Method for judging compliance of privacy operation of application program, electronic equipment and storage medium

By obtaining and analyzing the privacy operation content of the application and determining whether it has excessively collected precise location information, it solves the problem of inaccurate judgment on the compliance of the application privacy operation and improves the accuracy of the judgment.

CN120180427APending Publication Date: 2025-06-20ZTE CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311763244.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-19
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

In the prior art, applications may over-collect or use the user's precise location information without the user's authorization, resulting in inaccurate judgment on compliance with privacy operations.

Method used

By obtaining the operation content of the target application on the privacy information, it is judged that when the precise location information is collected and does not belong to the positioning application, it is determined that the operation of the user's privacy information by the application is excessively collected.

Benefits of technology

It effectively improves the accuracy of the application's privacy operation compliance judgment and avoids developers from over-collecting precise location information using relevant protocol files.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120180427A_ABST
    Figure CN120180427A_ABST
Patent Text Reader

Abstract

The invention discloses an application privacy operation compliance judgment method, electronic equipment and a storage medium, and belongs to the technical field of terminals. The method comprises the steps of obtaining operation content of a target application program on privacy information; and under the condition that the operation content comprises collection of accurate position information and the target application program does not belong to a positioning application program, judging that the operation of the target application program on the user privacy information is over-collection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the technical field of terminals, and in particular, to a method for determining compliance of application privacy operations, an electronic device, and a storage medium. Background Art

[0002] With the rapid development of mobile communication technology, mobile applications have penetrated into all fields of people's lives and work. From social networking to travel, from online shopping to food delivery, from office work to entertainment, the types and quantities of mobile applications have grown explosively. At the same time, users are also facing the risks of personal information being misused and leaked. In some technologies, it is possible to determine whether the privacy operations of an application are compliant based on the authorization operations of the user for the application. However, some applications may bypass the user authorization step and directly collect or use their personal data without the user's authorization, resulting in inaccurate judgment of the compliance of the application's privacy operations. Summary of the Invention

[0003] The embodiments of the present application provide a method for determining compliance of application privacy operations, an electronic device, and a storage medium, so as to at least solve the problem of inaccurate judgment of the compliance of application privacy operations.

[0004] To solve the above technical problems, the embodiments of the present application are implemented as follows:

[0005] In a first aspect, a method for determining compliance of application privacy operations is provided, including: obtaining the operation content of a target application for privacy information; and determining that the operation of the target application on the user's privacy information is excessive collection when the operation content includes collecting precise location information and the target application does not belong to a location-based application.

[0006] In a second aspect, an electronic device is provided. The electronic device includes a processor and a memory, and a program or instruction that can run on the processor is stored on the memory. When the program or instruction is executed by the processor, the method shown in the first aspect above is implemented.

[0007] In a third aspect, a storage medium is provided. A program or instruction is stored on the storage medium, and when the program or instruction is executed by a processor, the method shown in the first aspect above is implemented.

[0008] In a fourth aspect, a computer program product is provided. The computer program product includes at least one computer program, and the computer program is loaded and executed by a processor to implement the method shown in the first aspect above.

[0009] The technical solutions provided by the embodiments of the present application may include the following beneficial effects:

[0010] In an embodiment of the present application, by obtaining the operation content of a target application on privacy information, when the operation content includes collecting precise location information and the target application does not belong to a location-based application, it is determined that the operation of the target application on user privacy information is over-collection, which can effectively improve the accuracy of the compliance judgment of the privacy operation of the application, thereby preventing the developer of the target application from over-collecting precise location information by using relevant protocol files.

[0011] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and do not limit the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] The accompanying drawings herein are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present application and used together with the specification to explain the principles of the present application.

[0013] Figure 1 FIG. shows a schematic flowchart of a method for determining the compliance of the privacy operation of an application provided by an exemplary embodiment of the present application;

[0014] Figure 2 FIG. shows a schematic flowchart of a method for determining the compliance of the privacy operation of an application provided by an exemplary embodiment of the present application;

[0015] Figure 3 FIG. shows a schematic flowchart of a method for determining the compliance of the privacy operation of an application provided by an exemplary embodiment of the present application;

[0016] Figure 4 FIG. shows another schematic flowchart of a method for determining the compliance of the privacy operation of an application provided by an exemplary embodiment of the present application;

[0017] Figure 5 FIG. shows yet another schematic flowchart of a method for determining the compliance of the privacy operation of an application provided by an exemplary embodiment of the present application;

[0018] Figure 6 FIG. shows a schematic structural diagram of a device for determining the compliance of the privacy operation of an application provided by an exemplary embodiment of the present application;

[0019] Figure 7 is a block diagram of the structure of an electronic device shown according to an exemplary embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0020] Exemplary embodiments will be described in detail herein, and examples thereof are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.

[0021] Figure 1 FIG. 4 shows a schematic flowchart of a method for determining compliance of an application privacy operation provided by an exemplary embodiment of the present application. This method can be executed by an electronic device, and the electronic device may include: a terminal device. In other words, this method can be executed by software or hardware installed in the electronic device. The method includes the following steps:

[0022] S110: Obtain the operation content of the target application on the privacy information.

[0023] Wherein, the operation content refers to the permission declarations related to operations such as collection, use, storage, and sharing of privacy information.

[0024] In one implementation, the above S110 may include: obtaining the operation content from the privacy terms of the target application; and / or obtaining the operation content from the information description file of the target application. That is to say, the operation content can be obtained from the privacy terms and / or information description file of the target application. The privacy terms refer to a document or file published by the developer or operator of the target application to inform users how the target application collects, uses, stores, shares, and protects users' personal information, that is, the permission request terms. The permission request terms may include a location acquisition permission clause (such as whether to allow obtaining the approximate location information or precise location information of the terminal device), a personal information acquisition clause (such as whether to obtain the user's identity information), a personal information sharing clause (such as whether to share the user's identity information with a third-party application), etc. The information description file refers to a file that describes various attributes and components of the target application, including that the target application may need to access certain functions or resources of the terminal device, such as network access, reading contacts, etc. The target application can declare the required permissions in this information description file.

[0025] Optionally, the information description file may be AndroidManifest.xml.

[0026] Optionally, obtaining the operation content of the target application on the privacy information may be triggered manually by the user or triggered by a scheduled task.

[0027] In this implementation, since the privacy terms or user agreements of each application usually provide users with detailed terms on how to handle their personal information and the way of data usage, the operation content of privacy information can be directly obtained from the privacy terms of the target application. At the same time, the information description file is the configuration file of each application, which contains all the permission declarations required by the application. Therefore, the operation content of privacy information can be obtained from the information description file. In addition, if the privacy terms or user agreements of the target application are not detailed enough, the information description file can provide more specific permission request information, so that the operation content of the target application on privacy information can be obtained more accurately.

[0028] S120: In the case where the operation content includes collecting precise location information and the target application does not belong to a location-based application, it is determined that the operation of the target application on the user's privacy information is excessive collection.

[0029] It can be understood that precise location information is relative to rough location information. Rough location information refers to generating approximate location information using network positioning (such as wireless network, communication base station, Bluetooth, etc.); precise location information refers to, in addition to generating approximate location information using network positioning (location information of wireless network, communication base station, Bluetooth, etc.), precise location information generated by using satellite positioning, sensors and other information at the same time. For example, precise location information can accurately locate the location of a certain building, street or specific area, while rough location information cannot accurately locate a specific location or building, but rough location information can already meet the needs of users in most scenarios. Considering the protection of user privacy and security, it can be judged whether the target application needs to collect precise location information according to usage scenarios, applicable scopes, etc. For example, precise location information needs to be collected in usage scenarios such as navigation and maps, while rough location information can meet the needs in usage scenarios such as advertisement push and online social networking. That is to say, in the case where the operation content includes collecting precise location information and the target application does not belong to a location-based application, it can be determined that the operation of the target application on the user's privacy information is excessive collection. Then, the applications corresponding to usage scenarios such as navigation and maps can collect precise location information, and the applications corresponding to usage scenarios such as advertisement push and online social networking can collect rough location information. If the operation content of the applications corresponding to usage scenarios such as advertisement push and online social networking includes collecting precise location information, it can be determined that the operation of the applications in this usage scenario on the user's privacy information is excessive collection.

[0030] Determining whether the target application belongs to a positioning application may include: identifying whether the SDK is positioned according to the package name (package name) and / or application name (app name) of the target application. The package name of the Android application includes multi-level package names. The first-level package name is the prefix of the business organization. The prefix usually indicates the type of business organization, such as com for business organization, net for network organization, org for non-profit organization, etc.; the second-level package name is the domain name or name of the business organization, such as the company name; the third-level package name is the application name, and the fourth-level package name and the fifth-level package name can also be used according to the actual situation. The fourth-level package name is generally a module name or a level name. For example:

[0031] The package name of aa map is com.aa.map;

[0032] The package name of bb map is com.bb.minimap;

[0033] The package name of cc map is com.cc.CCMap;

[0034] The package name of dd map is com.dd.android.apps.maps;

[0035] The package name of mm NLP is com.mm.android.location;

[0036] The package name of nn NLP is com.nn.android.location;

[0037] The package name of ll NLP is com.ll.map.location;

[0038] The package name of zz NLP is com.zz.android.gms.

[0039] Then, we can determine whether the target application is a positioning SDK by reading the last level registration. If the last level registration contains map, location or gms, it is determined that the target application is a positioning SDK, that is, it belongs to the positioning type application.

[0040] In addition, if the application name of the target application contains characters such as map, location, gms, map, location, etc., it can be determined that the target application is a positioning SDK, that is, a positioning application.

[0041] In an embodiment of the present application, by obtaining the operation content of the target application on privacy information; when the operation content includes collecting precise location information and the target application does not belong to a location-based application, it is determined that the operation of the target application on user privacy information is excessive collection, which can effectively improve the accuracy of the compliance judgment of the privacy operation of the application, thereby preventing the developer of the target application from excessively collecting precise location information using relevant protocol documents.

[0042] In one implementation, after determining that the operation of the target application on user privacy information is excessive collection, the method further includes: prompting the target application for excessive collection of user privacy information. The prompting methods include but are not limited to: highlighting, bold display, full-screen display, ringing, vibration, pop-up notification, banner notification, etc.

[0043] Exemplarily, the above embodiments are illustrated below through two specific embodiments.

[0044] As Figure 2 shown, the steps included in Embodiment 1 are:

[0045] S201: Obtain the privacy policy text of the target application.

[0046] S202: Parse the privacy policy text of the target application and extract the content regarding location information collection.

[0047] S203: Query from the extracted content regarding location information collection whether precise location information is disclosed.

[0048] If not, then execute S204; if so, then execute S205.

[0049] S204: Query the AndroidManifest.xml of the target application to see if the precise location information permission is declared.

[0050] If so, then continue to execute step S205; if not, then execute step S207.

[0051] S205: Identify whether the target application is a location SDK.

[0052] If not, then continue to execute S206; if so, then execute S207.

[0053] S206: Remind the user that the target application excessively collects precise location information.

[0054] S207: End.

[0055] This Embodiment 1 determines whether to over-collect precise location information based on the permission declarations of the target application, AndroidManifest.xml, in combination with the identification of the location SDK.

[0056] As Figure 3 shown, the steps included in Embodiment 2 are as follows:

[0057] S301: Obtain the AndroidManifest.xml of the target application.

[0058] S302: Query the AndroidManifest.xml of the target application to check whether the precise location information permission is declared.

[0059] If yes, proceed to step S303; if no, execute step S305.

[0060] S303: Identify whether the target application has a location SDK.

[0061] If no, proceed to S304; if yes, execute S305.

[0062] S304: Remind the user that the target application over-collects precise location information.

[0063] S305: End.

[0064] This Embodiment 2 determines whether to over-collect precise location information based on the AndroidManifest.xml of the target application, in combination with the identification of the location SDK.

[0065] Figure 4 Another flowchart showing the determination method for the compliance of application privacy operations provided by an exemplary embodiment of the present application is as follows. The method includes the following steps:

[0066] S410: Obtain the operation content of the target application for privacy information;

[0067] S420: When the operation content includes collecting precise location information and the target application does not belong to a location-based application, determine that the operation of the target application on the user's privacy information is over-collection.

[0068] Among them, for the specific content of S410 and S420, reference can be made to Figure 1 the specific descriptions of S110 and S120 in the shown embodiment, which will not be elaborated here.

[0069] S430: When the operation content includes sharing personal sensitive information, obtain at least one third-party sharing application associated with the target application.

[0070] Among them, personal sensitive information refers to personal information that may endanger personal and property safety, and is extremely likely to cause damage to personal reputation, physical and mental health, or discriminatory treatment, etc. once leaked, illegally provided, or misused. Personal sensitive information includes, but is not limited to, identity document numbers, personal biometric information, bank account numbers, communication records and contents, property information, credit information, whereabouts tracks, accommodation information, health and physiological information, transaction information, etc.

[0071] To ensure the stable operation of the target application or to implement related functions, the target application may access third-party shared applications to achieve the foregoing purposes. That is to say, the third-party shared applications are not developed and managed by the developer of the target application, but are software development kits (SDKs) provided by the accessed third parties. For example, a certain shopping App, in order to facilitate users to use the xx payment application for payment, realizes this by accessing the xx payment application SDK. During the payment process, the user authorization will be obtained to associate the account of the xx payment application with the shopping App. After the user authorizes, the xx payment application SDK may obtain some basic information of the user, such as name, mobile phone number, the account number of the xx payment application, etc.

[0072] Optionally, after obtaining the first access times of each third-party shared application to personal sensitive information, each third-party shared application can be displayed in the list in descending order of the first access times. The user can click on any third-party shared application in the list to view the specific information, which includes the specific time and reason for each access to personal sensitive information.

[0073] S440: Determine whether the operation of the target application on the user privacy information is compliant based on the first access times of at least one of the third-party shared applications to personal sensitive information.

[0074] That is to say, if the first access times of at least one of the third-party shared applications to personal sensitive information exceed the set threshold, it indicates that the operation of the target application on the user privacy information is non-compliant.

[0075] In this embodiment, by obtaining the operation content of the target application on the privacy information; when the operation content includes collecting precise location information and the target application does not belong to a location-based application, it is determined that the operation of the target application on the user's privacy information is over-collection; when the operation content includes sharing personal sensitive information, at least one third-party sharing application associated with the target application is obtained; based on the first access times of at least one of the third-party sharing applications to the personal sensitive information, it is determined whether the operation of the target application on the user's privacy information is compliant, achieving the determination of whether the operation of the target application on the user's privacy information is compliant through various methods, effectively improving the accuracy of the compliance judgment of the privacy operation of the application, thereby preventing developers of the target application or developers of third-party sharing applications from over-collecting or sharing personal sensitive information using relevant protocol documents.

[0076] In one implementation, the above S440 may include: when a first predetermined condition is met, it is determined that the operation of the target application on the user's privacy information is over-sharing; where the first predetermined condition includes at least one of the following (1) to (3):

[0077] (1) The maximum access times is greater than a first threshold, where the maximum access times is the maximum value of at least one of the first access times.

[0078] It can be understood that if the maximum access times is greater than the first threshold, it indicates that the target application may abuse its permissions and consent for a third-party sharing application to access personal sensitive information.

[0079] (2) The ratio of the total access times to the second access times is greater than a second threshold, where the total access times is the sum of at least one of the first access times, and the second access times is the access times of the target application to the personal sensitive information.

[0080] It can be understood that each time a third-party sharing application accesses personal sensitive information, the target application will first access it and then share it with the third-party sharing application. Therefore, usually, the total access times is equal to the second access times. The second threshold can be 1. If the ratio is greater than the second threshold, it indicates that the total access times is greater than the second access times. Then, the third-party sharing application may use certain means to bypass the user's explicit consent to access personal sensitive information.

[0081] (3) The ratio of the maximum access times to the second access times is greater than a third threshold.

[0082] Among them, the types of the above-mentioned first threshold, second threshold, and third threshold include, but are not limited to: number of times, frequency, access time period, access timing (such as foreground, background), etc. Optionally, the threshold can be user-defined to meet the needs of different users.

[0083] Among them, in one implementation manner, after determining that the operation of the target application on user privacy information is oversharing, the method further includes: prompting to set the third-party sharing application permissions. It can be understood that after determining that a certain third-party application overaccesses personal sensitive information, the user can be prompted to set the third-party sharing application permissions. The user can turn off all permissions of the third-party sharing application with one key, or turn off some permissions of the third-party sharing application. The permissions include, but are not limited to: collecting personal sensitive information, sharing personal sensitive information, etc.

[0084] In another implementation manner, S440 mentioned above may include the following steps:

[0085] S442: When the personal sensitive information includes collecting precise location information, obtain the first shared application, where the first shared application is the third-party shared application with the first access number greater than 0.

[0086] S444: Traverse the first shared application.

[0087] S446: When the currently traversed first shared application does not belong to a location-based application, determine that the operation of the currently traversed first shared application on user privacy information is overcollection.

[0088] In this implementation manner, if the first shared application does not belong to a location-based application but collects precise location information, it means that the operation of the first shared application on user privacy information is overcollection, because usually, for example, personalized services, locating nearby merchants or activities only require rough precise location information to meet the user's needs.

[0089] Among them, after determining that the operation of the currently traversed first shared application on user privacy information is overcollection, the method further includes: prompting to set the permissions of the currently traversed first shared application. Refer to the specific description in the foregoing content and will not be elaborated here.

[0090] Figure 5 Another flowchart of the method for determining compliance of application privacy operations provided by an exemplary embodiment of the present application is shown. The method includes the following steps:

[0091] S510: Obtain the operation content of the target application on privacy information;

[0092] S520: When the operation content includes collecting precise location information and the target application does not belong to the location-based application category, it is determined that the operation of the target application on the user's privacy information is excessive collection.

[0093] Among them, for the specific content of S510 and S520, reference can be made to Figure 1 the specific descriptions of S110 and S120 in the illustrated embodiments, which will not be elaborated here.

[0094] S530: When the operation content includes sharing personal sensitive information, obtain at least one third-party sharing application associated with the target application.

[0095] For the specific content of S530, reference can be made to Figure 4 the specific description of S430 in the illustrated embodiments, which will not be elaborated here.

[0096] S540: Based on the sharing times of the personal sensitive information of the target application for each of the third-party sharing applications, determine whether the operation of the target application on the user's privacy information is compliant.

[0097] That is to say, if the sharing times of the personal sensitive information of the target application for each of the third-party sharing applications exceed the set threshold, it indicates that the operation of the target application on the user's privacy information is non-compliant.

[0098] In this embodiment, by obtaining the operation content of the target application on the privacy information; when the operation content includes collecting precise location information and the target application does not belong to the location-based application category, determining that the operation of the target application on the user's privacy information is excessive collection; when the operation content includes sharing personal sensitive information, obtaining at least one third-party sharing application associated with the target application; and based on the sharing times of the personal sensitive information of the target application for each of the third-party sharing applications, determining whether the operation of the target application on the user's privacy information is compliant, it is possible to determine whether the operation of the target application on the user's privacy information is compliant through multiple methods, effectively improving the accuracy of the privacy operation compliance judgment of the application, thereby preventing developers of the target application or developers of third-party sharing applications from excessively collecting or sharing personal sensitive information using relevant protocol files.

[0099] In one implementation, the above S540 may include: when a second predetermined condition is met, determining that the operation of the target application on the user's privacy information is excessive sharing; where the second predetermined condition includes at least one of the following (1) and (2):

[0100] (1) The total number of shares is greater than a fourth threshold, where the total number of shares is the sum of at least one of the number of shares.

[0101] (2) The maximum number of shares is greater than a fifth threshold, where the maximum number of shares is the maximum value among at least one of the number of shares.

[0102] Optionally, the fourth threshold and the fifth threshold can be user-defined to meet the needs of different users.

[0103] In this implementation, to determine that the operation of the target application on user privacy information is oversharing, it can be evaluated by the number of times the target application actively shares personal sensitive information with a third-party sharing application. This number of shares can reflect the behavior of the target application during data collection and sharing.

[0104] Among them, in one implementation, after determining that the operation of the target application on user privacy information is oversharing, the method further includes: prompting the target application for oversharing user privacy information. Referring to the specific description in the foregoing content, it will not be elaborated here.

[0105] In another implementation, the above S540 may include the following steps:

[0106] S542: When the personal sensitive information includes collecting precise location information, obtain a second sharing application, where the second sharing application is the third-party sharing application with the number of shares greater than 0.

[0107] S544: Traverse the second sharing application.

[0108] S546: When the currently traversed second sharing application does not belong to a location-based application, determine that the operation of the target application on the user privacy information of the currently traversed second sharing application is oversharing.

[0109] In this implementation, if the second sharing application does not belong to a location-based application but collects precise location information, it indicates that the operation of the second sharing application on user privacy information is overcollection.

[0110] Among them, in one implementation, after determining that the operation of the target application on the user privacy information of the currently traversed second sharing application is oversharing, the method further includes: prompting to set a sharing permission configuration, where the sharing permission configuration is the permission configuration for the sharing operation of the target application on the user privacy information of the currently traversed second sharing application. Optionally, it can also prompt to set the permissions of the second sharing application.

[0111] Based on the above embodiments, the present application further provides a determination device for the compliance of application privacy operations, as follows Figure 6 As shown, the device includes a parsing module 601, a query module 602, an identification module 603, a reminder module 604, an application list module 605, a display module 606, a comparison module 607, a pop-up window module 608, and a permission setting module 609.

[0112] Among them, the parsing module 601 is used to parse the privacy clause text of the target application.

[0113] The query module 602 is used to query whether the target application discloses collecting precise location information in the privacy clause, and to query the third-party sharing applications of the target application.

[0114] The identification module 603 is used to identify whether the target application locates the SDK.

[0115] The reminder module 604 is used to remind the user that the target application over-collects and over-shares personal sensitive information.

[0116] The application list module 605 is used to list the locally installed third-party sharing applications.

[0117] The display module 606 is used to display the applications in the third-party sharing application list, and the number of times each third-party application accesses personal sensitive information.

[0118] The comparison module 607 is used to compare the number of times the third-party applications in the list access personal sensitive information with that of the target application.

[0119] The pop-up window module 608 is used to display the permission configuration interface of the third-party application.

[0120] The permission setting module 609 is used to set the permissions of the third-party applications.

[0121] In this embodiment, by identifying whether the target application over-collects and over-shares the user's personal sensitive information and providing a permission configuration interface for the user to operate, not only can the user determine whether the operation of the target application on the user information is compliant in the shortest time, but also the user information security is effectively improved.

[0122] In an exemplary embodiment, an electronic device is further provided, and this electronic device is used to execute the above-mentioned determination method for the compliance of application privacy operations. Figure 7Schematic diagram of the structure of an electronic device for implementing various embodiments of the present application. The electronic device may vary greatly due to different configurations or performances, and may include a processor 701, a communications interface 702, a memory 703, and a communication bus 704. Among them, the processor 701, the communications interface 702, and the memory 703 complete mutual communication through the communication bus 704. The processor 701 can call a computer program stored on the memory 703 and executable on the processor 701 to perform the following steps:

[0123] Obtain the operation content of the target application on privacy information; in the case where the operation content includes collecting precise location information and the target application does not belong to a location-based application, determine that the operation of the target application on the user's privacy information is excessive collection.

[0124] For the specific execution steps, reference can be made to the respective steps of the embodiment of the determination method for compliance of application privacy operations described above, and the same technical effects can be achieved. To avoid repetition, details are not elaborated here.

[0125] The above structure of the electronic device does not constitute a limitation on the electronic device. The electronic device may include more or fewer components than shown in the figure, or combine certain components, or have different component arrangements. For example, the input unit may include a Graphics Processing Unit (GPU) and a microphone, and the display unit may be configured with a display panel in the form of a liquid crystal display, an organic light-emitting diode, etc. The user input unit includes at least one of a touch panel and other input devices. The touch panel is also called a touch screen. Other input devices may include, but are not limited to, a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, a joystick, which are not elaborated here.

[0126] The memory can be used to store software programs and various data. The memory may mainly include a first storage area for storing programs or instructions and a second storage area for storing data. Among them, the first storage area can store an operating system, application programs or instructions required for at least one function (such as a sound playback function, an image playback function, etc.). In addition, the memory can include volatile memory or non-volatile memory, or the memory can include both volatile and non-volatile memory. Among them, the non-volatile memory can be a Read-Only Memory (ROM), a Programmable ROM (PROM), an Erasable PROM (EPROM), an Electrically Erasable PROM (EEPROM), or a flash memory. The volatile memory can be a Random Access Memory (RAM), a Static RAM (SRAM), a Dynamic RAM (DRAM), a Synchronous DRAM (SDRAM), a Double Data Rate SDRAM (DDR SDRAM), an Enhanced SDRAM (ESDRAM), a Synchlink DRAM (SLDRAM), and a Direct Rambus RAM (DRRAM).

[0127] The processor may include one or more processing units; optionally, the processor integrates an application processor and a modem processor. Among them, the application processor mainly processes operations related to the operating system, user interface, and application programs, etc., and the modem processor mainly processes wireless communication signals, such as a baseband processor. It can be understood that the above-mentioned modem processor may not be integrated into the processor either.

[0128] In an exemplary embodiment, a readable storage medium is further provided. At least one computer program is stored in the readable storage medium, and the computer program is loaded and executed by the processor to implement all or part of the steps in the above-mentioned determination method for compliance of application program privacy operations. For example, the readable storage medium can be a Read-Only Memory (ROM), a Random Access Memory (RAM), a Compact Disc Read-Only Memory (CD-ROM), magnetic tape, floppy disk, and optical data storage device, etc.

[0129] Other embodiments of the present application will be readily apparent to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. The present application is intended to cover any variations, uses, or adaptations of the present application, which follow the general principles of the present application and include known common general knowledge or conventional technical means in the technical field not disclosed in the present application. The specification and examples are only illustrative, and the true scope and spirit of the present application are pointed out by the claims.

[0130] It should be understood that the present application is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present application is only limited by the appended claims.

Claims

1. A method for determining compliance of application privacy operations, characterized in that, The method includes: Obtaining the operation content of the target application on privacy information; When the operation content includes collecting precise location information and the target application does not belong to a location-based application, determining that the operation of the target application on user privacy information is excessive collection.

2. The method according to claim 1, characterized in that, The obtaining the operation content of the target application on privacy information includes: Obtaining the operation content from the privacy terms of the target application; and / or, Obtaining the operation content from the information description file of the target application.

3. The method according to claim 1, characterized in that, After determining that the operation of the target application on user privacy information is excessive collection, the method further includes: Prompting the target application for excessive collection of user privacy information.

4. The method according to claim 1, characterized in that, After obtaining the operation content of the target application on privacy information, it further includes: When the operation content includes sharing personal sensitive information, obtaining at least one third-party sharing application associated with the target application; Determining whether the operation of the target application on user privacy information is compliant based on the first access times of at least one third-party sharing application to personal sensitive information.

5. The method according to claim 4, characterized in that, The determining whether the operation of the target application on user privacy information is compliant based on the first access times of at least one third-party sharing application to personal sensitive information includes: When a first predetermined condition is met, determining that the operation of the target application on user privacy information is excessive sharing; Wherein, the first predetermined condition includes at least one of the following: The maximum access times is greater than a first threshold, where the maximum access times is the maximum value among at least one of the first access times; The ratio of the total access times to the second access times is greater than a second threshold, where the total access times is the sum of at least one of the first access times, and the second access times is the access times of the target application to the personal sensitive information; The ratio of the maximum access times to the second access times is greater than a third threshold.

6. The method according to claim 5, characterized in that, After determining that the operation of the target application on user privacy information is excessive sharing, the method further includes: Prompting to set the permissions of the third-party sharing application.

7. The method according to claim 4, characterized in that, The determining whether the operation of the target application on user privacy information is compliant based on the first access times of at least one third-party sharing application to personal sensitive information includes: When the personal sensitive information includes collecting precise location information, obtaining a first sharing application, where the first sharing application is the third-party sharing application with the first access times greater than 0; Traversing the first sharing application; When the currently traversed first sharing application does not belong to a location-based application, determining that the operation of the currently traversed first sharing application on user privacy information is excessive collection.

8. The method according to claim 7, characterized in that, After determining that the operation of the currently traversed first sharing application on user privacy information is excessive collection, the method further includes: Prompting to set the permissions of the currently traversed first sharing application.

9. The method according to claim 1, characterized in that, After obtaining the operation content of the target application on privacy information, it further includes: When the operation content includes sharing personal sensitive information, obtain at least one third-party sharing application associated with the target application; Based on the number of times of sharing personal sensitive information of the target application for each third-party sharing application, determine whether the operation of the target application on the user's privacy information complies with the regulations.

10. The method according to claim 9, characterized in that, The determining whether the operation of the target application on the user's privacy information complies with the regulations based on the number of times of sharing personal sensitive information of the target application for each third-party sharing application includes: When a second predetermined condition is met, determine that the operation of the target application on the user's privacy information is oversharing; Wherein, the second predetermined condition includes at least one of the following: The total number of sharing times is greater than a fourth threshold value, where the total number of sharing times is the sum of at least one of the sharing times; The maximum number of sharing times is greater than a fifth threshold value, where the maximum number of sharing times is the maximum value among at least one of the sharing times.

11. The method according to claim 9, wherein, The determining whether the operation of the target application on the user's privacy information complies with the regulations based on the number of times of sharing personal sensitive information of the target application for each third-party sharing application includes: Obtain the third access number of the target application to personal sensitive information; When a third predetermined condition is met, determine that the operation of the target application on the user's privacy information is oversharing; Wherein, the third predetermined condition includes at least one of the following: The ratio of the total number of sharing times to the third access number is greater than a sixth threshold value, where the total number of sharing times is the sum of at least one of the sharing times; The ratio of the maximum number of sharing times to the third access number is greater than a seventh threshold value, where the maximum number of sharing times is the maximum value among at least one of the sharing times.

12. The method according to claim 10 or 11, wherein, After determining that the operation of the target application on the user's privacy information is oversharing, the method further includes: Prompt the target application for oversharing the user's privacy information.

13. The method according to claim 9, wherein, The determining whether the operation of the target application on the user's privacy information complies with the regulations based on the number of times of sharing personal sensitive information of the target application for each third-party sharing application includes: When the personal sensitive information includes collecting precise location information, obtain a second sharing application, where the second sharing application is the third-party sharing application with the number of sharing times greater than 0; Traverse the second sharing application; When the currently traversed second sharing application does not belong to a location-based application, determine that the operation of the target application on the user's privacy information for the currently traversed second sharing application is oversharing.

14. The method according to claim 13, wherein, After determining that the operation of the target application on the user's privacy information for the currently traversed second sharing application is oversharing, the method further includes: Prompt to set the sharing permission configuration, where the sharing permission configuration is the permission configuration for the sharing operation of the user's privacy information of the target application for the currently traversed second sharing application.

15. An electronic device, wherein, The electronic device includes a processor and a memory, and a program or instruction that can run on the processor is stored on the memory. When the program or instruction is executed by the processor, it implements the determination method for compliance of application program privacy operations as described in any one of claims 1 to 14.

16. A storage medium, wherein, A program or instruction is stored on the storage medium. When the program or instruction is executed by a processor, it implements the determination method for compliance of application program privacy operations as described in any one of claims 1 to 14.