Authority management method and device, electronic equipment and storage medium
By detecting the application's permission request history and operation status, and returning real data or proxy data, the data leakage caused by users without knowingly authorization permissions is solved, and the security of electronic devices is improved.
Patent Information
- Application Number
- CN202510508707.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-22
- Publication Date
- 2025-08-01
AI Technical Summary
In the prior art, users authorize application permissions without their knowledge, resulting in personal data breach and the security of electronic devices is poor.
Return real or proxy data to prevent user personal data from being leaked by detecting the application's permission request history and request interval, as well as the operating status.
Improve the security of electronic devices and prevent user personal data from being leaked without their knowledge.
Smart Images

Figure CN120408672A_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the field of communication technology, and specifically relates to a rights management method, device, electronic device and storage medium. Background Art
[0002] Currently, in order to realize the functions in the application, the application usually applies for some permissions, such as location permission, camera permission, etc.; however, some applications may obtain the user's personal data by applying for unnecessary permissions.
[0003] In related technologies, to avoid the aforementioned issues, the aforementioned issues can be addressed by strengthening the review of app permissions when they are released to the platform, and by explicitly stating the permissions that apps use, to prevent users from authorizing unnecessary permissions. However, most users may not understand the technical terms for permissions, and as a result, they may unknowingly grant permissions to apps, leading to the leakage of their personal data and poor security for electronic devices. Summary of the Invention
[0004] The purpose of the embodiments of the present application is to provide a permission management method, device, electronic device and storage medium, which can prevent the leakage of user personal data and thus improve the security of electronic devices.
[0005] In a first aspect, an embodiment of the present application provides a permission management method, which includes: receiving a first permission request from a first application, where the first permission request is used to apply for a first permission; when the number of historical request times for the permission request for the first permission is greater than a first threshold, obtaining a first request interval for the permission request for the first permission; and returning real data or proxy data of the first permission to the first application based on the running status of the first application and the first request interval.
[0006] In a second aspect, an embodiment of the present application provides a permission management device, which includes: a receiving module, an acquisition module, and a processing module. The receiving module is used to receive a first permission request from a first application, where the first permission request is used to apply for a first permission. The acquisition module is used to obtain a first request interval of permission requests for the first permission when the number of historical request times for the permission requests for the first permission received by the receiving module is greater than a first threshold. The processing module is used to return real data or proxy data of the first permission to the first application based on the running status of the first application and the first request interval obtained by the acquisition module.
[0007] In a third aspect, an embodiment of the present application provides an electronic device comprising a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps of the method described in the first aspect are implemented.
[0008] Fourthly, an embodiment of the present application provides a readable storage medium, on which a program or instruction is stored, and when the program or instruction is executed by a processor, the steps of the method described in the first aspect are implemented.
[0009] Fifthly, an embodiment of the present application provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor, and the processor is used to run a program or instruction to implement the method described in the first aspect.
[0010] Sixthly, an embodiment of the present application provides a computer program product, which is stored in a storage medium and is executed by at least one processor to implement the method described in the first aspect.
[0011] In the embodiment of the present application, a first permission request of a first application is received, and the first permission request is used to apply for a first permission. Then, when the historical request times of the permission request of the first permission are greater than a first threshold, a first request interval of the permission request of the first permission is obtained. Finally, based on the running state of the first application and the first request interval, real data or proxy data of the first permission is returned to the first application. In this solution, since an application generally calls permissions frequently in the background to obtain user privacy data when obtaining user privacy data, by detecting whether the first request interval is less than a preset request interval and detecting whether the running state of the first application is foreground running, it is determined whether to return real data or proxy data to the first application. It can be understood that when the running state of the first application is foreground running and the first request interval is less than the preset request interval, if the user grants the first application permission, the permission data returned by the electronic device to the first application is also proxy data, that is, virtual data. In this way, even if the user grants the application permission without knowing it, the user's personal data will not be leaked, thereby improving the security of the electronic device. Description of the Drawings
[0012] Figure 1 is one of the flowcharts of a permission management method provided by an embodiment of the present application;
[0013] Figure 2 is another flowchart of a permission management method provided by an embodiment of the present application;
[0014] Figure 3 is yet another flowchart of a permission management method provided by an embodiment of the present application;
[0015] Figure 4 is still another flowchart of a permission management method provided by an embodiment of the present application;
[0016] Figure 5It is the fifth flowchart of a permission management method provided by an embodiment of the present application;
[0017] Figure 6 It is the sixth flowchart of a permission management method provided by an embodiment of the present application;
[0018] Figure 7 It is the seventh flowchart of a permission management method provided by an embodiment of the present application;
[0019] Figure 8 It is the structural schematic diagram of a permission management device provided by an embodiment of the present application;
[0020] Figure 9 It is one of the hardware structural schematic diagrams of an electronic device provided by an embodiment of the present application;
[0021] Figure 10 It is the second hardware structural schematic diagram of an electronic device provided by an embodiment of the present application. Specific embodiments
[0022] Next, the technical solutions in the embodiments of the present application will be clearly described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art belong to the scope of protection of the present application.
[0023] The terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects, rather than to describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first", "second", etc. generally belong to the same category, and the number of objects is not limited. For example, the first object can be one or more. In addition, "and / or" in the specification and claims means at least one of the connected objects, and the character " / " generally means an "or" relationship between the associated objects before and after.
[0024] The terms "at least one (item)", "at least one of", etc. in the specification and claims of the present application refer to any one, any two or more combinations of the objects they contain. For example, at least one (item) of a, b, and c can represent: "a", "b", "c", "a and b", "a and c", "b and c", and "a, b, and c", where a, b, and c can be single or multiple. Similarly, "at least two (items)" refers to two or more, and its meaning is similar to that of "at least one (item)".
[0025] The following provides a specific explanation of the professional terms provided in the embodiments of this application.
[0026] Proxy data: Proxy data refers to the use of solidified data or forged data to close the business logic of an application without making an application request to disturb the user after the user clearly rejects the permission request of the application.
[0027] Permission: Permission refers to the right of a specific application to use specific system resources. Permissions mainly solve two problems: authentication (who you are) and authorization (what you can do). In the management of a multi-user computer system, permission refers to the right of a specific application to use specific system resources, such as folders, the use of specific system instructions, or storage limits. Usually, the system administrator, or the network administrator in a network, assigns different permissions to applications for the use of a specific resource, and the system software automatically enforces these permissions.
[0028] Permission request: In software development, a permission request is a request made by an application to the operating system or other control entity to obtain the ability to perform a specific operation. Permission request in the Android system: In the Android system, the permission request is an important mechanism to ensure user privacy and application security. Android divides permissions into two categories: normal permissions and dangerous permissions. Normal permissions usually involve operations that have less impact on user privacy, such as accessing the network, while dangerous permissions involve user personal data or sensitive operations, such as accessing contacts or location information. When an application needs to use a dangerous permission, it must request authorization from the user at runtime, and the user can change the permissions of the application at any time in the settings.
[0029] Privacy data: Privacy data refers to the right of an individual or organization to keep the data they own or control private and confidential. This data can include personal identity information, financial information, medical information, social media activities, emails, communication records, location data, etc.
[0030] Timestamp: A timestamp is a character sequence used to record the time when data is generated and is commonly used to verify the originality of a file and manage caches. A timestamp is a data type that can represent a specific point in time. In computer science, a timestamp usually refers to the number of seconds or milliseconds elapsed from January 1, 1970, 00:00:00 UTC (Coordinated Universal Time) to a specific point in time. This starting point is called the "Unix epoch" or "Epoch", so this type of timestamp is also called a Unix timestamp. The value of a timestamp is an ever-increasing number, which can be used to represent the order in which events occur and serve as a unified time reference in different computer systems and network communications.
[0031] The following, in conjunction with the accompanying drawings, describes in detail the rights management method, device, electronic device, storage medium and program product provided in the embodiments of the present application through specific embodiments and their application scenarios.
[0032] Currently, the use of permissions in electronic devices is plagued by issues such as abuse, excessive openness, and excessive user authorization. App developers may obtain user personal data by requesting unnecessary permissions.
[0033] When using apps, users often request many unnecessary permissions, leading to information leakage and even the risk of fraud and personal information exposure. To increase the chances of permission approval, apps frequently request permissions from users, disrupting their normal use. Even after users grant permissions, apps frequently access user data and upload it to the server backend, potentially leaking user data.
[0034] Existing permission management solutions obtain user authorization by strengthening the review of app permission requests when apps are launched on the platform and increasing explicit disclosure of app permissions. However, users often struggle to understand many of the system's technical terms, and many app functions are tied to permission requests. Users who disagree with permission are unable to use the app's features. Some apps frequently pop up inquiry boxes, even after users explicitly deny permission, asking for permission. This allows users to obtain permissions without their knowledge and frequently access personal data, such as location information and contact information, during use. This can lead to the leakage of users' personal information.
[0035] The permission management method, apparatus, electronic device, and storage medium provided in the embodiments of the present application can be applied to scenarios where an electronic device returns permission request data. Specifically, the electronic device can receive a permission request from an application and return the data corresponding to the permission request to the application. For example, the permission request can be a location permission request, a contact permission request, a storage permission request, etc.
[0036] For example, a navigation application applies for location permission, and the electronic device returns the geographic location to the navigation application, such as scenario 1.
[0037] Scenario 1: When a user needs navigation and triggers the electronic device to run the navigation application, the navigation application will display a request for location permission information in the foreground. If the user agrees to grant the navigation application location permission, the navigation application can obtain the user's real geographical location based on the location permission and provide navigation for the user. However, after the user no longer needs navigation and exits the navigation application, the navigation application may still be running in the background. Since the user has already granted the navigation application location permission, the navigation application may frequently call the location permission in the background. As a result, the navigation application may learn about the user's real-time dynamics based on the user's real-time geographical location information, infringing on the user's personal privacy.
[0038] Exemplarily, take the camera application applying for storage permission and the electronic device returning images in the album application to the camera application as an example, such as Scenario 2.
[0039] Scenario 2: When a user needs to take a photo or video using the electronic device and triggers the electronic device to run the camera application, the camera application will display a request for storage permission information in the foreground. If the user agrees to grant the storage permission, the camera application can store the captured images or videos in the album application. However, after the user finishes taking photos or videos, the camera application may still be running in the background. Since the user has already granted the camera application storage permission, the camera application may frequently call the storage permission in the background, thereby obtaining all the stored images in the album application and infringing on the user's personal privacy.
[0040] Exemplarily, take the video application applying for microphone permission and the user refusing to grant the video application microphone permission as an example, such as Scenario 3.
[0041] Scenario 3: When a user needs to watch a movie using the video application and triggers the electronic device to run the video application, the video application will display a request for microphone permission information in the foreground. If the user does not agree to grant the video application microphone permission at this time, the video application will frequently pop up to display the request for microphone permission information, affecting the user experience; or, the video application will directly exit the operation. The user must agree to grant the video application microphone permission in order to use the video application. If the user agrees to grant the video application microphone permission, it may also result in the leakage of the user's privacy data.
[0042] In this solution, when an application obtains user privacy data, it generally calls permissions frequently in the background to obtain user privacy data. Therefore, by detecting whether the first request interval is less than a preset request interval and detecting whether the running state of the first application is foreground running, it is determined whether to return real data or proxy data to the first application. It can be understood that when the running state of the first application is foreground running and the first request interval is less than the preset request interval, if the user grants the first application permission, the permission data returned by the electronic device to the first application is also proxy data, that is, virtual data. In this way, even if the user grants the application permission without knowing it, the user's personal data will not be leaked, thus improving the security of the electronic device.
[0043] The execution subject of the permission management method provided by the embodiments of the present application may be a permission management device, and this permission management device may be an electronic device or a functional module in the electronic device. Hereinafter, taking the electronic device as an example, the technical solution provided by the embodiments of the present application will be described.
[0044] The embodiments of the present application provide a permission management method. Figure 1 The flowchart of a permission management method provided by the embodiments of the present application is shown. As Figure 1 shown, the permission management method provided by the embodiments of the present application may include the following steps 201 to step 203.
[0045] Step 201: The electronic device receives a first permission request from a first application.
[0046] In the embodiments of the present application, the above first permission request is used to apply for a first permission.
[0047] Optionally, in the embodiments of the present application, the above first application may be any one of all the applications included in the electronic device.
[0048] Exemplarily, the above first application includes but is not limited to any one of the following: navigation application, camera application, album application, video application, instant messaging application, etc. It can be specifically determined according to actual usage requirements, and the embodiments of the present application do not make limitations.
[0049] Optionally, in the embodiments of the present application, the above first permission includes but is not limited to any one of the following: location permission, storage permission, microphone permission, or network permission, etc. It can be specifically determined according to actual usage requirements, and the embodiments of the present application do not make limitations.
[0050] Optionally, in the embodiments of the present application, the above first permission request may carry an application identifier of the first application, and this application identifier is used to uniquely identify the first application. In this way, the electronic device can determine the initiator of the first permission request, that is, the first application, according to this first permission request.
[0051] Optionally, in the embodiments of the present application, the above application identifier may be any one of the following: a text identifier, a numeric identifier, or a special symbol identifier. Specifically, it may be determined according to actual usage requirements, and the embodiments of the present application do not make any restrictions.
[0052] Exemplarily, the above text identifier may be the application name or application package name of the first application.
[0053] Exemplarily, the above numeric identifier may be a random number or a Universally Unique Identifier (UUID).
[0054] Optionally, in the embodiments of the present application, when the first application requests the first permission, the first application may send a first permission request to the Central Processing Unit (CPU) in the electronic device through a process or a thread. The first permission request carries the UUID of the first application, so that the CPU can determine that the first permission request is sent by the first application according to the UUID.
[0055] In one example, in combination with the above Scenario 1, taking the electronic device as a mobile phone as an example, when the navigation application requests the location permission, the navigation application may send a location permission request to the CPU in the mobile phone through a thread. The UUID carried by the location permission request is 16235645641, and this UUID is used to uniquely identify the navigation application. When the CPU receives the location permission request, it can determine that the location permission request comes from the navigation application according to the UUID.
[0056] In another example, in combination with the above Scenario 2, when the camera application requests the storage permission, the camera application may send a storage permission request to the CPU in the mobile phone through a thread. The UUID carried by the storage permission request is 165645614564897, and this UUID is used to uniquely identify the camera application. When the CPU receives the storage permission request, it can determine that the storage permission request comes from the camera application according to the UUID.
[0057] Optionally, in the embodiments of the present application, after the electronic device receives the first permission request of the first application, the electronic device may display the specific content of the first permission request through a pop-up window, so that the user can agree to authorize the first permission request or reject authorizing the first permission request.
[0058] In one example, in combination with the above-mentioned Scenario 1, taking the first permission request as a location permission request as an example, when the CPU in the mobile phone determines that the location permission request comes from a navigation application and the navigation application is running in the foreground, the mobile phone can display a pop-up window in the application interface of the navigation application. The pop-up window includes "Request to use location permission. Do you agree?", an agree control, and a reject control. Then, if the user clicks on the agree control, the mobile phone can determine that the user agrees to authorize the location permission. If the user clicks on the reject control, the mobile phone can determine that the user refuses to authorize the location permission.
[0059] In another example, in combination with the above-mentioned Scenario 2, taking the first permission request as a storage permission request as an example, when the CPU in the mobile phone determines that the storage permission request comes from a camera application and the camera application is running in the foreground, the mobile phone can display a pop-up window in the application interface of the camera application. The pop-up window includes "Request to use storage permission. Do you agree?", an agree control, and a reject control. Then, if the user clicks on the agree control, the mobile phone can determine that the user agrees to authorize the storage permission. If the user clicks on the reject control, the mobile phone can determine that the user refuses to authorize the storage permission.
[0060] Step 202: When the historical request count of the permission request for the first permission is greater than the first threshold, the electronic device obtains the first request interval of the permission request for the first permission.
[0061] Optionally, in the embodiments of the present application, the above-mentioned first threshold can be preset by the electronic device; or, the above-mentioned first threshold can be user-defined. It can be specifically determined according to actual usage requirements, and the embodiments of the present application do not make any restrictions.
[0062] Exemplarily, the above-mentioned first threshold can be any one of the following: 2, 3, 4, etc. It can be specifically determined according to actual usage requirements, and the embodiments of the present application do not make any restrictions.
[0063] For example, the electronic device can count the historical request count of the permission request for the first permission. Thus, when the historical request count is greater than 2, the electronic device can obtain the first request interval of the permission request for the first permission.
[0064] Optionally, in the embodiments of the present application, the electronic device can obtain the historical request count of the permission request for the first permission through a counter.
[0065] Optionally, in the embodiments of the present application, the above-mentioned counter can be an increment counter or a decrement counter. It can be specifically determined according to actual usage requirements, and the embodiments of the present application do not make any restrictions.
[0066] It can be understood that when the historical request times of the permission request for the first permission are less than or equal to the first threshold, the electronic device can follow the permission request process in the prior art. That is, when the electronic device receives a first permission request and the user agrees to authorize the first permission, the electronic device can return the real data corresponding to the first permission for the first permission request.
[0067] It should be noted that the first request interval of the permission request for the electronic device to obtain the first permission can be found in the following embodiments. To avoid repetition, it will not be elaborated here.
[0068] Optionally, in the embodiments of the present application, in combination with Figure 1 , such as Figure 2 shown, the above step 202 can be specifically implemented by the following step 202a.
[0069] Step 202a: When the permission status of the first permission is the authorized status and the historical request times of the permission request for the first permission are greater than the first threshold, the electronic device obtains the first request interval.
[0070] Optionally, in the embodiments of the present application, the electronic device can determine that the permission status of the first permission is the authorized status according to the user's input to the above consent authorization control; or, the electronic device can determine that the permission status of the first permission is the authorized status according to the permission status stored in the first application.
[0071] Exemplarily, in combination with the above scenario 1, for the permission status stored in the first application, taking the first application as a navigation application and the first permission as a positioning permission as an example, the electronic device can store the permission status of the navigation application in the form of key-value pairs, as shown in Table 1.
[0072] Table 1
[0073]
[0074] In the embodiments of the present application, only when the electronic device determines that the permission status is the authorized status and the historical request times of the permission request for the first permission are greater than the first threshold, the electronic device can obtain the first request interval, and thus determine whether to return the real data or proxy data corresponding to the first permission to the first application according to the first request interval, improving the flexibility of the electronic device to return the data corresponding to the first permission.
[0075] Step 203: The electronic device returns the real data or proxy data of the first permission to the first application based on the running state of the first application and the first request interval.
[0076] Optionally, in the embodiments of the present application, the above running state can be foreground running or background running.
[0077] Optionally, in the embodiments of the present application, the above proxy data may be randomly generated by the electronic device; or, the electronic device downloads it from the network by itself.
[0078] Exemplarily, for different permissions, the above proxy data may be as shown in Table 2 below.
[0079] Table 2
[0080]
[0081]
[0082] In one example, in combination with the above Scenario 1, when the above first permission is the location permission, the above proxy data may be a geographical location coordinate containing longitude and latitude randomly generated by the electronic device.
[0083] In another example, in combination with the above Scenario 2, when the above first permission is the storage permission, the above proxy data may be a picture containing a cat downloaded by the electronic device from the network by itself.
[0084] Optionally, in the embodiments of the present application, the electronic device may return the real data or proxy data of the first permission to the first application through a process or a thread.
[0085] In one example, in combination with the above Scenario 1, the CPU in the mobile phone may return the real geographical address information or virtual geographical address information corresponding to the location permission, the above proxy data, to the navigation application through a thread.
[0086] In another example, in combination with the above Scenario 2, the CPU in the mobile phone may return the real image or virtual image corresponding to the storage permission, that is, the above proxy data, to the camera application through a thread.
[0087] It should be noted that the above image is a macroscopic image, that is, the image may include pictures or videos.
[0088] Exemplarily, the above pictures may include at least one of the following: emoji pictures, animated pictures, pictures of people, pictures of animals, pictures of landscapes, etc. It can be specifically determined according to actual usage requirements, and the embodiments of the present application do not make limitations.
[0089] In the permission management method provided by the embodiments of the present application, an electronic device may receive a first permission request from a first application, where the first permission request is used to apply for a first permission. Then, when the historical request count of the permission request for the first permission is greater than a first threshold, the electronic device obtains a first request interval of the permission request for the first permission. Finally, based on the running state of the first application and the first request interval, the electronic device returns real data or proxy data of the first permission to the first application. In this solution, since an application generally frequently calls permissions in the background to obtain user privacy data when obtaining user privacy data, by detecting whether the first request interval is less than a preset request interval and detecting whether the running state of the first application is foreground running, it is determined whether to return real data or proxy data to the first application. It can be understood that when the running state of the first application is foreground running and the first request interval is less than the preset request interval, if the user grants the first application permission, the permission data returned by the electronic device to the first application is also proxy data, that is, virtual data. In this way, even if the user grants the application permission without knowing it, the user's personal data will not be leaked, thereby improving the security of the electronic device.
[0090] Optionally, in the embodiments of the present application, in combination with Figure 1 , as Figure 3 shown, the "electronic device obtains a first request interval of the permission request for the first permission" in step 202 above can be specifically implemented by the following steps 301 and 302.
[0091] Step 301: The electronic device calculates a historical request interval between two adjacent historical permission requests based on the request timestamps corresponding to the historical permission requests for the first permission.
[0092] Optionally, in the embodiments of the present application, the electronic device may record the system time of each historical permission request for the first permission, so as to obtain the request timestamp corresponding to each historical permission request for the first permission.
[0093] Optionally, in the embodiments of the present application, the electronic device may perform a subtraction operation on the request timestamps between all adjacent two historical permission requests for the first permission, so as to obtain the historical request intervals between all adjacent two historical permission requests.
[0094] Example 1, in combination with the above scenario 1, assuming that the navigation permission request is currently the fourth permission request, for the above first permission request, the timestamp of the first permission request is 10:53, the timestamp of the second permission request is 10:55, and the timestamp of the third permission request is 11:00. Then the historical request interval between the first permission request and the second permission request is 2 minutes, and the historical request interval between the second permission request and the third permission request is 5 minutes.
[0095] Step 302: The electronic device determines a first request interval based on the historical request interval and the second request interval.
[0096] In the embodiments of the present application, the second request interval is the request interval between the first permission request and the second permission request; the second permission request is the permission request of the previous first permission of the first permission request.
[0097] Optionally, in the embodiments of the present application, the electronic device may calculate the second request interval through the timestamps between the first permission request and the second permission request.
[0098] Example 2: Combining the above Example 1, assuming that the timestamp of the fourth permission request for the navigation permission request is 11:10, then the request interval between the fourth permission request and the third permission request is 10 minutes.
[0099] Optionally, in the embodiments of the present application, the electronic device may start from the request interval between the first two adjacent historical permissions, calculate the first average value between the request intervals of the first two adjacent historical permissions, and calculate the second average value between the first average value and the request interval of the next adjacent historical permission; until calculating the third average value between the request interval of the penultimate request interval and the request interval of the last historical permission among all the historical permission request intervals; finally, calculate the average value between the third average value and the second request interval to obtain the first request interval.
[0100] Exemplarily, combining the above Example 1 and Example 2, the mobile phone obtains 3 request intervals, and the 3 request intervals are respectively: 2 minutes, 5 minutes, and 10 minutes; at this time, the mobile phone may calculate the average value of the first request interval of 2 minutes and the second request interval of 5 minutes to obtain an average value of 3.5 minutes; calculate the average value of the 3.5 minutes and the third request interval of 10 minutes to obtain an average value of 6.75 minutes, and use the average value of 6.75 minutes as the first request interval.
[0101] Optionally, in the embodiments of the present application, the electronic device may accumulate and average the historical request intervals and the second request interval between all adjacent historical permission requests to obtain the first average request interval of the historical permission requests of the first permission, and use the first average request interval as the first request interval.
[0102] Exemplarily, combining the above Example 1 and Example 2, the mobile phone obtains 3 request intervals, and the 3 request intervals are respectively: 2 minutes, 5 minutes, and 10 minutes; at this time, the mobile phone may accumulate and average these request intervals, that is, (2 + 5 + 10) / 3, to obtain an average value of 5.6 minutes, and use the average value of 5.6 minutes as the first request interval.
[0103] Optionally, in the embodiments of the present application, after obtaining the above average value of 6.75 minutes or the average value of 5.6 minutes, the electronic device may divide the average value of 6.75 minutes or the average value of 5.6 minutes by a predetermined coefficient to obtain the above first request interval.
[0104] Optionally, in the embodiments of the present application, the above predetermined coefficient may be preset by the electronic device; or, the above predetermined coefficient may be user-defined. It can be specifically determined according to actual usage requirements, and the embodiments of the present application do not limit it.
[0105] Exemplarily, the above predetermined coefficient may be 4, 5, 6, etc. It can be specifically determined according to actual usage requirements, and the embodiments of the present application do not limit it.
[0106] For example, taking the above predetermined coefficient as 4 and the above average value as 6.75 minutes as an example, the mobile phone can perform a division operation on the average value of 6.75 and the predetermined coefficient 4 to obtain 1.68 minutes, and then use the 1.68 minutes as the above first request interval.
[0107] For example, taking the above predetermined coefficient as 4 and the above average value as 5.6 minutes as an example, the mobile phone can perform a division operation on the average value of 5.6 and the predetermined coefficient 4 to obtain 1.4 minutes, and then use the 1.4 minutes as the above first request interval.
[0108] For example, the electronic device can calculate the first request interval through the following formula (1), and the formula (1) is specifically:
[0109]
[0110] where f(t) is the first request interval, t n is the timestamp of the first permission request, t n-1 is the timestamp of the second permission request, t n-2 is the timestamp of the previous permission request before the second permission request.
[0111] In this way, by dividing the calculated average value by a predetermined coefficient, the electronic device can ensure that the first request interval is always convergent, thereby avoiding the first permission from frequently obtaining data.
[0112] In the embodiments of the present application, the electronic device calculates the first request interval, so as to determine whether the first request interval is less than the preset request interval. Furthermore, when the first request interval is less than the preset request interval, if the user grants the first application permission, the permission data returned by the electronic device to the first application is also proxy data; in this way, even if the user grants the application permission without knowing it, the user's personal data will not be leaked, thereby improving the security of the electronic device.
[0113] Optionally, in the embodiments of the present application, in combination with Figure 1 , such as Figure 4 shown, the above step 203 can be specifically implemented by the following step 203a or step 203b.
[0114] Step 203a: When the running state of the first application and the first request interval meet the first condition, the electronic device returns the real data of the first permission to the first application.
[0115] Optionally, in the embodiments of the present application, the above first condition includes: the running state of the first application is foreground running and the first request interval is greater than or equal to the first threshold; or, the running state of the first application is background running and the first request interval is greater than or equal to the second threshold, where the second threshold is the product of the average request interval of the first permission and the first predetermined multiple.
[0116] Optionally, in the embodiments of the present application, the electronic device can determine whether the first application is in the foreground running or the background running according to the first value in the life cycle callback interface of the first application.
[0117] Exemplarily, when the electronic device detects that the first value in the life cycle callback interface of the first application is 1, the electronic device can determine that the first application is in the foreground running; when the electronic device detects that the first value in the life cycle callback interface of the first application is 0, the electronic device can determine that the first application is in the background running.
[0118] Optionally, in the embodiments of the present application, the above first threshold can be preset by the electronic device; or, the above first threshold can be user-defined. It can be specifically determined according to the actual usage requirements, and the embodiments of the present application do not make limitations.
[0119] Exemplarily, the above first threshold can be 1, 2, 3, etc. It can be specifically determined according to the actual usage requirements, and the embodiments of the present application do not make limitations.
[0120] It should be noted that the unit of the above first threshold is minutes.
[0121] Optionally, in the embodiments of the present application, the above first predetermined multiple can be preset by the electronic device; or, the above first predetermined multiple can be user-defined. It can be specifically determined according to the actual usage requirements, and the embodiments of the present application do not make limitations.
[0122] Exemplarily, the above first predetermined multiple can be 1, 2, 3, etc. It can be specifically determined according to the actual usage requirements, and the embodiments of the present application do not make limitations.
[0123] For example, in combination with the above scenario 1, when the mobile phone determines that the running state of the navigation application is foreground running and the first request interval is 1.68, the mobile phone can compare the first request interval with the first threshold 1 to determine that the first request interval is greater than the first threshold 1; at this time, the mobile phone can return the real geographical location information of the positioning permission to the navigation application.
[0124] For example, in combination with the above scenario 1, when the mobile phone determines that the running state of the navigation application is background running and the first request interval is 20 minutes, the mobile phone can compare the first request interval with the second threshold 16.8 to determine that the first request interval is greater than the second threshold 16.8; at this time, the mobile phone can return the real geographical location information of the positioning permission to the navigation application, where the second threshold is obtained by multiplying the average request interval 5.6 of the first permission request by the first predetermined multiple 3.
[0125] Optionally, in the embodiments of the present application, the electronic device can return the real data of the first permission to the first application when the first application is foreground running and the first request interval is greater than or equal to the first threshold, and the first request interval is greater than or equal to the average request interval of the first permission.
[0126] Optionally, in the embodiments of the present application, the electronic device can return the real data of the first permission to the first application when the first application is background running and the first request interval is greater than or equal to the first threshold, and the first request interval is greater than or equal to the second threshold.
[0127] Optionally, in the embodiments of the present application, when the running state of the first application, the screen state of the electronic device, and the first request interval meet the third condition, the electronic device returns the real data of the first permission to the first application.
[0128] Exemplarily, when the first application is foreground running and the screen state of the electronic device is the user touch screen state, and the first request interval is greater than or equal to the first threshold, and the first request interval is greater than or equal to the average request interval of the first permission, the electronic device can return the real data of the first permission to the first application; or, when the first application is foreground running and the screen state of the electronic device is the non-user touch screen state, and the first request interval is greater than or equal to the first threshold, and the first request interval is greater than or equal to the third threshold, the electronic device can return the real data of the first permission to the first application; where the third threshold is obtained by multiplying the average request interval of the first permission request by the third predetermined multiple.
[0129] Optionally, in the embodiments of the present application, the above third predetermined multiple can be preset by the electronic device or user-defined. It can be specifically determined according to actual usage requirements, and the embodiments of the present application do not make limitations.
[0130] Exemplarily, the above-mentioned third predetermined multiple may be 1, 2, 3, etc. It can be specifically determined according to actual usage requirements, and the embodiments of the present application do not limit it.
[0131] For example, the above-mentioned third threshold value can be obtained by multiplying the average request interval of 5.6 minutes of the first permission request by the third predetermined multiple of 2, resulting in a third threshold value of 11.2 minutes.
[0132] Step 203b, when the running state of the first application and the first request interval meet the second condition, the electronic device returns the proxy data of the first permission to the first application.
[0133] Optionally, in the embodiments of the present application, the above-mentioned second condition includes: the running state of the first application is running in the background and the first request interval is less than the first threshold; or, the running state of the first application is running in the background and the first request interval is less than the second threshold.
[0134] For example, in combination with the above scenario 1, when the mobile phone determines that the running state of the navigation application is running in the foreground and the first request interval is 0.68, the mobile phone can compare the first request interval with the first threshold of 1, so as to determine that the first request interval is less than the first threshold of 1; at this time, the mobile phone can return false geographical location information of the positioning permission to the navigation application.
[0135] For example, in combination with the above scenario 1, when the mobile phone determines that the running state of the navigation application is running in the background and the first request interval is 10 minutes, the mobile phone can compare the first request interval with the second threshold of 16.8, so as to determine that the first request interval is less than the second threshold of 16.8; at this time, the mobile phone can return false geographical location information of the positioning permission to the navigation application.
[0136] Optionally, in the embodiments of the present application, when the first application is running in the foreground and the first request interval is greater than or equal to the first threshold and less than the average request interval of the first permission, the electronic device can return the proxy data of the first permission to the first application.
[0137] Optionally, in the embodiments of the present application, when the first application is running in the background and the first request interval is greater than or equal to the first threshold and less than the second threshold, the electronic device can return the proxy data of the first permission to the first application.
[0138] Optionally, in the embodiments of the present application, when the running state of the first application, the screen state of the electronic device and the first request interval meet the fourth condition, the electronic device returns the proxy data of the first permission to the first application.
[0139] Exemplarily, when the first application is running in the foreground, the screen state of the electronic device is the user touch screen state, the first request interval is greater than or equal to the first threshold, and the first request interval is less than the average request interval of the first permission, the electronic device may return the proxy data of the first permission to the first application; or, when the first application is running in the foreground and the screen state of the electronic device is the non-user touch screen state, the first request interval is greater than or equal to the first threshold, and the first request interval is less than the third threshold, the electronic device may return the proxy data of the first permission to the first application.
[0140] In the embodiments of the present application, by determining the application state of the first application and the magnitudes of the first request interval and the predetermined threshold, the electronic device can determine whether the current first application is frequently obtaining the data corresponding to the permission, so as to determine whether to return the proxy data or the real data of the first permission to the first application, avoiding the leakage of the user's personal data, thereby improving the security of the electronic device.
[0141] Optionally, in the embodiments of the present application, in combination with Figure 1 , as Figure 5 shown, the above step 203 may be specifically implemented by the following step 203c.
[0142] Step 203c: The electronic device returns the real data or the proxy data of the first permission to the first application based on the running state of the first application, the first request interval, and the second request interval.
[0143] In the embodiments of the present application, the above second request interval is the request interval between the first permission request and the second permission request, and the second permission request is the historical permission request of the previous first permission of the first permission request.
[0144] Optionally, in the embodiments of the present application, the above first condition further includes: the first request interval is greater than or equal to the second request interval.
[0145] In one example, the above first condition may be: when the first application is running in the foreground, the first request interval is greater than or equal to the first threshold, and the first request interval is greater than or equal to the average request interval of the first permission, if the first request interval is greater than or equal to the second request interval, the electronic device returns the real data of the first permission to the first application.
[0146] In another example, the above first condition may be: when the first application is running in the foreground and the screen state of the electronic device is the user touch screen state, the first request interval is greater than or equal to the first threshold, and the first request interval is greater than or equal to the average request interval of the first permission, if the first request interval is greater than or equal to the second request interval, the electronic device returns the real data of the first permission to the first application.
[0147] In yet another example, the above first condition may be: when the first application is running in the background, the first request interval is greater than or equal to the first threshold, and the first request interval is greater than or equal to the second threshold, if the first request interval is greater than or equal to the second request interval, the electronic device returns the real data of the first permission to the first application.
[0148] Optionally, in the embodiments of the present application, the above second condition further includes: the first request interval is less than the second request interval.
[0149] In one example, the above first condition may be: when the first application is running in the foreground, the first request interval is greater than or equal to the first threshold, and the first request interval is greater than or equal to the average request interval of the first permission, if the first request interval is less than the second request interval, the electronic device returns the proxy data of the first permission to the first application.
[0150] In another example, the above first condition may be: when the first application is running in the foreground and the screen state of the electronic device is the user touch screen state, the first request interval is greater than or equal to the first threshold, and the first request interval is greater than or equal to the average request interval of the first permission, if the first request interval is less than the second request interval, the electronic device returns the proxy data of the first permission to the first application.
[0151] In yet another example, the above first condition may be: when the first application is running in the background, the first request interval is greater than or equal to the first threshold, and the first request interval is greater than or equal to the second threshold, if the first request interval is less than the second request interval, the electronic device returns the proxy data of the first permission to the first application.
[0152] In the embodiments of the present application, the electronic device can comprehensively judge whether to return the proxy data or the real data of the first permission to the first application by combining the application state of the first application, the first request interval, and the second request interval, improving the accuracy of the electronic device in determining the proxy data or the real data.
[0153] Optionally, in the embodiments of the present application, in combination with Figure 1 , as Figure 6 shown, the permission management method provided by the embodiments of the present application further includes the following step 401.
[0154] Step 401: When the permission state of the first permission is the unauthorized state, the electronic device returns the proxy data of the first permission to the first application.
[0155] Optionally, in the embodiments of the present application, the electronic device may determine that the permission status of the first permission is an unauthorized status according to the user's input to the above-mentioned rejection authorization control; alternatively, the electronic device may determine that the permission status of the first permission is an unauthorized status according to the permission status stored in the first application.
[0156] It should be noted that the execution timing of the above step 401 may be after step 201, or the execution timing of the above step 401 may be after step 203, which can be specifically determined according to actual usage requirements, and the embodiments of the present application do not make any restrictions. Exemplarily, as Figure 6 shown, the execution timing of the above step 401 may be after step 201.
[0157] It can be understood that in the case where the permission status of the first permission is an unauthorized status, the electronic device returns the proxy data of the first permission to the first application, which can avoid the phenomenon that some functions of some applications in the electronic device cannot be used when they do not obtain the data corresponding to the permission, as well as the frequent pop-up of authorization information.
[0158] It should be noted that the above embodiments only explain the permission management process of one permission. For the permission management processes of other permissions in the electronic device, they can all be implemented through the above embodiments. To avoid repetition, they will not be elaborated here.
[0159] Exemplarily, as Figure 7 shown, the permission management method provided by the embodiments of the present application will be specifically explained below, which can be specifically implemented through the following steps 20 to 40.
[0160] Step 20: The permission service in the electronic device applies for location permissions for each application in the electronic device and stores the status of the location permissions in the form of key-value pairs.
[0161] It should be noted that for the specific status of the location permissions, reference can be made to Table 1 above.
[0162] Step 21: The permission service in the electronic device can set proxy data for each permission.
[0163] It should be noted that for the proxy data set by the permission service in the electronic device for the location permissions, reference can be made to Table 2 above.
[0164] Step 22: When the user uses the navigation application, the navigation application applies to the CPU in the electronic device for location permissions. The permission service checks that the location permission authorization status value of the navigation application is 0 and displays a pop-up window in the navigation application.
[0165] Step 23: The electronic device determines whether to grant the location permissions.
[0166] In an embodiment of the present application, the pop-up window includes "whether to agree that the navigation application uses the location permission", an agree button, and a reject button; if the user selects the agree button, the electronic device determines to grant the location permission and executes step 24; if the user selects the reject button, the electronic device determines not to grant the location permission and executes step 40.
[0167] Step 24: The electronic device updates the authorization status of the location permission to 1.
[0168] Step 25: When the user uses the navigation application in the foreground and the navigation application obtains the user's location information for the first time through the location permission, the electronic device records the permission request time of the current navigation application. The location service checks that the authorization status value of the location permission is 1 and returns the real location to the navigation application.
[0169] Step 26: When the user uses the navigation application in the foreground and the navigation application obtains the user's location information for the second time through the location permission, the electronic device records the permission request time of the current navigation application. The location service checks that the authorization status value of the location permission is 1 and returns the real location to the navigation application.
[0170] Step 27: When the user uses the navigation application in the foreground and the navigation application obtains the user's location information for the third time through the location permission, the electronic device records the permission request time of the current navigation application, and calculates the first request interval, the average request interval, and the second request interval of the location permission.
[0171] In an embodiment of the present application, the specific process of calculating the first request interval, the average request interval, and the second request interval can be found in the above embodiments in detail. To avoid repetition, it will not be elaborated here.
[0172] Step 28: When the navigation application is running in the foreground, the screen state of the electronic device is the user touch state, and the first request interval is greater than or equal to 1, and the first request interval is greater than or equal to the average request interval, and the first request interval is greater than or equal to the second request interval, the electronic device returns the real geographical location information to the navigation application.
[0173] Step 29: When the navigation application is running in the foreground, the screen state of the electronic device is the user touch state, and the first request interval is greater than or equal to 1, and the first request interval is less than the average request interval, the electronic device returns the virtual geographical location information to the navigation application.
[0174] Step 30: When the navigation application is running in the foreground, the screen state of the electronic device is the user touch state, and the first request interval is less than 1, the electronic device returns the virtual geographical location information to the navigation application.
[0175] Step 31: When the navigation application is running in the foreground, the screen state of the electronic device is in a non-user touch state, the first request interval is greater than or equal to 1, the first request interval is greater than or equal to twice the average request interval, and the first request interval is greater than or equal to the second request interval, the electronic device returns the real geographical location information to the navigation application.
[0176] Step 32: When the navigation application is running in the foreground, the screen state of the electronic device is in a non-user touch state, the first request interval is greater than or equal to 1, and the first request interval is less than twice the average request interval, the electronic device returns the virtual geographical location information to the navigation application.
[0177] Step 33: When the navigation application is running in the foreground, the screen state of the electronic device is in a non-user touch state, and the first request interval is less than 1, the electronic device returns the virtual geographical location information to the navigation application.
[0178] Step 34: When the navigation application is running in the background, the first request interval is greater than or equal to 1, the first request interval is greater than or equal to three times the average request interval, and the first request interval is greater than or equal to the second request interval, the electronic device returns the real geographical location information to the navigation application.
[0179] Step 35: When the navigation application is running in the background, the first request interval is greater than or equal to 1, and the first request interval is less than three times the average request interval, the electronic device returns the virtual geographical location information to the navigation application.
[0180] Step 36: When the navigation application is running in the background, and the first request interval is less than 1, the electronic device returns the virtual geographical location information to the navigation application.
[0181] Step 37: After the user has used it for a period of time, if the user wants to adjust the positioning proxy data of the navigation application, the user can trigger the electronic device to display the proxy data interface of the settings application. The user can modify the positioning proxy data of the navigation application in the proxy data interface so that the electronic device can update the positioning proxy data of the navigation application.
[0182] Step 38: The permission service in the electronic device detects the user's modification and changes the status value of the positioning permission of the navigation application to 2.
[0183] Step 39: When the user is using the application and the navigation application requests the location permission of the electronic device, the location service in the electronic device checks that the status value of the positioning permission is 2 and returns the proxy data of the positioning permission set by the user to the navigation application.
[0184] Step 40: When the electronic device determines that it does not agree to grant the positioning permission to the navigation application, the electronic device returns proxy data of the positioning permission to the navigation application.
[0185] In the embodiments of the present application, since an application generally calls permissions frequently in the background to obtain user privacy data when obtaining user privacy data, by detecting whether the first request interval is less than the preset request interval and detecting whether the running state of the first application is foreground running, it is determined whether to return real data or proxy data to the first application. It can be understood that when the running state of the first application is foreground running and the first request interval is less than the preset request interval, if the user grants the permission to the first application, the permission data returned by the electronic device to the first application is also proxy data, that is, virtual data. In this way, even if the user grants the application permission without knowing it, the user's personal data will not be leaked, thereby improving the security of the electronic device.
[0186] Each of the above method embodiments, or various possible implementation manners in each method embodiment, can be executed alone, or, on the premise of no contradiction, can also be executed in combination with each other, which can be specifically determined according to actual usage requirements, and the embodiments of the present application do not limit this.
[0187] It should be noted that the execution subject of the permission management method provided in the embodiments of the present application can be a permission management device. In the embodiments of the present application, taking the permission management device executing the permission management method as an example, the permission management device provided in the embodiments of the present application is described.
[0188] Figure 8 shows a possible structural schematic diagram of the permission management device involved in the embodiments of the present application. As Figure 8 shown, the permission management device 70 may include: a receiving module 71, an obtaining module 72, and a processing module 73.
[0189] Among them, the receiving module 71 is configured to receive a first permission request of a first application, where the first permission request is used to apply for a first permission. The obtaining module 72 is configured to obtain a first request interval of the permission request of the first permission when the historical request times of the permission request of the first permission received by the receiving module 71 is greater than a first threshold. The processing module 73 is configured to return real data or proxy data of the first permission to the first application based on the running state of the first application and the first request interval obtained by the obtaining module 72.
[0190] In a possible implementation manner, the above-mentioned obtaining module 72 is specifically configured to calculate the historical request interval between two adjacent historical permission requests based on the request timestamps corresponding to the historical permission requests of the first permission; and determine the first request interval based on the historical request interval and the second request interval, where the second request interval is the request interval between the first permission request and the second permission request; and the second permission request is the permission request of the previous first permission of the first permission request.
[0191] In a possible implementation manner, the above-mentioned processing module 73 is specifically configured to return the real data of the first permission to the first application when the running state of the first application and the first request interval meet the first condition; or return the proxy data of the first permission to the first application when the running state of the first application and the first request interval meet the second condition.
[0192] In a possible implementation manner, the above-mentioned first condition includes: the running state of the first application is foreground running and the first request interval is greater than or equal to the first threshold; or the running state of the first application is background running and the first request interval is greater than or equal to the second threshold, where the second threshold is the product of the average request interval of the first permission and the first predetermined multiple; the above-mentioned second condition includes: the running state of the first application is foreground running and the first request interval is less than the first threshold; or the running state of the first application is background running and the first request interval is less than the second threshold.
[0193] In a possible implementation manner, the above-mentioned processing module 73 is specifically configured to return the real data or proxy data of the first permission to the first application based on the running state of the first application, the first request interval, and the second request interval; where the second request interval is the request interval between the first permission request and the second permission request, and the second permission request is the historical permission request of the previous first permission of the first permission request; the first condition further includes: the first request interval is greater than or equal to the second request interval; the second condition further includes: the first request interval is less than the second request interval.
[0194] In a possible implementation manner, the above-mentioned processing module 73 is further configured to return the proxy data of the first permission to the first application when the permission state of the first permission is the unauthorized state.
[0195] In a possible implementation manner, the above-mentioned processing module 73 is specifically configured to obtain the first request interval when the permission state of the first permission is the authorized state and the historical request times of the permission request of the first permission are greater than the first threshold.
[0196] An embodiment of the present application provides a permission management device. Since an application generally frequently calls permissions in the background to obtain user privacy data when obtaining user privacy data, by detecting whether a first request interval is less than a preset request interval and detecting whether the running state of a first application is foreground running, it is determined whether to return real data or proxy data to the first application. It can be understood that when the running state of the first application is foreground running and the first request interval is less than the preset request interval, if the user grants the first application permission, the permission data returned by the permission management device to the first application is also proxy data, that is, virtual data. Thus, even if the user grants the application permission without knowing it, the user's personal data will not be leaked, thereby improving the security of the permission management device.
[0197] The permission management device in the embodiment of the present application can be an electronic device or a component in an electronic device, such as an integrated circuit or a chip. The electronic device can be a terminal or other devices other than a terminal. Exemplarily, the mobile electronic device can be a mobile phone, a tablet computer, a laptop computer, a handheld computer, an in-vehicle electronic device, a Mobile Internet Device (MID), an augmented reality (AR) / virtual reality (VR) device, a robot, a wearable device, an ultra-mobile personal computer (UMPC), a netbook, or a personal digital assistant (PDA), etc. It can also be a server, a Network Attached Storage (NAS), a personal computer (PC), a television (TV), a teller machine, or a self-service machine, etc. The embodiment of the present application does not make specific limitations.
[0198] The permission management device in the embodiment of the present application can be a device with an operating system. The operating system can be an Android operating system, an iOS operating system, or other possible operating systems. The embodiment of the present application does not make specific limitations.
[0199] The permission management device provided by the embodiment of the present application can implement each process implemented by the above embodiment. To avoid repetition, it will not be elaborated here.
[0200] Optionally, as Figure 9As shown in the figure, an embodiment of the present application further provides an electronic device 90, which includes a processor 91 and a memory 92. A program or instruction that can run on the processor 91 is stored on the memory 92. When the program or instruction is executed by the processor 91, each step of the above-mentioned permission management method embodiment is implemented, and the same technical effect can be achieved. To avoid repetition, it will not be elaborated here.
[0201] It should be noted that the electronic devices in the embodiments of the present application include the above-mentioned mobile electronic devices and non-mobile electronic devices.
[0202] Figure 10 It is a schematic diagram of the hardware structure of an electronic device according to an embodiment of the present application.
[0203] The electronic device 100 includes, but is not limited to: a radio frequency unit 101, a network module 102, an audio output unit 103, an input unit 104, a sensor 105, a display unit 106, a user input unit 107, an interface unit 108, a memory 109, and a processor 110, etc.
[0204] Those skilled in the art can understand that the electronic device 100 may further include a power supply (such as a battery) for supplying power to each component. The power supply can be logically connected to the processor 110 through a power management system, so as to realize functions such as management of charging, discharging, and power consumption management through the power management system. Figure 10 The structure of the electronic device shown in the figure does not constitute a limitation on the electronic device. The electronic device may include more or fewer components than shown in the figure, or combine certain components, or have different component arrangements, which will not be elaborated here.
[0205] Among them, the processor 110 is used to receive a first permission request of a first application. The first permission request is used to apply for a first permission, and when the historical request times of the permission request of the first permission are greater than a first threshold, obtain a first request interval of the permission request of the first permission; and based on the running state of the first application and the first request interval, return real data or proxy data of the first permission to the first application.
[0206] Optionally, in an embodiment of the present application, the above-mentioned processor 110 is specifically used to calculate a historical request interval between two adjacent historical permission requests based on the request timestamps corresponding to the historical permission requests of the first permission; and determine the first request interval based on the historical request interval and a second request interval. The second request interval is the request interval between the first permission request and a second permission request; the second permission request is the permission request of the previous first permission of the first permission request.
[0207] Optionally, in the embodiments of the present application, the above-mentioned processor 110 is specifically configured to return the real data of the first permission to the first application when the running state of the first application and the first request interval meet the first condition; or, when the running state of the first application and the first request interval meet the second condition, return the proxy data of the first permission to the first application.
[0208] Optionally, in the embodiments of the present application, the above-mentioned processor 110 is specifically configured to return the real data or proxy data of the first permission to the first application based on the running state of the first application, the first request interval, and the second request interval; wherein, the second request interval is the request interval between the first permission request and the second permission request, and the second permission request is the historical permission request of the previous first permission of the first permission request; the first condition further includes: the first request interval is greater than or equal to the second request interval; the second condition further includes: the first request interval is less than the second request interval.
[0209] Optionally, in the embodiments of the present application, the above-mentioned processor 110 is further configured to return the proxy data of the first permission to the first application when the permission state of the first permission is the unauthorized state.
[0210] Optionally, in the embodiments of the present application, the above-mentioned processor 110 is specifically configured to obtain the first request interval when the permission state of the first permission is the authorized state and the historical request times of the permission request of the first permission are greater than the first threshold.
[0211] In the embodiments of the present application, an electronic device is provided. Since an application generally calls permissions frequently in the background to obtain user privacy data when obtaining user privacy data, by detecting whether the first request interval is less than the preset request interval and detecting whether the running state of the first application is foreground running, it is determined whether to return real data or proxy data to the first application. It can be understood that when the running state of the first application is foreground running and the first request interval is less than the preset request interval, if the user grants the first application permission, the permission data returned by the electronic device to the first application is also proxy data, that is, virtual data; thus, even if the user grants the application permission without knowing it, the user's personal data will not be leaked, thereby improving the security of the electronic device.
[0212] The electronic device provided by the embodiments of the present application can implement each process implemented by the above method embodiments and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.
[0213] The beneficial effects of various implementation manners in this embodiment can be specifically referred to the beneficial effects of the corresponding implementation manners in the above method embodiments. To avoid repetition, it will not be elaborated here.
[0214] It should be understood that in the embodiments of the present application, the input unit 104 may include a Graphics Processing Unit (GPU) 1041 and a microphone 1042. The GPU 1041 processes the image data of static pictures or videos obtained by an image capturing device (such as a camera) in a video capturing mode or an image capturing mode. The display unit 106 may include a display panel 1061, and the display panel 1061 may be configured in the form of a liquid crystal display, an organic light emitting diode, etc. The user input unit 107 includes at least one of a touch panel 1071 and other input devices 1072. The touch panel 1071 is also referred to as a touch screen. The touch panel 1071 may include two parts, a touch detection device and a touch controller. The other input devices 1072 may include, but are not limited to, a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, a joystick, which will not be elaborated herein.
[0215] The memory 109 can be used to store software programs and various data. The memory 109 mainly includes a first storage area for storing programs or instructions and a second storage area for storing data. Among them, the first storage area can store an operating system, applications or instructions required for at least one function (such as a sound playback function, an image playback function, etc.). In addition, the memory 109 may include volatile memory or non-volatile memory, or the memory 109 may include both volatile and non-volatile memory. Among them, the non-volatile memory may be a Read-Only Memory (ROM), a Programmable ROM (PROM), an Erasable PROM (EPROM), an Electrically Erasable PROM (EEPROM), or a flash memory. The volatile memory may be a Random Access Memory (RAM), a Static RAM (SRAM), a Dynamic RAM (DRAM), a Synchronous DRAM (SDRAM), a Double Data Rate SDRAM (DDR SDRAM), an Enhanced SDRAM (ESDRAM), a Synchlink DRAM (SLDRAM), and a Direct Rambus RAM (DRRAM). The memory 109 in the embodiments of the present application includes, but is not limited to, these and any other suitable types of memory.
[0216] The processor 110 may include one or more processing units; optionally, the processor 110 integrates an application processor and a modem processor. Among them, the application processor mainly processes operations related to the operating system, user interface, applications, etc., and the modem processor mainly processes wireless communication signals, such as a baseband processor. It can be understood that the above-mentioned modem processor may not be integrated into the processor 110 either.
[0217] The embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, it implements each process of the above method embodiment and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.
[0218] Among them, the processor is the processor in the electronic device described in the above embodiment. The readable storage medium includes a computer-readable storage medium, such as a computer read-only memory ROM, a random access memory RAM, a magnetic disk, or an optical disc, etc.
[0219] The embodiment of the present application further provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run a program or instruction to implement each process of the above method embodiment and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.
[0220] It should be understood that the chip mentioned in the embodiment of the present application may also be referred to as a system-on-chip, system chip, chip system, or system-on-chip, etc.
[0221] The embodiment of the present application provides a computer program product, which is stored in a storage medium. The program product is executed by at least one processor to implement each process of the above permission management method embodiment and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.
[0222] It should be noted that in this text, the term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the phrase "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising that element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in a reverse order according to the functions involved. For example, the described methods may be performed in an order different from that described, and various steps may be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.
[0223] Through the description of the above embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, can be embodied in the form of a computer software product. The computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to enable a terminal (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of the present application.
[0224] The embodiments of the present application have been described above in conjunction with the accompanying drawings. However, the present application is not limited to the above specific embodiments. The above specific embodiments are merely illustrative and not restrictive. Those of ordinary skill in the art, under the inspiration of the present application, without departing from the purpose of the present application and the scope protected by the claims, can also make many forms, all of which fall within the protection scope of the present application.
Claims
1. A permission management method, characterized in that, The method includes: Receiving a first permission request of a first application, where the first permission request is used to apply for a first permission; When the historical request count of the permission request for the first permission is greater than a first threshold, obtaining a first request interval of the permission request for the first permission; Based on the running state of the first application and the first request interval, returning real data or proxy data of the first permission to the first application.
2. The method according to claim 1, wherein The obtaining of the first request interval of the permission request for the first permission includes: Based on the request timestamps corresponding to the historical permission requests for the first permission, calculating a historical request interval between two adjacent historical permission requests; Based on the historical request interval and a second request interval, determining the first request interval, where the second request interval is the request interval between the first permission request and a second permission request; the second permission request is the previous permission request for the first permission of the first permission request.
3. The method according to claim 1 or 2, characterized in that, The returning of real data or proxy data of the first permission to the first application based on the running state of the first application and the first request interval includes: When the running state of the first application and the first request interval meet a first condition, returning real data of the first permission to the first application; or, When the running state of the first application and the first request interval meet a second condition, returning proxy data of the first permission to the first application.
4. The method according to claim 3, characterized in that, The first condition includes: the running state of the first application is foreground running and the first request interval is greater than or equal to the first threshold; or, the running state of the first application is background running and the first request interval is greater than or equal to the second threshold, where the second threshold is the product of the average request interval of the first permission and a first predetermined multiple; The second condition includes: the running state of the first application is foreground running and the first request interval is less than the first threshold; or, the running state of the first application is background running and the first request interval is less than the second threshold.
5. The method according to claim 3, characterized in that, The returning of real data or proxy data of the first permission to the first application based on the running state of the first application and the first request interval includes: Based on the running state of the first application, the first request interval and the second request interval, returning real data or proxy data of the first permission to the first application; where the second request interval is the request interval between the first permission request and a second permission request, and the second permission request is the previous historical permission request for the first permission of the first permission request; The first condition further includes: the first request interval is greater than or equal to the second request interval; The second condition further includes: the first request interval is less than the second request interval.
6. The method according to claim 1, wherein The method further includes: When the permission state of the first permission is an unauthorized state, returning proxy data of the first permission to the first application.
7. The method according to claim 1, wherein When the historical request count of the permission request for the first permission is greater than a first threshold, obtaining a first request interval of the permission request for the first permission, includes: When the permission status of the first permission is an authorized status and the historical request count of the permission request for the first permission is greater than the first threshold, obtaining the first request interval.
8. A permission management device, characterized in that, The permission management device includes: a receiving module, an obtaining module, and a processing module; The receiving module is configured to receive a first permission request of a first application, where the first permission request is used to apply for a first permission; The obtaining module is configured to obtain a first request interval of the permission request for the first permission when the historical request count of the permission request for the first permission received by the receiving module is greater than a first threshold; The processing module is configured to return real data or proxy data of the first permission to the first application based on the running status of the first application and the first request interval obtained by the obtaining module.
9. An electronic device, characterized in that, It includes a processor, a memory, and a program or instruction stored on the memory and executable on the processor. When the program or instruction is executed by the processor, the steps of the permission management method according to any one of claims 1 to 7 are implemented.
10. A readable storage medium, characterized in that, A program or instruction is stored on the readable storage medium. When the program or instruction is executed by a processor, the steps of the permission management method according to any one of claims 1 to 7 are implemented.