Extension program management method and device, medium and equipment
Through the management background, the installation of browser extensions is managed uniformly, the security risks of browser extensions are solved, and the security control of extensions is achieved, and the risk of enterprise data leakage is reduced.
Patent Information
- Application Number
- CN202311754932.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-19
- Publication Date
- 2025-06-20
AI Technical Summary
Browser extensions pose security risks, especially for enterprise users, some extensions may collect user-sensitive data, resulting in the leakage of enterprise privacy information.
The installation of browser extensions is uniformly managed through the management background, obtain permission configuration information and match the permission information of the target extensions. If it does not match, the installation will be terminated to prevent unauthorized extensions from accessing sensitive data.
Effectively reduce security risks, ensure that the installed extensions comply with security standards, and prevent potentially dangerous operations, thereby improving the data security management capabilities of enterprises or organizations.
Smart Images

Figure CN120180392A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular, to a method, apparatus, medium, and device for managing extension programs. Background Art
[0002] Browser extension programs, commonly referred to as extensions or add-ons, are software components used to enhance the functionality and performance of web browsers. Extensions can add new features or extend existing features to the browser, thereby improving the user experience. For example, extensions can include ad blockers, password managers, search tools, news readers, language translators, etc. In the related art, users can select and install these extensions from the browser's extension store according to their personal needs and preferences, or directly install third-party self-extracting extensions locally. Although extension programs can bring convenience and enhanced functionality to users, there are also certain security risks, especially for enterprise users. For example, some extension programs may collect sensitive user data, which may lead to the leakage of enterprise privacy information. Summary of the Invention
[0003] Embodiments of this application provide a method, apparatus, medium, and device for managing extension programs, which can uniformly manage the installation of browser extension programs through a management background, ensure that the installed extension programs meet security standards, prevent unauthorized extensions from accessing sensitive data or performing potentially dangerous operations, thereby reducing security risks. The above technical solutions are as follows:
[0004] In a first aspect, an embodiment of this application provides a method for managing extension programs, the method including:
[0005] When detecting that the browser is started, obtain permission configuration information from the management background;
[0006] After detecting an installation instruction for a target extension program, obtain first permission information for the target extension program;
[0007] Determine whether the first permission information matches the permission configuration information;
[0008] If not, terminate the installation of the target extension program.
[0009] In a possible implementation, the method further includes:
[0010] Receive a permission configuration change instruction from the management background; the permission configuration change instruction carries permission configuration change information;
[0011] Update the permission configuration information based on the permission configuration change information.
[0012] In a possible implementation, the above method further includes:
[0013] Obtain second permission information corresponding to the installed extensions in the above browser;
[0014] Determine whether the above second permission information matches the above permission configuration information;
[0015] If not, disable the above installed extensions.
[0016] In a possible implementation, the above method further includes:
[0017] After detecting the installation instruction of the above target extension, when the above target extension belongs to a self-extracting extension, determine whether the developer mode of the above browser is enabled;
[0018] If not enabled, terminate the installation of the above target extension.
[0019] In a possible implementation, the above method further includes:
[0020] When detecting the startup of the above browser, obtain mode configuration information from the above management background;
[0021] Determine the control permission of the above developer mode based on the above mode configuration information;
[0022] When the above control permission is disabled, prohibit the opening of the developer mode of the above browser.
[0023] In a possible implementation, the above method further includes:
[0024] When the above control permission is disabled, receive a mode control instruction from the above management background; the above mode control instruction carries the enable control information of the above developer mode;
[0025] Based on the above enable control information, set the above control permission to enabled, and after detecting the completion of the installation of the above target extension or after the above control permission is enabled for a preset duration, set the above control permission to disabled.
[0026] In a possible implementation, the above method further includes:
[0027] After detecting the installation instruction of the above target extension, obtain the data source information of the above target extension;
[0028] Determine whether the above data source information meets a preset safe channel;
[0029] If not, terminate the installation of the above target extension.
[0030] Second aspect, embodiments of the present application provide an extended program management device, which includes:
[0031] A first acquisition module, configured to acquire permission configuration information from a management background when detecting the startup of a browser;
[0032] A second acquisition module, configured to acquire first permission information of the target extended program after detecting an installation instruction of the target extended program;
[0033] A first judgment module, configured to judge whether the first permission information matches the permission configuration information;
[0034] A first processing module, configured to terminate the installation of the target extended program if not.
[0035] In a possible implementation manner, the device further includes:
[0036] A first receiving module, configured to receive a permission configuration change instruction from the management background; the permission configuration change instruction carries permission configuration change information;
[0037] An update module, configured to update the permission configuration information based on the permission configuration change information.
[0038] In a possible implementation manner, the device further includes:
[0039] A third acquisition module, configured to acquire second permission information corresponding to the installed extended programs in the browser;
[0040] A second judgment module, configured to judge whether the second permission information matches the permission configuration information;
[0041] A second processing module, configured to disable the installed extended program if not.
[0042] In a possible implementation manner, the device further includes:
[0043] A third judgment module, configured to judge whether the developer mode of the browser is enabled when detecting the installation instruction of the target extended program and the target extended program belongs to a self-extracting extended program;
[0044] A third processing module, configured to terminate the installation of the target extended program if not.
[0045] In a possible implementation manner, the device further includes:
[0046] A fourth acquisition module, configured to acquire mode configuration information from the management background when detecting the startup of the browser;
[0047] A determination module, configured to determine the control permission of the above-mentioned developer mode based on the above-mentioned mode configuration information;
[0048] A fourth processing module, configured to prohibit the activation of the developer mode of the above-mentioned browser when the above-mentioned control permission is disabled.
[0049] In a possible implementation manner, the above-mentioned apparatus further includes:
[0050] A second receiving module, configured to receive a mode control instruction from the above-mentioned management background when the above-mentioned control permission is disabled; the above-mentioned mode control instruction carries the enabling control information of the above-mentioned developer mode;
[0051] A fifth processing module, configured to set the above-mentioned control permission to enabled based on the above-mentioned enabling control information, and set the above-mentioned control permission to disabled after detecting that the above-mentioned target extension program is installed or after a preset duration since the above-mentioned control permission is enabled.
[0052] In a possible implementation manner, the above-mentioned apparatus further includes:
[0053] A fifth obtaining module, configured to obtain the data source information of the above-mentioned target extension program after detecting the installation instruction of the above-mentioned target extension program;
[0054] A fourth judging module, configured to judge whether the above-mentioned data source information meets a preset security channel;
[0055] A sixth processing module, configured to terminate the installation of the above-mentioned target extension program if it does not meet the requirement.
[0056] In one or more embodiments of the present application, when detecting the startup of a browser, obtain permission configuration information from a management background; after detecting the installation instruction of a target extension program, obtain the first permission information of the above-mentioned target extension program; judge whether the above-mentioned first permission information matches the above-mentioned permission configuration information; if not, terminate the installation of the above-mentioned target extension program. The present application obtains permission configuration information from a management background and compares it with the permission information of the extension program to be installed, avoiding the installation of extension programs that do not meet the preset security standards, preventing unauthorized extension programs from accessing sensitive data or performing potentially dangerous operations, thereby reducing security risks. In addition, since the installation of all extension programs depends on the permission configuration of the management background, it provides the ability to centrally manage and control the installation of browser extension programs, which helps to maintain the data security management of enterprises or organizations. Description of the Drawings
[0057] To more clearly illustrate the technical solutions in the embodiments of the present application, the accompanying drawings required for the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.
[0058] Figure 1 A schematic structural diagram of an extended program management system provided by an exemplary embodiment of the present application;
[0059] Figure 2 A schematic flowchart of an extended program management method provided by an exemplary embodiment of the present application;
[0060] Figure 3 A schematic flowchart of an extended program management method provided by an exemplary embodiment of the present application;
[0061] Figure 4 A schematic flowchart of an extended program management method provided by an exemplary embodiment of the present application;
[0062] Figure 5 A schematic flowchart of an extended program management method provided by an exemplary embodiment of the present application;
[0063] Figure 6 A schematic structural diagram of an extended program management device provided by an exemplary embodiment of the present application;
[0064] Figure 7 A schematic structural diagram of an electronic device provided by an exemplary embodiment of the present application. Detailed implementation manners
[0065] When the following description involves the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with the present application. On the contrary, they are only examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.
[0066] In the description of this application, it should be understood that terms such as "first" and "second" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance. For those of ordinary skill in the art, the specific meanings of the above terms in this application can be understood according to specific circumstances. In addition, in the description of this application, unless otherwise specified, "a plurality of" means two or more. "And / or" describes the association relationship of associated objects and indicates that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after.
[0067] The following will describe this application in detail with specific embodiments.
[0068] Please refer to Figure 1 , Figure 1 which is a schematic diagram of the architecture of an extended program management system provided for an exemplary embodiment of this application. As Figure 1 shown, the extended program management system may include a user side 110 and a management side 120.
[0069] The user side 110 may be a laptop computer, a desktop computer, a smart phone, a tablet computer, or other terminal devices capable of running a browser. The browser running on the user side 110 can install and use various extended programs. The user side 110 is connected to the management side 120 through a network 130 and can be managed and controlled by the management side 120, including but not limited to installation, update, and permission management of extended programs. The network 130 may be a wireless network or a wired network.
[0070] The management side 120 may be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery network (CDN), and big data and artificial intelligence platforms. The management side 120 may also be another terminal device acting as a management role. The management side 120 may be responsible for overall policy formulation, permission configuration, and security monitoring, etc. For example, it can control which extensions can be installed and run on the user side 110 and the specific permission settings of these extensions.
[0071] Those skilled in the art will be aware that the number of the above-mentioned client 110 and management terminal 120 can be more or less. For example, both the above-mentioned client 110 and management terminal 120 are only one, or both the above-mentioned client 110 and management terminal 120 are dozens or hundreds, or a larger number. At this time, the above system architecture further includes other clients 110 and management terminals. The embodiments of the present application do not limit the number and device types of the client 110 and management terminal 120.
[0072] The extension program management method involved in one or more embodiments of the present application can be implemented depending on a computer program and can run on an extension program management device based on the von Neumann architecture. This computer program can be integrated in an application or run as an independent tool-type application. The execution subject corresponding to this extension program management method can be the above-mentioned client 110, and the management terminal 120 can be used as a management background to uniformly configure and issue configuration information or instructions.
[0073] The following will specifically describe the extension program management method provided by the present application with reference to specific embodiments.
[0074] Please refer to Figure 2 , which is a schematic flowchart of an extension program management method provided by an exemplary embodiment of the present application. As Figure 2 shown, this extension program management method includes the following steps:
[0075] S201, when detecting the startup of the browser, obtain permission configuration information from the management background.
[0076] Specifically, the management background can be a centralized management system and can be a server-side application for setting and storing browser extension management policies, including the permission configuration of extension programs. An administrator can formulate and update the management policies of browser extensions through the interface or platform provided by the management background to uniformly manage the client browsers within an enterprise or organization.
[0077] In this embodiment, the permission configuration information refers to the specific rules and policies regarding the permissions required for extensions set in the management background. Among them, the permissions required for extensions refer to the browser function access permissions required for extension programs to execute their functions. For example, accessing browsing history, modifying user data, etc.; these permissions determine what operations the extension can perform and what data it can access. Exemplarily, the permission configuration information can include an extension permission list, in which the permissions allowed for the extension and the permissions prohibited for the extension are included. An administrator can log in to the management background and set the permission configuration through the interface, such as specifying which permissions are allowed and which are prohibited. For example, an administrator can configure a policy in the management background to prohibit all extensions from accessing the download history of the browser.
[0078] When the browser of the client device is detected to start, the client device can request permission configuration information from the management background through the network, that is, obtain the latest permission configuration information each time the browser starts, ensure that all policy changes take effect in a timely manner, and improve the security of the overall system. The client device can receive the permission configuration information by means of push notifications, API (Application Programming Interface) calls, scheduled polling, etc. The permission configuration information can be transmitted in various data formats (such as JSON, XML) to ensure that the client device can correctly parse and apply the updates.
[0079] S202, after detecting the installation instruction of the target extension program, obtain the first permission information of the target extension program.
[0080] Specifically, the target extension program refers to a new extension program that the user attempts to add in the browser. The system can recognize the action or request of the target extension program to attempt installation, that is, the installation instruction. For example, when the user clicks the "Add" button in the browser extension store, or attempts to load a local extension, these can all be regarded as installation instructions.
[0081] After the installation instruction is detected, the client device will read the first permission information requested by the target extension program. The first permission information can be the browser function access permissions required by the extension program to execute its functions. For example, the permission list declared in its manifest file (such as manifest.json), these permissions are necessary for the extension program to work properly, and these permission information can include accessing web page data, modifying browser settings, accessing browsing history, etc.
[0082] By obtaining and analyzing the permission information of the target extension program, it is convenient to conduct a security review to ensure that the extension program does not request permissions beyond the scope required by its functions, thereby reducing security risks, and also enabling the system to determine whether the extension meets the installation standards according to the preset security policies or permission configuration rules.
[0083] S203, determine whether the first permission information matches the permission configuration information.
[0084] Specifically, if the permissions requested by the target extension match the permission configuration information set by the management background, that is, all the permissions requested by the target extension are allowed, then it is judged as a match, and step S204 is executed.
[0085] If the target extension requests some permissions that are not allowed, or its permission request exceeds the scope of the permission configuration information, then it is judged as a mismatch, and step S205 is executed.
[0086] S204, execute the installation of the target extension program.
[0087] Specifically, if the first permission information matches the target extension request of the permission configuration information, it indicates that the extension program is secure and complies with the preset security policies and standards. Then the system allows the installation of the target extension program to continue, ensuring that all installed extension programs meet the security standards and policies of the enterprise or organization.
[0088] S205, terminate the installation of the target extension program.
[0089] Specifically, if the first permission information does not match the target extension request of the permission configuration information, it indicates that the extension program violates the set policies or has security risks. The system will block the installation of this extension program, which can effectively prevent potential security threats.
[0090] In the embodiments of the present application, when it is detected that the browser is started, the permission configuration information is obtained from the management background; after detecting the installation instruction of the target extension program, the first permission information of the above target extension program is obtained; it is determined whether the first permission information matches the permission configuration information; if not, the installation of the above target extension program is terminated. The present application obtains the permission configuration information from the management background and compares it with the permission information of the extension program to be installed, avoiding the installation of extension programs that do not meet the preset security standards, preventing unauthorized extension programs from accessing sensitive data or performing potentially dangerous operations, thereby reducing security risks. In addition, since the installation of all extension programs depends on the permission configuration of the management background, it provides the ability to centrally manage and control the installation of browser extension programs, which helps to maintain the data security management of the enterprise or organization.
[0091] In some embodiments, the above method further includes: obtaining the second permission information corresponding to the installed extension program in the browser; determining whether the second permission information matches the permission configuration information; if not, disabling the installed extension program.
[0092] Specifically, in addition to monitoring and managing the permissions of newly installed extension programs, it is also necessary to monitor and manage the permissions of the installed extension programs in the browser to ensure that all extension programs always comply with the latest security standards and policies.
[0093] The user device can read the permission settings of each installed extension program, that is, the second permission information. The second permission information refers to the permissions owned by the installed extension program, and these permission information can include the access permissions to browser functions, the permissions to modify data, etc.
[0094] The client device compares the permission information of each installed extension program with the permission configuration information set by the management background respectively. If the permissions of the installed extension program match the permission configuration information set by the management background (i.e., all requested permissions are allowed), it indicates that the extension program complies with the preset security policies and standards and can be enabled normally. If the permissions of the installed extension program do not match the permission configuration information set by the management background, it means that the extension program has requested some unallowed permissions and does not comply with the preset security policies and standards. Measures will be taken to disable the extension program to prevent potential security risks caused by the extension program.
[0095] The disabling operation of the installed extension program means that although the disabled extension program is still installed on the browser, it will no longer be active or execute its functions until the permission settings of the disabled extension program are modified to comply with the security policy.
[0096] It should be noted that the client device can compare the permission information of each installed extension program with the permission configuration information set by the management background when the browser starts or when the permission configuration information set by the management background is updated, to ensure that all extension programs always comply with the latest security standards and policies.
[0097] Through the above method, the permissions of the installed extension programs can be continuously monitored and dynamically adjusted, enhancing security. It can ensure that even after the extension programs are installed, their permissions still comply with the preset security standards, preventing the operation of those extension programs that may have been installed but are later considered insecure or non-compliant, thus reducing potential security risks.
[0098] In some embodiments, the above method further includes: receiving a permission configuration change instruction from the management background; the permission configuration change instruction carries permission configuration change information; updating the permission configuration information based on the permission configuration change information.
[0099] Specifically, when the administrator makes a configuration change (such as updating the extension permission list) in the management background and selects to apply the change, the management background can generate a permission configuration change instruction and send it to the connected client device through the network. Among them, the permission configuration change instruction carries permission configuration change information, and the permission configuration change information can be the updated permission configuration information, such as the updated extension permission list, detailed permission settings, or incremental permission settings and other information, which can indicate which permissions are changed, added, or removed. The client device will update its locally obtained permission configuration information according to the received permission configuration change information to ensure that the permission configuration information obtained by the client device is always consistent with the management background and reflects the latest security policies and rules.
[0100] Through the above method, the management background can dynamically and real-time update the permission configuration without waiting for the user to restart the browser every time. When the security policy needs to be adjusted quickly (such as in response to newly discovered security threats), this method can ensure that all user terminals quickly respond to these changes and help maintain the policy consistency in the entire network environment, ensuring the network security of enterprises or organizations.
[0101] Exemplarily, as Figure 3 shown, a method for managing extensions provided by the present application is further described in combination with a specific implementation scenario.
[0102] The administrator configures the permission configuration information of the extension in the management terminal (management background), selects the permissions that the extension is allowed to use and the permissions that are not allowed to be used, and generates an extended permission list.
[0103] When the user enables the browser, the user terminal device obtains the permission configuration information including the extended permission list from the management terminal. If the administrator does not configure the permission configuration information in the management terminal, the default permission configuration is executed, for example, allowing all extensions to be installed and used, or prohibiting all extensions from being installed and used.
[0104] After the user terminal device obtains the permission configuration information, it parses the permission configuration information to determine the permissions that are allowed to be used and the permissions that are not allowed to be used in the extended permission list.
[0105] After the user enables the browser, the user terminal device also detects the installed extensions, obtains the required permissions of the installed extensions; determines whether the required permissions of the installed extensions all belong to the permissions allowed to be used in the extended permission list; if the required permissions of the installed extensions are all permissions allowed to be used, the extension is normally started; if there are permissions that are not allowed to be used in the installed extensions, starting the extension is prohibited. At the same time, the user can see the list of enabled and disabled extensions on the extension management page.
[0106] When the user terminal device installs an extension program, it obtains the required permissions of the extension program to be installed; determines whether the required permissions of the extension program to be installed all belong to the permissions allowed to be used in the extended permission list; if the required permissions of the extension program to be installed are all permissions allowed to be used, the extension program is normally installed; if there are permissions that are not allowed to be used in the extension program to be installed, installing the extension program is prohibited.
[0107] Please refer to Figure 4 , which is a schematic flowchart provided by an exemplary embodiment of the present application. As Figure 4 shown, the method for managing extensions includes the following steps:
[0108] S401. After detecting the installation instruction of the target extension program, determine whether the target extension program belongs to a self-extracting extension program.
[0109] Specifically, after identifying the action of the user attempting to install an extension program, it is necessary to first determine whether the extension program belongs to a self-extracting extension program. Self-extracting extension programs usually refer to those extensions that are not installed through the official browser app store, but are directly downloaded from the Internet or locally made compressed files, and users need to manually load these files in the browser to install the extensions.
[0110] The client device can determine the type of the extension program being installed through the installation instruction. For example, if the installation instruction is the user clicking the install button in the browser app store, it means that the official extension program (non-self-extracting extension) is being installed; if the installation instruction is the user's action of attempting to load an extension file in the browser, it means that the self-extracting extension program is being installed. In addition, the client device can also determine the type of the extension program being installed by checking the source of the extension (such as whether it comes from the official app store) and the format (such as whether it is a compressed file).
[0111] Since self-extracting extension programs have not been reviewed by the official store, there may be security risks. In order to prevent potentially unsafe extensions from being installed on the user's browser, stricter control is required for the installation of self-extracting extension programs.
[0112] If the target extension program belongs to a self-extracting extension program, execute step S402; if the target extension program does not belong to a self-extracting extension program, directly execute step S403.
[0113] S402. Determine whether the developer mode of the browser is enabled.
[0114] Specifically, the developer mode is a special mode of the browser that can be used for developing and testing extension programs. In the developer mode, users can install extensions that are not published in the official app store, that is, self-extracting extensions.
[0115] When the client device detects the installation instruction of a self-extracting extension program, it will check whether the browser is currently in the developer mode. If the browser is in the developer mode, the user has the permission and ability to install extensions from non-official stores, and the system allows the installation of the self-extracting extension program, and execute step S404. If the browser is not in the developer mode, it means that the client has not enabled the developer mode or does not have the permission to install self-extracting extensions, and the system will block the installation of the self-extracting extension and execute step S405.
[0116] S403. Execute the installation of the target extension program.
[0117] Specifically, if the developer mode of the browser is enabled, it indicates that the user has the permission and ability to install the self-extracting extension program, and the installation of the self-extracting extension program can be executed. At the same time, the steps for installing the self-extracting extension program can refer to steps S201 - S205 in this application, which will not be elaborated here. By further determining whether the permissions required by the self-extracting extension program match the permission configuration information of the management background, it can be ensured that the secure self-extracting extension program meets the preset security standards, preventing unauthorized self-extracting extensions from accessing sensitive data or performing potentially dangerous operations.
[0118] S404, terminate the installation of the target extension program.
[0119] Specifically, if the developer mode of the browser is closed, it indicates that the developer mode has not been enabled on the user side or the user does not have the permission to install the self-extracting extension, and the system will block the installation of the self-extracting extension. If the user side has the permission to install the self-extracting extension, then it has the permission to control the developer mode switch, and can try to install again after enabling the developer mode to execute step S403.
[0120] If the user side does not have the permission to install the self-extracting extension, then it does not have the permission to enable the developer mode and cannot enable the developer mode, thus unable to continue the installation of the self-extracting program. Since the self-extracting extension program has not undergone a security review, it may be a dangerous extension program with malicious code. Controlling the permission of the user side to install the self-extracting extension program can reduce the security risk and protect the network data security of enterprises or organizations.
[0121] In some embodiments, the above method further includes: when detecting the startup of the browser, obtaining mode configuration information from the management background; determining the control permission of the developer mode based on the mode configuration information; and prohibiting the enabling of the developer mode of the browser when the control permission is disabled.
[0122] Specifically, the administrator will configure the control permission of the user side device regarding the developer mode in the management background (management end), generate mode configuration information, and send it to the user side device. When the browser starts up, the user side device will obtain this mode configuration information from the management background and determine the control permission of the developer mode according to this mode configuration information. When the control permission is disabled, the user side does not have the permission to enable the developer mode of the browser, and the user side is prohibited from enabling the developer mode of the browser. When the control permission is enabled, the user side has the permission to enable the developer mode of the browser, and the user side is allowed to freely enable or disable the developer mode of the browser.
[0123] The control permissions of the developer mode can be adaptively controlled according to the security standards of enterprises or organizations, the identity roles of the client devices, or other conditions, that is, different client devices can have different control permissions for the developer mode. By controlling the permissions of the developer model, it is possible to prevent users (especially non-technical users) from inadvertently installing self-extracting extension programs that may pose security risks. By centrally managing the control of the browser's developer mode, the security and stability of the overall network environment can be improved while ensuring flexibility.
[0124] In some embodiments, the above method further includes: when the control permission is disabled, receiving a mode control instruction from the management background; the mode control instruction carries the enabling control information of the developer mode; based on the enabling control information, setting the control permission to enabled, and after detecting that the target extension program is installed or after a preset duration from when the control permission is enabled, setting the control permission to disabled.
[0125] Specifically, when the control permission is set to disable the developer mode, if the client device has a need to temporarily install a self-extracting extension program, it can receive a mode control instruction from the management background to temporarily change the control permission of the developer mode, so that the client device can install the self-extracting extension program.
[0126] Exemplarily, when the client device needs to install a specific extension or conduct development and testing, it needs to temporarily use the developer mode. At this time, it can apply to the management background for temporary developer mode permissions. After the management background approves, it issues a mode control instruction to the client device. This mode control instruction is used to temporarily change the control permission of the developer mode. The client device can, according to this mode control instruction, change the control permission of the developer mode from disabled to enabled to freely enable the developer mode, and then can perform the installation action of the self-extracting extension program in the developer mode. In some cases, such as when only installing a specific extension on the client device, the client device can, according to the control conditions of the mode control instruction, after detecting that the user has completed the installation of the self-extracting extension program, restore the control permission of the developer mode of the client device from enabled to disabled to disable the developer mode of the client device. In other cases, such as during development and testing, the client device can, according to the control conditions of the mode control instruction, control the enabling time of the developer mode permission based on time, that is, after the control permission of the developer mode is set to enabled and reaches a preset duration (such as one day), then restore the control permission of the developer mode of the client device from enabled to disabled to disable the developer mode of the client device. Among them, what control conditions the mode control instruction adopts and the specific value of the preset duration can be freely set by the management background according to the specific implementation situation and are not limited here.
[0127] Through the above method, it is possible to temporarily enable the developer mode permission under specific circumstances to temporarily allow users to install self-extracting extension programs, which can meet some specific user needs without sacrificing the overall security policy. And after meeting certain control conditions, the control permission is automatically reset to disabled to ensure that the developer mode will not remain open for a long time, thereby reducing security risks and the continuous monitoring burden on administrators, and improving management efficiency. In this way, the management of the browser's developer mode is both flexible and secure, adapting to changing usage scenarios while maintaining the overall security and stability of the network environment.
[0128] In some embodiments, the above method further includes: after detecting an installation instruction for a target extension program, obtaining the data source information of the target extension program; determining whether the data source information meets a preset secure channel; if not, terminating the installation of the above target extension program.
[0129] Specifically, in some cases, even when the browser developer mode is disabled, it is still possible to install extension programs from third-party stores. These extension programs may disguise themselves as normal extension programs, but actually come from untrusted or un-reviewed sources. Even if the installation process seems normal, there are still security risks.
[0130] When detecting that an extension program is attempting to install, the data source information of the extension program can be obtained. The data source information generally refers to the download source of the extension program, such as whether it is downloaded from the official browser application store or from other third-party websites or sources. The data source can be determined by analyzing the metadata of the extension installation package or checking the URL during the installation process.
[0131] Then determine whether the data source information meets the preset secure channel. Only when the data source information meets the preset secure channel, execute the installation process of the target extension program; in the case where the data source information does not meet the preset secure channel, terminate the installation of the above target extension program.
[0132] The preset secure channel refers to a pre-defined source of extension programs that is considered to be secure and reliable. This generally includes the official browser application store and known, trusted third-party developer websites.
[0133] Through the above method, by verifying the data source of the extension, it is possible to ensure that all installed extensions come from trusted and reviewed channels, effectively preventing the installation of malicious extensions and protecting the security of the user's device and data.
[0134] Exemplarily, as Figure 5 shown, a method for managing extension programs provided by the present application is further described in combination with a specific implementation scenario.
[0135] The administrator configures the mode configuration information of the extension program in the management terminal (management background), selects which user terminals are allowed to use the developer mode, and selects which user terminals are not allowed to use the developer mode. This can be set batchwise by setting the identity roles of the user terminals, etc., to generate the mode configuration information.
[0136] When the user enables the browser, the user terminal device obtains the corresponding mode configuration information from the management terminal. If the administrator does not configure the mode configuration information in the management terminal, the default mode configuration is executed. For example, the developer mode is allowed to be enabled by default, or the developer mode is prohibited from being enabled by default.
[0137] After the user terminal device obtains the mode configuration information, it parses the mode configuration information and determines whether it has the permission to enable the developer mode according to the mode configuration information. When the user terminal device has the permission to enable the developer mode and when enabling the developer mode, the user is allowed to install the self-extracting extension program. When the user terminal device disables the permission of the developer mode, the developer mode is always in the closed state, and the user is not allowed to install the self-extracting extension program.
[0138] Next, please refer to Figure 6 , Figure 6 which is an extension program management device provided for an exemplary embodiment of this application. As Figure 6 shown, the extension program management device 600 includes:
[0139] A first acquisition module 610, configured to obtain permission configuration information from the management background when detecting the startup of the browser;
[0140] A second acquisition module 620, configured to obtain the first permission information of the target extension program after detecting the installation instruction of the target extension program;
[0141] A first judgment module 630, configured to judge whether the first permission information matches the permission configuration information;
[0142] A first processing module 640, configured to terminate the installation of the target extension program if not.
[0143] In some possible embodiments, the device 600 further includes:
[0144] A first receiving module, configured to receive the permission configuration change instruction of the management background; the permission configuration change instruction carries permission configuration change information;
[0145] An update module, configured to update the permission configuration information based on the permission configuration change information.
[0146] In some possible embodiments, the device 600 further includes:
[0147] A third acquisition module, configured to acquire second permission information corresponding to the installed extension programs in the browser;
[0148] A second judgment module, configured to judge whether the second permission information matches the permission configuration information;
[0149] A second processing module, configured to, if not, disable the installed extension programs.
[0150] In some possible embodiments, the apparatus 600 further includes:
[0151] A third judgment module, configured to, after detecting an installation instruction of the target extension program, judge whether the developer mode of the browser is enabled when the target extension program is a self-extracting extension program;
[0152] A third processing module, configured to, if not enabled, terminate the installation of the target extension program.
[0153] In some possible embodiments, the apparatus 600 further includes:
[0154] A fourth acquisition module, configured to acquire mode configuration information from the management background when detecting the startup of the browser;
[0155] A determination module, configured to determine the control permission of the developer mode based on the mode configuration information;
[0156] A fourth processing module, configured to, when the control permission is disabled, prohibit the opening of the developer mode of the browser.
[0157] In some possible embodiments, the apparatus 600 further includes:
[0158] A second receiving module, configured to, when the control permission is disabled, receive a mode control instruction from the management background; the mode control instruction carries enabling control information of the developer mode;
[0159] A fifth processing module, configured to set the control permission to enabled based on the enabling control information, and set the control permission to disabled after detecting the completion of the installation of the target extension program or after a preset duration since the control permission is enabled.
[0160] In some possible embodiments, the apparatus 600 further includes:
[0161] A fifth acquisition module, configured to acquire data source information of the target extension program after detecting an installation instruction of the target extension program;
[0162] A fourth judgment module, configured to judge whether the data source information meets a preset secure channel;
[0163] The sixth processing module is configured to terminate the installation of the above-mentioned target extension program if the condition is not met.
[0164] The division of each module in the above extension program management device is only for illustrative purposes. In other embodiments, the extension program management device may be divided into different modules as needed to complete all or part of the functions of the above extension program management device. In the embodiments of the present application, the implementation of each module in the provided extension program management device may be in the form of a computer program. This computer program can run on a terminal or a server. The program module constituted by this computer program can be stored in the memory of the terminal or the server. When this computer program is executed by a processor, all or part of the steps of the extension program management method described in the embodiments of the present application are implemented.
[0165] Please refer to Figure 7 , Figure 7 which is a schematic structural diagram of an electronic device provided by an exemplary embodiment of the present application. As Figure 7 shown, the electronic device 700 may include: at least one processor 710, at least one communication bus 720, a user interface 730, at least one network interface 740, and a memory 750. Among them, the communication bus 720 can be used to realize the connection and communication of the above-mentioned various components.
[0166] Among them, the user interface 730 may include a display screen (Display) and a camera (Camera). Optionally, the user interface may further include a standard wired interface and a wireless interface.
[0167] Among them, the network interface 740 may optionally include a Bluetooth module, a Near Field Communication (NFC) module, a Wireless Fidelity (Wi-Fi) module, etc.
[0168] Among them, the processor 710 may include one or more processing cores. The processor 710 connects various parts within the entire electronic device 700 through various interfaces and lines, and executes various functions of the routing electronic device 700 and processes data by running or executing instructions, programs, code sets, or instruction sets stored in the memory 750, and by calling data stored in the memory 750. Optionally, the processor 710 may be implemented in at least one hardware form of digital signal processing (DSP), field-programmable gate array (FPGA), or programmable logic array (PLA). The processor 710 may integrate a combination of one or several of a central processing unit (CPU), a graphics processing unit (GPU), and a modem, etc. Among them, the CPU mainly processes the operating system, user interface, application programs, etc.; the GPU is responsible for rendering and drawing the content to be displayed on the display screen; the modem is used to process wireless communication. It can be understood that the above-mentioned modem may not be integrated into the processor 710 and may be implemented separately by a single chip.
[0169] Among them, the memory 750 may include random access memory (RAM) and may also include read-only memory (ROM). Optionally, the memory 750 includes a non-transitory computer-readable medium. The memory 750 can be used to store instructions, programs, code, code sets, or instruction sets. The memory 750 may include a program storage area and a data storage area. Among them, the program storage area may store instructions for implementing the operating system, instructions for at least one function (such as acquisition function, optimization function, etc.), instructions for implementing the above-mentioned various method embodiments, etc.; the data storage area may store the data involved in the above-mentioned various method embodiments. The memory 750 may optionally also be at least one storage device located far from the aforementioned processor 710. As Figure 7 shown, the memory 750, as a computer storage medium, may include an operating system, a network communication module, a user interface module, and program instructions.
[0170] Specifically, the processor 710 may be used to call the program instructions stored in the memory 750 and specifically perform the following operations:
[0171] When detecting the startup of the browser, obtain permission configuration information from the management background;
[0172] After detecting the installation instruction of the target extension program, obtain the first permission information of the above-mentioned target extension program;
[0173] Determine whether the above-mentioned first permission information matches the above-mentioned permission configuration information;
[0174] If not, terminate the installation of the above-mentioned target extension program.
[0175] In some possible embodiments, the above-mentioned processor 710 further specifically executes:
[0176] Receive the permission configuration change instruction from the above-mentioned management background; the above-mentioned permission configuration change instruction carries permission configuration change information;
[0177] Update the above-mentioned permission configuration information based on the above-mentioned permission configuration change information.
[0178] In some possible embodiments, the above-mentioned processor 710 further specifically executes:
[0179] Obtain the second permission information corresponding to the installed extension programs in the above-mentioned browser;
[0180] Determine whether the above-mentioned second permission information matches the above-mentioned permission configuration information;
[0181] If not, disable the above-mentioned installed extension program.
[0182] In some possible embodiments, the above-mentioned processor 710 further specifically executes:
[0183] After detecting the installation instruction of the above-mentioned target extension program, in the case where the above-mentioned target extension program is a self-extracting extension program, determine whether the developer mode of the above-mentioned browser is enabled;
[0184] If not, terminate the installation of the above-mentioned target extension program.
[0185] In some possible embodiments, the above-mentioned processor 710 further specifically executes:
[0186] When detecting the startup of the above-mentioned browser, obtain the mode configuration information from the above-mentioned management background;
[0187] Determine the control permission of the above-mentioned developer mode based on the above-mentioned mode configuration information;
[0188] In the case where the above-mentioned control permission is disabled, prohibit the opening of the developer mode of the above-mentioned browser.
[0189] In some possible embodiments, the above-mentioned processor 710 further specifically executes:
[0190] When the above control permission is disabled, receive the mode control instruction from the above management background; the above mode control instruction carries the enabling control information of the above developer mode;
[0191] Based on the above enabling control information, set the above control permission to enabled, and after detecting that the above target extension program is installed or after a preset duration since the above control permission is enabled, set the above control permission to disabled.
[0192] In some possible embodiments, the above processor 710 further specifically executes:
[0193] After detecting the installation instruction of the above target extension program, obtain the data source information of the above target extension program;
[0194] Determine whether the above data source information meets the preset secure channel;
[0195] If not, terminate the installation of the above target extension program.
[0196] The embodiment of the present application also provides a computer-readable storage medium, in which instructions are stored. When they run on a computer or a processor, the computer or the processor is caused to execute one or more steps in the above embodiments. If each component module of the above extension program management device is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in the above computer-readable storage medium.
[0197] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The above computer program product includes one or more computer instructions. When the above computer program instructions are loaded and executed on a computer, the processes or functions described above in the embodiments of the present application are generated in whole or in part. The above computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The above computer instructions can be stored in a computer-readable storage medium or transmitted through the above computer-readable storage medium. The above computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, Digital Subscriber Line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The above computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more integrated available media. The above available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a Digital Versatile Disc (DVD)), or a semiconductor medium (for example, a Solid State Disk (SSD)), etc.
[0198] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. This program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above various methods. The foregoing storage medium includes: various media such as ROM, RAM, magnetic disk, or optical disc that can store program codes. Without conflict, the technical features in this embodiment and the implementation solutions can be combined arbitrarily.
[0199] The above-described embodiments are merely described as preferred implementation manners of the present application, and do not limit the scope of the present application. Without departing from the design spirit of the present application, various deformations and improvements made by those of ordinary skill in the art to the technical solutions of the present application shall fall within the protection scope determined by the claims.
[0200] The above description has been made of specific embodiments of the present application. Other embodiments are within the scope of the appended claims. In some cases, the acts or steps recited in the claims and the specification may be performed in an order different from that in the embodiments described in the specification and still achieve the desired results. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
Claims
1. An extended program management method, characterized in that The method includes: When detecting the startup of the browser, obtaining permission configuration information from the management background; After detecting the installation instruction of the target extension program, obtaining the first permission information of the target extension program; Determining whether the first permission information matches the permission configuration information; If not, terminating the installation of the target extension program.
2. The method according to claim 1, characterized in that The method further includes: Receiving a permission configuration change instruction from the management background; the permission configuration change instruction carries permission configuration change information; Updating the permission configuration information based on the permission configuration change information.
3. The method according to claim 2, characterized in that The method further includes: Obtaining the second permission information corresponding to the installed extension programs in the browser; Determining whether the second permission information matches the permission configuration information; If not, disabling the installed extension programs.
4. The method according to claim 1, characterized in that The method further includes: After detecting the installation instruction of the target extension program, when the target extension program is a self-extracting extension program, determining whether the developer mode of the browser is enabled; If not, terminating the installation of the target extension program.
5. The method according to claim 4, characterized in that The method further includes: When detecting the startup of the browser, obtaining mode configuration information from the management background; Determining the control permission of the developer mode based on the mode configuration information; When the control permission is disabled, prohibiting the enabling of the developer mode of the browser.
6. The method according to claim 5, characterized in that The method further includes: When the control permission is disabled, receiving a mode control instruction from the management background; the mode control instruction carries the enabling control information of the developer mode; Based on the enabling control information, setting the control permission to enabled, and after detecting the completion of the installation of the target extension program or after the control permission is enabled for a preset duration, setting the control permission to disabled.
7. The method according to claim 1, characterized in that The method further includes: After detecting the installation instruction of the target extension program, obtaining the data source information of the target extension program; Determining whether the data source information meets a preset secure channel; If not, terminating the installation of the target extension program.
8. An extended program management device, characterized in that Configured in the browser, the device includes: A first obtaining module, configured to obtain permission configuration information from the management background when detecting the startup of the browser; A second obtaining module, configured to obtain the first permission information of the target extension program after detecting the installation instruction of the target extension program; A first judging module, configured to determine whether the first permission information matches the permission configuration information; A first processing module, configured to, if not, terminate the installation of the target extension program.
9. A computer storage medium, characterized in that The computer storage medium stores multiple instructions, and the instructions are adapted to be loaded and executed by a processor to perform the method steps of any one of claims 1-7.
10. An electronic device, characterized in that, Including: A processor and a memory; The processor is connected to the memory; The memory is configured to store executable program code; The processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, so as to perform the method steps of any one of claims 1-7.