Permission application management method, electronic equipment, storage medium and program product

By obtaining and demonstrating the usage purpose and usage scenarios of target permissions, and determining compliance target permissions based on the privacy agreement, the problem of excessive or misauthorized by users in the prior art is solved, and more accurate permission management is achieved.

CN120217404APending Publication Date: 2025-06-27KE COM (BEIJING) TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510206727.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-24
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

The existing permission application plan cannot effectively inform the user of the purpose and use scenarios of the requested permissions, resulting in the user failing to understand the role of permissions and excessive or misauthorization.

Method used

By obtaining the purpose and usage scenarios of target permissions, determine the compliance target permissions based on the scope of permissions in the application's privacy agreement, and display the permission application box and permission description box on the application page to inform users of the purpose and usage scenarios of compliance target permissions.

Benefits of technology

It improves users' understanding of the purpose and scenarios of permission use, reduces the probability of users misauthorization, and ensures that users make authorization decisions on an informed basis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120217404A_ABST
    Figure CN120217404A_ABST
Patent Text Reader

Abstract

The invention provides a permission application management method, electronic equipment, a readable storage medium and a computer program product. The permission application management method comprises the steps of obtaining an applied target permission in response to a permission application request of an application, and obtaining a use purpose and a use scene of the target permission; based on a permission permission range in a privacy protocol of the application, determining a target permission in the permission permission range as a compliance target permission; and in response to the fact that the compliance target permission is not authorized, displaying a permission application box and a permission description box on a page of the application, the permission application box being used for displaying the compliance target permission and being used for responding to a click event in the permission application box to obtain an authorization result of the compliance target permission, the permission description frame is used for displaying the use purpose and the use scene of the compliance target permission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer technology, and particularly to a method for managing permission applications, an electronic device, a storage medium, and a program product. Background Art

[0002] Currently, when an application software or program accesses privacy permissions, it needs to apply for permissions in accordance with relevant privacy compliance requirements. Existing permission application schemes only inform users which permission is requested, but do not inform what the requested permission is used for, which may cause users to over-authorize or mis-authorize without understanding the function of the requested permission. Summary of the Invention

[0003] The present disclosure provides a method for managing permission applications, an electronic device, a storage medium, and a program product.

[0004] According to one aspect of the present disclosure, there is provided a method for managing permission applications, including: In response to a permission application request of an application, obtaining the target permission being applied for, and obtaining the purpose and scenario of using the target permission; Based on the permission scope permitted in the privacy protocol of the application, determining the target permission within the permission scope as a compliant target permission; In response to the compliant target permission not being authorized, displaying a permission application box and a permission description box on the page of the application, where the permission application box is used to display the compliant target permission and to obtain the authorization result of the compliant target permission in response to a click event on the permission application box, and the permission description box is used to display the purpose and scenario of using the compliant target permission.

[0005] According to the method for managing permission applications according to at least one embodiment of the present disclosure, obtaining the purpose and scenario of using the target permission includes: Extracting custom comments in the application request of the target permission to obtain the purpose and scenario of using the target permission.

[0006] According to the method for managing permission applications according to at least one embodiment of the present disclosure, based on the permission scope permitted in the privacy protocol of the application, determining the target permission within the permission scope as a compliant target permission includes: Obtaining a permission whitelist based on the privacy protocol of the application, where the permission whitelist includes permissions that have obtained usage permission in the privacy protocol; In response to the target permission being a permission in the permission whitelist, determining that the target permission is within the permission scope and determining it as the compliant target permission.

[0007] A permission application management method according to at least one embodiment of the present disclosure, in response to the compliance target permission not being authorized, displays a permission application box and a permission description box on the page of the application, including: In response to the compliance target permission not being authorized, obtain the time interval between the application time of the application for the compliance target permission in the last application and the current application, and obtain the target time interval; Based on the purpose of use and the usage scenario of the compliance target permission, determine the time interval threshold corresponding to the compliance target permission as the target time interval threshold; In response to the target time interval being greater than or equal to the target time interval threshold, display a permission application box and a permission description box on the page of the application.

[0008] The permission application management method according to at least one embodiment of the present disclosure further includes: Based on the responded permission application requests, count the names and application times of the target permissions applied for in each of the responded permission application requests; Obtain the application result of each of the target permissions, and the application result is used to represent that the application of the target permission is abnormal, the application is refused authorization, or the application is authorized; In response to the application result of the target permission representing that the application of the target permission is abnormal, obtain the abnormal cause report of the target permission whose application result represents application abnormality; Generate a data dashboard based on the names, application times, application results of the target permissions applied for in each of the responded permission application requests, and the abnormal cause report.

[0009] The permission application management method according to at least one embodiment of the present disclosure, obtaining the abnormal cause report of the target permission whose application result represents application abnormality, includes: In response to the target permission not being within the permission scope, determine that the application result of the target permission is application abnormality, and generate a first abnormal report, and the first abnormal report represents that the target permission is not within the permission scope; Or in response to the time interval between the last application of the target permission by the application and the current application of the target permission by the application being less than the target time interval, determine that the application result of the target permission is application abnormality, and generate a second abnormal report, and the second abnormal report represents that the target permission is applied too frequently; Or in response to a permission application request including applications for two or more of the target permissions, determine that the application results of the applications for the two or more target permissions are all application abnormalities, and generate a third abnormal report, and the third abnormal report represents that there is a batch application for the target permission; Alternatively, in response to the usage purpose and usage scenario of the target permission not being included in the permission application request, determine that the application result of the target permission is an abnormal application, and generate a fourth abnormal report, where the fourth abnormal report indicates that the target permission lacks a permission description.

[0010] According to the permission application management method of at least one embodiment of the present disclosure, displaying a permission application box and a permission description box on the page of the application includes: Adding the page components of the application to a permission application container; Using the page components to trigger the respective generation events of the permission application box and the permission description box; In response to both the permission application box and the permission description box being generated, display the generated permission application box and permission description box on the page of the application; In response to the click event of the permission application box being triggered, use the page components to obtain the authorization result of the compliant target permission, and notify the application of the authorization result through the permission application container.

[0011] According to another aspect of the present disclosure, there is provided an electronic device, including: a memory storing execution instructions; and a processor that executes the execution instructions stored in the memory, such that the processor executes the permission application management method of any one of the embodiments of the present disclosure.

[0012] According to still another aspect of the present disclosure, there is provided a readable storage medium storing execution instructions, and when the execution instructions are executed by a processor, they are used to implement the permission application management method of any one of the embodiments of the present disclosure.

[0013] According to yet another aspect of the present disclosure, there is provided a computer program product including a computer program, and when the computer program is executed by a processor, it implements the permission application management method of any one of the embodiments of the present disclosure. Description of the Drawings

[0014] The drawings illustrate exemplary embodiments of the present disclosure and, together with the description thereof, are used to explain the principles of the present disclosure. These drawings are included to provide a further understanding of the present disclosure and are included in this specification and form a part of this specification.

[0015] Figure 1 is a flowchart of the permission application management method of an embodiment of the present disclosure.

[0016] Figure 2 is a schematic diagram of an application scenario of the permission application management method of an embodiment of the present disclosure.

[0017] Figure 3 It is a schematic flowchart of a permission application management method according to an embodiment of the present disclosure.

[0018] Figure 4 It is a schematic flowchart of a permission application management method according to an embodiment of the present disclosure.

[0019] Figure 5 It is a schematic flowchart of a permission application management method according to an embodiment of the present disclosure.

[0020] Figure 6 It is a schematic flowchart of a permission application management method according to an embodiment of the present disclosure.

[0021] Figure 7 It is a schematic diagram of a data dashboard according to an embodiment of the present disclosure.

[0022] Figure 8 It is a schematic flowchart of a permission application management method according to an embodiment of the present disclosure.

[0023] Figure 9 It is a schematic flowchart of a permission application management method according to an embodiment of the present disclosure.

[0024] Figure 10 It is a schematic diagram of the process of processing a permission application request using a transparent fragment control according to an embodiment of the present disclosure.

[0025] Figure 11 It is a schematic block diagram of the structure of a permission application management device according to an embodiment of the present disclosure.

[0026] Figure 12 It is a schematic block diagram of the structure of an electronic device according to an embodiment of the present disclosure. Detailed Embodiments

[0027] The present disclosure will be further described in detail below with reference to the accompanying drawings and examples. It can be understood that the specific examples described herein are only used to explain the relevant content and do not limit the present disclosure. Additionally, it should be noted that for the sake of description, only parts related to the present disclosure are shown in the drawings.

[0028] It should be noted that, without conflict, the embodiments in the present disclosure and the features in the embodiments can be combined with each other. The technical solutions of the present disclosure will be described in detail below with reference to the drawings and in combination with the embodiments.

[0029] According to relevant regulations, when an application software or program accesses permissions related to privacy information such as geographical location, photo album, camera, microphone, etc., it needs to submit a permission application visible to the user, and can use the corresponding permission only when the user authorizes it (including the right given by the user to the system for automatic authorization or default authorization). However, if the user is only informed of what the requested permission is, it is difficult for the user to know exactly how the application that requests the permission will use the permission, and there may be a situation where the way the application uses the permission exceeds the user's authorization expectation. For example, an application requests the user to obtain the location information of the device where the application is located. The user agrees to authorize it thinking that the purpose of the application collecting the location information is to provide navigation services. However, after obtaining the location information, the application uses it to recommend merchants near the location. The behavior of the application using the location information to recommend merchants exceeds the user's expectation of authorizing the application to obtain the location information, resulting in the user accidentally authorizing the application against their own will.

[0030] Embodiments of the present disclosure provide a permission application management method, which can be executed by electronic devices such as mobile phones and computers, and is used for permission application management when an application in an electronic device such as a mobile phone or a computer applies for permissions.

[0031] Figure 1 The overall flowchart of the permission application management method M100 according to an embodiment of the present disclosure is shown. As Figure 1 The method shown includes steps S110 to S150.

[0032] Specifically, Figure 1 The method shown includes: S110. In response to a permission application request of an application, obtain the target permission being applied for, and obtain the purpose and scenario of using the target permission.

[0033] Among them, the application may refer to an application program or software, such as an APP, a mini-program, etc. The permission application request is used to obtain the authorization for using the permission. Such permissions often involve privacy permissions, such as the permissions for an application to access functions or file locations such as geographical location, photo album, camera, microphone, etc.

[0034] The target permission refers to the permission that the permission application request wants to apply for authorization. For example, when a picture optimization software applies for the access permission of the local photo album, the access permission of the local photo album is the target permission.

[0035] The purpose and usage scenario of the target permission need to be described by the application that requests the target permission in the permission request in combination with its own business. For example, the business of an application of a merchant includes recommending the offline store closest to the user's location to the user. Then, in the permission request for obtaining the location permission, the application needs to explain that the purpose of using the location permission is to recommend the closest offline store and explain that the usage scenario of the location permission is to locate the city where the user is located.

[0036] S130. Based on the permission scope permitted in the privacy protocol of the application, screen the target permissions within the permission scope as compliant target permissions.

[0037] Among them, the privacy protocol of the application is usually a series of terms that pop up when the application is installed, including the business service content of the application and the permissions required for the business service content of the application. When the user agrees to the terms of the privacy protocol of the application, the permissions included in the privacy protocol of the application are considered the permissions permitted by the user for the application to use. Based on this, each permission included in the permission scope permitted in the privacy protocol of the application refers to each permission included in the privacy protocol of the application when the user agrees to the terms of the privacy protocol of the application.

[0038] When obtaining the applied target permission, the compliance of the target permission can be judged according to the permission scope permitted in the privacy protocol of the application. If the target permission is a permission within the permission scope, it is considered that the target permission is compliant and it is determined as a compliant target permission, indicating that this permission is an applied permission of the application and complies with the provisions of the privacy protocol of the application. For example, the permission scope permitted in the privacy protocol of a photo processing application does not include the permission to use the microphone. If the target permission applied by this photo processing application is the permission to use the microphone, it cannot pass the compliance check and will not be determined as a compliant target permission.

[0039] In one embodiment, even if the applied target permission fails to pass the compliance check and is not determined as a compliant target permission, relevant application records will be left, including information such as the name of the target permission, the number of application times, and the reason for failing to pass the compliance check. These data information will be summarized in the background and fed back to the application for the application party to refer to.

[0040] S150. In response to the non-authorization of the compliant target permission, display a permission application box and a permission description box on the page of the application.

[0041] The compliance target permissions can be determined through the compliance verification in step S130. If the target permissions fail to pass the compliance verification in step S130, for example, if the target program is outside the scope of permission granted in the privacy agreement of the application, then the target permissions will not be determined as compliance target permissions, and the authorization verification in step S150 and the display of the permission application box and the permission description box will not be triggered. In this way, it can be ensured that the permissions that comply with the privacy agreement of the application are displayed to the user only when they are applied, avoiding the user's misauthorization of non-compliant permissions.

[0042] The permission application box is used to display the compliance target permissions and to obtain the authorization result of the compliance target permissions in response to the click event on the permission application box. That is to say, in addition to being used to display the specific content of the compliance target permissions to the user, the permission application box is also configured with a click interaction area that can respond to the user's click event, such as a clickable button. According to the click events triggered by the user in different click interaction areas of the permission application box, different authorization results can be obtained correspondingly. For example, the permission application box includes two buttons. When responding to the user's click on the first button, it is determined that the user has triggered the first click event, and the authorization result of the compliance target permissions is "agree to authorize". When responding to the user's click on the second button, it is determined that the user has triggered the second click event, and the authorization result of the compliance target permissions is "disagree to authorize".

[0043] The permission description box is used to display the purpose and usage scenario of the compliance target permissions. In one example, the display method may include displaying through text content, displaying through picture content, displaying through audio broadcast, and displaying through video demonstration. For example, if the purpose and usage scenario of the compliance target permissions are text content, then the text content is displayed in the permission description box. Another example is that if the purpose and usage scenario of the compliance target permissions are video files, and the purpose and usage scenario of the compliance target permissions are demonstrated in the form of an animation, in this case, the permission description box can be configured to play the video file using a multimedia playback container.

[0044] Among them, the permission application box and the permission description box are displayed synchronously on the page of the application, so as to inform the user which permission is being applied while synchronously informing the user of the purpose and usage scenario of applying for this permission, enabling the user to further judge whether to authorize based on the purpose and usage scenario of the permission, so as to reduce the probability of the user's over-authorization or misauthorization.

[0045] In summary, the embodiments of the present disclosure can, when applying for permissions, display the compliance target permissions within the scope of the permission license that complies with the privacy agreement of the application on the page of the application, and simultaneously display the usage purpose and usage scenario of the compliance target permissions, so as to inform the user synchronously of how the application will specifically use the applied compliance target permissions, so as to ensure that the user can make an authorization decision that does not violate his or her own will on the basis of knowing how the compliance target permissions will be used.

[0046] Please refer to Figure 2 , Figure 2 which is a schematic diagram of an application scenario of the permission application management method according to some embodiments of the present disclosure.

[0047] In Figure 2 the application scenario shown, the currently displayed page is the page of an application (software or program, the same below), and the permission application box and the permission description box displayed on this page. Among them, the permission description box is only used to inform the user of the usage purpose and usage scenario of the applied permission. The permission application box has an interactive area that can trigger a click event, for example, including a "Prohibit" button and an "Agree only during use" button, and the click events triggered by the areas where these two buttons are located respectively correspond to the authorization results of "Disagree to authorize" and "Agree to authorize during use". The authorization result corresponding to the triggered click event will be notified to the application where this page is located to trigger the subsequent logic of the application in the case of obtaining or not obtaining authorization.

[0048] In Figure 2 the application scenario shown, the permission application box and the permission description box are displayed on the upper layer of the page of the application. Among them, the permission application box is displayed at the bottom of the page, and the permission description box is synchronously displayed at the top of the page. The two are synchronously displayed and do not block each other. The sizes and specific display positions of the permission application box and the permission description box can be configured using a layout scheme other than the Figure 2 embodiments shown under the principle of not blocking each other.

[0049] Regarding step S110, in some embodiments of the present disclosure, it can be specifically executed in the manner of step S1101.

[0050] S1101. Extract the usage purpose and usage scenario of the target permission from the custom annotation in the application request of the target permission.

[0051] Among them, the custom annotation refers to an annotation file used to describe the usage purpose and usage scenario of the target permission in the application request for the target permission, and the content of the annotation file is defined and edited by the application party itself. The annotation file can be a text file, a picture file, an audio file, a video file, etc. Extracting the custom annotation in the application request for the target permission means extracting the annotation file in the application request for the target permission as the usage purpose and usage scenario of the target permission.

[0052] The usage purpose and usage scenario of the target permission are obtained based on the custom annotation of the application party, aiming to enable the application party to explain the intention of requesting the permission based on its own business, so as to make the description of the usage purpose and usage scenario of the target permission more accurate. For example, if the target permission is the usage permission of the camera, and an application request for the usage permission of the camera is initiated on the QR code scanning page of the application, the custom annotation in this application request can be used to describe that the usage purpose is to scan the QR code; if an application request for the usage permission of the camera is initiated on the face recognition page of the application, the custom annotation in this application request can be used to describe that the usage purpose is to capture the face. In this way, for the same permission, different custom annotations can be corresponding in different business pages of the application to describe the specific usage method of this permission in different business pages, so as to reduce the probability of users misjudging the usage method of the permission and resulting in misauthorization.

[0053] In one example, the custom annotation is a text file, which can be specified in the application request for the target permission through the customDesc component.

[0054] Regarding step S130, in some embodiments of the present disclosure, it may include steps S1301 to S1302 as Figure 3 shown.

[0055] S1301. Obtain the permission whitelist based on the privacy protocol of the application.

[0056] Among them, the permission whitelist includes the permissions that have obtained usage permission in the privacy protocol.

[0057] In one example, the system where the application is located (such as the Android system, the IOS system, etc.) maintains a database for each application as the permission whitelist of this application. Specifically, this database can be only used to record the permissions that have obtained usage permission in the privacy protocol of this application and be used as the permission whitelist database.

[0058] S1302. In response to the target permission being a permission in the permission whitelist, determine that the target permission is within the scope of permission and determine it as a compliant target permission.

[0059] When obtaining a target permission, it is possible to determine whether the target permission is a compliant target permission by querying whether the target permission is in the permission whitelist. If the target permission is in the permission whitelist, it is determined as a compliant target permission. Otherwise, if the target permission is not in the permission whitelist, the application request for the target permission can be rejected.

[0060] Regarding step S150, in some embodiments of the present disclosure, it may include steps S1501 to S1503 as Figure 4 shown.

[0061] S1501. In response to the compliant target permission not being authorized, obtain the time interval between the application time of the application for the compliant target permission in the previous application and the current application, to obtain the target time interval.

[0062] In one example, each time responding to the permission application request of the application, record the moment of responding to the permission application request of the application as the time when the application applies for the target permission. In the case where the target permission is determined as a compliant target permission and it has been verified that the compliant target permission is not authorized, by obtaining the time interval between the two times when the application applies for the compliant target permission in the most recent two times (i.e., the current time and the previous time) as the target time interval. The target time interval is used to count the application frequency of the compliant target permission, so as to limit the number of times the application applies for the compliant target permission within a certain period of time based on the application frequency of the compliant target permission, and avoid the application applying for the same qualified target permission at a high frequency.

[0063] In one example, the limitation on the application frequency of the compliant target permission is mainly used to limit an application from applying for the same compliant target permission at a high frequency. Based on this, the target time interval is the time interval between the previous application of the compliant target permission by the same application and the current application of the compliant target permission.

[0064] In yet another example, the limitation on the application frequency of the compliant target permission is mainly used to limit the same business page of an application from applying for the same compliant target permission at a high frequency. Based on this, the time when the application applies for the target permission specifically includes the time when the business page of the application applies for the target permission. The target time interval is the time interval between the previous application of the compliant target permission and the current application of the compliant target permission by the same target page of the same application. For example, if the a business page of application X applied for the camera usage permission 2 hours ago, the b business page of application X applied for the camera usage permission 1 hour ago, and the a business page of application X applies for the camera usage permission again at the current moment, then it can be determined that the target time interval for the a business page of application X to apply for the camera usage permission is 2 hours rather than 1 hour.

[0065] In one example, for the same permission, the same time interval threshold can be set for different applications. For example, all applications are only allowed one application within 48 hours, and applications with a frequency exceeding this limit will be rejected. In this case, for the same permission, although the usage purposes and scenarios provided by each application may be different, the configured time interval threshold corresponding to this permission is 48 hours.

[0066] In another example, for the same permission, different time interval thresholds can be set for different applications. For example, a camera application is allowed to apply for the usage permission of the camera once every 24 hours, and another search application is allowed to apply for the usage permission of the camera once every 48 hours. At this time, the time interval threshold corresponding to the camera application's application for the usage permission of the camera is 24 hours, and the time interval threshold corresponding to the search application's application for the usage permission of the camera is 48 hours.

[0067] S1502. Determine the time interval threshold corresponding to the compliance target permission based on the usage purpose and scenario of the compliance target permission as the target time interval threshold.

[0068] In the solution of step S1502, for the same compliance target permission, different time interval thresholds can be set for different business pages of the same application. Since the usage purposes and scenarios of different business pages of the same application for the same compliance target permission may be different, based on this, the time interval threshold corresponding to the compliance target permission can be determined based on the usage purpose and scenario of the compliance target permission, and the determined time interval threshold is used as the target time interval threshold corresponding to the compliance target permission.

[0069] For example, the usage scenario and purpose of the camera on the shooting page of a camera application is to take a portrait photo. Also, the usage scenario and purpose of the camera on the QR code scanning page of this camera application is to take a payment QR code for payment. Considering that the frequency of taking portraits by the camera application is higher than that of taking QR codes, based on the usage scenario and purpose of taking portraits by this camera application, when applying for the usage permission of the camera on the shooting page, the target time interval threshold corresponding to the usage permission of the camera is determined to be 24 hours, and when applying for the usage permission of the camera on the QR code scanning page, the target time interval threshold corresponding to the usage permission of the camera is determined to be 48 hours.

[0070] S1503. In response to the target time interval being greater than or equal to the target time interval threshold, display a permission application box and a permission description box on the page of the application.

[0071] Displaying the permission application box and the permission description box on the page of the application only when the target time interval is greater than or equal to the target time interval threshold can prevent the page of the application from applying for permissions too frequently and disturbing the user.

[0072] In some embodiments of the present disclosure, the permission application management method M100 further includes step S170 as Figure 5 shown.

[0073] S170. Generate a data dashboard based on the responded permission application requests.

[0074] Among them, the data dashboard is used to display the behavior statistics of applying for the target permission in the responded permission application requests. For example, the data dashboard includes information such as the name of the applied permission and the number of applications, the authorized permissions, the unauthorized permissions, the reasons for the rejection of the application request, and the reasons for the non-authorization of the application.

[0075] Regarding step S170, in some embodiments of the present disclosure, it may include steps S1710 to S1740 as Figure 6 shown.

[0076] S1710. Based on the responded permission application requests, count the name and the number of applications of the target permissions applied in each responded permission application request.

[0077] As long as it is a responded permission application request, regardless of whether the request is rejected or whether the target permission of the request is authorized, it is included in the data statistics, including the name and the number of applications of the target permissions requested in the responded permission application requests. Among them, the number of applications can be the total number of times all applications apply for the target permission of this name; it can also be the total number of times an application applies for the target permission of this name; it can also be the total number of times a business page of an application applies for the target permission of this name.

[0078] S1720. Obtain the application results of each target permission.

[0079] Among them, the application result is used to represent that the application of the target permission is abnormal, the application is rejected from authorization, or the application is authorized. An abnormal application means a situation where the application of the target permission is rejected due to factors such as abnormal application processes or the target permission not meeting the regulations.

[0080] S1730. In response to the application result of the target permission representing that the application of the target permission is abnormal, obtain the abnormal reason report of the target permission whose application result represents an abnormal application.

[0081] In the case of an abnormal application, collecting the abnormal reason report can help the application party discover the errors causing the abnormality, summarize the reasons behind the behavior of rejecting the application, etc., and enable the application party to perform corresponding improvement processing.

[0082] Generate a data dashboard based on the names, application frequencies, application results, and abnormal reason reports of the target permissions applied for in each responded permission application request.

[0083] Please combine Figure 7 , Figure 7 is a schematic diagram of a partial data display module in the data dashboard. In Figure 7 In the illustrated example, a chart is used as the data display module. Figure 7 The data shown in one of the illustrated charts is the permission authorization rate today based on the names, application frequencies, and application results of the target permissions applied for today, including the results of applications being authorized and applications being refused authorization. This chart includes the statistically calculated probabilities of being refused authorization and being authorized. When clicking on the color block representing the probability of being refused authorization, one can jump to the list of permissions that have been refused authorization, and obtain the number of times each permission in the list has been refused. Similarly, when clicking on the color block representing the probability of being authorized, one can jump to the list of permissions that have been authorized, and obtain the number of times each permission in the list has been authorized. Shown in another chart is the statistical analysis of the abnormal reasons for application anomalies obtained based on the abnormal reason report, including anomalies caused by batch applications and anomalies caused by missing synchronization reports. Among them, a missing synchronization report means that the usage purpose and usage scenario of the target permission cannot be obtained in the permission application request.

[0084] Regarding step S1730, in some embodiments of the present disclosure, it may include steps S1731 to S1734 as Figure 8 shown.

[0085] S1731. In response to the target permission not being within the scope of permission, determine that the application result of the target permission is an abnormal application, and generate a first abnormal report.

[0086] Among them, the first abnormal report indicates that the target permission is not within the scope of permission. For example, if a target permission that is not in the permission whitelist is applied for, then the application result of the target permission is an abnormal application, and a first abnormal report is generated.

[0087] S1732. In response to the time interval between the previous application of the target permission and the current application being less than the target time interval, determine that the application result of the target permission is an abnormal application, and generate a second abnormal report.

[0088] Among them, the second abnormal report indicates that the target permission has been applied for with excessive frequency. For example, if the target time interval for a business page to apply for a target permission is 48 hours, but the business page submits a second application for the same target permission within 48 hours, then the application result of the second application for the target permission is an abnormal application, and a second abnormal report is generated.

[0089] S1733. In response to a permission application request including applications for two or more target permissions, determine that the application results of the applications for the two or more target permissions are all application anomalies, and generate a third anomaly report.

[0090] Among them, the third anomaly report indicates that there are batch applications for the target permissions. The situation where two or more permissions are applied for simultaneously in a permission application request is called a batch application. Permission application requests with batch application phenomena will be rejected and the anomalies will be recorded. For example, if a business page applies for the usage permissions of the camera and location simultaneously in a permission application request, then the application results of both the usage permission of the camera and the usage permission of the location are application anomalies, and two third anomaly reports are generated respectively. One is used to report that there is a batch application for the usage permission of the camera, and the other is used to report that there is a batch application for the usage permission of the location.

[0091] S1734. In response to the permission application request not including the usage purpose and usage scenario of the target permission, determine that the application result of the target permission is an application anomaly, and generate a fourth anomaly report.

[0092] Among them, the fourth anomaly report indicates that the target permission lacks permission description. For example, if a permission application request of an application only includes that the target permission being applied for is the usage permission of the camera, but does not explain the usage purpose and usage scenario of the usage permission of the camera, then determine that the application result of the usage permission of the camera is an application anomaly, and generate a fourth anomaly report.

[0093] Regarding step S150, in some embodiments of the present disclosure, step S150 specifically includes step S1510: Based on the permission application container, display a permission application box and a permission description box on the page of the application. Step S1510 may include steps S1511 to S1514 as Figure 9 shown.

[0094] S1511. Add the page components of the application to the permission application container.

[0095] In an example, Activity can be used as the permission application container, responsible for checking permissions, requesting permissions, and processing permission results. When applying for permissions through Activity, page components of the application can be added to Activity to process permission application requests.

[0096] Please combine Figure 10 , Figure 10Illustrate a process of using a transparent Fragment component as a page component of an application to handle a permission application request. In one embodiment, compliant permission application processing logic is pre-encapsulated in the transparent Fragment component. When it is necessary to request authorization from the user for permissions, that is, in the embodiments of the present disclosure, in response to the non-authorization of the compliant target permissions, a transparent Fragment component pre-encapsulated with permission application processing logic is temporarily added to the business page carried by the Activity, so as to use this transparent Fragment component to request authorization from the user for the compliant target permissions and obtain the authorization result. When the authorization result is obtained, this transparent Fragment component is removed, and then the authorization result is called back to the application. In this way, the process of the transparent Fragment component requesting authorization from the user is transparent and imperceptible to the application. The application only needs to call the permission application processing logic encapsulated in the Fragment component to achieve it, which can reduce the amount of code required when the application requests authorization from the user and relieve the development burden of the application side.

[0097] S1512. Use the page component to trigger the generation events of the permission application box and the permission description box respectively.

[0098] In the embodiments of the present disclosure, a permission application container (such as an Activity) requests authorization from the user through an interactive permission application box, and provides a permission description box to synchronously inform the purpose and usage scenario of the compliant target permissions. Specifically, the generation events of the permission application box and the permission description box can be pre-encapsulated in the page component of the application (such as a Fragment component). When this page component is added to the permission application container, the generation events of the permission application box and the permission description box are triggered through this page component to obtain the permission application box and the permission description box.

[0099] When the generation event of the permission application box is triggered, the device system where the application is located (such as the Android system) generates a permission application box for displaying the compliant target permissions, and configures a click interaction area on the permission application box that can trigger a click event. When the generation event of the permission description box is triggered, the device system where the application is located generates a permission description box for displaying the purpose and usage scenario of the compliant target permissions.

[0100] S1513. In response to the generation of both the permission application box and the permission description box, display the generated permission application box and permission description box on the page of the application.

[0101] In the case where the device system where the application is located generates a permission application box and a permission description box, the permission application container obtains the permission application box and the permission description box from the device system where the application is located, and displays the permission application box and the permission description box in the permission application container according to the layout settings of the permission application container.

[0102] S1514. In response to the click event of the permission application box being triggered, use the page component to obtain the authorization result of the compliance target permission, and notify the application of the authorization result through the permission application container.

[0103] When the click event of the permission application box is triggered, the page component added to the permission application container obtains the corresponding authorization result based on the triggered click event, and notifies the application of the authorization result through the permission application container. During this process, the Fragment component is automatically removed after the permission application container issues a notification, making the process of obtaining the authorization result transparent and imperceptible to the application.

[0104] Based on any of the above embodiments, the present disclosure also provides a permission application management device. Figure 11 It is a structural schematic block diagram of a permission application management device according to an embodiment of the present disclosure.

[0105] As Figure 11 shown, the permission application management device includes: A request response module 110, configured to, in response to a permission application request of an application, obtain the target permission being applied for, and obtain the purpose and usage scenario of the target permission.

[0106] A compliance verification module 120, configured to determine the target permission within the permission permission scope as a compliance target permission based on the permission permission scope in the privacy protocol of the application.

[0107] A synchronous display module 130, configured to, in response to the compliance target permission not being authorized, display a permission application box and a permission description box on the page of the application.

[0108] The above permission application management device may be computer software, and each of its modules may be a computer software module. The implementation processes of the functions and roles of each module in the above permission application management device are specifically described in detail in the implementation processes of the corresponding steps in the above method, and will not be elaborated here.

[0109] The execution subject of the permission application management method in the specific embodiment of the present disclosure may be an electronic device such as a mobile phone or a computer.

[0110] Therefore, based on any of the above embodiments, the present disclosure also provides an electronic device, which can execute the permission application management method of any of the above embodiments described in the present disclosure.

[0111] Figure 12 It is a structural schematic block diagram of an electronic device 1000 according to an embodiment of the present disclosure.

[0112] The hardware structure of the electronic device 1000 can be implemented using a bus architecture. The bus architecture can include any number of interconnecting buses and bridges, depending on the specific application of the hardware and the overall design constraints. The bus 1100 connects various circuits including one or more processors 1200, a memory 1300, and / or hardware modules together. The bus 1100 can also connect various other circuits 1400 such as peripheral devices, voltage regulators, power management circuits, external antennas, etc.

[0113] The bus 1100 can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one connecting line is shown in this figure, but it does not mean that there is only one bus or one type of bus.

[0114] The present disclosure also provides a readable storage medium. A computer program is stored in the readable storage medium, and when the computer program is executed by a processor, it is used to implement the above-mentioned method. The "readable storage medium" can be any device that can contain, store, communicate, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. More specific examples of the readable storage medium include the following: an electrical connection part (electronic device) having one or more wirings, a portable computer disk cartridge (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable read-only memory (CDROM), etc.

[0115] The present disclosure also provides a computer program product. The method of the present disclosure can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed, the process or function of the present disclosure is executed in whole or in part.

[0116] Computer programs or instructions can be stored in a readable storage medium or transmitted from one readable storage medium to another. For example, computer programs or instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired or wireless manner. The readable storage medium can be any available medium that can be accessed or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; it can also be an optical medium, such as a digital video disc; or it can be a semiconductor medium, such as a solid-state drive. The computer-readable storage medium can be a volatile or non-volatile storage medium, or can include both volatile and non-volatile types of storage media.

[0117] Those skilled in the art should understand that the embodiments of the present disclosure can be provided as a method, system, or computer program product. Therefore, the present disclosure can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present disclosure can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0118] The present disclosure is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the present disclosure. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable rights application management devices to produce a machine, such that the instructions executed by the processor of the computer or other programmable rights application management devices produce means for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or the combination of one or more flows and / or blocks.

[0119] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable rights application management device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including instruction means that implement the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or the combination of one or more flows and / or blocks.

[0120] These computer program instructions can also be loaded onto a computer or other programmable rights application management device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide for implementing the process Figure 1 one process or multiple processes and / or blocks Figure 1 steps for the functions specified in one block or multiple blocks.

[0121] In the description of this specification, the descriptions with reference to the terms "one embodiment / way", "some embodiments / ways", "example", "specific example", or "some examples", etc. mean that the specific features, structures, or characteristics described in connection with the embodiment / way or example are included in at least one embodiment / way or example of the present disclosure. In this specification, the schematic expressions of the above terms do not necessarily refer to the same embodiment / way or example. Moreover, the specific features, structures, or characteristics described can be combined in a suitable manner in any one or more embodiments / ways or examples. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments / ways or examples described in this specification and the features of different embodiments / ways or examples.

[0122] In addition, the terms "first" and "second" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one of the features. In the description of the present disclosure, "a plurality of" means at least two, such as two, three, etc., unless otherwise specifically defined.

[0123] Those skilled in the art should understand that the above embodiments are only for clearly explaining the present disclosure and are not intended to limit the scope of the present disclosure. For those skilled in the art, other changes or modifications can be made on the basis of the above disclosure, and these changes or modifications are still within the scope of the present disclosure.

[0124] It can be understood that before using the technical solutions disclosed in the embodiments of the present disclosure, the types, usage scopes, usage scenarios, etc. of the personal information involved in the present disclosure should be informed to the users and the authorization of the users should be obtained in an appropriate manner in accordance with relevant laws and regulations.

[0125] For example, when receiving an active request from a user, a prompt message is sent to the user to clearly prompt the user that the operation requested by the user will require obtaining and using the user's personal information. Thus, the user can autonomously choose whether to provide personal information to software or hardware such as an electronic device, an application program, a server, or a storage medium that performs the operations of the technical solution of the present disclosure according to the prompt message.

[0126] As an optional but non-limiting implementation manner, the manner of sending a prompt message to the user in response to receiving the user's active request may be, for example, a pop-up window manner, and the prompt message may be presented in text in the pop-up window. In addition, the pop-up window may also carry a selection control for the user to choose "agree" or "disagree" to provide personal information to the electronic device.

[0127] It can be understood that the above notification and user authorization process is only illustrative and does not limit the implementation manner of the present disclosure, and other manners that comply with relevant laws and regulations can also be applied to the implementation manner of the present disclosure.

[0128] At the same time, it can be understood that the data involved in the technical solution of the present disclosure (including but not limited to the data itself, the acquisition or use of the data) should comply with the requirements of the corresponding laws, regulations and related regulations.

Claims

1. A method for managing permission application, characterized in that: include: In response to the permission application request of the application, obtain the applied target permission, and obtain the purpose and usage scenario of the target permission; Based on the permission scope in the privacy agreement of the application, determining the target permission within the permission scope as a compliant target permission; as well as In response to the compliance target permission not being authorized, a permission application box and a permission description box are displayed on the application page, the permission application box is used to display the compliance target permission, and is used to obtain the authorization result of the compliance target permission in response to a click event in the permission application box, and the permission description box is used to display the purpose and usage scenarios of the compliance target permission.

2. The permission application management method according to claim 1, characterized in that: The purpose and scenario of obtaining the target permission include: The custom annotation in the application request of the target permission is extracted to obtain the purpose and usage scenario of the target permission.

3. The permission application management method according to claim 1, characterized in that: Based on the permission scope in the privacy agreement of the application, determining the target permission within the permission scope as a compliant target permission includes: Obtaining a permission whitelist based on the privacy agreement of the application, wherein the permission whitelist includes permissions to obtain usage permission in the privacy agreement; and In response to the target permission being a permission in a permission whitelist, the target permission is determined to be within the permission range and is determined as the compliant target permission.

4. The permission application management method according to claim 1, characterized in that: In response to the compliance target permission not being authorized, a permission application box and a permission description box are displayed on the application page, including: In response to the compliance target permission not being authorized, obtaining a time interval between the application time of the application last time and the application time of the compliance target permission this time, to obtain a target time interval; Determining, based on the purpose and scenario of use of the compliance target authority, a time interval threshold corresponding to the compliance target authority as the target time interval threshold; and In response to the target time interval being greater than or equal to the target time interval threshold, a permission application box and a permission description box are displayed on the application page.

5. The permission application management method according to claim 1, characterized in that: Also includes: Based on the responded permission application requests, counting the name and application times of the target permission applied for by each responded permission application request; Obtaining the application results of each of the target permissions, where the application results are used to indicate whether the application of the target permissions is abnormal, the application is denied authorization, or the application is authorized; In response to the application result of the target permission indicating that the application of the target permission is abnormal, obtaining an abnormality cause report of the target permission whose application result indicates that the application is abnormal; as well as A data dashboard is generated based on the name of the target permission applied for by each responded permission application request, the number of applications, the application result and the abnormal reason report.

6. The permission application management method according to claim 5, characterized in that: Obtaining an abnormality reason report for the target permission characterized by an application abnormality, including: In response to the target permission not being within the permission scope, determining that the application result of the target permission is an application exception, and generating a first exception report, wherein the first exception report indicates that the target permission is not within the permission scope; or In response to the time interval between the last time the target permission was applied by the application and the current time the target permission is applied by the application being less than a target time interval, determining that the application result of the target permission is an application exception, and generating a second exception report, wherein the second exception report indicates an over-frequency application of the target permission; or In response to a permission application request including applications for two or more target permissions, determining that the application results of the two or more target permissions are all application exceptions, and generating a third exception report, wherein the third exception report indicates that there are batch applications for the target permissions; or In response to the permission application request not including the purpose and usage scenario of the target permission, determining that the application result of the target permission is an application exception, and generating a fourth exception report, wherein the fourth exception report indicates that the target permission lacks a permission description.

7. The permission application management method according to any one of claims 1 to 6, characterized in that: The permission application box and permission description box are displayed on the application page, including: Adding the page component of the application to the permission application container; Using the page component to trigger generation events of the permission application box and the permission description box respectively; In response to the permission application box and the permission description box being generated, displaying the generated permission application box and the permission description box on the page of the application; and In response to a click event of the permission application box being triggered, the page component is used to obtain the authorization result of the compliant target permission, and the authorization result is notified to the application through the permission application container.

8. An electronic device, characterized in that: include: A memory storing execution instructions; as well as A processor, wherein the processor executes the execution instructions stored in the memory, so that the processor executes the permission application management method according to any one of claims 1 to 7.

9. A readable storage medium, characterized in that: The readable storage medium stores execution instructions, which, when executed by a processor, are used to implement the permission application management method described in any one of claims 1 to 7.

10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the permission application management method described in any one of claims 1 to 7 is implemented.