Data processing method and device and electronic equipment

By receiving and matching the verifiable information of the target application, ensuring that only data within the scope of legal permissions is obtained, the problem of low security of user privacy data is solved and more efficient permission management and data security is achieved.

CN120234797APending Publication Date: 2025-07-01CHINA MOBILE COMM GRP TERMINAL +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510384487.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-28
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

After a user accidentally touches the permission to grant the control, the application may obtain data permissions that should not be obtained, resulting in poor user privacy data security.

Method used

By receiving the operation permission verification request of the target application, obtain the first verifiable information approved by the preset auditor, generate the second verifiable information, and perform matching processing. When the match is successful, obtain the operation data to execute the target instruction, ensuring that only data within the scope of legal permissions is obtained.

Benefits of technology

It effectively avoids applications from obtaining data outside their permission scope, improves the security of user privacy data, and enhances the flexibility and security of permission management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120234797A_ABST
    Figure CN120234797A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a data processing method and device and electronic equipment. The method comprises the steps that an operation authority verification request for a target instruction in a target application program is received; in response to the operation authority verification request, first verifiable information corresponding to the target application program and a first operation authority corresponding to the target instruction are obtained, and the first verifiable information is obtained after a preset auditor verifies operation authority information provided by a developer of the target application program and passes the verification of the operation authority information provided by the developer of the target application program; generating verifiable information for the operation authority information; determining second verifiable information corresponding to the first operation authority, and performing matching processing on the first verifiable information and the second verifiable information; under the condition that the first verifiable information and the second verifiable information are successfully matched, obtaining operation data corresponding to the first operation authority; and executing the target instruction according to the operation data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular, to a data processing method, apparatus, and electronic device. Background Art

[0002] With the rapid development of computer technology, there are more and more application programs available in terminal devices. To protect the security of user privacy data, terminal devices can perform data permission control management on application programs according to user needs.

[0003] However, if the user accidentally touches the permission granting control, then the application program may obtain some data permissions that it should not obtain, which will lead to low security of user privacy data. Therefore, a technical solution for managing application program permissions to improve the security of user privacy data is needed. Summary of the Invention

[0004] The purpose of the embodiments of the present invention is to provide a technical solution for managing application program permissions to improve the security of user privacy data.

[0005] To solve the above technical problems, the embodiments of the present invention are implemented as follows: In a first aspect, a data processing method provided by an embodiment of the present invention includes: Receiving an operation permission verification request for a target instruction in a target application program; In response to the operation permission verification request, obtaining first verifiable information corresponding to the target application program and a first operation permission corresponding to the target instruction, where the first verifiable information is verifiable information generated for the operation permission information after a preset review party verifies the operation permission information provided by the developer of the target application program; Determining second verifiable information corresponding to the first operation permission, and performing matching processing on the first verifiable information and the second verifiable information; When the first verifiable information and the second verifiable information match successfully, obtaining operation data corresponding to the first operation permission; Executing the target instruction according to the operation data.

[0006] In a second aspect, an embodiment of the present invention provides a data processing apparatus, including: A first receiving module, configured to receive an operation permission verification request for a target instruction in a target application program; A first acquisition module, configured to obtain first verifiable information corresponding to the target application program and a first operation permission corresponding to the target instruction in response to the operation permission verification request, where the first verifiable information is verifiable information generated for the operation permission information after a preset review party verifies the operation permission information provided by the developer of the target application program; A first matching module, configured to determine second verifiable information corresponding to the first operation permission and perform a matching process on the first verifiable information and the second verifiable information; A second acquisition module, configured to obtain operation data corresponding to the first operation permission when the first verifiable information and the second verifiable information match successfully; A first execution module, configured to execute the target instruction according to the operation data.

[0007] In a third aspect, an embodiment of the present invention provides an electronic device, including a processor, a memory, and a computer program stored on the memory and executable on the processor. When the computer program is executed by the processor, the steps of the data processing method provided in the above embodiment are implemented.

[0008] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the data processing method provided in the above embodiment are implemented.

[0009] In a fifth aspect, an embodiment of the present invention provides a computer program product, including a computer program. When the computer program is executed by a processor, the steps of the data processing method provided in the above embodiment are implemented. Description of the Drawings

[0010] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments recorded in the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0011] Figure 1 It is a schematic flowchart of a data processing method of the present invention; Figure 2 It is a schematic flowchart of another data processing method of the present invention; Figure 3 It is a schematic diagram of a target data generation process of the present invention; Figure 4 It is a schematic diagram of a data processing process of the present invention; Figure 5 Schematic flowchart of another data processing method of the present invention; Figure 6 Schematic diagram of the acquisition process of a temporary operation permission of the present invention; Figure 7 Schematic structural diagram of a data processing device of the present invention; Figure 8 Schematic structural diagram of an electronic device of the present invention. Detailed implementation manners

[0012] Embodiments of the present invention provide a data processing method, device and electronic device.

[0013] In order to enable those skilled in the art to better understand the technical solutions in the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without making creative efforts shall fall within the protection scope of the present invention.

[0014] Embodiments of this specification provide a data processing method, apparatus, and device. With the rapid development of computer technology, more and more application programs can be used in terminal devices. To protect the security of user privacy data, the terminal device can perform data permission control management on application programs according to user needs. However, if the user accidentally touches the permission-granting control, then the application program may obtain some data permissions that it should not obtain, which will lead to low security of user privacy data. Therefore, a technical solution is needed to manage the permissions of application programs to improve the security of user privacy data. In this solution, an operation permission verification request for a target instruction in a target application program is received. In response to the operation permission verification request, first verifiable information corresponding to the target application program and a first operation permission corresponding to the target instruction are obtained. The first verifiable information can be verifiable information generated for the operation permission information after a preset auditing party verifies the operation permission information provided by the developer of the target application program. The second verifiable information corresponding to the first operation permission is determined, and the first verifiable information and the second verifiable information are matched. When the first verifiable information and the second verifiable information match successfully, the operation data corresponding to the first operation permission is obtained, and the target instruction is executed according to the operation data. In this way, since the first verifiable information is verifiable information generated for the operation permission information after the auditing party verifies the operation permission information provided by the developer of the target application program, it is possible to determine whether to obtain the operation data corresponding to the first operation permission based on the matching situation between the second verifiable information corresponding to the first operation permission and the first verifiable information, and it is possible to prevent the target application program from obtaining data outside its permission scope, thereby improving the security of user privacy data. The specific processing can refer to the specific content in the following embodiments.

[0015] As Figure 1 shown, embodiments of the present invention provide a data processing method. The execution subject of this method can be a terminal device or a server. The terminal device can be a mobile terminal device such as a mobile phone, a tablet computer, a smart watch, etc., or a terminal device such as a computer. The server can be an independent server or a server cluster composed of multiple servers. This method can specifically include the following steps: In step S102, an operation permission verification request for a target instruction in a target application program is received.

[0016] Among them, the target application can be any installable application. For example, the target application can be an instant messaging application, a video viewing application, or a resource transfer application. The target instruction can be any instruction that needs to obtain user data (such as location information, image data, video data, file data, time data, etc.). For example, the target instruction can be a location information sharing instruction, an image data access instruction, an address book data acquisition instruction, a calendar data sharing instruction, etc.

[0017] In implementation, taking the target application as an instant messaging application as an example, when the user uses the instant messaging application, the user can trigger a location information sharing instruction to share the user's location with other users.

[0018] When the terminal device receives the location information sharing instruction, it can trigger an operation permission verification request for the location information sharing instruction of the instant messaging application to determine whether the instant messaging application has the location information acquisition permission.

[0019] The above method for obtaining the operation permission verification request is an optional and implementable obtaining method. In actual application scenarios, there can also be various different obtaining methods, and different obtaining methods can be selected according to different actual application scenarios. This embodiment of the specification does not make specific limitations on this.

[0020] In step S104, in response to the operation permission verification request, obtain the first verifiable information corresponding to the target application and the first operation permission corresponding to the target instruction.

[0021] Among them, the first verifiable information can be the verifiable information generated for the operation permission information after the preset review party verifies the operation permission information provided by the developer of the target application. The operation permission information can include the operation permissions that the target application needs to use and the data types corresponding to the operation permissions.

[0022] In implementation, the developer can provide a permission description document (i.e., operation permission information) for the target application to the review party. The review party can verify the permission description document. For example, the review party can verify the operation permissions that the target application needs to use according to the application type to which the target application belongs. At the same time, the review party can also verify the data types corresponding to the operation permissions in the permission description document.

[0023] Specifically, the auditor can determine whether the operation permissions required by the target application are compliant according to the preset corresponding relationship between the application type and the operation permissions, and based on the application type to which the target application belongs. For example, assuming that the application type to which the target application belongs is the video viewing type, according to the preset corresponding relationship between the application type and the operation permissions, it can be determined that the operation permissions corresponding to the video viewing type include the address book access permission and the location information access permission. If the operation permissions required by the target application include operation permissions other than the address book access permission and the location information access permission, it can be determined that the first verification result is that the verification fails.

[0024] In addition, the auditor can also perform a verification process on the data types corresponding to the operation permissions in the permission description document according to the preset corresponding relationship between the operation permissions and the data types, and obtain a second verification result.

[0025] The auditor can determine the verification result of the operation permission information for the target application according to the first verification result and / or the second verification result.

[0026] In addition, the above method for verifying the operation permission information is an optional and implementable verification method. In actual application scenarios, there can be multiple different verification methods, and different verification methods can be selected according to the different actual application scenarios. The embodiments of this specification do not make specific limitations on this.

[0027] In step S106, determine the second verifiable information corresponding to the first operation permission, and perform a matching process on the first verifiable information and the second verifiable information.

[0028] In implementation, taking the first verifiable information as the verifiable information generated by the auditor for the operation permission information through a preset verifiable function (such as a hash function) as an example, the terminal device can generate the second verifiable information for the first operation permission through the preset verifiable function, and perform a matching process on the first verifiable information and the second verifiable information.

[0029] In step S108, when the first verifiable information and the second verifiable information match successfully, obtain the operation data corresponding to the first operation permission.

[0030] In implementation, when the first verifiable information and the second verifiable information match successfully, the terminal device can obtain the operation data corresponding to the first operation permission through the read application programming interface (API) interface of the local storage provided by the operating system (OS).

[0031] For example, with the first operation permission being the location information acquisition permission, when the first verifiable information and the second verifiable information match successfully, the terminal device can obtain the location information (ie, operation data) through the API interface provided by the operating system.

[0032] In step S110 , the target instruction is executed according to the operation data.

[0033] In implementation, taking the case where the target instruction is a location information sharing instruction as an example, the terminal device can send the acquired operation data (ie, location information) to the sharing object corresponding to the target instruction.

[0034] The embodiment of the present invention provides a data processing method, receiving an operation permission verification request for a target instruction in a target application, and in response to the operation permission verification request, obtaining first verifiable information corresponding to the target application and a first operation permission corresponding to the target instruction, wherein the first verifiable information can be verifiable information generated for the operation permission information after a preset auditor verifies the operation permission information provided by the developer of the target application, determining the second verifiable information corresponding to the first operation permission, and matching the first verifiable information with the second verifiable information, and obtaining operation data corresponding to the first operation permission when the first verifiable information and the second verifiable information match successfully, and executing the target instruction according to the operation data. In this way, since the first verifiable information is verifiable information generated for the operation permission information after the auditor verifies the operation permission information provided by the developer of the target application, it is possible to determine whether to obtain the operation data corresponding to the first operation permission by matching the second verifiable information corresponding to the first operation permission with the first verifiable information, thereby preventing the target application from obtaining data outside its authority scope, and improving the security of user privacy data.

[0035] In actual applications, the target application may include a small program installed in the host program for executing multimedia communication services. For example, the target application may be a new call small program, and the new call may be a call installed on the basis of the VoNR audio and video channel and the IP Multimedia Subsystem (IMS) data channel (IMS DC for short). In this way, the audio and video data of VoNR can be transmitted on the IMS data channel. On the basis of high-definition audio and video calls, any multimedia information can be synchronously transmitted through IMS DC, and traditional calls can be upgraded to real-time interactive / immersive calls.

[0036] In actual applications, there are many ways to install the target application. The following is an optional way to install the target application. Figure 2As shown, it may specifically include the processing of the following steps S202 to S210.

[0037] In step S202, receive an installation request for the target application.

[0038] In step S204, in response to the installation request, obtain the target data corresponding to the target application.

[0039] Among them, the target data may include the installation data of the target application provided by the developer, and the target encrypted data. The target encrypted data may be data obtained by the auditor encrypting the first verifiable information and the third verifiable information after passing the verification of the installation data. The third verifiable information may be verifiable information generated by the developer for the installation data.

[0040] In practice, after the developer completes the development of the target application, all files of the target application can be packaged to generate an installation package (i.e., installation data). At the same time, the developer can generate the third verifiable information for the installation data. For example, the developer can generate an MD5 digest value (i.e., the third verifiable information) of a preset length for the installation data according to a preset hash function.

[0041] The developer can send the installation data, operation permission information, and third verifiable information of the target application to a preset auditor for review.

[0042] The auditor can perform a rationality check on the operation permission information according to the function of the target application. In the case of passing the check, the auditor can generate the first verifiable information according to the operation permission information. For example, in the case where the operation permission information includes multiple operation permissions, the auditor can split the operation permission information to obtain multiple sub-operation permission information, and generate a corresponding index value for each sub-operation permission information, so as to determine the first verifiable information according to the obtained multiple index values. Among them, there are various methods for determining the index value. For example, the auditor can generate an index value of a preset length for each sub-operation permission information according to a preset verifiable function (such as a hash function), or the auditor can also encrypt the sub-operation permission information according to a preset encryption function and determine the encrypted data as the index value, etc. The method for determining the index value can vary according to different actual application scenarios, and the embodiments of this specification do not make specific limitations on this.

[0043] The auditor can also perform a compliance check on the installation data provided by the developer, and after passing the check, encrypt the first verifiable information and the third verifiable information according to a preset encryption algorithm to obtain the target data corresponding to the target application.

[0044] For example, such as Figure 3As shown, the auditor can concatenate the index values corresponding to each sub-operation permission information, append the concatenated index values after the third verifiable information, and then generate a signature fingerprint file in the format of cert (i.e., the target encrypted data) through the auditor's private algorithm.

[0045] The auditor can return the target data (i.e., the installation data and the target encrypted data) to the developer, and the developer can upload the target data corresponding to the target application to the server and wait for the user to download and use it.

[0046] When the terminal device receives an installation request for the target application, it can download the target data corresponding to the target application from the server according to the program identifier of the target application.

[0047] In step S206, the target encrypted data is decrypted to obtain the first verifiable information and the third verifiable information.

[0048] In implementation, the software development kit (SDK) of the target application can decrypt the signature fingerprint file (i.e., the target encrypted data) according to the same private algorithm as the auditor to obtain the first verifiable information and the second verifiable information.

[0049] In step S208, the fourth verifiable information corresponding to the installation data is determined, and the third verifiable information and the fourth verifiable information are matched.

[0050] In implementation, the terminal device can determine the fourth verifiable information corresponding to the installation data according to the same preset verifiable function as the developer. For example, the terminal device can generate an MD5 digest value of a preset length for the installation data as the fourth verifiable information according to the preset hash function.

[0051] In step S210, when the third verifiable information and the fourth verifiable information match successfully, the target application is installed according to the installation data, and the first verifiable information is stored.

[0052] In implementation, when the third verifiable information and the fourth verifiable information match successfully, the terminal device can consider that the obtained target data has not been tampered with, and can perform program installation processing according to the installation data. The terminal device can install the target application according to the installation data and store the first verifiable information.

[0053] In this way, as Figure 4As shown, when the target application needs to call a certain operation permission, the target application SDK can determine whether the operation permission to be called is the operation permission approved by the auditor according to the stored first verifiable information. In this way, when the operation permission to be called is consistent with the stored first verifiable information, the target application SDK can obtain the operation data corresponding to the operation permission through the local storage read API interface provided by the operating system. Otherwise, it can be considered that the operation permission to be called is an operation permission not approved by the auditor, and the terminal device can return an error code.

[0054] In practical applications, when the first verifiable information and the second verifiable information fail to match, a temporary operation permission can also be applied to the auditor. The processing method for applying for a temporary operation permission can be various. The following provides an optional processing method, as Figure 5 shown, which can specifically include the processing of the following steps S502~S506.

[0055] In step S502, when the first verifiable information and the second verifiable information fail to match, an operation permission acquisition request for the first operation permission is sent to the auditor.

[0056] In implementation, when the first verifiable information and the second verifiable information fail to match, the user can trigger an operation permission acquisition request for the first operation permission. For example, the terminal device can send an operation permission acquisition request for the first operation permission to the auditor in the form of email, phone call, short message, etc.

[0057] In step S504, when receiving the operation permission granting instruction returned by the auditor, the target operation permission corresponding to the operation permission granting instruction is obtained, and a matching process is performed between the target operation permission and the first operation permission.

[0058] In implementation, the operation permission acquisition request can carry the scenario information corresponding to the first operation permission, such as the usage scenario, usage requirements, etc. information input by the user for the first operation permission. The auditor can review the first operation permission according to this scenario information and return an operation permission granting instruction to the terminal device when the review is passed.

[0059] When the terminal device receives the operation permission granting instruction, it can obtain the target operation permission corresponding to the operation permission granting instruction and perform a matching process between the target operation permission and the first operation permission.

[0060] In step S506, when the target operation permission and the first operation permission match successfully, the operation data corresponding to the first operation permission is obtained, and the target instruction is executed according to the operation data.

[0061] In practical applications, the operation permission granting instruction may include the valid time period corresponding to the target operation permission. There are various specific processing methods for executing the target instruction according to the operation data in step S506 above. The following provides an optional processing method, which may specifically include the processing of step A1 below.

[0062] In step A1, within the valid time period, execute the target instruction according to the operation data.

[0063] In implementation, if the auditor decides to grant temporary permissions, details such as the temporary permission and the valid time period can be informed to the user by email, phone, or text message (i.e., send the operation permission granting instruction with the valid time period to the terminal device). At the same time, the auditor can set a preset permission mark for the target application so that the target application can use the operation permission within the valid time period.

[0064] Among them, the preset permission mark can be: on the user interface (UI) of the terminal device, a preset mark (such as an asterisk or a red dot, etc.) can be displayed at a preset display position (such as the upper right corner of the user interface). In terms of the underlying data information, a field can be added. For example, assuming the operation permission information provided by the developer is: content sharing_location information, the temporary operation permission (i.e., the target operation permission) can be: content sharing_location information_temp.

[0065] In practical applications, it is also possible to detect whether there is any illegal use of permissions during the running process of the target application. There are various specific processing methods for detecting illegal use of permissions. The following provides an optional processing method, as Figure 5 shown, which may specifically include the processing of steps S502 to S506 below.

[0066] In step S508, obtain the log data of the target application.

[0067] In implementation, the log data of the target application within a preset detection period (such as the last three days, the last week, etc.) can be obtained.

[0068] In step S510, detect whether there is any illegal use of permissions during the running process of the target application according to the target operation permission and the corresponding valid time period.

[0069] In implementation, as Figure 6 shown, during the use of the temporary operation permission, the platform or the auditor can detect the use of the target operation permission by the target application.

[0070] That is, the auditing party can detect whether there are any unauthorized uses of permissions (such as abuse of permissions, violation of user privacy protection, etc.) during the running process of the target application according to the target operation permissions and the corresponding valid time periods.

[0071] In step S512, if it is detected that there are unauthorized uses of permissions during the running process of the target application, the instruction with the unauthorized use of permissions is suspended from execution, and a preset warning message corresponding to the instruction with the unauthorized use of permissions is output.

[0072] In implementation, if it is detected that there are unauthorized uses of permissions during the running process of the target application, the auditing party can revoke the temporary operation permissions (i.e., the target operation permissions), and can take corresponding penalty measures against the target application or the user.

[0073] In this way, when the target application applies for access to a certain operation permission, some unnecessary operation permission applications can be blocked through the first verifiable information, further ensuring the information security of the user.

[0074] When the target application does not have a certain operation permission, the user can propose reasonable usage scenarios and purposes, and temporarily apply for the operation permission that the target application is unauthorized to use. After the auditing party approves it, the user can use it temporarily, making the permission management of the target application more flexible.

[0075] The embodiments of this specification provide a data processing method, which receives an operation permission verification request for a target instruction in a target application, and in response to the operation permission verification request, obtains the first verifiable information corresponding to the target application and the first operation permission corresponding to the target instruction. Among them, the first verifiable information can be the verifiable information generated for the operation permission information after the preset auditing party verifies the operation permission information provided by the developer of the target application. Determine the second verifiable information corresponding to the first operation permission, and perform a matching process on the first verifiable information and the second verifiable information. In the case where the first verifiable information and the second verifiable information match successfully, obtain the operation data corresponding to the first operation permission, and execute the target instruction according to the operation data. In this way, since the first verifiable information is the verifiable information generated for the operation permission information after the auditing party verifies the operation permission information provided by the developer of the target application, it is possible to determine whether to obtain the operation data corresponding to the first operation permission through the matching situation between the second verifiable information corresponding to the first operation permission and the first verifiable information, and it is possible to prevent the target application from obtaining data outside its permission scope, improving the security of user privacy data.

[0076] The above is the data processing method provided by the embodiments of this specification. Based on the same concept, the embodiments of this specification also provide a data processing device, as Figure 7 shown.

[0077] The data processing device includes: a first receiving module 701, a first obtaining module 702, a first matching module 703, a second obtaining module 704, and a first execution module 705, where: The first receiving module 701 is configured to receive an operation permission verification request for a target instruction in a target application program; The first obtaining module 702 is configured to, in response to the operation permission verification request, obtain first verifiable information corresponding to the target application program and a first operation permission corresponding to the target instruction, where the first verifiable information is verifiable information generated for the operation permission information after a preset auditing party verifies the operation permission information provided by the developer of the target application program; The first matching module 703 is configured to determine second verifiable information corresponding to the first operation permission and perform a matching process on the first verifiable information and the second verifiable information; The second obtaining module 704 is configured to, when the first verifiable information and the second verifiable information match successfully, obtain operation data corresponding to the first operation permission; The first execution module 705 is configured to execute the target instruction according to the operation data.

[0078] In the embodiments of this specification, the target application program includes a small program running in a host program for performing multimedia communication services.

[0079] In the embodiments of this specification, the device further includes: A second receiving module, configured to receive an installation request for the target application program; A third obtaining module, configured to, in response to the installation request, obtain target data corresponding to the target application program, where the target data includes installation data of the target application program provided by the developer and target encrypted data, and the target encrypted data is data obtained by the auditing party encrypting the first verifiable information and third verifiable information after verifying the installation data, and the third verifiable information is verifiable information generated by the developer for the installation data; A data decryption module, configured to decrypt the target encrypted data to obtain the first verifiable information and the third verifiable information; An information determination module, configured to determine fourth verifiable information corresponding to the installation data and perform a matching process on the third verifiable information and the fourth verifiable information; An information storage module, configured to install the target application according to the installation data and store the first verifiable information when the third verifiable information and the fourth verifiable information match successfully.

[0080] In the embodiments of the present specification, the device further includes: A request sending module, configured to send an operation permission acquisition request for the first operation permission to the auditing party when the first verifiable information and the second verifiable information do not match; A second matching module, configured to obtain the target operation permission corresponding to the operation permission granting instruction and perform a matching process on the target operation permission and the first operation permission when receiving the operation permission granting instruction returned by the auditing party; A second execution module, configured to obtain the operation data corresponding to the first operation permission and execute the target instruction according to the operation data when the target operation permission and the first operation permission match successfully.

[0081] In the embodiments of the present specification, the operation permission granting instruction includes a valid time period corresponding to the target operation permission, and the second execution module is configured to: Execute the target instruction according to the operation data within the valid time period.

[0082] In the embodiments of the present specification, the device further includes: A fourth acquisition module, configured to acquire the log data of the target application; A violation detection module, configured to detect whether there is any unauthorized use of permissions during the running process of the target application according to the target operation permission and the corresponding valid time period; An alarm module, configured to suspend the execution of the instruction with unauthorized use of permissions and output a preset alarm message corresponding to the instruction with unauthorized use of permissions if it is detected that there is any unauthorized use of permissions during the running process of the target application.

[0083] An embodiment of this specification provides a data processing device that receives an operation permission verification request for a target instruction in a target application. In response to the operation permission verification request, the device obtains first verifiable information corresponding to the target application and a first operation permission corresponding to the target instruction. Here, the first verifiable information can be verifiable information generated for the operation permission information after a preset reviewer verifies and passes the operation permission information provided by the developer of the target application. The device determines second verifiable information corresponding to the first operation permission, and performs a matching process on the first verifiable information and the second verifiable information. When the first verifiable information and the second verifiable information match successfully, the device obtains operation data corresponding to the first operation permission and executes the target instruction according to the operation data. In this way, since the first verifiable information is verifiable information generated for the operation permission information after the reviewer verifies and passes the operation permission information provided by the developer of the target application, it is possible to determine whether to obtain operation data corresponding to the first operation permission based on the matching situation between the second verifiable information corresponding to the first operation permission and the first verifiable information, which can prevent the target application from obtaining data outside its permission scope and improve the security of user privacy data.

[0084] The above is the data processing device provided by the embodiment of this specification. Based on the same concept, the embodiment of this specification also provides a data processing device as Figure 8 shown.

[0085] The data processing device can be a terminal device or a server provided in the above embodiment, etc.

[0086] The data processing device may vary significantly due to configuration or performance differences, and may include one or more processors 801 and a memory 802. One or more application programs or data may be stored in the memory 802. Among them, the memory 802 can be a transient storage or a persistent storage. The application programs stored in the memory 802 may include one or more modules (not shown in the figure), and each module may include a series of computer-executable instructions in the data processing device. Further, the processor 801 can be set to communicate with the memory 802 and execute a series of computer-executable instructions in the memory 802 on the data processing device. The data processing device may also include one or more power supplies 803, one or more wired or wireless network interfaces 804, one or more input / output interfaces 805, and one or more keyboards 806.

[0087] Specifically, in this embodiment, the data processing device includes a memory and one or more programs. One or more of the programs are stored in the memory, and one or more of the programs may include one or more modules. Each module may include a series of computer-executable instructions in the data processing device and is configured to be executed by one or more processors. The one or more programs include the following computer-executable instructions for: Receiving an operation permission verification request for a target instruction in a target application program; In response to the operation permission verification request, obtaining first verifiable information corresponding to the target application program and a first operation permission corresponding to the target instruction. The first verifiable information is verifiable information generated for the operation permission information after a preset reviewer verifies the operation permission information provided by the developer of the target application program; Determining second verifiable information corresponding to the first operation permission and performing a matching process on the first verifiable information and the second verifiable information; When the first verifiable information and the second verifiable information match successfully, obtaining operation data corresponding to the first operation permission; Executing the target instruction according to the operation data.

[0088] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the data processing device embodiment, since it is basically similar to the method embodiment, the description is relatively simple. For related parts, reference can be made to the partial description of the method embodiment.

[0089] An embodiment of this specification provides a data processing device that receives an operation permission verification request for a target instruction in a target application program. In response to the operation permission verification request, the device obtains first verifiable information corresponding to the target application program and a first operation permission corresponding to the target instruction. The first verifiable information may be verifiable information generated for the operation permission information after a preset reviewer verifies the operation permission information provided by the developer of the target application program. The device determines second verifiable information corresponding to the first operation permission and performs a matching process on the first verifiable information and the second verifiable information. When the first verifiable information and the second verifiable information match successfully, the device obtains operation data corresponding to the first operation permission and executes the target instruction according to the operation data. In this way, since the first verifiable information is verifiable information generated for the operation permission information after the reviewer verifies the operation permission information provided by the developer of the target application program, it is possible to determine whether to obtain operation data corresponding to the first operation permission based on the matching between the second verifiable information corresponding to the first operation permission and the first verifiable information, which can prevent the target application program from obtaining data outside its permission scope and improve the security of user privacy data.

[0090] Further, based on the method described above Figures 1 to 6 One or more embodiments of this specification also provide a storage medium for storing computer-executable instruction information. In a specific embodiment, the storage medium may be a USB flash drive, an optical disc, a hard disk, etc. When the computer-executable instruction information stored in the storage medium is executed by a processor, the following process can be implemented: Receive an operation permission verification request for a target instruction in a target application program; In response to the operation permission verification request, obtain first verifiable information corresponding to the target application program and a first operation permission corresponding to the target instruction. The first verifiable information is verifiable information generated for the operation permission information after a preset reviewer verifies the operation permission information provided by the developer of the target application program; Determine second verifiable information corresponding to the first operation permission and perform a matching process on the first verifiable information and the second verifiable information; When the first verifiable information and the second verifiable information match successfully, obtain operation data corresponding to the first operation permission; Execute the target instruction according to the operation data.

[0091] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other, and the key point of each embodiment is to illustrate the differences from other embodiments. In particular, for the above-mentioned embodiment of a storage medium, since it is basically similar to the method embodiment, the description is relatively simple, and reference can be made to the relevant part of the method embodiment for the related content.

[0092] An embodiment of this specification provides a storage medium that receives an operation permission verification request for a target instruction in a target application program. In response to the operation permission verification request, it obtains first verifiable information corresponding to the target application program and a first operation permission corresponding to the target instruction. The first verifiable information can be verifiable information generated for the operation permission information after a preset reviewer verifies the operation permission information provided by the developer of the target application program. Determine the second verifiable information corresponding to the first operation permission, and perform a matching process on the first verifiable information and the second verifiable information. When the first verifiable information and the second verifiable information match successfully, obtain the operation data corresponding to the first operation permission, and execute the target instruction according to the operation data. In this way, since the first verifiable information is verifiable information generated for the operation permission information after the reviewer verifies the operation permission information provided by the developer of the target application program, it is possible to determine whether to obtain the operation data corresponding to the first operation permission based on the matching situation between the second verifiable information corresponding to the first operation permission and the first verifiable information, which can prevent the target application program from obtaining data outside its permission scope and improve the security of user privacy data.

[0093] Furthermore, based on the above Figures 1 to 6 shown method, one or more embodiments of this specification also provide a computer program product, including a computer program. When the computer program in this computer program product is executed by a processor, it can implement the following process: Receive an operation permission verification request for a target instruction in a target application program; In response to the operation permission verification request, obtain the first verifiable information corresponding to the target application program and the first operation permission corresponding to the target instruction. The first verifiable information is verifiable information generated for the operation permission information after a preset reviewer verifies the operation permission information provided by the developer of the target application program; Determine the second verifiable information corresponding to the first operation permission, and perform a matching process on the first verifiable information and the second verifiable information; When the first verifiable information and the second verifiable information match successfully, obtain the operation data corresponding to the first operation permission; Execute the target instruction according to the operation data.

[0094] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the above embodiment of a computer program product, since it is basically similar to the method embodiment, the description is relatively simple, and reference can be made to the corresponding part of the method embodiment for the relevant content.

[0095] An embodiment of this specification provides a computer program product, which receives an operation permission verification request for a target instruction in a target application program. In response to the operation permission verification request, it obtains first verifiable information corresponding to the target application program and a first operation permission corresponding to the target instruction. Among them, the first verifiable information can be the verifiable information generated for the operation permission information after a preset auditor verifies the operation permission information provided by the developer of the target application program. Determine the second verifiable information corresponding to the first operation permission, and perform a matching process on the first verifiable information and the second verifiable information. When the first verifiable information and the second verifiable information match successfully, obtain the operation data corresponding to the first operation permission, and execute the target instruction according to the operation data. In this way, since the first verifiable information is the verifiable information generated for the operation permission information after the auditor verifies the operation permission information provided by the developer of the target application program, it is possible to determine whether to obtain the operation data corresponding to the first operation permission through the matching situation between the second verifiable information corresponding to the first operation permission and the first verifiable information, which can avoid the target application program obtaining data outside its permission scope and improve the security of user privacy data.

[0096] The above describes specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the specific order or sequential order shown to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0097] In the 1990s, improvements to a technology could be clearly distinguished as either hardware improvements (e.g., improvements to circuit structures such as diodes, transistors, switches, etc.) or software improvements (improvements to method flows). However, with the development of technology, many method flow improvements today can be regarded as direct improvements to hardware circuit structures. Designers almost always obtain the corresponding hardware circuit structure by programming the improved method flow into the hardware circuit. Therefore, it cannot be said that an improvement to a method flow cannot be implemented using a hardware entity module. For example, a programmable logic device (PLD) (such as a field programmable gate array (FPGA)) is an integrated circuit whose logical function is determined by the user programming the device. Designers can program themselves to "integrate" a digital system onto a single PLD, without having to ask a chip manufacturer to design and fabricate a dedicated integrated circuit chip. Moreover, nowadays, instead of manually fabricating integrated circuit chips, this programming is mostly implemented using "logic compiler" software, which is similar to the software compiler used in program development and writing. The original code before compilation also has to be written in a specific programming language, which is called a hardware description language (HDL), and there is not just one type of HDL, but many types, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones currently are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also be aware that by simply performing a little logical programming on the method flow using the above-mentioned several hardware description languages and programming it into the integrated circuit, it is easy to obtain the hardware circuit that implements the logical method flow.

[0098] The controller can be implemented in any suitable manner. For example, the controller can take the form of, for example, a microprocessor or a processor and a computer-readable medium storing computer-readable program code (such as software or firmware) executable by the (micro)processor, logic gates, switches, an application specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller. Examples of the controller include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art also know that in addition to implementing the controller in the form of pure computer-readable program code, it is entirely possible to logically program the method steps to enable the controller to be implemented in the form of logic gates, switches, application specific integrated circuits, programmable logic controllers, embedded microcontrollers, etc. to achieve the same function. Therefore, such a controller can be considered a hardware component, and the devices included therein for implementing various functions can also be regarded as the structures within the hardware component. Or even, the devices for implementing various functions can be regarded as either software modules for implementing the method or the structures within the hardware component.

[0099] The systems, devices, modules, or units illustrated in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer can be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or any combination of these devices.

[0100] For the convenience of description, when describing the above devices, they are described separately as various units according to their functions. Of course, when implementing one or more embodiments of this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.

[0101] Those skilled in the art should understand that the embodiments of this specification can be provided as a method, a system, or a computer program product. Therefore, one or more embodiments of this specification can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, one or more embodiments of this specification can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) containing computer-usable program code.

[0102] Embodiments of this specification are described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this specification. It should be understood that each flow and / or block in the flowchart and / or block diagram, and combinations of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable serial-parallel devices for fraud cases to produce a machine, such that the instructions executed by the processors of the computer or other programmable serial-parallel devices for fraud cases produce means for implementing the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or means for implementing the functions specified in one block or multiple blocks.

[0103] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable serial-parallel device for fraud cases to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including instruction means that implement the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or means for implementing the functions specified in one block or multiple blocks.

[0104] These computer program instructions can also be loaded onto a computer or other programmable serial-parallel device for fraud cases, such that a series of operation steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or means for implementing the functions specified in one block or multiple blocks.

[0105] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.

[0106] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of computer-readable media.

[0107] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined in this article, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.

[0108] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0109] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems or computer program products. Therefore, one or more embodiments of this specification may be in the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware. Furthermore, one or more embodiments of this specification may be in the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0110] One or more embodiments of the present specification may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. One or more embodiments of the present specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.

[0111] The various embodiments in this specification are described in a progressive manner. For the same or similar parts among the various embodiments, reference can be made to each other, and the key points of each embodiment are the differences from other embodiments. In particular, for the system embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and for the relevant parts, reference can be made to the partial description of the method embodiments.

[0112] The above is only the embodiment of this specification and is not used to limit this document. For those skilled in the art, various modifications and changes can be made to this specification. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of this specification shall be included within the scope of the claims of this specification.

Claims

1. A data processing method, characterized in that: The method comprises: Receive an operation permission verification request for a target instruction in a target application; In response to the operation permission verification request, obtaining first verifiable information corresponding to the target application and first operation permission corresponding to the target instruction, wherein the first verifiable information is verifiable information generated for the operation permission information after a preset reviewer verifies and passes the operation permission information provided by the developer of the target application; Determining second verifiable information corresponding to the first operation authority, and matching the first verifiable information with the second verifiable information; When the first verifiable information and the second verifiable information match successfully, obtaining operation data corresponding to the first operation authority; The target instruction is executed according to the operation data.

2. The method according to claim 1, characterized in that The target application program includes a small program installed in a host program for executing multimedia communication services.

3. The method according to claim 2, characterized in that Before obtaining the first verifiable information corresponding to the target application, the method further includes: receiving an installation request for the target application; In response to the installation request, obtaining target data corresponding to the target application, the target data including installation data of the target application provided by the developer, and target encrypted data, the target encrypted data being data obtained by the auditor after verifying the installation data by encrypting the first verifiable information and the third verifiable information, the third verifiable information being verifiable information generated by the developer for the installation data; Decrypting the target encrypted data to obtain the first verifiable information and the third verifiable information; Determining fourth verifiable information corresponding to the installation data, and matching the third verifiable information with the fourth verifiable information; In the event that the third verifiable information and the fourth verifiable information match successfully, the target application is installed according to the installation data, and the first verifiable information is stored.

4. The method according to claim 1, characterized in that: The method further comprises: In the case where the first verifiable information and the second verifiable information fail to match, sending an operation permission acquisition request for the first operation permission to the reviewer; Upon receiving the operation permission granting instruction returned by the reviewer, obtaining the target operation permission corresponding to the operation permission granting instruction, and matching the target operation permission with the first operation permission; When the target operation permission matches the first operation permission successfully, operation data corresponding to the first operation permission is acquired, and the target instruction is executed according to the operation data.

5. The method according to claim 4, characterized in that The operation permission granting instruction includes a valid time period corresponding to the target operation permission, and executing the target instruction according to the operation data includes: During the effective time period, the target instruction is executed according to the operation data.

6. The method according to claim 5, characterized in that The method further comprises: Obtaining log data of the target application; According to the target operation permission and the corresponding valid time period, detecting whether there is any violation of permission usage during the operation of the target application; If it is detected that there is a permission violation during the operation of the target application, the execution of the instruction involving the permission violation is suspended, and preset alarm information corresponding to the instruction involving the permission violation is output.

7. A data processing device, characterized in that: The device comprises: A first receiving module is used to receive an operation permission verification request for a target instruction in a target application program; A first acquisition module, configured to acquire, in response to the operation permission verification request, first verifiable information corresponding to the target application and a first operation permission corresponding to the target instruction, wherein the first verifiable information is verifiable information generated for the operation permission information after a preset reviewer verifies the operation permission information provided by the developer of the target application; A first matching module, configured to determine second verifiable information corresponding to the first operation authority, and perform matching processing on the first verifiable information and the second verifiable information; A second acquisition module, configured to acquire operation data corresponding to the first operation authority when the first verifiable information and the second verifiable information match successfully; The first execution module is used to execute the target instruction according to the operation data.

8. An electronic device, characterized in that: The method comprises a processor, a memory and a computer program stored in the memory and executable on the processor, wherein the computer program implements the steps of the data processing method according to any one of claims 1 to 6 when executed by the processor.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the data processing method according to any one of claims 1 to 6 are implemented.

10. A computer program product, characterized in that The invention comprises a computer program, which implements the steps of the data processing method according to any one of claims 1 to 6 when being executed by a processor.