Windows application permission management method and device, medium and equipment

By displaying the application permission list and operation window of the Windows system, users can manage and adjust the application permission status, solving the complex and inconvenient application permission management of Windows system, and achieving simplified permission management processes and improved system security.

CN119945725APending Publication Date: 2025-05-06成都安易迅科技有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411915129.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-24
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The application permission management of Windows systems is complex and inconvenient, making it difficult for ordinary users to effectively manage and restrict application permissions, which increases the potential harm of malware.

Method used

By obtaining the application permission list of Windows system and displaying the application permission list and operation window based on the permission display interface, users can manage and adjust the permission status of each application (on or off).

Benefits of technology

Simplifies permission management processes, improves user experience and system security, promotes application compliance, and has good flexibility and scalability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945725A_ABST
    Figure CN119945725A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of application permission management, and provides a Windows application permission management method and device, a medium and equipment, and the method comprises the steps: firstly obtaining an application permission list of a Windows system; wherein the Windows system comprises a plurality of applications, the application permission list comprises a plurality of permissions corresponding to each application and a permission state corresponding to each permission, and the permission states comprise an opening state and a closing state; displaying an application permission list and an application permission operation window based on the permission display interface; wherein the application permission operation window comprises two operation options of permission and rejection, so that the permission state of any permission corresponding to any application is modified based on the interactive operation corresponding to the application permission operation window. According to the embodiment, the application permission list and the operation window are displayed, so that the user can manage and adjust the permission state requested by each application, the permission management process is simplified, and the user experience is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of application permission management, and in particular to a Windows application permission management method, apparatus, medium and device. Background Art

[0002] With the vigorous development of Internet technology, computer technology, big data and other technologies, the collection and use of personal data has become the norm in daily life. However, this trend is also accompanied by a sharp increase in network security threats, such as hacker attacks, malware, ransomware and data theft, which have led to a large amount of personal sensitive information being illegally obtained or abused. The frequent occurrence of privacy leaks and the public attention they have aroused have prompted all sectors of society to attach great importance to privacy protection issues. Enterprises and developers are also under tremendous pressure and have to re-examine and strengthen user privacy protection mechanisms to prevent data from being maliciously leaked or abused.

[0003] In the relevant technologies, mobile operating systems such as iOS and Android are relatively mature in application permission management, and the user operation is simple and easy to understand. However, the application permission management on the Windows system seems to be lagging behind, and the operation is complicated and inconvenient. Especially for ordinary users, the permission management of the Windows system is too cumbersome, the permission settings are scattered, and there is a lack of a unified request and control mechanism. Most users do not understand this very well, and are prone to granting too many permissions to applications without knowing it, or failing to effectively manage and restrict application permissions when facing security threats. In addition, the control of application permissions by the Windows system is not as detailed and intuitive as that of the mobile terminal. Many applications obtain extensive permissions when they are installed or used for the first time, such as file system access and administrator permissions, making it difficult for users to clearly understand the data access status of the application. This not only increases the potential harm of malware, but also makes it impossible for users to manage the permissions and privacy settings of Windows applications as conveniently as managing mobile applications in daily use. Summary of the invention

[0004] The disclosed embodiments at least provide a Windows application permission management method, apparatus, medium and device, which enable users to manage and adjust the permission status (on or off) requested by each application by displaying an application permission list and an operation window, thereby improving user experience and system security, simplifying the permission management process, and promoting application compliance, while having good flexibility and scalability to meet the permission management requirements of various applications in the Windows system.

[0005] The present disclosure provides a Windows application permission management method, including:

[0006] Obtain an application permission list of the Windows system; wherein the Windows system includes multiple applications, the application permission list includes multiple permissions corresponding to each application and a permission status corresponding to each permission, and the permission status includes an on state and a off state;

[0007] The application permission list and the application permission operation window are displayed based on the permission display interface; wherein the application permission operation window includes two operation options of allow and deny, so as to modify the permission status of any permission corresponding to any application based on the interactive operation corresponding to the application permission operation window.

[0008] In some possible embodiments, obtaining the application permission list of the Windows system includes:

[0009] Scan all applications in the Windows system, identify and record the permissions and permission status corresponding to each application;

[0010] The permissions and permission status corresponding to each of the applications are adjusted based on the sensitivity rules, and the application permission list is determined based on the adjustment results.

[0011] In some possible embodiments, adjusting the permission and permission status corresponding to each of the applications based on the sensitivity rule includes:

[0012] Obtaining permission information of the Windows system; wherein the permission information includes multiple permissions and a function corresponding to each permission;

[0013] Determine a permission level based on the role corresponding to each permission and the sensitivity rule, and determine whether the permission corresponding to each application in the Windows system is a sensitive permission based on the permission level;

[0014] In the case where the permission corresponding to the application is a sensitive permission, the permission state corresponding to the permission is set to a closed state.

[0015] In some possible embodiments, the displaying of the application permission list and the application permission operation window based on the permission display interface includes:

[0016] Based on the permission display interface, a permission display mode selection window is displayed; wherein the permission display mode selection window includes two display mode options: permission perspective display and application perspective display;

[0017] In response to the interactive instruction of the permission display mode selection window, displaying the application permission list and the application permission operation window on the permission display interface based on the interactive instruction includes:

[0018] In the case where the interaction instruction instructs the permission display interface to display in the manner of displaying from the perspective of the permission, displaying the application corresponding to each permission and the permission status corresponding to each application, and the application permission operation window based on the permission display interface according to the application permission list;

[0019] When the interaction instruction instructs the permission display interface to be displayed in the manner of displaying from the application perspective, the permission and permission status corresponding to each application and the application permission operation window are displayed based on the permission display interface according to the application permission list.

[0020] In some possible embodiments, the permission state further includes an unauthorized state, and the method further includes:

[0021] In response to a running operation of any application in the Windows system, determining whether the running operation of any application is an executable operation based on a permission status corresponding to the any application;

[0022] In the permission status corresponding to the any application, it is displayed that the permission status corresponding to the running operation of the any application is enabled, and it is determined that the running operation corresponding to the any application is an executable operation; in response to the executable operation, execution prompt information corresponding to the executable operation is displayed to the user, and interaction information of the user to the execution prompt information is received, and the running result corresponding to the executable operation is returned based on the interaction information;

[0023] In the permission status corresponding to the any application, it is displayed that the permission status corresponding to the running operation of the any application is a closed state or an unauthorized state, it is determined that the running operation corresponding to the any application is not an executable operation, and a warning interface is displayed to the user; wherein the warning interface includes the application name, the permission corresponding to the running operation, the permission status corresponding to the permission, and the application permission operation window; wherein the application permission operation window also includes an ignore operation option.

[0024] In some possible embodiments, the method further includes:

[0025] In response to a permission request operation of any application in the Windows system, displaying a permission request purpose and permission request content corresponding to the permission request operation based on the permission display interface;

[0026] In response to a triggering operation on the permission operation window in the permission display interface, the permission and permission status corresponding to the any application in the application permission list are updated based on the operation option triggering result.

[0027] In some possible embodiments, the method further includes:

[0028] Obtain application permission behavior records within a preset time period in the Windows system, and generate a permission behavior analysis report based on the application permission behavior records; wherein the permission behavior analysis report includes application permission usage frequency and application permission change records.

[0029] The present disclosure provides a Windows application rights management device, including:

[0030] A permission acquisition module, used to acquire an application permission list of a Windows system; wherein the Windows system includes multiple applications, the application permission list includes multiple permissions corresponding to each application and a permission status corresponding to each permission, and the permission status includes an open state and a closed state;

[0031] A permission display module is used to display the application permission list and the application permission operation window based on the permission display interface; wherein the application permission operation window includes two operation options: allow and deny, so as to modify the permission status of any permission corresponding to any application based on the interactive operation corresponding to the application permission operation window.

[0032] In some possible embodiments, the permission acquisition module is specifically used to:

[0033] Scan all applications in the Windows system, identify and record the permissions and permission status corresponding to each application;

[0034] The permissions and permission status corresponding to each of the applications are adjusted based on the sensitivity rules, and the application permission list is determined based on the adjustment results.

[0035] In some possible embodiments, the permission acquisition module is specifically used to:

[0036] Obtaining permission information of the Windows system; wherein the permission information includes multiple permissions and a function corresponding to each permission;

[0037] Determine a permission level based on the role corresponding to each permission and the sensitivity rule, and determine whether the permission corresponding to each application in the Windows system is a sensitive permission based on the permission level;

[0038] In the case where the permission corresponding to the application is a sensitive permission, the permission state corresponding to the permission is set to a closed state.

[0039] In some possible embodiments, the permission display module is specifically used to:

[0040] Based on the permission display interface, a permission display mode selection window is displayed; wherein the permission display mode selection window includes two display mode options: permission perspective display and application perspective display;

[0041] In response to the interactive instruction of the permission display mode selection window, displaying the application permission list and the application permission operation window on the permission display interface based on the interactive instruction includes:

[0042] In the case where the interaction instruction instructs the permission display interface to display in the manner of displaying from the perspective of the permission, displaying the application corresponding to each permission and the permission status corresponding to each application, and the application permission operation window based on the permission display interface according to the application permission list;

[0043] When the interaction instruction instructs the permission display interface to be displayed in the manner of displaying from the application perspective, the permission and permission status corresponding to each application and the application permission operation window are displayed based on the permission display interface according to the application permission list.

[0044] In some possible embodiments, the permission state further includes an unauthorized state, and the device further includes a permission monitoring module, which is specifically used to:

[0045] In response to a running operation of any application in the Windows system, determining whether the running operation of any application is an executable operation based on a permission status corresponding to the any application;

[0046] In the permission status corresponding to the any application, it is displayed that the permission status corresponding to the running operation of the any application is enabled, and it is determined that the running operation corresponding to the any application is an executable operation; in response to the executable operation, execution prompt information corresponding to the executable operation is displayed to the user, and interaction information of the user to the execution prompt information is received, and the running result corresponding to the executable operation is returned based on the interaction information;

[0047] In the permission status corresponding to the any application, it is displayed that the permission status corresponding to the running operation of the any application is a closed state or an unauthorized state, it is determined that the running operation corresponding to the any application is not an executable operation, and a warning interface is displayed to the user; wherein the warning interface includes the application name, the permission corresponding to the running operation, the permission status corresponding to the permission, and the application permission operation window; wherein the application permission operation window also includes an ignore operation option.

[0048] In some possible embodiments, the device further includes a permission request module, specifically configured to:

[0049] In response to a permission request operation of any application in the Windows system, displaying a permission request purpose and permission request content corresponding to the permission request operation based on the permission display interface;

[0050] In response to a triggering operation on the permission operation window in the permission display interface, the permission and permission status corresponding to the any application in the application permission list are updated based on the operation option triggering result.

[0051] In some possible embodiments, the device further includes a permission recording module, which is specifically configured to:

[0052] Obtain application permission behavior records within a preset time period in the Windows system, and generate a permission behavior analysis report based on the application permission behavior records; wherein the permission behavior analysis report includes application permission usage frequency and application permission change records.

[0053] An embodiment of the present disclosure provides a computer device, including: a processor, a memory, and a bus, wherein the memory stores machine-readable instructions executable by the processor, and when the computer device is running, the processor communicates with the memory via the bus, and when the machine-readable instructions are executed by the processor, the Windows application permission management method described in any possible implementation manner described above is performed.

[0054] An embodiment of the present disclosure provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the Windows application permission management method as described in any possible implementation manner described above is implemented.

[0055] The Windows application permission management method, apparatus, medium and device provided in the embodiments of the present disclosure enable users to manage and adjust the permission status (on or off) requested by each application by displaying the application permission list and the application permission operation window. In this way, not only the user experience and system security are improved, the permission management process is simplified, and application compliance is promoted, while having good flexibility and scalability to meet the permission management requirements of various applications in the Windows system.

[0056] In order to make the above-mentioned objectives, features and advantages of the present disclosure more obvious and easy to understand, preferred embodiments are specifically cited below and described in detail with reference to the attached drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the following briefly introduces the drawings required to be cited in the embodiments. The drawings herein are incorporated into the specification and constitute a part of the specification. These drawings illustrate embodiments consistent with the present disclosure and are used together with the specification to illustrate the technical solutions of the present disclosure. It should be understood that the following drawings only illustrate certain embodiments of the present disclosure and should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without creative work.

[0058] Figure 1 A flowchart of a Windows application permission management method provided by an embodiment of the present disclosure is shown;

[0059] Figure 2 A schematic diagram of a permission display mode selection window provided by an embodiment of the present disclosure is shown;

[0060] Figure 3 A schematic diagram showing a permission perspective display provided by an embodiment of the present disclosure is shown;

[0061] Figure 4 A schematic diagram showing an application angle display provided by an embodiment of the present disclosure is shown;

[0062] Figure 5 A flowchart of a permission monitoring method provided by an embodiment of the present disclosure is shown;

[0063] Figure 6 A schematic diagram of the structure of a Windows application rights management device provided by an embodiment of the present disclosure is shown;

[0064] Figure 7 A schematic diagram showing the structure of another Windows application rights management device provided by an embodiment of the present disclosure is shown;

[0065] Figure 8 A schematic diagram of the structure of a computer device provided by an embodiment of the present disclosure is shown. DETAILED DESCRIPTION

[0066] In order to make the purpose, technical scheme and advantages of the embodiments of the present disclosure clearer, the technical scheme in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only part of the embodiments of the present disclosure, rather than all of the embodiments. The components of the embodiments of the present disclosure generally described and shown in the drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present disclosure provided in the drawings is not intended to limit the scope of the present disclosure for protection, but merely represents the selected embodiments of the present disclosure. Based on the embodiments of the present disclosure, all other embodiments obtained by those skilled in the art without making creative work belong to the scope of protection of the present disclosure.

[0067] It should be noted that similar reference numerals and letters denote similar items in the following drawings, and therefore, once an item is defined in one drawing, further definition and explanation thereof is not required in subsequent drawings.

[0068] The term "and / or" herein only describes an association relationship, indicating that three relationships may exist. For example, A and / or B may represent the following three situations: A exists alone, A and B exist at the same time, and B exists alone. In addition, the term "at least one" herein represents any combination of at least two of any one or more of a plurality of. For example, including at least one of A, B, and C may represent including any one or more elements selected from the set consisting of A, B, and C.

[0069] With the vigorous development of Internet technology, computer technology, big data and other technologies, the collection and use of personal data has become the norm in daily life. However, this trend is also accompanied by a sharp increase in network security threats, such as hacker attacks, malware, ransomware and data theft, which have led to a large amount of personal sensitive information being illegally obtained or abused. The frequent occurrence of privacy leaks and the public attention they have aroused have prompted all sectors of society to attach great importance to privacy protection issues. Enterprises and developers are also under tremendous pressure and have to re-examine and strengthen user privacy protection mechanisms to prevent data from being maliciously leaked or abused.

[0070] According to research, mobile operating systems such as iOS and Android are relatively mature in application permission management, and are easy for users to operate and understand. However, application permission management on Windows systems is relatively backward, complicated and inconvenient to operate. Especially for ordinary users, the permission management of Windows systems is too cumbersome, the permission settings are scattered, and there is a lack of unified request and control mechanisms. Most users do not understand this very well, and are prone to granting too many permissions to applications without knowing it, or failing to effectively manage and restrict application permissions when facing security threats. In addition, the control of application permissions by the Windows system is not as detailed and intuitive as that of mobile terminals. Many applications obtain extensive permissions when they are installed or used for the first time, such as file system access and administrator permissions, making it difficult for users to clearly understand the data access status of the application. This not only increases the potential harm of malware, but also makes it impossible for users to manage the permissions and privacy settings of Windows applications as conveniently as managing mobile applications in daily use.

[0071] Based on the above research, a Windows application permission management method, apparatus, medium and device are provided in the embodiments of the present disclosure. First, an application permission list of the Windows system is obtained; wherein the Windows system includes multiple applications, and the application permission list includes multiple permissions corresponding to each application and a permission status corresponding to each permission, and the permission status includes an on state and a off state; then, the application permission list and the application permission operation window are displayed based on a permission display interface; wherein the application permission operation window includes two operation options, namely, allow and deny, so as to modify the permission status of any permission corresponding to any application based on the interactive operation corresponding to the application permission operation window.

[0072] In the disclosed embodiment, by displaying the application permission list and the operation window, the user can manage and adjust the permission status requested by each application, which simplifies the permission management process and improves the user experience.

[0073] To facilitate understanding of this embodiment, the execution subject of the Windows application permission management method provided by the embodiment of the present disclosure is first introduced in detail. The execution subject of the Windows application permission management method provided by the embodiment of the present disclosure is a computer device. The computer device can be a terminal device. Among them, the terminal device can also be a mobile device, a user terminal, a terminal, a handheld device, a computing device, a vehicle-mounted device, a wearable device, etc.

[0074] The Windows application permission management method provided by the embodiment of the present application is described in detail below with reference to the accompanying drawings. Figure 1 FIG. 1 is a flowchart of a Windows application permission management method provided by an embodiment of the present disclosure, and the method includes the following S101 to S102:

[0075] S101, obtaining an application permission list of the Windows system.

[0076] It is understandable that Windows system is a widely used computer operating system developed by Microsoft that supports the operation of a variety of software applications. The Windows system includes multiple applications (i.e., software programs that can perform specific functions). The application permission list is a list of all applications in the Windows system, their required permissions, and the permission status (on or off) corresponding to the permissions. Among them, permissions refer to the ability of an application to access operating system resources or data when performing its functions. It can be read and write permissions for specific files, access rights to the network, permissions to use system devices, etc. The granting of permissions is generally managed by the operating system through security policies or user settings; the permission status refers to whether these permissions are currently allowed (on) or prohibited (off).

[0077] Exemplarily, when obtaining the application permission list of the Windows system, the following steps (1) to (2) may be included:

[0078] (1) Scan all applications in the Windows system, identify and record the permissions and permission status corresponding to each application;

[0079] (2) Adjusting the permissions and permission status corresponding to each of the applications based on the sensitivity rules, and determining the application permission list based on the adjustment results.

[0080] Specifically, when scanning all applications in the Windows system, technical means, such as system API calls or professional software tools, can be used to identify and record the types of permissions requested by each application and whether these permissions are currently in the "on" state, that is, the application can access the resource without restriction, or the "off" state, that is, the application is restricted from accessing the resource. Then, the collected permission information is evaluated and adjusted based on sensitivity rules, where sensitivity rules are a series of standards formulated based on security policies, user privacy protection requirements and other factors to determine the degree of impact of a certain permission on system security and personal privacy. When adjusting the permissions and permission status corresponding to each application according to the sensitivity rules, the following steps (a) to (c) can be included:

[0081] (a) obtaining permission information of the Windows system; wherein the permission information includes a plurality of permissions and a function corresponding to each permission;

[0082] (b) determining a permission level based on the role corresponding to each permission and the sensitivity rule, and determining whether the permission corresponding to each application in the Windows system is a sensitive permission based on the permission level;

[0083] (c) When the permission corresponding to the application is a sensitive permission, the permission state corresponding to the permission is set to a closed state.

[0084] Here, since different permissions may have different degrees of impact on system security and personal privacy, all types of system permissions and the specific functions of each permission are collected in order to subsequently evaluate the permission level corresponding to each permission to determine whether each permission is a sensitive permission. The permission level reflects the sensitivity of the permission and can be divided into different levels such as high, medium, and low. According to these permission levels, it is determined whether the permissions corresponding to each application in the Windows system are sensitive permissions. Sensitive permissions usually refer to permissions that may pose a serious threat to system security or user privacy. In the case where the permissions corresponding to the application are determined to be sensitive permissions, in order to ensure system security and personal privacy protection, it may be necessary to increase the security level of certain permissions, that is, set the permission status corresponding to the permission to the closed state. This means that unless the user explicitly agrees or the system security policy allows it, the application will not be able to access these sensitive resources.

[0085] S102: Display the application permission list and the application permission operation window based on the permission display interface.

[0086] Specifically, after obtaining the application permission list, a clear and easy-to-operate permission display interface can be presented to the user. The permission display interface will display the application permission list, that is, the permission information corresponding to all installed applications (multiple permissions corresponding to each application and the permission status corresponding to each permission). Users can intuitively view the specific permissions required by each application through this interface, such as the permission information of application A is to allow storage access, allow camera use, and deny location services. This display interface provides users with a unified permission management entrance, simplifying the process of monitoring and adjusting permissions.

[0087] In this interface, in addition to listing each application and its related permissions, it also displays an "application permission operation window" that provides users with two basic operation options: "Allow" and "Deny". These two options allow users to easily manage the permissions of any application, thereby making personalized adjustments to the permission settings of different applications. For example, users can choose to allow an application to use the camera or location services, or they can choose to deny an application access to certain sensitive permissions, thereby protecting their privacy and device security.

[0088] It is understandable that when a user operates a permission of an application on the permission operation window, the system will respond in real time and update the permission status of the application through a series of background mechanisms. For example: when a user chooses "allow" or "deny" a specific permission, this operation can be converted into a corresponding permission change instruction and take effect immediately. Specifically, it includes: first, obtaining the permission information of the current application and checking the user's interactive input; then, modifying the permission settings of the application according to the user's choice, which may involve modifying the operating system's permission database or calling related APIs to adjust the application's permissions; finally, based on the updated permission status, the application permission list is updated and immediately fed back to the user interface to ensure that the user sees the latest permission configuration.

[0089] Reference Figure 2 As shown, in the present disclosure, when displaying the application permission list and the application permission operation window based on the permission display interface, the permission display mode selection window is first displayed based on the permission display interface. In the permission display mode selection window, two display mode options are provided: permission angle display and application angle display. The user can select the perspective from which the permission display interface displays the application permission list and the application permission operation window according to their needs in the permission display mode selection window. Here, in the permission angle display mode, the user can see the application corresponding to each permission and understand the permission status corresponding to each application; the application angle display is based on the application, and the user can see at a glance which permissions each application has requested and its current permission status.

[0090] For example, when the interactive instruction instructs the permission display interface to display the application from the perspective of permissions, the application corresponding to each permission and the permission status of each application, as well as the application permission operation window, are displayed based on the permission display interface according to the application permission list. At this time, the user can clearly know which applications have enabled or disabled a specific permission (such as storage access permission). Figure 3 As shown, taking the permission display interface shown in the figure as an example, the applications corresponding to permission A are application 1, application 2, application 3, and application 4; among them, permission A of application 1 and application 2 is in the enabled state, and permission A of application 3 and application 4 is in the disabled state; the applications corresponding to permission B are application 1 and application 4; among them, permission B of application 1 is in the disabled state, and permission B of application 4 is in the enabled state. Here, the user can use the application permission operation window to set the permission status corresponding to each application.

[0091] Exemplarily, when the interactive instruction instructs the permission display interface to display in an application perspective, the permission display interface displays the permission and permission status corresponding to each application, as well as the application permission operation window, based on the application permission list. Figure 4As shown, taking the permission display interface shown in the figure as an example, the permissions corresponding to application 1 include permission A, permission B, and permission Z, where permission A and permission Z are enabled permissions and permission B is disabled permissions; the permissions corresponding to application 2 include permission A, which is enabled. Here, users can use the application permission operation window to set the permission status corresponding to each application.

[0092] In some other embodiments, the permission display interface may also be displayed in other ways, which are not specifically limited here.

[0093] This disclosure provides two different display methods to help users manage and control the permissions of each application more efficiently. Whether managing from the perspective of permissions or from the perspective of applications, users can quickly view and adjust permission settings through a simple and intuitive interface, improving the user experience.

[0094] It is understandable that in order to protect user privacy and information security, Figure 5 As shown, a permission monitoring method provided by the present disclosure is used to ensure that each application operation is within the control and authorization scope of the user, specifically including the following S501 to S503:

[0095] S501, in response to a running operation of any application in the Windows system, determining whether the running operation of any application is an executable operation based on a permission status corresponding to the any application.

[0096] Specifically, in response to the running operation of any application in the Windows system, it is determined whether the running operation is an executable operation based on the permission status of the application, that is, the current permission setting of the application is checked to ensure whether it has obtained sufficient permissions to perform the operation.

[0097] S502, in which the permission status corresponding to the any application shows that the permission status corresponding to the running operation of the any application is enabled, and determines that the running operation corresponding to the any application is an executable operation; in response to the executable operation, displaying execution prompt information corresponding to the executable operation to the user, receiving the user's interaction information on the execution prompt information, and returning the running result corresponding to the executable operation based on the interaction information.

[0098] It is understandable that when it is found that the permission status of the application is turned on, it means that the application has sufficient permissions to perform the operation. At this time, the operation is determined to be an executable operation, and an execution prompt information is displayed to the user to inform the user that the operation will be performed. At the same time, the system will receive the user's interactive feedback on the prompt information (such as confirmation, rejection, etc.), and return the final operation result of the operation based on the user's interactive information. For example, a user grants a picture editing application permission to access the camera and album. When the application needs to take a picture or select a picture from the album for editing, it will remind the user of this behavior (such as displaying a pop-up window prompt), and only if the user agrees will it continue to perform the operation of taking a picture or selecting a picture. In this way, the user's right to know and control the operation is ensured to prevent malicious operations or unauthorized activities. Here, after the user completes the interaction, the user's authorization information can also be counted. If the permissions of an application are allowed by the user in multiple operations, it can be inferred based on this trend that when performing the same operation in the future, the user may not need to confirm the permission again, thereby reducing the user's operation steps. In addition, you can also stop asking the user for a period of time and then re-request permission confirmation after the period of time to further improve the user experience.

[0099] S503, when the permission status corresponding to the any application shows that the permission status corresponding to the running operation of the any application is a closed state or an unauthorized state, it is determined that the running operation corresponding to the any application is not an executable operation, and a warning interface is displayed to the user; wherein the warning interface includes the application name, the permission corresponding to the running operation, the permission status corresponding to the permission, and the application permission operation window; wherein the application permission operation window also includes an ignore operation option.

[0100] For example, if it is detected that the permission status of the application is closed or unauthorized, it means that the application lacks the permission required to perform a certain operation, and the operation will be judged as unexecutable. At this time, the system will pop up a warning interface to remind the user that the authorization status of the operation is closed or unauthorized, and display relevant information in detail, including the name of the application, the requested permissions, the current status of the permissions, and an application permission operation window so that users can directly view and manage application permissions. In this application permission operation window, users can not only choose to turn the permission on or off, but also choose whether to ignore the permission request operation to decide whether to allow the operation to continue. Similarly, if the user rejects the permission request multiple times, you can pause and ask again for a period of time to avoid frequently disturbing the user.

[0101] It can be understood that in order to enhance the permission management and operation transparency in the Windows system, the present disclosure proposes that when a permission request exists in any application in the Windows system, the permission request purpose and permission request content corresponding to the permission request are displayed on the permission display interface to ensure that the user can clearly understand the permission request content of the application and can flexibly manage and update the corresponding permission status, thereby improving the security of the system and the user's sense of control.

[0102] Specifically, when responding to a permission request operation from any application in the Windows system, the permission display interface presents detailed information about the permission request, namely the purpose of the permission request and the specific content of the permission request. Here, the purpose of the permission request is the reason why the application requests the permission, which may be to perform certain operations (such as accessing files, using cameras, obtaining location information, etc.), while the permission request content specifically describes the type of permissions the application wants to obtain and its scope. In this way, users can understand why the application requires specific permissions, which helps to enhance their right to know about permission requests.

[0103] Exemplarily, when a user interacts with the permission operation window in the permission display interface, the corresponding result is triggered according to the operation option selected by the user. Specifically, after the user makes a selection, the application permission list is updated according to the trigger result, that is, the permission items and permission status corresponding to the application are updated to ensure that the permission management system is always consistent with the user's decision. For example, if the user agrees to the permission requested by the application, the status of the permission is updated to "on"; if the user rejects the request, the permission status is updated to "off".

[0104] Exemplarily, the present disclosure also proposes to generate an analysis report based on application permission behavior records, aiming to help users understand the permission usage of applications in Windows systems within a specific time period. The length of the time period can be set as needed. By collecting and analyzing the permission behavior records of applications, an analysis report containing the frequency of application permission usage and permission change records is generated to help users or administrators track permission changes, detect abnormal behavior, and improve system security. In this way, it is helpful to promptly discover potential security risks or abuse, thereby effectively protecting user privacy and system security.

[0105] The Windows application permission management method, apparatus, medium and device provided in the embodiments of the present disclosure enable users to manage and adjust the permission status (on or off) requested by each application by displaying the application permission list and the application permission operation window. In this way, not only the user experience and system security are improved, the permission management process is simplified, and application compliance is promoted, while having good flexibility and scalability to meet the permission management requirements of various applications in the Windows system.

[0106] Those skilled in the art will appreciate that, in the above method of specific implementation, the order in which the steps are written does not imply a strict execution order and does not constitute any limitation on the implementation process. The specific execution order of the steps should be determined by their functions and possible internal logic.

[0107] Based on the same inventive concept, the embodiments of the present disclosure also provide a Windows application permission management device corresponding to the Windows application permission management method. Since the principle of solving the problem by the device in the embodiments of the present disclosure is similar to the above-mentioned Windows application permission management method in the embodiments of the present disclosure, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be repeated.

[0108] Reference Figure 6 FIG. 6 is a schematic diagram of a Windows application permission management device 600 provided in an embodiment of the present disclosure, wherein the device includes:

[0109] The permission acquisition module 601 is used to acquire an application permission list of the Windows system; wherein the Windows system includes multiple applications, the application permission list includes multiple permissions corresponding to each application and a permission state corresponding to each permission, and the permission state includes an open state and a closed state;

[0110] The permission display module 602 is used to display the application permission list and the application permission operation window based on the permission display interface; wherein the application permission operation window includes two operation options of allow and deny, so as to modify the permission status of any permission corresponding to any application based on the interactive operation corresponding to the application permission operation window.

[0111] In some possible embodiments, the permission acquisition module 601 is specifically used to:

[0112] Scan all applications in the Windows system, identify and record the permissions and permission status corresponding to each application;

[0113] The permissions and permission status corresponding to each of the applications are adjusted based on the sensitivity rules, and the application permission list is determined based on the adjustment results.

[0114] In some possible embodiments, the permission acquisition module 601 is specifically used to:

[0115] Obtaining permission information of the Windows system; wherein the permission information includes multiple permissions and a function corresponding to each permission;

[0116] Determine a permission level based on the role corresponding to each permission and the sensitivity rule, and determine whether the permission corresponding to each application in the Windows system is a sensitive permission based on the permission level;

[0117] In the case where the permission corresponding to the application is a sensitive permission, the permission state corresponding to the permission is set to a closed state.

[0118] In some possible embodiments, the permission display module 602 is specifically used to:

[0119] Based on the permission display interface, a permission display mode selection window is displayed; wherein the permission display mode selection window includes two display mode options: permission perspective display and application perspective display;

[0120] In response to the interactive instruction of the permission display mode selection window, displaying the application permission list and the application permission operation window on the permission display interface based on the interactive instruction includes:

[0121] In the case where the interaction instruction instructs the permission display interface to display in the manner of displaying from the perspective of the permission, displaying the application corresponding to each permission and the permission status corresponding to each application, and the application permission operation window based on the permission display interface according to the application permission list;

[0122] When the interaction instruction instructs the permission display interface to be displayed in the manner of displaying from the application perspective, the permission and permission status corresponding to each application and the application permission operation window are displayed based on the permission display interface according to the application permission list.

[0123] In some possible embodiments, the permission status also includes an unauthorized state, referring to Figure 7 As shown, the device also includes a permission monitoring module 603, which is specifically used to:

[0124] In response to a running operation of any application in the Windows system, determining whether the running operation of any application is an executable operation based on a permission status corresponding to the any application;

[0125] In the permission status corresponding to the any application, it is displayed that the permission status corresponding to the running operation of the any application is enabled, and it is determined that the running operation corresponding to the any application is an executable operation; in response to the executable operation, execution prompt information corresponding to the executable operation is displayed to the user, and interaction information of the user to the execution prompt information is received, and the running result corresponding to the executable operation is returned based on the interaction information;

[0126] In the permission status corresponding to the any application, it is displayed that the permission status corresponding to the running operation of the any application is a closed state or an unauthorized state, it is determined that the running operation corresponding to the any application is not an executable operation, and a warning interface is displayed to the user; wherein the warning interface includes the application name, the permission corresponding to the running operation, the permission status corresponding to the permission, and the application permission operation window; wherein the application permission operation window also includes an ignore operation option.

[0127] In some possible embodiments, the device further includes a permission request module 604, which is specifically configured to:

[0128] In response to a permission request operation of any application in the Windows system, displaying a permission request purpose and permission request content corresponding to the permission request operation based on the permission display interface;

[0129] In response to a triggering operation on the permission operation window in the permission display interface, the permission and permission status corresponding to the any application in the application permission list are updated based on the operation option triggering result.

[0130] In some possible embodiments, the device further includes a permission recording module 605, which is specifically configured to:

[0131] Obtain application permission behavior records within a preset time period in the Windows system, and generate a permission behavior analysis report based on the application permission behavior records; wherein the permission behavior analysis report includes application permission usage frequency and application permission change records.

[0132] Based on the same technical concept, the embodiment of the present disclosure also provides a computer device. Figure 8 , which is a schematic diagram of the structure of a computer device 800 provided in an embodiment of the present disclosure, including a processor 801, a memory 802, and a bus 803. The memory 802 is used to store execution instructions, including a memory 8021 and an external memory 8022; the memory 8021 is also called an internal memory, which is used to temporarily store the operation data in the processor 801 and the data exchanged with the external memory 8022 such as a hard disk. The processor 801 exchanges data with the external memory 8022 through the memory 8021.

[0133] In the embodiment of the present application, the memory 802 is specifically used to store the application code for executing the solution of the present application, and the execution is controlled by the processor 801. That is, when the computer device 800 is running, the processor 801 communicates with the memory 802 through the bus 803, so that the processor 801 executes the application code stored in the memory 802, and then executes the method described in any of the above embodiments.

[0134] Among them, the memory 802 can be, but is not limited to, random access memory (Random Access Memory, RAM), read only memory (Read Only Memory, ROM), programmable read-only memory (Programmable Read-Only Memory, PROM), erasable programmable read-only memory (Erasable Programmable Read-Only Memory, EPROM), electrically erasable read-only memory (Electric Erasable Programmable Read-Only Memory, EEPROM), etc.

[0135] Processor 801 may be an integrated circuit chip with signal processing capabilities. The above-mentioned processor may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. The disclosed methods, steps and logic block diagrams in the embodiments of the present invention may be implemented or executed. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0136] It is to be understood that the structure illustrated in the embodiment of the present application does not constitute a specific limitation on the computer device 800. In other embodiments of the present application, the computer device 800 may include more or fewer components than shown in the figure, or combine some components, or split some components, or arrange the components differently. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware.

[0137] The present disclosure also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the Windows application permission management method described in the above method embodiment are executed. The storage medium can be a volatile or non-volatile computer-readable storage medium.

[0138] The embodiments of the present disclosure also provide a computer program product, which carries a program code. The instructions included in the program code can be used to execute the steps of the Windows application permission management method described in the above method embodiment. For details, please refer to the above method embodiment, which will not be repeated here.

[0139] The computer program product may be implemented in hardware, software or a combination thereof. In one optional embodiment, the computer program product is implemented as a computer storage medium. In another optional embodiment, the computer program product is implemented as a software product, such as a software development kit (SDK).

[0140] Those skilled in the art can clearly understand that, for the convenience and simplicity of description, the specific working process of the system and device described above can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here. In the several embodiments provided in the present disclosure, it should be understood that the disclosed system and method can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0141] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0142] In addition, each functional unit in each embodiment of the present disclosure may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0143] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a non-volatile computer-readable storage medium that is executable by a processor. Based on this understanding, the technical solution of the present disclosure, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present disclosure. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0144] Finally, it should be noted that the above-described embodiments are only specific implementation methods of the present disclosure, which are used to illustrate the technical solutions of the present disclosure, rather than to limit them. The protection scope of the present disclosure is not limited thereto. Although the present disclosure is described in detail with reference to the above-described embodiments, ordinary technicians in the field should understand that any technician familiar with the technical field can still modify the technical solutions recorded in the above-described embodiments within the technical scope disclosed in the present disclosure, or can easily think of changes, or make equivalent replacements for some of the technical features therein; and these modifications, changes or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present disclosure, and should be included in the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure should be based on the protection scope of the claims.

Claims

1. A Windows application rights management method, characterized in that: include: Obtain an application permission list of the Windows system; wherein the Windows system includes multiple applications, the application permission list includes multiple permissions corresponding to each application and a permission status corresponding to each permission, and the permission status includes an on state and a off state; The application permission list and the application permission operation window are displayed based on the permission display interface; wherein the application permission operation window includes two operation options of allow and deny, so as to modify the permission status of any permission corresponding to any application based on the interactive operation corresponding to the application permission operation window.

2. The method according to claim 1, characterized in that: The obtaining of the Windows system application permission list includes: Scan all applications in the Windows system, identify and record the permissions and permission status corresponding to each application; The permissions and permission status corresponding to each of the applications are adjusted based on the sensitivity rules, and the application permission list is determined based on the adjustment results.

3. The method according to claim 2, characterized in that The adjusting the permission and permission status corresponding to each of the applications based on the sensitivity rule includes: Obtaining permission information of the Windows system; wherein the permission information includes multiple permissions and a function corresponding to each permission; Determine a permission level based on the role corresponding to each permission and the sensitivity rule, and determine whether the permission corresponding to each application in the Windows system is a sensitive permission based on the permission level; In the case where the permission corresponding to the application is a sensitive permission, the permission state corresponding to the permission is set to a closed state.

4. The method according to claim 3, characterized in that The displaying of the application permission list and the application permission operation window based on the permission display interface includes: Based on the permission display interface, a permission display mode selection window is displayed; wherein the permission display mode selection window includes two display mode options: permission perspective display and application perspective display; In response to the interactive instruction of the permission display mode selection window, displaying the application permission list and the application permission operation window on the permission display interface based on the interactive instruction includes: In the case where the interaction instruction instructs the permission display interface to display in the manner of displaying from the perspective of the permission, displaying the application corresponding to each permission and the permission status corresponding to each application, and the application permission operation window based on the permission display interface according to the application permission list; When the interaction instruction instructs the permission display interface to be displayed in the manner of displaying from the application perspective, the permission and permission status corresponding to each application and the application permission operation window are displayed based on the permission display interface according to the application permission list.

5. The method according to claim 1, characterized in that The permission status also includes an unauthorized state, and the method further includes: In response to a running operation of any application in the Windows system, determining whether the running operation of any application is an executable operation based on a permission status corresponding to the any application; In the permission status corresponding to the any application, it is displayed that the permission status corresponding to the running operation of the any application is enabled, and it is determined that the running operation corresponding to the any application is an executable operation; in response to the executable operation, execution prompt information corresponding to the executable operation is displayed to the user, and interaction information of the user to the execution prompt information is received, and the running result corresponding to the executable operation is returned based on the interaction information; In the permission status corresponding to the any application, it is displayed that the permission status corresponding to the running operation of the any application is a closed state or an unauthorized state, it is determined that the running operation corresponding to the any application is not an executable operation, and a warning interface is displayed to the user; wherein the warning interface includes the application name, the permission corresponding to the running operation, the permission status corresponding to the permission, and the application permission operation window; wherein the application permission operation window also includes an ignore operation option.

6. The method according to any one of claims 1 to 5, characterized in that: The method further comprises: In response to a permission request operation of any application in the Windows system, displaying a permission request purpose and permission request content corresponding to the permission request operation based on the permission display interface; In response to a triggering operation on the permission operation window in the permission display interface, the permission and permission status corresponding to the any application in the application permission list are updated based on the operation option triggering result.

7. The method according to any one of claims 1 to 5, characterized in that: The method further comprises: Obtain application permission behavior records within a preset time period in the Windows system, and generate a permission behavior analysis report based on the application permission behavior records; wherein the permission behavior analysis report includes application permission usage frequency and application permission change records.

8. A Windows application rights management device, characterized in that: include: A permission acquisition module, used to acquire an application permission list of a Windows system; wherein the Windows system includes multiple applications, the application permission list includes multiple permissions corresponding to each application and a permission status corresponding to each permission, and the permission status includes an open state and a closed state; A permission display module is used to display the application permission list and the application permission operation window based on the permission display interface; wherein the application permission operation window includes two operation options: allow and deny, so as to modify the permission status of any permission corresponding to any application based on the interactive operation corresponding to the application permission operation window.

9. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.

10. A computer device comprising a storage medium, a processor, and a computer program stored in the storage medium and executable on the processor, characterized in that: When the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.