Data sharing method and related device

By implementing system-level file encryption and sharing controls, as well as access control, the problem of poor security in user data sharing has been solved, enabling flexible permission settings and improved user experience.

CN119442305BActive Publication Date: 2026-02-06HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411433826.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-19
Publication Date
2026-02-06
Estimated Expiration
2044-06-19

AI Technical Summary

Technical Problem

In existing technologies, when users share data through verbal instructions, security is poor. User 2 can freely forward, print, copy, or take screenshots, resulting in a poor user experience.

Method used

It provides system-level file encryption control and sharing functions. Electronic devices can set permissions and share files in different ways. The receiving device dynamically adjusts application access permissions according to the permission control policy set in the file to prevent secondary forwarding, copying, screenshotting and other operations.

Benefits of technology

It improves the security and eco-friendliness of data sharing, enhances the user experience, supports multiple permission settings and flexible sharing methods, and adapts to different scenario needs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119442305B_ABST
    Figure CN119442305B_ABST
Patent Text Reader

Abstract

The application discloses a data sharing method. For a sender, a sender device can provide a system-level file encryption management and control sharing function, and does not depend on the sender device having to install an application. The sender can select a file to be shared from the system through the sender device, set a permission control policy, and send the file to a receiver device through one or more different sending modes. For a receiver, a receiver device can provide a data management function. The receiver can receive and open the shared file through the receiver device. The system can dynamically adjust the permission of an application to access different functions of the system based on the permission control policy set in the file. For example, the receiver cannot copy, screen capture, print, or perform other operations on the file. Even if an attacker attacks the application that opens the file, the attacker cannot perform the above operations on the file. In this way, the scene support, security, and ecological friendliness are improved, and the user experience is better.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of terminals, and in particular to a data sharing method and related equipment. BACKGROUND

[0002] With the rapid development of terminal technology, a user 1 can share data such as documents and pictures to a terminal device of a user 2 through a terminal device such as a smart phone or a tablet computer. Some data may not be intended to be leaked by the user 2, and the user 1 usually orally instructs the user 2 not to forward the data. However, the oral instruction has limited effect, and the user 2 can still randomly forward, print, copy, and screen capture the data, which is poor in security and user experience. SUMMARY

[0003] Embodiments of the present application provide a data sharing method, which can provide system-level file encryption management and control sharing function and data management and control function, and has improved scene support, security, and ecological friendliness, and better user experience.

[0004] In a first aspect, embodiments of the present application provide a data sharing method applied to a first electronic device, which includes: determining, by the first electronic device, that a first file is selected; in response to an operation of sharing the first file on a first interface, sending, by the first electronic device, the first file to a second electronic device associated with a first user; and setting, by the first electronic device, a first permission for the first file, the first permission being effective for a plurality of applications on the first electronic device when the first file is sent, and the first permission being used to indicate one or more operations authorized to be performed on the first file by the first user.

[0005] The first electronic device may, for example, be an electronic device 100 (a sender device), the second electronic device may, for example, be an electronic device 200 (a receiver device), the first file may be a file to be shared, and may include but is not limited to pictures, documents, and audio and video, the first interface may, for example, be an interface as shown in FIG. 1, and the first user may be a receiver, and may be an individual or a group. FIG. 3B Or FIG. 3C Or FIG. 10C The first user may be a receiver, and may be an individual or a group.

[0006] By implementing the method of the first aspect, the electronic device can support the user to use the system function to configure to whom the file is sent and what permissions (for example, read-only permission and editable permission) the file receiver has, and the upper application does not need to be aware, which improves the ecological friendliness and better user experience.

[0007] In a possible implementation, the method further includes: before the first electronic device sends the first file to the second electronic device associated with the first user, the first electronic device displays at least one of a device list, an application list, and a user list on an interface, the interface being the first interface or the second interface; and the first electronic device sends the first file to the second electronic device associated with the first user, specifically including: in response to an operation of selecting the second electronic device in the device list, the first electronic device sends the first file to the second electronic device associated with the first user; or, in response to an operation of selecting the first application in the application list, the first electronic device sends the first file to the second electronic device associated with the first user through the first application; or, in response to an operation of selecting the first user in the user list, the first electronic device sends the first file to the second electronic device associated with the first user.

[0008] The second interface may, for example, be FIG. 5F The interface shown in FIG. 1, the device list may include options of one or more devices (for example, the options of FIG. 5F Yun’s Mate 50 shown in FIG. 2), the application list may include options of one or more applications (for example, the options of FIG. 5F Huawei Share, Freely, Chat shown in FIG. 3), and the user list may include options of one or more users (for example, the options of FIG. 5F Alice, Alee shown in FIG. 4).

[0009] The first electronic device sending the first file to the second electronic device associated with the first user through the first application may include two ways: the first way is that the first application first determines the first user, then determines the device associated with the first user based on the first user, and finally sends the first file to the device; and the second way is that the first application directly determines the receiving device and sends the first file to the device.

[0010] In this way, the electronic device can support the user to share files in different ways, which is flexible and improves the user experience.

[0011] In a possible implementation, the first electronic device sends the first file to the second electronic device associated with the first user, specifically including: in response to an operation of sharing the first file triggered by the interface, the first electronic device sends the first file to the second electronic device associated with the first user, the interface being an interface for a session with the first user.

[0012] The interface may, for example, be FIG. 10A or FIG. 10C the interface shown in FIG. 5.

[0013] In this way, the electronic device can support the user to share the file set with the system permission within the application (for example, a communication application), so as to solve the problem that the permission setting must be implemented by the application if the permission setting is initiated within the application, and if other applications want to control the file, the problem of repeated implementation needs to be solved.

[0014] In a possible implementation, the first file is set with the first permission before the operation of sharing the first file; or, the first file is set with the first permission after the operation of sharing the first file, and is sent to the second electronic device associated with the first user.

[0015] That is, the electronic device can support the user to set the permission for the file first, and then perform the sharing operation, and can also support the user to perform the sharing operation first, which can trigger the electronic device to set the permission for the file and send the file.

[0016] In a possible implementation, the method further includes: in response to the operation of sharing the first file on the first interface, the first electronic device sends the first file to a third electronic device associated with a second user; wherein the first electronic device is configured to set a second permission for the first file, the second permission is effective for multiple applications on the first electronic device when the first file is sent, and the second permission is used to indicate one or more operations authorized to be performed on the first file by the second user.

[0017] The second permission can be the same as or different from the first permission.

[0018] In this way, for the same file, the electronic device can set corresponding permissions for multiple users respectively.

[0019] In a possible implementation, the method further includes: the first electronic device determines that the second file is selected; in response to the operation of sharing the second file on the first interface, the first electronic device sends the second file to the second electronic device associated with the first user; wherein the first electronic device is configured to set a third permission for the second file, the third permission is effective for multiple applications on the first electronic device when the second file is sent, and the third permission is used to indicate one or more operations authorized to be performed on the second file by the first user.

[0020] The third permission can be the same as or different from the first permission.

[0021] In this way, for different files, the electronic device can set corresponding permissions for the same user respectively.

[0022] In a possible implementation, the first user belongs to a first group, and the first group further includes a third user. The method further includes: in response to the operation of sharing the first file on the first interface, the first electronic device sends the first file to a fourth electronic device associated with the third user, and the first permission is further used to indicate that the third user is authorized to perform one or more operations on the first file; or, in response to the operation of sharing the first file on the first interface, the first electronic device sends the first file to the fourth electronic device associated with the third user; and the first electronic device is further configured to set a fourth permission for the first file, the fourth permission is effective for all the applications on the first electronic device when the first file is sent, and the fourth permission is used to indicate that the third user is authorized to perform one or more operations on the first file.

[0023] In this way, when the receiver belongs to a certain group, the electronic device can set permissions for group members in the group uniformly, or set permissions for group members in the group respectively.

[0024] In a possible implementation, before the first electronic device sends the first file to the second electronic device associated with the first user, the method further includes: the first electronic device logs in a first account, and the first account belongs to an account of a fourth user.

[0025] The fourth user is the sender, so that after logging in the account, the receiver can know who the sender of the first file is.

[0026] In a possible implementation, before the first electronic device sends the first file to the second electronic device associated with the first user, the method further includes: the first electronic device obtains a credential corresponding to the first user; and the first electronic device encrypts the first file based on the credential.

[0027] In this way, the electronic device can encrypt the file before sending the file, thereby improving security.

[0028] In a possible implementation, the credential is obtained by the first electronic device on a server, or the credential is obtained by the first electronic device locally, or the credential is obtained by the first electronic device on the second electronic device.

[0029] In a possible implementation, the first electronic device is configured to set the first permission for the first file, and specifically includes: the first electronic device is configured to write field information of the first permission in the first file; or the first electronic device is configured to send a first message to a server, the first message including the field information of the first permission and identification information of the first file, and the first message being used to indicate that the server saves an association relationship between the field information of the first permission and the identification information of the first file.

[0030] In a possible implementation, the first permission comprises a read-only permission, or an editable permission, or a forwarding permission, and the editable permission comprises one or more of an edit permission, a save-as permission, a screenshot permission, a screen recording permission, a print permission, and a copy permission.

[0031] In the embodiments of the present application, the forwarding permission can or can not belong to the definition range of the first permission (i.e., the forwarding permission can be parallel to the first permission).

[0032] In a possible implementation, the first file comprises sensitive information.

[0033] In a possible implementation, the credential corresponding to the first user is associated with an identity corresponding to the first user, and the identity corresponding to the first user is manually input by the user, or is selected by the user from a contact list of the first electronic device, or is obtained by the first electronic device from the second electronic device.

[0034] In a possible implementation, the first electronic device sets the first permission for the first file, specifically comprising: the first electronic device displays first prompt information, the first prompt information being used to prompt the user whether to agree to set the first permission for the first file; and in a case where it is confirmed that the user agrees to set the first permission for the first file, the first electronic device sets the first permission for the first file.

[0035] The first prompt information can be, for example, the prompt information shown in FIG. 1. FIG. 7B

[0036] In a second aspect, the embodiments of the present application provide a data sharing method, applied to a second electronic device, comprising: receiving, by the second electronic device, a first file sent by a first electronic device, the first file being controlled by a first permission, the first permission being effective when a plurality of applications on the second electronic device perform an operation within a range of the first permission control on the first file, and the plurality of applications comprising a first application; obtaining, by the second electronic device, a first operation on the first file in the first application; and in response to the first operation, if the second electronic device determines that the first operation is one or more operations authorized for the first file by a first user indicated by the first permission, the second electronic device responds to the first operation.

[0037] The first application can be a system application or a third-party application.

[0038] ​By implementing the method provided in the second aspect, the electronic device can provide a data management function, the receiver can receive and open the shared file through the electronic device, and the system can dynamically adjust the permission of the application to access different functions of the system based on the permission control policy set in the file. For example, the receiver cannot perform secondary forwarding, copying, screen capturing, printing, and other operations on the file, and even if the attacker attacks the application that opens the file, the attacker cannot perform the above operations on the file. In this way, the scene support, security, ecological friendliness, and other aspects are improved, and the user experience is better.

[0039] In a possible implementation, before the second electronic device determines that the first operation is one or more operations that the first user with the first permission indication is authorized to perform on the first file, the method further includes: determining, by the second electronic device, that the user performing the first operation is the first user who is authenticated to have the operation permission on the first file.

[0040] That is, when the user associated with the account logged in by the receiver device is the receiver of the first file specified by the sender, the receiver device can further determine whether the first operation is one or more operations that the first user with the first permission indication is authorized to perform on the first file.

[0041] In a possible implementation, the second electronic device determines that the user performing the first operation is the first user who is authenticated to have the operation permission on the first file, and specifically includes: determining, by the second electronic device, that the account logged in by the second electronic device is the account of the first user; or, determining, by the second electronic device, that the biometric feature of the user performing the first operation matches the biometric feature of the first user; or, receiving, by the second electronic device, a first message sent by a third electronic device, the first message being used to indicate that the user performing the first operation is the first user who is authenticated to have the operation permission on the first file, and the third electronic device is associated with the second electronic device.

[0042] In this way, the electronic device can authenticate the receiver in different ways, which is convenient and flexible and improves the user experience.

[0043] In a possible implementation, the method further includes: in a case where the second electronic device determines that the first operation does not belong to one or more operations that the first user with the first permission indication is authorized to perform on the first file, displaying, by the second electronic device, first prompt information, the first prompt information being used to prompt the user that the second electronic device refuses to respond to the first operation.

[0044] The first prompt information may, for example, be a prompt information as shown in FIG. 11G or FIG. 11H or FIG. 11I .

[0045] In a possible implementation, the method further includes: in response to the operation of sharing the first file, the second electronic device sends the first file to a third electronic device associated with the first user.

[0046] In this way, the electronic device can support the user to forward the first file to other electronic devices associated with the user.

[0047] In a possible implementation, the method further includes: in response to the operation of sharing the first file, the second electronic device sends the first file to a fourth electronic device associated with the second user.

[0048] In this way, the electronic device can support the user to forward the first file to electronic devices associated with other users.

[0049] In a possible implementation, when the first file is forwarded by the second electronic device, the first file is set to a third permission, and an authorization range of the third permission is not more than an authorization range of the first permission.

[0050] That is, in the case of twice forwarding the file, the authorization range of the permission set for the file can be smaller than the authorization range of the permission in the first forwarding, for example, read-only permission can be set in the second forwarding. In this way, the security can be improved.

[0051] In a possible implementation, the method further includes: the second electronic device sends a second message to the first electronic device, the second message being used to instruct the first electronic device to authorize a second operation performed by the first user on the first file, the second operation not belonging to one or more operations performed by the first user on the first file and authorized by the first permission.

[0052] In this way, the receiving device can notify the sending device to re-authorize in the case of performing an operation on the file that is not authorized to be performed.

[0053] In a possible implementation, the method further includes: the second electronic device sends a third message to the first electronic device, the third message being used to instruct the first electronic device to authorize a forwarding operation performed by the first user on the first file.

[0054] In this way, the receiving device can notify the sending device to authorize the receiving device to perform the forwarding operation on the file when the forwarding operation is performed on the first file.

[0055] In a possible implementation, the first file is an encrypted file, and before the second electronic device responds to the first operation, the method further includes: the second electronic device obtains a credential corresponding to the first user; and the second electronic device decrypts the first file based on the credential.

[0056] In a possible implementation, the second electronic device displays a first identifier, and the first identifier is used to indicate that the first file is an encrypted file.

[0057] The first identifier may be, for example, an icon of the encrypted file. FIG. 11A The icon of the encrypted file may be, for example, an icon of the encrypted file as shown in the document 1 (i.e., all the icons of the encrypted files are the same encrypted icon). FIG. 11B The icon of the encrypted file may be, for example, an icon of the encrypted file as shown in the document 1 (i.e., the encrypted icon is superimposed on the exclusive icon).

[0058] In a possible implementation, the first permission is obtained by the second electronic device in the first file, or the first permission is obtained by the second electronic device from the server.

[0059] In a possible implementation, the first permission includes a read-only permission, or an editable permission, or a forwarding permission, and the editable permission includes one or more of a save permission, a screenshot permission, a screen recording permission, a print permission, and a copy permission.

[0060] In a third aspect, an electronic device is provided, which includes one or more processors and one or more memories; the one or more memories are coupled to the one or more processors, and are configured to store computer program codes, the computer program codes include computer instructions, when the one or more processors execute the computer instructions, the electronic device performs the method in any possible implementation of the first aspect or the second aspect.

[0061] In a fourth aspect, a computer storage medium is provided, which stores a computer program, the computer program includes program instructions, when the program instructions are executed on an electronic device, the electronic device performs the method in any possible implementation of the first aspect or the second aspect.

[0062] In a fifth aspect, a computer program product is provided, when the computer program product is executed on a computer, the computer performs the method in any possible implementation of the first aspect or the second aspect. BRIEF DESCRIPTION OF DRAWINGS

[0063] FIG. 1 is a software structure diagram provided by an embodiment of the present application;

[0064] FIG. 2A is an architecture diagram of a communication system provided by an embodiment of the present application;

[0065] FIG. 2B is a software structure diagram of an electronic device 100 provided by an embodiment of the present application;

[0066] FIG. 2C is a software structure schematic diagram of an electronic device 200 provided by an embodiment of the present application;

[0067] FIG. 3A-FIG. 3C is a group of user interface schematic diagrams involved in a scenario of initiating data sharing by a system provided by an embodiment of the present application;

[0068] FIG. 4A-FIG. 4C is another group of user interface schematic diagrams involved in a scenario of initiating data sharing by a system provided by an embodiment of the present application;

[0069] FIG. 5A-FIG. 5F is another group of user interface schematic diagrams involved in a scenario of initiating data sharing by a system provided by an embodiment of the present application;

[0070] FIG. 6A-FIG. 6C is a group of schematic diagrams of an electronic device 100 acquiring credentials of a receiving party provided by an embodiment of the present application;

[0071] FIG. 7A-FIG. 7B is another group of user interface schematic diagrams involved in a scenario of initiating data sharing by a system provided by an embodiment of the present application;

[0072] FIG. 8A-FIG. 8J is another group of user interface schematic diagrams involved in a scenario of initiating data sharing by a system provided by an embodiment of the present application;

[0073] FIG. 9A-FIG. 9D is another group of user interface schematic diagrams involved in a scenario of initiating data sharing by a system provided by an embodiment of the present application;

[0074] FIG. 10A-FIG. 10D is a group of user interface schematic diagrams involved in a scenario of initiating data sharing by a communication application provided by an embodiment of the present application;

[0075] FIG. 11A-FIG. 11I is a group of user interface schematic diagrams involved in a scenario of receiving and opening a shared file by a system provided by an embodiment of the present application;

[0076] FIG. 12 is a flow schematic diagram of controlling a network, Bluetooth and the like provided by an embodiment of the present application;

[0077] FIG. 13 is a flow schematic diagram of controlling a print, copy and the like provided by an embodiment of the present application;

[0078] FIG. 14 is a flow schematic diagram of controlling a screen capture and the like provided by an embodiment of the present application;

[0079] FIG. 15A-FIG. 15B is a group of user interface schematic diagrams involved in a scenario of receiving and opening a shared file through a communication application provided by an embodiment of the present application;

[0080] FIG. 16 is a method flow schematic diagram of data sharing provided by an embodiment of the present application;

[0081] FIG. 17 is another method flow schematic diagram of data sharing provided by an embodiment of the present application;

[0082] FIG. 18 is a hardware structure schematic diagram of an electronic device 100 provided by an embodiment of the present application. DETAILED DESCRIPTION

[0083] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. In the description of the embodiments of the present application, unless otherwise specified, " / " represents the meaning of or, for example, A / B can represent A or B; "and / or" in the text is only a description of the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B, which means that there are three cases of A alone, A and B together, and B alone. In addition, in the description of the embodiments of the present application, "multiple" means two or more than two.

[0084] It should be understood that the terms "first", "second" and the like in the specification and claims of the present application and the drawings are used to distinguish different objects, and are not used to describe a particular order. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but can optionally include steps or units not listed, or can optionally include other steps or units inherent to the process, method, product or device.

[0085] In the present application, "embodiment" means that the specific features, structures or characteristics described in conjunction with the embodiment can be included in at least one embodiment of the present application. The phrase appears in the specification at various places does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment to other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described in the present application can be combined with other embodiments.

[0086] The term "user interface (UI)" in the embodiments of the present application is a medium interface for interaction and information exchange between an application or an operating system and a user, which realizes conversion between an internal form of information and a form acceptable by the user. The user interface is source code written in a specific computer language such as Java, extensible markup language (XML), and the like. The interface source code is parsed and rendered on an electronic device, and finally presented as content recognizable by the user. A commonly used form of the user interface is a graphic user interface (GUI), which refers to a user interface related to computer operation displayed in a graphical manner. It can be a visual interface element such as text, icons, buttons, menus, tabs, text boxes, dialog boxes, status bars, navigation bars, Widgets, and the like displayed in the display screen of the electronic device.

[0087] Currently, a controlled sharing function of a file can be implemented in some office document applications. Generally, a sending device can perform encryption processing on a file to be shared in the office document application, specify that a specific receiving device can decrypt the file, and set specific permissions (for example, read-only, editable, and the like) of the file. The receiving device can open the shared file in the office document application, the application can parse the file content, and the application can execute the permissions set for the file.

[0088] Exemplarily, refer to FIG. 1 The above office document application can be one of a plurality of applications installed on an electronic device. The application can include a controlled sharing software development kit, which can include a credential management module and a policy analysis module. The credential management module can be used to acquire and save credentials of a user, and the policy analysis module can be used to analyze permission policies of a file.

[0089] Controlled sharing of a file by the above office document application also has some problems. For example, in terms of scene support, only specific document encryption sharing scenarios are usually supported, which is relatively limited. For example, in terms of security (for example, credential management and permission management), when the application is Hooked, the credentials of the user can be leaked through the credential management module. In addition, the permissions set for the file are analyzed by the policy analysis module, and the permission control depends on the application deep customization interception. When the application is Hooked, the permission control point can be invalid. For example, in terms of ecological friendliness, the controlled sharing function is strongly dependent on the adaptation of various applications. The receiving device can only use one application to open the shared file (for example, the permission control method implemented in an application is not adapted to other applications, so only this application can open the file with the permission settings added), and the experience is poor.

[0090] Based on the above problems, the embodiment of the application provides a data sharing method. For a sender, the electronic device 100 (sender device) can provide a system-level file encryption control sharing function, and the sender can select a file (for example, a picture, a document, etc.) to be shared from the system through the electronic device 100, set a permission control policy, and send the file to a receiver device through one or more different sending modes. For a receiver, the electronic device 200 (receiver device) can provide a data control function, and the receiver can receive and open the shared file through the electronic device 200. The system can dynamically adjust the permission of an application to access different functions of the system based on the permission control policy set in the file, for example, the receiver cannot perform secondary forwarding, copying, screen capturing, printing, etc. on the file, and even if an attacker attacks the application that opens the file, the attacker cannot perform the above operations on the file. In this way, the scene support, security, ecological friendliness, etc. are improved, and the user experience is better.

[0091] Next, first introduce a communication system provided by the embodiment of the application.

[0092] FIG. 2A An exemplary communication system provided by the embodiment of the application is shown.

[0093] Referring to FIG. 2A The communication system can include an electronic device 100 (sender device), an electronic device 200 (receiver device), and a server 300.

[0094] The electronic device 100 and the electronic device 200 are both terminal devices, which can be various types, and the embodiment of the application does not limit this.

[0095] For example, the electronic device 100, i.e., the sender device (or the sharing device), can be a mobile phone, a large screen, a tablet, a personal computer (PC), a car machine, a watch, a bracelet, a virtual reality device (VR) / augmented reality device (AR), etc.

[0096] In the embodiment of the application, the electronic device 100 can provide a system-level file encryption control sharing function, and the electronic device 100 does not need to install a certain application, which can be specifically referred to related content in subsequent embodiments.

[0097] For example, the electronic device 200, i.e., the receiver device, can be a mobile phone, a large screen, a tablet, a PC, a car machine, a watch, a bracelet, a VR / AR, etc.

[0098] In the embodiments of the present application, the electronic device 200 can provide a data management function. The system can dynamically adjust the permissions of the application to access different functions of the system based on the permission management strategy set in the shared file. For details, please refer to the related content in the subsequent embodiments.

[0099] The server 300 can be a traditional server or a cloud server, and the embodiments of the present application do not limit this.

[0100] In the embodiments of the present application, the server 300 can be used to store the mapping relationship table of the user's identity and the credential.

[0101] The electronic device 100 in the communication system can establish a wired connection, other wireless connection, such as Bluetooth communication connection, wireless local area network (WLAN) such as wireless fidelity point to point (Wi-Fi P2P) connection, near field communication (NFC) connection, infrared technology (IR) connection, remote connection (such as remote connection established through a server), etc., or can also be connected and communicated in combination with any of the above ways.

[0102] The electronic device 100 and the electronic device 200 in the communication system can be configured with different software operating systems (OS), including but not limited to and the like. Among them, Harmony system of Huawei. The electronic device 100 and the electronic device 200 can also be configured with the same software operating system, for example, can be configured with

[0103] It should be understood that FIG. 2A This is only a schematic diagram of the architecture of the communication system, and should not be construed as a limitation of the present application. The number of electronic devices 100, electronic devices 200 and servers 300 included in the communication system is not limited in the embodiments of the present application.

[0104] The software architecture of the electronic device 100 provided by the embodiments of the present application is introduced below.

[0105] FIG. 2B The software architecture of the electronic device 100 is exemplarily shown.

[0106] Referring to FIG. 2BThe electronic device 100 can include one or more applications (for example, a gallery / file management application, etc.), a file permission management service module, a system sharing service module, a Bluetooth / WIFI communication module, etc.

[0107] The one or more applications can be system applications or third-party applications.

[0108] In some examples, the upper-layer application can not include the gallery / file management application, etc. For example, the upper-layer application can be an application capable of performing access, sharing, etc. on files in the gallery / file management application, etc.

[0109] In some other examples, the upper-layer application can also include the gallery / file management application, etc.

[0110] The gallery / file management application, etc. can be used to provide a file access entry, provide a file selector, receive a file selection event, provide a file path, display a file, etc.

[0111] The file permission management service module can be used to encrypt a file, generate a permission control policy of the file, etc.

[0112] The file permission management service module can include a file encryption module and a control policy generation module.

[0113] The file encryption module can be used to obtain a credential for a specified receiver identity, receive a permission control policy of a file, encrypt a content of the file and the permission control policy of the file using the credential, generate a file ciphertext with the permission control policy, etc.

[0114] The control policy generation module can be used to receive a user permission control configuration operation on a file to generate a permission control policy of the file, etc.

[0115] The system sharing service module can be used to provide a system-level data sharing function.

[0116] The Bluetooth / WIFI communication module, etc. can be used to provide a communication function of the electronic device 100. For example, the electronic device 100 can send a file to be shared to the electronic device 200 through the Bluetooth / WIFI communication module, etc.

[0117] It can be understood that, FIG. 2B The above is only exemplary and should not limit the software architecture of the electronic device 100 in the embodiments of the present application.

[0118] The software architecture of the electronic device 200 provided by the embodiments of the present application is introduced below.

[0119] FIG. 2CAn example is shown to illustrate the software architecture of the electronic device 200.

[0120] Referring to FIG. 2C The electronic device 200 can include an upper-layer application (such as an office document type application), a file management module, an application permission management service module, a file permission management service module, an application management module, a network / Bluetooth / storage, etc. service module, a screenshot / recording application, a print / copy, etc. service module, a window management service module.

[0121] The upper-layer application can be used to open a file (such as a file shared by the electronic device 100). The upper-layer application can be a system application or a third-party application. For example, the upper-layer application can be an office document type application, or a gallery, file management, etc. application.

[0122] The file management module (such as a file management application) can be used to provide a file path, determine a file attribute (such as determining whether a file is a controlled sharing file), etc.

[0123] The application permission management service module can be used to provide a system common permission management capability, provide a permission management judgment capability when an application uses one or more functions, in the embodiments of the present application, can also be used to provide a dynamic permission setting capability when an application opens a file and a dynamic control capability when an application executes an operation, can also be used to receive a permission control policy configured by the application management module for a certain application identifier (such as application identifier 11), etc.

[0124] The file permission management service module can be used to decrypt a received file, perform operations such as parsing, configuring, storing, reading, etc. on a permission control policy of the file, etc.

[0125] The file permission management service module can include a file decryption module, a control policy parsing module, a control policy configuration module, a control policy storage module, and a control policy reading module.

[0126] The file decryption module can be used to obtain a credential for a receiver identity, decrypt file ciphertext (such as decrypting file content, decrypting a permission control policy of the file), etc.

[0127] The control policy parsing module can be used to parse a permission control policy of a decrypted file, generate a parsing result, etc.

[0128] The control policy configuration module can be used to provide a configuration capability of the parsing result, etc.

[0129] The control policy storage module can be used to provide a storage capability of the parsing result, etc.

[0130] The control strategy reading module can be configured to read the analysis result, provide query capability of the analysis result, and the like.

[0131] The application management module can be configured to start the application, configure the permission of the application, and the like.

[0132] The application management module can include an application starting module and an application permission configuration module.

[0133] The application starting module can be configured to start the application in an independent process based on the application result selected by the user, assign an application identifier, and the like.

[0134] The application permission configuration module can be configured to determine whether the file is an encryption-controlled file, obtain the permission control strategy for the file from the file permission management service module, and configure the permission control strategy for the application identifier to the application permission management service module.

[0135] The network / Bluetooth / storage service module can be configured to determine whether to allow access based on the permission control strategy when the application initiates access to the network / Bluetooth / storage service module, and the like. For example, the current application is an application that does not open a controlled file (which can also be referred to as a normal application), and the application can be controlled or passed through based on a conventional permission authorization record. For another example, the current application is an application that opens a controlled file, and the application can be controlled or passed through based on the permission control strategy dynamically configured when the file is opened.

[0136] The screenshot / recording application can be configured to perform a screenshot operation or a recording operation on the file content, and the like.

[0137] The printing / copying service module can be configured to determine whether to allow access based on the permission control strategy when the application initiates access to the printing / copying service module. For example, the current application is an application that does not open a controlled file, and the application can be directly passed through when there is no special limitation in the system. For another example, the current application is an application that opens a controlled file, and the application can obtain a decision result of whether to allow passing through from the file permission management service module and control or pass through based on the decision result.

[0138] The window management service module can be configured to manage a window program. The window management service module can obtain the size of a display screen, and intercept a screen, and the like.

[0139] It can be understood that, FIG. 2C The above is only exemplary and should not limit the software architecture of the electronic device 200 in the embodiments of the present application.

[0140] The data sharing method provided in the embodiments of the present application will be described in detail below in combination with a series of exemplary user interfaces.

[0141] For the sender (or sharer), in this embodiment of the application, the electronic device 100 can support users to initiate sharing through the system or through communication applications.

[0142] For the recipient, in this embodiment of the application, the electronic device 200 can support the user to receive and open the shared file through the system, or it can support the user to initiate sharing and receive and open the shared file through a communication application.

[0143] Scenario 1: Initiating sharing through the system

[0144] See FIG. 3A , FIG. 3A The exemplary user interface 310 may be a user interface for a user to select files / folders in the system. The user interface 310 may include a file management list, one or more options (e.g., sharing option 311, copy option, move option, delete option, more options), wherein the aforementioned file management list may include one or more files (e.g., the document "Design Patent Disclosure.txt", the image "IMG_3392.jpg"), one or more folders (e.g., folder 1), and the sharing option 311 may be used to directly share the selected file / folder.

[0145] In this embodiment of the application, the electronic device 100 can support users to select files / folders in the system. The entry point for selecting files / folders may include, but is not limited to, application entry points that can display files, such as gallery and file management. The operation of selecting files / folders may include, but is not limited to, long press operation, click operation, drag operation, etc. The number of files / folders selected may be one or multiple.

[0146] Taking a mobile phone as an example, electronic device 100 can support users to select one or more files / folders by long-pressing. For example, see the following documentation. FIG. 3A As can be seen, the document "Design Patent Disclosure.txt" is selected, which means that the user has selected the document "Design Patent Disclosure.txt" as the file to be shared.

[0147] It's easy to understand that if electronic device 100 is a PC, then one or more files / folders can be selected by using accessories such as a mouse and keyboard.

[0148] Continue reading FIG. 3A When the system of electronic device 100 detects that a file / folder is selected, electronic device 100 can display sharing option 311. Electronic device 100 can detect user actions on sharing option 311 (e.g., click actions), and in response to such actions, electronic device 100 can display...FIG. 3B The window 320 is exemplarily shown.

[0149] Referring to FIG. 3B , the encryption sharing option 321 can be included in the window 320.

[0150] It is easy to understand that the user can trigger the electronic device 100 to perform the data sharing method provided by the embodiments of the present application by operating (for example, clicking operation) the encryption sharing option 321.

[0151] In some examples, referring to FIG. 3C , the system of the electronic device 100 can also directly display the encryption sharing option 321 when it is perceived that the file / folder is in the selected state.

[0152] In other examples, if the electronic device 100 is a PC, the system of the electronic device 100 can also directly display the encryption sharing option 321 when it is perceived that the file / folder is in the selected state, and can also support the user to display the encryption sharing option 321 by clicking the right mouse button or other menu bar.

[0153] In the embodiments of the present application, after detecting that the user operates the encryption sharing option 321, the electronic device 100 can perceive the login state of the local account. If the user has not logged in the account, the electronic device 100 can guide the user to log in the account by the interface display mode. If the user has logged in the account, the electronic device 100 can directly display the related user interface for subsequent data sharing without displaying the user interface for guiding the user to log in the account.

[0154] Exemplarily, referring to FIG. 4A , when it is detected that the user has not logged in the account (for example, Huawei account), the electronic device 100 can display FIG. 4A The window 410 is exemplarily shown, which can be used to support the user to log in the account by manually inputting the mobile phone number and the SMS verification code.

[0155] In some examples, the electronic device 100 can also support the user to log in the account by using other ways, for example, the user can log in the account by using FIG. 4B The fingerprint verification mode is exemplarily shown; for another example, the user can log in the account by using FIG. 4C The face verification mode is exemplarily shown; for another example, the user can log in the account by using the account password login mode; for another example, the user can log in the account by using the scan code login mode; and the like.

[0156] Optionally, if the user has been authenticated by the user account or the biometric feature such as fingerprint or face before the user performs the encrypted sharing operation, and the identity is considered to be trusted, the electronic device 100 can also not require the user to input the credential information again after the user selects the encrypted sharing. Optionally, the user can also complete the cross-device authentication through other associated devices such as wearable devices, without the need to authenticate through the electronic device 100.

[0157] In the embodiments of the present application, after detecting that the user logs in the account, the electronic device 100 can display a user interface for guiding the user to select the identity of the recipient. The identity of the recipient can include, but is not limited to, the mobile phone number, the email address, the account ID, and the like of the recipient, which can be used to identify the identity of the user.

[0158] The way of selecting the identity of the recipient can include, but is not limited to, the following three ways:

[0159] Way 1, manually inputting the identity of the recipient.

[0160] For example, referring to FIG. 5A , the electronic device 100 can display a window 510, which can include an input box 511. The electronic device 100 can support the user to input the mobile phone number of the recipient in the input box 511.

[0161] In some examples, after detecting that the user inputs the mobile phone number of the recipient, the electronic device 100 can identify whether the mobile phone number is bound to a Huawei account. If the mobile phone number is not bound to a Huawei account, the electronic device 100 can display FIG. 5B the window 520 shown in the example, which can include a prompt information 521 (for example, “No Huawei account identified, please input again”). The prompt information 521 can be used to prompt the user to input the mobile phone number of the Huawei account again.

[0162] In the embodiments of the present application, the electronic device 100 can support the user to input the identity of one or more recipients.

[0163] Way 2, selecting the identity of the recipient in the address book

[0164] For example, referring to FIG. 5A , the input box 511 can include an option 512. The option 512 can be used to trigger the electronic device 100 to display the related user interface of the address book, so as to support the user to select the identity of the recipient from the address book.

[0165] For example, the electronic device 100 can detect the operation (for example, the click operation) of the user on the option 512. In response to the operation, the electronic device 100 can display FIG. 5C the window 530 shown in the example orFIG. 5D The exemplary window 540, window 530 or window 540 may include a list of recipients. The list of recipients may include information about one or more recipients (such as name, avatar, etc.). Users can select the identity of a recipient by performing an operation on the list of recipients (such as a click operation).

[0166] In this embodiment of the application, the electronic device 100 can support the user to select one or more recipient identity identifiers, for example, see [reference]. FIG. 5E As can be seen, the user selected three receivers.

[0167] It should be noted that, in the embodiments of this application, the recipient can refer to a user or a group.

[0168] Method 3: Select the receiver's identity identifier in the near-field device.

[0169] Electronic device 100 can discover surrounding devices based on Bluetooth, WIFI, or other near-field communication methods, and can... FIG. 5F The exemplary window 550 displays a device list 551, and the information displayed in the device list 551 may include, but is not limited to, one or more of the following: device name, user name, and avatar. The electronic device 100 can support the user to select the user device (i.e., the receiving device) to interact with from the device list 551. Furthermore, the electronic device 100 can obtain the identity identifier of the receiving device corresponding to the selected user device to interact with through near-field communication methods.

[0170] In this embodiment of the application, after detecting the identity identifier of the recipient selected by the user, the electronic device 100 can obtain the identity credentials (public key or symmetric key) of the recipient based on the identity identifier of the recipient selected by the user.

[0171] The methods for obtaining the recipient's identity credentials may include, but are not limited to, the following three:

[0172] Method 1: Obtain from the server

[0173] The server side (i.e., the cloud side) can store a mapping table of the recipient's identity and credentials (e.g., the mapping table shown in Table 1). The electronic device side (i.e., the terminal side) can upload the recipient's identity to the server side. The server side can determine the credentials corresponding to the identity based on the mapping table of the recipient's identity and credentials, and send the credentials to the electronic device side.

[0174] For example, see FIG. 6A, the file permission management service module of the electronic device 100 can upload the identity selected by the user to the file permission management service module of the server, and the file permission management service module of the server can determine, based on the mapping relationship table of the identity of the receiver and the credential, that the credential corresponding to the identity 1 is the credential 1, and issue the credential 1 to the electronic device 100.

[0175] Identity Credential Identity 1 Credential 1 Identity 2 Credential 2

[0176] Table 1

[0177] Method 2, locally acquired

[0178] The electronic device side (i.e., the end side) can synchronize the mapping relationship table of the identity of the receiver and the credential on the server side (i.e., the cloud side) and store it locally. The identity credential of the receiver is acquired based on the identity selected by the user and the above-mentioned mapping relationship table of the identity of the receiver and the credential.

[0179] Exemplarily, refer to FIG. 6B The file permission management service module of the server can issue the mapping relationship table of the identity of the receiver and the credential to the electronic device 100, and the file permission management service module of the electronic device 100 can store the above-mentioned mapping relationship table of the identity of the receiver and the credential. Further, the file permission management service module of the electronic device 100 can query the credential corresponding to the identity based on the identity selected by the user and the above-mentioned mapping relationship table of the identity of the receiver and the credential.

[0180] Method 3, acquired in near field device

[0181] The electronic device 100 (sender device) can initiate a connection to the electronic device 200 through near field communication, and can acquire the identity of the receiver and the credential corresponding to the electronic device 200 (receiver device) based on the connection.

[0182] Exemplarily, refer to FIG. 6C The file permission management service module of the electronic device 100 can acquire the identity of the receiver and the credential corresponding to the electronic device 200 stored in the file permission management service module of the electronic device 200 based on the near field connection.

[0183] In the embodiments of the present application, after the electronic device 100 acquires the identity credential of the receiver, the credential can be used to protect the file selected by the user. The protection method can include but is not limited to the following three methods:

[0184] Method 1, only provide "read only" function of the file by default

[0185] The electronic device 100 can set the permission of the file selected by the user as the "read-only" permission by default, or a permission range pre-configured by the user, without the need for user confirmation. For example, refer to FIG. 7A After the "read-only" permission is set, the electronic device 100 can display relevant prompt information (for example, "File encryption successful") to prompt the user that the file selected by the user has been encrypted.

[0186] Method 2: Prompt the user whether to confirm adding the "read-only" permission, and wait for the user to confirm before completing encryption

[0187] For example, refer to FIG. 7B The electronic device 100 can display a window 710, which can be used to prompt the user whether to confirm adding the "read-only" permission to the selected file. After detecting that the user confirms adding the "read-only" permission to the selected file (for example, the user clicks the "Yes" option in the window 710), the electronic device 100 can add the "read-only" permission to the selected file, and complete encryption.

[0188] Method 3: Provide a permission setting panel to support the user to set the "read-only" permission and the "editable" permission independently, which can include but is not limited to the following two methods:

[0189] Method (1),

[0190] For example, refer to FIG. 8A The electronic device 100 can display a window 810, which can include a "read-only" permission option 811 and an "editable" permission option 812. The "read-only" permission option 811 can be used to set the permission of the selected file as the "read-only" permission, and the "editable" permission option 812 can be used to set the permission of the selected file as the "editable" permission. The "editable" permission can include but is not limited to editing, saving, printing, transmitting, copying, screenshot, and screen recording.

[0191] In the embodiments of the present application, the same user cannot simultaneously configure the "read-only" permission and the "editable" permission for a file. For example, if the electronic device 100 detects that the user selects to set the permission of the file as the "read-only" permission (for example, the user clicks the "read-only" permission option 811), the electronic device 100 can disable all operations that can cause the file content to be leaked (for example, forwarding, copying, saving, screenshot, printing, and the like) and operations that can cause the file content to be damaged (for example, editing). In addition, the "editable" permission option 812 can also be automatically displayed in grayscale and in a non-selectable state, without the need for the user to manually select.

[0192] Method (2),

[0193] Exemplarily, referring to FIG. 8B , the electronic device 100 can display a window 820, the window 820 can include a “read-only” permission option 821, one or more “editable” permission refinement configuration options (for example, save option 822, print option 823, transfer option 824, copy option 825), and the electronic device 100 can support the user to operate (for example, click operation) the one or more “editable” permission refinement configuration options to select the configuration of the operations that the receiving device can perform on the file.

[0194] It is easy to understand that if there are multiple recipients, in the embodiments shown in FIG. 8A and FIG. 8B , the permissions of the file are uniformly set.

[0195] In some examples, if there are multiple recipients (for example, multiple independent users, multiple group members in a group), the electronic device 100 can also set different permissions for the file for different recipients, that is, the “read-only” permission and the “editable” permission of the file can be set for the specified user. In the case of multiple independent users as recipients, the electronic device 100 can set the permissions of the file for the multiple independent users respectively; in the case of a group as a recipient, the electronic device 100 can set the permissions of the file for the multiple group members in the group respectively; in the case of a group as a recipient, the electronic device 100 can also uniformly set the permissions of the file for all group members in the group, in which case the group members can share the same credential, that is, one group identifier corresponds to one credential, and the process of obtaining the credential can refer to the foregoing related content, which will not be repeated here.

[0196] Optionally, referring to FIG. 8C , the electronic device 100 can display a window 830, the window 830 can be used to prompt the user to input one or more recipient account information to specify the recipient of the encrypted file.

[0197] Exemplarily, referring to FIG. 8D , the electronic device can display a window 840, the window 840 can include an option 841 and an option 842, wherein the option 841 can be used to set the “read-only” permission of the file for the specified user, and the option 842 can be used to set the “editable” permission of the file for the specified user.

[0198] Exemplarily, referring to FIG. 8E, the electronic device can also display a window 850, which can include an option 851, an option 852, an option 853, an option 854, and an option 855, where the option 851 can be used to set the "read-only" permission of the file for the specified user, the option 852 can be used to set the save permission in the "editable" permission of the file for the specified user, the option 853 can be used to set the print permission in the "editable" permission of the file for the specified user, the option 854 can be used to set the transmission permission in the "editable" permission of the file for the specified user, and the option 855 can be used to set the copy permission in the "editable" permission of the file for the specified user.

[0199] For the setting of the specified user, taking the "read-only" permission of the file for the specified user as an example, the electronic device 100 can detect an operation (e.g., a click operation) of the user on the option 841 or the option 851 shown in FIG. 8B, and in response to the operation, the electronic device 100 can display a window 860 shown in an example in FIG. 8C, where the window 860 can display one or more recipients selected by the user, and the electronic device 100 can support the user to select the one or more recipients for the permission setting, for example, refer to FIG. 8D. FIG. 8D FIG. 8E For the setting of the specified user, taking the "read-only" permission of the file for the specified user as an example, the electronic device 100 can detect an operation (e.g., a click operation) of the user on the option 841 or the option 851 shown in FIG. 8B, and in response to the operation, the electronic device 100 can display a window 860 shown in an example in FIG. 8C, where the window 860 can display one or more recipients selected by the user, and the electronic device 100 can support the user to select the one or more recipients for the permission setting, for example, refer to FIG. 8D. FIG. 8F FIG. 8G As can be seen, the user Alice and the group family are in the selected state, that is, the user Alice and the group family are selected as the specified user of the "read-only" permission of the file, and the user Alice and the group family have the "read-only" permission of the file. It is easy to understand that the "editable" permission of the file for the specified user is similar to the "read-only" permission of the file for the specified user, and will not be described here.

[0200] It is easy to understand that in the embodiment shown in FIG. 8B, for the group family, the permissions set for each group member of the group are the same. In some examples, the electronic device 100 can also support the user to set the corresponding permission for each group member in the group individually. Continue to refer to FIG. 8B. FIG. 8G FIG. 8F Also taking the "read-only" permission as an example, the electronic device 100 can detect an operation (e.g., a click operation) of the user on the option 861, and in response to the operation, the electronic device 100 can display a window 870 shown in an example in FIG. 8E, where the window 870 can include one or more group members (e.g., group member 1, group member 2, group member 3, and group member 4) in the group family, and the electronic device 100 can support the user to select one or more group members for the permission setting, for example, refer to FIG. 8F. FIG. 8H FIG. 8I ​​​​It can be seen that the group member 1 is in the selected state, that is, the group member 1 is a designated user selected as the "read-only" permission of the file, and the group member 1 has the "read-only" permission of the file.

[0201] In the embodiment of the present application, for the case that the user has selected multiple files, the electronic device 100 can support the user to protect the permissions of the multiple files respectively, or can support the user to merge the multiple files into an independent file and then uniformly protect the permissions.

[0202] In some examples, for the same type of file, the way of permission protection can be the same, so that for multiple files of the same type, the user can uniformly set the permissions, simplifying the user operation. For example, referring to FIG. 8J , the user-selected files can be divided into two types of files (for example, type 1 files and type 2 files), and the user can trigger the electronic device 100 to protect the permissions of the files by clicking the type 1 files or the type 2 files. The specific process can refer to the related content of the foregoing permission protection, which will not be described here.

[0203] Next, a possible specific implementation mechanism of permission protection is introduced.

[0204] After detecting that the user selects the permission protection attribute (for example, read-only, editable, etc.) of the file, the electronic device 100 can encapsulate the permission protection attribute configured by the user as a field description, as the permission definition of the file. Further, the electronic device 100 can encrypt the file content and the above permission definition based on the identity credential of the receiver. The encryption method can include but is not limited to the following two methods:

[0205] Method 1,

[0206] Insert the permission definition into the file content, and encrypt the whole result (that is, the file content and the permission definition as a whole) after the insertion, and the ciphertext is used as the new file content.

[0207] Method 2,

[0208] Encrypt the permission definition and the file content respectively, and the ciphertext is used as the new file content, and the ciphertext of the permission definition is written into the metadata of the file.

[0209] In some examples, the above permission definition can also not follow the file associated therewith. For example, the electronic device 100 can upload the above permission definition and the ID of the file associated therewith to the server, and the server can save the mapping relationship table of the permission definition and the file ID. Subsequently, the receiver can obtain the permission definition corresponding to the file from the server after receiving the file.

[0210] For the encrypted file, the suffix of the file name can be changed or not.

[0211] In the case of changing the suffix of the file name, a specific suffix name (for example,.a) can be set. For example, the original file can be file1.docx, and after the file permission definition and file content are encrypted, it can be file1.docx.a. It is easy to understand that the above suffix name.a is only an example and should not be construed as limiting.

[0212] In the case of not changing the suffix of the file name, for example, the original file can be file1.docx, and after encryption, it is still file1.docx. The encrypted file content can include the file permission definition ciphertext and the file content ciphertext.

[0213] After encryption is completed, an encryption result can be generated, and the encryption result can include an encrypted file and an index corresponding to the encrypted file, wherein the index corresponding to the encrypted file can include, but is not limited to, a file path, a file address, a file handle, and other indexes that can be used to obtain file information.

[0214] In an embodiment of the present application, after encryption is completed, the electronic device 100 can display FIG. 9A The window 910 shown in the example can include a prompt information 911 and an option 912, wherein the prompt information 911 can be used to prompt the user that the file has been encrypted and completed, and the file can be stored to a specified path, and the option 912 can be used to store the file to the specified path. After the user clicks the option 912, the electronic device 100 can display a storage path, and the user can manually select a new storage path to trigger the electronic device 100 to store the file with the set permission protection to the path.

[0215] In some examples, after encryption is completed, the electronic device 100 can also store the file to a default path, for example, an XXX path, and can display FIG. 9B The window 920 shown in the example can include relevant prompt information to prompt the user that the file has been stored in the XXX path.

[0216] In an embodiment of the present application, after the file that has been permission protected (i.e., the above-mentioned encrypted file) is stored, the electronic device 100 can support the user to perform a sharing operation on the file, and the sharing operation can include, but is not limited to, the following two ways:

[0217] Way 1:

[0218] After the file that has been permission protected is stored, the electronic device 100 can directly obtain the path or other types of indexes of the file locally, initiate sharing, and the sharing way can include, but is not limited to, the following two ways:

[0219] (1) Near field sharing based on the sharing service provided by the system

[0220] For example, referring to FIG. 5F , the electronic device 100 can display a device list 551, and support the user to select a device in the device list 551 as a receiving device, so that the above-mentioned file that has been permission-protected can be sent to the receiving device, and the sharing is completed.

[0221] (2) Sharing through an application

[0222] For example, continuing to refer to FIG. 5F , the electronic device 100 can display an application list 552, and the application list 552 can include one or more applications that can share files. The electronic device 100 can support the user to select an application in the application list 552 to share the file to a receiving device.

[0223] It is easy to understand that the above-mentioned two sharing methods are only exemplary, and the sharing method of the above-mentioned file that has been permission-protected can be consistent with the sharing method of a common file, and the embodiments of the present application are not limited in this regard.

[0224] Method 2:

[0225] After the file that has been permission-protected is stored, the electronic device 100 can support the user to reselect the file under the new storage path corresponding to the file to initiate sharing. It is easy to understand that the method of selecting and sharing the file that has been permission-protected can be consistent with the method of selecting and sharing a common file, and the embodiments of the present application are not limited in this regard.

[0226] For example, referring to FIG. 9C , it can be seen that the document "appearance patent disclosure.txt" is a file that has been permission-protected after being saved, and is in a selected state. The user can trigger the electronic device 100 to share the file by clicking the sharing option in FIG. 9C .

[0227] In some examples, the electronic device 100 can display a window 940 as shown in the example when detecting that the file that has been permission-protected is in a selected state. FIG. 9D The window 940 can be used to display the authorized users of the file and the permissions that the authorized users have (for example, user A has "read-only" permission, and user B has "editable" permission).

[0228] In some examples, continuing to refer to FIG. 9D, the electronic device 100 can support the user to add a new authorized user to the file which has been protected by the permission, for example, the user can click the "add a new authorized user" option to trigger the electronic device 100 to perform the related steps of adding a new authorized user, and the process of adding a new authorized user can refer to the foregoing related content of selecting the receiver identity and performing the permission protection, which will not be described here.

[0229] As can be seen from the above scenario one, by implementing the method provided in the embodiments of the present application, the encryption setting of the file can be initiated in the application, and the electronic device can support the user to use the system function to configure who the file is sent to and what permissions (for example, "read-only" permission and "editable" permission) the file receiver has, without the upper application needing to perceive the encryption of the file, improving the ecological friendliness and providing a better user experience.

[0230] Scenario two: initiating sharing through a communication application

[0231] In the embodiments of the present application, the electronic device 100 can support the user to select a file in a communication tool (for example, a chat, an email and the like) having a sending function to initiate file sharing.

[0232] Exemplarily, the user interface 1010 shown in FIG. 10A , FIG. 10A may be a chat interface provided by a chat application, which can be a chat interface between the user of the electronic device 100 and a user Lily. It can be easily understood that the user Lily can be a file receiver. The electronic device 100 can support the user to select an option for sending a picture, a document and the like, which can be in any form and is not limited in the embodiments of the present application.

[0233] Taking sending a picture as an example, continuing to refer to FIG. 10A , if the user wants to send a picture to Lily, the electronic device 100 can detect the operation of the user on the album option, and in response to the operation, the electronic device 100 can display FIG. 10B the user interface 1020 shown in the example, which can include a preview picture list 1021, and the preview picture list 1021 can include one or more pictures (for example, picture 1 and picture 2).

[0234] In the embodiments of the present application, the system can provide a file selection function for the application, and the system can display an encryption sharing option on the interface when it is perceived that the file is in a selected state. The option can be displayed at any position on the interface, which is not limited in the embodiments of the present application.

[0235] For example, continuing to refer to FIG. 10B , the electronic device 100 can detect an operation (e.g., an operation of clicking the picture 1) of selecting one or more pictures by the user, and in response to the operation, the electronic device 100 can display FIG. 10C the encryption sharing option 1021.

[0236] It is easy to understand that the function of selecting one or more pictures by the user can be an in-application function, and the function of displaying the encryption sharing option 1021 can be an in-system function.

[0237] In the embodiments of the present application, after detecting the operation (e.g., a click operation) of the user on the encryption sharing option 1021, the electronic device 100 can start to perform the process of setting the permission, and the process of setting the permission can refer to the related content in the foregoing scenario one (including the related content of selecting the identity of the receiver and performing the permission protection), which will not be repeated here.

[0238] In some examples, on the basis that the current communication application provides a function of reading the identity of the user, the electronic device 100 can obtain the identity of the receiver in the current interface, and further, can obtain the corresponding credential based on the identity, and protect the file selected by the user based on the credential. The specific process can refer to the related content in the foregoing scenario one, which will not be repeated here.

[0239] After completing the permission setting of the file, the electronic device 100 can support the user to send the file to the receiver device. For example, continuing to refer to FIG. 10C , the electronic device 100 can detect an operation (e.g., a click operation) of the user on the sending option, and in response to the operation, the electronic device 100 can send the picture 1 with the set permission to the receiver device (e.g., the device of Lily).

[0240] In some examples, the system can perceive the selected state of the file, and in the case that the file is in the selected state, the system can scan the file after obtaining the authorization of the user, so as to obtain the information contained in the file. In the case that the file contains personal information (e.g., portrait, ID number, bank card number, etc.), the electronic device 100 can display the encryption sharing option. For example, referring to FIG. 10B , it is assumed that the picture 1 does not contain personal information, and the picture 2 contains personal information. If the user selects the picture 1 but does not select the picture 2, the electronic device 100 can not display the encryption sharing option, referring to FIG. 10DIf the user selects image 1 and then image 2, the electronic device 100 can display an encrypted sharing option. Optionally, the encrypted sharing control can also be located at the same level as controls for photo albums, video calls, etc. When the user clicks the encrypted sharing control, it triggers the selection of the file and encrypted sharing. The path to the file to be encrypted and shared can be a dedicated path for the encrypted file or a selection path shared with general files. After the user selects encrypted sharing, the encryption operation is completed in a way that is imperceptible to the user, and then the file is shared.

[0241] As can be seen from Scenario 2 above, by implementing the method provided in this application embodiment, after selecting a file within an application (system application or third-party application), the system triggers encrypted file sharing (e.g., displaying an encrypted sharing option). The electronic device can then support users using system functions to configure who the file is sent to and what permissions the file recipient has (e.g., "read-only" permission, "editable" permission). Upper-layer applications do not need to be aware of file encryption, improving ecosystem friendliness and user experience. This solves the problem that initiating data encryption and permission settings within upper-layer applications must be implemented separately by the application itself, and that other applications need to implement this repeatedly if they want to manage file permissions.

[0242] Scenario 3: Receiving and opening shared files via the system

[0243] In this embodiment of the application, the electronic device 200 can receive encrypted files shared by the electronic device 100 through different receiving channels (such as near-field sharing, communication application sharing).

[0244] See FIG. 11A , FIG. 11A The exemplary user interface 1110 can be used by a user to select files / folders in the system. The user interface 1110 may include a file management list, which may include one or more files (e.g., Document 1, Document 2, Document 3) and one or more folders. The user interface for selecting files / folders in the system may be provided by applications with file display functions, such as file management or image galleries.

[0245] In some examples, encrypted files may have an icon to identify them as encrypted files. This icon may be displayed in ways including, but not limited to, the following two:

[0246] Method 1:

[0247] All encrypted files, regardless of format (e.g., doc, jpg, etc.), use the same encryption icon. FIG. 11A The icon for document 1 shown is a lock icon.

[0248] Way 2:

[0249] Different formats of encrypted files show the original format of the exclusive icon, and the encryption icon is superimposed on the exclusive icon, for example FIG. 11B The icon of the document 1 doc file is superimposed with the icon of a lock.

[0250] In the embodiments of the present application, the user's operation of selecting a file / folder can include but is not limited to a long press operation, a click operation, etc., and the number of selected files / folders can be one or more.

[0251] For example, referring to FIG. 11B , the user can select the encrypted file document 1 by a click operation.

[0252] In the embodiments of the present application, after the electronic device 200 detects that the user selects the file, the system of the electronic device 200 can perceive that the file is in a selected state, and further, the system can analyze the type of the file and determine whether the file is a controlled encrypted sharing file (also referred to as an encrypted file or a controlled file).

[0253] For example, in the case where the file has a specific file name suffix, the system can analyze whether the file is a controlled encrypted sharing file based on the suffix.

[0254] For example, in the case where the file does not have a specific file name suffix, the system can analyze the file content and determine the "controlled encrypted sharing file attribute" feature. Analyzing the file content can include but is not limited to analyzing the permission configuration field from the file content and analyzing the permission configuration field from the file metadata.

[0255] In the embodiments of the present application, after the electronic device 200 detects that the user selects the file, the system of the electronic device 200 can determine the current login state of the user's account. If the user is not logged in, the electronic device 200 can guide the user to log in through the interface display, for example, referring to FIG. 11C The electronic device 200 can support the user to log in by manually inputting the mobile phone number and the SMS verification code. However, it is not limited to this, and other ways (such as face verification, fingerprint verification, etc.) can also be used to log in.

[0256] In the embodiments of the present application, after the electronic device 200 detects that the user logs in, the decryption credentials associated with the account can be obtained, and the obtaining method can include but is not limited to the following two ways:

[0257] Way 1, obtain from the server

[0258] The server can store a mapping table of identity (associated with the login account) and credential. The electronic device 200 can upload the identity of the user of the electronic device 200 (i.e., the user of the logged-in account) to the server. The server can determine the credential corresponding to the identity based on the mapping table of identity and credential, and deliver the credential to the electronic device 200.

[0259] Method 2, locally obtain

[0260] The electronic device 200 can synchronize the mapping table of identity and credential with the server, and store it locally. The electronic device 200 can obtain the credential based on the mapping table of identity and credential locally.

[0261] In the embodiments of the present application, if the user of the logged-in account is consistent with the specified receiver of the controlled encrypted sharing file, the electronic device 200 can open the file, for example, display the user interface 1130 shown in FIG. 11D If the user of the logged-in account is not consistent with the specified receiver of the controlled encrypted sharing file, the electronic device 200 cannot open the file. For example, the electronic device 200 can display the window 1140 shown in FIG. 11E The window 1140 can include relevant prompt information to prompt the user that the user has no permission to open the file.

[0262] In the embodiments of the present application, for the user who has the permission to open the controlled encrypted sharing file, the system of the electronic device 200 can determine which application to use to open the file.

[0263] In some examples, the electronic device 200 can use a default application to open the file without the user manually selecting which application to use to open the file. For example, after detecting that the user selects to open the file, the electronic device 200 can directly use the default application to open the file, for example, display the file content as shown in FIG. 11D

[0264] In other examples, the electronic device 200 can provide an application list display panel installed by the system to support the user to independently select which application to use to open the file. For example, as shown in FIG. 11F After detecting that the user selects to open the file, the electronic device 200 can display the window 1150, which can include an application list. The application list can include one or more applications (e.g., application 1, application 2, application 3, and application 4). The user can manually select an application to trigger the electronic device 200 to launch the application and open the file in the application to display the file content. The one or more applications can be system applications or third-party applications installed by the user.

[0265] ​It is easy to understand that if the application selected by the user does not have the opening ability of the original document type itself (for example, the user selects to open an encrypted.doc file by using a picture editing application), the electronic device 200 can display relevant prompt information to prompt the user that the application cannot open the file (for example, display error information "Cannot open.doc file").

[0266] In the embodiment of the present application, if the controlled encryption sharing file is configured with "read-only" permission, after the user opens the file, the user can only read the file and cannot initiate other operations (for example, printing, saving, screenshot, and the like) on the file. As a possible implementation manner, a system-level interception can be provided by the user device, which can not need to care about the capability and control range of the third-party application, and enhances the data control capability, wherein the system-level interception manner can include but is not limited to the following three manners.

[0267] Manner 1: The system displays prompt information (or error information), and at the same time, the system intercepts the above operations (for example, printing, saving, screenshot, and the like)

[0268] Exemplarily, in a case where it is detected that the user performs a copy operation on the file, the electronic device 200 can display the window 1160 shown in FIG. 11B, and the window 1160 can include prompt information 1161, which can be used to prompt the user that the user can only read the file and cannot initiate a copy operation on the file. FIG. 11G

[0269] Exemplarily, in a case where it is detected that the user performs a save operation on the file, the electronic device 200 can display the window 1170 shown in FIG. 11C, and the window 1170 can include prompt information 1171, which can be used to prompt the user that the user can only read the file and cannot initiate a save operation on the file. FIG. 11H

[0270] Exemplarily, in a case where it is detected that the user performs a screenshot operation on the file, the electronic device 200 can display the window 1180 shown in FIG. 11D, and the window 1180 can include prompt information 1181, which can be used to prompt the user that the user can only read the file and cannot initiate a screenshot operation on the file. FIG. 11I

[0271] Manner 2: The system does not display prompt information (or error information), and the system only intercepts the above operations (for example, printing, saving, screenshot, and the like) in the background

[0272] Manner 3: The system does not display prompt information (or error information), the system intercepts the above operations (for example, printing, saving, screenshot, and the like) in the background, and the system provides interception notification, and the application implements the interception notification prompt ​​​

[0273] It is easy to understand that when the user opens other files that are not protected by permissions using the same application and performs the above copy, print, etc. operations, the electronic device 200 can not perform the interception operation.

[0274] Exemplarily, for different management and control functions, the functions can be divided into the following three different modes, which can be referred to the contents in Table 2 below.

[0275]

[0276]

[0277] Table 2

[0278] The control processes when the functions of the above three different modes are executed will be introduced respectively.

[0279] I. Network and Bluetooth control process

[0280] FIG. 12 An example of a specific process for controlling network, Bluetooth and other functions provided by the embodiments of the application is shown.

[0281] As shown in FIG. 12 , the process can be applied to the electronic device 200. The electronic device 200 can include a file management module, a controlled application (i.e. an application that opens a controlled file), an application management module, a file permission management service module, a network service module, a Bluetooth service module, and an application permission management service module. The specific steps will be introduced in detail as follows:

[0282] S1201, the file management module requests the application management module to open the controlled file and starts the controlled application.

[0283] S1202, the application management module instructs the file permission management service module to load the controlled file.

[0284] S1203, the file permission management service module decrypts the controlled file and the permission control policy, parses the application permission policy set by the controlled file, including disallowing access to the network and Bluetooth.

[0285] S1204, the file permission management service module sends the decrypted controlled file path to the application management module.

[0286] S1205, the application management module allocates a controlled ID of the controlled application to the file permission management service module.

[0287] In some examples, the above controlled ID can be an application identifier 11.

[0288] S1206, the application management module sends the set permission control policy to the application permission management service module, including that the controlled application is not allowed to access the network and Bluetooth.

[0289] It is easy to understand that the application management module can obtain the permission control policy of the controlled file under the path after receiving the decrypted controlled file path sent by the file permission management service module.

[0290] S1207, the application permission management service module records that the controlled application is not allowed to access the network and Bluetooth.

[0291] S1208, the application management module starts the controlled application and allocates a controlled ID.

[0292] In some examples, the application management module can start the controlled application in the form of an independent process.

[0293] S1209, the controlled application requests networking from the network service module.

[0294] S1210, the network service module requests the permission control policy of the controlled application from the application permission management service module.

[0295] S1211, the application permission management service module sends the permission control policy of the controlled application to the network service module, including that the controlled application is not allowed to access the network.

[0296] S1212, the network service module rejects the controlled application to access the network.

[0297] Specifically, after receiving the permission control policy of the controlled application sent by the application permission management service module, the network service module can reject the controlled application to access the network in a case that the network service module determines that the controlled application is not allowed to access the network based on the permission control policy.

[0298] In some examples, the above steps S1209-S1212 are optional.

[0299] S1213, the controlled application requests Bluetooth connection from the Bluetooth service module.

[0300] S1214, the Bluetooth service module requests the permission control policy of the controlled application from the application permission management service module.

[0301] S1215, the application permission management service module sends the permission control policy of the controlled application to the Bluetooth service module, including that the controlled application is not allowed to access Bluetooth.

[0302] S1216, the Bluetooth service module rejects the controlled application to access Bluetooth.

[0303] Specifically, after receiving the access control policy of the controlled application sent by the application access management service module, the Bluetooth service module can refuse the controlled application's access to Bluetooth if it determines based on the access control policy that the controlled application is not allowed to access Bluetooth.

[0304] In some examples, steps S1213-S1216 above are optional.

[0305] It should be noted that the execution order of steps S1209-S1212 and steps S1213-S1216 in this embodiment is not limited. For example, steps S1209-S1212 may be executed before steps S1213-S1216; or, for another example, steps S1209-S1212 may be executed after steps S1213-S1216.

[0306] It is easy to understand that the storage control process for controlled files is similar to the aforementioned network and Bluetooth control processes. Applications can be restricted from accessing file storage. For details, please refer to the relevant content of the aforementioned network and Bluetooth control processes, which will not be repeated here.

[0307] II. Printing and Copying Control Process

[0308] FIG. 13 This example illustrates a specific process for controlling functions such as printing and copying, provided by an embodiment of this application.

[0309] like FIG. 13 As shown, this process can be applied to electronic device 200. Electronic device 200 may include a file management module, controlled applications (i.e., applications that open controlled files), an application management module, a file permission management service module, a print service module, and a clipboard service module. The specific steps are detailed below:

[0310] S1301, The file management module requests the application management module to open the controlled file and start the controlled application.

[0311] S1302, The application management module instructs the file permission management service module to load controlled files.

[0312] S1303, The file permission management service module decrypts the controlled file and permission control policy, and parses the application permission policy set for the controlled file, including disallowing access to printing and copying.

[0313] S1304. The file permission management service module sends the decrypted controlled file path to the application management module.

[0314] S1305. The application management module assigns the controlled ID of the controlled application to the file permission management service module.

[0315] In some examples, the controlled ID can be an application identifier 11.

[0316] S1306, the file permission management service module records that the controlled application does not allow printing and copying.

[0317] S1307, the application management module starts the controlled application and assigns a controlled ID.

[0318] In some examples, the application management module can start the controlled application in the form of an independent process.

[0319] S1308, the controlled application requests printing from the print service module.

[0320] S1309, the print service module requests the permission control policy of the controlled application from the file permission management service module.

[0321] S1310, the file permission management service module sends the permission control policy of the controlled application to the print service module, including that the controlled application does not allow printing.

[0322] S1311, the print service module rejects the printing of the controlled application.

[0323] Specifically, after receiving the permission control policy of the controlled application sent by the file permission management service module, the print service module can reject the printing of the controlled application on the controlled file in the case of determining that the controlled application does not allow to perform the printing operation based on the permission control policy.

[0324] In some examples, the above steps S1308-S1311 are optional.

[0325] S1312, the controlled application requests copying from the clipboard service module.

[0326] S1313, the clipboard service module requests the permission control policy of the controlled application from the file permission management service module.

[0327] S1314, the file permission management service module sends the permission control policy of the controlled application to the clipboard service module, including that the controlled application does not allow copying.

[0328] S1315, the clipboard service module rejects the copying of the controlled application.

[0329] Specifically, after receiving the permission control policy of the controlled application sent by the file permission management service module, the clipboard service module can reject the copying of the controlled application on the controlled file in the case of determining that the controlled application does not allow to perform the copying operation based on the permission control policy.

[0330] In some examples, the steps S1312-S1315 are optional.

[0331] It should be noted that the execution time sequence of the steps S1308-S1311 and the steps S1312-S1315 is not limited in the embodiments of the present application. For example, the steps S1308-S1311 can be executed before the steps S1312-S1315; for another example, the steps S1308-S1311 can be executed after the steps S1312-S1315.

[0332] III. Screenshot control flow

[0333] FIG. 14 An example is shown to illustrate a specific flow of controlling a function such as screenshot provided by the embodiments of the present application.

[0334] As shown in FIG. 14 , the flow can be applied to the electronic device 200. The electronic device 200 can include a file management module, a screenshot application, a controlled application (i.e., an application that opens a controlled file), an application management module, a file permission management service module, and a window management service module. The specific steps are described in detail as follows:

[0335] S1401, the file management module requests the application management module to open a controlled file and starts a controlled application.

[0336] S1402, the application management module requests the file permission management service module for a screenshot permission control policy associated with the controlled application.

[0337] It is easy to understand that before the step S1402 is executed, the application management module can instruct the file permission management service module to load the controlled file and obtain the permission control policy of the controlled file.

[0338] S1403, the file permission management service module determines that the controlled application is not allowed to take screenshots.

[0339] It is easy to understand that the file permission management service module can determine whether the controlled application is allowed to perform a screenshot operation on the controlled file based on the permission control policy of the controlled file that has been obtained.

[0340] S1404, the file permission management service module sends the application management module a screenshot permission control policy, including that the controlled application is not allowed to take screenshots.

[0341] S1405, the application management module sends the window management service module a set SecurityFlag of the controlled application.

[0342] It is easy to understand that the application management module can set the SecurityFlag of the controlled application in the case that the controlled application is not allowed to perform the screenshot operation on the controlled file.

[0343] S1406, the application management module starts the controlled application and assigns a controlled ID.

[0344] S1407, the window management service module records the SecurityFlag of the controlled application.

[0345] S1408, the screenshot application detects that the user initiates the screenshot.

[0346] S1409, the screenshot application requests the window management service module for the screenshot.

[0347] S1410, the window management service module determines that there is a record of the SecurityFlag of the controlled application.

[0348] S1411, the window management service module rejects the screenshot application to perform the screenshot operation.

[0349] Specifically, in the case that the window management service module determines that there is a record of the SecurityFlag of the controlled application, the window management service module can reject the screenshot application to perform the screenshot operation on the content of the controlled file displayed in the controlled application.

[0350] It is easy to understand that the screen recording control process for the controlled file is similar to the foregoing network and Bluetooth control processes, and the specific process can refer to the related content of the foregoing screenshot control process, which will not be described here.

[0351] Scenario three

[0352] Scenario four: receiving and opening the shared file through the communication application

[0353] The electronic device 200 can support the user to receive the encrypted file shared by the electronic device 100 through the communication application (such as chat, email, etc.).

[0354] Exemplarily, the user interface 1510 shown in FIG. 15A , FIG. 11C The user interface 1510 can be a chat interface provided by the chat application, which can be a chat interface between the user of the electronic device 200 and the user Ann. It can be seen that the document XXX.doc is an encrypted file, and the sender of the file is Ann. The user can perform a click operation on the encrypted file to trigger the electronic device 200 to open the file.

[0355] In this embodiment, after detecting a user's click on the encrypted file, the electronic device 200 can determine whether the user has logged into the account specified in the recipient scope of the file. If the user has not logged into the account specified in the recipient scope of the file, the electronic device 200 can prompt the user to log in. For example, the electronic device 200 can display the aforementioned... FIG. 15A The window shown prompts the user to log in. If the user logs in with the account specified in the recipient range of the file, the electronic device 200 can determine which application to use to open the file. Similar to scenario three above, the electronic device 200 can use the default application to open the file, or it can provide a list of installed applications to allow the user to choose which application to use. In some examples, if the aforementioned communication application has its own file browsing function, the electronic device 200 can also open the file directly within that application.

[0356] It should be noted that the account specified for the recipient scope of the encrypted file can be different from or the same as the account system used in the aforementioned communication applications. In some examples, if the account specified in the encrypted file is a designated account of account system 2 (e.g., a Huawei account), then when a user uses an account of account system 1 (e.g., a chat account used in a chat application) and wants to open the file, the electronic device 200 can prompt the user to log in to an account of account system 2. In other examples, if the account of account system 1 (e.g., a chat account used in a chat application) is associated with a designated account of account system 2 (e.g., a Huawei account), when a user wants to open the file, the electronic device 200 can directly obtain the account association information of the user's logged-in account, thereby further obtaining the designated account of account system 2. In this case, the electronic device 200 does not need to prompt the user to log in to an account of account system 2.

[0357] See further examples. FIG. 15B After detecting a user's click on the encrypted file, the electronic device 200 can automatically store the encrypted file locally. Subsequent methods for opening the file can refer to the description of the initial file opening in the aforementioned content, which will not be repeated here; alternatively, after the initial file opening, subsequent openings can follow relevant business rules, such as allowing direct opening within a preset time, while requiring re-authentication after the preset time has elapsed.

[0358] In other examples, see FIG. 16, the electronic device 200 can display, in the user interface 1510, a receiving option 1511 and a saving option 1512. The receiving option 1511 can be used to receive the file and store the file to a default path locally. The saving option 1512 can be used to receive the file and store the file to a user-specified path locally. The manner in which the user opens the file later can refer to the foregoing related content, and will not be described here again.

[0359] Similar to the foregoing scenario three, if the encrypted file is configured with a "read-only" permission, after the user opens the file, the user can only read the file, and cannot initiate other operations (such as printing, saving, screenshot, etc.) on the file.

[0360] In the embodiments of the present application, the manner in which the electronic device 100 (i.e., the sender device) encrypts the file and the electronic device 200 (i.e., the receiver device) decrypts the file can include, but is not limited to, the four manners in Table 5 below:

[0361]

[0362]

[0363] Table 5

[0364] In the embodiments of the present application, it can also be limited which devices of the receiver can open the file shared by the sender. The specific strategies can include, but are not limited to, the following three:

[0365] Strategy 1:

[0366] As long as the device is logged in to the account specified in the receiver range, the device can open the file. For example, after the receiver receives the file on the electronic device 200, the receiver can forward the file to other devices of the receiver, and open the file on the other devices.

[0367] Strategy 2:

[0368] Only one device of the receiver (which is logged in to the account specified in the receiver range) is allowed to open the file; or, in the case where the number of devices of the receiver is less than a certain preset threshold, the receiver is allowed to open the file on multiple devices (which are all logged in to the same account specified in the receiver range).

[0369] Strategy 3:

[0370] The device is logged in to the account specified in the receiver range, and the device can open the file only when the device meets the corresponding security conditions (such as setting a lock screen, the device having a trusted execution environment, the device not being rooted, etc.).

[0371] In the embodiments of the present application, in the case where the sender of a file grants the receiver the "editable" permission of the file, it can also be limited whether the receiver can perform the forwarding operation on the file, and the specific strategy can include but is not limited to the following four kinds:

[0372] Strategy 1:

[0373] The receiver device can share the above-mentioned file to one or more users in the manner of the aforementioned scenario one or scenario two after receiving and storing the file locally, or directly forward the above-mentioned file.

[0374] Strategy 2:

[0375] The receiver device can only view or edit the above-mentioned file, and cannot share the above-mentioned file to one or more users in the manner of the aforementioned scenario one or scenario two.

[0376] Strategy 3:

[0377] The receiver device can view or edit the above-mentioned file, and can also forward, but the receiver after forwarding only has the "read-only" permission of the above-mentioned file, and if you want to get the "editable" permission, you need to contact the sender to make relevant settings.

[0378] Strategy 4:

[0379] The receiver device can view or edit the above-mentioned file, and can also forward, but before forwarding, the sender needs to be notified, and the sender reinitiates authorization, and after authorization, the receiver device can forward the above-mentioned file.

[0380] FIG. 16 An exemplary embodiment of the present application provides a specific flow of a data sharing method.

[0381] As shown in FIG. 10A , the method can be applied to a first electronic device. The specific steps of the method are described in detail as follows:

[0382] S1601, the first electronic device determines that the first file is selected.

[0383] S1602, in response to the operation of sharing the first file on the first interface, the first electronic device sends the first file to the second electronic device associated with the first user; wherein the first electronic device is used to set the first permission for the first file, and the first permission is effective when the first file is sent by the plurality of applications on the first electronic device, and the first permission is used to indicate one or more operations authorized by the first user to perform on the first file.

[0384] The first electronic device is a sending device (for example, the electronic device 100), the second electronic device is a receiving device (for example, the electronic device 200), and the first file is a file to be shared, which can include but is not limited to a picture, a document, and an audio / video.

[0385] In a possible implementation, the method further includes: before the first electronic device sends the first file to the second electronic device associated with the first user, the first electronic device displays at least one of a device list, an application list, and a user list on an interface, where the interface is the first interface or the second interface; and the first electronic device sends the first file to the second electronic device associated with the first user, specifically including: in response to an operation of selecting the second electronic device in the device list, the first electronic device sends the first file to the second electronic device associated with the first user; or, in response to an operation of selecting the first application in the application list, the first electronic device sends the first file to the second electronic device associated with the first user through the first application; or, in response to an operation of selecting the first user in the user list, the first electronic device sends the first file to the second electronic device associated with the first user.

[0386] In a possible implementation, the first electronic device sends the first file to the second electronic device associated with the first user, specifically including: in response to an operation of sharing the first file triggered on an interface, the first electronic device sends the first file to the second electronic device associated with the first user, where the interface is an interface in which the first user is in a conversation (for example, the interface shown in FIG. 2). FIG. 17

[0387] In a possible implementation, the first file is set with the first permission before the operation of sharing the first file; or the first file is set with the first permission after the operation of sharing the first file and is sent to the second electronic device associated with the first user.

[0388] In a possible implementation, the method further includes: in response to an operation of sharing the first file on the first interface, the first electronic device sends the first file to a third electronic device associated with a second user; and the first electronic device is configured to set a second permission for the first file, the second permission being effective for a plurality of applications on the first electronic device when the first file is sent, and the second permission being used to indicate one or more operations authorized to be performed on the first file by the second user.

[0389] ​In a possible implementation, the method further includes: determining, by the first electronic device, that the second file is selected; and sending, by the first electronic device, the second file to a second electronic device associated with the first user in response to the operation of sharing the second file on the first interface; wherein the first electronic device is configured to set a third permission for the second file, and the third permission takes effect for all the applications on the first electronic device when the second file is sent, and the third permission is used to indicate one or more operations that the first user is authorized to perform on the second file.

[0390] In a possible implementation, the first user belongs to a first group, and the first group further includes a third user. The method further includes: sending, by the first electronic device, the first file to a fourth electronic device associated with the third user in response to the operation of sharing the first file on the first interface, and the first permission is further used to indicate one or more operations that the third user is authorized to perform on the first file; or sending, by the first electronic device, the first file to the fourth electronic device associated with the third user in response to the operation of sharing the first file on the first interface; wherein the first electronic device is further configured to set a fourth permission for the first file, and the fourth permission takes effect for all the applications on the first electronic device when the first file is sent, and the fourth permission is used to indicate one or more operations that the third user is authorized to perform on the first file.

[0391] In a possible implementation, before the first electronic device sends the first file to the second electronic device associated with the first user, the method further includes: logging in, by the first electronic device, a first account, and the first account belongs to an account of a fourth user.

[0392] In a possible implementation, before the first electronic device sends the first file to the second electronic device associated with the first user, the method further includes: obtaining, by the first electronic device, a credential corresponding to the first user; and encrypting, by the first electronic device, the first file based on the credential.

[0393] In a possible implementation, the credential is obtained by the first electronic device on a server, or the credential is obtained by the first electronic device locally, or the credential is obtained by the first electronic device on the second electronic device.

[0394] In a possible implementation, the first electronic device is configured to set the first permission for the first file, and specifically includes: the first electronic device is configured to write field information of the first permission into the first file; or the first electronic device is configured to send a first message to a server, and the first message includes the field information of the first permission and identification information of the first file, and the first message is used to indicate that the server saves an association relationship between the field information of the first permission and the identification information of the first file.

[0395] In a possible implementation, the first permission includes a read-only permission, or an editable permission, or a forwarding permission, and the editable permission includes one or more of a save permission, a screenshot permission, a screen recording permission, a print permission, and a copy permission.

[0396] In the embodiments of the present application, the forwarding permission can or can not belong to the definition range of the first permission (that is, the forwarding permission can be parallel to the first permission).

[0397] In a possible implementation, the first file includes sensitive information (for example, a portrait, an ID number, a bank card number, etc.).

[0398] FIG. 17 An example is shown to illustrate the specific process of another data sharing method provided by the embodiments of the present application.

[0399] As shown in FIG. 18 , the method can be applied to a second electronic device. The specific steps of the method are described in detail as follows:

[0400] S1701, the second electronic device receives a first file sent by a first electronic device, the first file is controlled by a first permission, the first permission takes effect when a plurality of applications on the second electronic device perform an operation (such as an opening operation) within the control range of the first permission on the first file, and the plurality of applications include a first application.

[0401] S1702, the second electronic device obtains a first operation on the first file in the first application.

[0402] S1703, in response to the first operation, if the second electronic device determines that the first operation is one or more operations that a first user indicated by the first permission is authorized to perform on the first file, the second electronic device responds to the first operation.

[0403] The second electronic device is a receiver device (for example, the electronic device 200), the first electronic device is a sender device (for example, the electronic device 100), and the first file is a shared file, which can include but is not limited to a picture, a document, and an audio / video. The first operation can include but is not limited to viewing, saving, taking a screenshot, recording a screen, printing, copying, and forwarding.

[0404] In a possible implementation, before the second electronic device determines that the first operation is one or more operations that the first user indicated by the first permission is authorized to perform on the first file, the above method further includes: the second electronic device determines that the user performing the first operation is the first user who is authenticated to have an operation permission on the first file.

[0405] In a possible implementation, the second electronic device determines that the user performing the first operation is a first user who is authenticated to have the operation permission on the first file, specifically including: the second electronic device determines that an account logged in the second electronic device is an account of the first user; or, the second electronic device determines that a biological feature of the user performing the first operation is consistent with a biological feature of the first user; or, the second electronic device receives a first message sent by a third electronic device, the first message being used to indicate that the user performing the first operation is the first user who is authenticated to have the operation permission on the first file, the third electronic device being associated with the second electronic device.

[0406] In a possible implementation, the method further includes: in a case where the second electronic device determines that the first operation does not belong to one or more operations that the first user who is authenticated to have the operation permission on the first file is authorized to perform, the second electronic device displays first prompt information, the first prompt information being used to prompt the user that the second electronic device rejects responding to the first operation.

[0407] In a possible implementation, the method further includes: in response to the operation of sharing the first file, the second electronic device sends the first file to a third electronic device associated with the first user.

[0408] In a possible implementation, the method further includes: in response to the operation of sharing the first file, the second electronic device sends the first file to a fourth electronic device associated with the second user.

[0409] In a possible implementation, when the first file is forwarded by the second electronic device, the first file is set to a third permission, an authorization range of the third permission being no more than an authorization range of the first permission.

[0410] In a possible implementation, the method further includes: the second electronic device sends a second message to the first electronic device, the second message being used to indicate that the first electronic device authorizes a second operation of the first user on the first file, the second operation not belonging to one or more operations that the first user who is authenticated to have the operation permission on the first file is authorized to perform.

[0411] In a possible implementation, the method further includes: the second electronic device sends a third message to the first electronic device, the third message being used to indicate that the first electronic device authorizes a forwarding operation of the first user on the first file.

[0412] In a possible implementation, the first file is an encrypted file, and before the second electronic device responds to the first operation, the method further includes: the second electronic device obtains a credential corresponding to the first user; and the second electronic device decrypts the first file based on the credential.

[0413] In one possible implementation, a first identifier is displayed on the second electronic device, which indicates that the first file is an encrypted file.

[0414] In one possible implementation, the first permission is obtained by the second electronic device from the first file; or, the first permission is obtained by the second electronic device from the server.

[0415] In one possible implementation, the first permission includes read-only permission, or editable permission, or forwarding permission. Editable permissions include one or more of the following: save as permission, screenshot permission, screen recording permission, print permission, and copy permission.

[0416] The following is a schematic diagram of the structure of an electronic device 100 provided in an embodiment of this application.

[0417] FIG. 18 An exemplary embodiment of an electronic device 100 provided in this application is shown.

[0418] like FIG. 18 As shown, the electronic device 100 may include: a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, a headphone jack 170D, a sensor module 180, buttons 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and a subscriber identification module (SIM) card interface 195, etc. The sensor module 180 may include a pressure sensor 180A, a gyroscope sensor 180B, a barometric pressure sensor 180C, a magnetic sensor 180D, an accelerometer sensor 180E, a distance sensor 180F, a proximity sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, etc.

[0419] It is understood that the structures illustrated in the embodiments of this application do not constitute a specific limitation on the electronic device 100. In other embodiments of this application, the electronic device 100 may include more or fewer components than illustrated, or combine some components, or split some components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.

[0420] The processor 110 can include one or more processing units, for example: the processor 110 can include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Different processing units can be independent devices or integrated in one or more processors.

[0421] The controller can be the nerve center and command center of the electronic device 100. The controller can generate operation control signals according to instruction operation codes and timing signals, and complete the control of fetching and executing instructions.

[0422] The memory in the processor 110 can also be configured to store instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. The memory can save instructions or data that have just been used or are repeatedly used by the processor 110. If the processor 110 needs to use the instructions or data again, it can directly call them from the memory. This avoids repeated access and reduces the waiting time of the processor 110, thereby improving the efficiency of the system.

[0423] In some embodiments, the processor 110 can include one or more interfaces. The interfaces can include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface, etc.

[0424] The I2C interface is a bidirectional synchronous serial bus, including a serial data line (SDA) and a serial clock line (SCL). In some embodiments, the processor 110 can contain multiple sets of I2C buses. The processor 110 can be coupled to the touch sensor 180K, the charger, the flash, the camera 193, etc. through different I2C bus interfaces respectively. For example, the processor 110 can be coupled to the touch sensor 180K through an I2C interface, so that the processor 110 and the touch sensor 180K communicate through the I2C bus interface to realize the touch function of the electronic device 100.

[0425] The USB interface 130 is an interface conforming to the USB standard specification, and can be a Mini USB interface, a Micro USB interface, a USB Type C interface, etc. The USB interface 130 can be used to connect a charger to charge the electronic device 100, and can also be used to transmit data between the electronic device 100 and a peripheral device. It can also be used to connect earphones to play audio through the earphones. The interface can also be used to connect other terminal devices, such as AR devices, etc.

[0426] It can be understood that the interface connection relationship between the modules shown in the embodiments of the present application is only illustrative and does not constitute a structural limitation of the electronic device 100. In some other embodiments of the present application, the electronic device 100 can also use different interface connection methods or combinations of multiple interface connection methods in the above embodiments.

[0427] The wireless communication function of the electronic device 100 can be realized through the antenna 1, the antenna 2, the mobile communication module 150, the wireless communication module 160, the modem processor, and the baseband processor, etc.

[0428] The antenna 1 and the antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in the electronic device 100 can be used to cover a single or multiple communication frequency bands. Different antennas can also be multiplexed to improve the utilization rate of the antennas. For example, the antenna 1 can be multiplexed as a diversity antenna of a wireless local area network. In some other embodiments, the antenna can be used in combination with a tuning switch.

[0429] The mobile communication module 150 can provide a solution for wireless communication including 2G / 3G / 4G / 5G, etc. applied to the electronic device 100. The mobile communication module 150 can include at least one filter, a switch, a power amplifier, a low noise amplifier (LNA), etc. The mobile communication module 150 can receive electromagnetic waves by the antenna 1, and perform filtering, amplification, etc. on the received electromagnetic waves, and transfer to a modem processor for demodulation. The mobile communication module 150 can also amplify the signal modulated by the modem processor, and radiate as electromagnetic waves through the antenna 1. In some embodiments, at least part of the function modules of the mobile communication module 150 can be disposed in the processor 110. In some embodiments, at least part of the function modules of the mobile communication module 150 can be disposed in the same device as at least part of the modules of the processor 110.

[0430] The modem processor can include a modulator and a demodulator. The modulator is configured to modulate a low-frequency baseband signal to be transmitted into a medium-high frequency signal. The demodulator is configured to demodulate a received electromagnetic wave signal into a low-frequency baseband signal. The demodulator then transmits the demodulated low-frequency baseband signal to the baseband processor for processing. The low-frequency baseband signal processed by the baseband processor is transmitted to the application processor. The application processor outputs a sound signal through an audio device (not limited to the speaker 170A, the microphone 170B, etc.), or displays an image or a video through the display screen 194. In some embodiments, the modem processor can be a separate device. In other embodiments, the modem processor can be independent of the processor 110, and disposed in the same device as the mobile communication module 150 or other function modules.

[0431] The wireless communication module 160 can provide a solution for wireless communication including wireless local area networks (WLAN) (e.g., wireless fidelity (Wi-Fi) network), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared (IR) technology, etc. applied to the electronic device 100. The wireless communication module 160 can be one or more devices that integrate at least one communication processing module. The wireless communication module 160 receives an electromagnetic wave via the antenna 2, frequency-modulates and filters the electromagnetic wave signal, and transmits the processed signal to the processor 110. The wireless communication module 160 can also receive a signal to be transmitted from the processor 110, frequency-modulate it, amplify it, and radiate it as an electromagnetic wave via the antenna 2.

[0432] In some embodiments, the antenna 1 and the mobile communication module 150 of the electronic device 100 are coupled, and the antenna 2 and the wireless communication module 160 are coupled, so that the electronic device 100 can communicate with a network and other devices through wireless communication technology. The wireless communication technology can include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technology, etc. The GNSS can include a global positioning system (GPS), a global navigation satellite system (GLONASS), a beidu navigation satellite system (BDS), a quasi-zenith satellite system (QZSS), and / or a satellite based augmentation systems (SBAS).

[0433] In the embodiments of the present application, the electronic device 100 can communicate with other electronic devices (for example, the electronic device 200) through Bluetooth communication, WIFI communication, etc. For example, the electronic device 100 can send a file that wants to be encrypted and shared to the electronic device 200 through Bluetooth communication, WIFI communication, etc.

[0434] The electronic device 100 realizes the display function through the GPU, the display screen 194, and the application processor, etc. The GPU is a microprocessor for image processing, which is connected to the display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. The processor 110 can include one or more GPUs, which execute program instructions to generate or change display information.

[0435] The display screen 194 is used to display images, videos, etc. The display screen 194 includes a display panel. The display panel can adopt a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light emitting diode (AMOLED), a flex light-emitting diode (FLED), a Miniled, a MicroLed, a Micro-oLed, a quantum dot light emitting diodes (QLED), etc. In some embodiments, the electronic device 100 can include 1 or N display screens 194, N being a positive integer greater than 1.

[0436] The digital signal processor is used to process digital signals, in addition to being able to process digital image signals, it can also process other digital signals. For example, when the electronic device 100 selects a frequency point, the digital signal processor is used to perform Fourier transform on the frequency point energy, etc.

[0437] The video codec is used to compress or decompress digital videos. The electronic device 100 can support one or more video codecs. In this way, the electronic device 100 can play or record videos in multiple encoding formats, such as: moving picture experts group (MPEG) 1, MPEG 2, MPEG 3, MPEG 4, etc.

[0438] The external memory interface 120 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the electronic device 100. The external memory card communicates with the processor 110 through the external memory interface 120 to realize the data storage function. For example, save music, video, etc. files in the external memory card.

[0439] The internal memory 121 can be used to store computer executable program codes including instructions. The processor 110 performs various functional applications and data processing of the electronic device 100 by running the instructions stored in the internal memory 121. The internal memory 121 can include a program storage area and a data storage area. The program storage area can store an operating system, at least one application program (such as a sound playing function, an image playing function, etc.) required by a function, etc. The data storage area can store data (such as audio data, a phone book, etc.) created during the use of the electronic device 100, etc. In addition, the internal memory 121 can include a high-speed random access memory, and can further include a non-volatile memory such as at least one magnetic disk storage device, a flash memory device, a universal flash storage (UFS), etc.

[0440] The pressure sensor 180A is used to sense a pressure signal and can convert the pressure signal into an electrical signal. In some embodiments, the pressure sensor 180A can be disposed on the display screen 194. There are many types of pressure sensors 180A, such as a resistive pressure sensor, an inductive pressure sensor, a capacitive pressure sensor, etc. The capacitive pressure sensor can include at least two parallel plates with conductive material. When a force is applied to the pressure sensor 180A, the capacitance between the electrodes changes. The electronic device 100 determines the intensity of the pressure according to the change in capacitance. When a touch operation is applied to the display screen 194, the electronic device 100 detects the intensity of the touch operation according to the pressure sensor 180A. The electronic device 100 can also calculate the position of the touch according to the detection signal of the pressure sensor 180A. In some embodiments, touch operations applied to the same touch position but with different touch operation intensities can correspond to different operation instructions. For example, when a touch operation with a touch operation intensity less than a first pressure threshold is applied to a short message application icon, an instruction to view a short message is executed. When a touch operation with a touch operation intensity greater than or equal to the first pressure threshold is applied to the short message application icon, an instruction to create a new short message is executed.

[0441] The fingerprint sensor 180H is used to collect a fingerprint. The electronic device 100 can use the characteristics of the collected fingerprint to implement fingerprint unlocking, access to an application lock, fingerprint photographing, fingerprint answering a call, etc.

[0442] Touch sensor 180K, also referred to as "touch panel". Touch sensor 180K can be disposed on display screen 194, and touch screen, also referred to as "touch panel", can be formed by touch sensor 180K and display screen 194. Touch sensor 180K is configured to detect touch operation applied thereto or in the vicinity thereof. Touch sensor 180K can transmit detected touch operation to application processor to determine touch event type. Visual output related to touch operation can be provided through display screen 194. In some other embodiments, touch sensor 180K can also be disposed on the surface of electronic device 100, which is different from the position where display screen 194 is disposed.

[0443] Keys 190 include power key, volume key, and the like. Keys 190 can be mechanical keys. Alternatively, keys 190 can be touch keys. Electronic device 100 can receive key input and generate key signal input related to user settings and function control of electronic device 100.

[0444] Motor 191 can generate vibration prompt. Motor 191 can be used for incoming call vibration prompt, and can also be used for touch vibration feedback. For example, touch operation applied to different applications (e.g., taking pictures, playing audio, and the like) can correspond to different vibration feedback effects. Touch operation applied to different regions of display screen 194 can also correspond to different vibration feedback effects. Different application scenarios (e.g., time reminder, receiving information, alarm, game, and the like) can also correspond to different vibration feedback effects. Touch vibration feedback effects can also be customizable.

[0445] Indicator 192 can be an indicator light, which can be used to indicate charging status, power change, and can also be used to indicate messages, missed calls, notifications, and the like.

[0446] It should be understood that, FIG. 18 Electronic device 100 shown is only an example, and electronic device 100 can have more or fewer components than those shown in FIG. 18 embodiments, two or more components can be combined, or a different component configuration can be used. FIG. 18 Various components shown in the above embodiments can be implemented in hardware, software, or a combination of hardware and software, including one or more signal processing and / or application specific integrated circuits.

[0447] Electronic device 200 can have the same or similar structure as electronic device 100, and related content about the structure of electronic device 200 can be referred to the related description of the structure of electronic device 100 shown in ​ embodiments, two or more components can be combined, or a different component configuration can be used.

[0448] The chip system provided in the embodiments of the present application comprises: a processor, which is coupled with a memory, and the memory is used to store programs or instructions, and when the programs or instructions are executed by the processor, the chip system implements the method in any of the method embodiments.

[0449] Optionally, the processor in the chip system can be one or more. The processor can be implemented by hardware or software. When implemented by hardware, the processor can be a logic circuit, an integrated circuit, etc. When implemented by software, the processor can be a general-purpose processor, which is implemented by reading software codes stored in the memory.

[0450] Optionally, the memory in the chip system can also be one or more. The memory can be integrated with the processor or arranged separately from the processor, and the embodiments of the present application do not limit this. For example, the memory can be a non-transient processor, such as a read-only memory (ROM), which can be integrated on the same chip as the processor or arranged on different chips respectively, and the embodiments of the present application do not limit the type of the memory and the arrangement of the memory and the processor.

[0451] For example, the chip system can be a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on chip (SoC), a central processing unit (CPU), a network processor (NP), a digital signal processor (DSP), a microcontroller unit (MCU), a programmable logic device (PLD) or other integrated chips.

[0452] It should be understood that each step in the above method embodiments can be completed by the integrated logic circuit of the hardware in the processor or the instructions in the form of software. The method steps disclosed in the embodiments of the present application can be directly embodied as hardware processor execution or executed by the combination of hardware and software modules in the processor.

[0453] In the above embodiments, all or part of the processes can be implemented by software, hardware, firmware, or any combination thereof. When implemented by software, all or part of the processes can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes described in the present application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions can be transferred from one website, computer, server or data center to another website, computer, server or data center through wired (such as coaxial cable, optical fiber, digital subscriber line) or wireless (such as infrared, wireless, microwave, etc.) manner. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. that includes one or more available media sets. The available media can be magnetic media (such as floppy disks, hard disks, magnetic tapes), optical media (such as DVDs), or semiconductor media (such as solid state disks (SSD)), etc.

[0454] Those of ordinary skill in the art can understand that all or part of the processes in the above embodiments can be instructed by a computer program to complete the relevant hardware, and the program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the above-mentioned embodiments. The storage medium includes ROM or random access memory (RAM), magnetic disks or optical disks, and various media that can store program codes.

[0455] The above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that they can modify the technical solutions described in the above embodiments, or make equivalent replacements for part of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present application.

Claims

1. A data sharing method, applied to a first electronic device, characterized in that, The method includes: The first electronic device acquires the first operation; Based on the first operation, the first electronic device determines that the first file has been selected; The first electronic device determines that the recipient is the first user and obtains credentials associated with the first user's account, wherein the credentials are obtained by the first electronic device from the server, or sent to the server after being obtained by the first electronic device; The first electronic device sends the first file, encrypted based on the credentials, to the second electronic device, wherein the second electronic device is a device associated with the first user, and the second electronic device needs to obtain the credentials from the server to decrypt the first file; The first electronic device is configured to set a first permission on the first file before sending the first file to the second electronic device. The first permission is set by a first system service module in the operating system of the first electronic device. The first permission is used to indicate that the first user is authorized to perform one or more operations on the first file.

2. The method according to claim 1, characterized in that, The method further includes: Before the first electronic device sends the first file to the second electronic device, the first electronic device displays at least one of the following on the interface: a device list, an application list, and a user list. The first electronic device sends the first file, encrypted based on the credentials, to the second electronic device, specifically including: In response to the operation of selecting the second electronic device in the device list, the first electronic device sends the first file encrypted based on the credentials to the second electronic device; or, In response to the operation of selecting a first application in the application list, the first electronic device sends the first file, encrypted based on the credentials, to the second electronic device through the first application; or, In response to the operation of selecting the first user in the user list, the first electronic device sends the first file encrypted based on the credentials to the second electronic device.

3. The method according to claim 1, characterized in that, The first electronic device sends the first file, encrypted based on the credentials, to the second electronic device, specifically including: In response to an operation triggered on the interface to share the first file, the first electronic device sends the first file, encrypted based on the credentials, to the second electronic device, wherein the interface is an interface for conversing with the first user.

4. The method according to any one of claims 1-3, characterized in that, The method further includes: In response to the operation of sharing the first file on the first interface, the first electronic device sends the first file to a third electronic device associated with the second user; The first electronic device is used to set a second permission for the first file. The second permission is effective when multiple applications on the first electronic device send the first file. The second permission is used to indicate that the second user is authorized to perform one or more operations on the first file.

5. The method according to any one of claims 1-3, characterized in that, The method further includes: The first electronic device determines that the second file has been selected; In response to the operation of sharing the second file on the first interface, the first electronic device sends the second file to a second electronic device associated with the first user; The first electronic device is used to set a third permission for the second file. The third permission is effective when multiple applications on the first electronic device send the second file. The third permission is used to indicate that the first user is authorized to perform one or more operations on the second file.

6. The method according to claim 4, characterized in that, The method further includes: The first electronic device determines that the second file has been selected; In response to the operation of sharing the second file on the first interface, the first electronic device sends the second file to a second electronic device associated with the first user; The first electronic device is used to set a third permission for the second file. The third permission is effective when multiple applications on the first electronic device send the second file. The third permission is used to indicate that the first user is authorized to perform one or more operations on the second file.

7. The method according to claim 1, 2, 3, or 6, characterized in that, The first user belongs to a first group, which also includes a third user. The method further includes: In response to the operation of sharing the first file on the first interface, the first electronic device sends the first file to a fourth electronic device associated with the third user, and the first permission is further used to instruct the third user to perform one or more operations on the first file. or, In response to the operation of sharing the first file on the first interface, the first electronic device sends the first file to the fourth electronic device associated with the third user; wherein, the first electronic device is further configured to set a fourth permission for the first file, the fourth permission being effective when multiple applications on the first electronic device send the first file, the fourth permission being used to instruct the third user to be authorized to perform one or more operations on the first file.

8. The method according to claim 4, characterized in that, The first user belongs to a first group, which also includes a third user. The method further includes: In response to the operation of sharing the first file on the first interface, the first electronic device sends the first file to a fourth electronic device associated with the third user, and the first permission is further used to instruct the third user to perform one or more operations on the first file. or, In response to the operation of sharing the first file on the first interface, the first electronic device sends the first file to the fourth electronic device associated with the third user; wherein, the first electronic device is further configured to set a fourth permission for the first file, the fourth permission being effective when multiple applications on the first electronic device send the first file, the fourth permission being used to instruct the third user to be authorized to perform one or more operations on the first file.

9. The method according to claim 5, characterized in that, The first user belongs to a first group, which also includes a third user. The method further includes: In response to the operation of sharing the first file on the first interface, the first electronic device sends the first file to a fourth electronic device associated with the third user, and the first permission is further used to instruct the third user to perform one or more operations on the first file. or, In response to the operation of sharing the first file on the first interface, the first electronic device sends the first file to the fourth electronic device associated with the third user; wherein, the first electronic device is further configured to set a fourth permission for the first file, the fourth permission being effective when multiple applications on the first electronic device send the first file, the fourth permission being used to instruct the third user to be authorized to perform one or more operations on the first file.

10. The method according to claim 1, 2, 3, 6, 8, or 9, characterized in that, Before the first electronic device sends the first file, encrypted based on the credentials, to the second electronic device, the method further includes: The first electronic device logs into the first account, which belongs to the fourth user.

11. The method according to claim 4, characterized in that, Before the first electronic device sends the first file, encrypted based on the credentials, to the second electronic device, the method further includes: The first electronic device logs into the first account, which belongs to the fourth user.

12. The method according to claim 5, characterized in that, Before the first electronic device sends the first file, encrypted based on the credentials, to the second electronic device, the method further includes: The first electronic device logs into the first account, which belongs to the fourth user.

13. The method according to claim 1, 2, 3, 6, 8, 9, 11, or 12, characterized in that, The first electronic device is configured to set a first permission on the first file before sending the first file to the second electronic device, specifically including: The first electronic device is used to write the field information of the first permission in the first file before sending the first file to the second electronic device; or, The first electronic device is used to send a first message to the server before sending the first file to the second electronic device. The first message includes field information of the first permission and identification information of the first file. The first message is used to instruct the server to save the association between the field information of the first permission and the identification information of the first file.

14. The method according to claim 4, characterized in that, The first electronic device is configured to set a first permission on the first file before sending the first file to the second electronic device, specifically including: The first electronic device is used to write the field information of the first permission in the first file before sending the first file to the second electronic device; or, The first electronic device is used to send a first message to the server before sending the first file to the second electronic device. The first message includes field information of the first permission and identification information of the first file. The first message is used to instruct the server to save the association between the field information of the first permission and the identification information of the first file.

15. The method according to claim 5, characterized in that, The first electronic device is configured to set a first permission on the first file before sending the first file to the second electronic device, specifically including: The first electronic device is used to write the field information of the first permission in the first file before sending the first file to the second electronic device; or, The first electronic device is used to send a first message to the server before sending the first file to the second electronic device. The first message includes field information of the first permission and identification information of the first file. The first message is used to instruct the server to save the association between the field information of the first permission and the identification information of the first file.

16. The method according to claim 1, 2, 3, 6, 8, 9, 11, 12, 14, or 15, characterized in that, The first permission includes read-only permission, or editable permission, or forwarding permission. The editable permission includes one or more of the following: edit permission, save as permission, screenshot permission, screen recording permission, print permission, and copy permission.

17. The method according to claim 4, characterized in that, The first permission includes read-only permission, or editable permission, or forwarding permission. The editable permission includes one or more of the following: edit permission, save as permission, screenshot permission, screen recording permission, print permission, and copy permission.

18. The method according to claim 5, characterized in that, The first permission includes read-only permission, or editable permission, or forwarding permission. The editable permission includes one or more of the following: edit permission, save as permission, screenshot permission, screen recording permission, print permission, and copy permission.

19. The method according to claim 1, 2, 3, 6, 8, 9, 11, 12, 14, 15, 17, or 18, characterized in that, The first file contains sensitive information.

20. The method according to claim 4, characterized in that, The first file contains sensitive information.

21. The method according to claim 5, characterized in that, The first file contains sensitive information.

22. A data sharing method applied to a second electronic device, characterized in that, The method includes: The second electronic device receives a first file sent by the first electronic device, wherein the first file is controlled by a first permission. When an operation is performed on the first file, multiple applications on the second electronic device take effect to control the first file according to the first permission. The multiple applications include the first application. The second electronic device acquires a first operation performed by the first user on the first file in the first application, wherein the first user is associated with the second electronic device; The second electronic device obtains credentials associated with the first user's account from the server using the first user's account; The second electronic device decrypts the first file based on the credentials through the second system service module in the operating system of the second electronic device; The second electronic device determines the first permission through the second system service module, and determines the first operation as one or more operations authorized to be performed on the first file as indicated by the first permission based on the first permission, then the second electronic device responds to the first operation.

23. The method according to claim 22, characterized in that, in, Before determining that the first operation is one or more operations authorized to be performed on the first file as indicated by the first permission, the method further includes: The second electronic device determines that the user performing the first operation is the first user who has been authenticated and has operation permissions for the first file; The second electronic device determines that the first operation is one or more operations authorized to be performed on the first file as indicated by the first permission, including: the second electronic device determines that the first operation is one or more operations authorized to be performed on the first file as indicated by the first permission.

24. The method according to claim 23, characterized in that, The second electronic device determines that the user performing the first operation is the first user who has been authenticated and has operation permissions for the first file, specifically including: The second electronic device determines that the account logged in by the second electronic device is the account of the first user; or, The second electronic device determines that the biometrics of the user performing the first operation match the biometrics of the first user; or, The second electronic device receives a first message from the third electronic device, the first message indicating that the user performing the first operation is the first user who is authenticated and has operation rights to the first file, and the third electronic device is associated with the second electronic device.

25. The method according to any one of claims 22-24, characterized in that, The method further includes: If the second electronic device determines that the first operation does not fall under one or more operations authorized by the first user to perform on the first file as indicated by the first permission, the second electronic device displays a first prompt message, which prompts the user that the second electronic device refuses to respond to the first operation.

26. The method according to any one of claims 22-24, characterized in that, The method further includes: In response to the operation of sharing the first file, the second electronic device sends the first file to a third electronic device associated with the first user.

27. The method according to claim 25, characterized in that, The method further includes: In response to the operation of sharing the first file, the second electronic device sends the first file to a third electronic device associated with the first user.

28. The method according to claim 22, 23, 24, or 27, characterized in that, The method further includes: In response to the operation of sharing the first file, the second electronic device sends the first file to a fourth electronic device associated with the second user.

29. The method according to claim 25, characterized in that, The method further includes: In response to the operation of sharing the first file, the second electronic device sends the first file to a fourth electronic device associated with the second user.

30. The method according to claim 26, characterized in that, The method further includes: In response to the operation of sharing the first file, the second electronic device sends the first file to a fourth electronic device associated with the second user.

31. The method according to claim 22, 23, 24, 27, 29, or 30, characterized in that, When the first file is forwarded by the second electronic device, the first file is set to third permission, and the scope of authorization of the third permission does not exceed the scope of authorization of the first permission.

32. The method according to claim 25, characterized in that, When the first file is forwarded by the second electronic device, the first file is set to third permission, and the scope of authorization of the third permission does not exceed the scope of authorization of the first permission.

33. The method according to claim 26, characterized in that, When the first file is forwarded by the second electronic device, the first file is set to third permission, and the scope of authorization of the third permission does not exceed the scope of authorization of the first permission.

34. The method according to claim 22, 23, 24, 27, 29, 30, 32, or 33, characterized in that, The method further includes: The second electronic device sends a second message to the first electronic device, the second message being used to instruct the first electronic device to authorize the first user to perform a second operation on the first file, the second operation not being one or more operations authorized by the first permission to be performed on the first file by the first user.

35. The method according to claim 25, characterized in that, The method further includes: The second electronic device sends a second message to the first electronic device, the second message being used to instruct the first electronic device to authorize the first user to perform a second operation on the first file, the second operation not being one or more operations authorized by the first permission to be performed on the first file by the first user.

36. The method according to claim 26, characterized in that, The method further includes: The second electronic device sends a second message to the first electronic device, the second message being used to instruct the first electronic device to authorize the first user to perform a second operation on the first file, the second operation not being one or more operations authorized by the first permission to be performed on the first file by the first user.

37. The method according to claim 22, 23, 24, 27, 29, 30, 32, 33, 35, or 36, characterized in that, The method further includes: The second electronic device sends a third message to the first electronic device, the third message being used to instruct the first electronic device to authorize the first user to perform a forwarding operation on the first file.

38. The method according to claim 25, characterized in that, The method further includes: The second electronic device sends a third message to the first electronic device, the third message being used to instruct the first electronic device to authorize the first user to perform a forwarding operation on the first file.

39. The method according to claim 26, characterized in that, The method further includes: The second electronic device sends a third message to the first electronic device, the third message being used to instruct the first electronic device to authorize the first user to perform a forwarding operation on the first file.

40. The method according to claim 22 or 23 or 24 or 27 or 29 or 30 or 32 or 33 or 35 or 36 or 38 or 39, characterized in that, The second electronic device displays a first identifier, which is used to indicate that the first file is an encrypted file.

41. The method according to claim 25, characterized in that, The second electronic device displays a first identifier, which is used to indicate that the first file is an encrypted file.

42. The method according to claim 26, characterized in that, The second electronic device displays a first identifier, which is used to indicate that the first file is an encrypted file.

43. The method according to claim 22 or 23 or 24 or 27 or 29 or 30 or 32 or 33 or 35 or 36 or 38 or 39 or 41 or 42, characterized in that, The first permission is obtained by the second electronic device from the first file; or, the first permission is obtained by the second electronic device from the server.

44. The method according to claim 25, characterized in that, The first permission is obtained by the second electronic device from the first file; or, the first permission is obtained by the second electronic device from the server.

45. The method according to claim 26, characterized in that, The first permission is obtained by the second electronic device from the first file; or, the first permission is obtained by the second electronic device from the server.

46. ​​The method according to claim 22 or 23 or 24 or 27 or 29 or 30 or 32 or 33 or 35 or 36 or 38 or 39 or 41 or 42 or 44 or 45, characterized in that, The first permission includes read-only permission, or editable permission, or forwarding permission. The editable permission includes one or more of the following: edit permission, save as permission, screenshot permission, screen recording permission, print permission, and copy permission.

47. The method according to claim 25, characterized in that, The first permission includes read-only permission, or editable permission, or forwarding permission. The editable permission includes one or more of the following: edit permission, save as permission, screenshot permission, screen recording permission, print permission, and copy permission.

48. The method according to claim 26, characterized in that, The first permission includes read-only permission, or editable permission, or forwarding permission. The editable permission includes one or more of the following: edit permission, save as permission, screenshot permission, screen recording permission, print permission, and copy permission.

49. The method according to claim 22 or 23 or 24 or 27 or 29 or 30 or 32 or 33 or 35 or 36 or 38 or 39 or 41 or 42 or 44 or 45 or 47 or 48, characterized in that, The method further includes: The second electronic device receives a second file, which is encrypted with credentials corresponding to the second user's account; The second electronic device acquires the first user's operations on the second file within the first application; The second electronic device obtains the credentials corresponding to the first user's account based on the first user's account; The second electronic device determines not to decrypt the second file based on the credentials corresponding to the first user's account.

50. The method according to claim 25, characterized in that, The method further includes: The second electronic device receives a second file, which is encrypted with credentials corresponding to the second user's account; The second electronic device acquires the first user's operations on the second file within the first application; The second electronic device obtains the credentials corresponding to the first user's account based on the first user's account; The second electronic device determines not to decrypt the second file based on the credentials corresponding to the first user's account.

51. The method according to claim 26, characterized in that, The method further includes: The second electronic device receives a second file, which is encrypted with credentials corresponding to the second user's account; The second electronic device acquires the first user's operations on the second file within the first application; The second electronic device obtains the credentials corresponding to the first user's account based on the first user's account; The second electronic device determines not to decrypt the second file based on the credentials corresponding to the first user's account.

52. An electronic device, characterized in that, The electronic device includes one or more processors and one or more memories; wherein the one or more memories are coupled to the one or more processors, and the one or more memories are used to store computer program code, the computer program code including computer instructions, which, when executed by the one or more processors, cause the electronic device to perform the method as described in any one of claims 1-21 or 22-51.

53. A computer storage medium, characterized in that, The computer storage medium stores a computer program, which includes program instructions that, when executed on an electronic device, cause the electronic device to perform the method as described in any one of claims 1-21 or 22-51.

54. A computer program product, when run on a computer, causes the computer to perform the method as described in any one of claims 1-21 or 22-51.

Citation Information

Patent Citations

  • Shared file access method, device and equipment and storage medium

    CN108111511A

  • Content sharing method and device, electronic equipment, storage medium and program product

    CN115550298A