Mobile equipment sandbox area data access marking and shielding device
By adding call tracking links and visualizing data flow during IPC calls, the problem of data outflow in the sandbox area on mobile devices is solved, and the security of user-informed and controlled data sharing is achieved.
Patent Information
- Application Number
- CN202510865006.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-26
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2045-06-26
AI Technical Summary
On mobile devices, the user's privacy data is improperly shared through IPC calls in the sandbox area, resulting in data outflow, which is unaware of and cannot be blocked.
During the IPC call process, by adding call tracking links, recording and marking data owners and destinations, visual data flow is provided and users can control switches to prohibit data outflow.
Effectively identify and prevent data outflow, protect users' right to know and control, and ensure data security.
Smart Images

Figure CN120354438A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of data access control, and particularly relates to a device for marking and shielding data access in the sandbox area of a mobile device. Background Art
[0002] On a mobile device, the user's usage data is stored in the sandbox area (i.e., the software private data area). Apparently, other software is prohibited from accessing this area, but application developers themselves are allowed to share the sandbox area data of their own applications with other software. This has led to the insecurity and abuse of user privacy data, and this situation occurs without the user's knowledge or when the user knows but cannot prevent it.
[0003] A typical scenario of sandbox data outflow is: IPC call, that is, cross-process communication call. For example, a software A shares content to software B. There are private data of the application itself in the sandbox area of software A, such as username, mobile phone number, avatar, device id, serial number, etc. When the user uses the sharing function, software A combines the private data in the sandbox area into sharing data and gives it to software B for use. This has caused the sandbox data of software A to flow out to software B. Currently, the user authorizes software A to normally use the sandbox area data of this software, but software A directly provides the sandbox area data of this software for software B to use, and the user is unaware and unable to prevent it.
[0004] The above sharing function is just a typical scenario. Other scenarios such as third-party login, document editing, starting a new page, etc. may all become common scenarios of sandbox data outflow when IPC calls are used. Summary of the Invention
[0005] In view of the above technical problems, the present invention proposes a solution for marking and shielding data access in the sandbox area of a mobile device.
[0006] In a first aspect of the present invention, a device for marking and shielding data access in the sandbox area of a mobile device is proposed. The device includes a processing unit, and the processing unit is configured to execute: On the side of application software A on the intelligent device: Invoke application software B through an IPC call; Wherein, during the IPC call, the package name visitorName of application software A and the process ID visitorId of the data caller are passed in. The package name visitorName of application software A refers to the unique identifier of application software A, and the process ID visitorId of the data caller refers to the process space of application software A; On the side of application software B on the intelligent device: Initiate a data sharing process, and query all process IDs created by application software A according to the package name visitorName of application software A; Among them, all process numbers created by application software A are represented as {progressA1, progressA2, ... ,progressAn}, and progressAn represents the nth process number created by application software A; Match the process number visitorId of the data caller with all process numbers {progressA1, progressA2, ... ,progressAn} created by application software A. If a match is found, continue with the subsequent process; otherwise, terminate this process. Obtain the process number progressB of application software B itself and continue to initiate a kernel-mode system call, passing in the call parameters. Among them, the call parameters are {process number of the data owner: progressB, process number of the data caller: visitorId}, and the process number of application software B itself is used to represent the process number of the data owner. Query the dataTab data table, read the switch data corresponding to the passed-in call parameters, and determine whether to enter the kernel-mode system call process based on the switch data. Among them: when the read switch data is on, enter the kernel-mode system call process, add an external access record for the relevant data, and store the external access record in the dataTab data table; when the read switch data is off, terminate this process. Among them, application software A is the data caller, and application software B is the data owner.
[0007] According to the device of the first aspect of the present invention, during the kernel-mode system call process, copy the sandbox area data sandboxB of application software B to the process space of application software A corresponding to the process number visitorId of the data caller via the data pipeline.
[0008] According to the device of the first aspect of the present invention, during the kernel-mode system call process, the process space of application software A enters the user mode from the kernel mode, and application software A thus obtains the sandbox area data sandboxB of application software B.
[0009] According to the device of the first aspect of the present invention, the processing unit is further configured to execute: provide the dataTab data table to the system setting software on the intelligent device to visualize the data flow, and the data flow includes: application software B provides a certain number of bytes of data to application software A and the recorded data providing time.
[0010] According to the device of the first aspect of the present invention, the processing unit is further configured to execute: configure the on or off state of the switch data and update the configuration record to the dataTab data table.
[0011] A second aspect of the present invention proposes a method for marking and shielding data access in the sandbox area of a mobile device, the method comprising: On the side of application software A on the intelligent device: Invoke application software B through IPC call; Wherein, during the IPC call, the package name visitorName of application software A and the process ID visitorId of the data caller are passed in. The package name visitorName of application software A refers to the unique identifier of application software A, and the process ID visitorId of the data caller refers to the process space of application software A; On the side of application software B on the intelligent device: Initiate a data sharing process, and query all process IDs created by application software A according to the package name visitorName of application software A; Wherein, all process IDs created by application software A are represented as {progressA1, progressA2, ... ,progressAn}, and progressAn represents the nth process ID created by application software A; Match the process ID visitorId of the data caller with all process IDs {progressA1, progressA2, ... ,progressAn} created by application software A. If the match is successful, continue with the subsequent process; otherwise, terminate this process; Obtain the process ID progressB of application software B itself, and continue to initiate a kernel-mode system call, passing in call parameters; Wherein, the call parameters are {process ID of the data owner: progressB, process ID of the data caller: visitorId}, and the process ID of application software B itself represents the process ID of the data owner; Query the dataTab data table, read the switch data corresponding to the passed-in call parameters, and determine whether to enter the kernel-mode system call process according to the switch data; Wherein: when the read switch data is on, enter the kernel-mode system call process, and add an external access record for the relevant data, and store the external access record in the dataTab data table; when the read switch data is off, terminate this process; Wherein, application software A is the data caller, and application software B is the data owner.
[0012] According to the method of the second aspect of the present invention, during the core state system call process, the sandbox area data sandboxB of application software B is copied via a data pipeline to the process space of application software A corresponding to the process ID visitorId of the data caller.
[0013] According to the method of the second aspect of the present invention, during the core state system call process, the process space of application software A enters the user state from the core state, and thus application software A obtains the sandbox area data sandboxB of application software B.
[0014] According to the method of the second aspect of the present invention, the dataTab data table is provided to the system settings software on the intelligent device to visualize the data flow direction, and the data flow direction includes: application software B provides a certain number of bytes of data to application software A and the recorded data providing time.
[0015] According to the method of the second aspect of the present invention, the on or off state of the switch data is configured, and the configuration record is updated to the dataTab data table.
[0016] A third aspect of the present invention discloses an electronic device. The electronic device includes a memory and a processor. When the processor executes the computer program stored in the memory, a method for accessing and shielding the sandbox area data of a mobile device according to the second aspect of the present disclosure is implemented.
[0017] A fourth aspect of the present invention discloses a computer-readable storage medium. When the computer program stored on the computer-readable storage medium is executed by a processor, a method for accessing and shielding the sandbox area data of a mobile device according to the second aspect of the present disclosure is implemented.
[0018] In summary, in the technical solution disclosed in the present invention, a new type of call tracking link is added, including key nodes such as call initiation, user state call, core state execution, and data processing process during the IPC call execution process; the external access to the data in the sandbox area records and marks the data owner and the data destination, so as to effectively identify the above data outflow behavior; finally, these records are summarized for the user, and the user is allowed to use the device switch. When a data outflow situation occurs, this access operation is prohibited by closing the switch. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for the description of the specific embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0020] Figure 1 Schematic diagram of the data access marking and shielding process in the sandbox area of a mobile device according to an embodiment of the present invention. Detailed implementation manners
[0021] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are only a part rather than all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0022] A first aspect of the present invention proposes a data access marking and shielding device for the sandbox area of a mobile device. The device includes a processing unit, and the processing unit is configured to execute (as Figure 1 shown): On the side of application software A on the intelligent device: Invoke application software B through IPC call; Among them, during the IPC call, the package name visitorName of application software A and the process ID visitorId of the data caller are passed in. The package name visitorName of application software A refers to the unique identifier of application software A, and the process ID visitorId of the data caller refers to the process space of application software A; On the side of application software B on the intelligent device: Initiate a data sharing process, and query all the process IDs created by application software A according to the package name visitorName of application software A; Among them, all the process IDs created by application software A are represented as {progressA1, progressA2,..., progressAn}, and progressAn represents the nth process ID created by application software A; Match the process ID visitorId of the data caller with all the process IDs {progressA1, progressA2,..., progressAn} created by application software A. If the match is successful, continue with the subsequent process; otherwise, terminate this process; Obtain the process ID progressB of application software B itself and continue to initiate a kernel-mode system call, passing in the call parameters; Among them, the call parameters are {process ID of the data owner: progressB, process ID of the data caller: visitorId}, and the process ID of application software B itself is used to represent the process ID of the data owner; Query the dataTab data table, read the switch data corresponding to the passed-in call parameters, and determine whether to enter the kernel-mode system call process according to the switch data; Among them: when the read switch data is on, enter the kernel-mode system call process, add an external access record for the relevant data, and store the external access record in the dataTab data table; when the read switch data is off, terminate this process; Among them, application software A is the data caller, and application software B is the data owner.
[0023] According to the device of the first aspect of the present invention, during the kernel-mode system call process, copy the sandbox area data sandboxB of application software B to the process space of application software A corresponding to the process ID visitorId of the data caller via the data pipeline.
[0024] According to the device of the first aspect of the present invention, during the kernel-mode system call process, the process space of application software A enters the user mode from the kernel mode, and application software A thus obtains the sandbox area data sandboxB of application software B.
[0025] According to the device of the first aspect of the present invention, the processing unit is further configured to execute: provide the dataTab data table to the system setting software on the intelligent device to visualize the data flow, and the data flow includes: application software B provides a certain number of bytes of data to application software A and the recorded data providing time.
[0026] According to the device of the first aspect of the present invention, the processing unit is further configured to execute: configure the on or off state of the switch data, and update the configuration record to the dataTab data table.
[0027] The second aspect of the present invention proposes a method for marking and shielding data in the sandbox area of a mobile device, and the method includes (as Figure 1 shown): On the side of application software A on the intelligent device: Invoke application software B through IPC call; Among them, during the IPC call process, the package name visitorName of application software A and the process ID visitorId of the data caller are passed in. The package name visitorName of application software A refers to the unique identifier of application software A, and the process ID visitorId of the data caller refers to the process space of application software A; On the side of application software B on the intelligent device: Initiate a data sharing process, and query all process IDs created by application software A according to the package name visitorName of application software A; Among them, all process numbers created by application software A are represented as {progressA1, progressA2, ... ,progressAn}, and progressAn represents the nth process number created by application software A; Match the process number visitorId of the data caller with all process numbers {progressA1, progressA2, ... ,progressAn} created by application software A. If a match is found, continue with the subsequent process; otherwise, terminate this process. Obtain the process number progressB of application software B itself, and continue to initiate a kernel-mode system call, passing in the call parameters. Among them, the call parameters are {process number of the data owner: progressB, process number of the data caller: visitorId}, and the process number of application software B itself is used to represent the process number of the data owner. Query the dataTab data table, read the switch data corresponding to the passed-in call parameters, and determine whether to enter the kernel-mode system call process based on the switch data. Among them: when the read switch data is on, enter the kernel-mode system call process, add an external access record for the relevant data, and store the external access record in the dataTab data table; when the read switch data is off, terminate this process. Among them, application software A is the data caller, and application software B is the data owner.
[0028] According to the method of the second aspect of the present invention, during the kernel-mode system call process, copy the sandbox area data sandboxB of application software B to the process space of application software A corresponding to the process number visitorId of the data caller via the data pipeline.
[0029] According to the method of the second aspect of the present invention, during the kernel-mode system call process, the process space of application software A enters the user mode from the kernel mode, and application software A thus obtains the sandbox area data sandboxB of application software B.
[0030] According to the method of the second aspect of the present invention, provide the dataTab data table to the system setting software on the intelligent device to visualize the data flow, and the data flow includes: application software B provides a certain number of bytes of data to application software A and the recorded data providing time.
[0031] According to the method of the second aspect of the present invention, configure the on or off state of the switch data, and update the configuration record to the dataTab data table.
[0032] The first embodiment (such as Figure 1as shown The intelligent device application software A uses IPC call to evoke the application software B. This IPC call needs to pass in the package name of the application software A (the unique identifier of the application software) and the process ID of the current caller A, and is marked as visitorName and visitorId.
[0033] The application software B initiates a data sharing process and queries all the process IDs created by the software A according to the current visitorName. For example, if the software A currently has three processes, progressA1, progressA2, and progressA3.
[0034] Compare the visitorId with progressA1 / progressA2 / progressA3. If it belongs to one of the three, continue to execute; otherwise, terminate this process.
[0035] The application software B obtains its current process ID progressB and continues to initiate a kernel-mode system call, passing in the call parameters {the process ID of the data owner: progressB, the process ID of the data caller: visitorId}.
[0036] The application software B queries the dataTab data table, reads the record switch of this record. If it is on, it enters the kernel-mode process call and adds an external data access record to be stored in the dataTab data table; otherwise, terminate this process.
[0037] The kernel-mode process call copies the data sandboxB in the application software B to the visitorId process space through a data pipeline.
[0038] The visitorId process space enters the user mode from the kernel mode, and the application software A obtains the sandbox data sandboxB.
[0039] The intelligent device provides the content of the dataTab data table to the system settings software to display a visual page of the data flow. For example, the local record shows that the application software B provides XX bytes of data to the application software A, and the recording time is xxxx-xx-xx.
[0040] The user can click to operate the record switch to be on or off. The default is on, and it is recorded in the dataTab data table. For example, to prohibit the application software B from providing data to the application software A, modify the record switch of this item to off, and initiate the above operation process again, and no new data flow record will be generated.
[0041] A third aspect of the present invention discloses an electronic device. The electronic device includes a memory and a processor. The memory stores a computer program. When the processor executes the computer program, a method for marking and shielding data access in the sandbox area of a mobile device according to the second aspect of the present disclosure is implemented.
[0042] A fourth aspect of the present invention discloses a computer-readable storage medium. A computer program is stored on the computer-readable storage medium. When the computer program is executed by a processor, a method for marking and shielding data access in the sandbox area of a mobile device according to the second aspect of the present disclosure is implemented.
[0043] In summary, in the technical solution disclosed in the present invention, a new type of call tracing link is added, including key nodes such as call initiation, user-mode call, kernel-mode execution, and data processing during the IPC call execution process; all external accesses to data in the sandbox area record and mark the data owner and the data destination, so as to effectively identify the above data outflow behavior; finally, these records are summarized for the user, and the user is allowed to use the device switch. When a data outflow situation occurs, this access operation can be prohibited by turning off the switch. Through this device, the outflow situation of sandbox area data can be intuitively shown to the user, and a switch control is provided to allow the user to turn off this function, ensuring data security while protecting the user's right to know and right of control.
[0044] Please note that the technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification. The above embodiments only express several implementation manners of the present application, and the description thereof is relatively specific and detailed, but it should not be understood as a limitation to the scope of the invention patent. It should be pointed out that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application should be subject to the appended claims.
Claims
1. A mobile device sandbox area data access marking and shielding device, characterized in that, The device includes a processing unit configured to execute: On the side of Application A on the intelligent device: Invoke Application B through IPC call; Wherein, during the IPC call, the package name visitorName of Application A and the process ID visitorId of the data caller are passed in. The package name visitorName of Application A refers to the unique identifier of Application A, and the process ID visitorId of the data caller refers to the process space of Application A; On the side of Application B on the intelligent device: Initiate a data sharing process, and query all process IDs created by Application A according to the package name visitorName of Application A; Wherein, all process IDs created by Application A are represented as {progressA1, progressA2, ... ,progressAn}, and progressAn represents the nth process ID created by Application A; Match the process ID visitorId of the data caller with all process IDs {progressA1,progressA2, ... ,progressAn} created by Application A. If the match is successful, continue with the subsequent process; otherwise, terminate this process; Obtain the process ID progressB of Application B itself and continue to initiate a kernel-mode system call, passing in call parameters; Wherein, the call parameters are {process ID of the data owner: progressB, process ID of the data caller: visitorId}, and the process ID of Application B itself is used to represent the process ID of the data owner; Query the dataTab data table, read the switch data corresponding to the passed-in call parameters, and determine whether to enter the kernel-mode system call process according to the switch data; Wherein: when the read switch data is on, enter the kernel-mode system call process, add an external access record for the relevant data, and store the external access record in the dataTab data table; when the read switch data is off, terminate this process; Wherein, Application A is the data caller and Application B is the data owner.
2. The data access marking and shielding device for the sandbox area of a mobile device according to claim 1, characterized in that During the kernel-mode system call process, copy the sandbox area data sandboxB of Application B to the process space of Application A corresponding to the process ID visitorId of the data caller through the data pipeline.
3. The data access marking and shielding device for the sandbox area of a mobile device according to claim 2, characterized in that, During the kernel-mode system call process, the process space of Application A enters the user mode from the kernel mode, and Application A thus obtains the sandbox area data sandboxB of Application B.
4. The data access marking and shielding device for the sandbox area of a mobile device according to claim 3, characterized in that, The processing unit is further configured to execute: provide the dataTab data table to the system settings software on the intelligent device to visualize the data flow. The data flow includes: Application B provides a certain number of bytes of data to Application A and the recorded data providing time.
5. The data access marking and shielding device for the sandbox area of a mobile device according to claim 4, wherein The processing unit is further configured to execute: configure the on or off state of the switch data and update the configuration record to the dataTab data table.
6. A method for data access marking and shielding in the sandbox area of a mobile device, characterized in that, The method includes: On the side of Application A on the intelligent device: Invoke application software B through IPC call; Among them, during the IPC call, the package name visitorName of application software A and the process ID visitorId of the data caller are passed in. The package name visitorName of application software A refers to the unique identifier of application software A, and the process ID visitorId of the data caller refers to the process space of application software A; On the side of application software B on the intelligent device: Initiate a data sharing process, and query all process IDs created by application software A according to the package name visitorName of application software A; Among them, all process IDs created by application software A are represented as {progressA1, progressA2,..., progressAn}, and progressAn represents the nth process ID created by application software A; Match the process ID visitorId of the data caller with all process IDs {progressA1, progressA2,..., progressAn} created by application software A. If the match is successful, continue with the subsequent process; otherwise, terminate this process; Obtain the process ID progressB of application software B itself and continue to initiate a kernel-mode system call, passing in the call parameters; Among them, the call parameters are {process ID of the data owner: progressB, process ID of the data caller: visitorId}, and the process ID of application software B itself is used to represent the process ID of the data owner; Query the dataTab data table, read the switch data corresponding to the passed-in call parameters, and determine whether to enter the kernel-mode system call process according to the switch data; Among them: when the read switch data is on, enter the kernel-mode system call process, add an external access record for the relevant data, and store the external access record in the dataTab data table; when the read switch data is off, terminate this process; Among them, application software A is the data caller, and application software B is the data owner.
7. A method for marking and shielding data access in the sandbox area of a mobile device according to claim 6, characterized in that, During the kernel-mode system call process, copy the sandbox area data sandboxB of application software B to the process space of application software A corresponding to the process ID visitorId of the data caller through the data pipeline.
8. A method for marking and shielding data access in the sandbox area of a mobile device according to claim 7, characterized in that, During the kernel-mode system call process, the process space of application software A enters the user mode from the kernel mode, and application software A thus obtains the sandbox area data sandboxB of application software B.
9. A method for marking and shielding data access in the sandbox area of a mobile device according to claim 8, characterized in that, In the said method: Provide the dataTab data table to the system settings software on the intelligent device to visualize the data flow. The data flow includes: application software B provides a certain number of bytes of data to application software A and the recorded data providing time.
10. A method for marking and shielding data access in a sandbox area of a mobile device according to claim 9, characterized in that, In the said method: Configure the on or off state of the switch data, and update the configuration record to the dataTab data table.
Citation Information
Patent Citations
Web application sandbox safe operation environment based on centralized control model
CN114065191A
Sandbox-based data security protection method, computer equipment and storage medium
CN115481392A
Sandbox-based transformer area fusion type terminal software security detection method
CN115774872A
Application management method, device and system and shared equipment
CN116662977A
Data access permission control method and device, computer equipment and storage medium
CN117034324A