Authority management method and terminal equipment
By caching the application's permission information in the kernel of the terminal device and using the system call interface for permission verification, the problem that the permission verification communication between the application and the sensitive resource provider affects performance, achieving more efficient permission management and improved user experience.
Patent Information
- Application Number
- CN202311520428.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-14
- Publication Date
- 2025-05-16
AI Technical Summary
Permission verification communication between applications in terminal devices and sensitive resource providers affects overall performance, resulting in performance degradation and poor user experience.
By caching the permission information of the application in the kernel and using the system call interface for permission verification, the proportion of communication between processes is reduced and permissions is directly managed in the kernel.
It effectively improves the overall performance of terminal devices and the performance of permission verification interfaces, and improves the user experience.
Smart Images

Figure CN120012057A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of terminal technology, and in particular to a permission management method and terminal device. Background Art
[0002] With the rapid development of terminal application technology, more and more applications (applications, APPs) can be installed on terminal devices. While the information interaction between applications brings great convenience to users, it also brings some security risks. In order to protect user privacy and device security, when an application accesses sensitive resources (such as cameras, location information or user data, etc.), the application sends an access request to the sensitive resource provider. The sensitive resource provider verifies whether the application is granted permission to call sensitive resources based on the access request. If the application has been granted permission, the sensitive resource provider allows the application to access sensitive resources; otherwise, the sensitive resource provider rejects the application's access request. For example, when a shopping app in a terminal device is installed for the first time, the user grants the shopping app permission to access camera resources based on the content of the dynamic pop-up window. When the user uses the shopping app to take photos and search for products, the shopping app sends an access request to the camera service in the terminal device. The camera service determines that the shopping app has been granted permission to access camera resources based on the access request, and allows the shopping app to use the camera function to take pictures of products.
[0003] However, the communication between the application and the sensitive resource provider during permission verification in the above solution will affect the overall performance of the terminal device. Therefore, how to optimize the permission verification in the terminal device has become a technical problem that needs to be solved urgently. Summary of the invention
[0004] The present application provides a permission management method and terminal device, which can optimize the permission management strategy and improve the overall performance of the terminal device.
[0005] In order to achieve the above technical objectives, this application provides the following technical solutions:
[0006] In a first aspect, the present application provides a permission management method, which includes: in response to a user's instruction to call a first sensitive resource in a first application, the terminal device obtains the current permission information of the first application from the kernel; the terminal device determines whether the first application has permission to call the first sensitive resource based on the current permission information of the first application.
[0007] In this method, the permission information of each application of the terminal device is stored in the kernel. When the first application runs and calls sensitive resources, the current permission information of the first application is obtained from the kernel through the system service, and the permission is checked according to the current permission information of the first application. This application manages permissions through kernel system calls, without the need to manage permissions through inter-process communication, which greatly reduces the proportion of IPC communication of permission services during permission verification and effectively improves the performance of the entire machine. In addition, there is no need for cross-process communication when verifying permissions, which effectively improves the performance of the permission verification interface and improves the user experience.
[0008] According to the first aspect, permission information of at least one application is stored in the kernel, and the at least one application includes a first application.
[0009] The first application includes system applications and / or third-party applications that come with the terminal device system.
[0010] According to the first aspect, or any implementation of the first aspect above, before the terminal device obtains the current permission information of the first application from the kernel in response to the user's instruction to call the first sensitive resource in the first application, the method also includes: the terminal device obtains the initialization permission of the first application; the terminal device sends a cache request to the kernel through the system call interface; the kernel of the terminal device determines whether to cache the initialization permission of the first application based on the cache request; if caching is determined, the kernel caches the initialization permission of the first application; otherwise, the kernel does not cache the initialization permission of the first application.
[0011] In some examples, the initialization permission is the permission corresponding to the first application when the first application is installed; the cache request includes the initialization permission of the first application; and the first sensitive resource is a sensitive resource of the terminal device system.
[0012] In some examples, the first sensitive resources include user data, application data, and / or system functionality.
[0013] In some examples, the kernel of the terminal device determines whether the cache request satisfies a first preset condition. If so, the kernel caches the initialization permission of the first application; otherwise, the kernel does not cache the initialization permission of the first application.
[0014] Among them, the first preset condition is: the process that initiates the cache request is a rights management service.
[0015] In this way, in this embodiment, the kernel only allows the authorized permission management service to manage permission information, preventing other applications from rewriting permission information, reducing the probability of privacy data leakage, and improving the security of terminal devices.
[0016] In some examples, a terminal device obtains initialization permissions for a first application, including: when the first application is installed, the terminal device receives a user's setting operation for each permission involved in the first application and the permission status corresponding to each permission, and the terminal device obtains initialization permissions for the first application in response to the setting operation.
[0017] In other examples, the terminal device obtains the initialization permission of the first application, including: when the first application is installed, the user does not change the relevant permissions of the first application, and the terminal device obtains the default initialization permission of the first application.
[0018] According to the first aspect, or any implementation method of the first aspect above, the terminal device obtains the current permission information of the first application from the kernel in response to the user's instruction to call the first sensitive resource in the first application, including: the terminal device sends a permission verification request to the kernel through the system call interface in response to the user's instruction to call the first sensitive resource in the first application; the terminal device obtains the current permission information of the first application from the kernel according to the permission verification request.
[0019] According to the first aspect, or any implementation of the first aspect above, the permission verification request includes parameter information of the first application and parameter information of the first sensitive resource.
[0020] In some examples, the current permission information of the first application is all the permission information of the current first application. In response to the user's instruction to call the first sensitive resource in the first application, the terminal device sends a permission verification request to the permission service that provides the first sensitive resource through inter-process communication. The permission service obtains all the permission information of the current first application from the kernel through the system call interface according to the permission verification request.
[0021] In other examples, the current permission information of the first application is the permission information corresponding to the first sensitive resource in the current first application. In response to the user's instruction to call the first sensitive resource in the first application, the first application sends a permission verification request to the permission service that provides the first sensitive resource through inter-process communication. The permission service obtains the permission information corresponding to the first sensitive resource in the current first application from the kernel through the system call interface according to the permission verification request.
[0022] According to the first aspect, or any implementation method of the first aspect above, the terminal device determines whether the first application has permission to call the first sensitive resource based on the current permission information of the first application, including: if the terminal device determines that the first application has permission to call the first sensitive resource based on the current permission information of the first application, the terminal device allows the first application to call the first sensitive resource; or, if the terminal device determines that the first application does not have permission to call the first sensitive resource based on the current permission information of the first application, the terminal device refuses the first application to call the first sensitive resource.
[0023] In some examples, if the current permission information of the first application indicates that the first application is allowed to access the first sensitive resource, it is determined that the first application has permission to call the first sensitive resource. Alternatively, if the current permission information of the first application indicates that the first application is not allowed to access the first sensitive resource, it is determined that the first application does not have permission to call the first sensitive resource.
[0024] According to the first aspect, or any implementation method of the first aspect above, the terminal device determines whether the first application has permission to call the first sensitive resource based on the current permission information of the first application, including: the terminal device determines whether the first application has permission to call the first sensitive resource based on the current permission information of the first application and the parameter information of the first sensitive resource.
[0025] According to the first aspect, or any implementation of the first aspect above, the method further includes: the terminal device updates the permission information of the first application currently cached in the kernel in response to the user's operation of updating the permission information of the first application.
[0026] According to the first aspect, or any implementation method of the first aspect above, the terminal device updates the permission information of the first application currently cached in the kernel in response to the user's operation of updating the permission information of the first application, including: the terminal device sends an update request to the kernel through the system call interface in response to the user's operation of updating the permission information of the first application; the kernel of the terminal device determines whether to update according to the cache request; if it is determined to update, the kernel updates the permission information of the first application currently cached according to the updated permission information of the first application; otherwise, the kernel does not update the permission information of the first application currently cached.
[0027] In some examples, the update request includes updated permission information of the first application.
[0028] In some examples, the kernel of the terminal device determines whether the update request satisfies a second preset condition. If so, the kernel performs an update according to the updated permission information of the first application; otherwise, the kernel does not perform an update.
[0029] The second preset condition is that the process that initiates the update request is a rights management service.
[0030] In this way, the terminal device responds to the user's update operation and updates the permission information of each application cached in the memory in real time, so that when an application calls a sensitive resource manager, it can obtain the latest permission information corresponding to the application, thereby improving accuracy.
[0031] In a second aspect, the present application provides a terminal device, comprising: one or more processors; a memory; wherein one or more computer programs are stored in the memory, and the one or more computer programs include instructions; when the instructions are executed by the terminal device, the terminal device executes: the terminal device responds to the user's instruction to call a first sensitive resource in the first application, and obtains the current permission information of the first application from the kernel; the terminal device determines whether the first application has the permission to call the first sensitive resource based on the current permission information of the first application.
[0032] In a third aspect, the present application provides a chip system comprising at least one processor and at least one interface circuit, wherein the at least one interface circuit is used to perform transceiver functions and send instructions to at least one processor, and when the at least one processor executes the instructions, the at least one processor executes a method as described in the first aspect or any one of the embodiments of the first aspect.
[0033] In a fourth aspect, the present application provides a computer-readable storage medium, which includes a computer program or instructions. When the computer program or instructions are run on a computer, the computer executes a method as described in the first aspect or any one of the embodiments of the first aspect.
[0034] In a fifth aspect, the present application provides a computer program product, which includes: a computer program or instructions, which, when the computer program or instructions are run on a computer, enable the computer to execute a method as described in the first aspect or any one of the embodiments of the first aspect.
[0035] It should be noted that the technical effects brought about by any design in the above-mentioned second to fifth aspects can refer to the technical effects brought about by the corresponding design in the first aspect, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Figure 1 A schematic diagram of a process for implementing permission verification based on an inter-process communication mechanism provided in an embodiment of the present application;
[0037] Figure 2 A schematic diagram of a terminal device provided in an embodiment of the present application Figure 1 ;
[0038] Figure 3 A schematic diagram of a system architecture of a terminal device provided in an embodiment of the present application;
[0039] Figure 4 A schematic diagram of a permission management method provided in an embodiment of the present application Figure 1 ;
[0040] Figure 5 A scenario example of a permission management method provided in an embodiment of the present application Figure 1 ;
[0041] Figure 6 A scenario example of a rights management method provided in an embodiment of the present application Figure 2 ;
[0042] Figure 7 A schematic diagram of a permission management method provided in an embodiment of the present application Figure 2 ;
[0043] Figure 8 A schematic diagram of a terminal device provided in an embodiment of the present application Figure 2 ;
[0044] Fig. 9 A schematic diagram of the structure of a chip system provided in an embodiment of the present application. DETAILED DESCRIPTION
[0045] In the description of the embodiments of the present application, unless otherwise specified, " / " means or, for example, A / B can mean A or B; "and / or" in this article is merely a way to describe the association relationship of associated objects, indicating that three relationships may exist, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone.
[0046] In the following, the terms "first" and "second" are used for descriptive purposes only and are not to be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features.
[0047] In the description of the embodiments of the present application, unless otherwise specified, "multiple" means two or more. In the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or descriptions. Any embodiment or design described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a concrete way.
[0048] In some examples, such as Figure 1 As shown, the terminal device implements permission verification based on the inter-process communication (IPC) mechanism. Specifically, the application process and the permission service process complete cross-process communication through the IPC communication mechanism to implement permission verification. The stub of the permission service process registers the permission service in the service manager (sa manager). The application process (which can be understood as the client) initiates a permission verification request, and the proxy of the application process obtains the proxy object of the permission service from the sa manager. Subsequently, the proxy communicates with the stub, that is, the proxy sends the proxy object to the stub of the permission service process through the underlying driver (such as Binder or soft bus). The permission service process (which can be understood as the server) performs permission verification based on the proxy object to determine the permission status of the application (that is, whether the application is granted permission, if the application is granted permission, the permission status is authorized, and if the application is not granted permission, the permission status is unauthorized).
[0049] However, in the above example, the number of IPC communications during permission verification accounts for a large proportion of the IPC communications of the terminal device, accounting for approximately 20%. This will occupy the communication resources of other processes, thereby affecting the performance of the entire device. In addition, cross-process communication involves task scheduling between different processes, which requires frequent process switching, resulting in large fluctuations in the performance of the permission verification interface during permission verification, resulting in a certain delay, which does not meet the requirements of performance-sensitive scenarios or API calls.
[0050] In order to solve the technical problems described above, the embodiment of the present application provides a permission management method. When the first application is installed, the initialization permission of the first application is cached to the kernel through the system service. When the user updates the permission of the first application, the permission of the first application is updated through the system service. When the first application runs and calls sensitive resources, the current permission information of the first application is obtained from the kernel through the system service, and permission verification is performed. The method provided by the embodiment of the present application optimizes the permission management strategy, improves the overall performance during permission verification, and also improves the permission verification interface performance and user experience.
[0051] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all of the embodiments.
[0052] In some embodiments of the present application, the terminal device may include but is not limited to a smart phone, a netbook, a tablet computer, a smart drawing board, a handwriting board, a smart watch, a smart bracelet, a phone watch, smart glasses, a smart camera, a PDA, a car computer, a personal computer (PC), a personal digital assistant (PDA), a portable multimedia player (PMP), an augmented reality (AR) / virtual reality (VR) device, a smart TV, a projection device, or a somatosensory game console in a human-computer interaction scene, etc. Alternatively, the terminal device may also be a terminal device of other types or structures, which is not limited in the present application.
[0053] As an example, see Figure 2 , Figure 2 A schematic diagram of the hardware structure of a terminal device provided in an embodiment of the present application is shown.
[0054] like Figure 2 As shown, the terminal device may include a processor 210, a memory (including an external memory interface 220 and an internal memory 221), a universal serial bus (USB) interface 230, a charging management module 240, a power management module 241, a battery 242, an antenna 1, an antenna 2, a mobile communication module 250, a wireless communication module 260, an audio module 270, a speaker 270A, a receiver 270B, a microphone 270C, an earphone interface 270D, a sensor module 280, a button 290, a motor 291, an indicator 292, a camera 293, a display screen 294, etc. Among them, the sensor module 280 may include a touch sensor and a pressure sensor. Optionally, the sensor module 280 may also include a gyroscope sensor, an air pressure sensor, a magnetic sensor, an acceleration sensor, a distance sensor, a proximity light sensor, a fingerprint sensor, a temperature sensor, an ambient light sensor, a bone conduction sensor, etc.
[0055] It is to be understood that the structure illustrated in the embodiment of the present invention does not constitute a specific limitation on the terminal device. In other embodiments of the present application, the terminal device may include more or fewer components than shown in the figure, or combine certain components, or split certain components, or arrange the components differently. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware.
[0056] The processor 210 may include one or more processing units. For example, the processor 210 may include an application processor (AP), a modem processor, a graphics processor (GPU), an image signal processor (ISP), a flight controller, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU). Different processing units may be independent devices or integrated into one or more processors.
[0057] The processor 210 may also be provided with a memory for storing instructions and data. In some embodiments, the memory in the processor 210 is a cache memory. The memory may store instructions or data that the processor 210 has just used or cyclically used. If the processor 210 needs to use the instruction or data again, it may be directly called from the memory. This avoids repeated access, reduces the waiting time of the processor 210, and thus improves the efficiency of the system.
[0058] In some embodiments, the processor 210 may include one or more interfaces. The interface may include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface, etc.
[0059] The charging management module 240 is used to receive charging input from the charger. The power management module 241 is used to connect the battery 242, the charging management module 240 and the processor 210. The power management module 241 receives input from the battery 242 and / or the charging management module 240 to power the processor 210, the internal memory 221, the display screen 294, the camera 293 and the wireless communication module 260.
[0060] The wireless communication function of the terminal device can be realized through antenna 1, antenna 2, mobile communication module 250, wireless communication module 260, modem processor and baseband processor.
[0061] Antenna 1 and antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in the terminal device can be used to cover a single or multiple communication frequency bands. Different antennas can also be reused to improve the utilization of the antennas. For example, antenna 1 can be reused as a diversity antenna for a wireless local area network. In some other embodiments, the antenna can be used in combination with a tuning switch.
[0062] The mobile communication module 250 can provide solutions for wireless communications including 2G / 3G / 4G / 5G applied to terminal devices. The mobile communication module 250 may include at least one filter, switch, power amplifier, low noise amplifier (LNA), etc. The mobile communication module 250 may receive electromagnetic waves from the antenna 1, filter, amplify, and process the received electromagnetic waves, and transmit them to the modulation and demodulation processor for demodulation. The mobile communication module 250 may also amplify the signal modulated by the modulation and demodulation processor, and convert it into electromagnetic waves for radiation through the antenna 1. The modulation and demodulation processor may include a modulator and a demodulator. Among them, the modulator is used to modulate the low-frequency baseband signal to be sent into a medium-high frequency signal. The demodulator is used to demodulate the received electromagnetic wave signal into a low-frequency baseband signal. The demodulator then transmits the demodulated low-frequency baseband signal to the baseband processor for processing. After the low-frequency baseband signal is processed by the baseband processor, it is transmitted to the application processor. The application processor outputs sound signals through an audio device (not limited to the speaker 270A, the receiver 270B, etc.), or displays images or videos through the display screen 294.
[0063] The wireless communication module 260 can provide wireless communication solutions applied to terminal devices, including wireless local area networks (WLAN) (such as WiFi networks), Bluetooth BT, global navigation satellite system (GNSS), frequency modulation (FM), near field communication technology (NFC), infrared technology (IR), etc.
[0064] In some embodiments, the antenna 1 of the terminal device is coupled to the mobile communication module 250, and the antenna 2 is coupled to the wireless communication module 260, so that the terminal device can communicate with the network and other devices through wireless communication technology. The wireless communication technology may include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technology. The GNSS may include a global positioning system (GPS), a global navigation satellite system (GLONASS), a Beidou navigation satellite system (BDS), a quasi-zenith satellite system (QZSS) and / or a satellite based augmentation system (SBAS).
[0065] In some embodiments of the present application, the coupling of antenna 1 and mobile communication module 250 and the coupling of antenna 2 and wireless communication module 260 can be used to support communication between the terminal device and other terminal devices or network devices, such as receiving and sending one or more data such as device information, device capability information, user data, application data, application version information, etc. with other terminal devices.
[0066] The terminal device implements the display function through a GPU, a display screen 294, and an application processor. The GPU is a microprocessor for image processing, which connects the display screen 294 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. The processor 210 may include one or more GPUs, which execute program instructions to generate or change display information.
[0067] The display screen 294 is used to display images, videos, etc. The display screen 294 includes a display panel.
[0068] The external memory interface 220 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the terminal device. The external memory card communicates with the processor 210 through the external memory interface 220 to implement a data storage function.
[0069] The internal memory 221 can be used to store computer executable program codes. Exemplarily, the computer program may include an operating system program and an application program. Among them, the executable program code includes instructions. The processor 210 executes various functional applications and data processing of the terminal device by running the instructions stored in the internal memory 221. The internal memory 221 may include a program storage area and a data storage area. Among them, the program storage area may store an operating system, an application program required for at least one function, etc. The data storage area may store data created during the use of the terminal device, etc. In addition, the internal memory 221 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), etc. The processor 210 executes various functional applications and data processing of the terminal device by running the instructions stored in the internal memory 221, and / or the instructions stored in the memory provided in the processor.
[0070] In some embodiments of the present application, the internal memory 221 and / or the external memory card connected to the external memory interface 220 can be used to store application-related data, user data, etc. Application-related data such as application information and account information are not specifically limited in the embodiments of the present application, but depend on the specific device functions and application configurations, etc.
[0071] The terminal device can implement audio functions such as music playing and recording through the audio module 270, the speaker 270A, the receiver 270B, the microphone 270C and the application processor.
[0072] For the introduction of hardware such as the button 290 , the motor 291 , and the indicator 292 , reference may be made to conventional technologies, and the embodiments of the present application will not be described in detail.
[0073] It is understandable that this application Figure 2 The illustrated structure does not constitute a specific limitation on the terminal device. In other embodiments of the present application, the terminal device may include more or fewer components than shown in the figure, or combine some components, or split some components, or arrange the components differently. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.
[0074] The permission management method provided in the embodiment of the present application can be applied to scenarios involving accessing / calling sensitive resources. For example, when an application needs to access sensitive resources during use, the sensitive resource provider needs to verify whether the application is granted permission to access sensitive resources. If authorized, the application is allowed to access sensitive resources, otherwise the application is denied access to sensitive resources. The embodiment of the present application does not impose any special restrictions on the specific form of the scenario of accessing sensitive resources.
[0075] For example, Figure 3 A schematic diagram of the system architecture of a terminal device provided in an embodiment of the present application is shown.
[0076] like Figure 3 As shown, the system of the terminal device may include an application layer, a framework layer and a kernel layer.
[0077] In the embodiment of the present application, the application layer includes application programs and permission management applications. Among them, the application programs include various types of applications installed on the terminal device. For example, communication applications, shopping applications, work applications, etc. The permission management application is used to manage the permissions of each application in the terminal device. For example, the permission management application is a settings application.
[0078] In an embodiment of the present application, the application includes a system application and / or a third-party application that comes with the terminal device system. Among them, the system application can also be called an embedded application, and the embedded application is an application that is a part of the function implemented by the terminal device. The third-party application can also be called a downloadable application. A downloadable application is an application that can provide its own Internet protocol multimedia subsystem (IMS) connection. The downloadable application can be an application pre-installed in the terminal device or can be an application downloaded and installed in the terminal device by the user.
[0079] It can be understood that the permission management application in the above example is a type of application in the application program, and is shown separately for the convenience of explaining the interaction process of each module in the permission management method.
[0080] In the embodiment of the present application, the framework layer (which can also be described as the system layer) includes a package management service, a permission management service, and a permission service. Among them, the package management service is used to manage the installation of applications. The permission management service is used to manage the various permissions involved in each application in the terminal device. The permission service is used to determine the permission status of the application that calls the permission, and determine whether the application can call the sensitive resources corresponding to the permission based on the permission status.
[0081] In the embodiment of the present application, the permission status includes an authorized status and an unauthorized status. The authorized status is used to indicate that the application is granted permission, and the unauthorized status is used to indicate that the application is not granted permission. The permission status may also include an inquiry status, and the inquiry status is used to indicate that when the application uses the sensitive information corresponding to the permission, the terminal device asks the user whether to grant the application permission to use the sensitive information. That is, each time the application uses the sensitive information, the user's intention is asked, and permission is granted or not authorized based on the user's intention. The embodiment of the present application does not limit the specific information of the permission status.
[0082] It is understandable that the permission service includes the service corresponding to each sensitive resource in the terminal device, such as camera service, recording service, etc.
[0083] In the embodiment of the present application, the kernel layer includes inter-process communication and the kernel. Among them, the inter-process communication is used for the application to interact with the permission service so that the permission service can determine the permission status of the application. The kernel includes a permission cache, which is used to cache the permission status of various permissions involved in each application.
[0084] For ease of understanding, the interaction process between the modules in the above system architecture is explained below in conjunction with the life cycle of the application.
[0085] In the embodiment of the present application, when the application is installed, the package management service obtains the initialization permission of the application and sends the initialization permission to the permission management service. For example, the package management service calls the process to send the initialization permission of the application to the permission management service. The permission management service uses the system call interface ( Figure 3(shown in the figure) calls the process to set the initialization permission of the application to the kernel's permission cache. The permission cache verifies whether the process that sends the initialization permission of the application to itself (that is, the process that the permission management service sends the initialization permission of the application to the permission cache) has the permission to set various permissions and permission states. If so, the initialization permission of the application is cached in the permission cache; otherwise, the initialization permission of the application is not cached and a null value (empty) is returned.
[0086] In the embodiment of the present application, the permission cache in the kernel only authorizes the permission management service to manage permissions. In one possible implementation, the permission cache verifies whether the process currently setting permissions is a process initiated by the permission management service. If so, the data in the process is cached in the permission cache. Otherwise, the data in the process is not accepted and a null value is returned.
[0087] It is understandable that the application in the terminal device can also initiate the process of setting permissions to the permission cache, but in this application, the permission cache only caches the process of setting permissions initiated by the permission management service. In the embodiment of this application, only the permission management service manages the setting of permissions for each terminal device.
[0088] Exemplarily, the application is a communication application. When the terminal device installs the communication application, the terminal device prompts the user to set the permissions of the communication application (such as whether to allow the communication application to access the media library, whether to allow the communication application to use the camera, whether to allow the communication application to locate and / or whether to allow the communication application to record, etc.) and the permission status corresponding to each permission (such as reject, always allow, only allow during use, or ask, etc.) in a dynamic pop-up window or other means. The user can set each permission and the permission status corresponding to each permission on the dynamic pop-up window. The terminal device determines the initialization permission of the communication application (such as always allowing the communication application to use the camera) in response to the user's operation on the dynamic pop-up window. The initialization permission includes the permissions involved in the communication application and the permission status corresponding to each permission. The package management service obtains the initialization permission of the communication application and sends it to the permission management service. The permission management service initiates a process through the system call interface and sends the initialization permission of the communication application to the permission cache. After the permission cache receives the initialization permission of the communication application, it verifies that the process that sends the initialization permission of the communication application is a process initiated by the permission management service, and then caches the initialization permission of the communication application.
[0089] It is understandable that the above example assumes that the user sets the permissions of the application when the application is installed. In actual applications, the user can update the permissions of the application through the permission management application after the application is installed.
[0090] In the embodiment of the present application, after the application is installed, if the user wants to update the permissions of the application, the permissions can be updated through the permission management application. Specifically, the user performs an update operation on the permission management application, and the permission management application sends the updated permission information of the application to the permission management service in response to the user's update operation. The permission management service calls the system through the interface ( Figure 3 ) updates the permission information of the updated application to the permission cache of the kernel. The permission cache checks whether the process that currently sends the updated permission to itself (that is, the process that sends the permission of the updated application) has the permission to update various permissions and permission status. If so, the permissions in the permission cache are updated according to the permission information of the updated application; otherwise, the permissions in the permission cache are not updated and a null value (empty) is returned.
[0091] In the embodiment of the present application, the permission cache in the kernel only authorizes the permission management service to update the permission. That is, the permission cache verifies whether the process currently updating the permission is the process initiated by the permission management service. If so, the permission in the permission cache is updated according to the permission information of the updated application. Otherwise, the permission in the permission cache is not updated and a null value is returned.
[0092] It is understandable that the permission management application in the terminal device can also initiate the process of updating permissions to the permission cache, but in this application, the permission cache only caches the process of updating permissions initiated by the permission management service. In the embodiment of this application, only the permission management service manages the updating of permissions of each terminal device.
[0093] Exemplarily, based on the example of the initialization permission set by the above communication application including always allowing the communication application to use the camera, after installing the communication application, the user uses the permission management application to view the permissions of each application on the terminal device, and the user can click on the communication application to view the permissions and permission status involved in the communication application. If the user wants to change the permission of the communication application to use the camera, the user clicks on the camera permission, and the terminal device prompts the user through a dynamic pop-up window that the currently selected permission status is always allowed, and the dynamic pop-up window also includes permission states such as rejection and only allowed during use. The user selects the permission status of only allowed during use in the dynamic pop-up window and closes the pop-up window. In response to the user operation, the permission management application sends the updated permission information of the communication application, that is, the communication application is only allowed to use the camera during use, to the permission management service. The permission management service initiates a process through the system call interface and sends the updated permission information of the communication application to the permission cache. After the permission cache receives the updated permission information of the communication application, it verifies that the process that sends the updated permission information of the communication application is the process initiated by the permission management service, and then according to the updated permission information of the communication application, the communication application is updated from always allowing the communication application to use the camera to allowing the communication application to use the camera only during use.
[0094] It can be understood that the above examples illustrate how to set and update permissions in a terminal device. The following describes how the terminal device performs permission verification in a business scenario.
[0095] In the embodiment of the present application, during the use of the application, if a sensitive resource needs to be called, the application communicates with the permission service that provides the sensitive resource through inter-process communication, that is, the application initiates an access request to the permission service through inter-process communication. The permission service accesses the sensitive resource through the system call interface ( Figure 3 (not shown) obtains the cache information of the application in the permission cache, and verifies whether the application is granted permission to call sensitive resources based on the cache information. If authorized, the application is allowed to access the sensitive resources; otherwise, the application is denied access to the sensitive resources.
[0096] Exemplarily, based on the initialization permissions set by the above communication application, the communication application is always allowed to use the camera. After the communication application is installed, the user uses the communication application and initiates a video call. The communication application needs to use the camera to complete the video call. Therefore, the communication application calls the camera interface to interact with the camera service through inter-process communication. The camera service obtains the cache information of the communication application in the permission cache through the system call interface (that is, the communication application always allows the communication application to use the camera). The camera service determines that the communication application is granted permission to call the camera based on the cache information, and then allows the communication application to use the camera for video calls.
[0097] It is understandable that if a user uninstalls an application, the permission management service in the terminal device responds to the user's uninstall operation and sends the uninstall information to the permission cache through the system call interface. The permission cache checks whether the current process has the permission to update various permissions and permission status. If so, the permissions involved in the application in the permission cache are deleted according to the uninstall information. Otherwise, the permissions in the permission cache are not updated and a null value (empty) is returned.
[0098] In an embodiment of the present application, the permissions of the terminal device are cached in the kernel, and the permissions are set, updated, and verified through system calls, without the need for cross-process permission verification.
[0099] It is understandable that in the prior art, when verifying permissions through cross-process communication, the permission management service contains the permission information of each application. After the application determines the permission service to be called through inter-process communication, the permission service communicates with the permission management service across processes, and the permission service obtains the permission information of the application from the permission management service. According to the permission information of the application, it determines whether the application is granted to use the permission. If authorized, the application is allowed to access or call the sensitive information corresponding to the permission; otherwise, the application is denied access to or call the sensitive information corresponding to the permission. That is, in the prior art, the permission information is stored in the permission management service, which is managed and cached by the permission management service. When the application uses sensitive resources, it interacts with the permission management service through cross-process communication to obtain permission information. However, the permission information in this application is stored in the permission cache of the kernel, and the permission cache only authorizes the permission management service to perform permission management, update and setting, etc. When the application uses sensitive resources, it directly accesses the permission information of the kernel through the system call interface, and there is no need to complete the permission verification through the permission management service, which optimizes the permission verification strategy.
[0100] Understandably, Figure 3 The system architecture of the terminal device is only used as a possible division method. In actual applications, the system architecture of the terminal device may include more or fewer modules, or there may be other module division methods, which is not limited in this application.
[0101] It is understood that in the embodiment of the present application, the terminal device can perform some or all of the steps in the embodiment of the present application, and these steps or operations are only examples. The embodiment of the present application can also perform other operations or variations of various operations. In addition, the various steps can be performed in different orders presented in the embodiment of the present application, and it is possible that not all operations in the embodiment of the present application need to be performed.
[0102] For example, the technical solutions involved in the following embodiments can be Figure 2 The following is a detailed introduction to the rights management method provided by the embodiment of the present application in conjunction with the accompanying drawings and application scenarios.
[0103] For example, take the life cycle of an application as an example. Figure 4 A schematic diagram of a method for managing permissions provided in an embodiment of the present application is shown, and the method includes the following steps S401-S404:
[0104] S401. The terminal device obtains initialization permission for the first application.
[0105] In the embodiment of the present application, the first application is an application currently being installed on the terminal device, and the application includes a system application and / or a third-party application that comes with the terminal device system.
[0106] In the embodiment of the present application, the initialization permission is the permission corresponding to the first application when the first application is installed. The initialization permission includes each permission involved in the first application and the permission status corresponding to each permission.
[0107] In some embodiments of the present application, when the first application is installed, the terminal device receives the user's setting operation on each permission involved in the first application and the permission status corresponding to each permission. The terminal device obtains the initialization permission of the first application in response to the setting operation, and caches the initialization permission to the terminal device kernel.
[0108] It is understandable that in the above example, when the first application is installed, the user actively sets permissions. However, in actual applications, when the first application is installed, the user will not actively set permissions, and the initialization permissions of the first application are mostly system default permissions.
[0109] In other embodiments of the present application, when the first application is installed, the user does not change the relevant permissions of the first application, and the terminal device obtains the default initialization permissions of the first application.
[0110] In one possible implementation, Figure 4 As shown, S401 may include S401a-S401e:
[0111] S401a. The package management service determines the initialization permission of the first application, and sends the initialization permission of the first application to the permission management service.
[0112] In an embodiment of the present application, during the process of installing the first application on the terminal device, the package management service determines the initialization permission of the first application according to the user's setting operation, and sends the initialization permission of the first application to the permission management service.
[0113] In a possible implementation, when the first application is installed, the package management service obtains the initialization permission of the first application set by the user or by default, and sends the initialization permission of the first application to the permission management service.
[0114] It is understandable that if the user does not change the permission settings when installing the first application, the initialization permissions of the first application are the permissions that the system defaults to be callable by the first application.
[0115] For example, the terminal device is a mobile phone and the first application is a communication application. Figure 5As shown in (a) of FIG. 1 , the mobile phone is currently installing a communication application, and the mobile phone displays interface 501. Interface 501 includes permissions related to the communication application, including multimedia-related permissions, privacy-related permissions, and other permissions. Interface 501 also includes a "Cancel" button and an "Install" button. If the user wants to view or modify the specific information of a certain permission (such as camera (taking photos and recording videos)), the user can click the arrow corresponding to the permission, and the mobile phone will respond to the user operation and display the following information: Figure 5 In the interface 502 shown in (b) of FIG. 5 , the interface 502 includes a dynamic pop-up window 503. The dynamic pop-up window shows that the permission status of the camera permission selected by the user is always allowed. The user can select other options in the dynamic pop-up window to change the permission status of the camera permission.
[0116] S401b: The rights management service sends a cache request to the kernel through the system call interface, where the cache request includes the initialization rights of the first application.
[0117] In the embodiment of the present application, a system call can be understood as a process call when an application requests the operating system kernel to complete a certain function. The system call interface is an interface provided by the operating system for directly calling the underlying kernel of the system.
[0118] In an embodiment of the present application, the permission management service initiates a cache request process to the kernel based on the system call interface, and the process includes the initialization permission of the first application. In this way, the initialization permission of the first application is sent to the kernel.
[0119] S401c: The kernel determines whether to cache the initialization permission of the first application according to the cache request. If yes, execute S401d; otherwise, execute S401e.
[0120] In the embodiment of the present application, only the permission management service is authorized in the kernel to perform permission setting.
[0121] In an embodiment of the present application, the kernel determines whether the cache request satisfies a first preset condition, wherein the first preset condition is: the process initiating the cache request is a rights management service. If so, the kernel caches the initialization permission of the first application; otherwise, the kernel does not cache the initialization permission of the first application. That is, the kernel verifies whether the process sending the cache request is a process initiated by the rights management service. If so, the initialization permission of the first application in the process is cached to the kernel, and a cache success is returned; otherwise, the data in the process is not accepted, and a null value is returned.
[0122] In some embodiments of the present application, the kernel obtains the process control block of the cache request process according to the process identification (PID) of the cache request process; determines whether the current cache request process is a process initiated by the permission management service according to the information in the process control block. If so, the initialization permission information of the first application in the process control block is cached to the kernel, and the cache success is returned; otherwise, the data in the process is not accepted and a null value is returned.
[0123] In some embodiments of the present application, the pid of the rights management service process is stored in the kernel, and the kernel determines whether the current cache request process is a process initiated by the rights management service by comparing the pid of the cache request process with the pid of the rights management service process.
[0124] Exemplarily, the process control block of the cache request process is as follows:
[0125] struct task_struct{
[0126] …
[0127] #ifdef CONFIG_ACCESS_TOKENID
[0128] u64 token;
[0129] u64 ftoken;
[0130] u64 permCode;
[0131] endif
[0132] …
[0133] };
[0134] Among them, "u64 permCode" is a 64-bit integer type permission code variable, which indicates the permission information contained in the process. For example, when permCode is 0, it means no permission; when permCode is 1, it means permission.
[0135] S401d. The kernel caches the initialization permission of the first application and returns a cache success.
[0136] S401e: The kernel does not cache the initialization permission of the first application and returns a null value.
[0137] In addition, after the first application is installed, when the user updates the permissions of the first application, the permissions of the first application are updated through the system service. In this way, when the first application obtains the current permission information of the first application from the kernel through the system service, the latest permission information of the first application can be obtained.
[0138] The following takes the case where a user updates the permissions of a first application after the first application is installed on the terminal as an example to describe in detail the specific implementation method of updating the application permissions.
[0139] S402: The terminal device updates the initialization authority of the first application in response to the update operation.
[0140] In the embodiment of the present application, the update operation includes an operation of the user updating the permissions of the first application. It can be understood that updating the initialization permissions of the first application can also be described as modifying the initialization permissions of the first application.
[0141] In an embodiment of the present application, after the first application is installed, the terminal device receives an update operation of the user on the first application permissions, and updates the initialization permissions of the first application in the kernel in response to the update operation.
[0142] For example, based on the above Figure 5 For example, after installing a communication app on a mobile phone, the user wants to update the camera permissions of the communication app. The user checks the permissions of the communication app through the permission management app (such as Settings). Figure 6 As shown in (a) of FIG. 6 , the mobile phone displays interface 601. The display interface includes the permissions and permission status related to the communication application in the settings, such as always allowing access to read and write content in the mobile phone storage, camera, and display floating layer, and prohibiting access to recording, Bluetooth, and privacy-related permissions. Users can also view other permissions of the communication application through "View other permissions". If the user wants to modify the camera permission, click on the permission status of the camera or camera permission (always allow), and the mobile phone responds to the user operation and displays the following Figure 6 The interface 602 shown in (b) of FIG. 6 includes a dynamic pop-up window 603. The dynamic pop-up window shows that the permission status of the current camera permission is "Allow all the time". If the user selects the option "Allow only when in use" and closes the dynamic pop-up window, the mobile phone changes the permission status of the camera permission to "Allow only when in use".
[0143] It is understandable that in the above example, the user actively updates / modifies permissions, but in actual applications, after the first application is installed, when the user runs the first application, the first application prompts the user to set permissions. For example, after the terminal device installs the first application, when the user uses the first application for the first time, the first application prompts the user to set permissions through a window or pop-up window. For another example, after the terminal device installs the first application, when the user uses certain functions of the first application (such as functions that require calling sensitive resources), the first application prompts the user to set permissions through a window or pop-up window. The embodiments of the present application do not limit the timing and specific implementation methods of application permission management, setting, and updating.
[0144] In one possible implementation, Figure 4As shown, S402 may include S402a-S402e:
[0145] S402a: The permission management application updates the initialization permission of the first application in response to the update operation, and sends the updated permission information of the first application to the permission management service.
[0146] In an embodiment of the present application, after the terminal device installs the first application, the permission management application receives the user's update operation on the initialization permissions of the first application, updates the initialization permissions of the first application in response to the user's update operation, obtains the updated permission information of the first application, and sends the updated permission information of the first application to the permission management service.
[0147] S402b: The rights management service sends an update request to the kernel through the system call interface. The update request includes the updated rights information of the first application.
[0148] In an embodiment of the present application, the permission management service initiates an update request process to the kernel based on the system call interface, and the process includes the permission information of the updated first application. In this way, the permission information of the updated first application is sent to the kernel.
[0149] S402c, the kernel determines whether to update according to the update request. If yes, execute S402d; otherwise, execute S402e.
[0150] In the embodiment of the present application, only the permission management service is authorized in the kernel to perform permission updates.
[0151] In an embodiment of the present application, the kernel determines whether the update request satisfies a second preset condition, wherein the second preset condition is: the process initiating the update request is a rights management service. If so, the kernel updates according to the updated rights information of the first application; otherwise, the kernel does not update. That is, the kernel verifies whether the process sending the update request is a process initiated by the rights management service. If so, the rights of the first application in the kernel are updated according to the updated rights information of the first application, and an update success is returned; otherwise, the rights of the first application are not updated, and a null value is returned.
[0152] S402d. The kernel updates the permission of the first application according to the updated permission information of the first application, and returns an update success.
[0153] S402e: The kernel does not update the permission of the first application and returns a null value.
[0154] It is understandable that in the above step S402, after the first application is installed, the user updates the relevant permissions of the first application. Wherein, updating the relevant permissions of the first application includes updating all permissions related to the first application, or updating some permissions related to the first application. That is, updating at least one permission related to the first application. Moreover, in actual use, the user may not update the relevant permissions of the first application. That is, in actual application, step S402 may not be performed.
[0155] It is understandable that the above example takes the case where the user updates the initialization permissions of the first application after the terminal installs the first application as an example. In actual applications, the update operation not only includes the user updating the initialization permissions of the first application after the first application is installed. The update operation can also be that the user updates the updated permission information again. That is, after the first application is installed, the user can dynamically update the relevant permissions of the first application according to usage requirements.
[0156] In some embodiments of the present application, the terminal device updates the permission information of the first application currently cached in the kernel in response to an update operation. Specifically, the terminal device sends an update request to the kernel through a system call interface in response to the user's update operation; the update request includes the updated permission information of the first application; the kernel of the terminal device determines whether to update according to the cache request; if the update is determined, the kernel updates the permission information of the first application currently cached according to the updated permission information of the first application; otherwise, the kernel does not update the permission information of the first application currently cached.
[0157] It is understandable that the specific information of the relevant permissions of the first application is dynamically changed according to the user's usage requirements. The embodiment of the present application does not specifically limit the updating of the permissions of the first application.
[0158] S403: The terminal device obtains current permission information of the first application from the kernel in response to the calling operation.
[0159] In the embodiment of the present application, the calling operation includes an operation in which a user triggers the first application to call a first sensitive resource, that is, the calling operation is an operation in which the user calls the first sensitive resource during the process of using the first application.
[0160] The first sensitive resources are sensitive resources of the terminal device system, for example, user data (such as user personal information, contact information, text messages, etc.), application data (such as the user's current location information in a map application, etc.) and / or system functions (such as camera, positioning, etc.).
[0161] In the embodiment of the present application, when the user uses the first application, if the first sensitive resource needs to be called, the first application sends a permission verification request to the kernel through the system call interface. The kernel queries and obtains the current permission information of the first application according to the permission verification request.
[0162] Among them, the permission verification request includes parameter information of the first application and parameter information of the first sensitive resource. For example, the parameter information of the first application includes the application identifier of the first application; the parameter information of the first sensitive resource includes the identifier of the first sensitive resource. It can be understood that the application identifier of the first application (which can also be described as the application package name) can be a unique identifier of the first application, which is used to identify different applications. The identifier of the first sensitive resource can be a unique identifier of the first sensitive resource, which is used to identify different sensitive resources.
[0163] In some embodiments of the present application, the first application, in response to a user's call operation, initiates a permission check request process to the kernel based on a system call interface. The kernel queries the current permission information of the first application based on the information in the permission check request process, and returns the current permission information of the first application to the first application.
[0164] In a possible implementation, the current permission information of the first application is all the permission information of the current first application. During the use of the first application, if the first sensitive resource needs to be called, the first application communicates with the permission service that provides the first sensitive resource through inter-process communication. That is, the first application initiates a permission verification request to the permission service through inter-process communication. Among them, the permission verification request includes parameter information of the first application and parameter information of the first sensitive resource. After the permission service communicates with the first application, the permission service obtains the current permission information of the first application in the permission cache (that is, all the permission information of the first application in the current permission cache) through the system call interface, and verifies whether the first application is granted permission to call the first sensitive resource based on the current permission information of the first application and the first sensitive resource. If authorized, the first application is allowed to call the first sensitive resource, otherwise, the first application is denied to call the first sensitive resource.
[0165] In another possible implementation, the current permission information of the first application is the permission information corresponding to the first sensitive resource in the current first application. During the use of the first application, if the first sensitive resource needs to be called, the first application sends a permission verification request to the permission service that provides the first sensitive resource through inter-process communication, and the permission verification request includes parameter information of the first application and parameter information of the first sensitive resource. The permission service obtains the permission information corresponding to the first sensitive resource in the current first application in the permission cache through the system call interface according to the permission verification request, and verifies whether the first application is granted permission to call the first sensitive resource according to the permission information corresponding to the first sensitive resource in the current first application. If authorized, the first application is allowed to call the first sensitive resource, otherwise, the first application is denied to call the first sensitive resource. The embodiment of the present application does not limit the specific implementation method of the terminal device to verify permissions.
[0166] In some embodiments of the present application, if the user does not update the permissions of the first application after the terminal device installs the first application, the current permission information of the first application is the initialization permission of the first application.
[0167] For example, based on the above Figure 5 For example, after installing the communication application on the mobile phone, the user did not update the camera permission (i.e., the first sensitive resource) in the communication application. When the user uses the communication application to make a video call, the current permission information of the first application obtained by the terminal device should be the initialization permission of the camera permission in the communication application stored in the kernel of the terminal device, i.e., "Always Allow".
[0168] In other embodiments of the present application, if the user updates the permissions of the first application after the terminal device installs the first application, the current permission information of the first application is the updated permission information of the first application.
[0169] For example, based on the above Figure 6 For example, after installing a communication app on a mobile phone, the user updates the camera permission in the communication app to "allow only while in use". When the user uses the communication app to make a video call, the current permission information of the first application obtained by the terminal device should be the updated permission information of the camera permission in the communication app stored in the kernel of the terminal device, that is, "allow only while in use".
[0170] In one possible implementation, Figure 4 As shown, S403 may include S403a-S403b:
[0171] S403a: In response to the calling operation, the first application sends a permission verification request to the kernel through the system call interface.
[0172] S403b: The kernel determines the current permission information of the first application according to the permission verification request, and returns it to the first application.
[0173] S404: The terminal device performs a permission check based on the current permission information of the first application.
[0174] In an embodiment of the present application, if the terminal device determines that the first application has been granted permission to call the first sensitive resource based on the current permission information of the first application, the terminal device allows the first application to call the first sensitive resource; if the terminal device determines that the first application has not been granted permission to call the first sensitive resource based on the current permission information of the first application, the terminal device refuses the first application to call the first sensitive resource.
[0175] In an embodiment of the present application, if the current permission information of the first application (such as always allowed or allowed only when in use) indicates that the first application is allowed to access the first sensitive resource, it is determined that the first application has permission to call the first sensitive resource (that is, authorized), and the first sensitive resource corresponding to the permission can be called; if the current permission information of the first application (such as prohibited) indicates that the first application is not allowed to access the first sensitive resource, it is determined that the first application does not have permission to call the first sensitive resource (that is, unauthorized), and the first sensitive resource corresponding to the permission cannot be called.
[0176] Exemplarily, in the above example, the current permission information of the first application indicates that the communication application is allowed to access the camera permission, then it is determined that the communication application has been authorized to access the camera and a video call can be made.
[0177] Through the above technical solution, in the embodiment of the present application, when the first application is installed, the terminal device caches the initialization permissions of the first application to the kernel through the system service. When the first application runs and calls sensitive resources, the current permission information of the first application is obtained from the kernel through the system service, and the permission is checked. The technical solution of the present application manages permissions through kernel system calls, without the need to manage permissions through inter-process communication, which greatly reduces the proportion of IPC communication of permission services during permission verification and effectively improves the performance of the entire machine. In addition, there is no need for cross-process communication when verifying permissions, which effectively improves the performance of the permission verification interface and improves the user experience.
[0178] It is understandable that in the embodiment of the present application, the terminal device can perform some or all of the steps in the embodiment of the present application, and these steps or operations are only examples. The embodiment of the present application can also perform other operations or variations of various operations. In addition, the various steps can be performed in different orders presented in the embodiment of the present application, and it is possible that not all operations in the embodiment of the present application need to be performed.
[0179] For example, Figure 7 As shown, another permission management method provided by an embodiment of the present application includes the following steps S701-S702:
[0180] S701: In response to a user instructing a first application to call a first sensitive resource, the terminal device obtains current permission information of the first application from the kernel.
[0181] In an embodiment of the present application, the terminal device includes a kernel, and the kernel stores permission information of at least one application, and the at least one application includes a first application.
[0182] In an embodiment of the present application, before the terminal device obtains current permission information of the first application from the kernel in response to the user's instruction to call the first sensitive resource in the first application, the method also includes: the terminal device obtains initialization permission of the first application; the terminal device sends a cache request to the kernel through the system call interface; the kernel of the terminal device determines whether to cache the initialization permission of the first application based on the cache request; if caching is determined, the kernel caches the initialization permission of the first application; otherwise, the kernel does not cache the initialization permission of the first application.
[0183] The initialization permission is the permission corresponding to the first application when the first application is installed. The cache request includes the initialization permission of the first application.
[0184] In some embodiments, the kernel of the terminal device determines whether the cache request satisfies a first preset condition. If so, the kernel caches the initialization permission of the first application; otherwise, the kernel does not cache the initialization permission of the first application.
[0185] Among them, the first preset condition is: the process that initiates the cache request is a rights management service.
[0186] In an embodiment of the present application, the terminal device obtains current permission information of the first application from the kernel in response to a user's instruction to call a first sensitive resource in the first application, including: the terminal device sends a permission verification request to the kernel through the system call interface in response to a user's instruction to call a first sensitive resource in the first application; the terminal device obtains the current permission information of the first application from the kernel according to the permission verification request.
[0187] The limited verification request includes parameter information of the first application and parameter information of the first sensitive resource.
[0188] S702: The terminal device determines whether the first application has permission to call the first sensitive resource based on the current permission information of the first application.
[0189] In an embodiment of the present application, the terminal device determines whether the first application has permission to call the first sensitive resource based on the current permission information of the first application, including: if the terminal device determines that the first application has permission to call the first sensitive resource based on the current permission information of the first application, the terminal device allows the first application to call the first sensitive resource; or, if the terminal device determines that the first application does not have permission to call the first sensitive resource based on the current permission information of the first application, the terminal device refuses the first application to call the first sensitive resource.
[0190] In other embodiments of the present application, the terminal device determines whether the first application has permission to call the first sensitive resource based on the current permission information of the first application, including: the terminal device determines whether the first application has permission to call the first sensitive resource based on the current permission information of the first application and parameter information of the first sensitive resource.
[0191] In addition, after the first application is installed on the terminal device, the user can also update the permissions of the first application.
[0192] In an embodiment of the present application, the terminal device updates the permission information of the first application currently cached in the kernel in response to the user's operation of updating the permission information of the first application.
[0193] In one possible implementation, the terminal device updates the permission information of the first application currently cached in the kernel in response to the user's operation of updating the permission information of the first application, including: the terminal device sends an update request to the kernel through a system call interface in response to the user's operation of updating the permission information of the first application; the update request includes the updated permission information of the first application; the kernel of the terminal device determines whether to update according to the cache request; if it is determined to update, the kernel updates the permission information of the first application currently cached according to the updated permission information of the first application; otherwise, the kernel does not update the permission information of the first application currently cached.
[0194] In some embodiments, the kernel of the terminal device determines whether the update request satisfies a second preset condition. If so, the kernel performs an update according to the updated permission information of the first application; otherwise, the kernel does not perform an update.
[0195] The second preset condition is that the process that initiates the update request is a rights management service.
[0196] Through the above technical solution, in the embodiment of the present application, the terminal device responds to the user's instruction to call the first sensitive resource in the first application, obtains the current permission information of the first application from the kernel, and determines whether the first application has the permission to call the first sensitive resource based on the current permission information of the first application. The technical solution of the present application manages permissions through kernel system calls, without the need to manage permissions through inter-process communication, which greatly reduces the proportion of IPC communication of permission services during permission verification and effectively improves the performance of the entire machine. In addition, there is no need for cross-process communication when verifying permissions, which effectively improves the performance of the permission verification interface and improves the user experience.
[0197] The above mainly introduces the solution provided by the embodiment of the present application from the perspective of the method. It is understandable that, in order to realize the above functions, the electronic device includes a hardware structure and / or software module corresponding to the execution of each function. In combination with the units and algorithm steps of each example described in the embodiment disclosed in this application, the embodiment of the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer-driven hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the technical solution of the embodiment of the present application.
[0198] The present application is an embodiment that can divide the functional modules of the electronic device according to the above method example. For example, each functional module can be divided corresponding to each function, or two or more functions can be integrated into one processing unit. The above integrated unit can be implemented in the form of hardware or in the form of software functional modules. It should be noted that the division of units in the embodiment of the present application is schematic and is only a logical function division. There may be other division methods in actual implementation.
[0199] like Figure 8 , which is a schematic diagram of the structure of another terminal device provided in an embodiment of the present application, and the terminal device 800 can be used to implement the methods described in the above method embodiments. Exemplarily, the terminal device 800 may specifically include: a processing module 801, an acquisition module 802, and a display module 803.
[0200] The processing module 801 is used to execute the support terminal device 800 to execute Figures 4 to 7 The processing function of any one of the items.
[0201] The acquisition module 802 is used to execute the support terminal device 800 to execute Figures 4 to 7 The acquisition function of any one of the items.
[0202] The display module 803 may be used to display a screen according to the display driver data, etc. And / or, the display module 803 may also be used to support the terminal device 800 to perform other display operations performed by the terminal device in the embodiment of the present application.
[0203] Optional, Figure 8 The terminal device 800 shown may also include a communication module ( Figure 8 ), a communication module, which is used to support the terminal device 800 in executing the steps of communication between the terminal device and other devices in the embodiment of the present application.
[0204] Optional, Figure 8 The terminal device 800 shown may also include a storage module ( Figure 8 (not shown), the storage module stores programs or instructions. When the processing module 801 executes the program or instruction, Figure 8 The terminal device 800 shown can execute the method shown in the above method embodiment.
[0205] Figure 8 The technical effects of the terminal device 800 shown can refer to the technical effects of the method described in the above method embodiment, and will not be repeated here. Figure 8 The processing module 801 involved in the terminal device 800 shown can be implemented by a processor or a processor-related circuit component, which can be a processor or a processing module. The communication module can be implemented by a transceiver or a transceiver-related circuit component, which can be a transceiver or a transceiver module. The display module 803 can be implemented by display screen-related components.
[0206] The present application also provides a chip system, such as Fig. 9 As shown, the chip system 900 includes at least one processor 901 and at least one interface circuit 902. As an example, when the chip system 900 includes a processor and an interface circuit, the processor may be Fig. 9 The processor 901 shown in the solid line frame (or the processor 901 shown in the dotted line frame) may be an interface circuit. Fig. 9 The interface circuit 902 shown in the solid line frame (or the interface circuit 902 shown in the dotted line frame) is shown in the solid line frame. When the chip system 900 includes two processors and two interface circuits, the two processors include Fig. 9 The processor 901 shown in the solid line frame and the processor 901 shown in the dotted line frame, the two interface circuits include Fig. 9 The interface circuit 902 shown in the solid line frame and the interface circuit 902 shown in the dotted line frame are not limited to this.
[0207] The processor 901 and the interface circuit 902 can be interconnected via a line. For example, the interface circuit 902 can be used to receive a signal. For another example, the interface circuit 902 can be used to send a signal to another device (such as the processor 901). Exemplarily, the interface circuit 902 can read instructions stored in the memory and send the instructions to the processor 901. When the instructions are executed by the processor 901, the various steps in the above embodiment can be executed. Of course, the chip system can also include other discrete devices, which is not specifically limited in the embodiments of the present application.
[0208] Optionally, there may be one or more processors in the chip system. The processor may be implemented by hardware or by software. When implemented by hardware, the processor may be a logic circuit, an integrated circuit, etc. When implemented by software, the processor may be a general-purpose processor implemented by reading software code stored in a memory.
[0209] Optionally, the chip system may further include a memory ( Fig. 9 As shown in the figure, the memory may be one or more, and the memory may be integrated with the processor or may be separately arranged with the processor, which is not limited in the present application. Exemplarily, the memory may be a non-transient processor, such as a read-only memory (ROM), which may be integrated with the processor on the same chip or may be arranged on different chips, and the present application does not specifically limit the type of memory and the arrangement of the memory and the processor.
[0210] Exemplarily, the chip system can be a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on chip (SoC), a central processor unit (CPU), a network processor (NP), a digital signal processor (DSP), a microcontroller unit (MCU), a programmable logic device (PLD), or other integrated chips.
[0211] It should be understood that each step in the above method embodiment can be completed by an integrated logic circuit of hardware in a processor or by instructions in the form of software. The method steps disclosed in the embodiments of the present application can be directly embodied as being executed by a hardware processor, or by a combination of hardware and software modules in a processor.
[0212] The embodiment of the present application also provides a computer storage medium, in which computer instructions are stored. When the computer instructions are executed on a terminal device, the terminal device executes the method described in the above method embodiment.
[0213] Computer-readable storage media include, but are not limited to, any of the following: a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, and other media that can store program codes.
[0214] An embodiment of the present application provides a computer program product, which includes: a computer program or instructions, when the computer program or instructions are executed on a computer, the computer executes the method described in the above method embodiment.
[0215] In addition, an embodiment of the present application also provides a device, which can specifically be a chip, component or module, and the device may include a connected processor and memory; wherein the memory is used to store computer-executable instructions, and when the device is running, the processor can execute the computer-executable instructions stored in the memory so that the device executes the methods in the above-mentioned method embodiments.
[0216] Among them, the terminal device, computer storage medium, computer program product or chip provided in this embodiment is used to execute the corresponding method provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding method provided above, and will not be repeated here.
[0217] The steps of the method or algorithm described in conjunction with the disclosure of the embodiments of the present application can be implemented in hardware or by executing software instructions by a processor. The software instructions can be composed of corresponding software modules, and the software modules can be stored in random access memory (RAM), flash memory, read-only memory, erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), registers, hard disks, mobile hard disks, compact disc read-only memory (CD-ROM) or any other form of storage medium known in the art. An exemplary storage medium is coupled to a processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can be located in an application specific integrated circuit (ASIC).
[0218] Through the description of the above implementation methods, those skilled in the art can clearly understand that for the convenience and simplicity of description, only the division of the above functional modules is used as an example. In practical applications, the above functions can be assigned to different functional modules as needed; that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, device and unit described above can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.
[0219] In the several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The various embodiments can be combined with each other or referenced to each other without conflict. The device embodiments described above are merely schematic. For example, the division of modules or units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the coupling or direct coupling or communication connection between each other shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0220] The units described as separate components may or may not be physically separated, and the components shown as units may be one physical unit or multiple physical units, that is, they may be located in one place or distributed in multiple different places. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0221] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0222] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the software product is stored in a storage medium, including a number of instructions to enable a device (which can be a single-chip microcomputer, chip, etc.) or a processor (processor) to perform all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read only memory (ROM), random access memory (RAM), disk or optical disk and other media that can store program code.
[0223] The above contents are only specific implementation methods of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
Claims
1. A rights management method, characterized in that: The method comprises: The terminal device obtains the current permission information of the first application from the kernel in response to the user instructing the first sensitive resource to be called in the first application; The terminal device determines whether the first application has permission to call the first sensitive resource according to the current permission information of the first application.
2. The method according to claim 1, characterized in that The kernel stores permission information of at least one application, and the at least one application includes the first application.
3. The method according to claim 1 or 2, characterized in that: Before the terminal device obtains the current permission information of the first application from the kernel in response to the user's instruction to call the first sensitive resource in the first application, the method further includes: The terminal device obtains the initialization permission of the first application; the initialization permission is the permission corresponding to the first application when the first application is installed; The terminal device sends a cache request to the kernel through a system call interface; the cache request includes the initialization permission of the first application; The kernel of the terminal device determines whether to cache the initialization permission of the first application according to the cache request; If caching is determined, the kernel caches the initialization permission of the first application; otherwise, the kernel does not cache the initialization permission of the first application.
4. The method according to any one of claims 1 to 3, characterized in that: The terminal device obtains the current permission information of the first application from the kernel in response to the user instructing the first sensitive resource to be called in the first application, including: In response to the user instructing in the first application to call the first sensitive resource, the terminal device sends a permission verification request to the kernel through a system call interface; The terminal device obtains current permission information of the first application from the kernel according to the permission verification request.
5. The method according to claim 4, characterized in that The permission verification request includes parameter information of the first application and parameter information of the first sensitive resource.
6. The method according to any one of claims 1 to 5, characterized in that: The terminal device determines, according to the current permission information of the first application, whether the first application has permission to call the first sensitive resource, including: If the terminal device determines, according to the current permission information of the first application, that the first application has permission to call the first sensitive resource, the terminal device allows the first application to call the first sensitive resource; Alternatively, if the terminal device determines, based on the current permission information of the first application, that the first application does not have permission to call the first sensitive resource, the terminal device denies the first application from calling the first sensitive resource.
7. The method according to claim 5, characterized in that The terminal device determines, according to the current permission information of the first application, whether the first application has permission to call the first sensitive resource, including: The terminal device determines whether the first application has permission to call the first sensitive resource according to the current permission information of the first application and the parameter information of the first sensitive resource.
8. The method according to any one of claims 1 to 7, characterized in that: The method further comprises: In response to a user operation of updating the permission information of the first application, the terminal device updates the permission information of the first application currently cached in the kernel.
9. The method according to claim 8, characterized in that The terminal device updates the permission information of the first application currently cached in the kernel in response to the user's operation of updating the permission information of the first application, including: The terminal device sends an update request to the kernel through a system call interface in response to a user's operation of updating the permission information of the first application; the update request includes the updated permission information of the first application; The kernel of the terminal device determines whether to update according to the cache request; If it is determined to update, the kernel updates the currently cached permission information of the first application according to the updated permission information of the first application; otherwise, the kernel does not update the currently cached permission information of the first application.
10. A terminal device, characterized in that: include: one or more processors; Memory; One or more computer programs are stored in the memory, and the one or more computer programs include instructions. When the instructions are executed by the terminal device, the terminal device executes the method according to any one of claims 1 to 9.
11. A chip system, characterized in that: It includes at least one processor and at least one interface circuit, wherein the at least one interface circuit is used to perform transceiver functions and send instructions to the at least one processor, and the at least one processor executes the instructions, and the at least one processor executes the method as described in any one of claims 1-9.
12. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a computer program or instructions. When the computer program or instructions are run on a computer, the computer is caused to execute the method according to any one of claims 1 to 9.
13. A computer program product, characterized in that The computer program product comprises: a computer program or instructions, and when the computer program or instructions are run on a computer, the computer is caused to execute the method according to any one of claims 1 to 9.