Authority control method and device, electronic equipment, medium and product

By obtaining user demand information and generating authorization strategies based on data level, dynamically managing access rights of multimodal large models to user data, solving the problem of cumbersome user data authorization operations in the prior art, and improving the efficiency of permission control and model use.

CN120124098APending Publication Date: 2025-06-10VIVO MOBILE COMM CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510181130.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-18
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

In the prior art, when using user data, multimodal large models need to prompt users to authorize one by one. The authorization operation of each type of data increases the burden of user manual operations and reduces the efficiency of permission control and model use.

Method used

By obtaining user demand information, determining the user data related to it, and generating authorization strategies based on the data level, it determines whether to prompt the user to authorize when reading user data in a multimodal large model, and dynamically manage the access rights of user data.

Benefits of technology

It reduces the user's manual authorization operations, improves the efficiency of permission control and the efficiency of multimodal large models, and enhances the security of user data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120124098A_ABST
    Figure CN120124098A_ABST
Patent Text Reader

Abstract

The invention discloses a permission control method and device, electronic equipment, a medium and a product, and belongs to the technical field of artificial intelligence, the method comprises the steps that user demand information is acquired, and the user demand information is used for indicating the demand of a user for using a multi-modal large model; determining user data related to the user demand information according to the user demand information; based on the data hierarchy of the user data, an authorization strategy is generated, the authorization strategy is used for indicating whether the multi-modal large model prompts the user to authorize when reading the user data, and the data hierarchy is used for representing the security level of the user data; and according to the authorization strategy, displaying authorization prompt information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of artificial intelligence technology, and particularly relates to a method, device, electronic device, medium and product for permission control. Background Art

[0002] More and more multimodal large models can be installed in electronic devices such as mobile phones and tablets to provide services for simple operations such as sending text messages, making phone calls, setting reminders, etc. for users, as well as services with complex logics such as health management, text creation assistance, and financial services. In order to ensure the security of user data, authorization from the user is required before using this user data.

[0003] In related technologies, the authorization method for user data is usually a single - data - type authorization method. For example, when the user is navigating, the user is prompted to authorize the permission to access the location, or when the user takes a picture, the user is prompted to authorize the permission to access local photos. However, the services provided by multimodal large models usually use a large number of different types of user data. Based on the aforementioned method, the user will be prompted to authorize the permission for each type of user data one by one, which not only increases the user's manual authorization operations, reduces the efficiency of permission control, but also affects the usage efficiency of multimodal large models. Summary of the Invention

[0004] The purpose of the embodiments of this application is to provide a method, device, electronic device, medium and product for permission control, which can reduce the user's manual authorization operations and improve the efficiency of permission control and the usage of multimodal large models.

[0005] In a first aspect, the embodiments of this application provide a method for permission control, including:

[0006] Obtain user requirement information, where the user requirement information is used to indicate the user's requirements for using the multimodal large model;

[0007] Determine the user data related to the user requirement information according to the user requirement information;

[0008] Generate an authorization policy based on the data level of the user data, where the authorization policy is used to indicate whether to prompt the user for authorization when the multimodal large model reads the user data, and the data level is used to represent the security level of the user data;

[0009] Display an authorization prompt message according to the authorization policy.

[0010] In a second aspect, the embodiments of this application provide a permission control device, including:

[0011] An obtaining module, configured to obtain user requirement information, where the user requirement information is used to indicate the user's requirements for using the multimodal large model;

[0012] A determination module, configured to determine user data related to the user requirement information according to the user requirement information;

[0013] A generation module, configured to generate an authorization policy based on the data level of the user data, where the authorization policy is used to indicate whether to prompt the user for authorization when the multi-modal large model reads the user data, and the data level is used to represent the security level of the user data;

[0014] A display module, configured to display an authorization prompt message according to the authorization policy.

[0015] In a third aspect, an embodiment of the present application provides an electronic device, which includes a processor, a memory, and a program or instruction stored on the memory and executable on the processor. When the program or instruction is executed by the processor, the steps of the permission control method shown in the first aspect are implemented.

[0016] In a fourth aspect, an embodiment of the present application provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by the processor, the steps of the permission control method shown in the first aspect are implemented.

[0017] In a fifth aspect, an embodiment of the present application provides a chip, which includes a processor and a display interface. The display interface is coupled to the processor, and the processor is configured to run a program or instruction to implement the steps of the permission control method shown in the first aspect.

[0018] In a sixth aspect, an embodiment of the present application provides a computer program product, which is stored in a storage medium and is executed by at least one processor to implement the steps of the permission control method shown in the first aspect.

[0019] In the embodiments of the present application, user data related to the obtained user demand information can be determined according to the obtained user demand information, where the user demand information is used to indicate the user demand for using the multimodal large model; then, based on the data level of the user data, an authorization policy is generated, and the authorization policy is used to indicate whether to prompt the user for authorization when the multimodal large model reads the user data. The data level is used to represent the security level of the user data. According to the authorization policy, an authorization prompt message is displayed. In this way, it is possible to make full use of the understanding of the multimodal large model for the user demand information to determine the purpose of the multimodal large model accessing the user data, and combine the understanding of the classification of the user data to dynamically judge whether the use of the multimodal large model for the user data is reasonable, so as to indicate whether to prompt the user for authorization when the multimodal large model reads the user data through the authorization policy. For the user data that needs to prompt the user for authorization, an authorization prompt message can be displayed to assist the user in better and more detailed management of whether the user data can be read by the untrusted multimodal large model, improving the security of the user data. For the user data that does not require prompting the user for authorization, it can directly participate in the process of the multimodal large model executing operations related to the user demand information, reducing the operation of the user manually authorizing these user data, improving the efficiency of permission control, and at the same time, it can also improve the speed when the multimodal large model reads the user data, and improve the use efficiency of the multimodal large model. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] Figure 1 Schematic diagram of a permission control system provided by some embodiments of the present application;

[0021] Figure 2 Flowchart of a permission control method provided by some embodiments of the present application;

[0022] Figure 3 Schematic diagram of the data level and data category of user data of a permission control method provided by some embodiments of the present application;

[0023] Figure 4 Flow schematic diagram of a permission control method provided by some embodiments of the present application;

[0024] Figure 5 Schematic diagram of the structure of a permission control device provided by some embodiments of the present application;

[0025] Figure 6 Schematic diagram of the structure of an electronic device provided by some embodiments of the present application;

[0026] Figure 7 Hardware structure schematic diagram of an electronic device provided by some embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0027] Next, the technical solutions in the embodiments of the present application will be clearly described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art belong to the scope of protection of the present application.

[0028] The terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects, rather than to describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first", "second", etc. are usually of the same category, and the number of objects is not limited. For example, the first object can be one or more. In addition, "and / or" in the specification and claims means at least one of the connected objects, and the character " / " generally indicates an "or" relationship between the associated objects before and after.

[0029] To solve the problems in the related art, the embodiments of the present application provide a permission control method, apparatus, electronic device, and storage medium. The following will be described in detail Figures 1 to 4 the permission control method provided by the embodiments of the present application through specific embodiments and their application scenarios.

[0030] First, in conjunction with Figure 1 a permission control system provided by the embodiments of the present application will be described in detail.

[0031] Figure 1 is a schematic diagram of a permission control system provided by some embodiments of the present application.

[0032] As Figure 1 shown, the permission control system in the embodiments of the present application can be set in an electronic device, and the permission control system can use the operating system framework, kernel, and device hardware in the electronic device to execute the steps of the permission control method.

[0033] In the embodiments of the present application, considering the export of user data, a layer of a multi-modal large model (AI agent) can be set between the layer where the user data is located in the operating system framework and the application layers where each involved application is located, so as to determine the purpose of the multi-modal large model to access user data based on the understanding of user demand information by the AI agent, and combine the understanding of the classification of user data to dynamically judge whether the use of user data by the multi-modal large model is reasonable, so as to indicate whether to prompt the user for authorization when the multi-modal large model reads user data through an authorization policy. For user data that requires prompting the user for authorization, the AI agent can trigger the device hardware to display an authorization prompt message, which can assist the user to better and more carefully manage whether the user data can be read by untrusted applications and the AI agent itself, improving the security of user data. For user data that does not require prompting the user for authorization, the AI agent can generate operation process information and assist in completion through any number of applications in the electronic device, such as Application A, Application B, Application C, Application D, reducing the operation of the user manually authorizing this user data, improving the efficiency of permission control, and at the same time, it can also improve the speed when the multi-modal large model reads user data, improving the usage efficiency of the multi-modal large model.

[0034] Exemplarily, the AI agent obtains user demand information, such as buying a cup of American coffee. The AI agent can determine user data based on a cup of American coffee, such as the user's location, and whether the user has the behavioral habit of adding milk or sugar when drinking American coffee, and which coffee shop's American coffee, etc. These behavioral habits can be obtained from applications such as Application A, Application B, Application C, Application D that can provide services for the user to place an order for coffee. Then, the AI agent determines the data layer of the user's location and the data layer of the behavioral habits, and further judges whether the AI agent has the permission to access the user's location and the behavioral habits in each application. If there is permission to access this data, the instructions of the user related to the user demand information can be completed through the AI agent and / or applications in the electronic device such as Application A, Application B, Application C, Application D.

[0035] Accordingly, when a user uses a multimodal large model on an electronic device to process various services, after the multimodal large model obtains user demand information such as ordering coffee and buying tickets, it can understand the user's demand and the purpose of using the user data related to the user demand information, and dynamically determine whether the use of the user data by the multimodal large model is reasonable, so as to indicate whether to prompt the user for authorization when the multimodal large model reads the user data through an authorization policy. For the user data that needs to prompt the user for authorization, the device hardware can be triggered by an AI agent to display an authorization prompt message, which can assist the user to better and more carefully manage whether the user data can be read by untrusted applications and the AI agent itself, improving the security of the user data. Moreover, for the user data that does not require prompting the user for authorization, relevant operations can be performed through the AI agent. For the user, the operations related to the user demand information are imperceptible, thus reducing the user's manual operation of authorizing this user data. While improving the efficiency of permission control, it can also increase the speed when the multimodal large model reads the user data, improving the usage efficiency of the multimodal large model.

[0036] Secondly, in combination with Figure 2 A permission control method provided by an embodiment of the present application will be described in detail.

[0037] Figure 2 It is a flowchart of the permission control method provided by some embodiments of the present application.

[0038] As Figure 2 shown, the permission control method provided by an embodiment of the present application can be applied to the permission control system as Figure 1 shown. Based on this, the permission control method may include steps 210, 220, 230, and 240 as specifically shown below.

[0039] Step 210: Obtain user demand information, where the user demand information is used to indicate the user's demand for using the multimodal large model; Step 220: Determine the user data related to the user demand information according to the user demand information; Step 230: Generate an authorization policy based on the data level of the user data, where the authorization policy is used to indicate whether to prompt the user for authorization when the multimodal large model reads the user data, and the data level is used to represent the security level of the user data; Step 240: Display an authorization prompt message according to the authorization policy.

[0040] Exemplarily, an electronic device can obtain user demand information through an AI agent. For example, to buy an American coffee, the AI agent can determine user data such as the user's geographical location data, coffee preference data, frequently visited coffee shop data, and user communication number data based on an American coffee. If the data levels of the user's coffee preference data and frequently visited coffee shop data are S2, the user's geographical location data is S3, and the data level of the user's communication number data is S4, at this time, it can be determined whether to prompt the user for authorization based on the number of levels of the data level. That is, when the number of levels of the data level is greater than or equal to the reference level number of 4, it can be indicated that the multi-modal large model prompts the user for authorization when reading user data. Then, the AI agent can directly access and use the user's coffee preference data, frequently visited coffee shop data, and geographical location data, and pop up a window to ask the user whether to authorize the use of the user's communication number data. In this way, when it is determined that the user authorizes the AI agent to access and use the user's communication number data, operations related to the user demand information can be executed.

[0041] Therefore, it is possible to fully utilize the understanding of the multi-modal large model for user demand information to determine the purpose of the multi-modal large model accessing user data, and combine the understanding of the classification of user data to dynamically judge whether the use of the multi-modal large model for user data is reasonable, so as to indicate whether to prompt the user for authorization when the multi-modal large model reads user data through an authorization policy. For user data that requires prompting the user for authorization, it can assist the user to better and more carefully manage whether the user data can be read by an untrusted multi-modal large model, improving the security of user data. For user data that does not require prompting the user for authorization, it can directly participate in the process of the multi-modal large model executing operations related to user demand information, reducing the operation of the user manually authorizing these user data, improving the efficiency of permission control, and at the same time, it can also improve the speed when the multi-modal large model reads user data, improving the usage efficiency of the multi-modal large model.

[0042] The above steps will be described in detail below, as follows.

[0043] Regarding step 210, in some embodiments of the present application, an electronic device can obtain user demand information through an AI agent. Among them, the AI agent in the embodiments of the present application can be a model of the operating system in the electronic device or a model in any application in the electronic device.

[0044] It should be noted that the user demand information in the embodiments of the present application refers to information for the user to use the multi-modal large model to meet specific goals or solve problems, such as please help me buy an American coffee, play music, etc. The user demand information includes but is not limited to information in formats such as images, texts, and audios.

[0045] Regarding step 220, after the user obtains the user requirement information, it is possible to analyze which user data is required for the user requirement information. Based on this, in some embodiments of the present application, this step 220 may specifically include step 2201 and step 2202.

[0046] Step 2201, identify the user requirement information through a multimodal large model to obtain an intent instruction for the user to operate the electronic device. Among them, the intent instruction in the embodiments of the present application refers to an intention defined by the user's expression for realizing natural interaction with the user. Here, by identifying the user requirement information through the multimodal large model, the user's intention can be understood more accurately, and more accurate responses and services can be provided.

[0047] Exemplarily, if the user requirement information is an image including coffee, the image can be identified through the multimodal large model to obtain an intent instruction for the user to operate the electronic device, such as ordering coffee; if the user requirement information includes audio, the audio can be speech-recognized through the multimodal large model to obtain an intent instruction for the user to operate the electronic device, such as purchasing an American coffee.

[0048] Step 2202, determine the user data required for the user to operate the electronic device according to the intent instruction.

[0049] Exemplarily, through the AI agent, user data such as the user's geographical location data, coffee preference data, frequently visited coffee shop data, and user communication number data can be determined based on an American coffee.

[0050] Thus, the embodiments of the present application can identify multimodal user requirement information to obtain an intent instruction, thereby determining the user data required for the user to operate the electronic device. It can not only understand the user's intention more accurately and provide more accurate responses and services, but also broaden the permission control from the applications in the electronic device to the permission control of the multimodal large models set between the application levels where each application is located, improving the universality of the application of the permission control method.

[0051] In some embodiments, before step 220, this permission control method may further include step 2401 to step 2403.

[0052] Step 2401, determine the data category of the user data according to the content of the user data. Among them, the data category in the embodiments of the present application is used to reflect the nature and characteristics of the user data. In the embodiments of the present application, the data category includes at least one of the following: biometric, personal data, device data, health care, whereabouts location, contact information, Internet browsing record, media file, public interest, account device, financial information, behavior habit and social activity information, education and work information, information communication.

[0053] Exemplarily, as Figure 3 shown, if the user data is the user's geographical location data, the data category of the user data can be the whereabouts location category; if the user data is the user's coffee preference data, the data category of the user data can be the behavior habit and social activity information category; if the user data is the user's communication number data, the data type of the user data can be the information communication category.

[0054] Step 2402: Based on the association information between the reference data category and the reference data level, determine the data level associated with the data category. Among them, the data levels in the embodiments of the present application include S1, S2, S3, S4, and S5, which are related to the sensitivity, importance, or security level of the data, and are used to represent the gradually increasing sensitivity, importance, or security level of the data. Specifically, S1 represents publicly available data, and this type of data has the property of public dissemination and can be publicly released and forwarded. S2 represents internal-level data, and this type of data is usually shared and used within the organization and among related parties, and can be shared outside the organization after authorization by the relevant parties. S3 represents sensitive-level data, and this type of data can only be accessed by authorized objects. S4 represents important-level data, and this type of data needs to be strictly managed according to the approved authorization list and can only be shared or disseminated within the controlled range after user authorization. S5 represents core-level data, and this type of data is prohibited from being shared or disseminated externally.

[0055] The reference data category is a pre-set data category, which is used to reflect the nature and characteristics of the user data. Its function is to classify and describe the user data to ensure the standardization and consistency of the data.

[0056] The reference data level is a pre-set data level, which is used to represent the gradually increasing sensitivity, importance, or security level of the data. Its function is to classify and describe the reference data category, and it provides a basis for the standardization and consistency of the data category.

[0057] The association information between the reference data category and the reference data level is a mapping relationship between the pre-set data category and the data level, which is used to reflect the corresponding relationship between the data category and the data level. Its function is to match the corresponding data level when the data category is known, or to match the corresponding data category when the data level is known, enhancing the understandability and usability of the data, and promoting the standardization and consistency of the data. Exemplarily, the whereabouts location category can be associated with S3, the behavior habit and social activity information category can be associated with S2, and the information communication category can be associated with S4. Step 2403: Determine the data level associated with the data category as the data level of the user data.

[0058] Exemplarily, if the whereabouts and location category is associated with S3, the data level associated with the user's geographic location data is determined to be S3; if the behavior habits and social activity information category is associated with S2, the data level associated with the user's coffee preference data is determined to be S2; if the information communication category is associated with S4, the data level of the user's communication number data is determined to be S4.

[0059] In this way, user data, data categories of user data and data levels of user data can be strictly managed, and whether it is necessary to prompt the user for authorization can be determined through the dimensions of the user data itself. The multimodal big model's understanding of user demand information can be fully utilized to determine the purpose of the multimodal big model's access to user data, and whether the multimodal big model's use of user data is reasonable can be dynamically judged. For user data that requires prompting the user for authorization, it can assist the user to better and more meticulously manage whether the user data can be read by untrusted multimodal big models, thereby improving the security of user data.

[0060] Involving step 230, in some embodiments of the present application, since individual users have different sensitivities to data, for example, some users are highly sensitive to geographic location, the static framework can be used to close any scene or any command that calls this type of data, thereby ensuring that such data will not be used regardless of the result of the dynamic permission usage framework. Based on this, the user requirement permission policy can be adjusted through the preset static usage permission policy set by the static framework to obtain an accurate authorization policy. Based on this, step 230 can specifically include steps 2301 and 2302.

[0061] Step 2301, based on the data level of the user data, determine the user required authority policy.

[0062] Exemplarily, the data level of the user's coffee preference data and the data of the coffee shops frequently visited by the user is S2, the data level of the user's geographic location data is S3, and the data level of the user's communication number data is S4. The user requirement permission policy may include allowing access to and use of the user's coffee preference data, the data of the coffee shops frequently visited by the user, and the user's geographic location data, but not allowing access to the user's communication number data, and the user may be asked via a pop-up window whether to authorize the use of the user's communication number data.

[0063] Step 2302: Generate an authorization policy based on the user's required permission policy and the preset static usage permission policy. The preset static usage permission policy is a permission policy for data access preset by the user, which includes which data set by the user is prohibited from being shared or disseminated externally, or which data set by the user needs to be asked by a pop-up window and can only be shared or disseminated after the user's authorization.

[0064] Exemplarily, if the AI agent is a service of the operating system in an electronic device, the preset static usage permission policy can be that after the electronic device is started, the user manually sets the permission for the AI agent to read user data. In this way, the user requirement permission policy obtained by analyzing the user requirement information through the preset static usage permission policy can be adjusted. That is, if the user data corresponding to the preset static usage permission policy is the user's geographical location data, then the user's geographical location data is not allowed to be read by the AI agent and the user needs to be asked through a pop-up window whether to authorize the use. At this time, the authorization policy can include allowing access to and using the user's coffee preference data and the data of the coffee shops the user often goes to, not allowing access to the user's communication number data and the user's geographical location data, and the user can be asked through a pop-up window whether to authorize the use of the user's communication number data and the user's geographical location data.

[0065] It should be noted that the forms of the user requirement permission policy, the preset static usage permission policy, and the authorization policy involved in the embodiments of the present application can include user data or data levels, allowing access and reading; user data or user levels, not allowing access and reading and asking for the user's opinion.

[0066] Thus, when the authorization policy indicates whether to prompt the user for authorization when the multimodal large model reads user data, for the user data that requires prompting the user for authorization, it can assist the user to better and more carefully manage whether the user data can be read by the untrusted multimodal large model, improving the security of the user data. For the user data that does not require prompting the user for authorization, it can directly participate in the process of the multimodal large model performing operations related to the user requirement information, reducing the operation of the user manually authorizing these user data, improving the efficiency of permission control, and at the same time, it can also improve the speed when the multimodal large model reads user data, improving the usage efficiency of the multimodal large model.

[0067] In some embodiments, the user requirement permission policy in the embodiments of the present application includes at least one of the following: the first requirement permission policy, the second requirement permission policy. Based on this, step 2301 can specifically include:

[0068] In the case where the number of levels of the data level is greater than or equal to the reference number of levels, the permission policy for indicating that the multimodal large model prompts the user for authorization when reading user data is determined as the first requirement permission policy. The reference number of levels refers to a standard number of levels set in advance to trigger prompting the user for authorization when reading user data. If the number of levels of the data level is greater than or equal to the reference number of levels, it indicates that the sensitivity, importance, or security level of the data is higher than the standard, and it needs to be asked through a pop-up window and can only be read after the user authorizes.

[0069] In the case where the number of levels at the data level is less than the reference number of levels, the permission policy used to indicate that the multimodal large model does not prompt the user for authorization when reading the user data is determined as the second required permission policy. Among them, if the number of levels at the data level is greater than or equal to the reference number of levels, it indicates that the sensitivity, importance, or security level of the data is lower than the standard, and the data can be read without pop - up asking the user.

[0070] Exemplarily, the reference number of levels can be 4. That is, in the case where the number of levels at the data level is greater than or equal to 4 (the reference number of levels), it can be indicated that the multimodal large model prompts the user for authorization when reading the user data. Then, the AI agent can directly access and use the user's coffee preference data, the data of the user's frequently visited coffee shops, and the user's geographical location data, and pop - up a window to ask the user whether to authorize the use of the user's communication number data. In this way, in the case where it is determined that the user authorizes the AI agent to access and use the user's communication number data, operations related to the user's demand information can be executed.

[0071] In some embodiments, the preset static usage permission policy in the embodiments of the present application is used to indicate that the multimodal large model prompts the user for authorization when reading the user data. The user demand permission policy at least includes the second required permission policy. Based on this, step 2302 above can specifically include:

[0072] In the case where the first user permission data related to the second required permission policy includes the second user permission data related to the preset static usage permission policy, the permission policy related to the second user permission data is adjusted to the first required permission policy.

[0073] Exemplarily, the first user permission data is the data to be accessed determined based on the data level of the user data, and the second user permission data is the data pre - set by the user in the preset static usage permission policy. For example, the first user permission data is to use the user's coffee preference data, the data of the user's frequently visited coffee shops, and the user's geographical location data, and the second user permission data is the user's geographical location data. Then, the permission policy related to the second user permission data can be adjusted to the first required permission policy, that is, changing the permission to allow access to the user's geographical location data to not allowing access to the user's geographical location data, and a pop - up window can be used to ask the user whether to authorize the use of the user's geographical location data.

[0074] In some embodiments of the present application, since individual users have different sensitivities to data. For example, some users have a high sensitivity to geographical location. Then, any scenario and any command to call this type of data can be closed through the static framework, so as to ensure that this type of data will not be used regardless of the result of the dynamic permission usage framework. Based on this, a process for determining the preset static usage permission policy is provided before step 230. Based on this, before step 230, this permission control method further includes steps 2501 to 2504.

[0075] Step 2501, receive a first input from a user to select a first data level from N data levels, where N is a positive integer, and the security levels of each level in the N data levels are different. As Figure 3 shown, N is 5, and its security levels can be arranged from high to low as S5, S4, S3, S2, S1.

[0076] Step 2502, in response to the first input, display M data categories corresponding to the first data level, where M is a positive integer.

[0077] It should be noted that the N data levels and M data categories in the embodiments of the present application can be classified according to standards, such as the standard of TC260 national standard GB / T 43697 "Data Security Technology - Data Classification and Grading Rules".

[0078] Step 2503, receive a second input from the user to select a first data category from the M data categories.

[0079] Step 2504, in response to the second input, determine the permission policy for instructing the multi-modal large model not to prompt the user for authorization when reading the user data of the first data category as the preset static usage permission policy.

[0080] Exemplarily, the user defines specific data type permissions through the data static usage permission framework. The user can define that location information cannot be used, and other permissions can be authorized for use through the AI agent. This framework can be the permission framework of the operating system itself, that is, there are clear and fixed control rules for data. For example, for the access of geographical location data, it can be clearly indicated whether the application can use this data through the permission switch in the settings.

[0081] Thus, it can assist the user to better and more carefully manage whether the user data can be read by untrusted applications and the AI agent itself, improve the security of the user data, and, for the user data that does not require prompting the user for authorization, relevant operations can be performed through the AI agent. For the user, performing operations related to the user's required information is imperceptible, thereby reducing the user's manual authorization operations for these user data, improving the efficiency of permission control, and at the same time, increasing the speed of the multi-modal large model when reading the user data, and improving the usage efficiency of the multi-modal large model.

[0082] In addition, after step 230, the permission control method provided by the embodiments of the present application may further include step 2601 and step 2602.

[0083] Step 2601: Generate operation process information according to the authorization policy. Herein, the operation process information refers to a series of ordered and coherent steps or operations carried out according to the authorization policy to complete the process of reading a certain item of user data.

[0084] Exemplarily, if the authorization policy includes directly accessing and using the user's coffee preference data, the data of the coffee shops the user often visits, and the user's geographical location data, and a pop-up window is used to ask the user whether to authorize the use of the user's communication number data. In this way, when it is determined that the user authorizes the AI agent to access and use the user's communication number data, operation process information can be generated. The operation process information includes "launch the application of Coffee Shop B", "select the specific location of Coffee Shop B: Coffee Shop B at Subway Station A", "type of coffee: American coffee", "quantity: 1", "remark: take away", "order the communication number 12345678910", "launch the payment account 610123456789 for payment", and "display the order completion information after payment is completed".

[0085] Step 2602: Through the multi-modal large model, perform operations related to the operation process information according to the operation process information.

[0086] Exemplarily, the application of Coffee Shop B can be run in the background of the electronic device, and Coffee Shop B at Subway Station A can be selected. Through the communication number 123, an order can be placed for a cup of American coffee with the remark of taking away.

[0087] In some embodiments of the present application, after step 2602, the permission control method provided by the embodiments of the present application may further include step 2603 and step 2604.

[0088] Step 2603: Store the records of the operations performed by the multi-modal large model related to the user demand information.

[0089] Exemplarily, still taking the above example, the records of the operations performed related to the user demand information may include running the application of Coffee Shop B in the background of the electronic device, selecting Coffee Shop B at Subway Station A, and placing an order for a cup of American coffee with the remark of taking away through the communication number 123.

[0090] Step 2604: When receiving the third input of the user, display the interface of the operations performed by the multi-modal large model related to the user demand information according to the records of the operations performed by the multi-modal large model related to the user demand information.

[0091] Exemplarily, since the above operations are invisible to the user, the above operations can be recorded, and when the user wants to view, the interface of the application of B Coffee Shop can be displayed, the interface of B Coffee Shop at A Subway Station can be selected, an order can be placed for a cup of American coffee with the communication number of account 123 and a note of takeout, and the interface of successful payment.

[0092] Thus, it is convenient for the user to view the records of the operations performed by the multimodal large model related to the user demand information, so as to improve the usage effect of the multimodal large model.

[0093] In some embodiments of the present application, there may be a situation where user data is uploaded to the server for processing or processed by an untrusted third-party application. In this case, in order to ensure data security, the user data or operation process information can be desensitized to avoid overusing the user data. Based on this, before step 2602, the permission control method provided by the embodiments of the present application may further include step 2605 of performing data desensitization processing on the operation process information to obtain the desensitized operation process information. Among them, data desensitization refers to the transformation of sensitive information through desensitization rules to achieve reliable protection of sensitive privacy data. In the embodiments of the present application, sensitive information includes but is not limited to the user's payment account, communication number, etc.

[0094] Exemplarily, before the multimodal large model transfers data to the corresponding application or server when performing operations related to the operation process information, through an intermediate layer, the user data or operation process information is desensitized, anonymized or privacy-computed to avoid the plaintext transmission of user data to the application. For example, if the operation process information includes an operation of querying the weather, the geographical location information at the city level can be provided instead of the location information accurate to a specific street.

[0095] Based on this, step 2602 may specifically include:

[0096] Through the multimodal large model, perform operations related to the operation process information according to the desensitized operation process information to obtain operation result information.

[0097] Exemplarily, the operation process information includes "launch the application of B Coffee Shop", "select the specific location of B Coffee Shop: B Coffee Shop at A Subway Station", "type of coffee is American coffee", "quantity: 1", "note: takeout", "order the communication number of account 12345678910", "launch payment with payment account 610123456789", and "display order completion information after payment". Then the operation result information can be "1 cup of takeout American coffee has been ordered at B Coffee Shop at A Subway Station".

[0098] Accordingly, the embodiments of the present application provide a method and system for data authorization based on the understanding of the classification and categorization of user data by a multimodal large model of an electronic device and the understanding of the purpose of using user data, aiming to help users better and more meticulously manage whether their data can be used by third parties or untrusted multimodal large models. Thus, compared with the authorization method using a single data type in the related art, the data categories, data levels, and the purpose of using data of user data can be automatically authorized and managed.

[0099] Based on this, in order to better illustrate the permission control method provided by the embodiments of the present application, the following will be described in detail in conjunction with Figure 4 this.

[0100] As Figure 4 shown, the permission control method in the embodiments of the present application can be as shown in the following steps 1 to 6.

[0101] Step 1, the user defines a specific preset static usage permission policy through the data static usage permission framework. For example, the user can define that the user's geographical location data in the information communication category at data level S2 cannot be used, and other permissions can be authorized for use through the AI agent.

[0102] Step 2, the user issues a command through the AI agent interface. After receiving the command, the AI agent analyzes which data is required for the command, and then analyzes the level and type of the data used according to the defined data classification and categorization criteria. Exemplarily, as shown in Figure 3 , by classifying and categorizing user data, user data of a certain data type can be identified. Then, according to the user's setting, that is, data greater than or equal to S4 and above cannot be automatically granted through the dynamic understanding of the command, and it is required that the user click to confirm after a pop-up window appears to use this type of data.

[0103] Step 3, based on the understanding of the type and level of the data used and the purpose of using the data, the AI agent determines whether the data can be authorized for use. For example, after the user issues a command to order coffee to the AI agent, it can be foreseen that this command will use 1. the user's geographical location data; 2. the user's coffee preference data; 3. the user's frequent coffee shop data; 4. the user's communication number data. Now assume that the user's coffee preference data and the user's frequent coffee shop data are S2 data, the geographical location is S3 data, and the user's communication number is S4 data. Then, the AI agent directly obtains and uses the coffee preference data, the user's frequent coffee shop data, and the user's geographical location data, and pops up a window to ask the user whether to authorize the use of the user's communication number data.

[0104] Step 4: Combine the user requirement permission policy of the AI agent and the preset static usage permission policy defined by the user to give an authorization policy for dynamic data usage. As in the example in Step 3 above, after the AI agent receives the command to order coffee, the result of classifying and grading the data used in the command is correct. Then, combined with the settings of the user in the static permission framework, such as the geographical location data cannot be used, it is determined whether the command can be completed, whether a pop-up window needs to be shown again and the user is required to authorize.

[0105] Step 5: Store the records of the multi-modal large model performing operations related to user requirement information in the monitoring system for later viewing by the user.

[0106] Step 6: Before the multi-modal large model determines that it can transfer data to the corresponding application according to the authorization policy, through an intermediate layer, the user data and / or the operation process information generated according to the authorization policy are desensitized, anonymized or privacy-computed to avoid the plaintext transmission of user data to the application.

[0107] Thus, the embodiments of the present application can make full use of the AI agent's understanding of commands, as well as its understanding of data classification and grading and the purpose of data usage, to dynamically and automatically judge whether the use of user data is reasonable, and then automatically authorize the use of data without the need for manual authorization by the user. This reduces the operation of the user manually authorizing this user data, improves the efficiency of permission control, and at the same time can also improve the speed when the multi-modal large model reads user data, and improves the usage efficiency of the multi-modal large model.

[0108] It should be noted that for the permission control method provided by the embodiments of the present application, the execution subject can be an electronic device such as a mobile phone, a tablet computer, a notebook computer, a handheld computer, a wearable device, etc. In some embodiments of the present application, taking the electronic device as the execution subject to execute the permission control method as an example, the permission control method provided by the embodiments of the present application is described.

[0109] For the permission control method provided by the embodiments of the present application, the execution subject can be a permission control device. In the embodiments of the present application, taking the permission control device to execute the permission control method as an example, the device of the permission control method provided by the embodiments of the present application is described.

[0110] The present application also provides a permission control device. Specifically, it is described in detail in combination with Figure 5 for details.

[0111] Figure 5 is the structural schematic diagram of the permission control device provided by some embodiments of the present application.

[0112] As Figure 5As shown, the permission control device 50 can be applied to an electronic device. Specifically, the permission control device 50 may include:

[0113] An acquisition module 501, configured to acquire user requirement information, where the user requirement information is used to indicate the requirements of the user for using the multimodal large model;

[0114] A determination module 502, configured to determine user data related to the user requirement information according to the user requirement information;

[0115] A generation module 503, configured to generate an authorization policy based on the data level of the user data. The authorization policy is used to indicate whether to prompt the user for authorization when the multimodal large model reads the user data, and the data level is used to represent the security level of the user data;

[0116] A display module 504, configured to display an authorization prompt message according to the authorization policy.

[0117] The permission control device 50 in the embodiments of the present application will be described in detail below, as specifically shown below.

[0118] In some embodiments of the present application, the generation module 503 may specifically be configured to determine a user requirement permission policy based on the data level of the user data;

[0119] Generate an authorization policy based on the user requirement permission policy and a preset static usage permission policy.

[0120] In some embodiments of the present application, when the user requirement permission policy includes at least one of the following: a first requirement permission policy and a second requirement permission policy, the determination module 502 may specifically be configured to, when the number of levels of the data level is greater than or equal to a reference number of levels, determine the permission policy for indicating that the multimodal large model prompts the user for authorization when reading the user data as the first requirement permission policy;

[0121] When the number of levels of the data level is less than the reference number of levels, determine the permission policy for indicating that the multimodal large model does not prompt the user for authorization when reading the user data as the second requirement permission policy.

[0122] In some embodiments of the present application, the generation module 503 may specifically be configured to, when the preset static usage permission policy is used to indicate that the multimodal large model prompts the user for authorization when reading the user data, the user requirement permission policy includes at least the second requirement permission policy, and the first user permission data related to the second requirement permission policy includes the second user permission data related to the preset static usage permission policy, adjust the permission policy related to the second user permission data to the first requirement permission policy.

[0123] In some embodiments of the present application, the permission control device 50 in the embodiments of the present application may further include a receiving module and a display module; wherein,

[0124] The receiving module is configured to receive a first input from the user to select a first data level from N data levels when the data level includes N data levels, and N is a positive integer;

[0125] The display module is configured to display M data categories corresponding to the first data level in response to the first input, and M is a positive integer;

[0126] The receiving module may further be configured to receive a second input from the user to select a first data category from the M data categories;

[0127] The determining module 502 may further be configured to, in response to the second input, determine the permission policy that does not prompt the user for authorization as a preset static usage permission policy, and the permission policy that does not prompt the user for authorization is the permission policy for instructing the multi-modal large model to read the user data of the first data category.

[0128] In some embodiments of the present application, the determining module 502 may further be configured to determine the data category of the user data according to the content of the user data;

[0129] Based on the association information between the reference data category and the reference data level, determine the data level associated with the data category;

[0130] Determine the data level associated with the data category as the data level of the user data.

[0131] In some embodiments of the present application, the permission control device 50 in the embodiments of the present application may further include an identification module and a determination module; wherein,

[0132] The identification module is configured to identify the user demand information through a multi-modal large model to obtain an intention instruction for the user to operate the electronic device;

[0133] The determining module may further be configured to determine the user data required for the user to operate the electronic device according to the intention instruction.

[0134] In some embodiments of the present application, the permission control device 50 in the embodiments of the present application may further include a generation module and an execution module; wherein,

[0135] The generation module is configured to generate operation process information according to the authorization policy;

[0136] The execution module is configured to execute an operation related to the operation process information through a multi-modal large model according to the operation process information.

[0137] In some embodiments of the present application, the permission control device 50 in the embodiments of the present application may further include a storage module and a display module; wherein,

[0138] The storage module is used to store records of operations performed by the multimodal large model related to user demand information;

[0139] The display module is used to, upon receiving a third input from the user, display an interface for the multimodal large model to perform operations related to user demand information according to the records of operations performed by the multimodal large model related to user demand information.

[0140] In some embodiments of the present application, the permission control device 50 in the embodiments of the present application may further include a processing module, which is used to perform data desensitization processing on the operation process information to obtain the desensitized operation process information;

[0141] The execution module may specifically be used to execute operations related to the operation process information through the multimodal large model according to the desensitized operation process information to obtain operation result information.

[0142] The permission control device in the embodiments of the present application may be an electronic device or a component in an electronic device, such as an integrated circuit or a chip. The electronic device may be a terminal or other devices other than a terminal. Exemplarily, the electronic device may be a mobile phone, a tablet computer, a laptop computer, a handheld computer, an in-vehicle electronic device, a Mobile Internet Device (MID), an augmented reality (AR) / virtual reality (VR) device, a robot, a wearable device, an ultra-mobile personal computer (UMPC), a netbook, or a personal digital assistant (PDA), etc., and may also be a server, a Network Attached Storage (NAS), a personal computer (PC), a television (TV), a teller machine, or a self-service machine, etc. The embodiments of the present application do not make specific limitations.

[0143] The permission control device in the embodiments of the present application may be a device with an operating system. The operating system may be an Android operating system, an IOS operating system, or other possible operating systems. The embodiments of the present application do not make specific limitations.

[0144] The permission control device provided by the embodiments of the present application can achieve Figures 1 to 4The various processes implemented by the embodiments of the permission control method shown achieve the same technical effects. To avoid repetition, they will not be elaborated here.

[0145] Based on this, the permission control device provided by the embodiments of the present application can determine user data related to the user demand information according to the obtained user demand information, where the user demand information is used to indicate the user demand of using a multimodal large model; then, based on the data level of the user data, an authorization policy is generated, and the authorization policy is used to indicate whether to prompt the user for authorization when the multimodal large model reads the user data. The data level is used to represent the security level of the user data. According to the authorization policy, an authorization prompt message is displayed. In this way, it is possible to fully utilize the understanding of the user demand information by the multimodal large model to determine the purpose of the multimodal large model accessing the user data, and combine the understanding of the classification of the user data to dynamically judge whether the use of the multimodal large model for the user data is reasonable, so as to indicate whether to prompt the user for authorization when the multimodal large model reads the user data through the authorization policy. For the user data that needs to prompt the user for authorization, an authorization prompt message can be displayed to assist the user in better and more detailed management of whether the user data can be read by an untrusted multimodal large model, improving the security of the user data. For the user data that does not need to prompt the user for authorization, it can directly participate in the process of the multimodal large model executing operations related to the user demand information, reducing the operation of the user manually authorizing these user data, improving the efficiency of permission control, and at the same time, it can also improve the speed when the multimodal large model reads the user data, improving the usage efficiency of the multimodal large model.

[0146] Optionally, as Figure 6 shown, the embodiments of the present application also provide an electronic device 60, including a processor 601 and a memory 602. A program or instruction that can run on the processor 601 is stored on the memory 602. When the program or instruction is executed by the processor 601, it implements the various steps of the above-mentioned embodiments of the permission control method and can achieve the same technical effects. To avoid repetition, they will not be elaborated here.

[0147] It should be noted that the electronic devices in the embodiments of the present application include the above-mentioned mobile electronic devices and non-mobile electronic devices.

[0148] Figure 7 This is a schematic diagram of the hardware structure of an electronic device provided by the embodiments of the present application.

[0149] The electronic device 700 includes but is not limited to: a radio frequency unit 701, a network module 702, an audio output unit 703, an input unit 704, a sensor 705, a display unit 706, a user input unit 705, an interface unit 708, a memory 709, a processor 710, and other components.

[0150] Those skilled in the art can understand that the electronic device 700 may further include a power source (such as a battery) for supplying power to each component. The power source can be logically connected to the processor 710 through a power management system, so as to manage functions such as charging, discharging, and power consumption management through the power management system.

[0151] Figure 7 The structure of the electronic device shown in does not limit the electronic device. The electronic device may include more or fewer components than shown in the figure, or combine certain components, or have different component arrangements, which will not be elaborated here.

[0152] Among them, in some embodiments of the present application, the processor 710 is used to obtain user demand information, and the user demand information is used to indicate the user's demand for using the multimodal large model. The processor 710 can also be used to determine user data related to the user demand information according to the user demand information. The processor 710 can also be used to generate an authorization policy based on the data level of the user data. The authorization policy is used to indicate whether to prompt the user for authorization when the multimodal large model reads the user data, and the data level is used to represent the security level of the user data. The display unit 706 is used to display an authorization prompt message according to the authorization policy.

[0153] The following will elaborate on the electronic device 700 in detail, as follows.

[0154] In some embodiments of the present application, the processor 710 can specifically be used to determine a user demand permission policy based on the data level of the user data;

[0155] Generate an authorization policy based on the user demand permission policy and a preset static usage permission policy.

[0156] In some embodiments of the present application, when the user demand permission policy includes at least one of the following: a first demand permission policy and a second demand permission policy, the processor 710 can be used to, when the number of levels of the data level is greater than or equal to a reference number of levels, determine the permission policy for indicating that the multimodal large model prompts the user for authorization when reading the user data as the first demand permission policy;

[0157] When the number of levels of the data level is less than the reference number of levels, determine the permission policy for indicating that the multimodal large model does not prompt the user for authorization when reading the user data as the second demand permission policy.

[0158] In some embodiments of the present application, the processor 710 may specifically be configured to prompt the user for authorization when a preset static usage permission policy is used to instruct the multi-modal large model to read user data. When the user requirement permission policy at least includes a second requirement permission policy, and the first user permission data related to the second requirement permission policy includes the second user permission data related to the preset static usage permission policy, the permission policy related to the second user permission data is adjusted to the first requirement permission policy.

[0159] In some embodiments of the present application, the user input unit 705 is configured to receive a first input from the user to select a first data level from N data levels when the data level includes N data levels, where N is a positive integer;

[0160] The display unit 706 is configured to display M data categories corresponding to the first data level in response to the first input, where M is a positive integer;

[0161] The user input unit 705 may further be configured to receive a second input from the user to select a first data category from the M data categories;

[0162] The processor 710 may further be configured to determine the permission policy that does not prompt the user for authorization as the preset static usage permission policy in response to the second input. The permission policy that does not prompt the user for authorization is the authorization policy for instructing the multi-modal large model to read the user data of the first data category.

[0163] In some embodiments of the present application, the processor 710 may further be configured to determine the data category of the user data according to the content of the user data;

[0164] Based on the association information between the reference data category and the reference data level, determine the data level associated with the data category;

[0165] Determine the data level associated with the data category as the data level of the user data.

[0166] In some embodiments of the present application, the processor 710 may further be configured to identify the user requirement information through the multi-modal large model to obtain the intent instruction for the user to operate the electronic device;

[0167] Determine the user data required for the user to operate the electronic device according to the intent instruction.

[0168] In some embodiments of the present application, the processor 710 may further be configured to generate operation process information according to the authorization policy;

[0169] Execute the operations related to the operation process information through the multi-modal large model according to the operation process information.

[0170] In some embodiments of the present application, the memory 709 is used to store records of operations performed by the multi-modal large model related to user requirement information;

[0171] The display unit 706 is used to display an interface for the multi-modal large model to perform operations related to user requirement information according to the records of operations performed by the multi-modal large model related to user requirement information when receiving a third input from the user.

[0172] In some embodiments of the present application, the processor 710 is used to perform data desensitization processing on the operation process information to obtain the desensitized operation process information after desensitization;

[0173] The multi-modal large model is used to perform operations related to the operation process information according to the desensitized operation process information to obtain operation result information.

[0174] It should be understood that the input unit 704 may include a Graphics Processing Unit (GPU) 7041 and a microphone 7042. The graphics processor 7041 processes the image data of static images or videos obtained by an image capture device (such as a camera) in a video capture mode or an image capture mode. The display unit 706 may include a display panel, and the display panel may be configured in the form of a liquid crystal display, an organic light-emitting diode, etc. The user input unit 705 includes at least one of a touch panel 7051 and other input devices 7052. The touch panel 7051 is also called a touch screen. The touch panel 7051 may include two parts: a touch detection device and a touch display. The other input devices 7052 may include, but are not limited to, a physical keyboard, function keys (such as volume display keys, switch keys, etc.), a trackball, a mouse, and a joystick, which will not be elaborated here.

[0175] The memory 709 can be used to store software programs and various data. The memory 709 mainly includes a first storage area for storing programs or instructions and a second storage area for storing data. Among them, the first storage area can store an operating system, application programs or instructions required for at least one function (such as a sound playback function, an image playback function, etc.). In addition, the memory 709 can include volatile memory or non-volatile memory, or the memory 709 can include both volatile and non-volatile memory. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM), a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDR SDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a synch link dynamic random access memory (SLDRAM), and a direct rambus random access memory (DRRAM). The memory 709 in the embodiments of the present application includes but is not limited to these and any other suitable types of memory.

[0176] The processor 710 can include one or more processing units; optionally, the processor 710 integrates an application processor and a modem processor. Among them, the application processor mainly processes operations related to the operating system, user interface, and application programs, etc., and the modem processor mainly processes wireless display signals, such as a baseband processor. It can be understood that the above modem processor may not be integrated into the processor 710.

[0177] The embodiments of the present application also provide a readable storage medium. Programs or instructions are stored on the readable storage medium. When the programs or instructions are executed by a processor, each process of the above embodiment of the permission control method is implemented, and the same technical effects can be achieved. To avoid repetition, it will not be elaborated here.

[0178] Among them, the processor is the processor in the electronic device in the above embodiments. Among them, the readable storage medium includes computer-readable storage media, such as computer read-only memory ROM, random access memory RAM, magnetic disks or optical discs, etc.

[0179] In addition, an embodiment of the present application further provides a chip, which includes a processor and a display interface. The display interface is coupled to the processor. The processor is used to run programs or instructions to implement each process of the above-mentioned embodiment of the permission control method, and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.

[0180] It should be understood that the chip mentioned in the embodiments of the present application may also be referred to as a system-on-chip, system chip, chip system, or system-on-chip, etc.

[0181] An embodiment of the present application provides a computer program product. The program product is stored in a storage medium and is executed by at least one processor to implement each process of the above-mentioned embodiment of the permission control method, and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.

[0182] It should be noted that in this article, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the phrase "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including the element.

[0183] In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed. It may also include performing functions in a substantially simultaneous manner or in a reverse order according to the functions involved. For example, the described methods may be performed in an order different from that described, and various steps may be added, omitted, or combined. In addition, the features described with reference to certain examples may be combined in other examples.

[0184] Through the description of the above embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases, the former is a better implementation method. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, can be embodied in the form of a computer software product. The computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions to enable a terminal (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods of the various embodiments of the present application.

[0185] The embodiments of the present application have been described above in conjunction with the accompanying drawings. However, the present application is not limited to the above specific implementation manners. The above specific implementation manners are merely illustrative and not restrictive. Under the inspiration of the present application, those of ordinary skill in the art can also make many forms without departing from the scope protected by the purpose and claims of the present application, and all of them belong to the protection scope of the present application.

Claims

1. A permission control method, characterized in that: include: Acquiring user demand information, where the user demand information is used to indicate the user's demand for using a multimodal large model; Determining user data related to the user demand information according to the user demand information; Based on the data level of the user data, an authorization policy is generated, wherein the authorization policy is used to indicate whether to prompt the user for authorization when the multimodal large model reads the user data, and the data level is used to indicate the security level of the user data; According to the authorization policy, authorization prompt information is displayed.

2. The method according to claim 1, characterized in that The generating of the authorization policy based on the data level of the user data includes: Determining a user requirement authority policy based on the data level of the user data; The authorization policy is generated based on the user demand authority policy and the preset static usage authority policy.

3. The method according to claim 2, characterized in that The user requirement authority policy includes at least one of the following: a first requirement authority policy and a second requirement authority policy; The determining of the user requirement authority policy based on the data level of the user data includes: When the number of levels of the data level is greater than or equal to the number of reference levels, determining the permission policy for instructing the multimodal large model to prompt the user for authorization when reading the user data as the first required permission policy; In a case where the number of levels of the data hierarchy is less than the reference number of levels, a permission policy for instructing the multimodal large model not to prompt the user for authorization when reading user data is determined as the second required permission policy.

4. The method according to claim 3, characterized in that The preset static usage permission policy is used to instruct the multimodal large model to prompt the user for authorization when reading user data, and the user requirement permission policy at least includes the second requirement permission policy; The generating the authorization policy based on the user demand authority policy and the preset static usage authority policy includes: In a case where the first user authority data associated with the second required authority policy includes the second user authority data associated with the preset static use authority policy, the authority policy associated with the second user authority data is adjusted to the first required authority policy.

5. The method according to claim 2, characterized in that: The data hierarchy includes N data hierarchies; and the method further includes: Receiving a first input from a user selecting a first data layer from N data layers, where N is a positive integer; In response to the first input, displaying M data categories corresponding to the first data level, where M is a positive integer; receiving a second input from a user selecting a first data category from the M data categories; In response to the second input, the permission policy that does not prompt the user for authorization is determined as the preset static usage permission policy, and the permission policy that does not prompt the user for authorization is the permission policy used to instruct the multimodal large model to read user data related to the first data category.

6. The method according to claim 1 or 2, characterized in that: Before generating the authorization policy based on the data level of the user data, the method further includes: Determining a data category of the user data according to content of the user data; Determining a data level associated with the data category based on association information between the reference data category and the reference data level; A data level associated with the data category is determined as the data level of the user data.

7. The method according to claim 1, characterized in that The determining, according to the user demand information, user data related to the user demand information includes: The user demand information is identified through the multimodal large model to obtain the user's intended instructions for operating the electronic device; According to the intention instruction, user data required for the user to operate the electronic device is determined.

8. The method according to claim 1, characterized in that The method further comprises: Generate operation process information according to the authorization policy; Through the multimodal large model, operations related to the operation process information are performed according to the operation process information.

9. The method according to claim 8, characterized in that The method further comprises: Storing records of operations performed by the multimodal large model related to the user demand information; When the third input from the user is received, an interface for the multimodal big model to perform the operation related to the user demand information is displayed according to the record of the multimodal big model performing the operation related to the user demand information.

10. The method according to claim 8, characterized in that Before performing the operation related to the operation process information according to the operation process information by using the multimodal large model, the method further includes: Performing data desensitization processing on the operation process information to obtain desensitized operation process information; The performing of operations related to the operation process information according to the operation process information through the multimodal large model includes: Through the multimodal large model, according to the desensitized operation process information, operations related to the operation process information are performed to obtain operation result information.

11. A permission control device, characterized in that: include: An acquisition module, used to acquire user demand information, where the user demand information is used to indicate the user's demand for using a multimodal large model; A determination module, configured to determine user data related to the user demand information according to the user demand information; A generating module, configured to generate an authorization policy based on the data level of the user data, wherein the authorization policy is used to indicate whether to prompt the user for authorization when the multimodal macro model reads the user data, and the data level is used to indicate the security level of the user data; The display module is used to display authorization prompt information according to the authorization policy.

12. An electronic device, characterized in that: include: A processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps of the permission management method as described in any one of claims 1 to 10 are implemented.

13. A readable storage medium, characterized in that: The readable storage medium stores a program or instruction, and when the program or instruction is executed by the processor, the steps of the permission management method as described in any one of claims 1-10 are implemented.

14. A computer program product, characterized in that The program product is stored in a storage medium, and the program product is executed by at least one processor to implement the steps of the permission management method according to any one of claims 1 to 10.

Citation Information

Cited By

  • Conversational zero-trust permission policy generation method and system based on AI

    CN121009562A

  • Permission management and control method and apparatus, electronic device, medium and product

    WO2026175298A1