Method, user interface and electronic device for managing permissions

By displaying application request permissions in a centralized permissions window and recommending the fewest permissions, the problem of users arbitrarily granting permissions is solved, thus simplifying the configuration process and protecting privacy.

CN118940317BActive Publication Date: 2025-12-12HONOR DEVICE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411107080.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-08-12
Publication Date
2025-12-12
Estimated Expiration
2041-08-12

AI Technical Summary

Technical Problem

Users lack understanding when granting permissions to applications, leading to arbitrary or malicious use of electronic device resources and increasing the risk of privacy leaks.

Method used

Provide a centralized permissions window that displays the permissions requested by the application and recommends the fewest permissions. Guide users to grant permissions through popular preferences and server configuration tables, increasing the ease and security of permission configuration.

Benefits of technology

It simplifies the user permission configuration process, improves user experience, reduces the risk of privacy information leakage, and ensures the normal operation of the application.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118940317B_ABST
    Figure CN118940317B_ABST
Patent Text Reader

Abstract

The application discloses a permission management method, a user interface and an electronic device. The method can display a centralized permission window when an application is opened for the first time. The centralized permission window is used to indicate a plurality of permissions requested by the application. The centralized permission window includes a plurality of permission items. The plurality of permission items can be divided into two categories. One category of permission items indicates that the electronic device recommends that a user grant the application permissions. One category of permission items indicates that the electronic device does not recommend that the user grant the application permissions. In this way, the user can refer to the recommended and non-recommended permissions indicated by the electronic device to authorize the application, guide the user to grant the application the least permissions, and minimize the risk of user privacy information leakage.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of terminal and communication, and particularly relates to a permission management method, a user interface and an electronic device. BACKGROUND

[0002] With the development of the Internet, more and more applications can be installed on electronic devices. During the running of the applications, the hardware and software resources of the electronic devices need to be called to support the running of the applications. The hardware and software resources of the electronic devices involve the private information of users, and therefore, the electronic devices display a permission window to prompt the users to grant the permissions when the applications are opened for the first time or during the running of the applications, and allow the applications to call the corresponding hardware or software resources in the electronic devices after the consent of the users is obtained.

[0003] However, since many users do not understand or do not pay attention to the pros and cons of granting the permissions to the applications, the users grant the permissions to the applications at will, which causes the applications to call the hardware and software resources of the electronic devices at will or maliciously, and leads to the risk of leakage of the private information of the users and affects the private security of the users.

[0004] Therefore, how to control the reasonable acquisition of the permissions by the applications is a problem to be solved at present. SUMMARY

[0005] The present application provides a permission management method, a user interface and an electronic device.

[0006] In some embodiments of the present application, the permissions requested to be acquired by an application are displayed through a centralized permission window, and the least permissions recommended by an electronic device are also displayed in the centralized permission window, so as to guide the users to grant the least permissions to the application.

[0007] In a first aspect, the present application provides a permission management method, comprising: an electronic device starts an application without running the application;

[0008] The electronic device displays a first window containing a first permission item and a second permission item in response to the starting of the application, the first window indicates the permissions requested to be acquired by the application, the first permission item indicates the permissions recommended by the electronic device for the users to grant to the application, the second permission item indicates the permissions not recommended by the electronic device for the users to grant to the application, and the permissions indicated by the first permission item are the least permissions allowed to be used by the application.

[0009] In the method provided by the first aspect, the electronic device can display a centralized permission window when the application is opened for the first time, the centralized permission window is used to display the multiple permissions requested by the application, and the centralized permission window displays the permissions recommended by the electronic device for the application and the permissions not recommended by the electronic device for the application. In this way, the user can refer to the permissions recommended and not recommended by the electronic device to configure the permissions for the application, avoid the user blindly granting the permissions to the application, cause the user privacy information to be leaked, and speed up the user in configuring the permissions for the application.

[0010] In a possible implementation of the first aspect, the permission recommended by the electronic device is a permission when the number of users who agree to grant the application the permission is greater than a threshold value in pre-authorization of the application by multiple users, and the permission not recommended by the electronic device is a permission when the number of users who refuse to grant the application the permission is greater than a threshold value in pre-authorization of the application by multiple users.

[0011] That is, the permission recommended by the electronic device and the permission not recommended by the electronic device in the pre-authorization of the application can be obtained by referring to the permissions granted to the application and the permissions refused to be granted to the application by multiple users in configuring the permissions. In this way, the electronic device can provide the tendency of the public in the pre-authorization of the application as a reference to the user, and help the user to quickly complete the pre-authorization of the application.

[0012] In a possible implementation of the first aspect, the permission recommended by the electronic device is a permission when the number of users who agree to grant the application of the same type as the application the permission is greater than a threshold value in pre-authorization of the application of the same type as the application by multiple users, and the permission not recommended by the electronic device is a permission when the number of users who refuse to grant the application of the same type as the application the permission is greater than a threshold value in pre-authorization of the application of the same type as the application by multiple users.

[0013] That is, the permission recommended by the electronic device and the permission not recommended by the electronic device in the pre-authorization of the application can be obtained by referring to the permissions granted to the application of the same type as the application and the permissions refused to be granted to the application of the same type as the application by multiple users in configuring the permissions. In this way, the electronic device can provide the tendency of the public in the pre-authorization of the application of the same type as the application as a reference to the user, and help the user to quickly complete the pre-authorization of the application.

[0014] In a possible implementation of the first aspect, before the electronic device starts the application without running the application, the method further includes: the electronic device acquires a permission configuration table sent by a server, the permission configuration table being used to determine the permission recommended by the electronic device and the permission not recommended by the electronic device.

[0015] That is, the recommended permission and the non-recommended permission of the electronic device can be determined by the server, and the server can determine the recommended permission and the non-recommended permission by analyzing the configuration of the permission by multiple users.

[0016] With reference to the first aspect, in a possible implementation, the method further includes: detecting, by the electronic device, an operation of starting a first function of the application, the permission required by the first function not being the permission indicated by the first permission item; and displaying, by the electronic device, a second window, the second window displaying a third permission item, the third permission item including first indication information of whether the electronic device recommends granting the permission required by the first function of the application to the user.

[0017] It can be seen that, in the process of running the application, the electronic device can also detect the operation of starting the function of the application, display the function permission window, prompt the user to grant the permission required by the function, and the function permission window also displays prompt information of whether the electronic device recommends the permission. In this way, the user can refer to the prompt information to determine whether to grant the permission to the application, and protect the privacy and security of the user as much as possible.

[0018] With reference to the first aspect, in a possible implementation, the permission indicated by the third permission item is location information, the second window includes an accurate location option, a blurred location option, and second indication information, the accurate location option is used to indicate that the application acquires a first location of the electronic device, the blurred location option is used to indicate that the application acquires a second location of the electronic device, the first location is the actual geographical location of the electronic device, the accuracy of the second location is lower than that of the first location, and / or the second location is offset from the first location, and the second indication information is used to indicate whether the location option recommended by the electronic device is the accurate location option or the blurred location option.

[0019] In the process of running the application, when the permission requested by the application is location information, the electronic device can also provide two modes of acquiring location information by the application: accurate location and blurred location, so that the electronic device can distinguish different scenes to recommend whether to grant the accurate location information to the user, and avoid the leakage of privacy information as much as possible under the premise of ensuring the running of the application.

[0020] With reference to the first aspect, in a possible implementation, the first permission item includes a switch option in an on state, and the second permission item includes a switch option in an off state.

[0021] That is, the electronic device can add a switch option in the permission window, and use the on or off state of the switch option to represent whether the electronic device recommends the permission.

[0022] With reference to the first aspect, in a possible implementation manner, the first permission item comprises first indication information, and the first indication information describes a proportion of users who agree to grant the permission indicated by the first permission item when the application is authorized by the plurality of users.

[0023] That is, the electronic device can add the selection condition of the public on the permission item in the permission window, for example, the proportion of users who agree to grant the permission, and use the proportion as the reference data of the user. When the proportion is high, the user can know that most people select to agree to grant the permission. When the proportion is low, the user can know that most people select to refuse to grant the permission. In this way, the proportion provides a reference for the user, helping the user to quickly complete the permission configuration of the application.

[0024] With reference to the first aspect, in a possible implementation manner, the first permission item comprises second indication information, and the second permission item does not comprise the second indication information. The second indication information is used to indicate that the permission indicated by the first permission item is a permission recommended by the electronic device for the user to grant to the application, and the permission indicated by the second permission item is a permission not recommended by the electronic device for the user to grant to the application.

[0025] That is, the electronic device can add additional information in the recommended permission item to distinguish from the non-recommended permission item. For example, the electronic device can add text information such as “recommended” and “priority” in the recommended permission item to guide the user to grant the permission to the application.

[0026] With reference to the first aspect, in a possible implementation manner, the first window further comprises countdown prompt information, the countdown prompt information is used to prompt the user to complete the authorization of the application within a countdown time, and after the electronic device displays the first window, the method further comprises: after the countdown ends, when the electronic device does not detect an operation on the first window, the electronic device grants the permission indicated by the first permission item to the application.

[0027] That is, by displaying the countdown in the permission window, the user can be guided to quickly complete the authorization of the application, and the waste of too much time of the user in the authorization of the application can be avoided.

[0028] With reference to the first aspect, in a possible implementation manner, the permission indicated by the first permission item is location information, the first permission item comprises a location mode option and third indication information, the location mode option is used to trigger the application to obtain the accurate geographic position of the electronic device, and the third indication information is used to indicate whether the electronic device recommends the application to obtain the accurate geographic position of the electronic device.

[0029] In a second aspect, an embodiment of the present application provides an electronic device, comprising a display screen, a memory, one or more processors, a plurality of application programs, and one or more programs; wherein the one or more programs are stored in the memory; and the one or more processors, when executing the one or more programs, cause the electronic device to implement the method described in the first aspect or any one of the implementation manners of the first aspect.

[0030] In a third aspect, an embodiment of the present application provides a computer-readable storage medium, which comprises instructions, and when the instructions run on an electronic device, cause the electronic device to execute the method described in the first aspect or any one of the implementation manners of the first aspect.

[0031] In a fourth aspect, an embodiment of the present application provides a computer program product, and when the computer program product runs on a computer, cause the computer to execute the method described in the first aspect or any one of the implementation manners of the first aspect.

[0032] By implementing the technical solution provided in the embodiments of the present application, the electronic device can provide a centralized permission window for the permission configuration of the application, display the permissions requested by the application in a permission window, simplify the operation of the user, and in addition, the electronic device can also indicate the recommended permissions granted by the user to the application and the permissions not recommended to be granted by the user in the centralized permission window, provide a reference for the user to grant the permissions to the application, guide the user to grant the minimum permissions to the application, and reduce the risk of leakage of user privacy information as much as possible. BRIEF DESCRIPTION OF DRAWINGS

[0033] Figures 1A-1C Some user interfaces involved in obtaining permissions for an application;

[0034] Figure 2 A hardware structure diagram of an electronic device provided in an embodiment of the present application;

[0035] Figure 3 A software structure diagram of an electronic device provided in an embodiment of the present application;

[0036] Figures 4A-4B 、 Figures 5A-5B 、 Figures 6A-6B Some user interfaces provided in an embodiment of the present application;

[0037] Figure 7 A flowchart of a permission management method provided in an embodiment of the present application. DETAILED DESCRIPTION

[0038] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings. In the description of the embodiments of the present application, unless otherwise specified, " / " represents the meaning of or, for example, A / B can represent A or B; the "and / or" in the text only describes the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B, which can represent: A alone, A and B together, and B alone, in addition, in the description of the embodiments of the present application, "multiple" means two or more than two.

[0039] Hereinafter, the terms "first" and "second" are used only for descriptive purposes, and cannot be understood as implying or suggesting relative importance or implicitly indicating the number of indicated technical features. Therefore, the features defined with "first" and "second" can explicitly or implicitly include one or more of the features, and in the description of the embodiments of the present application, unless otherwise specified, the meaning of "multiple" is two or more than two.

[0040] In the following embodiments of the present application, the term "user interface (UI)" is a medium interface for interaction and information exchange between an application or an operating system and a user, which realizes the conversion between the internal form of information and the form that the user can accept. The user interface is the source code written in a specific computer language such as Java, extensible markup language (XML), etc. The interface source code is parsed, rendered on the electronic device, and finally presented as content that the user can recognize. The commonly used form of user interface is graphic user interface (GUI), which refers to a user interface related to computer operation displayed in a graphical manner. It can be a visual interface element such as text, icon, button, menu, tab, text box, dialog box, status bar, navigation bar, Widget, etc. displayed in the display screen of the electronic device.

[0041] Figures 1A-1C Some user interfaces involved when the application obtains permissions are exemplarily shown.

[0042] Figure 1A 、 Figure 1B 、 Figure 1C The user interfaces displayed by the electronic device in turn when the application is started for the first time are shown. These user interfaces are respectively used to display permission windows 01-03, and each permission window is used to prompt the user to grant the application related permissions.

[0043] The permission windows 01-03 are used to prompt the user to grant the application the permission to obtain the device information, storage space, and location information of the electronic device. After receiving the user's processing of one permission window, the electronic device displays the next permission window to prompt the user to grant the application the next permission, for example, after the user sets the application to always allow, allow when using the application, or prohibit the application from using the permission mentioned in the permission window.

[0044] That is, before the user uses the application, the user needs to successively process multiple permission windows, that is, process whether to grant the application the corresponding permission. It can be seen that the continuous multiple prompts for authorization information and complex operations not only affect the user's operation experience of the application, but also easily wear out the user's patience, causing the user to randomly process the permission window, grant the application multiple permissions, and indirectly cause the user's privacy leakage problem. In addition, for a user who does not understand the application authorization related information, it is often difficult to decide whether to grant the application the corresponding permission, thereby wasting too much time in authorizing the application and causing the user to delay the normal use of the application.

[0045] The embodiments of the present application provide a permission management method, which can display a centralized permission window when an application is opened for the first time. The centralized authorization window is used to indicate the permissions requested by the application, and the centralized permission window includes multiple permission items. The multiple permission items can be divided into two categories: one category of permission items indicates that the electronic device recommends the user to grant the application the permission, and the other category of permission items indicates that the electronic device does not recommend the user to grant the application the permission. The permission item recommended by the electronic device for the user to grant the permission is the minimum permission item specified to ensure the normal operation of the application. After the electronic device completes the configuration of the application permissions, the running interface of the application can be displayed for the user to use the functions of the application.

[0046] It can be seen that the authorization recommendation method can display multiple permissions in a centralized permission window when the user opens the application for the first time, avoid the user's multiple processing of the permissions, simplify the user's operation, and improve the user's experience. In addition, the centralized permission window distinguishes which permissions are recommended to be granted and which permissions are not recommended to be granted, provides a reference for the user to grant the permissions, guides the user to grant the application the minimum permissions, and helps the user to quickly complete the authorization of the application. Moreover, the minimum permission item determined by the electronic device is the minimum permission specified for the application to use, which can also mean the minimum permission granted to the application to meet the application operation requirements. In this way, the risk of user privacy information leakage can be reduced as much as possible on the basis of ensuring the operation of the application.

[0047] The permission item indicates a permission requested by the application. The permission describes an access right of the application to a resource of the electronic device. Granting the application the permission can mean granting the application the right to access the resource of the electronic device. The resource of the electronic device includes a hardware resource and a software resource. The hardware resource includes a sensor, a detector, a memory, a microphone, a speaker, and the like on the electronic device. The software resource includes a storage space, location information, an application program (for example, a contacts, a message, a calendar, a telephone, a gallery, a camera), a floating window, and the like. Taking a navigation application as an example, when the navigation function of the navigation application is used, the navigation application needs to obtain the location information of the electronic device, so as to obtain the surrounding road conditions of the location of the user according to the location of the user, provide a navigation route for the user, and help the user to reach the destination. This means that the navigation application needs to be granted the permission to obtain the location information by the electronic device, so as to normally run the navigation function provided by the navigation application.

[0048] The electronic device can show whether the permission is recommended by using one or more of the following manners:

[0049] 1. Configuring different selection states for the permission items

[0050] Since the permission item can receive the operation of the user and change the selection state of the permission item, the selection state can include a selected state and an unselected state. The electronic device can configure a default selection state for each permission item when the centralized authorization window is displayed. The permission item recommended by the electronic device can be in the selected state, and the permission item not recommended can be in the unselected state. Specifically, the electronic device can show the selection state of the permission item by using a switch, font color, font size, font thickness, and the like. In this way, the user can determine whether the permission item is recommended by the electronic device through the different display manners of the permission item, and the user does not need to configure the permission again. The user can directly click the confirmation on the permission configured by default by the electronic device, so as to complete the configuration of the application permission, thereby reducing the operation of the user.

[0051] 2. Adding additional prompt information in one type of permission item

[0052] For example, the electronic device can add the word information such as “recommended” and “priority” behind the recommended permission item. In this way, the electronic device can know that the permission indicated by the permission item is the permission recommended by the electronic device for the user to grant the application according to the word information of the prompt in the permission item.

[0053] 3. Displaying statistical data on the permission item

[0054] The electronic device can determine whether the permission item is a recommended or non-recommended permission item by the amount of statistical data or comparison with other statistical data. For example, there is a permission item corresponding to the permission of location information, and the location information can display the proportion of other users granting the permission to the application or similar application, for example, 80%. Through the score, the user can know that 80% of people have selected to grant the permission, thereby indirectly knowing that the permission item is a recommended permission item for the electronic device to authorize.

[0055] It can be understood that the electronic device can also express whether the permission is recommended in other ways, for example, changing the arrangement order of the permissions, and the recommended permission items of the electronic device are arranged above the non-recommended permission items of the electronic device. For specific ways of expressing the recommended and non-recommended permissions of the electronic device, please refer to the subsequent content, which will not be described here.

[0056] Figure 2 A hardware structure schematic diagram of an electronic device 100 provided by an embodiment of the present application is shown.

[0057] The electronic device 100 can be a mobile phone, a tablet computer, a desktop computer, a laptop computer, a handheld computer, a notebook computer, an ultra-mobile personal computer (UMPC), a netbook, a cellular phone, a personal digital assistant (PDA), an augmented reality (AR) device, a virtual reality (VR) device, an artificial intelligence (AI) device, a wearable device, a vehicle-mounted device, a smart home device, and / or a smart city device, etc. The specific type of the electronic device is not specially limited in the embodiments of the present application.

[0058] The electronic device 100 can include a processor 101, a memory 102, a wireless communication module 103, a mobile communication module 104, an antenna 103A, an antenna 104A, a power switch 105, a sensor module 106, an audio module 107, a camera 108, a display screen 109, etc. The sensor module 106 can include a gyroscope sensor 106A, an air pressure sensor 106B, a touch sensor 106C, etc. The wireless communication module 103 can include a WLAN communication module, a Bluetooth communication module, etc., and the audio module 107 includes a speaker 107A, a receiver 107B, a microphone 107C, and a headphone interface 107D. The above-mentioned multiple parts can transmit data through a bus.

[0059] In some embodiments, the processor 101 can be configured to determine whether the permission requested by the application is a permission granted to the recommended user, and grant the application the corresponding permission according to the configuration of the user on the permission, or reject the application the corresponding permission.

[0060] In some embodiments, the memory 102 is configured to store a permission configuration table sent by the server, which records one or more applications, the minimum permission specified, and the permission granted to the recommended user and the permission not granted to the recommended user. The description of the permission configuration table will be described in subsequent embodiments, and will not be described here.

[0061] The electronic device 100 can realize the display function through the GPU, the display screen 109, and the application processor. The GPU is a microprocessor for image processing, connected to the display screen 109 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. The processor 101 can include one or more GPUs that execute program instructions to generate or change display information.

[0062] The display screen 109 is configured to display images, videos, and the like. The display screen 109 includes a display panel. The display panel can be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a Miniled, a MicroLed, a Micro-oLed, a quantum dot light-emitting diode (QLED), and the like. In some embodiments, the electronic device 100 can include one or N display screens 109, and N is a positive integer greater than 1.

[0063] In some embodiments, the display screen 109 can be configured to display an authorization window when configuring the permission of the application, and the authorization window is configured to display one or more permissions requested by the application to be granted by the user, and the permission recommended and not recommended by the electronic device 100 to be granted by the user.

[0064] For some sensitive permissions (such as location, shooting, or recording permissions), only single authorization can be recommended, such as recommending the default selection of only one-time permission.

[0065] It can be understood that the structure illustrated by the embodiments of the present application does not constitute a specific limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 can include more or fewer components than illustrated, or combine certain components, or split certain components, or different arrangement of components. The illustrated components can be implemented in hardware, software, or a combination of software and hardware.

[0066] The electronic device can be a portable terminal device such as a mobile phone, a tablet computer, a wearable device, etc. that runs an iOS, an Android, a Microsoft, or other operating system, and can also be a non-portable terminal device such as a laptop computer with a touch-sensitive surface or touch panel, a desktop computer with a touch-sensitive surface or touch panel, etc. The software system of the electronic device 100 can adopt a layered architecture, an event-driven architecture, a micro-kernel architecture, a micro-service architecture, or a cloud architecture. The embodiments of the present application take the Android system with a layered architecture as an example to illustrate the software structure of the electronic device 100.

[0067] Figure 3 is a software structure block diagram of the electronic device 100 of the embodiments of the present application.

[0068] The layered architecture divides the software into several layers, each of which has a clear role and division of labor. The layers communicate with each other through software interfaces. In some embodiments, the Android system is divided into four layers, from top to bottom, the application layer, the application framework layer, the Android runtime and system library, and the kernel layer.

[0069] The application layer can include a series of application packages.

[0070] As shown in Figure 3 , the application package can include camera, gallery, calendar, phone, address book, navigation, WLAN, music, settings, and SMS applications.

[0071] In some embodiments, during the running of an application, the application may need to access other applications to obtain resources required for its own functions, for example, access pictures in the gallery. At this time, the electronic device 100 can display an authorization window to prompt the user to request to grant the application permission to access other applications, which can refer to the above-mentioned camera, gallery, calendar, etc. applications.

[0072] The application framework layer provides the application layer with application programming interfaces (APIs) and programming frameworks for the applications. The application framework layer includes some pre-defined functions.

[0073] AsFigure 3 As shown, the application framework layer can include a window manager, a content provider, a view system, a phone manager, a resource manager, a notification manager, etc.

[0074] The window manager is used to manage windows. The window manager can acquire the size of the display screen, determine whether there is a status bar, lock the screen, and intercept the screen, etc.

[0075] The content provider is used to store and acquire data, and make the data accessible to applications. The data can include videos, images, audios, dialed and received calls, browsing history and bookmarks, phone books, etc. Before accessing the data, the electronic device 100 can display an authorization window to prompt the user to request permission for the application to access the data.

[0076] The view system includes visual controls, such as a control for displaying text, a control for displaying pictures, etc. The view system can be used to build an application. A display interface can be composed of one or more views. For example, a display interface including a short message notification icon can include a view for displaying text and a view for displaying pictures.

[0077] The phone manager is used to provide the communication function of the electronic device 100. For example, the management of the call state (including connection, hang-up, etc.).

[0078] The resource manager provides various resources for applications, such as localized strings, icons, pictures, layout files, video files, etc.

[0079] The notification manager enables an application to display notification information in the status bar, which can be used to convey a type of message that can automatically disappear after a short stay without user interaction. For example, the notification manager is used to inform the completion of downloading, message reminders, etc. The notification manager can also be a notification in the form of a chart or a scroll bar text appearing in the top status bar of the system, such as a notification of an application running in the background, or a notification in the form of a dialogue window appearing on the screen. For example, prompting text information in the status bar, issuing a prompt sound, the electronic device vibrating, the indicator light flashing, etc.

[0080] The Android runtime includes a core library and a virtual machine. The Android runtime is responsible for the scheduling and management of the Android system.

[0081] The core library includes two parts: one part is the function function called by the java language, and the other part is the core library of Android.

[0082] The application layer and application framework layer run in a virtual machine. The virtual machine executes the Java files of the application layer and application framework layer as binary files. The virtual machine is used to perform functions such as object lifecycle management, stack management, thread management, security and exception management, and garbage collection.

[0083] System libraries can include multiple functional modules. For example: surface manager, media libraries, 3D graphics processing libraries (e.g., OpenGL ES), 2D graphics engines (e.g., SGL), etc.

[0084] The Surface Manager is used to manage the display subsystem and provides the blending of 2D and 3D layers for multiple applications.

[0085] The media library supports playback and recording of various common audio and video formats, as well as still image files. It supports multiple audio and video encoding formats, such as MPEG4, H.264, MP3, AAC, AMR, JPG, and PNG.

[0086] The 3D graphics processing library is used to implement 3D graphics drawing, image rendering, compositing, and layer processing.

[0087] A 2D graphics engine is a graphics engine for 2D drawing.

[0088] The kernel layer is the layer between hardware and software. The kernel layer contains at least the display driver, camera driver, audio driver, and sensor driver.

[0089] The following is combined Figures 4A-4B , Figures 5A-5B , Figures 6A-6B This section introduces some of the user interfaces involved in this permission management method.

[0090] exist Figures 4A-4B , Figures 5A-5B , Figures 6A-6B In the user interface shown, taking the electronic device 100 running a browser application as an example, a browser application refers to a type of application used to retrieve, display, and transmit network information resources. In other embodiments of this application, the electronic device may run other applications. This application does not limit the applications that the electronic device runs.

[0091] Figures 4A-4B The diagram illustrates the user interface involved when the electronic device 100 first opens the application and displays the centralized permissions window.

[0092] Figure 4A An exemplary user interface 21 for an application menu is shown on an electronic device 100.

[0093] As shown in Figure 4A , the user interface 21 can include: a status bar 211, a calendar indicator 212, a weather indicator 213, a settings icon 214, a browser icon 215. Among them:

[0094] The status bar 211 can include one or more signal strength indicators of mobile communication signals, one or more signal strength indicators of wireless fidelity (WiFi) signals, a battery status indicator, and a time indicator. The calendar indicator 212 can be used to indicate the current time. The weather indicator 213 can be used to indicate the weather type.

[0095] As shown in Figure 4A , the electronic device 100 can detect an operation of opening the browser for the first time, that is, detect a user operation acting on the browser icon 215, and in response to the user operation, display the user interface 31 as shown in Figure 4B . Here, opening the browser for the first time can mean that the electronic device 100 opens the browser for the first time after installing or updating the browser, or opens the browser when the browser does not occupy data in the storage space of the electronic device 100.

[0096] As shown in Figure 4B , the user interface 31 is a user interface provided by the browser, which can be a main page provided by the browser, or a start page displayed when the browser is opened for the first time, etc. In Figure 4B , the user interface 31 is a main page provided by the browser.

[0097] In addition, the user interface 31 also contains a centralized permission window 311. The centralized permission window 311 is used to centrally display the permissions requested by the browser when it is started for the first time. Among them, the centralized permission window 311 contains a first permission item 311A, a second permission item 311B, and a third permission item 311C, which respectively indicate that the permissions requested by the browser are: storage, device information, and location information. The permission item also contains an authorization switch, such as the first switch 3111A in the first permission item 311A in the on state, the second switch 3111B in the second permission item 311B in the off state, and the third switch 3111C in the third permission item 311C. The "prohibit" option is in the on state. That is, the centralized permission window 311 also displays the default configuration of the electronic device 100 on the permissions. At the same time, the first switch 3111A to the third switch 3111C can all change the on or off state of the switch in response to the user's operation. In this way, the user can modify the configuration of the permissions again on the premise that the default configuration already exists in the centralized permission window 311.

[0098] From Figure 4BAs shown in the centralized permissions window 311, the permission items corresponding to "Storage" are granted permissions by default, while the permission items corresponding to "Device Information" and "Location Information" are not granted permissions by default. The cancel option 311D can be used to exit the settings for this centralized permissions window 311 and cancel granting permissions to applications. The confirm option 311E can be used to confirm the settings for this centralized permissions window 311 and grant corresponding permissions to applications according to the permissions configured in the centralized permissions window 311. For example, when an electronic device detects an application that interacts with... Figure 4B When the touch operation of the confirmed option 311E is performed, the electronic device 100 grants the browser permission to access the storage space of the electronic device 100 according to the permission configuration in the centralized permission window 311, and denies permission to access the device information and location information of the electronic device 100.

[0099] from Figures 4A-4B As can be seen, when the electronic device 100 first launches an application, the electronic device 100 can display a centralized permissions window. This centralized permissions window can contain the first or more permissions that the application requests before running. Furthermore, the electronic device 100 can set a default configuration for the permissions in the centralized permissions window. This default configuration can include whether to enable the permission, or further, include the authorization method of the permission. The authorization method indicates the duration for which the electronic device grants the permission to the application. For example, the authorization method can be: always allow, allow when using this application, prohibit, etc. Here, always allow means that after the electronic device grants the permission to the application, the application always has the permission. Allow when using this application means that after the electronic device grants the permission to the application, the application is allowed to use the permission during operation. Prohibit means that the electronic device refuses to grant the permission to the application.

[0100] It is understandable that electronic device 100 can... Figure 4B The default on / off state shown indicates whether the permission item is recommended. Alternatively, the electronic device 100 can also indicate whether the permission item is recommended in other ways. For example, the electronic device 100 can add text prompts such as "Recommended" or "Preferred" to the recommended permission item to inform the user that the permission item is recommended by the electronic device 100. Or, the permission item can display the percentage of other users who agree to or deny authorization. For details on how the electronic device 100 recommends permission items, please refer to the following embodiments, which will not be elaborated here.

[0101] Figures 5A-5B This example illustrates some user interfaces involved when an application requests permissions during runtime.

[0102] Figure 5AThe user interface 31 provided by the browser is shown in the process that the electronic device 100 runs the browser in the foreground.

[0103] The user interface 31 includes a search box 312 and a browsing area 313. The browsing area 313 can be used to display news or consultation information provided by the browser, and the search box 312 can be used to provide an entry for user search. The search box 312 includes a voice control 312A, which can be used to start the voice search function of the browser. When the electronic device 100 receives the operation of the user acting on the voice control 312A, the browser starts the voice search function, and the browser needs to obtain the voice input by the user through the microphone, and identify the search keyword output by the user according to the voice, so as to realize the search according to the search keyword. At this time, since the browser does not have the permission to access the microphone, the electronic device 100 can display the permission window 314 as shown in Figure 5B

[0104] As shown in Figure 5B , the permission window 314 is used to prompt the user whether to allow the "browser" to access the microphone of the electronic device 100. In addition, the permission window 314 can include multiple options for the electronic device 100 to grant different permission time lengths to the application. Specifically, the multiple options can include: an "always allow" option, a "when using this application allow" option, a "prohibit" option, and the like. The "always allow" option means that after granting the application permission, the application always has the permission regardless of whether the user uses the application. The "when using this application allow" option means that after granting the application permission, the application has the permission only when the user uses the application. The "prohibit" option means to refuse to grant the application permission. That is, the "always allow" option, the "when using this application allow" option, and the "prohibit" option gradually reduce the permission time length granted to the application. In addition, the permission window 314 also indicates the default permission setting of the electronic device 100. The electronic device 100 can indicate the recommended option of the electronic device 100 by highlighting the option, for example, Figure 5B It can be seen that the target option 314A is the recommended option of the electronic device 100.

[0105] ​That is, during the process that the electronic device 100 runs the application in the foreground, the electronic device 100 can still display the authorization box to prompt whether to allow the application to obtain the permission. Here, the permission requested by the application is different from the permission requested by the application when the application is started. The permission requested by the application during the running process can be the permission required for a specific function of the application, and the permission requested by the application when started can be the permission requested for the basic function of the application. In addition, the permission recommended by the electronic device 100 when the application is started is the minimum permission provided to ensure the basic running of the application. In this way, the electronic device 100 can minimize the risk of user privacy leakage as much as possible on the basis of ensuring the basic running of the application. At the same time, the authorization window displayed during the running process of the application can still indicate the authorization option recommended by the electronic device 100. In this way, it can help the user to make the most appropriate choice more quickly.

[0106] Figures 6A-6B Some user interfaces involved when the application requests to obtain location information and the electronic device 100 provides the precise location or the blurred location are exemplarily shown.

[0107] Figure 6A The user interface 31 displayed by the electronic device 100 when the browser is opened for the first time is shown.

[0108] Among them, the user interface 31 includes a centralized permission window 315, which is similar to the centralized permission window 311 in Figure 4B , which is used to centrally display the permission requested by the browser when it is started for the first time. The difference is that when the centralized permission window 315 contains location information, the centralized permission window 315 can also include a location mode option 315A, which is used to determine the mode of obtaining location information by the application. The mode includes: precise location and mode location. The precise location is used to provide the electronic device 100 correct and accurate geographic location for the application, and the blurred location is used to provide rough and incorrect geographic location for the application. In addition, the location mode option 315A includes a switch 3151A, which is used to control the selection of the location mode. Specifically, when the switch 3151A is in the off state, the mode of obtaining location information by the browser is the blurred location, and when the switch 3151A is in the on state, the mode of obtaining location information by the browser is the precise location. Similarly, similar to Figure 4BThe default configuration in the centralized permission window 311 can also exist in the centralized permission window 315, which refers to the minimum permissions that the electronic device 100 pre-sets in the centralized permission window 315. Whether the switch 3151A is in the on state can also be determined according to the function of the application. For example, when the browser can recommend nearby news for the user by obtaining the location information of the electronic device 100, thereby realizing the news recommendation function of the browser. However, although the browser can recommend nearby news to the electronic device 100 according to the location information of the electronic device 100, the browser can also realize the news recommendation function without accurate location, so here, the switch 3151A can be in the default off state.

[0109] Figure 6B It is shown that when the browser requests to obtain the location information during the running process, the permission window 316 displayed in the user interface 31.

[0110] The permission window 316 is used to prompt the user whether to allow the "browser" to obtain the location information of the electronic device 100. The permission window 316 includes the accurate location option 316A, the blurred location option 316B, the first optional option 316C, the target option 316D, and the second optional option 316E. The accurate location option 316A is used to allow the application to obtain accurate location information, and the blurred location option 316B is used to allow the application to obtain blurred location information. The first optional option 316C, the target option 316D, and the second optional option 316E are three options corresponding to different permission durations granted to the application by the electronic device 100. For a detailed description of the three options, please refer to the related description in Figure 5B In addition, the authorization mode indicated by the target option 316D is the authorization mode of the location information recommended by the browser by the electronic device 100. Compared with the first optional option 316C and the second optional option 316E, the target option 316D is in the selected state. Here, the selection of the option can be distinguished by highlighting, that is, changing the background color. When the option background color is darker, the option is in the selected state, and when the option background color is lighter, the option is in the unselected state. Furthermore, the blurred location 316B is in the selected state, and the accurate location option 316A is in the unselected state. Whether the accurate location option 316A and the blurred location option 316B are in the selected state can be embodied by whether the border is thickened. When the option border is thickened, the option is in the selected state, and when the option border is not thickened, the option is in the unselected state.

[0111] In addition, the electronic device 100 can also receive the operation (for example, a click operation) of the user acting on the precise location option 316A, the vague location option 316B, the first selectable option 316C, the target option 316D, and the second selectable option 316E, and modify the default configuration recommended by the electronic device 100.

[0112] It can be seen that when the application first starts or during the running of the application, when the application requests the permission to obtain the location information, the electronic device 100 can display the location mode option in the permission window, further subdividing the accuracy and / or precision of the location information obtained by the application, in addition, the electronic device 100 can also have a default configuration, that is, indicating in the permission window whether the electronic device 100 recommends the application to obtain the precise location or the vague location, providing a reference for the user to configure the permission of the location information, reducing the operation of the user, and under the premise of not affecting the running of the application, as far as possible, reducing the leakage of privacy.

[0113] Figure 7 An exemplary flowchart of the permission management method provided by the embodiments of the application is shown.

[0114] As shown in Figure 7 , the method comprises:

[0115] S101, the electronic device 100 obtains the permission configuration table from the server.

[0116] The permission configuration table is used to determine the permission recommendation of the application, that is, the permission granted by the user when the electronic device 100 first opens the application or during the running, and the permission recommended by the electronic device 100 for the user to grant to the application and the permission not recommended by the electronic device 100 for the user to grant to the application.

[0117] The permission describes the access right of the application to the resources of the electronic device 100, and granting the permission to the application can mean granting the right of the application to access the resources of the electronic device 100. The description of the resources of the electronic device 100 can be referred to the foregoing content, which will not be repeated here.

[0118] The generation of the permission configuration table can include the following ways:

[0119] 1) The permission configuration table can be obtained by the server according to the permission configuration of the user to the application or the same type of application.

[0120] The permission configuration describes whether the user grants the permission when authorizing the application or the same type of application. Specifically, for a permission, when the proportion of the user agreeing to authorize is greater than a first threshold, the server can determine that the permission is recommended for the user to grant to the application, and on the contrary, when the proportion of the user refusing to authorize is greater than the first threshold, the server can determine that the permission is not recommended for the user to grant to the application.

[0121] Wherein, the user can be the user using the application on the electronic device 100, at this time, the permission configuration table can embody the user's habit in configuring permissions. The user can be a plurality of users using the application, at this time, the permission configuration table can embody the habits of most users in configuring permissions.

[0122] 2) The permission configuration table can be obtained by the server testing the installation package of the application.

[0123] Specifically, the server can obtain the installation package of the application from the application market, and by installing the application, run the application in the server to determine the permissions requested by the application when starting and during running, and in combination with analyzing the privacy leakage risk of the application when configuring different authorization modes for the application, to determine which permissions are recommended to be granted to the application by the user, and which permissions are not recommended to be granted to the application by the user.

[0124] Wherein, when testing the application, the server obtains the permission window displayed by the application when starting for the first time, for example, when the application displays three permission windows in succession, the three permission windows request the user to grant the use permissions of storage, location information and device information, respectively, the server can instruct the electronic device 100 to display the three permissions in a centralized permission window.

[0125] The following shows the code involved when the electronic device 100 displays the three permissions in a centralized permission window:

[0126] <package packageName=”ctrip.android.view”>

[0127] <permissioncfg> 0< / permissioncfg>

[0128] <permissioncode> 280< / permissioncode>

[0129]

[0130] 3) The permission configuration table can be a configuration table determined according to the permission configuration rule.

[0131] For example, the permission configuration rule can be the relevant specification formulated by the Ministry of Industry and Information Technology for application authorization, or the permission configuration rule can be the principle of minimization of personal data in the General Data Protection Regulation (GDPR).

[0132] It can be understood that the permission configuration table can be generated in combination with one or more of the above-mentioned manners, wherein the permission configuration table at least needs to meet the permission configuration rule in manner 3. The generation manner of the permission configuration table is not limited to the above-mentioned three manners, and the embodiments of the present application do not limit this.

[0133] The permission configuration table will be described below with a specific example. Table 1 exemplarily shows a permission configuration table for an application.

[0134] Table 1

[0135] Permissions Recommended way First recommended Storage Always allow Y Device information Prohibit Y Location information Allow while using the app (vague location) Y Camera Allow while using the app N Microphone Allow while using the app N Address book Prohibit N Calendar Prohibit N

[0136] As can be seen from Table 1, the permission configuration table can include permissions, recommended manners, and first-time recommendations, the permissions include permissions requested by the application, the recommended manners include authorization manners of granting different time permissions to the application, such as always allowing, allowing when using the application, and prohibiting, and the first-time recommendation is used to determine whether to request the permissions from the user when the application is started for the first time, wherein “Y” indicates first-time recommendation, and “N” indicates non-first-time recommendation, and the non-first-time recommended permissions refer to permissions required by the application when the function of the application is triggered during the running of the application.

[0137] According to Table 1, it can be determined that when the application is started for the first time, the electronic device 100 can display authorization windows about “storage”, “device information”, and “location information”, and the “storage” is recommended by the electronic device 100 to be granted to the application by the user, and the “device information” and “location information” are not recommended by the electronic device 100 to be granted to the application by the user. At this time, the permission window displayed by the electronic device 100 can be a centralized permission window 315 as shown in Figure 6A

[0138] It can be understood that the content of the permission configuration table is not limited to the above-mentioned three items of permissions, recommended manners, and first-time recommendations, and in other embodiments of the present application, the permission configuration table can also include more or less content. The embodiments of the present application do not limit the content of the permission configuration table.

[0139] In some embodiments, the permission configuration table can also include a user ratio, which is used to indicate the proportion of granting or refusing to grant the permissions by multiple users when configuring the permissions, so that the proportion of the permission can be displayed in the permission window displayed by the electronic device 100 as reference data for the user to configure the permissions, helping the user to complete the configuration of the permissions more quickly.

[0140] ​In some other embodiments, the permission configuration table can further comprise a permission classification of the permissions, the permission classification comprising: a minimum necessary and a reasonable additional, the minimum necessary being the least permissions determined to ensure the running of the application, and the reasonable additional being the permissions required by the functions of the application except the minimum necessary. The minimum necessary can appear in the permission window displayed when the application is started for the first time, and the minimum necessary is the permission recommended to be granted to the application by the user. The reasonable additional can be the permission requested in the permission window when the application starts a function and the function requires the permission, and the permission can be the permission recommended to be granted to the application by the user or the permission not recommended to be granted to the application by the user. For example, in combination with the permissions in Table 1, it can be seen that the storage and location information can be the minimum necessary, and the other permissions can be the reasonable additional.

[0141] The timing at which the electronic device 100 obtains the permission configuration table can include the following cases:

[0142] 1) The electronic device 100 obtains the permission configuration table periodically

[0143] For example, the electronic device 100 can obtain the permission configuration table every 7 days. In this way, the electronic device 100 can periodically update the permission configuration table.

[0144] 2) The electronic device 100 obtains the permission configuration table when installing the application

[0145] That is, the electronic device 100 can obtain the permission configuration table when receiving the operation of the user installing the application, so that the electronic device 100 can determine the permissions recommended and not recommended by the electronic device 100 in the application according to the permission configuration table after the user installs the application.

[0146] In addition, the installation of the application by the electronic device 100 can mean that the electronic device 100 installs the application for the first time, or can also mean that the electronic device 100 updates the application.

[0147] 3) The electronic device 100 obtains the permission configuration table in response to the user operation

[0148] That is, the electronic device 100 can obtain the permission configuration table when receiving the user operation of the user obtaining the permission configuration table.

[0149] It can be understood that the timing at which the electronic device 100 obtains the permission configuration table can also include other cases, which are not limited by the embodiments of the present application.

[0150] Further, the permission configuration table can be used to determine the permission recommendation of the plurality of applications. In this case, the permission configuration table can include the permissions requested by the plurality of applications. In this way, the electronic device 100 can determine the permission recommendation of the plurality of applications after receiving the permission configuration table, thereby reducing the frequency of obtaining the permission configuration table by the electronic device 100.

[0151] S102, the electronic device 100 starts the application without running the application.

[0152] The starting of the application by the electronic device 100 refers to the first starting of the application by the electronic device 100, and before the starting of the application, the application is not in the foreground running state or the background running state.

[0153] The starting of the application can be in the following cases:

[0154] 1) The electronic device 100 starts the application for the first time after the installation of the application is completed

[0155] 2) The electronic device 100 starts the application for the first time when the application does not occupy data in the storage space of the electronic device 100

[0156] It can be understood that the starting of the application is not limited to the above two ways, and the starting of the application can also refer to the first starting after the starting of the electronic device 100, and the embodiments of the present application do not limit this.

[0157] The starting mode of the application can include but is not limited to the following three:

[0158] 1) User start, the application can be triggered to start in response to user operation.

[0159] 2) Association start, the application can be triggered to start in the process of running other applications.

[0160] 3) Self-start, the application can automatically trigger the starting when a preset condition (for example, a specific time) is reached.

[0161] Referring to Figure 4A , the electronic device 100 can trigger the starting of the browser application after receiving the user operation acting on the browser icon 215.

[0162] S103, in response to the starting of the application, the electronic device 100 displays the centralized permission window.

[0163] The centralized permission window indicates the permissions requested by the application, and the centralized permission window includes a first permission item and a second permission item, the first permission item indicates the permissions recommended by the electronic device 100 for the user to grant to the application, the second permission item indicates the permissions not recommended by the electronic device 100 for the user to grant to the application, and the first permission item is the minimum permission allowed for the use of the application.

[0164] The least permission describes the least permission that the application is allowed to use, or further describes the least time that the application is allowed to use the permission. The time that the application uses the permission can be represented by an authorization mode of the permission, and the authorization mode can include: always allowed, allowed during use, forbidden, and the like, wherein always allowed indicates that the time that the application uses the permission is the least, allowed during use indicates the second, and forbidden indicates that the time that the application uses the permission is zero. That is, in addition to the permissions that the electronic device 100 recommends to grant and the permissions that the electronic device 100 does not recommend to grant, the centralized permission window can also display the authorization mode recommended by the electronic device 100. In this way, a more detailed authorization reference can be provided for the user, and the user can be helped to make a more reasonable authorization.

[0165] The electronic device 100 can represent whether the permission is recommended by one or more of the following ways:

[0166] 1) Configure different selection states for the permission items

[0167] Since the permission item can receive the operation of the user and change the selection state of the permission item, the selection state can include a selected state and an unselected state, and the electronic device can configure a default selection state for each permission item when displaying the centralized authorization window. In this way, when the electronic device 100 displays the centralized permission window, the user can directly click to confirm to authorize the application according to the selection state of the different permissions in the centralized permission window.

[0168] Among them, the permission item recommended by the electronic device can be in the selected state, and the permission item not recommended can be in the unselected state. Specifically, the electronic device can represent the selection state of the permission item by display modes such as switches, font colors, font sizes, font thicknesses, and the like. In this way, the user can determine whether the electronic device recommends the permission item by the different display modes of the permission item, and the user does not need to configure the permission again, but can directly click to confirm on the permission configured by default by the electronic device to complete the configuration of the application permission, thereby reducing the operation of the user.

[0169] Referring to Figure 4B , the centralized permission window can refer to Figure 4BAs can be seen from the centralized permission window 311 shown in FIG. 11, it can be seen from the first switch 3111A in the open state in the first permission item 311A that the permission (i.e., storage) indicated by the first permission item 311A is the permission that the electronic device 100 recommends the user to grant to the application, it can be seen from the second switch 3111B in the closed state in the second permission item 311B, and it can be seen from the third switch 3111C in the closed state in the third permission item 311C that the permission (i.e., device information) indicated by the second permission item 311B and the permission (i.e., location information) indicated by the third permission item 311C are the permissions that the electronic device 100 does not recommend the user to grant to the application.

[0170] 2) Adding additional prompt information in one type of permission item

[0171] For example, the electronic device can add "recommended", "priority" and the like to the back of the recommended permission item. In this way, the electronic device can know that the permission indicated by the permission item is the permission that the electronic device recommends the user to grant to the application according to the prompt text in the permission item.

[0172] 3) Displaying statistical data on the permission item

[0173] The electronic device can determine whether the permission item is a recommended or non-recommended permission item by the amount of statistical data or comparison with other statistical data. For example, there is a permission item corresponding to the permission of location information, and the location information can display, for example, 80% of other users granting the permission to the application. Through the score, the user can know that 80% of people have chosen to agree to grant on the permission, thereby indirectly knowing that the permission item is a permission item that the electronic device recommends to grant.

[0174] It can be understood that the electronic device can also express whether the permission is recommended in other ways, such as changing the arrangement order of the permissions, and the permission items recommended by the electronic device are arranged above the permission items not recommended by the electronic device. The embodiments of the present application do not limit the expression manner of whether the electronic device 100 recommends the permission.

[0175] S104, the electronic device 100 completes the authorization of the application according to the centralized permission window.

[0176] Among them, the trigger manner of the electronic device 100 completing the authorization of the application can include the following two kinds:

[0177] 1) The electronic device completes the authorization of the application according to the operation of the user acting on the centralized permission window.

[0178] Among them, the operation can have the following three meanings:

[0179] a) The operation can be a confirmation operation of the user on the centralized permission window

[0180] The confirmation operation can be an operation of acting on Figure 4B determining the selected option 311E.

[0181] That is, in the centralized permission window, the permissions recommended by the electronic device 100 are in the checked state, and the permissions not recommended by the electronic device 100 are in the unchecked state. After the electronic device 100 receives the confirmation operation, the application is authorized according to the permissions configured by default by the electronic device 100, that is, the application is granted the permissions recommended by the electronic device 100 (for example, the permissions indicated by the first permission item 311A). In this way, when the electronic device 100 displays the centralized permission window, the user can directly authorize the application according to the permissions configured by the electronic device 100, reducing the user's operation and speeding up the user's entry into the application.

[0182] b) The operation can include a modification operation of the centralized permission window by the user, and the confirmation operation

[0183] The modification operation refers to an operation of modifying the permission configuration in the centralized permission window.

[0184] That is, in the centralized permission window, the permissions recommended by the electronic device 100 are in the checked state, and the permissions not recommended by the electronic device 100 are in the unchecked state. However, the centralized permission window can still accept user operations to modify the default configuration of the electronic device 100, and after the modification is completed, the user's confirmation operation is received, and the application is authorized according to the modified permission configuration. In this way, the operability of the user can be enhanced.

[0185] c) The operation can include a configuration operation of the centralized permission window by the user, and the confirmation operation

[0186] The configuration operation refers to an operation of configuring the permissions in the centralized permission window.

[0187] That is, in the centralized permission window, neither the permissions recommended by the electronic device 100 nor the permissions not recommended by the electronic device 100 are in the unchecked state, and the user needs to configure the permissions independently. The electronic device 100 can mark the permissions recommended by the electronic device 100 and the permissions not recommended by the electronic device 100 through the indication information in the permission item. The electronic device 100 also needs to receive the user's confirmation operation after the user completes the configuration, and then authorize the application according to the user's configured permissions. In this way, the user can refer to the permissions recommended by the electronic device 100 and the permissions not recommended by the electronic device 100 to configure the permissions in the centralized permission window.

[0188] 2) The electronic device 100 automatically completes the authorization of the application after the timing ends

[0189] In other words, when displaying the centralized permissions window, the electronic device 100 can display a countdown prompt in the window, which prompts the user to complete the authorization of the application within the countdown timer. If, during the display of the centralized permissions window, no user action is detected on the window, the application is automatically authorized, and the application is granted the permissions indicated by the first permission item.

[0190] In this way, by displaying countdown prompts, users can complete the application authorization process more quickly, avoiding wasting too much time when hesitating about configuring permissions for applications.

[0191] In some embodiments, when the centralized permissions window indicates that the permissions requested by the application include location information, the centralized permissions window may include a location mode option, which is used to trigger the application to obtain the precise geographical location of the electronic device.

[0192] It's important to note that the location mode option can only receive user input and determine whether the application needs to access the precise or approximate geographic location of the electronic device 100 when the location information is a permission recommended by the electronic device 100. In this case, the location information is a permission indicated by the first permission item. Additionally, the first permission item includes an indication message indicating whether the electronic device 100 recommends the application access to its precise geographic location. This allows users to refer to the permission recommendations of the electronic device 100 to decide whether to grant the application precise or approximate location information, minimizing the leakage of user location information and ensuring user privacy.

[0193] S105. During application operation, electronic device 100 detects the operation of activating the first function of the application.

[0194] After authorizing the application through the centralized permissions window, the electronic device 100 can run the application normally.

[0195] The first function refers to the functions that the application possesses, such as the photo-taking function of a photo-taking application, the navigation function of a navigation application, and so on.

[0196] See Figure 5A This operation can refer to Figure 5A The operation applied to the voice control 312A can refer to the browser's voice detection function.

[0197] S106. Electronic device 100 displays a function permission window, which shows a third permission item.

[0198] When the first function needs permission to be enabled, the electronic device 100 can display a function permission window, requesting the user to grant the first function required permission. The third permission item can contain indication information indicating whether the electronic device 100 recommends the user to grant the application the first function required permission. The first function required permission is not the permission indicated by the first permission item, but can be the permission indicated by the second permission item or other permission.

[0199] Referring to Figure 5B , the function permission window can be the permission window 314 in Figure 5B , and the permission indicated by the third permission item is the permission indicated in the permission window 314. The indication information can be the background highlight prompt information of the target option 314A.

[0200] Here, the manifestation of whether the electronic device 100 recommends the permission can refer to the related content of S103, which will not be repeated here.

[0201] S107, the electronic device 100 completes the authorization of the application according to the function permission window.

[0202] The electronic device 100 completes the authorization of the application according to the function permission window can mean that the electronic device 100 grants the application the first function required permission, or refuses to grant the application the first function required permission.

[0203] Here, the triggering manner of the electronic device 100 completing the authorization of the application can include two kinds:

[0204] 1) The electronic device 100 detects the operation on the function authorization window to complete the authorization of the application

[0205] 2) The electronic device 100 completes the authorization of the application after the countdown ends

[0206] Specifically, the manner of the electronic device 100 completing the authorization of the application can refer to the related content in S104, which will not be repeated here.

[0207] In some embodiments, when the first function required permission is location information, the function permission window can further contain a precise location option (for example, the precise location option 316A shown in Figure 6A ) and a blurred location option (for example, the blurred location option 316B shown in Figure 6B ), the precise location option can be used to provide the electronic device 100 precise geographic location for the application, and the blurred location option can be used to provide the electronic device 100 blurred geographic location for the application. The position accuracy of the blurred geographic location can be lower than that of the precise geographic location, and / or the blurred geographic location has a deviation from the precise geographic location.

[0208] It is important to note that the precise location option and the vague location option can only receive user input to select a precise or vague geographic location for the application when the electronic device 100 recommends that the user grant location information to the application. Furthermore, this third permission item also includes second instruction information (e.g., Figure 6A The highlighted background of target option 316D shown indicates that the second indication information is used to indicate whether the location option recommended by the electronic device 100 is a precise location option or a vague location option. In this way, when a user grants an application permission to access location information, it can further determine whether the application accesses precise or vague location information, minimizing the leakage of the user's true and precise location information.

[0209] In some embodiments, the electronic device 100 can also combine user profiles to determine which permissions to recommend and which permissions to discourage users from granting to applications. A user profile refers to a tag extracted from user information that represents a real user. For example, if the user profile indicates that the user is a photography enthusiast, then when displaying the permissions window, even if the permissions configuration table indicates that the electronic device 100 should not recommend the user grant the application permission to access the photo album, the electronic device 100 can still instruct the user in the permissions window to grant the application permission to access the photo album. This provides users with more personalized permission management, helping them to more appropriately authorize applications.

[0210] In summary, using the permission management method provided in this application, different applications can display permission windows containing different permissions, and the permissions recommended or not recommended by the electronic device 100 may not be the same. This is because different applications have different functions, and the minimum permissions they are required to have are also different. For the same application, the permission window displayed at different times may also contain different permissions, and the permissions recommended or not recommended by the electronic device 100 may not be the same. This is because the same application may contain different functions after an update, or, when analyzing the authorization of multiple users for the application, the ratio of authorization and denial by multiple users may change. In this case, the permission window displayed for the same application at different times may also be different. For the same application, different users may display different recommended or not recommended permissions in the permission window. This is because the electronic device 100 can combine user profiles to more reasonably customize personalized permission management schemes for different users, improving the user experience.

[0211] The various embodiments of this application can be combined arbitrarily to achieve different technical effects.

[0212] In the above embodiments, all or part of the methods can be implemented by software, hardware, firmware, or any combination thereof. When implemented by software, all or part of the methods can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the present application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions can be transferred from one website, computer, server or data center to another website, computer, server or data center through wired (such as coaxial cable, optical fiber, digital subscriber line) or wireless (such as infrared, wireless, microwave, etc.) manner. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. that includes one or more available media sets. The available media can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid state disk (SSD)), etc.

[0213] Those of ordinary skill in the art can understand that all or part of the processes in the above embodiments can be implemented by a computer program to instruct the relevant hardware, and the program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the above method embodiments. The storage medium includes ROM or random access memory (RAM), magnetic disk or optical disk, and various media that can store program codes.

[0214] In summary, the above only describes the embodiments of the present application, and is not intended to limit the protection scope of the present application. Any modification, equivalent replacement, improvement, etc. made according to the disclosure of the present application shall be included in the protection scope of the present application.

Claims

1. A rights management method, characterized by, The method is applied to an Android system, and the method comprises: After installing or updating a first application, in response to a first operation of a user first opening the first application, an electronic device displays a first user interface of the first application and a first window, the first window is displayed on the first user interface, the first window simultaneously displays a first permission item of the first application, a second permission item of the first application, a first authorization mode of the first permission item, a second authorization mode of the second permission item, and a first option, and does not display a third permission item, the second authorization mode is different from the first authorization mode, the first permission item and the second permission item are configured as permissions requested from a user when an application is first opened, the first permission item is any one of a storage permission, a device information permission, a location information permission, a permission camera, a microphone permission, an address book permission, or a calendar permission, the second permission item is any one of the storage permission, the device information permission, the location information permission, the permission camera, the microphone permission, the address book permission, or the calendar permission, and the first authorization mode is any one of always allow, allow when using the application, or prohibit; and the second authorization mode is any one of always allow, allow when using the application, or prohibit; In response to a second operation of the user on the first option, the first permission item is authorized in the first authorization mode, and the second permission item is authorized in the second authorization mode, the first authorization mode is configured as a recommendation by the electronic device, and the second authorization mode is configured as a recommendation by the electronic device; After displaying the first user interface, a second user interface of the first application is displayed, the second user interface comprises a first control, and the first control corresponds to a first function; In response to a third operation of the user on the first control, a second window is displayed, the third permission item is displayed in the second window, the first function is started after the third permission item is authorized, the third permission item is a permission requested when the first function is triggered after the first application is opened, the third permission item is not a permission configured as a permission requested from a user when an application is first opened, and the third permission item is any one of the storage permission, the device information permission, the location information permission, the permission camera, the microphone permission, the address book permission, or the calendar permission; In response to a fourth operation of the user on the second window, the third permission item is authorized in a third authorization mode, and the third authorization mode is any one of always allow, allow when using the application, or prohibit.

2. The method of claim 1, wherein, After receiving a fifth operation of the user modifying the first authorization mode to a fourth authorization mode in the first window, in response to a sixth operation of the user on the first control, the first permission item is authorized in the fourth authorization mode.

3. The method of claim 1, wherein, The second window simultaneously displays the third authorization mode and a fifth authorization mode, the third authorization mode is configured as a recommendation by the electronic device, and the fifth authorization mode is displayed in a display mode different from that of the third authorization mode.

4. An electronic device comprising: The electronic device includes a display screen, a memory, one or more processors, a plurality of application programs, and one or more programs; wherein the one or more programs are stored in the memory; and wherein the one or more processors, when executing the one or more programs, cause the electronic device to implement the method according to any one of claims 1 to 3. 5.A computer-readable storage medium including instructions, wherein the instructions, when executed on an electronic device, cause the electronic device to perform the method according to any one of claims 1 to 3.

Citation Information

Patent Citations

  • Permission setting method and terminal equipment

    CN111125680A

  • Application permission management method and electronic device

    CN112352239A