Permission access control method and equipment
By obtaining the usage data of application functions in the terminal device to generate permission authorization information, and performing refined permission access control, the security risks existing in permission access control in the prior art are solved, and the security of the terminal device and the protection level of user data are improved.
Patent Information
- Application Number
- CN202311454192.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-02
- Publication Date
- 2025-05-06
AI Technical Summary
The existing permission access control technology has security risks. Malicious APPs can make calls, send text messages or record sounds without user operations. The black and white listing scheme still has security risks, making it difficult to effectively protect user personal information.
By obtaining the usage data of application functions in the terminal device, generating permission authorization information, and performing permission access control based on this information, avoiding sensitive permissions for non-essential functions and improving access security.
It realizes more refined control over permission access, reduces the risk of malicious APP obtaining permissions, and improves the security of terminal devices and the protection level of user data.
Smart Images

Figure CN119939564A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of terminal technology, and in particular to a permission access control method and device. Background Art
[0002] With the rapid development of new-generation information technologies such as the Internet, big data, cloud computing, artificial intelligence, and blockchain, the number of users using terminals has increased, and the number of various applications (APPs) that can be installed on the terminals has also increased.
[0003] In order to protect the user's personal information, the industry has proposed the technology of permission access control. In one permission access control scheme, the APP obtains permission authorization when it is installed, or the user grants permission when the APP is running, such as setting it to allow only during use or always allowed. In this way, after the APP obtains the permission, it can use the permission at any time and in any state. There are still certain security risks. For example, malicious APPs can make calls, send text messages or record without user operation. In another permission access control scheme, on the basis of the first scheme, a black and white list of end-cloud collaboration can be added. Only APPs in the white list are allowed to obtain and use the corresponding permissions, and APPs in the black list are not allowed to apply for permission to use. This scheme still has security risks, and a high-security permission access control scheme needs to be proposed urgently. Summary of the invention
[0004] In order to solve the above technical problems, a permission access control method and device are provided. The technical solution provided in this application can effectively perform permission access control and improve the security of the device.
[0005] In order to achieve the above technical objectives, the following technical solutions are provided:
[0006] In a first aspect, a permission access control method is provided, which can be applied to a terminal device or a component (such as a chip) capable of realizing the function of a terminal device. The method may include: the terminal device obtains usage data of at least one application function of a first application; the terminal device generates permission authorization information for at least one application function based on the usage data of at least one application function, wherein the permission authorization information is used to indicate whether the application function is allowed to use the corresponding permission; the terminal device receives a permission application request for a first permission for a first application function, wherein the first application function belongs to at least one application function; in response to the permission application request, the terminal device refuses to grant the first permission to the first application function, or grants the first permission to the first application function based on the permission authorization information for at least one application function generated by the terminal device.
[0007] In this method, the application function of the application is used as the granularity, and authorization is performed or denied according to the permission application request of the application function, which can prevent unnecessary functions of an application from accessing sensitive permissions of the system and improve access security.
[0008] In addition, in this method, as the user uses the application functions, the terminal can obtain more usage data and determine more accurate permission authorization information based on more usage data, thereby improving the accuracy of permission access control.
[0009] In a possible implementation, it also includes: the terminal device displays a first interface, the first interface includes information of a page where a first application function is located, and authorization inquiry information, the authorization inquiry information is used to ask the user whether to allow the first application function to use the first permission, and the first application function belongs to at least one application function; the terminal device receives permission authorization information for the first application function input by the user.
[0010] In this method, the terminal can ask the user whether to grant the first permission to the first application function, so that the user can control the access rights to the application function, reduce the probability of user privacy data leakage, and improve the security of the terminal. In addition, the user can set the access rights to the application function, making the control granularity of the access rights more refined, further improving the access control security of the terminal.
[0011] In a possible implementation, the terminal device refuses to grant the first permission to the first application function, or grants the first permission to the first application function according to the permission authorization information for at least one application function generated by the terminal device, including:
[0012] If there is no user permission authorization information for the first application function, and there is permission authorization information generated by the terminal device for the first application function, then based on the permission authorization information generated by the terminal device for the first application function, refuse to grant the first permission to the first application function, or grant the first permission to the first application function, wherein the permission authorization information generated by the terminal device for the first application function belongs to the permission authorization information generated by the terminal device for at least one application function.
[0013] In a possible implementation, if there is user permission authorization information for the first application function, the first permission is denied to the first application function, or the first permission is granted to the first application function according to the user permission authorization information for the first application function.
[0014] This method means that if there is no user permission authorization information for the first application function, it is determined whether to authorize the first application function based on the permission authorization information generated by the terminal device; if there is user permission authorization information for the first application function, it is determined whether to authorize the first application function based on the user's permission authorization information for the first application function, thereby taking into account flexibility and fully respecting the user's authorization choice.
[0015] In a possible implementation, it also includes: sending usage data of at least one application function of the first application to the server; receiving permission authorization information generated by the server for the at least one application function from the server, wherein the permission authorization information generated by the server for the at least one application function is generated by the server based on the usage data of the at least one application function.
[0016] In this method, the server can refer to or determine the permission authorization information of the application function based on the usage data of the application function of multiple users, which is equivalent to considering the habitual settings of multiple users for permission access control. Therefore, the obtained permission authorization information is more accurate. Based on this, according to the accurate permission authorization information, more secure permission access control can be provided during the use of the terminal, thereby improving the security of user data.
[0017] In one possible implementation, the terminal device refuses to grant the first permission to a first application function, or grants the first permission to the first application function, based on the permission authorization information generated by the terminal device for at least one application function, including: if there is no user permission authorization information for the first application function, and there is permission authorization information generated by a server for the first application function, then, based on the permission authorization information generated by the server for the first application function, refuses to grant the first permission to the first application function, or grants the first permission to the first application function, wherein the permission authorization information generated by the server for the first application function belongs to the permission authorization information generated by the server for at least one application function.
[0018] In one possible implementation, if there is no permission authorization information generated by the server for the first application function, and there is permission authorization information generated by the terminal device for the first application function, then based on the permission authorization information generated by the terminal device for the first application function, the first permission is denied to the first application function, or the first permission is granted to the first application function.
[0019] That is to say, whether to grant the first permission to the first application function can be flexibly determined based on the permission authorization information for the first application function generated by the terminal device and the permission authorization information for the first application function generated by the server.
[0020] In one possible implementation, the permission authorization information includes at least one of the following: an application function that is allowed to be granted the first permission, an application function that is prohibited from being granted the first permission, the permission that the first application function is allowed to use, the permission that the first application function is prohibited from using, and authorization suggestions for different types of application functions.
[0021] In a possible implementation, the authorization suggestions for different types of application functions include at least one of the following suggestions: for an application function that applies for the first permission for the first time, ask the user whether to grant the first permission to the application function; for a common function that uses the first permission, allow the first permission to be granted to the common function; for an application function that does not need to use the first permission, do not allow the first permission to be granted to the application function; when the permission authorization information is generated by the server, for an application function whose authorized user ratio is higher than a first threshold and applies for the first permission, allow the first permission to be granted to the application function. Optionally, the ratio can be, but is not limited to, expressed in percentage.
[0022] In a possible implementation, the commonly used functions using the first permission include at least one of the following: an application function using the first permission with a frequency higher than a second threshold, and an application function with a time interval between two consecutive uses of the first permission less than a third threshold.
[0023] In this method, it is possible to make an intelligent decision on whether to authorize the first permission of the first application based on the various situations included in the permission authorization information.
[0024] For example, the terminal has already run some application functions and knows the application functions that frequently use the first permission. Considering that the application functions' application for the first permission is generally reasonable, the terminal can automatically grant the corresponding first permission for the application functions that are frequently used by users without the need for users to intervene in permission control.
[0025] For another example, some application functions have a relatively deep way of obtaining location information permissions, or a certain application function does not match the main function of the application, is triggered occasionally and at a low frequency, and rarely needs to obtain location information permissions. In this case, when the application function applies for location information permissions, the terminal device can refuse authorization or ask the user whether to authorize. For another example, when using a dictionary application, the dictionary application interface does not display any application functions related to location information permissions, but the application function in the dictionary application applies for location information permissions. In this case, the terminal device refuses authorization or asks the user whether to authorize.
[0026] For example, after a new map application is installed, navigation is the main application function on the homepage of the map application, so the navigation function is considered to be an application function that can obtain location information permissions. In the message interface, the message function does not have functions related to location information permissions, so the message function cannot obtain location information permissions.
[0027] In a possible implementation, the further step includes: the terminal device presenting a percentage of authorized users who have granted the first permission to the first application function.
[0028] In this way, when suspicious application functions appear, the terminal device can display the proportion of users who have authorized the function based on big data statistics for users to use in authorization decisions, avoiding the problem that users cannot judge whether to grant permissions, and improving the usability of the terminal device.
[0029] In one possible implementation, the usage data of the application function includes: context information corresponding to the application function, and / or, permission records corresponding to the application function, wherein the context information includes at least one of the following information: device information, application information, and user operation information, the device information is used to indicate the status of the terminal device, the application information is used to indicate the status of the first application, and the user operation information is used to indicate information generated by the user operating the first application.
[0030] In a possible implementation, the permission record corresponding to the application function includes: a record of historically applying for authorization or rejection of one or more permissions for the application function.
[0031] In a second aspect, a permission access control method is provided, which is applied to a server or related components (such as a chip), including: the server receives usage data of at least one application function of a first application by multiple users from multiple terminal devices; the server generates permission authorization information for at least one application function based on the usage data of at least one application function of the first application by multiple users, wherein the permission authorization information is used to indicate whether the application function is allowed to use the corresponding permission; the server sends the permission authorization information of at least one application function to multiple terminal devices.
[0032] This application collects and statistically analyzes the usage data of application functions, automatically generates permission authorization information for application functions, and can perform permission access control in a more fine-grained manner in the application function dimension, solving the problem of unrestricted usage permissions after all application functions under the application are granted unified permissions in the application dimension.
[0033] In one possible implementation, the permission authorization information includes at least one of the following: an application function that is allowed to be granted the first permission, an application function that is prohibited from being granted the first permission, the permission that the first application function is allowed to use, the permission that the first application function is prohibited from using, and authorization suggestions for different types of application functions.
[0034] In one possible implementation, the authorization suggestions for different types of application functions include at least one of the following suggestions: for an application function that applies for the first permission for the first time, asking the user whether to grant the first permission to the application function; for commonly used functions that use the first permission, allowing the first permission to be granted to the commonly used functions; for application functions that do not need to use the first permission, not allowing the first permission to be granted to the application functions; for application functions whose authorized user ratio is higher than the first threshold and which apply for the first permission, allowing the first permission to be granted to the application functions.
[0035] In a possible implementation, the commonly used functions using the first permission include at least one of the following: an application function using the first permission with a frequency higher than a second threshold, and an application function with a time interval between two consecutive uses of the first permission less than a third threshold.
[0036] In one possible implementation, the usage data of the application function includes: context information corresponding to the application function, and / or, permission records corresponding to the application function, wherein the context information includes at least one of the following information: device information, application information, and user operation information, the device information is used to indicate the status of the terminal device, the application information is used to indicate the status of the first application, and the user operation information is used to indicate information generated by the user operating the first application.
[0037] In a possible implementation, the permission record corresponding to the application function includes: a record of historically applying for authorization or rejection of one or more permissions for the application function.
[0038] Compared with the related technologies, most users (especially the elderly) find it difficult to understand the usage scenarios of application permissions, so they cannot judge whether authorization is needed and it is difficult to manage application authorization. In this application, the server can collect application function context information and user authorization results for application functions, and generate permission authorization information for application functions. The terminal can grant permissions, prohibit permissions, or ask users whether to authorize based on the percentage of authorized users based on this permission authorization information, which reduces the difficulty of manual authorization and makes it easier to manage application authorization.
[0039] In a third aspect, a terminal device is provided, which has the function of implementing the method described in the first aspect and any possible implementation thereof. The function can be implemented by hardware, or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. For example, it includes a processing module and a storage module. The processing module can perform operations or data processing related to the control and / or communication of at least one of the other elements of the device. The storage module can store data or instructions required by the device, etc.
[0040] In a fourth aspect, a server is provided, which has the function of implementing the method described in the second aspect and any possible implementation thereof. The function can be implemented by hardware, or by hardware executing corresponding software implementation. The hardware or software includes one or more modules corresponding to the above functions. For example, it includes a processing module and a storage module. The processing module can perform operations or data processing related to the control and / or communication of at least one of the other elements of the device. The storage module can store data or instructions required by the device, etc.
[0041] In a fifth aspect, a computer-readable storage medium is provided. The computer-readable storage medium stores a computer program (also referred to as an instruction or code), and when the computer program is executed by a device, the device executes the method in any of the above aspects or any implementation of any of the aspects.
[0042] According to a sixth aspect, a computer program product is provided. When the computer program product runs on a device, the device executes a method of any aspect or any implementation scheme of any aspect.
[0043] In a seventh aspect, a circuit system is provided, the circuit system comprising a processing circuit, and the processing circuit is configured to execute a method of any aspect or any implementation of any aspect.
[0044] In an eighth aspect, a chip system is provided, comprising at least one processor and at least one interface circuit, wherein the at least one interface circuit is used to perform transceiver functions and send instructions to the at least one processor, and when the at least one processor executes the instructions, the at least one processor executes a method in any aspect or any one of the embodiments of any aspect.
[0045] In a ninth aspect, a chip is provided, comprising a processor, wherein the processor is coupled to a memory, wherein the memory stores program instructions, and wherein the method in any of the above aspects or any one of the embodiments of any aspect is implemented when the program instructions stored in the memory are executed by the processor.
[0046] In a tenth aspect, a system is provided, comprising a terminal and a server in any of the above aspects or any implementation scheme of any aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] Figure 1A Schematic diagram of the packages.xml file provided for related technologies;
[0048] Figure 1B Schematic diagram of the system architecture for permission access control provided for related technologies 1;
[0049] Figure 1CA schematic diagram of a method for providing permission access control for related technologies;
[0050] Figure 1D Schematic diagram of the system architecture for permission access control provided for related technologies Figure 2 ;
[0051] Figure 2 A schematic diagram of the system architecture of the permission access control provided in the embodiment of the present application;
[0052] Figure 3 A schematic diagram of context information of an application function provided in an embodiment of the present application;
[0053] Figure 4 A schematic diagram of the system architecture of the permission access control provided in the embodiment of the present application;
[0054] Figure 5 A schematic diagram of the hardware structure of the device provided in the embodiment of the present application;
[0055] Figure 6 A schematic diagram of an interface provided in an embodiment of the present application;
[0056] Figure 7-Figure 9 A schematic diagram of a method provided in an embodiment of the present application;
[0057] Figure 10-12 A schematic diagram of a scenario of a permission access control method provided in an embodiment of the present application;
[0058] Fig.13 , Fig.14 A flowchart of a permission access control method provided in an embodiment of the present application;
[0059] Fig.15 A schematic diagram of a scenario of a permission access control method provided in an embodiment of the present application;
[0060] Fig.16 A schematic diagram of the structure of the device provided in the embodiment of the present application;
[0061] Fig.17 A schematic diagram of the structure of the chip system provided in an embodiment of the present application. DETAILED DESCRIPTION
[0062] At present, in order to protect the personal information security of users, the industry provides a permission access control technology. In this technology, for normal system permissions, when using the permission, it is necessary to explicitly declare it in the Manifest.xml file; for sensitive permissions, not only do they need to be explicitly declared in the Manifest.xml, but the user also needs to authorize when the APP uses the permission. When the APP is installed, the system will save the permission information in the Manifest.xml in the / … / packages.xml file. Figure 1A An example of a packages.xml file is shown in Figure 1. The permission information is used to declare the permissions that the system permits the APP to obtain. When the APP is started, the system reads the permission information in package.xml into memory. Figure 1B When an APP accesses a resource, it calls the system service interface (such as the WifiManager API). The system service compares the resource's required permissions with the permissions in the memory through the package manager service (PMS) to make access control decisions. Figure 1C An example process of this permission access control method is shown.
[0063] Table 1-1 shows an example of permission authorization information in this technology. It can be seen that for different applications, the system can authorize the application to obtain certain permissions, or prohibit the application from obtaining certain permissions.
[0064] Table 1-1 Permission authorization information
[0065]
[0066] Another permission access control method, such as Figure 1D The cloud side maintains a permission management policy library, which includes a blacklist and a whitelist. The blacklist includes some apps, and the whitelist includes some apps. The cloud side sends the blacklist and whitelist to the client side, and the client side sets them accordingly, allowing apps in the whitelist to obtain sensitive permissions of the system locally, and prohibiting apps in the blacklist from obtaining sensitive permissions of the system.
[0067] Although the above two methods can reduce the probability of malicious APPs illegally obtaining permissions to a certain extent, once the APP obtains the corresponding authorization, the subsequent APP will not be restricted from using the permission, and there are still security risks such as leaking user privacy data.
[0068] To solve the above technical problems, an embodiment of the present application provides a permission access control method, which performs permission access control on permission applications for application functions based on the granularity of application functions, thereby making the granularity of permission access control more refined, avoiding unnecessary application functions from calling sensitive permissions of the system, and thereby improving the security of the system.
[0069] The technical solutions in the embodiments of the present application are described below in conjunction with the accompanying drawings in the embodiments of the present application. Wherein, in the description of the embodiments of the present application, the terms used in the following embodiments are only for the purpose of describing specific embodiments, and are not intended to be used as limitations on the present application. As used in the specification and the appended claims of the present application, the singular expressions "one", "a kind of", "said", "above", "the" and "this" are intended to include expressions such as "one or more", unless there is a clear indication to the contrary in the context. It should also be understood that in the following embodiments of the present application, "at least one", "one or more" refer to one or more (including two).
[0070] References to "one embodiment" or "some embodiments" etc. described in this specification mean that one or more embodiments of the present application include specific features, structures or characteristics described in conjunction with the embodiment. Thus, the statements "in one embodiment", "in some embodiments", "in some other embodiments", "in some other embodiments", etc. that appear in different places in this specification do not necessarily refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "including", "comprising", "having" and their variations all mean "including but not limited to", unless otherwise specifically emphasized in other ways. The term "connection" includes direct connection and indirect connection, unless otherwise specified. "First" and "second" are used for descriptive purposes only and cannot be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated.
[0071] In the embodiments of the present application, the words "exemplarily" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "exemplarily" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of words such as "exemplarily" or "for example" is intended to present related concepts in a specific way.
[0072] In the technical solution of the embodiment of this application, the collection, storage, use, processing, transmission, provision and disclosure of user personal information involved are in compliance with the provisions of relevant laws and regulations and do not violate public order and good morals. For example, in the technical solution of the embodiment of this application, the processing of user personal information is carried out with the authorization of the user, which is uniformly explained here and will not be repeated below.
[0073] The embodiment of the present application provides a permission access control method, which is applicable to a permission access control system, and can better protect terminal security and user privacy when an APP applies for permission. Figure 2 A schematic diagram of a permission access control system to which the method is applicable.
[0074] The system may include a terminal 201. Optionally, the terminal 201 includes but is not limited to a mobile phone, a tablet, a computer, a netbook, a smart screen, a smart panel and other devices.
[0075] Various types of APPs can be installed in the terminal 201. After authorization, the terminal 201 can obtain the context information corresponding to the APP and the usage record of the corresponding permissions of the APP functions. Among them, the context information can be used to describe the application functions of the APP, such as the navigation function of the map application. The terminal 201 can perform fine-grained permission authorization management at the APP function level based on the context information corresponding to the APP and the permission record. For example, the terminal 201 authorizes the navigation function of the home page of the map application to use the location information permission, but prohibits the message page in the map application from using the location information permission.
[0076] Context information can also be called context state.
[0077] Figure 3 An example of context information corresponding to an application function is shown. The context information may include at least one of the following information: device information, application information, and user operation information. The device information may indicate the state of the terminal 201, such as whether the terminal 201 is in a locked screen state or unlocked state; the device information may indicate the network state of the terminal 201, such as whether the network state of the terminal 201 is connected to the network or disconnected from the network (such as in flight mode); the device information may indicate the current time of the terminal 201, such as the time when the terminal 201 is locked, unlocked, connected to the network, disconnected from the network, etc. The device information may also be referred to as the device state.
[0078] Application information can indicate the status of an application, such as the package information of the application, whether the application is running in the foreground or background, the activity currently displayed by the application, the way to launch the activity, the window information of the activity interface (such as full screen or non-full screen status), the information of the activity interface, the task stack of the activity, the name of the activity corresponding to the activity jump scene, or the name of the activity corresponding to the APP foreground and background state switching scene, and the time when the application status changes. For example, the name of the activity before the activity jumps, the name of the activity after the activity jumps, the name of the activity before the activity switches to the background, and the name of the activity displayed on the interface after the activity switches to the background. Application information can also be called application status.
[0079] Optionally, the method of launching the activity includes but is not limited to: launching the activity by triggering a user operation, jumping to another application to launch the corresponding activity. The task stack can be used to store the activity information of the APP. For example, the information of the last few interfaces of the APP can be stored in the stack.
[0080] User operation information may represent information generated by user operation of an application. Optionally, user operation information includes but is not limited to at least one of the following information: the type of user interface (UI) operation event, the component identifier targeted by the UI operation, the activity to which the component belongs, and the time of the UI operation. For example, when a user clicks a button on the interface, the type of operation event is click, and the name of the operated component is button. Application operation information may also be referred to as application status.
[0081] The one or more context information mentioned above can describe the application function. For example, when the phone is unlocked, the phone runs a map application in the foreground, and in response to the user clicking the navigation button, the phone applies for location information permission to perform the navigation task. It should be noted that the context information corresponding to the application function can also be other information. As long as it can be used to describe the application function, it can be used as the context information corresponding to the application function.
[0082] Alternatively, if Figure 2 The system may further include a server 202. The server 202 may be used to generate an APP permission management policy based on big data analysis, which is a policy for whether to grant the application function of the APP to use the corresponding permission. The server 202 may send the permission management policy to the terminal 201, and the terminal 201 may perform fine-grained management of the access rights of the application function according to the permission management policy.
[0083] It should be noted that the “for” mentioned in the embodiments of the present application means that it can be used for, and is not limited to being specifically used for. In other words, it means that it can have the uses described in the embodiments of the present application, and can also have other uses.
[0084] Figure 4 Another example of a system architecture provided by an embodiment of the present application is shown. The system includes a terminal. The terminal may include an application layer and a framework layer. Optionally, the application layer may include an application 402.
[0085] Optionally, the framework layer may include a usage record engine 403, a context engine 404, an application operations management (AppOps) module 405, an activity manager service 407, a package manager service 408, an input manager service 409, and a window manager service 410. The application operations management module 405 may include a permission policy engine 406.
[0086] Context engine 404: can be used to obtain context information corresponding to application functions.
[0087] As a possible implementation, a provider can be defined and implemented in the context engine 404. As one of the four major components of the system, the provider can provide an interface exposed to the outside. The PMS can call the interface provided by the provider and send the context information related to the application package to the context engine 404. For example, when the APP is installed and accesses resources, the PMS collects the package information of the application and reports the collected package information to the context engine 404.
[0088] Another provider can also be implemented in the context engine 404, and the activity manager service (AMS) can call the provider to report context information related to the application activity to the context engine 404. For example, when the activity jumps or the foreground and background states of the APP are switched, the AMS reports the name of the current activity, the task stack of the activity, and other information.
[0089] Another provider may be implemented in the context engine 404, and the window manager service (WMS) may call the provider to report context information related to the application window, such as reporting the window information of the interface corresponding to the activity.
[0090] Another provider may be implemented in the context engine 404, and the input manager service (IMS) may call the provider to report user operation information.
[0091] The above only provides an example of how the context engine 404 obtains context information. In other embodiments, the context engine 404 may also obtain context information in other ways, such as setting a provider and obtaining corresponding context information from PMS, WMS, AMS, and IMS through the provider.
[0092] As a possible implementation, the context engine 404 collects device status by subscribing to system broadcasts. For example, subscribing to system lock screen broadcasts, collecting device lock screen events and corresponding occurrence times. Subscribing to system unlock broadcasts, collecting device unlock events and corresponding occurrence times. Subscribing to system network status broadcasts, collecting network status change events and corresponding occurrence times. Subscribing to system flight mode broadcasts, collecting flight mode on / off events and corresponding occurrence times.
[0093] After the context engine 404 obtains the context information corresponding to the application function, it may send the context information to the usage record engine 403 .
[0094] The application operation management module 405 may be used to count the permission records of application functions and report the permission records to the usage record engine 403 .
[0095] Usage record engine 403: can be used to generate permission authorization information of the application function based on the permission record of the application function and the context information corresponding to the application function.
[0096] The permission policy engine 406 can be used to perform fine-grained permission authorization management for application functions.
[0097] Optionally, the cloud-side server may include a security control center 411. The security control center 411 may be used to generate fine-grained permission management policies for application functions based on big data analysis. Optionally, the application layer of the terminal may also include a permission policy management module 401. The permission policy management module 401: may be used to obtain permission management policies from the security control center 411, and the terminal performs permission access control on application functions based on the permission management policies.
[0098] Optionally, the cloud server may be, but is not limited to, a server corresponding to the application market.
[0099] The system architecture illustrated in the embodiment of the present application does not constitute a specific limitation on the system architecture. In other embodiments of the present application, the permission access control system may include more or fewer devices than shown in the figure, and the devices may communicate with each other in a suitable connection manner.
[0100] Optionally, the terminal 201, the server 202 and other devices in the embodiment of the present application can be implemented by different devices, or some devices can be integrated together. Figure 5 This can be achieved by using the devices in the Figure 5 The hardware structure diagram of the device provided in the embodiment of the present application is shown in FIG. The device includes at least one processor 501 , a memory 503 and at least one communication interface 502 . The memory 503 may also be included in the processor 501 .
[0101] It is understood that the structures and forms illustrated in the embodiments of the present application do not constitute specific limitations on the device. In other embodiments of the present application, the device may include more or fewer components than shown in the figure, or combine certain components, or split certain components, or arrange the components differently. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.
[0102] The processor 501 may be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the program of the present application.
[0103] There may be communication lines between the above components, and the communication lines may include a path to transmit information between the above components.
[0104] Communication interface 502, used to communicate with other devices. In the embodiment of the present application, the communication interface can be a module, a circuit, a bus, an interface, a transceiver or other device capable of realizing a communication function, used to communicate with other devices. Optionally, when the communication interface is a transceiver, the transceiver can be an independently arranged transmitter, which can be used to send information to other devices, and the transceiver can also be an independently arranged receiver, which is used to receive information from other devices. The transceiver can also be a component that integrates the functions of sending and receiving information, and the embodiment of the present application does not limit the specific implementation of the transceiver.
[0105] The memory 503 may be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store the desired program code in the form of an instruction or data structure and can be accessed by a computer, but is not limited thereto. The memory may exist independently and be connected to the processor via a communication line. The memory may also be integrated with the processor.
[0106] The memory 503 is used to store computer-executable instructions for implementing the solution of the present application, and the execution is controlled by the processor 501. The processor 501 is used to execute the computer-executable instructions stored in the memory 503, thereby implementing the method provided in the following embodiments of the present application.
[0107] Optionally, the computer-executable instructions in the embodiments of the present application may also be referred to as application code, instructions, computer program or other names, which are not specifically limited in the embodiments of the present application.
[0108] In a specific implementation, as an embodiment, the processor 501 may include one or more CPUs, such as Figure 5 CPU0 and CPU1 in.
[0109] In a specific implementation, as an embodiment, the device may include multiple processors, such as Figure 5 501 and 504 in the embodiment of the present invention. Each of these processors may be a single-CPU processor or a multi-CPU processor. The processor herein may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0110] Understandably, Figure 5The illustrated structure does not constitute a specific limitation of the device. In other embodiments of the present application, the device may include more or fewer components than shown in the figure, or combine some components, or split some components, or arrange the components differently. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.
[0111] The following mainly takes the case where the terminal 201 is a mobile phone as an example to illustrate the permission access control method provided in the embodiment of the present application.
[0112] A user can use a mobile phone to manage permissions for an application or an application function of an application. As a possible implementation method, the terminal device displays a first interface, which includes information about a page where a first application function is located and authorization inquiry information. The authorization inquiry information is used to inquire whether the user allows the page where the first application function is located to use the first permission. The terminal device can receive permission authorization information for the first application function input by the user on the first interface.
[0113] For example, Figure 6 (a) shows a mobile phone display interface 601. Interface 601 may include map application related permissions. Figure 6 In (a), the interface 601 includes the statistics of the map application's access to privacy permissions in the past three days, such as the number of accesses to the location information permission 601a is 2307, and the access to the camera, microphone, media and files, and address book permissions is prohibited. Figure 6 In (a), interface 601 may also include access permissions for the map application to other permissions, such as the system prohibiting the installation of other applications within the map application, prohibiting the map application from being displayed as a floating window, and allowing the map application to pop up in the background.
[0114] Taking the first application function as the address search function of the map application and the first interface as interface 602 as an example, in response to the user clicking the area where the location information permission 601a is located, the mobile phone can jump to the following interface: Figure 6The interface 602 shown in (b) of FIG. 602 may include information of a certain page 602a of the map application, such as information of the home page where the address search function of the map application is located. Optionally, the interface 602 may also include the name of the page 602a, such as the home page 602b. The interface 602 may also include authorization inquiry information "Do you agree to authorize the home page where the address search function is located to use the location information permission?", as well as a "yes" button and a "no" button. The user can determine whether the home page of the map application needs to use the location information permission. If the user determines that he agrees to authorize the home page of the map application to use the location information permission, he can click the "yes" button. In response to the user clicking the "yes" button, the mobile phone determines to allow the home page of the map application to apply for and use the location information permission. Subsequently, when the user uses the corresponding application function (such as finding a place and taking a bus) in the home page of the map application, the map application can apply for the location information permission from the mobile phone system, and the system grants the permission to the map application. In this way, after the map application obtains the location information permission, the user can realize the application functions such as finding a place and taking a bus on the home page.
[0115] Similarly, the user can also manage the permissions of other pages of the map application. Figure 6 Swipe left in the interface 602 shown in (b), triggering the mobile phone to jump to the Figure 6 Interface 603 shown in (c) includes information of another page 603a of the map application. The user can determine whether the message page of the map application needs to use the location information permission. After judgment, the message page is mainly used to view messages and does not need to use the location information permission, then the user can click the "No" button. In response to the user clicking the "No" button, the mobile phone determines to prohibit the message page of the map application from applying for and using the location information permission. Subsequently, the user uses the corresponding application function in the message page (such as clicking to view the message). If the map application applies to the system for location information permission, the mobile phone refuses to grant the map application the permission.
[0116] Similarly, the user can set permissions for at least one application function of the application. The mobile phone can store the user's permission authorization information for one or more application functions of the application. Table 1-2 shows an example of permission authorization information. Among them, the user allows the map application homepage, such as navigation and taxi functions, to use location information permissions, and also allows nearby pages, such as surrounding tour functions, and message viewing functions on the message page, to use location information permissions.
[0117] Table 1-2 Permission authorization information
[0118]
[0119] The method of the embodiment of the present application can adopt different permission management strategies for different application functions of the same APP, such as allowing the navigation function of the map application to use location information, and prohibiting other application functions of the map application from using location information. The granularity of permission management is made more refined, and the APP can reasonably apply for permission according to the granularity of application functions. It avoids some suspicious functions from calling sensitive permissions due to the coarse granularity of permission access control, improves terminal security, and ensures the security of users' personal information.
[0120] Figure 6 In the embodiment, the permission control is performed on the application functions in the page at the page level. In other embodiments, the permission control can also be performed at the application function level. For example, permission A is granted to application function B in a page, and permission A is denied to application function C in the page.
[0121] As a possible implementation, the terminal device displays a first interface, which includes information about a page where a first application function is located and authorization inquiry information, wherein the authorization inquiry information is used to inquire whether the user allows the first application function to use the first permission. The terminal device can receive permission authorization information for the first application function input by the user in the first interface. For example, the terminal device displays an interface, which includes information about the homepage where an address search function of a map application is located, and authorization inquiry information, which is used to inquire whether the user allows the address search function to use the corresponding permission.
[0122] like Figure 7 An exemplary process of the permission access control method of an embodiment of the present application is shown. Figure 7 , the method may include the following steps:
[0123] S101. A terminal device obtains usage data of at least one application function of a first application.
[0124] The usage data of the application function may include: context information corresponding to the application function, and / or permission records corresponding to the application function. The context information corresponding to the application function includes at least one of the following information: device information, application information, and user operation information. For a detailed introduction to the context information, please refer to the above embodiment. The permission record corresponding to the application function is: a record of the authorization or refusal of one or more permissions applied for the application function in the past.
[0125] As a possible implementation, Figure 7 , S101 may include the following S101a-S101c:
[0126] S101a, PMS reports the package information of the first application to the context state engine; AMS reports the context information related to the application activity to the context state engine; WMS reports the context information related to the application window to the context state engine; IMS reports the user operation information to the context state engine. The specific implementation of PMS, AMS, WMS, and IMS collecting and reporting the corresponding context information can refer to the relevant description of the above embodiment, which will not be repeated here.
[0127] S101b, the context engine receives a lock screen broadcast or an unlock broadcast; the context engine receives a network status broadcast; the context engine receives an airplane mode broadcast. The context engine receives the broadcast and determines the device information in the context information. For the specific implementation, please refer to the above embodiment.
[0128] S101c. The context engine sends context information of at least one application function of the first application to the usage record engine.
[0129] The mobile phone may also collect context information of application functions in other ways. The context information is not limited to the ones listed above. Any information that can be used to determine permission authorization information at a functional granularity may be used as context information.
[0130] Alternatively, if Figure 7 S101 may also include S101d, the application operation management module reports the permission record of at least one application function of the first application to the usage record engine.
[0131] Specifically, taking the terminal device as a mobile phone and the first application as a map application as an example, as the user uses the map application, the mobile phone can count the records of the map application applying for the corresponding permissions when the user uses each application function in the map application, and obtain the permission records of each application function. The permission record of the application function may include whether the application has applied for and used a certain permission for the application function in history. Optionally, the permission record of the application function may also include: whether the user has authorized the use of a certain permission for the application function in history, that is, the user's authorization record of the corresponding permission of the application function. The method for the user to authorize the application function to use a certain permission can be found in Figure 6 Before using the map application, the user can set permission authorization for one or more application functions of the map application; or, during the process of using the map application, the user can set permission authorization for one or more application functions of the map application; or, if the user does not set one or more application functions, the mobile phone can set permission authorization for one or more application functions by default.
[0132] For example, as shown in Table 2-1, according to statistics, when users use the message viewing function of the map application, the map application does not apply for location information permission; when using the navigation function, the map application applies for location information permission, and with the user's consent, the mobile phone authorizes the navigation function to use the location information permission.
[0133] Table 2-1 Permission record
[0134]
[0135] Optionally, Table 2-1 is divided according to permissions, and for each permission, statistics are recorded on at least one application function applying for the permission, such as the number of applications and the application time. Statistics can also be recorded on the user's authorization of at least one application function to use the permission, for example, the user allows navigation, taxi and other functions to use location information permissions.
[0136] In some other embodiments, permission authorization information can also be generated based on application functions. Table 2-2 shows another example form of permission authorization information. As shown in Table 2-2, for each application function, statistics are recorded on the application function's application for one or more permissions, such as the number of applications and the time of application. Statistics can also be recorded on the user's authorization of one or more permissions for the application function, for example, the user allows the navigation function to use the location information permission, and prohibits the navigation function from using the "address book" function.
[0137] Table 2-2 Permission record
[0138]
[0139] The terminal device may obtain the usage data of at least one of the above-mentioned application functions in other ways, which are not limited in the embodiments of the present application. For example, subscribing to one or more other types of broadcasts to obtain device information. For another example, obtaining part or all of the context information of the application function through one or more other providers.
[0140] S102: The terminal device generates permission authorization information for at least one application function according to usage data of at least one application function.
[0141] The permission authorization information is used to indicate whether the application function is allowed to use the corresponding permission.
[0142] As a possible implementation manner, a usage record engine may be used to execute S102.
[0143] For example, if the terminal device is a mobile phone and the first application is a map application, different application function types of the map application can be identified based on the context information corresponding to at least one application function in the map application. Application function types include but are not limited to: background functions, foreground functions, commonly used functions, infrequently used functions, suspicious functions, non-suspicious functions, first-run functions, and non-first-run functions. For example, according to the package name, activity name, and the time corresponding to the context information, the running frequency of the application function and the name of the permission applied for are counted to identify the application function type.
[0144] Among them, unreasonable functions may refer to application functions that do not need to use a certain permission. For example, the system already knows that the word query function of the dictionary application does not require location permission, so the word query function is regarded as an unreasonable function of location permission. Each permission can correspond to one or more unreasonable functions. Suspicious functions may refer to functions that the system does not know whether the function should obtain the corresponding permission. For example, when a function is triggered to run for the first time and applies for location permission, the system does not know whether the function needs to use location permission, and does not know whether the implementation of the function is related to the location, then the function can be marked as a suspicious function. Common functions may refer to application functions whose usage frequency is higher than a certain threshold.
[0145] As a possible implementation manner, the mobile phone may generate permission authorization information for the permission of the application function according to the application function type and the permission record of the application function.
[0146] In some examples, the permission authorization information may include: permission authorization information for specific content of application functions. As a possible implementation, the permission authorization information includes at least one of the following: application functions that are allowed to grant the first permission, application functions that are prohibited from granting the first permission, permissions that the first application function is allowed to use, permissions that the first application function is prohibited from using, and authorization suggestions for different types of application functions.
[0147] For example, for location information permission, the permission authorization information may include a list of application functions that are allowed to use location information permission, such as navigation function and taxi-hailing function.
[0148] For another example, for the navigation function, the permissions allowed for the navigation function include: location information permission and camera permission.
[0149] For another example, taking the terminal device as a mobile phone and the first application as a map application, based on the contextual information of the map application function, the mobile phone knows that the user clicks the navigation button and uses the navigation function frequently; and, based on the permission record of the navigation function, the mobile phone knows that each time the navigation function is used in the past, the map application will apply for location information permission, and the user agrees to authorize the navigation function to use the location information permission, then the mobile phone can generate permission authorization information for the high-frequency and commonly used navigation function: allowing the navigation function to use the location information permission.
[0150] For another example, based on the context information of the map application function, the mobile phone learns that the user uses the message viewing function less frequently, and this function is an infrequently used function; and based on the permission record of the navigation function, the mobile phone learns that the map application has not applied for location information permission when the message viewing function was used in the past. In order to avoid the leakage of user privacy due to the use of location information permission by infrequently used functions, the mobile phone can generate permission authorization information for the low-frequency message viewing function: prohibiting the message viewing function from using location information permission. For another example, when an infrequently used application function applies for permission, or when an application function applies for permission that has not been applied for before, the terminal can ask the user whether to authorize.
[0151] Table 3-1 shows an example of permission authorization information generated by the mobile phone for the application function of the map application, taking the terminal device as a mobile phone and the first application as a map application.
[0152] Table 3-1 Permission authorization information
[0153]
[0154] In some embodiments, the authorization suggestions for different types of application functions included in the permission authorization information are generated by local statistical analysis of the terminal device. Optionally, the authorization suggestions for different types of application functions include at least one of the following suggestions: for an application function that applies for the first permission for the first time, asking the user whether to grant the first permission to the application function; for commonly used functions that use the first permission, allowing the first permission to be granted to the commonly used functions; for application functions that do not need to use the first permission, not allowing the first permission to be granted to the application function.
[0155] It should be noted that if the permission authorization information is generated by the server, for an application function whose authorized user ratio is higher than the first threshold and which applies for the first permission, the first permission is allowed to be granted to the application function, which is specifically introduced in the subsequent step S203.
[0156] In some embodiments, the commonly used functions using the first permission include at least one of the following: an application function that uses the first permission with a frequency higher than the second threshold, and an application function that uses the first permission twice with a time interval less than a third threshold. For example, a user frequently uses the "location information" permission of the "navigation function" in Table 3-1, and the frequency of use is as high as dozens of times a week (second threshold); for another example, the time interval between two consecutive uses of the "location information" permission of the "navigation function" is less than one hour (third threshold), then the "navigation function" is a commonly used function that uses the "location information" permission. It should be noted that the specific values of the second threshold and the third threshold are not limited in the embodiments of the present invention.
[0157] For the first-time running of a function, the process of the permission authorization information may be: a permission application window with function granularity may pop up; and the user may choose to authorize or deny authorization to the application function through the permission application window.
[0158] For another example, for a background function that is run for the first time, the process of the permission authorization information may be: a permission application window with function granularity may pop up; and the user may choose to authorize or refuse authorization to the background function through the permission application window.
[0159] For another example, for unreasonable functions, the permission authorization information may be: authorization denied.
[0160] For another example, for a suspicious function, the permission authorization information may be: a permission application window with function granularity pops up.
[0161] Table 3-2 shows another example of permission authorization information generated for at least one application function of the first application, taking the terminal device as a mobile phone as an example. Exemplarily, Table 3-2 and Table 3-1 can be combined into one table.
[0162] Table 3-2 Permission authorization information
[0163]
[0164]
[0165] S103. The terminal device receives a permission application request for a first permission for a first application function.
[0166] Among them, the first application function belongs to the at least one application function mentioned above.
[0167] As a possible implementation manner, the first application function sends a permission application request to the permission policy engine of the application operation management module.
[0168] As a possible implementation method, the permission application request carries information about the first application function for which the first permission needs to be applied. Optionally, the permission application request may also carry information about the first permission to be applied for. For example, taking the case where the terminal device is a mobile phone, the first application is a map application, the first application function is a navigation function, and the first permission applied for is location information permission, the user clicks the navigation button of the map application, and the map application sends a permission application request carrying information about the navigation function and information about the location information permission, and the mobile phone can thereby learn that the map application is applying for location information permission for the navigation function.
[0169] S104. In response to the permission application request, the terminal device refuses to grant the first permission to the first application function, or grants the first permission to the first application function according to the permission authorization information generated by the terminal device for at least one application function.
[0170] As a possible implementation, the permission policy engine in the application operation management module of the terminal device can be used to execute S104. During the APP operation, if the system sensitive API is called to apply for permission, the terminal device can call the permission policy engine, and the permission policy engine determines whether to restrict the APP from calling the sensitive API to apply for permission.
[0171] For example, if the terminal device is a mobile phone, the first application is a map application, the first application function is a navigation function, and the first permission applied for is the location information permission, the mobile phone determines that the navigation function is authorized to use the location information permission by querying the generated permission authorization information such as shown in Table 3-1. For another example, if the first application function is the message viewing function of the map application, and the first permission applied for is the location information permission, the mobile phone determines that the message viewing function is prohibited from using the location information permission by querying the generated permission authorization information such as shown in Table 3-1. It can be seen that the mobile phone can automatically and intelligently intercept or allow the application function to use a certain permission based on the generated permission authorization information, thereby improving the efficiency of permission access control and ensuring high security.
[0172] As a possible implementation, if there is no user authorization information for the first application function, and there is authorization information for the first application function generated by the terminal device, then the first permission is refused to be granted to the first application function, or the first permission is granted to the first application function, based on the authorization information for the first application function generated by the terminal device. The authorization information for the first application function generated by the terminal device belongs to the authorization information for at least one application function generated by the terminal device in step S104. For example, taking the case where the terminal device is a mobile phone, the first application is a map application, the first application function is "message", and the first permission applied for is location information permission, if there is no user authorization information for the "message" function to use location information permission, and the mobile phone generates authorization information for the "message" function, then the mobile phone refuses to grant the "message" function permission to use location information based on the authorization information for the "message" function generated by it.
[0173] Or, as a possible implementation method, if there is user authorization information for the first application function, then according to the user authorization information for the first application function, the first permission is denied to the first application function, or the first permission is granted to the first application function. Figure 6 In the "message" function in the interface 603 shown in (c), in the option of "do you agree to authorize the message to use the location information permission", the user selects "no", then the mobile phone will refuse to grant the "message" function the permission to use the location information based on the user's choice.
[0174] Alternatively, as a possible implementation method, if the mobile phone does not generate permission authorization information, the mobile phone can determine whether to authorize the first application function to use the first permission based on the user's permission authorization information for the first application function. For example, if the first application function is "Nearby Tour" and the first permission applied for is location information permission, the user sets the permission for the "Nearby Tour" function to use location information permission, and the mobile phone grants the "Nearby Tour" function location information permission based on the user's settings.
[0175] Or, as a possible implementation method, if the mobile phone does not generate permission authorization information, the mobile phone may authorize or refuse to authorize the first permission of the first application function by default. For example, when a request is received from a map application to apply for location information permission for the first application function, and the mobile phone does not query the permission authorization information for the first application function, the mobile phone intercepts the first application function from using location information permission by default. Alternatively, the mobile phone may pop up a window to prompt the user to authorize the location information permission for the first application function. If the user agrees to the authorization, the mobile phone grants the first application function permission to use the location information.
[0176] According to the scheme of the embodiment of the present application, the terminal device can generate permission authorization information based on the user's usage data of at least one application function of the first application (such as a high-frequency function). Subsequently, when the user uses the first application again and the first application applies for a certain permission for one of the at least one application function, the terminal device can intelligently and automatically grant the permission to the application function, or prohibit authorization, based on the permission authorization information, thereby reducing user operations and improving the efficiency of permission access control and the ease of use of the terminal device. In addition, as the user uses the application function, the terminal device can obtain more usage data of the application function, and determine more accurate permission authorization information based on the usage data of more application functions, thereby improving the accuracy of permission access control. For example, taking the terminal device as a mobile phone and the first application as a map application, the mobile phone determines through the above process that navigation of the map application is the main function and "message viewing" is a low-frequency function. After a period of use, the terminal can automatically recommend to the user or automatically grant the corresponding permission for the navigation function.
[0177] Through the above method, after the first application is granted permission, the terminal device performs more fine-grained permission access control according to the application function, which can avoid the problem that the first application can access sensitive resources at any time and in any state after being granted permission.
[0178] In some embodiments, Figure 7 , the permission policy management module (also known as the privacy center) can provide the implementation of viewing or modifying function authorization. For example, users can view or modify the authorization settings of a certain permission for a certain application function through the interface. In response to the user's operation of modifying permissions, the permission policy management module sends the modified permission authorization information to the application operation management module. Subsequently, the usage record engine can obtain the modified permission authorization information from the application operation management module, and update the corresponding permission authorization information according to the user's permission authorization information for the application function.
[0179] Figure 8 FIG. 4 shows an example process of performing permission authorization management for application functions in a terminal device in S104. Figure 8 , the process may include the following steps:
[0180] S104a, the terminal device determines whether the first application applies for the first permission for the first time; if so, presents permission application inquiry information of the application; if not, executes S104b.
[0181] For example, if the first application is a map application and the first permission applied for is location information permission, Fig.10In (a), the user opens the map application interface and clicks the navigation button in the interface. In response to the user's operation, the map application applies for location information permission for the navigation function. If this is the first time that the map application applies for location information permission, the mobile phone may pop up the following in interface 1002: Fig.10 (b) shows an application-level permission application window 1002a. The user can use this window to allow or prohibit the map application from accessing location information. Fig.10 Taking the presentation of the permission application inquiry information of the application in window 1002a as an example, it should be understood that the permission application inquiry information at the application granularity may also be in other forms, which is not limited in the embodiment of the present application.
[0182] S104b, the terminal device determines whether the first application is prohibited from authorizing the first permission; if so, the authorization is rejected; if not, S104c is executed.
[0183] In the case that this is not the first time that the first application has applied for the first permission, the terminal device determines whether the first application has been granted the first permission, or determines whether the first application is prohibited from using the first permission. As a possible implementation method, the terminal device maintains application-granular permission authorization information, such as the permission authorization information shown in Table 1-1. After the terminal device receives the permission application request from the first application, the terminal device can query the application-granular permission authorization information. If, according to the permission authorization information, the first application is prohibited from using the first permission, the terminal device rejects the first application's permission application request for the first permission. For example, if the terminal device is a mobile phone, the first application is a dictionary application, and the first permission applied for is location information permission, for example, Fig.11 (a), after querying the permission authorization information at the application level, if the dictionary application is set to disable the location information permission, the mobile phone will reject the permission application request of the dictionary application and prohibit the dictionary application from accessing the location information. Fig.11 (a), the mobile phone may pop up a window 1001a on the interface 1001, prompting that the system has prohibited the dictionary application from accessing the location information.
[0184] On the contrary, if the first application is allowed to use the first permission according to the permission authorization information, the terminal device executes the following step S104c.
[0185] S104c. The terminal device determines whether the first application function is granted the first permission by the user or whether the first permission is disabled; if it is set to allow the use of the first permission, the first application function is allowed to be authorized with the first permission; if it is set to prohibit the use of the first permission, the first application function is refused to be authorized with the first permission; if the user's permission authorization information for the first application function is not queried, execute S104d.
[0186] In the case where the first application is allowed to use the first permission, the terminal device continues to determine whether the first application function is granted the first permission based on the information of the first application function carried in the permission application request of the first application. As a possible implementation method, the terminal device can maintain the user's permission authorization information for at least one application function of the first application. The mobile phone can query the permission authorization information at the application function granularity. If, according to the permission authorization information, the first application function of the first application is allowed to use the first permission, the terminal device allows the first application function to use the first permission this time.
[0187] As a possible approach, the permission policy engine stores the user's permission authorization information for at least one application function of the application, and the permission policy engine queries the stored permission authorization information to determine whether the first application function of the first application is allowed by the user to use the first permission.
[0188] For example, the terminal device is a mobile phone, the first application is a map application, the first application function is an address search function, and the first permission applied for is the location information permission. Fig.11 In (b), the user clicks on the search box 602c in the interface 602 and enters the search address. In response to the address search request, the map application sends a permission application request. In response to the permission application request, the mobile phone queries the permission authorization information at the application granularity. Upon query, the map application is set to allow the use of location information permission. Then the mobile phone queries the permission authorization information at the application function granularity set by the user. Upon query, the "address search" function is set to allow the use of location information permission. Then, the mobile phone can accept the permission application request of the map application based on this, and the map application can access the location information, thereby providing location search services for users.
[0189] For example, the user can Figure 6 The corresponding interface sets the permission authorization information of the application function.
[0190] S104d. The terminal device queries the authority authorization information generated locally by the terminal device, and allows or refuses authorization based on the authority authorization information.
[0191] As a possible implementation, if the terminal device fails to query the user's permission authorization information for the first application function, it means that it is impossible to allow or deny authorization based on the user's permission authorization information for the first application function. Then, the permission policy engine may query the usage record engine for permission authorization information generated locally by the terminal device for at least one application function of the first application, and allow or deny authorization based on the permission authorization information. Exemplarily, the specific implementation of the terminal device generating permission authorization information locally can refer to the above steps S101-S102, which will not be repeated here.
[0192] In some cases, the permission authorization information generated locally by the terminal device includes permission authorization information for the first application function. For example, when the terminal device is a mobile phone and the first application function is the designated driver function on the taxi-hailing page of the map application, the user has not set the permission for the designated driver function to use location information, and Table 2-1 does not include permission authorization information for the designated driver function. In this case, the mobile phone queries the permission authorization information generated by the usage record engine, such as querying Table 3-1. According to Table 3-1, the designated driver function is set to allow the use of location information permission, so the mobile phone accepts the map application's request for location information permission for the designated driver function, and allows the map application to access location information during the process of implementing the designated driver function.
[0193] In some cases, the permission authorization information generated locally on the terminal device does not directly include permission authorization information for the first application function, but the permission authorization information includes permission authorization information for different types of application functions. For example, when the terminal device is a mobile phone and the first application function is the food function of a takeaway application, the user has not set the permission for the food function to use location information, and Table 2-1 does not include permission authorization information for the food function. In this case, the mobile phone queries the permission authorization information generated locally on the mobile phone, such as querying Table 3-1 and Table 3-2. Among them, Table 3-1 does not include permission authorization information for the food function. The mobile phone can determine whether to grant location information permission to the food function based on the permission authorization information for specific types of application functions in Table 3-2.
[0194] As a possible implementation, Fig. 9 , the terminal device determines whether to grant the first permission to the first application function according to the permission authorization information of the application function type to which the first application function belongs, which can be implemented as follows:
[0195] S104e. The terminal device determines whether the first application function is running for the first time; if so, execute S104f; if not, execute S104g.
[0196] As a possible implementation manner, the permission policy engine in the terminal device may be used to determine whether the first application function of the first application is being run for the first time.
[0197] S104f. The terminal device determines whether the first application function is a background function; if so, it presents inquiry information for the application function permission application; if not, it allows authorization.
[0198] As a possible implementation method, when the first application function is run for the first time, if the first application function is a background function, in order to prevent the background function from calling sensitive system permissions in the background, the terminal device can present the inquiry information of the application function permission application to ask the user whether to agree to the first application function applying for the first permission. For example, the terminal device is a mobile phone, the first application function is the background function B of application A, and the first permission applied is the location information permission. Fig.12 (a), application A runs background function B for the first time and applies for background function B to access location information. The mobile phone pops up window 1201a in interface 1201 to ask the user whether to agree to background function B accessing location information. If the user clicks the "Allow only during use" option, the mobile phone will only allow application A to access location information while background function B is running. Subsequently, application A is also allowed to access location information while background function B is running. If the user clicks the "Allow this use" option, the mobile phone will only allow application A to access location information while background function B is running this time. If the user clicks the "Prohibit" option, the mobile phone will prohibit background function B from accessing location information.
[0199] On the contrary, if the first application runs the first application function for the first time and the first application function is not a background function, the terminal device may allow the first application function to use the first permission by default. Or, in other embodiments, if the first application runs the first application function for the first time and the first application function is not a background function, the terminal device prohibits the first application function from using the first permission by default.
[0200] In other embodiments, the terminal device does not distinguish whether the first application function is a background function. When it is detected that the first application runs the first application function for the first time and the first application function applies for the first permission, the terminal device can present an inquiry message for the application function permission application to ask the user whether he agrees to the first application function's application for the first permission.
[0201] S104g. The terminal device determines whether the first application function is a commonly used function; if it is a commonly used function, authorization is allowed; if it is not a commonly used function, step S104h is executed.
[0202] Take the terminal device as a mobile phone and the first application function as the address search function of the map application as an example. Fig.12 In (b), the user clicks the search box 1202a on the interface 1202 multiple times, triggering the mobile phone to run the address search function multiple times. Subsequently, when it is detected that the address search function applies for the first permission, the mobile phone determines that the address search function is not run for the first time, and the address search function is a commonly used function, the mobile phone considers that the commonly used function has a higher security, and allows the address search function, a commonly used function, to access the first permission.
[0203] On the contrary, if the first application function is an infrequently used function, in order to reduce the potential security risks caused by infrequently used functions calling sensitive permissions, the mobile phone continues to execute S104h to determine whether to grant the first permission to the first application function.
[0204] S104h, the terminal device determines whether the first application function is an unreasonable function; if it is an unreasonable function, the authorization is rejected; if it is not an unreasonable function, step S104i is executed.
[0205] As a possible implementation method, when the first application applies for the first permission for an infrequently used first application function, in order to prevent the infrequently used function from calling sensitive permissions, the terminal device determines whether the first application function is an unreasonable function. If the first application function is an infrequently used and unreasonable function, it means that the first application function does not need to use the first permission, or the implementation of the first application function is irrelevant to the first permission. In order to prevent the security risks caused by unnecessary application functions accessing system sensitive permissions, the terminal device prohibits the first application function from accessing the first permission.
[0206] On the contrary, if the first application function is an infrequently used reasonable function, it means that the first application function needs to use the first permission, or the implementation of the first application function is related to the first permission, then the terminal device continues to execute S104i to determine whether to grant the first permission to the first application function.
[0207] S104i. The terminal device determines whether the first application function is a suspicious function; if it is a suspicious function, the terminal device presents inquiry information for the application function permission application; if it is not a suspicious function, the terminal device allows authorization.
[0208] As a possible implementation method, when the first application applies for the first permission for an infrequently used first application function, in order to avoid infrequently used reasonable functions from calling sensitive permissions, the mobile phone determines whether the first application function is an infrequently used suspicious function. If the first application function is a suspicious function, it means that the first application function accessing the first permission may cause security risks. In one example, the terminal device may present an inquiry message for the application function permission application to ask the user whether to authorize or prohibit authorization for the first application function. Conversely, if the first application function is not a suspicious function, the terminal device may allow the first application function to use the first permission.
[0209] To summarize the above method, if the first application applies for the first permission for the first time, the terminal device may present the inquiry information of the permission application to ask the user whether to authorize the first application. If the first application does not apply for the first permission for the first time, the terminal device may first query whether the first application is granted the first permission, and if not, deny authorization. Conversely, if the first application is granted the first permission, the terminal device may query the user's permission authorization information for the first application function of the first application, and determine whether to authorize or deny authorization based on the user's permission authorization information for the first application function.
[0210] If the terminal device does not query the user's permission authorization information for the first application function, the terminal device queries the permission authorization information generated by local statistical analysis, and authorizes according to the permission authorization information, or refuses authorization, or presents permission application inquiry information to ask the user whether to authorize the first application function. If there is no permission authorization information locally, the terminal device grants permission by default, or refuses authorization, or presents permission application inquiry information to ask the user whether to authorize the first application function.
[0211] The solution of the embodiment of the present application can provide fine-grained permission access control at the application function granularity, so that some application functions of the same application can call corresponding permissions, while other application functions of the same application cannot call the same permissions. For example, only application functions that need to use location information permissions can use location information permissions, and other unnecessary application functions fail to apply for permissions. This can prevent unnecessary application functions or unsafe application functions from using privacy permissions, thereby reducing the security risks caused by these application functions calling sensitive permissions and improving the security of terminal devices.
[0212] The embodiment of the present application also provides a permission access control method, in which the terminal and the server can collaboratively perform permission access control, and the server can generate permission authorization information for at least one application function based on usage data of at least one application function of multiple users. Fig.13 An example process of this method is shown. Fig.13 , the method may include the following steps:
[0213] S201. A terminal device obtains usage data of at least one application function of a first application by a user.
[0214] As a possible implementation, Fig.13 As shown, S201 can be implemented as follows: the permission policy management module of the terminal device obtains the user's usage data of at least one application function of the first application from the usage record engine of the terminal device. Alternatively, the terminal device can also obtain the user's usage data of at least one application function of the first application in other ways. This embodiment of the application is not limited to this.
[0215] Optionally, the usage data of the application function includes, but is not limited to, at least one of the following data: context information of the application function, permission records, and statistical results obtained based on the context information and / or permission records.
[0216] The statistical results obtained based on the context information and / or permission records may be function information recognized by the terminal device, for example, commonly used functions, infrequently used functions, suspicious functions, unreasonable functions, etc. recognized by the terminal device.
[0217] Optionally, before S201, the above-mentioned S101-S102 may also be included.
[0218] S202. The terminal device sends usage data of at least one application function of the first application to the server.
[0219] As a possible implementation manner, the permission policy management module of the terminal device sends usage data of at least one application function of the first application by the first user to the security management and control center of the server.
[0220] It should be noted that there may be multiple terminal devices executing steps S201 and S202, that is, multiple terminal devices obtain usage data of at least one application function of the first application by multiple users; and multiple terminal devices send usage data of at least one application function of the first application to the server.
[0221] S203: The server generates permission authorization information for at least one application function according to usage data of at least one application function of the first application by multiple users.
[0222] The permission authorization information is used to indicate whether the application function is allowed to use the corresponding permission.
[0223] As a possible implementation method, the security control center of the server generates permission authorization information of at least one application function of the first application based on the usage data of at least one application function of the first application reported by multiple users on multiple terminal devices through big data aggregation statistical analysis. Optionally, the permission authorization information at the functional granularity may include at least one of the following information: the user authorization ratio of at least one application function, the application functions allowed to be authorized, and the application functions prohibited to be authorized. The permission authorization information can be used as a basis or reference for the terminal device to authorize / reject authorization of at least one application function of the first application.
[0224] Illustratively, Table 4 shows an example of the authority authorization information generated by the server.
[0225] Table 4 Cloud-side permission authorization information
[0226]
[0227] As a possible implementation method, the server may count the percentage of users who are granted corresponding permissions for at least one application function of the first application based on the usage data of at least one application function of the first application, and determine the permission authorization information based on the percentage of users who are granted corresponding permissions for at least one application function of the first application. As shown in Table 4, after calculation, the server determines that 99% of users agree that the "navigation function" of the map application accesses location information, and the navigation function is a commonly used function, then the server may determine that the permission authorization information for the "navigation function" is: authorization allowed; 5% of users allow the "message viewing function" to access location information, and 95% of users prohibit the "message viewing function" from accessing location information, then the server may determine that the permission authorization information for the "message viewing function" is: authorization prohibited. For authorization / prohibition of authorization information for other application functions, please refer to other entries in Table 4. That is to say, for application functions whose percentage of authorized users is higher than the first threshold and which apply for the first permission, the first permission is allowed to be granted to the application function.
[0228] Table 4 only shows an example of the permission authorization information generated by the server. The permission authorization information may also be in other forms, such as including at least one of the following: the user authorization percentage of application functions, a list / list of application functions allowed to be authorized, a list / list of application functions prohibited from being authorized, and a list / list of suspicious functions. The list of application functions allowed to be authorized may include, for example: one or more application functions that are allowed to access each of one or more permissions.
[0229] The server can update the permission authorization information of the function granularity maintained by the server according to a certain strategy. For example, the server receives the usage data of at least one application function of the first application from multiple terminal devices according to a period, and generates permission authorization information according to the usage data of at least one application function of the first application. Alternatively, when the application version of the first application is updated, the server updates the permission authorization information for at least one application function of the first application.
[0230] In the solution of the embodiment of the present application, the server can refer to or determine the permission authorization information of the application function based on the usage data of at least one application function of the first application by multiple users, which is equivalent to considering the habitual settings of multiple users for permission access control. Therefore, the obtained permission authorization information is more accurate. Based on this, according to the accurate permission authorization information, more secure permission access control can be provided during the use of the terminal device to improve the security of user data.
[0231] For example, if ten existing users are allowed to grant location information permission to the navigation function of a map application, after the eleventh user installs the map application on a terminal device, the terminal device can automatically grant location information permission to the navigation function based on the permission authorization information obtained from the server, thereby improving the efficiency of permission access control.
[0232] S204: The server sends permission authorization information for at least one application function generated by the server to multiple terminal devices.
[0233] As a possible implementation manner, the security management and control center of the server sends permission authorization information for at least one application function generated by the server to the permission policy management module of the terminal device.
[0234] Optionally, the permission policy management module obtains permission authorization information at the application function granularity from the security control center on a periodic basis. Alternatively, when the terminal device needs to upgrade the application version, the permission policy management module obtains permission authorization information of at least one application function of the first application from the security control center. Alternatively, the terminal device obtains permission authorization information under other conditions or timings according to other policies.
[0235] S205: The terminal device receives permission authorization information for at least one application function generated by the server.
[0236] The permission authorization information for at least one application function generated by the server is generated by the server according to usage data of at least one application function.
[0237] As a possible implementation manner, the permission policy management module of the terminal device saves the permission authorization information of at least one application function of the first application to the permission policy engine of the application operation management module.
[0238] S206: The first application sends a permission application request, where the permission application request can be used to apply for a first permission for a first application function of the first application.
[0239] As a possible implementation manner, the first application sends a permission application request to a permission policy engine of the terminal device.
[0240] S207. In response to the permission application request, the terminal device authorizes or refuses to authorize the first application function of the first application.
[0241] As a possible implementation method, during the operation of the first application function, if the first application function calls a system sensitive API to apply for permission, the terminal device can call a permission policy engine, and the permission policy engine determines whether to restrict the first application function from calling the sensitive API to apply for permission.
[0242] As a possible implementation method, the terminal device determines whether to authorize or reject authorization based on at least one item of information including the user's permission authorization information for at least one application function of the first application, the permission authorization information for at least one application function of the first application generated locally by the terminal device, and the permission authorization information for at least one application function of the first application generated by the server.
[0243] As a possible implementation, if there is no user permission authorization information for the first application function, and there is permission authorization information for the first application function generated by the server, then according to the permission authorization information for the first application function generated by the server, the first permission is denied to the first application function, or the first permission is granted to the first application function. The permission authorization information for the first application function generated by the server belongs to the permission authorization information for at least one application function generated by the server.
[0244] As a possible implementation method, if there is no permission authorization information generated by the server for the first application function, and there is permission authorization information generated by the terminal device for the first application function, then according to the permission authorization information generated by the terminal device for the first application function, the first permission is denied to the first application function, or the first permission is granted to the first application function.
[0245] For example, Fig.14 An example process of S207, where the terminal device authorizes / forbids authorization for the first application function of the first application, is shown. The method may include the following steps:
[0246] S301. The terminal device determines whether the first application applies for the first permission for the first time; if so, presents inquiry information of the first permission application of the first application; if not, executes S302.
[0247] S302, the terminal device determines whether the first application is prohibited from authorizing the first permission; if so, the authorization is rejected; if not, S303 is executed.
[0248] S303: The terminal device determines whether the first application function of the first application is allowed by the user to authorize the first permission or whether it is prohibited to authorize the first permission.
[0249] Specifically, if it is set to allow authorization of the first permission, authorization of the first permission for the first application function is allowed; if it is set to prohibit authorization of the first permission, authorization of the first permission for the first application function is denied; if no user permission authorization information for the first application function is found, execute S304.
[0250] The specific implementation of S301-S303 can refer to S104a-S104b and will not be described in detail.
[0251] S304: The terminal device queries the server for permission authorization information for the first application function of the first application.
[0252] In an embodiment of the present application, when the user's permission authorization information for the first application function of the first application is not queried, the terminal device can preferentially query the permission authorization information generated by the server so as to authorize / deny authorization for the first application function of the first application based on the permission authorization information.
[0253] S305. The terminal device determines whether the first application function is allowed to be authorized or prohibited from being authorized based on the permission authorization information of the first application function of the first application generated by the server. If the first application function is allowed to be granted the first permission, the authorization is allowed; if the first application function is prohibited from being granted the first permission, the authorization is rejected; otherwise, execute S306.
[0254] Taking the example of a terminal device being a mobile phone, the first application function being the navigation function of a map application, and the first permission applied for being the location information permission, illustratively, based on the cloud permission authorization information such as shown in Table 4, the navigation function is suggested to allow the "location information permission" to be granted. Therefore, when the mobile phone receives a request from the map application to apply for the "location information permission" for the navigation function, the mobile phone allows the navigation function to access the location information.
[0255] Taking the example of a terminal device being a mobile phone, the first application function being the message viewing function of a map application, and the first permission applied for being the location information permission, illustratively, according to the permission authorization information shown in Table 4, the navigation function is recommended to be prohibited from granting the "location information permission". Therefore, when the mobile phone receives a request from the map application for the "location information permission" for the "message viewing" function, the mobile phone prohibits the "message viewing" function from accessing the location information.
[0256] S306. The terminal device determines whether the first application function of the first application is a suspicious function. If it is a suspicious function, the terminal device presents inquiry information for the application function permission application; if it is not a suspicious function, execute S307.
[0257] In some cases, the permission authorization information generated by the server does not include specific permission authorization information for the first application function. In order to reduce the security risk of the first application function calling permission, the terminal device can execute S306 to determine whether the first application function is a suspicious function. For example, the terminal device is a mobile phone, the first application function is the background function B of application A, and the first permission applied for is the location information permission. Fig.15, application A applies for location information permission for background function B. The mobile phone queries Table 4 above and determines that Table 4 does not contain permission authorization information for background function B. Then the mobile phone can determine whether background function B is a suspicious function. If it is determined that background function B is a suspicious function, the mobile phone can pop up a window 1201a in interface 1201, which may include multiple users granting location information permission to background function B, accounting for 9%.
[0258] In this way, when a suspicious function appears, the terminal device can display the proportion of users who have authorized the function based on big data statistics for users to use in authorization decisions, avoiding the problem that users cannot judge whether to grant permissions, and improving the usability of the terminal.
[0259] S307: The terminal device queries the permission authorization information for the first application function generated locally by the terminal device, and authorizes or refuses to authorize the first application function according to the permission authorization information for the first application function generated locally by the terminal device.
[0260] The specific implementation of S307 may refer to S104d, which will not be described in detail here.
[0261] In summary, the above method is that if the first application applies for the first permission for the first time, the terminal device may present the inquiry information of the permission application. If the first application is not applying for the first permission for the first time, the terminal device may first query whether the first application has been granted the first permission, and if not, deny authorization. On the contrary, if the first application is granted the first permission, the terminal device may query the user's permission authorization information for the first application function, and determine whether to authorize or deny authorization based on the user's permission authorization information for the first application function.
[0262] If the terminal device does not query the user's permission authorization information for the first application function locally on the terminal device, the terminal device can query the permission authorization information generated by the server. If the permission authorization information is found, the terminal device will authorize according to the permission authorization information, or refuse authorization, or present inquiry information for the permission application.
[0263] If the terminal device does not query the permission authorization information generated by the server, the terminal device can query the permission authorization information generated by the local statistical analysis of the terminal device, and authorize according to the permission authorization information, or refuse authorization, or present the inquiry information of the permission application. If there is no permission authorization information locally, the terminal can grant permission by default, or refuse authorization, or present the inquiry information of the permission application. For example, check whether the application function for which permission is applied belongs to the list of application functions allowed to be authorized or the list of application functions prohibited from being authorized. If the application function is in the list of application functions allowed to be authorized, the permission is granted to the application function. If the application function is in the list of application functions prohibited from being authorized, the authorization is prohibited. If the application function is not in the above two lists, the percentage of authorized users of the application function is queried. If there is a result, the percentage of authorized users is returned.
[0264] It should be noted that the above-mentioned multiple embodiments can be combined and the combined scheme can be implemented. Optionally, some operations in the process of each method embodiment are optionally combined, and / or the order of some operations is optionally changed. In addition, the execution order between the steps of each process is only exemplary and does not constitute a limitation on the execution order between the steps. There can also be other execution orders between the steps. It is not intended to indicate that the execution order is the only order in which these operations can be performed. Ordinary technicians in this field will think of many ways to reorder the operations of this article. In addition, it should be pointed out that the process details involved in a certain embodiment of this article are also applicable to other embodiments in a similar manner, or different embodiments can be used in combination.
[0265] In addition, some steps in the method embodiment may be equivalently replaced with other possible steps. Alternatively, some steps in the method embodiment may be optional and may be deleted in certain usage scenarios. Alternatively, other possible steps may be added in the method embodiment. Alternatively, the execution subject (such as a functional module) of some steps in the method embodiment may be replaced with other execution subjects.
[0266] Furthermore, the above method embodiments may be implemented separately or in combination.
[0267] For example, Fig.13 The corresponding method can be used alone. Or Fig.13 The corresponding method can be Figure 7 The corresponding methods are used in combination.
[0268] Some other embodiments of the present application provide a device, which may be the first device, the second device, the third device, the fourth device, etc. The device may include: a display screen, a memory, and one or more processors. The display screen, the memory, and the processor are coupled. The memory is used to store computer program code, and the computer program code includes computer instructions. When the processor executes the computer instructions, the device may perform various functions or steps in the above method embodiments. The structure of the device may refer to Fig.16 The equipment (device) shown.
[0269] The core structure of the device can be expressed as Fig.16 As shown in the structure, the device includes: a processing module 1301, an input module 1302, a storage module 1303 and a display module 1304.
[0270] The processing module 1301 may include at least one of a central processing unit (CPU), an application processor (AP), or a communication processor (CP). The processing module 1301 may perform operations or data processing related to control and / or communication of at least one of other elements of the device.
[0271] The input module 1302 is used to obtain the instructions or data input by the user and transmit the obtained instructions or data to other modules of the device. Specifically, the input mode of the input module 1302 may include touch, gesture, approaching the screen, etc., or voice input. For example, the input module may be the screen of the device, obtain the user's input operation and generate an input signal according to the obtained input operation, and transmit the input signal to the processing module 1301.
[0272] The storage module 1303 may include a volatile memory and / or a non-volatile memory. The storage module is used to store at least one instruction or data related to other modules of the user equipment device.
[0273] The display module 1304 may include, for example, a liquid crystal display (LCD), a light emitting diode (LED) display, an organic light emitting diode (OLED) display, a micro-electromechanical system (MEMS) display, or an electronic paper display, and is used to display content (e.g., text, images, videos, icons, symbols, etc.) that can be viewed by a user.
[0274] Optionally, a communication module 1305 is also included to support personal devices (via a communication network) to communicate with other personal devices. For example, the communication module can be connected to a network via wireless communication or wired communication to communicate with other personal devices or network servers. Wireless communication can use at least one of cellular communication protocols, such as long-term evolution (LTE), advanced long-term evolution (LTE-A), code division multiple access (CDMA), wideband code division multiple access (WCDMA), universal mobile telecommunications system (UMTS), wireless broadband (WiBro) or global mobile communication system (GSM). Wireless communication may include, for example, short-range communication. Short-range communication may include at least one of wireless fidelity (Wi-Fi), Bluetooth, near field communication (NFC), magnetic stripe transmission (MST) or GNSS.
[0275] It should be noted that each functional module of the device can execute one or more steps in the above method embodiment.
[0276] The present application also provides a chip system, such as Fig.17As shown, the chip system includes at least one processor 1401 and at least one interface circuit 1402. The processor 1401 and the interface circuit 1402 can be interconnected via lines. For example, the interface circuit 1402 can be used to receive signals from other devices (such as the memory of the device). For another example, the interface circuit 1402 can be used to send signals to other devices (such as the processor 1401). Exemplarily, the interface circuit 1402 can read the instructions stored in the memory and send the instructions to the processor 1401. When the instruction is executed by the processor 1401, the device can execute the various steps in the above embodiments. Of course, the chip system can also include other discrete devices, which are not specifically limited in the embodiments of the present application.
[0277] An embodiment of the present application also provides a computer-readable storage medium, which includes computer instructions. When the computer instructions are executed on the above-mentioned device, the device executes each function or step in the above-mentioned method embodiment.
[0278] The embodiment of the present application also provides a computer program product. When the computer program product is run on a computer, the computer executes each function or step executed by the mobile phone in the above method embodiment.
[0279] Through the description of the above implementation methods, technical personnel in the relevant field can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0280] In the several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of modules or units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0281] The units described as separate components may or may not be physically separated, and the components shown as units may be one physical unit or multiple physical units, that is, they may be located in one place or distributed in multiple different places. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0282] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0283] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium, including several instructions to enable a device (which can be a single-chip microcomputer, chip, etc.) or a processor (processor) to perform all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read only memory (ROM), random access memory (RAM), disk or optical disk and other media that can store program code.
[0284] The above contents are only specific implementation methods of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions within the technical scope disclosed in the present application shall be included in the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.
Claims
1. A permission access control method, characterized in that: include: The terminal device obtains usage data of at least one application function of the first application; The terminal device generates permission authorization information for the at least one application function according to the usage data of the at least one application function, wherein the permission authorization information is used to indicate whether the application function is allowed to use the corresponding permission; The terminal device receives a permission application request for applying for a first permission for a first application function, wherein the first application function belongs to the at least one application function; In response to the permission application request, the terminal device refuses to grant the first permission to the first application function, or grants the first permission to the first application function according to the permission authorization information for the at least one application function generated by the terminal device.
2. The method according to claim 1, characterized in that The terminal device refuses to grant the first permission to the first application function or grants the first permission to the first application function according to the permission authorization information for the at least one application function generated by the terminal device, including: If there is no user permission authorization information for the first application function, and there is permission authorization information for the first application function generated by the terminal device, then according to the permission authorization information for the first application function generated by the terminal device, refuse to grant the first permission to the first application function, or grant the first permission to the first application function, wherein the permission authorization information for the first application function generated by the terminal device belongs to the permission authorization information generated by the terminal device for at least one application function.
3. The method according to claim 2, characterized in that Also includes: If there is user permission authorization information for the first application function, the first permission is denied to the first application function, or the first permission is granted to the first application function according to the user permission authorization information for the first application function.
4. The method according to any one of claims 1 to 3, characterized in that: Also includes: sending usage data of the at least one application function of the first application to a server; The permission authorization information for the at least one application function generated by the server is received from the server, wherein the permission authorization information for the at least one application function generated by the server is generated by the server according to usage data of the at least one application function.
5. The method according to claim 4, characterized in that The terminal device refuses to grant the first permission to the first application function or grants the first permission to the first application function according to the permission authorization information for the at least one application function generated by the terminal device, including: If there is no user permission authorization information for the first application function, and there is permission authorization information for the first application function generated by the server, then based on the permission authorization information for the first application function generated by the server, refuse to grant the first permission to the first application function, or grant the first permission to the first application function, wherein the permission authorization information for the first application function generated by the server belongs to the permission authorization information generated by the server for at least one application function.
6. The method according to claim 5, characterized in that Also includes: If the permission authorization information for the first application function generated by the server does not exist, and the permission authorization information for the first application function generated by the terminal device exists, then according to the permission authorization information for the first application function generated by the terminal device, the first permission is refused to be granted to the first application function, or the first permission is granted to the first application function.
7. The method according to any one of claims 1 to 6, characterized in that: The permission authorization information includes at least one of the following: application functions that are allowed to grant the first permission, application functions that are prohibited from granting the first permission, permissions that the first application function is allowed to use, permissions that the first application function is prohibited from using, and authorization suggestions for different types of application functions.
8. The method according to claim 7, characterized in that The authorization suggestions for different types of application functions include at least one of the following suggestions: for an application function that applies for the first permission for the first time, asking the user whether to grant the first permission to the application function; for a common function that uses the first permission, allowing the first permission to be granted to the common function; For an application function that does not need to use the first permission, granting the first permission to the application function is not allowed; When the permission authorization information is generated by the server, for an application function whose authorized user ratio is higher than a first threshold and which applies for the first permission, the first permission is allowed to be granted to the application function.
9. The method according to claim 8, characterized in that The common functions using the first permission include at least one of the following: An application function whose frequency of using the first permission is higher than a second threshold, and an application function whose time interval between two consecutive uses of the first permission is less than a third threshold.
10. The method according to any one of claims 1 to 9, characterized in that: The usage data of the application function includes: context information corresponding to the application function, and / or permission record corresponding to the application function, wherein the context information includes at least one of the following information: device information, application information, and user operation information, the device information is used to indicate the state of the terminal device, the application information is used to indicate the state of the first application, and the user operation information is used to indicate information generated by the user operating the first application.
11. The method according to claim 10, characterized in that The permission record corresponding to the application function includes: a record of historically applying for authorization or rejection of one or more permissions for the application function.
12. A permission access control method, characterized in that: include: The server receives usage data of at least one application function of the first application by multiple users from multiple terminal devices; The server generates permission authorization information for the at least one application function according to the usage data of the at least one application function of the first application by the multiple users, wherein the permission authorization information is used to indicate whether the application function is allowed to use the corresponding permission; The server sends permission authorization information of the at least one application function to the multiple terminal devices.
13. The method according to claim 12, characterized in that The permission authorization information includes at least one of the following: application functions that are allowed to be granted the first permission, application functions that are prohibited from being granted the first permission, permissions that the first application function is allowed to use, permissions that the first application function is prohibited from using, and authorization suggestions for different types of application functions.
14. The method according to claim 13, characterized in that The authorization suggestions for different types of application functions include at least one of the following suggestions: for an application function that applies for the first permission for the first time, asking the user whether to grant the first permission to the application function; for a common function that uses the first permission, allowing the first permission to be granted to the common function; For an application function that does not need to use the first permission, granting the first permission to the application function is not allowed; For an application function whose authorized user ratio is higher than a first threshold and which applies for the first permission, granting the first permission to the application function is allowed.
15. The method according to claim 14, characterized in that The common functions using the first permission include at least one of the following: An application function whose frequency of using the first permission is higher than a second threshold, and an application function whose time interval between two consecutive uses of the first permission is less than a third threshold.
16. The method according to any one of claims 12 to 15, characterized in that: The usage data of the application function includes: context information corresponding to the application function, and / or permission record corresponding to the application function, wherein the context information includes at least one of the following information: device information, application information, and user operation information, the device information is used to indicate the state of the terminal device, the application information is used to indicate the state of the first application, and the user operation information is used to indicate information generated by the user operating the first application.
17. The method according to claim 16, characterized in that The permission record corresponding to the application function includes: a record of historically applying for authorization or rejection of one or more permissions for the application function.
18. A terminal device, characterized in that: The device includes a processor and a memory; the memory is used to store computer-executable instructions. When the device is running, the processor executes the computer-executable instructions stored in the memory, so that the device executes the method according to any one of claims 1 to 11.
19. A server, characterized in that: The server includes a processor and a memory; the memory is used to store computer-executable instructions, and when the device is running, the processor executes the computer-executable instructions stored in the memory, so that the server executes the method as described in any one of claims 12-17.
20. A computer-readable storage medium, characterized in that: The method comprises a program or an instruction. When the program or the instruction is executed, the method according to any one of claims 1 to 11 is implemented, or the method according to any one of claims 12 to 17 is implemented.
21. A chip, characterized in that: The chip includes a processor, the processor is coupled to a memory, the memory stores program instructions, and when the program instructions stored in the memory are executed by the processor, the method described in any one of claims 1 to 11 is implemented, or the method described in any one of claims 12 to 17 is implemented.
Citation Information
Cited By
Data security sharing permission dynamic adjustment method based on block chain
CN121302446A