Processing method of application program and electronic device

By using temporary installation and behavioral analysis reports, the problem of users being unable to identify malicious applications has been solved, thus achieving security management and privacy protection for malicious applications.

CN118690359BActive Publication Date: 2025-12-26HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310328384.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-23
Publication Date
2025-12-26
Estimated Expiration
2043-03-23

AI Technical Summary

Technical Problem

Users are unable to effectively identify whether an application to be installed is malicious, leading to security risks on electronic devices, such as the leakage of sensitive information and the difficulty in uninstalling malicious applications.

Method used

By temporarily installing applications to be installed, restricting their permissions, and providing a behavior analysis report after the trial period, users can choose whether to permanently install or uninstall them, thus enabling the identification and isolation of malicious applications.

Benefits of technology

It effectively reduces security risks caused by malicious applications, protects user privacy data, and improves the security of application identification and management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118690359B_ABST
    Figure CN118690359B_ABST
Patent Text Reader

Abstract

The application discloses a processing method of an application and an electronic device. The method comprises: the electronic device displays a first installation interface of an application to be installed, and a control for triggering temporary installation is displayed on the interface. In response to an operation on the control, the electronic device temporarily installs the application to be installed as a temporary application on the electronic device. When the duration of the temporary application installed on the electronic device satisfies a threshold, the electronic device displays a second installation interface, and at least one option is displayed on the interface, the at least one option comprising: extending a trial duration, uninstalling, permanently installing, and viewing an application behavior analysis report. In response to an operation on a target option in the at least one option, the electronic device performs an operation corresponding to the target option. In this way, by temporarily installing the application to be installed as a temporary application on the electronic device, the available permissions of the application are less than the available permissions in the case of permanent installation, thereby avoiding or mitigating the security risks caused by the application.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present application relate to the technical field of electronic devices, and in particular, to a method for processing an application and an electronic device. BACKGROUND

[0002] With the rapid development of electronic devices, people have more and more demands for electronic devices, and therefore, people need to install various applications on electronic devices to meet the demands. As a result, more and more applications emerge in an endless stream. Among these applications, there are more and more applications carrying viruses (or malicious applications). When a user cannot distinguish whether a to-be-installed application is a malicious application, the user may install the malicious application on the electronic device. After the malicious application is installed on the electronic device by the user by mistake, the malicious application may bring some security risks to the electronic device, for example, the malicious application may obtain sensitive information on the electronic device. SUMMARY

[0003] The method for processing an application and the electronic device provided by the embodiments of the present application can make the permissions that can be used by an application in a temporary installation case less than the permissions that can be used by the application in a permanent installation case, so as to avoid or alleviate the security risks brought by the application.

[0004] To achieve the above object, the embodiments of the present application adopt the following technical solutions.

[0005] In a first aspect, the embodiments of the present application provide a method for processing an application. The execution subject of the method can be an electronic device or a component (for example, a chip, a chip system or a processor, etc.) in the electronic device. Hereinafter, the execution subject is taken as an example to be described, and the method comprises: displaying, by the electronic device, a first interface, the first interface being a first installation interface of a first application, and the first interface displaying a first control for triggering a temporary installation, the first application having fewer permissions that can be used in a temporary installation case than in a permanent installation case. In response to a first operation on the first control, the electronic device temporarily installs the first application on the electronic device. When a time length of the temporary installation of the first application satisfies a first threshold value, the electronic device displays a second interface, the second interface being a second installation interface of the first application, and the second interface displaying at least one first option, the first option including at least one of the following: extending a trial time length, uninstalling, permanently installing and viewing an application behavior analysis report. In response to a second operation on a target option in the at least one first option, the electronic device performs a target option corresponding operation.

[0006] The first threshold value can be understood as a trial time length. The first threshold value can be a predefined value, or a trial time length selected by a user through an operation interface, which is not limited in the embodiments of the present application.

[0007] In this way, by temporarily installing the to-be-installed application as a temporary application by the electronic device, the available permissions of the application are less than the available permissions in the case of permanent installation, thereby avoiding or mitigating the security risks brought by the application. In addition, after the temporary application is tried for a period of time, the user can be prompted how to handle the application according to the trial situation, thereby helping the user to distinguish whether the application is a malicious application, and further effectively avoiding the security risks brought by the malicious application.

[0008] In a specific implementable manner, the behavior types of the first application that are monitored in the case of temporary installation are more than the behavior types of the first application that are monitored in the case of permanent installation. The behavior types can be understood as the behavior types of the application on the electronic device, for example, the behavior of the application calling an interface, the behavior of the application accessing information, the behavior of the application obtaining data, and the like.

[0009] In a specific implementable manner, in response to the first operation on the first control, the electronic device temporarily installs the first application on the electronic device, and specifically can be that: in response to the first operation on the first control, the electronic device temporarily installs the first application in a target space on the electronic device; the target space is different from a second space, and the second space is used for permanently installing applications. For the same application, the available permissions in the target space are less than the available permissions in the second space.

[0010] In a specific implementable manner, the target space is a user space of a first account, and the second space is a user space of a second account, and the second account is different from the first account.

[0011] In this way, by installing the to-be-installed application as a temporary application under a specified account, the running space of the temporary application is independent of the running space of the permanently installed application (or normal application), which can provide a better isolation environment for the temporary application, and can achieve relatively relaxed management and control of the temporary application, while protecting the user's private data from being stolen to the maximum extent, and improving the experience of running the temporary application.

[0012] In a specific implementable manner, the target option includes permanent installation; in response to a second operation on the target option in the at least one first option, the electronic device performs a target option corresponding operation, and specifically can be that: in response to the second operation on the permanent installation, the electronic device permanently installs the first application in the second space on the electronic device. The electronic device migrates the data of the first application in the target space to the second space.

[0013] In some implementable manners, the method further includes: when the first application is temporarily installed, the electronic device configures marking information for the first application, and the marking information is used to mark the first application as a temporary application. The electronic device configures specified permissions for the first application based on the marking information.

[0014] In this way, by marking the to-be-installed application as a temporary application, the running space of the temporary application is independent of the running space of a permanently installed application (or normal application), achieving the purpose of isolating the temporary application from the normal application, that is, providing the temporary application with part of the permissions, and maximizing the protection of the user's private data from being stolen. In addition, by marking the to-be-installed application as a temporary application, the temporary application triggers the behavior monitoring mechanism when applying for permissions or making system interface calls, so that the behavior of the temporary application during the temporary running period can be monitored, improving the security.

[0015] In a specific implementable manner, the target option includes permanent installation; in response to the second operation on the target option in the at least one first option, the electronic device performs a target option corresponding operation, which can specifically be: in response to the second operation on the permanent installation, the electronic device clears the marking information of the first application. The electronic device reconfigures the permissions for the first application, so that the first application has the permissions that can be used in the case of permanent installation.

[0016] In some implementable manners, the method further includes: the electronic device displays a third interface, and the second option is displayed on the third interface, the second option being used to represent an option of a trial period. In response to the operation on the second option, the electronic device determines the trial period corresponding to the second option. The electronic device starts a timing operation to time the trial period of the first application on the electronic device to the trial period corresponding to the second option when the first application is temporarily installed successfully.

[0017] In the embodiments of the present application, by setting and timing the trial period of the application, the electronic device can control the application after the trial period expires, for example, to prevent the application from popping up, running in the background, binding a start service, registering a system broadcast, and the like.

[0018] In addition, after the trial period expires, the user can view the behavior analysis report of the application. If it is determined based on the behavior analysis report that the application is a malicious application, the application can be uninstalled, effectively avoiding the problem of the application evading uninstallation. If it is determined based on the behavior analysis report that the application is a non-malicious application, the application can be permanently installed on the electronic device, and the data of the application on the electronic device is retained without loss.

[0019] In some implementable manners, after the first application is temporarily installed on the electronic device, the method further includes: the electronic device determines the interfaces that can be called by the first application as a temporary application. The electronic device determines that the first interface belongs to the callable interfaces when the first application calls the first interface. The electronic device allows the first application to call the first interface.

[0020] In a specific implementable manner, the electronic device determines the interfaces that can be called by the first application as a temporary application, including:

[0021] The electronic device determines, according to the running strategy, an interface that the first application can call as a temporary application, and the running strategy is used to represent the permission of the temporary application during the temporary running.

[0022] In some embodiments, before the first application is temporarily installed on the electronic device, the method further includes: the electronic device obtaining, from a server or another device, application information of the first application, and the application information includes the running strategy.

[0023] In some embodiments, the method further includes: when the first application calls a second interface, the electronic device determines that the second interface does not belong to the callable interface. The electronic device does not allow the first application to call the second interface, or provides the first application with first information as a return result of the call of the second interface, and the first information is preset information or random information. That is, the electronic device does not return data that can be obtained by calling the second interface, but provides the first information as the return result of the call of the second interface.

[0024] In some embodiments, after the first application is temporarily installed on the electronic device, the method further includes: the electronic device obtaining, during the running of the first application, behavior information of the first application, and the behavior information is a request authorization behavior of the first application during the temporary running. The electronic device reports the behavior information of the first application to a server, and the behavior information of the first application is used to improve the running strategy of the first application by the server.

[0025] In the embodiments of the present application, during the trial period of the temporary application, the electronic device monitors the behavior of the temporary application and reports the monitored behavior information to the server, thereby providing analysis data for the server to improve the big data of the application.

[0026] In some embodiments, before the first interface is displayed, the method further includes: the electronic device determining the credibility of the first application, and the credibility of the first application is used to represent the security of the first application. The electronic device displays the first interface when it is determined that the credibility of the first application is less than or equal to a second threshold.

[0027] In a specific embodiment, the available permissions include at least one of the following: data access permission, device calling permission.

[0028] In a second aspect, an electronic device is provided. The electronic device includes a display module, an installation module, and an execution module. The display module is configured to display a first interface, the first interface being a first installation interface of a first application, and the first interface displaying a first control for triggering a temporary installation, and the first application having fewer permissions available in the case of the temporary installation than in the case of a permanent installation. The installation module is configured to temporarily install the first application on the electronic device in response to a first operation on the first control. The display module is configured to display a second interface when a duration of the temporary installation of the first application on the electronic device satisfies a first threshold, the second interface being a second installation interface of the first application, and the second interface displaying at least one first option, the at least one first option including at least one of the following: extending a trial duration, uninstalling, permanently installing, and viewing an application behavior analysis report. The execution module is configured to perform an operation corresponding to a target option of the at least one first option in response to a second operation on the target option.

[0029] In this way, by temporarily installing an application to be installed as a temporary application by the electronic device, the application has fewer permissions available than in the case of a permanent installation, thereby avoiding or mitigating security risks caused by the application. In addition, after the temporary application is used for a period of time, the user can be prompted on how to handle the application according to the trial, thereby helping the user to determine whether the application is a malicious application, and effectively avoiding security risks caused by the application being a malicious application.

[0030] In a specific implementation, the first application is monitored for more types of behaviors in the case of the temporary installation than in the case of the permanent installation.

[0031] In a specific implementation, in response to the first operation on the first control, the installation module is configured to: temporarily install the first application in a target space on the electronic device in response to the first operation on the first control, and the target space being different from a second space, the second space being configured to permanently install applications, and for the same application, the permissions available in the target space being fewer than the permissions available in the second space.

[0032] In a specific implementation, the target space is a user space of a first account, and the second space is a user space of a second account, the second account being different from the first account.

[0033] In this way, by installing the application to be installed as a temporary application under a specified account, the running space of the temporary application is independent of the running space of a permanently installed application (or normal application), a better isolation environment can be provided for the temporary application, and the temporary application can be controlled more leniently, thereby protecting the user's private data from being stolen to the maximum extent while improving the experience of running the temporary application.

[0034] In a specific implementation, the target option includes permanent installation; the installation module is configured to: in response to a second operation on the permanent installation, permanently install the first application in a second space on the electronic device; and migrate data of the first application in the target space to the second space.

[0035] In some implementations, the method further includes: the configuration module is configured to: configure the first application with mark information when the first application is temporarily installed, the mark information being used to mark the first application as a temporary application; and configure the first application with specified permissions based on the mark information.

[0036] In a specific implementation, the target option includes permanent installation; the installation module is configured to: in response to a second operation on the permanent installation, clear the mark information of the first application; and reconfigure the permissions of the first application, so that the first application has permissions that can be used in the case of permanent installation.

[0037] In this way, by marking the to-be-installed application as a temporary application, the running space of the temporary application is independent of the running space of a permanently installed application (or normal application), achieving the purpose of isolating the temporary application from the normal application, that is, providing the temporary application with part of the permissions, and maximizing the protection of the user's private data from being stolen. In addition, by marking the to-be-installed application as a temporary application, the temporary application triggers a behavior monitoring mechanism when applying for permissions or making a system interface call, so that the behavior of the temporary application during the temporary running period can be monitored, improving the security.

[0038] In some implementations, the display module is configured to display a third interface, and the second option is displayed on the third interface, the second option being used to represent an option of a trial period. The electronic device further includes: a determination module configured to: in response to an operation on the second option, determine the trial period corresponding to the second option. The start module is configured to, when the first application is temporarily installed successfully, start a timing operation to time the trial period of the first application on the electronic device to the trial period corresponding to the second option.

[0039] In the embodiments of the present application, by setting and timing the trial period of the application, the electronic device can control the application after the trial period expires, for example, to prevent the application from popping up, running in the background, binding a start service, registering a system broadcast, and the like.

[0040] In addition, after the trial period expires, the user can view the behavior analysis report of the application. If it is determined based on the behavior analysis report that the application is a malicious application, the user can choose to uninstall the application, effectively avoiding the problem of the application evading uninstallation. If it is determined based on the behavior analysis report that the application is a non-malicious application, the user can permanently install the application on the electronic device, and the data of the application on the electronic device is not lost.

[0041] In some embodiments, the determining module is configured to determine the interface that can be invoked by the first application as a temporary application; and determine that the first interface belongs to the invocable interface when the first application invokes the first interface. The invoking module is configured to allow the first application to invoke the first interface.

[0042] In some embodiments, the determining module is configured to determine the interface that can be invoked by the first application as a temporary application according to a running policy, the running policy being used to represent the permission of the temporary application during the temporary running.

[0043] In some embodiments, the electronic device further comprises an obtaining module configured to obtain the application information of the first application from a server or another device, the application information comprising the running policy.

[0044] In some embodiments, the determining module is configured to determine that the second interface does not belong to the invocable interface when the first application invokes the second interface. The invoking module is configured to not allow the first application to invoke the second interface, or provide the first application with first information, the first information being a return result of the invocation of the second interface, the first information being preset information or random information.

[0045] In some embodiments, the obtaining module is configured to obtain the behavior information of the first application when the first application is running, the behavior information being a request authorization behavior of the first application during the temporary running. The electronic device further comprises a reporting module configured to report the behavior information of the first application to a server, the behavior information of the first application being used by the server to improve the running policy of the first application.

[0046] In the embodiments of the present application, the behavior of the temporary application is monitored by the electronic device during the trial period of the temporary application, and the monitored behavior information is reported to the server, so as to provide analysis data for the server to improve the big data of the application.

[0047] In some embodiments, the determining module is configured to determine the trustworthiness of the first application, the trustworthiness of the first application being used to represent the security of the first application. The display module is configured to display the first interface when the trustworthiness of the first application is less than or equal to a second threshold.

[0048] In some embodiments, the available permission comprises at least one of the following: a data access permission, a device invoking permission.

[0049] In a third aspect, the embodiments of the present application provide an electronic device, comprising: one or more processors; and a memory, the memory storing code; when the code is executed by the processor, the electronic device performs the method of the first aspect.

[0050] Fourthly, embodiments of this application provide a computer-readable storage medium including computer instructions that, when executed on an electronic device, cause the electronic device to perform the method described in the first aspect.

[0051] For the specific implementation methods and corresponding technical effects of the embodiments in the second to fourth aspects mentioned above, please refer to the specific implementation methods and technical effects of the first aspect mentioned above. Attached Figure Description

[0052] Figure 1 A schematic diagram of the interface for installing the XX application on a mobile phone;

[0053] Figure 2 A schematic diagram of the interface for installing the YY application on a mobile phone;

[0054] Figure 3 A schematic diagram of the interface for installing the ZZ application on a mobile phone;

[0055] Figure 4 This is a schematic diagram of an interface for installing the XX application on a mobile phone in an embodiment of this application;

[0056] Figure 5 This is a schematic diagram of an interface for installing the XX application on a mobile phone in an embodiment of this application;

[0057] Figure 6 This is a schematic diagram of an interface for installing the XX application on a mobile phone in an embodiment of this application;

[0058] Figure 7 A schematic diagram of a communication system provided in an embodiment of this application;

[0059] Figure 8 This is another schematic diagram of a communication system provided in an embodiment of this application;

[0060] Figure 9 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application;

[0061] Figure 10 A flowchart illustrating an application processing method provided in an embodiment of this application;

[0062] Figure 11 A schematic diagram illustrating a scenario where an application is installed on an electronic device, as provided in an embodiment of this application.

[0063] Figure 12 A flowchart illustrating an application processing method provided in an embodiment of this application;

[0064] Figure 13Another flowchart of a processing method of an application program provided in an embodiment of the present application;

[0065] Figure 14 Another flowchart of a processing method of an application program provided in an embodiment of the present application;

[0066] Figure 15 A schematic diagram of an application management list provided in an embodiment of the present application;

[0067] Figure 16 Another flowchart of a processing method of an application program provided in an embodiment of the present application;

[0068] Figure 17 Another flowchart of a processing method of an application program provided in an embodiment of the present application;

[0069] Figure 18 Another flowchart of a processing method of an application program provided in an embodiment of the present application;

[0070] Figure 19 Another flowchart of a processing method of an application program provided in an embodiment of the present application;

[0071] Figure 20 A structural schematic diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0072] People need to install various application programs on electronic devices to meet their needs. The installation package of these application programs can come from an application market, can be downloaded from a webpage, or can be an installation package transmitted through other storage devices (such as a U disk). Therefore, these application programs can carry viruses (application programs carrying viruses can be referred to as malicious applications). When a user cannot distinguish whether a to-be-installed application program is a malicious application, the user can attempt to install the malicious application on the electronic device.

[0073] For example, the electronic device can be a mobile phone, Figure 1 A schematic diagram of an interface for installing an XX application on a mobile phone. As shown in Figure 1 The interface 101 shown in Figure 1 The interface 101 shown in Figure 1The control 103 on the interface 101 shown. At this time, the mobile phone 100 performs the operation of installing the XX application. If the user does not want to continue installing the application, the user clicks the control 102 on the interface 101 shown. Figure 1 The control 102 on the interface 101 shown. At this time, the mobile phone 100 does not perform the operation of installing the XX application.

[0074] An exemplary interface for installing the YY application on the mobile phone is shown in FIG. 2. As shown in FIG. 2, compared with the interface shown in FIG. 1, the content displayed is different. The prompt information can be "a risk item is found, which does not meet the Huawei Terminal Quality Detection and Security Review Standard. It is suggested to turn on the pure mode and preferentially install the application that has passed the security detection through the Huawei Application Market to better protect your rights and interests." The user can determine whether to continue installing the application according to the prompt information. If the user continues to install the application, the user clicks the control 203 on the interface 201 shown in FIG. 2. At this time, the mobile phone 100 performs the operation of installing the YY application. If the user does not want to continue installing the application, the user clicks the control 202 on the interface 201 shown in FIG. 2. At this time, the mobile phone 100 does not perform the operation of installing the YY application. Figure 2 Figure 2 The content displayed is different. The prompt information can be "a malicious application is found, which contains undesirable information." The user can determine whether to continue installing the application according to the prompt information. If the user continues to install the application, the user clicks the control 303 on the interface 301 shown in FIG. 3. At this time, the mobile phone 100 performs the operation of installing the ZZ application. If the user does not want to continue installing the application, the user clicks the control 302 on the interface 301 shown in FIG. 3. At this time, the mobile phone 100 does not perform the operation of installing the ZZ application. Figure 1 Figure 2 Figure 2

[0075] An exemplary interface for installing the ZZ application on the mobile phone is shown in FIG. 3. As shown in FIG. 3, compared with the interface shown in FIG. 1, the content displayed is different. The prompt information can be "a malicious application is found, which contains undesirable information." The user can determine whether to continue installing the application according to the prompt information. If the user continues to install the application, the user clicks the control 303 on the interface 301 shown in FIG. 3. At this time, the mobile phone 100 performs the operation of installing the ZZ application. If the user does not want to continue installing the application, the user clicks the control 302 on the interface 301 shown in FIG. 3. At this time, the mobile phone 100 does not perform the operation of installing the ZZ application. Figure 3 Figure 3 Figure 1 The content displayed is different. The prompt information can be "a malicious application is found, which contains undesirable information." The user can determine whether to continue installing the application according to the prompt information. If the user continues to install the application, the user clicks the control 303 on the interface 301 shown in FIG. 3. At this time, the mobile phone 100 performs the operation of installing the ZZ application. If the user does not want to continue installing the application, the user clicks the control 302 on the interface 301 shown in FIG. 3. At this time, the mobile phone 100 does not perform the operation of installing the ZZ application. Figure 3 Figure 3

[0076] It can be seen that the user cannot distinguish that the ZZ application, the XX application, and the YY application carry viruses, or when the ZZ application, the XX application, and the YY application carry viruses, the user still insists on installing the ZZ application, the XX application, and the YY application. Once these applications are installed on the electronic device, the electronic device will have some security risks, for example, the application can evade uninstallation by using the operating system characteristics of the electronic device, resulting in the occurrence of a situation that the malicious application cannot be uninstalled. In addition, the application will attack the operating system of the electronic device, resulting in leakage of sensitive information of the operating system of the electronic device.

[0077] ​​​​​​​​To solve the above problems, an embodiment of the present application provides a processing method of an application, the method comprising: displaying a first interface (or a first installation interface) on an electronic device, the first interface displaying a first control for triggering temporary installation. In response to a first operation on the first control, the electronic device temporarily installs a to-be-installed application as a temporary application on the electronic device. When a time length of the temporary application installed on the electronic device satisfies a threshold, the electronic device displays a second interface (or a second installation interface), the second interface displaying at least one option, the at least one option comprising: extending a trial time length, uninstalling, permanently installing, and viewing an application behavior analysis report. In response to an operation on a target option in the at least one option, the electronic device performs an operation corresponding to the target option. In this way, by temporarily installing the to-be-installed application as a temporary application on the electronic device, the available permissions of the application are less than the available permissions in the case of permanent installation, thereby avoiding or mitigating the security risks caused by the application. In addition, after the temporary application is used for a period of time, the user can be prompted about how to handle the application according to the trial situation, thereby helping the user to distinguish whether the application is a malicious application, and effectively avoiding the security risks caused by the malicious application.

[0078] The available permissions can include data access permissions. The data access permissions can include permissions for accessing contact information and permissions for accessing user information. The available permissions can also include device calling permissions, which can include camera calling permissions and microphone calling permissions.

[0079] The electronic device temporarily installs the to-be-installed application as a temporary application on the electronic device, specifically, the electronic device can mark the to-be-installed application as a temporary application, and configure specified permissions for the application, the specified permissions being less than the available permissions of the application in the case of permanent installation. The temporary application is installed on the electronic device. Alternatively, the electronic device installs the to-be-installed application as a temporary application under a specified account, the specified account being different from other accounts, and the application is permanently installed under the other accounts and temporarily installed under the specified account. That is, for the same application, the available permissions in the user space of the specified account are less than the available permissions in the user space of the other accounts. The space can be understood as a storage space and / or a running space.

[0080] The electronic device can be a mobile phone, a tablet computer, a laptop computer, a notebook computer, an ultra-mobile personal computer (UMPC), a handheld computer, a netbook, a personal digital assistant (PDA), a wearable electronic device, or the like. The specific form of the electronic device is not specially limited in the embodiment of the present application.

[0081] For example, let's take "the electronic device is a mobile phone" and "the electronic device marks the application to be installed as a temporary application, and the temporary application is installed on the electronic device" as examples for detailed explanation:

[0082] Figure 4 This is a schematic diagram of an interface for installing the XX application on a mobile phone 100 in an embodiment of this application. Figure 4 As shown, control 403 is displayed on mobile phone 100 to trigger temporary installation. When the user clicks control 403, mobile phone 100 will install the application to be installed (i.e., Figure 4 The application shown (e.g., XX application) is marked as a temporary application. Furthermore, the mobile phone 100 stores the tagging information of this temporary application, which is associated with the installation time of the temporary application. The mobile phone 100 displays as shown... Figure 5 The interface 501 shown displays a trial duration option 502. When the user clicks the 24-hour option in the trial duration option 502, the mobile phone 100 starts a timer based on the marker information and the trial duration. When the mobile phone 100 reaches the trial duration, the mobile phone 100 displays the following... Figure 6 The interface 601 shown displays a control 602 with at least one option, which may include at least one of the following: Extend Trial for 7 Days, Uninstall, Permanently Install, View Application Behavior Analysis Report, etc. When the user clicks any of the above options, the mobile phone 100 performs the operation corresponding to that option. For example, when the user clicks the "Extend Trial for 7 Days" option, the mobile phone 100 performs the operation of extending the trial period. When the user clicks the "Uninstall" option, the mobile phone 100 performs the uninstallation operation. When the user clicks the "Permanently Install" option, the mobile phone 100 performs the operation of modifying the marking information and converting the temporary application into a normal application for permanent installation. When the user clicks the "View Application Behavior Analysis Report" option, the mobile phone 100 obtains the behavior analysis report of the temporary application. The open source of this behavior analysis report is not specifically limited; for example, the behavior analysis report may come from a server or from the local machine. The behavior analysis report may include the following content: Application behavior: "The application called an uncallable interface, the application accessed user privacy information, etc." Analysis conclusion: "This application is a malicious application." Recommendation: "This application has security risks; it is recommended that the user choose to temporarily install this application."

[0083] As can be seen, the display interface of mobile phone 100 shows a control 403 for triggering temporary installation, a control 502 for the trial duration option, and a control 602 with at least one option. Upon receiving an operation on control 403, mobile phone 100 temporarily installs the application to be installed as a temporary application, ensuring that the application has fewer permissions available during temporary installation than during permanent installation, thereby avoiding or mitigating security risks. Upon receiving an operation on control 502, mobile phone 100 starts a timer to record the duration of the application's temporary installation on the phone. When the application's duration on the phone reaches the trial duration, control 602 with at least one option is displayed. Upon receiving an operation on control 602, mobile phone 100 can perform corresponding actions to handle the application based on the user's selection. In this way, based on the application's trial status, it can help the user determine whether the application is malicious, prompt the user on how to handle the application, and allow the user to select the appropriate option for appropriate action.

[0084] The application processing method provided in this application embodiment can be applied to the following communication systems. Specifically, in one embodiment, the application processing method provided in this application embodiment can be applied to... Figure 7 The communication system 70 shown. (e.g.) Figure 7 As shown, the system 70 may include an electronic device 100 and a server 110. The electronic device 100 can monitor the behavior of a temporary application during its trial period and report the behavior information of the temporary application to the server 110. The server 110 can analyze the behavior information of the temporary application and the large amount of collected behavior information of the application to obtain a behavior analysis report of the application.

[0085] Figure 8 This is another structural diagram of the aforementioned communication system 70, as shown below. Figure 8 As shown, the electronic device 100 in the communication system 70 may include: an installer 801, an application management module 802, an application permission management module 803, an application behavior monitoring module 804, and a policy management module 805. The installer 801 is electrically connected to the application management module 802. The application permission management module 803 may be electrically connected to the application management module 802, the application behavior monitoring module 804, and the policy management module 805, respectively. The application management module 802, the application behavior monitoring module 804, and the policy management module 805 may all be electrically connected to the server 110.

[0086] For example, the following describes one working principle of the communication system 70:

[0087] In a specific implementation, the working principle of the communication system 70 is as follows: ①The electronic device 100 sends a request for obtaining application information to the server 110, and the request can carry the identifier of the electronic device 100. The application information can include the basic information of the application and the running strategy of the application, and the basic information of the application can include the name of the application and the attribute of the application. The running strategy of the application can include the permission of the application and the information required for the running of the application (such as the running time of the application and the identifier of the interface that can be called by the application). ②The server 110 sends the application information to the electronic device 100 according to the request, and the basic information of the application in the application information is stored in the application management module 802, and the running strategy of the application in the application information is stored in the strategy management module 805. ③When the to-be-installed application is downloaded on the electronic device 100, and the installer 801 of the electronic device 100 is called by the application installation initiator (such as a file manager or a third-party website) to initiate temporary installation, the installer 801 marks the to-be-installed application as a temporary application, marks the application with the marking information, and stores the marking information of the application in the application management list of the application management module 802. ④After the application is temporarily installed on the electronic device 100, the application runs, and the application calls the interface 1 of the electronic device 100. The application permission management module 803 of the electronic device 100 sends a request for querying the information of the application to the application management module 802, and determines whether the application is a temporary application. ⑤The application management module 802 queries the marking information corresponding to the application according to the request, and determines that the application is a temporary application according to the marking information. At this time, the application management module 802 sends the query result that the application is a temporary application to the application permission management module 803. ⑥The application permission management module 803 sends a request for obtaining the running strategy of the temporary application to the strategy management module 805. ⑦The strategy management module 805 determines the running strategy of the temporary application according to the request, and obtains the interface that can be called by the temporary application according to the running strategy. The strategy management module 805 sends the information of the interface that can be called by the temporary application to the application permission management module 803. The application permission management module 803 compares the interface 1 with the interface that can be called by the temporary application. When the interface 1 belongs to the interface that can be called by the temporary application, the application permission management module 803 allows the temporary application to call the interface 1; when the interface 1 does not belong to the interface that can be called by the temporary application, the application permission management module 803 refuses the temporary application to call the interface 1, or provides the first information to the application, the first information is the return result of the calling of the interface 1, and the first information is preset information or random information. In addition, ⑧During the running of the application, the application behavior monitoring module 804 monitors the behavior of the application. Specifically, the application management module 802 reports the information corresponding to the calling behavior of the application to the application behavior monitoring module 804.The application behavior monitoring module 804 reports the behavior information of the application to the server 110, so that the server 110 analyzes the behavior of the application.

[0088] Of course, the working principle of the communication system 70 is not limited to this, and only one implementation manner is described in detail here.

[0089] Figure 9 A structural block diagram of the electronic device.

[0090] As Figure 9 shown, the electronic device 100 can include a processor 210, an external memory interface 220, a universal serial bus (USB) interface 230, a charge management module 240, a power management module 241, a battery 242, a memory 250, an antenna 1, a wireless communication module 260, a display screen 270, and a sensor module 280, etc. The sensor module 280 can include a pressure sensor 280A, an acceleration sensor 280B, a touch sensor 280C, etc.

[0091] It can be understood that the structure shown in the embodiments of the present application does not constitute a specific limitation on the electronic device. In other embodiments of the present application, the electronic device can include more or fewer components than shown, or combine certain components, or split certain components, or different component arrangements. The components shown can be implemented in hardware, software, or a combination of software and hardware.

[0092] The processor 210 can include one or more processing units, for example: the processor 210 can include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Different processing units can be independent devices, or can be integrated into one or more processors.

[0093] The controller can generate operation control signals according to instruction operation codes and timing signals, and complete the control of fetching and executing instructions.

[0094] The processor 210 can also include memory that stores instructions and data. In some embodiments, the memory within the processor 210 is a cache memory. This memory can hold instructions or data that the processor 210 has recently accessed or is likely to access again. If the processor 210 needs to access this data again, it can be retrieved directly from the memory, rather than from a slower source. This avoids repetition of access and reduces the latency of the processor 210, thus improving the efficiency of the system.

[0095] The charging management module 240 is configured to receive charging input from a charger. The charger can be a wireless charger or a wired charger. In some embodiments of wired charging, the charging management module 240 can receive charging input from a wired charger through the USB interface 230. In some embodiments of wireless charging, the charging management module 240 can receive wireless charging input through a wireless charging coil of the electronic device. The charging management module 240 can charge the battery 242 and supply power to the electronic device through the power management module 241.

[0096] The power management module 241 is configured to connect the battery 242, the charging management module 240, and the processor 210. The power management module 241 receives input from the battery 242 and / or the charging management module 240 to supply power to the processor 210, the internal memory 221, the display 270, the camera 293, and the wireless communication module 260. The power management module 241 can also be configured to monitor parameters such as battery capacity, battery cycle count, battery health status (leakage, impedance), and the like. In some other embodiments, the power management module 241 can also be disposed in the processor 210. In some other embodiments, the power management module 241 and the charging management module 240 can also be disposed in the same device.

[0097] The wireless communication function of the electronic device can be realized through the antenna 1, the wireless communication module 260, the modem processor, and the baseband processor.

[0098] The antenna 1 is configured to transmit and receive electromagnetic wave signals. Each antenna in the electronic device can be used to cover a single or multiple communication frequency bands. Different antennas can also be multiplexed to improve the utilization rate of the antennas. For example, the antenna 1 can be multiplexed as a diversity antenna for a wireless local area network. In some other embodiments, the antenna can be used in combination with a tuning switch.

[0099] The wireless communication module 260 can provide a solution for wireless communication applied to the electronic device, including wireless local area networks (WLAN) (e.g., a wireless fidelity (Wi-Fi) network), Bluetooth (BT), a global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared (IR) technology, and the like. The wireless communication module 260 can be one or more devices that integrate at least one communication processing module. The wireless communication module 260 receives an electromagnetic wave via the antenna 1, frequency-modulates and filters the electromagnetic wave signal, and transmits the processed signal to the processor 210. The wireless communication module 260 can also receive a signal to be transmitted from the processor 210, frequency-modulate it, amplify it, and radiate it as an electromagnetic wave via the antenna 1. In some embodiments, the wireless communication module 260 receives application information transmitted from a server.

[0100] The electronic device implements a display function through a GPU, a display screen 270, an application processor, and the like. The GPU is a microprocessor for image processing, which is connected to the display screen 270 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. The processor 210 can include one or more GPUs that execute program instructions to generate or change display information.

[0101] The display screen 270 is used to display images, videos, and the like. The display screen 270 includes a display panel. The display panel can employ a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flex light-emitting diode (FLED), a Miniled, a MicroLed, a Micro-oLed, a quantum dot light emitting diode (QLED), or the like. In some embodiments, the electronic device can include one or N display screens 270, N being a positive integer greater than 1.

[0102] In some embodiments, the display screen 270 displays, for example, Figure 4The interface 401 shown, on which the control 403 for triggering the temporary installation is displayed. In some embodiments, the display screen 270 displays, as shown in Figure 5 The interface 501 shown, on which the control 502 of the trial duration option is displayed. In some embodiments, the display screen 270 displays, as shown in Figure 6 The interface 601 shown, on which the control 602 with at least one option is displayed.

[0103] The external memory interface 220 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the electronic device. The external memory card communicates with the processor 210 through the external memory interface 220 to realize the data storage function. For example, files such as music and videos are saved in the external memory card. In some embodiments, an external storage device is connected through the memory interface 220 to copy the installation package of the application to be installed from the external storage device.

[0104] The memory 250 can be used to store computer executable program codes, including instructions. The memory 250 can include a program storage area and a data storage area. The program storage area can store an operating system, at least one application required by a function (such as a sound playing function, an image playing function, etc.), and the like. The data storage area can store data created during the use of the electronic device (such as audio data, a phone book, etc.), and the like. In addition, the memory 250 can include a high-speed random access memory, and can also include a non-volatile memory, such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), and the like. The processor 210 executes various function applications and data processing of the electronic device by running the instructions stored in the memory 250 and / or the instructions stored in the memory disposed in the processor.

[0105] The pressure sensor 280A is configured to sense a pressure signal and convert the pressure signal into an electrical signal. In some embodiments, the pressure sensor 280A can be disposed on the display screen 270. The pressure sensor 280A can be of various types, such as a resistive pressure sensor, an inductive pressure sensor, a capacitive pressure sensor, etc. The capacitive pressure sensor can include at least two parallel plates of conductive material. When a force is applied to the pressure sensor 280A, the capacitance between the electrodes changes. The electronic device determines the intensity of the pressure based on the change in capacitance. When a touch operation is applied to the display screen 270, the electronic device detects the intensity of the touch operation based on the pressure sensor 280A. The electronic device can also calculate the position of the touch based on the detection signal of the pressure sensor 280A. In some embodiments, touch operations applied to the same touch position but with different touch operation intensities can correspond to different operation instructions. For example, when a touch operation with a touch operation intensity less than a first pressure threshold is applied to a short message application icon, an instruction to view short messages is executed. When a touch operation with a touch operation intensity greater than or equal to the first pressure threshold is applied to the short message application icon, an instruction to create a new short message is executed.

[0106] The acceleration sensor 280B can detect the magnitude of acceleration of the electronic device in various directions (typically, three axes). When the electronic device is stationary, the acceleration sensor 280B can detect the magnitude and direction of gravity. The acceleration sensor 280B can also be used to identify the posture of the electronic device and applied to switching between landscape and portrait modes, a pedometer, etc.

[0107] The touch sensor 280C, also referred to as a "touch device". The touch sensor 280C can be disposed on the display screen 270, and the touch sensor 280C and the display screen 270 together form a touch screen, also referred to as a "touch screen". The touch sensor 280C is configured to detect a touch operation applied thereto or in the vicinity thereof. The touch sensor 280C can transmit the detected touch operation to the application processor to determine the type of touch event. Visual output related to the touch operation can be provided through the display screen 270. In other embodiments, the touch sensor 280C can also be disposed on the surface of the electronic device, which is different from the position of the display screen 270.

[0108] In some embodiments, the touch sensor 280C detects a touch operation of a user on the interface 401 shown in FIG. 4A to trigger the control 403 for temporary installation. In some embodiments, the touch sensor 280C detects a touch operation of a user on the interface 501 shown in FIG. 5A to trigger the control 502 for the trial duration option. In some embodiments, the touch sensor 280C detects a touch operation of a user on the interface 601 shown in FIG. 6A to trigger the control 602 having at least one option. Figure 4 Figure 5 Figure 6

[0109] ​​​Of course, the electronic device can also include other functional units, and the embodiments of the present application do not limit this.

[0110] In addition, the actions and terms involved between the embodiments of the present application can be mutually referenced and not limited. The message names or parameter names in the messages in the embodiments of the present application are only examples, and other names can also be used in specific implementations, and are not limited.

[0111] The processing method of the application provided by the embodiments of the present application can be described in the following stages, which can be specifically:

[0112] In the first stage, the electronic device obtains application information.

[0113] The application information can be the basic information and the running strategy of the application as described above.

[0114] The specific implementation of the electronic device obtaining the application information can be that the electronic device obtains the application information from the server. Specifically, the electronic device can request the server to send the application information, or the electronic device can receive the application information pushed by the server. Of course, the electronic device can also obtain the application information from other devices. The electronic device obtains the application information from other devices, and the embodiments of the present application do not make specific limitations.

[0115] Take the electronic device obtaining the application information from the server as an example for description:

[0116] Figure 10 A flowchart of the processing method of the application provided by the embodiments of the present application. As shown in S911-S913, Figure 10 Specifically:

[0117] S911, the server statistics the basic information of the application.

[0118] The basic information of the application can include the basic information such as the application name and the attribute information of the application. The basic information of the application can also include the interface that can be called by the application, the behavior information of the application (such as the information accessed during the application running, the interface called during the application running, etc.).

[0119] Specifically, the server will collect the basic information of the application reported by each electronic device, and statistics the basic information of the application.

[0120] S912, the server determines the running strategy of the application according to the statistics of the basic information of the application.

[0121] The running strategy can comprise a permission configuration of the application during the temporary running, the running strategy can also comprise an identification of an interface that can be invoked by the application during the temporary running, of course, the running strategy can also comprise a duration of the temporary running, the running strategy can also comprise an application behavior that is prohibited, and the like, and the embodiments of the application are not limited in particular.

[0122] Specifically, the server determines the running strategy of the application according to the basic information of the application, which can be explained by using the following examples: for example, it is assumed that the basic information of the application comprises an interface A, an interface B and an interface C invoked by the application during running, and the interface A, the interface B and the interface C are not sensitive interfaces, and then the running strategy can comprise the interface A, the interface B and the interface C that can be invoked by the application during running. It is assumed that the basic information of the application comprises a number of times of accessing user sensitive information by the application during running, which is greater than a threshold value, and then the running strategy can comprise that the application does not have the permission to access the user sensitive information during the temporary running. Of course, there can be other examples, which are not listed one by one here.

[0123] S913, the electronic device obtains the application information from the server, the application information comprising the basic information and the running strategy of the application.

[0124] S913 can comprise S9131-S1932, and the specific implementation can be as follows:

[0125] In a first mode, the electronic device actively obtains the application information from the server.

[0126] S9131, the electronic device sends a request for obtaining the application information to the server, and the request carries identification information of the electronic device. Correspondingly, the server receives the request.

[0127] The electronic device can send the request for obtaining the application information to the server when receiving a trigger operation, the electronic device can send the request for obtaining the application information to the server at a first preset time interval, or the electronic device can send the request for obtaining the application information to the server in real time. Of course, the embodiments of the application are not limited to the above.

[0128] Specifically, the specific implementation of S9131 can refer to step ① shown in Figure 8 , and details are not repeated here.

[0129] S9132, the server sends the application information to the electronic device according to the request. Correspondingly, the electronic device receives the application information sent by the server.

[0130] Specifically, the application information includes basic information of the application and a running strategy, and the server sends the running strategy to a policy management module of the electronic device and sends the basic information of the application to an application management module of the electronic device.

[0131] Specifically, the implementation of S9132 can refer to step ② shown in Figure 8 , which will not be repeated here.

[0132] Mode two, the electronic device passively acquires the application information from the server.

[0133] S913 can include S9133, and the implementation can be as follows:

[0134] S9133, the server pushes the application information to the electronic device.

[0135] The server can push the application information to the electronic device in real time, or the server can push the application information to the electronic device at a second preset time interval.

[0136] Second stage, the electronic device installs the application program.

[0137] Figure 11 A scene diagram of installing an application by an electronic device provided by an embodiment of the present application. As shown in Figure 11 , before the electronic device 100 installs an application program (referred to as an application), the user can download an installation package of the application from an application market, or the user can copy the installation package of the application from other storage devices, or the user can download the installation package of the application from a website. After downloading the installation package of the application, the user triggers an installation operation, at which time the electronic device performs the following operations:

[0138] Figure 12 , Figure 13 and Figure 16 A flow diagram of a processing method of an application program provided by an embodiment of the present application. As shown in Figure 12 , Figure 13 and Figure 16 ,

[0139] S920, the electronic device displays interface one, and a control one for triggering temporary installation is displayed on the interface one.

[0140] The control one can be a "temporary installation" control. The control is a control for triggering a temporary installation operation by the user.

[0141] The display position of the control one on the interface one is not specifically limited, for example, the control one can be located in a side region of the interface one, and the control one and other controls are arranged side by side in the region.

[0142] Exemplarily, the interface one displayed by the electronic device can be the interface 401 as shown in Figure 4 The control one can be the temporary installation control 403 on the interface 401 as shown in Figure 4 The interface 401 as shown in

[0143] The electronic device can directly display the interface one, or display the interface one under certain conditions. For example, the electronic device displays the interface one when it determines that the trustworthiness of the application to be installed meets a threshold. Specifically as follows:

[0144] In a specific implementation, when the trustworthiness of the application to be installed is greater than a first threshold, the electronic device determines that the application to be installed is trustworthy, and displays the interface two, which does not display the control one for triggering temporary installation. The first threshold can be a set value, which is not specifically limited herein. When the trustworthiness of the application to be installed is less than or equal to the first threshold, the electronic device determines that the application to be installed is untrustworthy, and displays the interface one.

[0145] Exemplarily, when the application to be installed is trustworthy, the electronic device displays the interface 101 (i.e., the interface one) as shown in Figure 1 The interface 101 displays the control 102 for canceling the installation operation and the control 103 for triggering continued installation. When the application to be installed is untrustworthy, the electronic device displays the interface 401 (i.e., the interface two) as shown in Figure 4 The interface 401 displays the control 402 for canceling the installation operation, the control 403 for triggering continued installation, and the control 404 (i.e., the control one) for triggering temporary installation.

[0146] In a specific implementation, the electronic device can generate a prompt information according to the trustworthiness of the application to be installed, and the prompt information is displayed on the interface of the electronic device. For example, when the electronic device determines that the application to be installed is untrustworthy, the electronic device generates the prompt information one, which can be “malicious application found” and “application temporary installation is recommended”, and the prompt information one can be displayed on the interface one. When the electronic device determines that the application to be installed is trustworthy, the electronic device generates the prompt information two, which can be “safety reminder” and “application continued installation is recommended”, and the prompt information two can be displayed on the interface two.

[0147] In a specific implementation, the electronic device can display the prompt information on the interface one or the interface two. For example, the electronic device displays the prompt information on the interface one when the application to be installed is untrustworthy, and displays the prompt information on the interface two when the application to be installed is trustworthy. Figure 13As shown, the credibility of the to-be-installed application can be determined according to the source of the to-be-installed application. For example, the electronic device determines the source of the to-be-installed application. When the electronic device determines that the to-be-installed application is from an application market, the electronic device determines that the credibility of the to-be-installed application is greater than a first threshold, and the to-be-installed application is credible. When the electronic device determines that the to-be-installed application is from a website or other storage device, the electronic device determines that the credibility of the to-be-installed application is less than or equal to the first threshold, and the to-be-installed application is not credible.

[0148] In a specific implementation, the source of the to-be-installed application can be determined according to the caller of the installer of the electronic device. For example, when the caller of the installer of the electronic device is an installation module of an application market, the electronic device determines that the to-be-installed application is from the application market. When the caller of the installer of the electronic device is a file manager, the electronic device determines that the to-be-installed application is from other storage devices. When the caller of the installer of the electronic device is a third-party application, the electronic device determines that the to-be-installed application is from a web page or other third-party provider.

[0149] S921, in response to the operation one on the control one, the electronic device performs an operation of temporarily installing the application.

[0150] The operation one can include a click operation or a press operation, etc. The click operation can include a single click operation, a multiple click operation, which is not limited in the embodiments of the present application.

[0151] In this way, by temporarily installing the to-be-installed application as a temporary application by the electronic device, the available permissions of the application are less than the available permissions in the case of permanent installation, thereby avoiding or mitigating the security risks caused by the application. In addition, after the temporary application is used for a period of time, the user can be prompted how to handle the application according to the trial situation, thereby helping the user to distinguish whether the application is a malicious application.

[0152] In the embodiments of the present application, the electronic device performs an operation of temporarily installing the application, which can be implemented in the following ways:

[0153] In a first way, the electronic device temporarily installs the application in a public space.

[0154] Specifically, Figure 12 and Figure 13 As shown, S921 can include S9211-S9215, which can be implemented as follows:

[0155] S9211, in response to the operation one on the control one, the electronic device configures the to-be-installed application with mark information, and at this time, the to-be-installed application becomes a temporary application.

[0156] Specifically, when the user operates the control, the application management module of the electronic device marks the to-be-installed application as a temporary application in the application management list in a manner of adding marking information. In addition, the electronic device configures a specified permission for the application after marking the application as a temporary application. Based on this, the temporary application can have a temporary application running space as shown in Figure 14 when running. The marking information can be presented in the application management list. The marking information can be a marking symbol as shown in Figure 15 or a field such as a bool type field. For example, in the application management list, the default field of a normal application is false, and the default field of a temporary application is true. Of course, this is not limited thereto. The marking information can also be presented as a positive integer in the application management list, and the value of the positive integer is associated with the installation time of the application, or in other words, the value of the positive integer can be used to provide timing information for uninstalling the application.

[0157] Specifically, the specific implementation of S9211 can refer to step ③ as shown in Figure 8 , and details are not described herein again.

[0158] For example, the user clicks the temporary installation control 403 on the interface 401 as shown in Figure 4 , at this time, the electronic device configures marking information for the to-be-installed application in response to the operation of the user.

[0159] In this way, by marking the to-be-installed application as a temporary application, the running space of the temporary application is independent of the running space of the permanently installed application (or normal application), so as to achieve the purpose of isolating the temporary application from the normal application, that is, to provide part of the permission for the temporary application, and to maximize the protection of the user's private data from being stolen. In addition, by marking the to-be-installed application as a temporary application, the temporary application triggers a behavior monitoring mechanism when applying for a permission or performing a system interface call, so as to monitor the behavior of the temporary application during the temporary running period, and to improve the security.

[0160] S9212, the electronic device displays interface three, and the interface three displays a trial duration option.

[0161] Specifically, the timing of the electronic device displaying the interface three can include the following examples:

[0162] In some examples, the electronic device displays the interface three before the temporary installation is successful. In other examples, the electronic device displays the interface three during the temporary installation. In yet other examples, the electronic device displays the interface three when the temporary installation is successful. The embodiments of the present application are not limited specifically.

[0163] Specifically, when the user operates the control one, the electronic device displays interface three according to the mark information, and displays the trial duration option of the temporarily installed application on the interface three. For example, after the user clicks the temporarily installed control 403 on the interface 401 shown in Figure 4 , the electronic device 100 displays the interface 501 shown in Figure 5 , and displays the trial duration option 502 on the interface 501, which can include 10 minutes, 24 hours, 7 days, and so on.

[0164] S9213, in response to the operation of the trial duration option, the electronic device performs a timing operation based on the trial duration corresponding to the option.

[0165] In some examples, the electronic device starts the timing operation when the temporary installation of the application is successful. When the trial duration option is operated, the electronic device performs timing in combination with the trial duration corresponding to the option.

[0166] In some examples, in combination with Figure 13 , when the user operates the trial duration option, the timer of the electronic device performs timing according to the application installation time associated with the trial duration option and the mark information. For example, it is assumed that the application installation time associated with the mark information is January 1, 2023 00:00:00. When the user clicks the 24-hour option in the trial duration option 502 shown in Figure 5 , the electronic device starts timing according to the application installation time and the trial duration. When the electronic device counts to January 2, 2023 00:00:00, the electronic device ends timing.

[0167] S9214, when the electronic device ends timing, the electronic device displays interface four, and the interface four displays at least one option, which can include at least one of extending the trial duration, uninstalling, permanently installing, and viewing the application behavior analysis report.

[0168] In a specific implementation, when the electronic device is in a bright screen state and when the electronic device ends timing (i.e., the trial duration arrives), the electronic device displays interface four.

[0169] Specifically, in combination with Figure 13 , when the electronic device counts to the selected trial duration, the timer of the electronic device stops timing, and at this time, the electronic device displays interface four, and the interface four displays at least one of extending the trial duration, uninstalling, permanently installing, and viewing the application behavior analysis report. For example, it is assumed that the trial duration is 24 hours, and when the electronic device counts to 24 hours, the electronic device 100 displays the interface 601 shown in Figure 6The interface 601 shown, on the interface 601, the option 602 of "XX application has been tried for 24 hours, whether to uninstall or install formally?" can include the following: extend the trial for 7 days, uninstall, permanently install, view the application behavior analysis report, etc.

[0170] In another specific implementation, when the electronic device timing ends and the screen of the electronic device is in the screen-off state, in this case, when the user operates the electronic device to make the electronic device screen-on, the electronic device displays interface four.

[0171] Among them, the application behavior analysis report can be obtained by the server according to the application data reported by the electronic device and the big data collected by the server, and suggestions are provided to the user according to whether the application is at risk.

[0172] S9215, in response to the operation of the target option in the at least one option, the electronic device performs the operation corresponding to the target option.

[0173] In the above example, when the user clicks Figure 6 The "extend the trial for 7 days" item in the option 602 shown, the electronic device performs the extension operation, that is, the timer of the electronic device continues to count for 7 days. When the user clicks Figure 6 The "uninstall" item in the option 602 shown, the electronic device performs the uninstall operation. When the user clicks Figure 6 The "permanent installation" item in the option 602 shown, the electronic device modifies the mark information of the temporary application, so that the temporary application is converted into a normal application, and reconfigures the permissions for the application, so that the application has the permissions that can be used in the case of permanent installation. When the user clicks Figure 6 The "view application behavior analysis report" item in the option 602 shown, the electronic device sends a report request to the server, the server finds the behavior analysis report of the application according to the request, and sends the behavior analysis report to the electronic device.

[0174] In the embodiment of the application, by setting the trial duration of the application and timing, the electronic device can control the application after the trial duration expires, for example, prevent the application from popping up, running in the background, binding the start service, registering the system broadcast, etc.

[0175] In addition, after the trial duration expires, the user can view the behavior analysis report of the application, if it is determined based on the behavior analysis report that the application is a malicious application, the application can be uninstalled, effectively avoiding the problem of the application avoiding uninstallation ability; if it is determined based on the behavior analysis report that the application is a non-malicious application, the application can be permanently installed on the electronic device, and the data of the application on the electronic device is not lost.

[0176] The second mode is that the electronic device temporarily installs the application in the independent space.

[0177] Specifically, Figure 13 and Figure 16 As shown in FIG. 9, S921 can include S9216, S9212-S9215, and specifically can be implemented as:

[0178] S9216, in response to operation one on control one, the electronic device installs the to-be-installed application as a temporary application under account one.

[0179] The electronic device can have multiple accounts, and each account corresponds to a storage and / or running space. That is, the storage spaces of each account are independent of each other, and the running spaces of each application in each storage space are also independent of each other.

[0180] Specifically, when the control one is operated, the electronic device installs the to-be-installed application as a temporary application under account one. For example, as shown in FIG. 9, the temporary application is installed in the independent user control. For example, when the user clicks the temporary installation control 403 shown in FIG. 9, the electronic device enters the space of account 1 and performs the operation of installing the temporary application in the space. The electronic device also has an account 2 in addition to the account 1, and stores and / or runs the permanently installed applications in the space of the account 2. Figure 17 Figure 4 As shown in FIG. 9, the temporary application is installed in the independent user control. For example, when the user clicks the temporary installation control 403 shown in FIG. 9, the electronic device enters the space of account 1 and performs the operation of installing the temporary application in the space. The electronic device also has an account 2 in addition to the account 1, and stores and / or runs the permanently installed applications in the space of the account 2.

[0181] As described above, after the electronic device performs S9216, the electronic device performs S9212-S9215, and the specific description can refer to the related description above, which will not be repeated here. Among them, the difference compared with the above is that, in S9215, when the user clicks the "permanent installation" item in the option 602 shown in FIG. 9, the electronic device moves the registration data, installation data, user usage data and other data under the account 1 to the account 2, so that the temporary application is converted into a normal application, and the application is configured with permissions. Figure 6

[0182] In this way, by installing the to-be-installed application as a temporary application under a specified account, the running space of the temporary application is independent of the running space of the permanently installed application (or normal application), which can provide a better isolation environment for the temporary application, can realize a relatively relaxed control on the temporary application, and can protect the user's privacy data from being stolen while improving the experience of running the temporary application.

[0183] The third stage is that the electronic device runs the application program.

[0184] Figure 18 A flowchart of a processing method of an application program provided by an embodiment of the present application. As shown in FIG. 9, S930-S934, specifically: Figure 18 ​​​

[0185] S930, when the application is running, the electronic device determines whether the application is a temporary application according to the marking information of the application. If the application is a temporary application, S931 is performed; if the application is not a temporary application, it is a permanently installed application (or normal application), S933 is performed.

[0186] In a specific implementation, when the application is running, the application calls the interface 1 of the electronic device, at this time, the application permission management module of the electronic device sends a request to the application management module, the request is used to request to query whether the application is a temporary application, and the request carries the marking information of the application. The application management module queries whether the application is a temporary application according to the marking information of the application. For example, if the application management module finds that the field corresponding to the marking information of the application in the application management list is false, it is determined that the application is not a temporary application; if the application management module finds that the field corresponding to the marking information of the application in the application management list is true, it is determined that the application is a temporary application.

[0187] Specifically, the specific implementation of S930 can refer to steps ④ and ⑤ shown in Figure 8 , which will not be described here.

[0188] S931, the electronic device determines the interface that can be called by the temporary application according to the running strategy.

[0189] In a specific implementation, after the application management module of the electronic device determines that the application is a temporary application, the application management module of the electronic device feeds back the query result to the application permission management module, the application permission management module sends a request to the strategy management module, the request is used to request to query the running strategy of the temporary application, and the request carries the basic information of the application. The strategy management module finds the running strategy corresponding to the application according to the basic information of the application, and sends the running strategy to the application permission management module. The application permission management module determines the interface that can be called by the temporary application according to the running strategy.

[0190] Specifically, the specific implementation of S931 can refer to steps ⑥ and ⑦ shown in Figure 8 , which will not be described here.

[0191] S932, when the application calls the interface 1 of the electronic device, the electronic device determines whether the interface 1 belongs to the interface that can be called by the temporary application. If the interface 1 belongs to the interface that can be called by the temporary application, S933 is performed; if the interface 1 does not belong to the interface that can be called by the temporary application, S934 is performed.

[0192] Specifically, the electronic device compares the interface 1 with the interfaces that can be invoked by the temporary application. When the interface 1 is consistent with one of the interfaces that can be invoked by the temporary application, the electronic device determines that the interface 1 belongs to the interfaces that can be invoked by the temporary application. When the interface 1 is inconsistent with all of the interfaces that can be invoked by the temporary application, the electronic device determines that the interface 1 does not belong to the interfaces that can be invoked by the temporary application.

[0193] S933, the electronic device allows the temporary application to invoke the interface 1.

[0194] After the electronic device determines that the interface 1 belongs to the interfaces that can be invoked by the temporary application, the electronic device allows the temporary application to invoke the interface 1.

[0195] After S933 is performed, the present flow ends.

[0196] S934, the electronic device does not allow the temporary application to invoke the interface 1, or the electronic device provides first information to the temporary application, the first information is a return result of invocation of the interface 1, and the first information is preset information or random information.

[0197] After the electronic device determines that the interface 1 does not belong to the interfaces that can be invoked by the temporary application, the electronic device does not allow the temporary application to invoke the interface 1. Specifically, the application permission management module of the electronic device determines that the temporary application will use sensitive permissions. At this time, the application permission management module refuses the temporary application to invoke the interface 1, or the application permission management module provides first information to the temporary application, the first information is preset information or random information, so as to protect the user privacy.

[0198] In the present application embodiment, the temporary application cannot be registered during the trial period, so as to not affect the uninstalled system service, and the temporary application is limited to obtain sensitive personal information, and the security is improved.

[0199] In other embodiments, Figure 19 A flowchart of a processing method of an application program is provided in the present application embodiment. As shown in the figure, Figure 19 the method can further include S940-S942, specifically,

[0200] S940, when the temporary application is running, the electronic device obtains behavior information of the temporary application.

[0201] Specifically, during the runtime of the temporary application, the application behavior monitoring module of the electronic device monitors the behavior of the temporary application, which can include background persistence, frequent pulling up, frequent positioning, etc. For example, the behavior is background persistence, and the electronic device can obtain the runtime length of the temporary application running in the background. The behavior is frequent pulling up, and the electronic device can obtain the behavior information of the temporary application frequently calling the interface that the temporary application cannot call. The behavior is frequent positioning, and the electronic device can obtain the number of times the temporary application calls the positioning interface. Of course, the embodiments of the present application are not limited to the above enumeration, and other examples can also be included, which are not listed one by one here.

[0202] Specifically, the specific implementation of S940 can refer to step 7 shown in Figure 8 here, and will not be repeated.

[0203] S941, the electronic device reports the behavior information of the temporary application to the server, and correspondingly, the server receives the behavior information of the temporary application.

[0204] Among them, the electronic device can report the behavior information of the temporary application to the server in real time, and the electronic device can also report the behavior information of the temporary application to the server at a preset time interval. Of course, after the server sends a request to the electronic device for obtaining the behavior information of the temporary application, the electronic device reports the behavior information of the temporary application to the server. Of course, the electronic device can also report the behavior information of the temporary application to the server after receiving an operation for triggering the reporting information.

[0205] Specifically, the specific implementation of S941 can refer to step 9 shown in Figure 8 here, and will not be repeated.

[0206] S942, the server obtains a behavior analysis report according to the behavior information of the temporary application.

[0207] Specifically, the server can analyze the behavior analysis report according to the behavior information of the temporary application reported by the electronic device, and in combination with a large amount of behavior data of the application collected by the server.

[0208] Among them, the behavior analysis report can provide a reference for formulating the running strategy of the temporary application, and the behavior analysis report can also provide a suggestion for the user to select whether to uninstall or permanently install the temporary application.

[0209] In the embodiments of the present application, during the trial period of the temporary application, the electronic device monitors the behavior of the temporary application and reports the monitored behavior information to the server, thereby providing analysis data for the server to perfect the big data of the application.

[0210] The terms and / or descriptions used in different embodiments of the present application are consistent and can be referred to each other if there is no special description and logical conflict. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.

[0211] The embodiments of the present application further provide an electronic device for implementing any of the above methods, for example, providing an electronic device comprising units (or means) for implementing each step performed by the electronic device in the above method S911-S942. For example, refer to Figure 20 , which is a schematic diagram of an electronic device provided by the embodiments of the present application. The electronic device 100 can include a display module 201, an installation module 202 and an execution module 203; wherein,

[0212] The display module 201 is configured to display a first interface, the first interface being a first installation interface of a first application, and the first interface displaying a first control for triggering temporary installation, the first application having fewer permissions available in the case of temporary installation than in the case of permanent installation. For example, the display module 201 can perform the steps of S920 described above. The display module 201 can be a display screen 270 as shown in Figure 9 .

[0213] The installation module 202 is configured to temporarily install the first application on the electronic device in response to a first operation on the first control. For example, the installation module 202 can perform the steps of S921 described above. Specifically, the installation module 202 can perform the steps of S9211 and S9216 described above. The installation module 202 can be an installer 801 as shown in Figure 8 .

[0214] The display module 201 is configured to display a second interface when the duration of the temporary installation of the first application on the electronic device satisfies a first threshold, the second interface being a second installation interface of the first application, and the second interface displaying at least one option, the at least one option including at least one of the following: extending the trial duration, uninstalling, permanently installing, and viewing an application behavior analysis report. For example, the display module 201 can perform the steps of S9214 described above.

[0215] The execution module 203 is configured to perform a first option corresponding operation in response to a second operation on a first option in the at least one option. For example, the execution module 203 can perform the steps of S9215 described above. The execution module 203 can be an installer 801 as shown in Figure 8 and / or a processor 210 as shown in Figure 9 .

[0216] In a specific implementation, the first application is monitored for more behavior types in the case of temporary installation than in the case of permanent installation.

[0217] In a specific implementation, in response to the first operation on the first control, the installation module 202 is configured to: in response to the first operation on the first control, temporarily install the first application in a target space on the electronic device; wherein the target space is different from a second space, the second space is used for permanently installing applications, and for the same application, the permissions available in the target space are less than the permissions available in the second space. For example, the installation module 202 can perform the steps of S9216 described above.

[0218] In a specific implementation, the target space is a user space of a first account, and the second space is a user space of a second account, the second account being different from the first account.

[0219] In a specific implementation, the target option includes permanent installation; the installation module 202 is configured to: in response to a second operation on the permanent installation, permanently install the first application in the second space on the electronic device; and migrate the data of the first application in the target space to the second space. For example, the installation module 202 can perform the steps of S9216 described above.

[0220] In some implementations, the electronic device 100 further includes a configuration module 204 configured to: when the first application is temporarily installed, configure the first application with mark information, the mark information being used to mark the first application as a temporary application; and configure the first application with specified permissions based on the mark information. For example, the configuration module 204 can perform the steps of S9211 described above. The configuration module 204 can configure the application management module 802 and the application permission management module 803 as shown in FIG. 8. Figure 8

[0221] In a specific implementation, the target option includes permanent installation; the installation module 202 is configured to: in response to a second operation on the permanent installation, clear the mark information of the first application; and reconfigure the permissions of the first application so that the first application has the permissions available in the case of permanent installation.

[0222] In some implementations, the display module 201 is configured to display a third interface, and the second option is displayed on the third interface, the second option being used to represent an option of a trial period. For example, the display module 201 can perform the steps of S9212 described above.

[0223] ​The electronic device 100 further includes a determination module 206 configured to determine the trial duration corresponding to the second option in response to the operation on the second option. The starting module 205 is configured to start a timing operation to time the trial duration of the first application on the electronic device to the trial duration corresponding to the second option when the temporary installation of the first application is successful. For example, the starting module 205 can perform the steps of S9213 described above.

[0224] In some embodiments, the determination module 206 is configured to determine the interface that can be invoked by the first application as a temporary application, and determine that the first interface belongs to the invocable interface when the first application invokes the first interface. For example, the determination module 206 can perform the steps of S932 described above. The determination module 206 can be the policy management module 805 shown in FIG. 8. Figure 8 The calling module 207 is configured to allow the first application to invoke the first interface. For example, the calling module 207 can perform the steps of S933 described above.

[0225] In a specific embodiment, the determination module 206 is configured to determine the interface that can be invoked by the first application as a temporary application according to a running policy, the running policy being used to represent the permission of the temporary application during the temporary running. For example, the determination module 206 can perform the steps of S930 and S931 described above.

[0226] In some embodiments, the electronic device 100 further includes an obtaining module 208 configured to obtain the application information of the first application from a server or another device, the application information including the running policy. For example, the obtaining module 208 can perform the steps of S913 described above. The obtaining module 208 can be the policy management module 805 shown in FIG. 8. Figure 8

[0227] In some embodiments, the determination module 206 is configured to determine that the second interface does not belong to the invocable interface when the first application invokes the second interface. The calling module 207 is configured to not allow the first application to invoke the second interface, or provide the first information to the first application, the first information being the return result of the invocation of the second interface, the first information being preset information or random information. For example, the calling module 207 can perform the steps of S934 described above.

[0228] In some embodiments, the obtaining module 208 is configured to obtain the behavior information of the first application when the first application is running, the behavior information being the request authorization behavior of the first application during the temporary running. For example, the obtaining module 208 can perform the steps of S940 described above. The obtaining module 208 can be the application behavior monitoring module 804 shown in FIG. 8. Figure 8

[0229] ​​The electronic device 100 further includes a reporting module 209 configured to report behavior information of the first application to a server, the behavior information of the first application being used by the server to improve a running strategy of the first application. For example, the reporting module 209 can perform the steps of S941.

[0230] In some embodiments, the determining module 206 is configured to determine a trustworthiness of the first application, the trustworthiness of the first application being used to represent the security of the first application. The display module 201 is configured to display the first interface when the trustworthiness of the first application is less than or equal to a second threshold.

[0231] In some embodiments, the available permissions include at least one of the following: a data access permission, a device call permission.

[0232] In the embodiments of the present application, the electronic device temporarily installs the to-be-installed application as a temporary application, so that the available permissions of the application are less than the available permissions in the case of permanent installation, thereby avoiding or mitigating the security risks caused by the application. In addition, after the temporary application is used for a period of time, the user can be prompted about how to handle the application according to the usage, thereby helping the user to distinguish whether the application is a malicious application, and effectively avoiding the security risks caused by the malicious application.

[0233] It should be noted that all related content of each step involved in the above method embodiments can be referred to the function description of the corresponding function module, and will not be repeated here.

[0234] The embodiments of the present application also provide a computer readable storage medium, including instructions, when running on a computer, causing the computer to execute any of the above methods.

[0235] The embodiments of the present application also provide a computer program product including instructions, when running on a computer, causing the computer to execute any of the above methods.

[0236] The embodiments of the present application also provide a chip, including a processor and an interface circuit, the interface circuit and the processor are coupled, the processor is used to run a computer program or instructions to realize the above method, and the interface circuit is used to communicate with other modules outside the chip.

[0237] Any feature or any step of the embodiments of the present application can be freely combined. The combined technical solutions are also within the scope of the present application.

[0238] In the description of the present application, unless otherwise specified, " / " means "or", for example, A / B can mean A or B. "And / or" in this article is only a description of the relationship between the associated objects, which means that there can be three relationships, for example, A and / or B, which can mean that A exists alone, A and B exist together, and B exists alone. In addition, "at least one" means one or more, and "multiple" means two or more. "First", "second", and the like do not limit the quantity and execution order, and "first", "second", and the like do not necessarily mean different.

[0239] In the description of the present application, "exemplary" or "for example" is used to mean an example, illustration, or description. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as more preferred or more advantageous than other embodiments or design schemes. Rather, the use of "exemplary" or "for example" is intended to present the relevant concept in a specific manner.

[0240] Through the description of the above embodiments, those skilled in the art can clearly understand that, for the convenience and brevity of description, only the above division of functional modules is taken as an example, and in actual application, the above functions can be completed by different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.

[0241] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic, for example, the division of the modules or units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another device, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed each other can be through some interface, indirect coupling or communication connection between devices or units, which can be electrical, mechanical or other forms.

[0242] The units described as separate components can or can not be physically separated, and the components shown as units can be one physical unit or multiple physical units, that is, they can be located in one place, or they can be distributed to multiple different places. According to actual needs, part or all of the units can be selected to achieve the purpose of the present embodiment scheme.

[0243] In addition, each function unit in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software function unit.

[0244] When the integrated unit is realized in the form of a software function unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on such understanding, the technical solutions of the embodiments of the present application essentially or the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The software product is stored in a storage medium, including a plurality of instructions to make a device (which can be a single-chip microcomputer, a chip, etc.) or a processor execute all or part of the steps of the method described in each embodiment of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various storage program codes.

[0245] The above is only a specific embodiment of the present application, but the protection scope of the present application is not limited thereto. Any change or replacement within the technical scope disclosed in the present application should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A processing method of an application program applied to an electronic device, comprising: The method comprises: displaying a first interface, the first interface being a first installation interface of a first application, a first control for triggering temporary installation being displayed on the first interface, the first application having fewer permissions available in the case of temporary installation than in the case of permanent installation; in response to a first operation on the first control, temporarily installing the first application on the electronic device; when the duration for which the first application is temporarily installed on the electronic device satisfies a first threshold, displaying a second interface, the second interface being a second installation interface of the first application, at least one first option being displayed on the second interface, the first option comprising at least one of the following: extending the trial duration, uninstalling, permanently installing, and viewing an application behavior analysis report; in response to a second operation on a target option in the at least one first option, performing an operation corresponding to the target option.

2. The method of claim 1, wherein, The first application is monitored for more types of behavior in the case of temporary installation than in the case of permanent installation.

3. The method according to claim 1 or 2, characterized in that, The response to the first operation on the first control to temporarily install the first application on the electronic device comprises: in response to the first operation on the first control, temporarily installing the first application in a target space on the electronic device; wherein the target space is different from a second space, the second space being used for permanently installing applications, and for the same application, fewer permissions are available in the target space than in the second space.

4. The method of claim 3, wherein, The target space is a user space of a first account, and the second space is a user space of a second account, the second account being different from the first account.

5. The method of claim 3, wherein, The target option comprises permanent installation; and the response to the second operation on the target option in the at least one first option to perform an operation corresponding to the target option comprises: in response to the second operation on the permanent installation, permanently installing the first application in the second space on the electronic device; migrating data of the first application in the target space to the second space.

6. The method of claim 1 or 2, wherein, The method further comprises: when the first application is temporarily installed, configuring the first application with marker information, the marker information being used to mark the first application as a temporary application; based on the marker information, configuring the first application with specified permissions.

7. The method of claim 6, wherein, The target option comprises permanent installation; and the response to the second operation on the target option in the at least one first option to perform an operation corresponding to the target option comprises: in response to the second operation on the permanent installation, clearing the marker information of the first application; reconfiguring permissions for the first application, so that the first application has permissions available in the case of permanent installation.

8. The method of claim 1 or 2, wherein, Further comprising: displaying a third interface, the third interface displaying a second option, the second option being used to represent a trial duration option; in response to an operation on the second option, determining a trial duration corresponding to the second option; When the first application is temporarily installed successfully, a timing operation is started to time a trial duration of the first application on the electronic device to a trial duration corresponding to the second option.

9. The method of claim 1 or 2, wherein, After the first application is temporarily installed on the electronic device, the method further includes: determining an interface that the first application can invoke as a temporary application; when the first application invokes a first interface, determining that the first interface belongs to the invocable interface; allowing the first application to invoke the first interface.

10. The method of claim 9, wherein, The determining of the interface that the first application can invoke as a temporary application includes: determining the interface that the first application can invoke as a temporary application according to a running policy, the running policy being used to represent a permission of the temporary application during a temporary running period.

11. The method of claim 10, wherein, Before the first application is temporarily installed on the electronic device, the method further includes: obtaining application information of the first application from a server or another device, the application information including the running policy.

12. The method of claim 9, wherein, The method further includes: when the first application invokes a second interface, determining that the second interface does not belong to the invocable interface; not allowing the first application to invoke the second interface, or providing first information to the first application, the first information being a return result of the invocation of the second interface, the first information being preset information or random information.

13. The method of claim 1 or 2, wherein, After the first application is temporarily installed on the electronic device, the method further includes: when the first application is running, obtaining behavior information of the first application, the behavior information being a request authorization behavior of the first application during the temporary running period; reporting the behavior information of the first application to a server, the behavior information of the first application being used by the server to perfect a running policy of the first application.

14. The method of claim 1 or 2, wherein, Before the first interface is displayed, the method further includes: determining a trustworthiness of the first application, the trustworthiness of the first application being used to represent a security of the first application; when the trustworthiness of the first application is determined to be less than or equal to a second threshold, displaying the first interface.

15. The method of claim 1 or 2, wherein, The usable permission includes at least one of the following: a data access permission, a device invocation permission.

16. An electronic device, comprising: The electronic device includes a display module, an installation module and an execution module, wherein the display module is used to display a first interface, the first interface being a first installation interface of a first application, the first interface displaying a first control for triggering temporary installation, the first application being able to use fewer permissions in a temporary installation case than in a permanent installation case; the installation module is used to temporarily install the first application on the electronic device in response to a first operation on the first control; the display module is used to display a second interface when a duration of the temporary installation of the first application on the electronic device satisfies a first threshold, the second interface being a second installation interface of the first application, the second interface displaying at least one first option, the first option including at least one of the following: extending a trial duration, uninstalling, permanently installing and viewing an application behavior analysis report; the execution module is used to perform an operation corresponding to a target option in response to a second operation on the target option.

17. An electronic device, comprising: The electronic device includes one or more processors and memory having code stored therein, which when executed by the processor(s) causes the electronic device to perform the method of any of claims 1-15.

18. A computer-readable storage medium, characterized in that, Computer instructions are included which, when executed on an electronic device, cause the electronic device to perform the method of any of claims 1-15.

Citation Information

Patent Citations

  • Trial application processing method and mobile terminal

    CN106775840A

  • Application process trial method and system

    CN108399331A