching, a pedometer, etc.
[0092] Touch sensor 280C, also referred to as "touch device". Touch sensor 280C can be disposed on display screen 270, and touch sensor 280C and display screen 270 form a touch screen, also referred to as "touch panel". Touch sensor 280C is configured to detect a touch operation acting on or near the touch sensor 280C. The touch sensor 280C can transmit the detected touch operation to the application processor to determine the touch event type. The visual output related to the touch operation can be provided through display screen 270. In some other embodiments, touch sensor 280C can also be disposed on the surface of the electronic device, which is different from the position where display screen 270 is located.
[0093] In some embodiments, touch sensor 280C detects a touch operation of a user on the control 201 of interface 201 shown in FIG. 2A for triggering the isolated installation. Figure 2 In some embodiments, touch sensor 280C detects a touch operation of a user on the control 201 of interface 201 shown in FIG. 2A for triggering the isolated installation. Figure 3 In some embodiments, touch sensor 280C detects a touch operation of a user on the control 201 of interface 201 shown in FIG. 2A for triggering the isolated installation. Figure 4 In some embodiments, touch sensor 280C detects a touch operation of a user on the control 201 of interface 201 shown in FIG. 2A for triggering the isolated installation. Figure 5 In some embodiments, touch sensor 280C detects a touch operation of a user on the control 201 of interface 201 shown in FIG. 2A for triggering the isolated installation.
[0094] Of course, the electronic device can also include other functional units, which are not limited in the embodiments of the present application.
[0095] In addition, the actions, terms, etc. involved in the embodiments of the present application can be mutually referred to and are not limited. The message names or parameter names in the messages in the embodiments of the present application are only one example, and other names can also be used in the specific implementation, which are not limited.
[0096] Figure 7-1 In some embodiments, the data calling method provided by the embodiments of the present application is shown in the flowchart of FIG. 4. As shown in FIG. 4, the method can be described in different stages, and the specific description is as follows: Figure 7-2 In some embodiments, the data calling method provided by the embodiments of the present application is shown in the flowchart of FIG. 4. As shown in FIG. 4, the method can be described in different stages, and the specific description is as follows: Figure 7-1 In some embodiments, the data calling method provided by the embodiments of the present application is shown in the flowchart of FIG. 4. As shown in FIG. 4, the method can be described in different stages, and the specific description is as follows: Figure 7-2 In some embodiments, the data calling method provided by the embodiments of the present application is shown in the flowchart of FIG. 4. As shown in FIG. 4, the method can be described in different stages, and the specific description is as follows:
[0097] First stage, application installation stage.
[0098] Figure 8 In some embodiments, the data calling method provided by the embodiments of the present application is shown in the flowchart of FIG. 4. As shown in FIG. 4, the method can be described in different stages, and the specific description is as follows: Figure 8As shown, before the electronic device 100 installs an application (application for short), the user can download the installation package of the application first. For example, the user can download the installation package of the application from an application market, or the user can copy the installation package of the application from another storage device, or the user can download the installation package of the application from a website. The embodiment of the present application does not limit the implementation manner of downloading the installation package of the application. When the installation package of the application is downloaded, the user triggers an installation operation, at this time, the electronic device performs S710, in detail:
[0099] S710, the electronic device displays a first interface of a first application, and the first interface displays a first control for triggering isolation of the first application.
[0100] Wherein, isolation can be understood as separation, isolation. Isolating the first application can be understood as storing or running the first application separately from other applications. That is, the data of the first application is stored separately from the data of other applications, or the running space of the first application is different from the running space of other applications.
[0101] That is, the data of the first application in the isolated case is located in a first isolated space of the electronic device, and the data of the first application in the non-isolated case is located in a common storage space of the electronic device, and the first isolated space is different from the common storage space.
[0102] The data of the first application can include registration data, installation data, user usage data, and the like. In different stages, the data of the first application contains different contents, for example, in the installation stage, the data of the first application can include registration data, and of course, the data of the first application can also include installation data. In the usage stage, the data of the first application can include registration data and user usage data. Of course, the embodiment of the present application is not limited thereto.
[0103] The first isolated space can refer to the data storage space of the application in the isolated case. The first isolated space can also be the storage space and running space of the first application in the isolated case. That is, the data storage spaces of various isolated applications are different from each other. The common storage space can refer to the common storage space of data on the electronic device, or the data storage space of the application in the non-isolated case. Optionally, the common storage space can also be understood as the data storage space of the first application in the non-isolated case, or the data storage space of all applications in the non-isolated case.
[0104] The first interface can be an installation interface of the application, and the first control can be a control for triggering installation and isolation, or a control for triggering installation and isolation running.
[0105] The display position of the first control on the first interface is not specifically limited. For example, the first control can be located in a side region of the first interface, and the first control and other controls are arranged side by side in the region.
[0106] For example, the first control can be an "isolated installation" control. The control is a control for triggering an isolated installation operation by a user. For example, the first interface displayed by the electronic device can be the interface 201 shown in FIG. 2A, and the first control can be the isolated installation control 204 on the interface 201 shown in FIG. 2B. Figure 2 Figure 2 For example, the first control can be an "isolated installation" control. The control is a control for triggering an isolated installation operation by a user. For example, the first interface displayed by the electronic device can be the interface 201 shown in FIG. 2A, and the first control can be the isolated installation control 204 on the interface 201 shown in FIG. 2B.
[0107] In some examples, the electronic device can directly display the first interface, and the electronic device can also display the first interface under certain conditions. For example, the electronic device displays the first interface when it is determined that the first application does not satisfy a trusted condition. The trusted condition can include that the download source of the first application belongs to a download source whitelist, or the download source of the first application does not belong to a download source blacklist, or the trustworthiness of the first application is greater than a first threshold. Details are as follows:
[0108] In a specific implementation, the electronic device displays the first interface when it is determined that the download source of the first application does not belong to the download source whitelist. The download source whitelist can be pre-stored by the electronic device, and the download source whitelist can refer to a list of download sources allowed by the electronic device. For example, the allowed download sources include a specified application store, such as Huawei AppGallery.
[0109] In another specific implementation, the electronic device displays the first interface when it is determined that the download source of the first application belongs to the download source blacklist. The download source blacklist can be pre-stored by the electronic device, and the download source blacklist can refer to a list of download sources not allowed by the electronic device. For example, the download sources not allowed can include websites, other storage devices (such as U disks, mobile hard disks), and the like.
[0110] In another specific implementation, when the electronic device determines that the trustworthiness of the first application is greater than the first threshold, the electronic device determines that the first application is trusted, and at this time, the electronic device displays a second interface, and the second interface does not display the first control for triggering isolated installation. The first threshold can be a set value, which is not specifically limited here. When the electronic device determines that the trustworthiness of the first application is less than or equal to the first threshold, the electronic device determines that the first application is not trusted, and at this time, the electronic device displays the first interface.
[0111] For example, when the electronic device determines that the first application satisfies the trusted condition, the electronic device displays, for example, the interface 201 shown in FIG. 2A. Figure 1 The interface 101 shown in the figure displays a control 102 for canceling the installation operation and a control 103 for triggering the continuation of the installation. When the electronic device determines that the first application does not meet the trusted condition, the electronic device displays the interface 201 shown in the figure, which displays a control 202 for canceling the installation operation, a control 203 for triggering the continuation of the installation, and a control 204 (i.e., the first control) for triggering the isolated installation. Figure 2 The interface 201 shown in the figure displays a control 202 for canceling the installation operation, a control 203 for triggering the continuation of the installation, and a control 204 (i.e., the first control) for triggering the isolated installation.
[0112] In a specific implementation, the electronic device can generate prompt information according to the trustworthiness of the first application, and the prompt information is displayed on the interface of the electronic device. For example, when the electronic device determines that the first application does not meet the trusted condition, the electronic device generates prompt information one, which can be “malicious application found” and “application isolation installation recommended”, and the prompt information one can be displayed on the first interface. When the electronic device determines that the first application meets the trusted condition, the electronic device generates prompt information two, which can be “safety reminder” and “application normal installation recommended”, and the prompt information two can be displayed on the second interface.
[0113] In a specific implementation, the trustworthiness of the first application can be determined according to the source of the first application. For example, the electronic device determines the source of the first application. When the electronic device determines that the first application comes from the application market, the electronic device determines that the trustworthiness of the first application is greater than the first threshold value, and thus the first application is trusted. When the electronic device determines that the first application comes from a website or other storage device, the electronic device determines that the trustworthiness of the first application is less than or equal to the first threshold value, and thus the first application is untrusted.
[0114] In a specific implementation, the source of the first application can be determined according to the calling party of the installer of the electronic device. For example, when the calling party of the installer of the electronic device is the installation module of the application market, the electronic device determines that the first application comes from the application market. When the calling party of the installer of the electronic device is the file manager, the electronic device determines that the first application comes from other storage devices. When the calling party of the installer of the electronic device is a third-party application, the electronic device determines that the first application comes from a web page or other third-party provider.
[0115] S720, in response to receiving the operation on the first control, the electronic device determines that the first application is an isolated application, and stores the data of the first application in the first isolated space.
[0116] The operation can include a click operation or a press operation, etc. The click operation can include a single-click operation, a multi-click operation, which is not limited in the embodiments of the present application.
[0117] After receiving the operation of the first control by the user, the electronic device marks the first application as an isolated application, and at this time, the electronic device stores data of the first application in the first isolated space. The following is described in detail in specific scenarios:
[0118] In the embodiments of the present application, S720 can be implemented in the following manner:
[0119] In a specific implementation manner, S720 can be specifically:
[0120] S721, in response to the operation of the first control, the electronic device configures the first application with first marking information, and the first marking information is used to mark the first application as an isolated application.
[0121] The first interface is an installation interface, and the first control is an isolated installation control. Specifically, when the user clicks the isolated installation control, the application management module of the electronic device marks the first application as an isolated application in the application management list in the form of adding marking information. Based on this, the isolated application can have an isolated application running space as shown in Figure 9 The marking information can be presented in the application management list. The marking information can be a marking symbol as shown in Figure 10 It can also be a field, such as a bool type field. For example, in the application management list, the default field of a normal application is false, and the default field of an isolated application is true. Of course, it is not limited to this. The marking information can also be presented as a positive integer in the application management list, and the value of the positive integer is associated with the installation time of the application, or in other words, the value of the positive integer can be used to provide timing information for the uninstallation of the application.
[0122] S722, the electronic device stores data of the first application in the first isolated space according to the first marking information.
[0123] For example, if the first marking information of the first application is true, the electronic device stores the data of the first application in the first isolated space; if the second marking information of the first application is false, the electronic device stores the data of the first application in the common storage space.
[0124] For example, as shown in Figure 11As shown, the electronic device configures an isolated space (such as / / Detention Area ( / APP Detained / )) under the external directory (such as / storage / emulated / <User_id>) of the system. The isolated space can include a first isolated space. When the first application is downloaded and installed, the electronic device marks the first application as an isolated application, and the system of the electronic device creates an application directory under the first isolated space, such as / storage / emulated / 0 / Detained / <pkg1>.
[0125] In some examples, the first isolated space and the common storage space can be different spaces under a user space of a same account. Alternatively, the first isolated space can be a user space of a first account, and the common storage space can be a user space of a second account, which is different from the first account. The electronic device can have multiple accounts, and each account corresponds to a storage and / or running space. That is, the storage spaces of each account are independent of each other, and the running spaces of each application in the storage spaces are also independent of each other.
[0126] Of course, in the first stage, if the first application is normally installed on the electronic device, the first application can be set as an isolated application in the second stage. Then, the first application can also be set as a normal application. Details are described as follows:
[0127] The second stage is an application setting stage. As shown in Figure 7-2
[0128] In S730, the electronic device displays a second interface, and the second interface displays a second control for triggering isolation.
[0129] The second interface can be a setting interface of the application, and of course, can also be another interface of the application, such as a use interface of the application. The embodiments of the present application do not make specific limitations.
[0130] For example, after the electronic device 100 installs the first application, the user can set the first application to be isolated through a setting application on the electronic device. For example, when the user clicks an icon of the setting application on the electronic device, the electronic device starts the setting application and displays an interface of the setting application, and the interface can display an application management control. When the user clicks the application management control, the electronic device 100 displays the interface 301 as shown in Figure 3 Figure 4 The interface 301 is an application management interface, and the interface displays information of each application (such as XX application, MM application, YY application, ZZ application, SS application, and KK application). The XX application is the first application. When the user clicks the information 302 of the XX application, the electronic device 100 displays the interface 401 as shown in
[0131] As shown in Figure 4 , the isolation option 402 on the interface 401 is in an unselected state, which indicates that the first application is a normal application. At this time, the mark information of the first application is false, and the data of the first application is stored in the common storage space of the electronic device. When the user clicks the isolation option 402 as shown in Figure 4 , the state of the isolation option 402 changes from the unselected state as shown in Figure 4 to a selected state as shown in Figure 5 The selected state is shown. At this time, the electronic device will modify the flag information of the first application, which will become true, and the first application will be converted from a normal application to an isolated application.
[0132] The second control can be Figure 4 The isolation option 402 shown is in an unselected state. Of course, this embodiment is not limited to this.
[0133] S740, In response to receiving an operation on the second control, the electronic device determines that the first application is an isolated application and stores the data of the first application in the first isolated space.
[0134] For example, the second control is Figure 4 The isolation option 402 is shown as unselected. When the user clicks... Figure 4 When option 402 is shown, isolation option 402 is presented. Figure 5 The selected state is shown below. At this time, as... Figure 11 As stated above, ① the electronic device can migrate the data of the first application (such as APP1) to the first isolated space, such as / storage / emulated / 0 / Detained / <pkg1>.
[0135] Of course, the first application can also be set as a normal application on the second interface, as shown in Figure 7-2 , and the implementation is as follows:
[0136] The data calling method provided by the embodiment of the present application further includes: the electronic device migrates the data of the first application in the first isolated space to the public storage space when detecting an operation of triggering the first application to be unisolated.
[0137] For example, the operation of triggering the first application to be unisolated can include an operation on the setting interface. The implementation can be as follows:
[0138] S750, in response to the operation on the second control, the electronic device migrates the data of the first application in the first isolated space to the public storage space.
[0139] For example, the second control is the isolation option 402 in the selected state as shown in Figure 5 .
[0140] In a specific implementation, as shown in Figure 7-2 , S750 can be implemented as follows:
[0141] S751, in response to the operation on the second control, the electronic device configures the second mark information for the first application.
[0142] In the above example, when the second mark information of the first application becomes true, the electronic device migrates the data of the first application from the first isolated space to the public storage space.
[0143] S752, the electronic device migrates the data of the first application in the first isolated space to the public storage space.
[0144] For example, as shown in Figure 5 , when the user clicks the option 402 as shown in Figure 5 , the isolation option 402 presents the unselected state as shown in Figure 4 . At this time, as shown in Figure 11 , the electronic device can migrate the data of the first application from the isolated space directory to the public storage space under the external directory, such as / storage / emulated / 0 / Android / data / <pkg1>.
[0145] The third stage is the application usage stage.
[0146] As described above, after the data of the first application is stored in the first isolated space, the first application can modify / delete / access / add data of other applications, which can refer to file management applications such as file managers, clones, and the like. The other application can also refer to a cross-space application, such as a media library application. The first application can also modify / delete / access / add data on the electronic device. The following is described in detail in different cases:
[0147] Case 1: The first application requests to call / add data.
[0148] In some examples, as shown in FIG. 8, the data calling method provided by the embodiments of the present application further includes: Figure 7-1
[0149] S760, the electronic device receives a first request of the first application, and the first request is used to call data.
[0150] The called data can be understood as accessed data, modified data, or deleted data, etc. The first request carries identification information of the first application.
[0151] S770, the electronic device determines, according to the first request, that the first application is an isolated application, and only calls data in the first isolated space.
[0152] In a specific implementable manner, the electronic device can find the marking information of the first application according to the first request, and the electronic device determines that the marking information of the first application marks the first application as an isolated application. At this time, the electronic device only calls data in the first isolated space. That is, when the electronic device determines that the first application is an isolated application, the electronic device only calls data under the first isolated space. Exemplarily, the first isolated space is storage / emulated / 0 / Detained / <pkg1>, then the electronic device only calls storage / emulated / 0 / Detained / <pkg1>data in the first isolated space.
[0153] For example, it is assumed that the first application calls data through the second application, and the normal application can also call data through the second application, which can be understood as a cross-space application, such as a media library application. When the first application requests to call the first data through the media library application, the electronic device determines that the space to which the first data belongs is different from the first isolated space application, and the first isolated space application is an isolated application. At this time, the electronic device changes the access address of the first data to the first application calling data in the first isolated space. In this way, the first application accesses the data in the first application isolated space through the media library application, and cannot access the data of other applications. For example, the first application is a photo editing application, the media library application is a gallery, and the normal application is a camera. When the user operates the interface of the photo editing application, the photo editing application needs to access the pictures in the gallery. At this time, the electronic device displays the interface of the gallery, and only the pictures of the photo editing application are displayed on the interface, and the pictures collected by the camera are not displayed. In this way, the photo editing application can be prevented from accessing or tampering with the pictures collected by the camera, and the security is improved.
[0154] In some examples, the data calling method provided by the embodiment of the present application further includes:
[0155] S780, the electronic device receives a third request of the first application, and the third request is used to add data.
[0156] S790, the electronic device adds data in the first isolated space according to the third request when it is determined that the first application is an isolated application.
[0157] In a specific implementable manner, the electronic device can find the marking information of the first application according to the third request, and the electronic device determines that the marking information of the first application marks the first application as an isolated application. At this time, the electronic device only adds data in the first isolated space. That is, when the electronic device determines that the first application is an isolated application, the electronic device only adds data in the first isolated space. For example, the first isolated space is storage / emulated / 0 / Detained / <pkg1>, then the electronic device only in storage / emulated / 0 / Detained / <pkg1>addition data in the first application.
[0158] In the embodiments of the present application, when the first application is an isolated application, the first application can only call data in the first isolated space when requesting to call data, and cannot call data of other applications. In this way, the application can be prevented from accessing or tampering with data in other spaces on the electronic device, and the security of the data can be improved.
[0159] Case two, the second application requests to call / add data.
[0160] In some examples, the data calling method provided by the embodiments of the present application further includes:
[0161] S761, the electronic device receives a second request of a second application, and the second request is used to call data.
[0162] The second application can be understood as an application other than the first application.
[0163] The data calling can be understood as accessing data, modifying data, or deleting data, etc. The second request carries identification information of the second application.
[0164] S771, the electronic device calls data in a target space according to the second request, when it is determined that the second application is a normal application, wherein the target space does not include an isolated space, and the isolated space includes the first isolated space.
[0165] In a specific implementable manner, the electronic device can find the marking information of the second application according to the second request, and the electronic device determines that the marking information of the second application marks the second application as a normal application. At this time, the electronic device calls data in the target space. That is, when it is determined that the second application is a normal application, the electronic device calls data in the target space. For example, the target space is / storage / emulated / 0 / Android / data, and the electronic device calls data in / storage / emulated / 0 / Android / data.
[0166] In some embodiments, for example, the second application can be a file management type application, such as a cloning application. The file management type application is used to copy application data on the electronic device to other devices. In this way, the second application can copy data of the first application and store the data in the first isolated space on the other device. The second application can also copy data of the normal application and store the data in the common storage space on the other device. That is, after being called by the second application, the data on the electronic device is migrated to the other device, and the isolated application and the normal application on the other device still remain isolated. Of course, other cases can also exist, which are not enumerated one by one in the embodiments of the present application.
[0167] In some examples, the data calling method provided by the embodiments of the present application further includes:
[0168] S781, the electronic device receives a fourth request of the second application, and the fourth request is used to add data.
[0169] S791, according to the fourth request, the electronic device adds data only in the target space when it is determined that the second application is a normal application.
[0170] In a specific implementation, the electronic device can find the marking information of the second application according to the fourth request, and the electronic device determines that the marking information of the second application marks the second application as a normal application. At this time, the electronic device adds data only in the target space. That is, the electronic device adds data only in the target space when it is determined that the second application is a normal application. For example, the target space is / storage / emulated / 0 / Android / data, and the electronic device adds data only in / storage / emulated / 0 / Android / data.
[0171] If there is no special description and logical conflict, the terms and / or descriptions of various embodiments of the present application are consistent and can be mutually referred to. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.
[0172] The embodiments of the present application also provide an electronic device for implementing any of the above methods, for example, an electronic device includes units (or means) for implementing each step performed by the electronic device in the above method S710-S790. For example, please refer to Figure 12 which is a schematic diagram of an electronic device provided by the embodiments of the present application. The electronic device 100 can include a display module 1201, a determination module 1204, a storage module 1202, a receiving module 1205 and a calling module 1203, wherein
[0173] The display module 1201 is used to display a first interface, and the first interface displays a first control for triggering the isolation of the first application. For example, the display module 1201 can perform the steps of S710 and S730 described above. The display module 1201 can be a display screen 270 as shown in Figure 6
[0174] The determination module 1204 is used to determine that the first application is an isolated application in response to receiving a first operation on the first control. For example, the determination module 1204 can perform the steps of S721 described above. The determination module 1204 can be a processor 210 as shown in Figure 6
[0175] The storage module 1202 is configured to store data of the first application in a first isolated space when it is determined that the first application is an isolated application, and the first isolated space is used only for storing data of the first application. For example, the storage module 1202 can perform the steps in S720, S740 and S750 described above. The storage module 1202 can be the memory 250 shown in FIG. 2. Figure 6
[0176] The receiving module 1205 is configured to receive a first request of the first application, and the first request is used to call data. For example, the receiving module 1205 can perform the step in S760 described above. The receiving module 1205 can be the processor 210 shown in FIG. 2. Figure 6
[0177] The calling module 1203 is configured to call only data in the first isolated space according to the first request when it is determined that the first application is an isolated application. For example, the calling module 1203 can perform the step in S770 described above. The calling module 1203 can be the processor 210 shown in FIG. 2. Figure 6
[0178] In a specific implementation, the receiving module 1205 is configured to receive a second request of a second application, and the second request is used to call data. For example, the receiving module 1205 can perform the step in S761 described above.
[0179] The calling module 1203 is configured to call data in a target space according to the second request when it is determined that the second application is a normal application, and the target space does not include an isolated space, and the isolated space includes the first isolated space. For example, the calling module 1203 can perform the step in S771 described above.
[0180] In some implementations, the electronic device 100 further includes an adding module 1206. The receiving module 1205 is configured to receive a third request of the first application, and the third request is used to add data. For example, the receiving module 1205 can perform the step in S780 described above. The adding module is configured to add data only in the first isolated space according to the third request when it is determined that the first application is an isolated application. For example, the adding module 1206 can perform the step in S790 described above.
[0181] In a specific implementation, the first interface is an installation interface of the first application, and the first control is an isolated installation control. Alternatively, the first interface is a setting interface, and the first control is an isolated setting control.
[0182] In a specific implementation, the first interface is a setting interface, and the first control is an isolated setting control. The storage module 1202 is configured to migrate data of the first application stored in a common storage space to the first isolated space when it is determined that the first application is an isolated application.
[0183] In a specific implementation, the determining module 1204 is configured to, in response to the first operation on the first control, configure the first application with first marking information, the first marking information being used to mark the first application as the isolated application.
[0184] In some implementations, the electronic device 100 further includes a migration module 1207, which is configured to, in response to detecting an operation that triggers un-isolation of the first application, migrate data of the first application in the first isolated space to a common storage space.
[0185] In a specific implementation, the storage module 1202 is configured to, in response to the second operation on the first control on the setting interface, configure the first application with second marking information, the second marking information being used to mark the first application as a normal application, and migrate data of the first application in the first isolated space to the common storage space.
[0186] In a specific implementation, the isolated space further includes a second isolated space, the second isolated space being used to store data of a third application in an isolated case.
[0187] In a specific implementation, the display module 1201 is configured to, in response to determining that the first application does not satisfy the trusted condition, display the first interface.
[0188] In a specific implementation, the first application not satisfying the trusted condition includes that a download source of the first application does not belong to a download source white list, or the download source of the first application belongs to a download source black list.
[0189] In a specific implementation, the first application not satisfying the trusted condition includes that a trustworthiness of the first application is less than or equal to a first threshold, where the trustworthiness of the first application is used to represent security of the first application.
[0190] In the embodiments of the present application, when the first application is an isolated application, the electronic device stores data of the first application in a first isolated space of the electronic device. When the second application is a normal application, the electronic device stores data of the second application in a common storage space of the electronic device, which is a common storage space of data on the electronic device. The first application can only call data in the first isolated space when calling data, and cannot call data in the common storage space. The second application can only call data in the common storage space when calling data, and cannot call data in the first isolated space. Thus, the storage space and the running space of the first application and the second application are isolated, so that the first application cannot access data of other applications, thereby reducing the security risks caused by the first application.
[0191] It should be noted that all relevant content of each step in the above method embodiments can be cited from the function description of the corresponding function module, and will not be described here.
[0192] The embodiment of the present application further provides a computer readable storage medium, including instructions, when running on a computer, causing the computer to execute any of the above methods.
[0193] The embodiment of the present application further provides a computer program product including instructions, when running on a computer, causing the computer to execute any of the above methods.
[0194] The embodiment of the present application further provides a chip, including a processor and an interface circuit, the interface circuit and the processor are coupled, the processor is used for running a computer program or instructions to realize the above method, and the interface circuit is used for communicating with other modules outside the chip.
[0195] Any feature or any step of the embodiments of the present application can be freely combined. The combined technical solutions are also within the scope of the present application.
[0196] In the description of the present application, unless otherwise specified, " / " means "or", for example, A / B can mean A or B. "And / or" in this paper is only a description of the association between the associated objects, which means that there can be three relationships, for example, A and / or B, which can mean that A exists alone, A and B exist together, and B exists alone. In addition, "at least one" means one or more, and "multiple" means two or more. "First", "second", etc. do not limit the quantity and execution order, and "first", "second", etc. do not necessarily mean different.
[0197] In the description of the present application, "exemplary" or "for example" means to serve as an example, illustration or description. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as more preferred or more advantageous than other embodiments or design schemes. Rather, the use of "exemplary" or "for example" is intended to present the relevant concept in a specific manner.
[0198] Through the description of the above embodiments, those skilled in the art can clearly understand that, for the convenience and brevity of description, only the above division of each functional module is taken as an example, and in actual application, the above functions can be completed by different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.
[0199] In several embodiments provided in the present application, it should be understood that the disclosed apparatus and method can be implemented by other manners. For example, the apparatus embodiments described above are merely illustrative, for example, the division of the modules or units is merely a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another apparatus, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units or components shown or discussed can be indirect coupling or communication connection through some interfaces, apparatuses or units, and can be electrical, mechanical or other forms.
[0200] The units described as separate components can or can not be physically separate, and the components shown as units can be one physical unit or multiple physical units, that is, can be located in one place or can be distributed to multiple different places. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.
[0201] In addition, the functional units in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0202] The integrated unit, if realized in the form of a software functional unit and sold or used as an independent product, can be stored in a readable storage medium. Based on this understanding, the technical solutions of the embodiments of the present application essentially or the parts that make contributions to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product, which is stored in a storage medium and includes a plurality of instructions for causing an apparatus (which can be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the method described in the embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various storage program codes.
[0203] The above is merely a specific embodiment of the present application, but the protection scope of the present application is not limited thereto, and any change or replacement within the technical scope disclosed in the present application should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A data calling method applied to an electronic device, characterized in that, The method comprises: displaying a first interface, wherein a first control for triggering isolation of a first application is displayed on the first interface; in response to receiving a first operation on the first control, determining that the first application is an isolated application; when it is determined that the first application is an isolated application, storing data of the first application in a first isolated space, wherein the first isolated space is used only for storing data of the first application; receiving a first request of the first application, wherein the first request is used for calling data; according to the first request, when it is determined that the first application is an isolated application, only data in the first isolated space is called. The electronic device further comprises a second isolated space, wherein the second isolated space is used for storing data of a third application in an isolated case; the first isolated space and the second isolated space both belong to isolated spaces and are isolated from each other, and the third application only calls data in the second isolated space when calling data.
2. The method of claim 1, wherein, Further comprising: receiving a second request of a second application, wherein the second request is used for calling data; according to the second request, when it is determined that the second application is a normal application, data in a target space is called, wherein the target space does not include the isolated space.
3. The method according to claim 1 or 2, characterized in that, Further comprising: receiving a third request of the first application, wherein the third request is used for adding data; according to the third request, when it is determined that the first application is an isolated application, data is added only in the first isolated space.
4. The method according to claim 1 or 2, characterized in that, The first interface is an installation interface of the first application, and the first control is an isolated installation control; or, the first interface is a setting interface, and the first control is an isolated setting control.
5. The method of claim 4, wherein, The first interface is the setting interface, and the first control is the isolated setting control. When it is determined that the first application is an isolated application, storing data of the first application in the first isolated space comprises: when it is determined that the first application is an isolated application, migrating data of the first application stored in a common storage space to the first isolated space.
6. The method of claim 1 or 2, wherein, The response to the first operation on the first control and the determination that the first application is an isolated application comprise: in response to the first operation on the first control, configuring first mark information for the first application, wherein the first mark information is used for marking the first application as an isolated application.
7. The method of claim 1, wherein, The method further comprises: when detecting an operation of triggering un-isolation of the first application, migrating data of the first application in the first isolated space to a common storage space.
8. The method of claim 1 or 2, wherein, The display of the first interface comprises: when it is determined that the first application does not satisfy a trusted condition, displaying the first interface.
9. The method of claim 8, wherein, The first application not satisfying the trusted condition comprises that a download source of the first application does not belong to a download source white list, or the download source of the first application belongs to a download source black list.
10. The method of claim 8, wherein, The first application not satisfying the trusted condition comprises that a trustworthiness of the first application is less than or equal to a first threshold value, wherein the trustworthiness of the first application is used for representing security of the first application.
11. An electronic device, comprising: The electronic device comprises a display module, a determination module, a storage module, a receiving module and a calling module, wherein The display module is configured to display a first interface, and the first interface displays a first control for triggering isolation of a first application; The determination module is configured to determine, in response to receiving a first operation on the first control, that the first application is an isolated application; The storage module is configured to store, when it is determined that the first application is an isolated application, data of the first application in a first isolated space, and the first isolated space is used only for storing data of the first application; The receiving module is configured to receive a first request of the first application, and the first request is used to call data; The calling module is configured to, according to the first request, call only data in the first isolated space when it is determined that the first application is an isolated application. In the electronic device, a second isolated space is further included, and the second isolated space is used to store data of a third application in an isolated case; the first isolated space and the second isolated space both belong to isolated spaces and are isolated from each other, and the third application calls only data in the second isolated space when calling data.
12. The electronic device of claim 11, wherein The receiving module is configured to receive a second request of a second application, and the second request is used to call data; The calling module is configured to, according to the second request, call data in a target space when it is determined that the second application is a normal application, and the target space does not include the isolated space.
13. The electronic device of claim 11 or 12, wherein, Further comprising: An adding module; The receiving module is configured to receive a third request of the first application, and the third request is used to add data; The adding module is configured to, according to the third request, add data only in the first isolated space when it is determined that the first application is an isolated application.
14. The electronic device of claim 11 or 12, wherein, The first interface is an installation interface of the first application, and the first control is an isolated installation control; or, the first interface is a setting interface, and the first control is an isolated setting control.
15. The electronic device of claim 14, wherein, The first interface is the setting interface, and the first control is the isolated setting control; and the storage module is configured to: migrate, when it is determined that the first application is an isolated application, data of the first application stored in a common storage space to the first isolated space.
16. The electronic device of claim 11 or 12, wherein, The determination module is configured to: configure, in response to the first operation on the first control, first marking information for the first application, and the first marking information is used to mark the first application as an isolated application.
17. The electronic device of claim 11, wherein, The electronic device further includes a migration module; The migration module is configured to, when detecting an operation of triggering un-isolation of the first application, migrate data of the first application in the first isolated space to a common storage space.
18. The electronic device of claim 11 or 12, wherein, The display module is configured to: display the first interface when it is determined that the first application does not satisfy a trusted condition.
19. The electronic device of claim 18, wherein, The first application does not satisfy the trusted condition includes that a download source of the first application does not belong to a download source white list, or the download source of the first application belongs to a download source black list.
20. The electronic device of claim 18, wherein, The first application does not satisfy the trusted condition includes that a trustworthiness of the first application is less than or equal to a first threshold value, and the trustworthiness of the first application is used to represent security of the first application.
21. An electronic device, comprising: The electronic device includes one or more processors and memory having code stored therein, which when executed by the processor(s) causes the electronic device to perform the method of any of claims 1-10.
22. A computer-readable storage medium, characterized in that, Computer instructions are included which, when executed on an electronic device, cause the electronic device to perform the method of any of claims 1-10.
Citation Information
Patent Citations
Isolation method and isolation device for application program
CN106778291A
Multi-task isolation method and device
CN107103234A