File operation authority control method, storage medium and electronic device

By setting file operation permissions corresponding to the simulation area for software applications, the problems of data leakage and permission constraints in the prior art are solved, and higher data security is achieved.

CN120145407APending Publication Date: 2025-06-13ZTE CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311695993.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-11
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

Existing file operation permission control methods can easily lead to data leakage to software applications that do not have permission to access the data, and cannot customize the file read and write permissions.

Method used

By setting the correspondence between the file operation permissions of the software application and the specified simulation area, the software application controls the file operation within the specified simulation area to ensure that the data can only be read and written in the specified simulation area.

Benefits of technology

Effectively prevent data leakage to software applications without permission, improving the data security of software applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120145407A_ABST
    Figure CN120145407A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a file operation authority control method, a storage medium and an electronic device. The method comprises the following steps: setting a corresponding relationship between a file operation authority of a software application and a specified simulation area; and controlling the software application to perform file operation in the specified simulation area according to the corresponding relation. According to the method and the device, the problem that the data is easily leaked to the software application without the right to access the data based on the existing file operation authority control method is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the field of information security technology. Specifically, the embodiments of the present invention relate to a file operation permission control method, a storage medium, and an electronic device. Background Art

[0002] Currently, the privacy security technology of terminal products has developed rapidly. As long as users install software applications using terminal products such as mobile phones and computers, they have to face the contradiction between the information security risks brought by software application permissions and the convenience of using the software applications themselves.

[0003] In the related art, usually, by setting the file security level or the way for users to customize access to files, different application software is granted the permission to access some files in the system files, so as to avoid privacy leakage caused by granting the permission for application software to access all files of a certain category. However, this file access permission control method is likely to leak the corresponding data to other software applications that do not have this permission through a software application with a certain permission; at the same time, it is also impossible to customize the constraints on file read and write permissions. Summary of the Invention

[0004] The embodiments of the present invention provide a file operation permission control method to at least solve the problem in the related art that based on the existing file operation permission control method, data is easily leaked to software applications that have no right to access the data.

[0005] According to an embodiment of the present invention, a file operation permission control method is provided, including: setting the correspondence between the file operation permissions of software applications and a specified simulation area; controlling the software applications to perform file operations within the specified simulation area according to the correspondence.

[0006] According to another embodiment of the present invention, a computer-readable storage medium is further provided. A computer program is stored in the computer-readable storage medium, where the computer program is configured to execute the steps in any one of the above method embodiments when running.

[0007] According to still another embodiment of the present invention, an electronic device is further provided, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.

[0008] Through the above embodiments of the present invention, since the correspondence between the file read / write permissions of the software application and the specified simulation area is set, the software application can only perform file operations within the specified simulation area according to this correspondence, that is, the software application only needs to perform file operations within the simulation area, and there is no need and it is also impossible to leak data to software applications that have no right to access the data within the simulation area. Therefore, it is possible to solve the problem that based on the existing file operation permission control method, it is easy to leak data to software applications that have no right to access the data, and achieve the effect of improving the data security of the software application. BRIEF DESCRIPTION OF THE DRAWINGS

[0009] Figure 1 is a hardware structure block diagram of a computer terminal for running a file operation permission control method according to an embodiment of the present invention;

[0010] Figure 2 is a flowchart of a file operation permission control method according to an embodiment of the present invention;

[0011] Figure 3 is a schematic diagram of the process of configuring file operation permissions after the installation of a software application according to an embodiment of the present invention;

[0012] Figure 4 is a schematic diagram of the process of a software application accessing a storage space according to an embodiment of the present invention;

[0013] Figure 5 is a flowchart of managing a simulation area of a certain payment software according to an embodiment of the present invention;

[0014] Figure 6 is a flowchart of managing the same simulation area of a social software according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0015] In the following, embodiments of the present invention will be described in detail with reference to the drawings and in conjunction with the embodiments.

[0016] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence.

[0017] The method embodiments provided in the embodiments of the present application can be executed on a mobile terminal, a computer terminal or a similar computing device. Taking running on a computer terminal as an example, Figure 1 is a hardware structure block diagram of a computer terminal for running a file read / write permission control method according to an embodiment of the present invention. As Figure 1 shown, the computer terminal may include one or more ( Figure 1Only one processor 102 is shown (the processor 102 may include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA), and a memory 104 for storing data. Among them, the above computer terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those of ordinary skill in the art can understand that Figure 1 The structure shown is only illustrative and does not limit the structure of the above computer terminal. For example, the computer terminal may further include more or fewer components than Figure 1 shown in, or have a different configuration from Figure 1 shown.

[0018] The memory 104 can be used to store computer programs. For example, software programs and modules of application software, such as the computer program corresponding to the file read / write permission control method in the embodiment of the present invention. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, implements the above method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely set relative to the processor 102, and these remote memories can be connected to the computer terminal through a network. Examples of the above network include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.

[0019] The transmission device 106 is used to receive or send data via a network. Specific examples of the above network may include a wireless network provided by a communication provider of the computer terminal. In one instance, the transmission device 106 includes a network adapter (Network Interface Controller, abbreviated as NIC), which can be connected to other network devices through a base station and thus communicate with the Internet. In one instance, the transmission device 106 may be a radio frequency (Radio Frequency, abbreviated as RF) module, which is used to communicate with the Internet wirelessly.

[0020] In this embodiment, a file read / write permission control method running on the above computer terminal is provided. Figure 2 It is a flowchart of the file read / write permission control method according to the embodiment of the present invention, as Figure 2 shown, and the process includes the following steps:

[0021] Step S202, set the correspondence between the file operation permissions of the software application and the specified simulation area;

[0022] Among them, the file operation permission of the software application, that is, whether the software application has the right to perform file operations in the corresponding simulation area.

[0023] In this embodiment, by creating one or more simulation areas on the terminal product, when the software application on the terminal product installs software or sets file operation permissions, its file operation permissions are further restricted. At the same time, the files generated by the software application can also be protected by the simulation space technology to prevent other software applications from obtaining the user's privacy records, effectively protecting the user's privacy.

[0024] In this embodiment, the determination of the specified simulation area includes: when there is an existing simulation area in the system, judging whether the existing simulation area is shared by different software applications according to the recommendation strategy; when the existing simulation area can be shared, determining the existing simulation area as the specified simulation area.

[0025] When there is no simulation area in the system, or the software application cannot share the existing simulation area, a new simulation area is set in the system, and the new simulation area is determined as the specified simulation area.

[0026] In one embodiment, before judging whether the existing simulation area is shared by different software applications according to the recommendation strategy, the method further includes: formulating the recommendation strategy through at least one of the following: the function of the software application, the software developer to which the software application belongs, the interaction association strength between the software application and other software applications, and the software classification strategy of different users.

[0027] In one embodiment, different software applications can be configured with different simulation areas.

[0028] In one embodiment, the simulation area is set as an empty area.

[0029] In one embodiment, the simulation area is a customized area for specified types of software applications. For example, several specified chat software share a simulation storage area.

[0030] In one embodiment, the files in the simulation area are managed by the user's self - definition.

[0031] In one embodiment, the entire simulation area can be encrypted so that the content in the simulation area can only be accessed by specified software applications, that is, only the software application with decryption permission has the decryption key and is recorded in the corresponding control mark.

[0032] Step S204, the corresponding relationship controls the software application to perform file operations in the specified simulation area.

[0033] The correspondence between the file operation permissions of a software application and a specified simulation area means: controlling and marking the file operation permissions of the software application, and recording the correspondence between the control mark of the software application and the physical address of the simulation area in the control mark file, so that the physical address of the simulation area can be known through the control mark and accessed.

[0034] In one embodiment, when the marked software application exercises the file access function, it can only control the files within the specified simulation area according to the control mark.

[0035] In this embodiment, the file operations at least include one of the following: file reading, file writing, file creation, file downloading, file editing, and file deletion.

[0036] In one embodiment, the content written to the file includes at least one of the following: the file generated by the software application, the local file outside the specified simulation area that the software application needs to read.

[0037] When the content written to the file is the local file outside the specified simulation area that the software application needs to read, controlling the software application to write the file within the specified simulation area according to the corresponding relationship includes: setting an interaction button, and when it is detected that the software application needs to read the local file and the interaction button is triggered, instructing the user through the user terminal to copy the local file to the specified simulation area.

[0038] In one embodiment, when the file operation is file editing, when the software application modifies the local file, synchronize the source file corresponding to the local file in the local to the modified local file.

[0039] After step S204 of this embodiment, the method further includes: transferring the file generated based on the file operation to the corresponding location through the specified simulation area.

[0040] For example: when the software application downloads, creates, or edits a file in the specified simulation area, a new file will be generated. At this time, the generated new file can be transferred to the corresponding location.

[0041] For another example: when the software application needs to call the target file outside the specified simulation area, the target file is written to the specified simulation area by copying. After that, the software application calls the target file in the specified simulation area. For example, file reading or file modification. When the target file is modified, the file generated by the modification is transferred to the source file corresponding to the target file.

[0042] In this embodiment, after controlling the software application to write files in the specified simulation area according to the corresponding relationship, the method further includes: encrypting the files written in the specified simulation area; decrypting the files when the software application calls the files in the specified simulation area.

[0043] In one embodiment, the files in the simulation area can be periodically cleared according to certain rules. For example: when the total size of the files in the specified simulation area exceeds a preset threshold, the files in the specified simulation area are cleared.

[0044] In one embodiment, when clearing the files in the specified simulation area, the files that have not been called for a long time are cleared first.

[0045] In this embodiment, the method further includes: querying the corresponding relationship, and deleting the specified simulation area when there is no software application corresponding to the specified simulation area.

[0046] In one embodiment, when the software application is uninstalled, query the corresponding relationship and check the control flag. If the specified simulation area is no longer enabled by any software application, delete and clear the specified simulation area.

[0047] Through the above steps, since the corresponding relationship between the file read / write permissions of the software application and the specified simulation area can be set, this corresponding relationship can record the corresponding simulation area, and the simulation area can be customized and encrypted according to the specified type of software, so that the content in the simulation area can only be operated on by the specified software application, and the files generated by the software application are protected through the simulation area to prevent other software applications from obtaining the privacy records therein. Therefore, the problem that the data generated by a single software application is leaked to other software can be solved, and the effects of protecting user privacy and improving the data security of software applications can be achieved.

[0048] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present invention, in essence, or the part that makes a contribution to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disc), and includes several instructions for causing a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in various embodiments of the present invention.

[0049] Means for restricting file operation permissions (such as storage permissions, read / write permissions) in related technologies include: classifying files so that software applications can only access one type of file; however, in this way, the permissions released to software applications are still too large to restrict file access (reading) for software applications specifically. In the embodiments of the present invention, by constructing a simulated space, software applications can only store, read, and write files in the simulated space, thereby further restricting the permissions of software applications and protecting user privacy. Among them, the timing of setting the permissions of software applications includes: when the software application is installed or after the software application is installed.

[0050] Figure 3 is a schematic diagram of the process for configuring file operation permissions after the installation of a software application according to an embodiment of the present invention. Among them, the file operation permissions take the file read / write permissions as an example, as Figure 3 shown, this process includes the following steps:

[0051] Step S301, software installation.

[0052] Step S302, determine whether the software application is granted file read / write permissions. If so, enter step S303; otherwise, enter step S304.

[0053] Specifically, when selecting to authorize file read / write permissions after the installation of the software application, set the file read / write permissions of the specified simulated area for the software application.

[0054] Step S303, determine whether there is an existing simulated area in the system. If not, enter step S307; otherwise, enter step S306.

[0055] Step S304, manage according to the default method.

[0056] Step S305, determine whether to share the existing simulated area. If so, enter step S307; otherwise, enter step S306.

[0057] Step S306, create a new simulated area and enter step S307.

[0058] Step S307, open the selected simulated area to the software application.

[0059] Specifically, determine a simulated area from the existing simulated areas in the system for giving the software application the permission to read and write files in this simulated area; this empty simulated area is equivalent to the above-mentioned specified simulated area.

[0060] For example, a recommendation strategy is formulated by means of functions provided by software, the software developer to which the software application belongs, the interaction correlation strength (i.e., the interaction correlation strength between software applications), and the classification strategy that can intelligently learn different users, so that different software applications can share a simulation area or create a new simulation area.

[0061] Step S308: Open the newly created simulation area to the software application.

[0062] Step S309: Create a control marker file to record the correspondence between the software application and the simulation area.

[0063] That is, record the correspondence between the file read / write permission of the software application and the specified simulation area in the control marker file.

[0064] Based on the above file operation permission settings, the software application can perform corresponding file access. Taking the software application's access to the storage space as an example, Figure 4 is a schematic diagram of the software application's access to the storage space according to an embodiment of the present invention. As Figure 4 shown, the process includes the following steps:

[0065] Step S401: The software application accesses the storage space.

[0066] Step S402: Determine whether the software application is marked by the control marker. If so, go to step S403; otherwise, go to step S404.

[0067] In this embodiment, the software application only perceives some files in the corresponding simulation area recorded by the control marker file and cannot actively perceive other files in the simulation area that have no read / write permission.

[0068] Step S403: The software application accesses the simulation area corresponding to the control marker.

[0069] Step S404: Access the storage space in the normal process.

[0070] Step S405: Determine whether the simulation area is encrypted. If so, go to step S407; otherwise, go to step S406.

[0071] Step S406: Read and write files normally.

[0072] Step S407: After decrypting according to the key of the control marker, perform file read and write.

[0073] In this embodiment, in addition to the normal access process, based on the above file operation permissions, the following file access steps are further included:

[0074] Step S1: Configure an interaction button to enable the software application to read and write files outside the simulation area corresponding to it.

[0075] For example, when the user needs the software application to read a file outside the simulated area to which it belongs, after the user clicks the interaction button, the user can select the target file outside the simulated area. Then, the system copies the target file to the simulated area, and the software application can call read and write operations in the simulated area.

[0076] In one embodiment, after the software application finishes calling, it detects whether the copied target file has been modified. If it has been modified, the modification is synchronized to the source file corresponding to the target file.

[0077] Step S2: The software application generates a file into the space of the corresponding simulated area according to the control mark of the software application. The generated file can only be read and written by the user, system processes, and software applications sharing the same simulated area.

[0078] Step S3: Transfer the files generated by the software application based on file download, file creation, and file editing to a specified location through the simulated area.

[0079] Step S4: When the total size of the files in the simulated area exceeds the threshold, clean up is performed. When cleaning up, files that have not been called for a long time are preferentially cleaned up;

[0080] Step S5: When the software application is uninstalled, check its control mark. If the simulated area is no longer enabled by any software, delete and clean up this simulated area.

[0081] To facilitate the understanding of the technical solution provided by the present invention, the following will be elaborated in detail with reference to embodiments in specific scenarios.

[0082] Scenario 1: Managing the simulated area of a certain payment software

[0083] Figure 5 is a flowchart for managing the simulated area of a certain payment software according to an embodiment of the present invention. As Figure 5 shown, the process includes the following steps:

[0084] Step S501: Create an independent simulated area for the payment software application and set the initial state of the simulated area to be empty;

[0085] Step S502: Store the files generated by the payment software application in the simulated area, encrypt the files in the simulated area, and decrypt the files in the simulated area only when the payment software application calls them;

[0086] Step S503: When the payment software application needs to read and write local files, detect this behavior, first guide the user to copy the files to be read and written to the simulated area, and then the payment software application obtains the files to be read and written from the simulated area;

[0087] Step S504, the user decides whether to immediately destroy the file copied to the simulation area after the payment software application calls the file according to the requirement;

[0088] Step S505, for the files actively downloaded and created by the user through the payment software application, they can be transferred from the simulation area to a specified location. If it is detected that the copied target file is modified, the modified target file will be synchronously modified to the source file, that is, the source file corresponding to the local file in the local area will be synchronized to the modified local file;

[0089] Step S506, the user decides whether to destroy, copy or transfer the files generated by the software application to other simulation areas according to the requirement;

[0090] Step S507, automatically clean the files in the simulation area that have not been called for a long time. For example, the files that have not been called for more than half a month can be automatically cleaned.

[0091] Scenario 2: Manage the same simulation area of social software, where there are multiple social software.

[0092] Figure 6 It is a flowchart for managing the same simulation area of social software according to an embodiment of the present invention. As Figure 6 shown, this process includes the following steps:

[0093] Step S601, create an independent simulation area for the social software application and set the initial state of this simulation area to be empty;

[0094] Step S602, store all the files generated by the social software application in the same simulation area;

[0095] Step S603, when the social software application needs to read the album, after detecting this behavior, first guide the user to copy the files to be read and written to the simulation area, and then the software application obtains the files to be read and written from the simulation area;

[0096] Step S604, the user decides whether to immediately destroy the file copied to the simulation area after the software application calls the file according to the requirement;

[0097] Step S605, for the files actively downloaded and created by the user through the social software application, they can be transferred from the simulation area to a specified location. If it is detected that the copied target file is modified, the modified target file will be synchronously modified to the source target file, that is, the source file corresponding to the local file in the local area will be synchronized to the modified local file;

[0098] Step S606, the user decides whether to destroy, copy or transfer the files generated by the software application to other simulation areas according to the requirement;

[0099] Step S607, automatically clean the files that have not been called for a long time in the simulation area. For example, the files that have not been called for more than half a month can be automatically cleaned up.

[0100] Through the above embodiments of the present invention, the screen refresh rate and reporting rate of the terminal can be intelligently reduced, the power consumption of the touch screen of the terminal product can be reduced, the software applications that need to obtain file read and write permissions can be further restricted, and the files available for reading and writing can be arranged specifically. The data generated by the software application is protected by the simulation space technology to prevent other software from obtaining the privacy records therein, and the privacy of users can be effectively protected.

[0101] An embodiment of the present invention also provides a computer-readable storage medium, in which a computer program is stored. Wherein, the computer program is set to execute the steps in any one of the above method embodiments when running.

[0102] In an exemplary embodiment, the above computer-readable storage medium may include, but is not limited to: USB flash drive, read-only memory (ROM for short), random access memory (RAM for short), mobile hard disk, magnetic disk or optical disc, etc., various media that can store computer programs.

[0103] An embodiment of the present invention also provides an electronic device, including a memory and a processor. A computer program is stored in the memory, and the processor is set to run the computer program to execute the steps in any one of the above method embodiments.

[0104] In an exemplary embodiment, the above electronic device may further include a transmission device and an input / output device. Wherein, the transmission device is connected to the above processor, and the input / output device is connected to the above processor.

[0105] The specific examples in this embodiment can refer to the examples described in the above embodiments and exemplary embodiments, and will not be repeated here.

[0106] Obviously, those skilled in the art should understand that the above-mentioned modules or steps of the present invention can be implemented by a general-purpose computing device. They can be concentrated on a single computing device or distributed on a network composed of multiple computing devices. They can be implemented by program codes executable by the computing device. Thus, they can be stored in a storage device and executed by the computing device. And in some cases, the steps shown or described can be executed in a sequence different from that here, or they can be separately fabricated into individual integrated circuit modules, or multiple modules or steps among them can be fabricated into a single integrated circuit module for implementation. In this way, the present invention is not limited to any specific combination of hardware and software.

[0107] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A method for controlling file operation permissions, characterized in that, it includes: setting the correspondence between the file operation permissions of a software application and a specified simulation area; controlling the software application to perform file operations within the specified simulation area according to the correspondence.

2. The method according to claim 1, characterized in that, wherein, the file operations at least include one of the following: file reading, file writing, file creation, file downloading, file editing, file deletion.

3. The method according to claim 1, characterized in that, before setting the correspondence between the file operation permissions of a software application and a specified simulation area, the method further includes: when there is an existing simulation area in the system, judging whether the existing simulation area is shared by different software applications according to a recommendation strategy; when the existing simulation area can be shared, determining the existing simulation area as the specified simulation area.

4. The method according to claim 3, characterized in that, before judging whether the existing simulation area is shared by different software applications according to a recommendation strategy, the method further includes: formulating the recommendation strategy through at least one of the following: the function of the software application, the software developer to which the software application belongs, the interaction association strength between the software application and other software applications, the software classification strategy of different users.

5. The method according to claim 3, characterized in that, before setting the correspondence between the file operation permissions of a software application and a specified simulation area, the method further includes: when there is no simulation area in the system, or the software application cannot share the existing simulation area, setting a new simulation area in the system and determining the new simulation area as the specified simulation area.

6. The method according to claim 2, characterized in that, wherein, the content written into the file includes at least one of the following: the file generated by the software application, the local file outside the specified simulation area that the software application needs to read.

7. The method according to claim 6, characterized in that, controlling the software application to perform file writing within the specified simulation area according to the correspondence includes: setting an interaction button, and when it is detected that the software application needs to read the local file and the interaction button is triggered, instructing the user through the user terminal to copy the local file to the specified simulation area.

8. The method according to claim 7, characterized in that, after controlling the software application to perform file operations within the specified simulation area according to the correspondence, the method further includes: when the software application modifies the local file, synchronizing the source file corresponding to the local file in the local to the modified local file.

9. The method according to claim 2, characterized in that, after controlling the software application to perform file operations within the specified simulation area according to the correspondence, the method further includes: transferring the file generated based on the file operation to the corresponding position through the specified simulation area.

10. The method according to claim 2, wherein, after controlling the software application to perform file writing in the specified simulation area according to the corresponding relationship, the method further includes: encrypting the file written in the specified simulation area; decrypting the file when the software application calls the file in the specified simulation area.

11. The method according to claim 1, wherein, the method further includes: when the total size of the files in the specified simulation area exceeds a preset threshold, cleaning the files in the specified simulation area.

12. The method according to claim 1, wherein, the method further includes: querying the corresponding relationship, and deleting the specified simulation area when there is no software application corresponding to the specified simulation area.

13. A computer-readable storage medium, wherein, a computer program is stored in the computer-readable storage medium, and when the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 12 are implemented.

14. An electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein, when the processor executes the computer program, the steps of the method according to any one of claims 1 to 12 are implemented.