Permission allocation method, terminal device, storage medium and program product
By obtaining natural language statements and terminal equipment usage scenarios automatically allocating permissions, combined with multimodal data detection and risk assessment, the problems of complex permission configuration and difficult identification of illegal applications in the existing technology are solved, and intelligent permission management and security protection are realized.
Patent Information
- Application Number
- CN202510635879.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-16
- Publication Date
- 2025-08-22
AI Technical Summary
The permission configuration of existing application software is complex, and users need to configure it manually, making it difficult to deal with complex and hidden illegal behaviors, and lacks intelligent security protection.
By obtaining natural language statements, determining the permission control policy, combining terminal device usage scenarios, automatically allocating application permissions, and running suspicious permissions in a sandbox environment, dynamically adjusting the permission opening policy, and using multimodal data for abnormal detection and risk assessment.
It simplifies user permission configuration operations, improves the flexibility and accuracy of permission allocation, improves the ability to identify and protect illegal applications, and dynamically adjusts permissions to deal with complex scenarios.
Smart Images

Figure CN120524501A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, for example, to a method for allocating permissions, a terminal device, a storage medium, and a program product. Background Art
[0002] With the widespread use of terminal devices, application software has become an indispensable tool in users' lives. During the use of application software, permission settings need to be performed.
[0003] Existing application software requires users to manually configure the permissions of the application software, and the configuration operation is relatively complicated. Summary of the Invention
[0004] The present application provides a permission allocation method, terminal device, storage medium and program product, so as to at least realize automatic allocation of permissions for applications, thereby reducing the complexity of application permission configuration.
[0005] In a first aspect, an embodiment of the present application provides a method for allocating permissions, including:
[0006] Obtaining permission control information, wherein the permission control information includes a natural language statement for controlling permissions of the application program;
[0007] Determining, based on the permission control information, a permission control policy corresponding to the permission control information, wherein the permission control policy includes applicable scenarios associated with the permission;
[0008] Determine the usage scenario of the terminal device;
[0009] Based on the matching result between the usage scenario of the terminal device and the applicable scenario, the permission of the application program in the usage scenario is determined.
[0010] In a second aspect, an embodiment of the present application provides a terminal device, including:
[0011] one or more processors;
[0012] a storage device for storing one or more programs;
[0013] When the one or more programs are executed by the one or more processors, the one or more processors implement the permission allocation method provided in the embodiments of the present application.
[0014] In a third aspect, an embodiment of the present application provides a storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the permission allocation method provided by the embodiment of the present application.
[0015] In a fourth aspect, an embodiment of the present application provides a computer program product, including a computer program, which, when executed by a processor, implements the permission allocation method provided according to the embodiment of the present application.
[0016] With respect to the above embodiments and other aspects of the present application and their implementation, further description is provided in the accompanying drawings, detailed description and claims. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 This is a flowchart of a method for allocating permissions provided by an embodiment of the present application;
[0018] Figure 2 This is a schematic diagram of a system architecture provided by an embodiment of the present application;
[0019] Figure 3 This is a flowchart of a permission allocation provided by an embodiment of the present application;
[0020] Figure 4 This is a schematic diagram of the structure of a rights allocation device provided in an embodiment of the present application;
[0021] Figure 5 This is a structural diagram of a terminal device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0022] To make the purpose, technical solutions and advantages of this application more clear, the embodiments of this application will be described in detail below with reference to the accompanying drawings. It should be noted that, unless there is a conflict, the embodiments and features in the embodiments of this application can be combined with each other in any way.
[0023] The steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions. Also, although a logical order is shown in the flowcharts, in some cases, the steps shown or described can be performed in an order different from that shown here.
[0024] In this application, the terms "first", "second", etc. are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.
[0025] The acquisition, storage, use and processing of data in the technical solution of this application comply with the relevant provisions of relevant laws and regulations.
[0026] With the widespread use of smart terminal devices, application software (hereinafter referred to as "applications") plays an important role in users' lives. However, the existence of malicious and illegal applications, such as stealing user privacy, maliciously deducting fees, or destroying system security, poses a serious security threat to users. Current application security protection technologies, such as permission control and virus scanning, usually rely on static rules or feature libraries, which are difficult to deal with increasingly hidden and complex illegal behaviors. In addition, current security systems often require users to manually configure permissions, and the complex operation increases the complexity of user use. For example, for permission management during the use of an application, users are always required to choose whether to grant, permanently grant, or temporarily not grant the permission when using the application this time, which results in a poor user experience. Therefore, the present application provides an automated and intelligent technical solution that can simplify user operations and improve security.
[0027] In an exemplary embodiment, Figure 1 This is a flowchart of a permission allocation method provided by an embodiment of the present application. This method can be adapted to simplify the configuration of application permissions. The method can be performed by a permission allocation device, which can be implemented by software and / or hardware and integrated into a terminal device. The terminal device can be any device capable of running an application, such as a mobile phone, computer, or personal digital assistant.
[0028] like Figure 1 As shown, the permission allocation method provided in the embodiment of the present application includes the following operations:
[0029] S110: Obtain permission control information, where the permission control information includes natural language statements for controlling permissions of the application program.
[0030] Permission control information can be considered as information that controls the permissions of an application. Permission control information can indicate the permissions that an application can use and / or restrict the permissions that an application can use. Permissions can be permissions requested by an application. Permissions can be the operating system's security control mechanism for applications to access device resources or data. The permissions allocated by this application can cover all or part of the permissions from the download and installation to the operation of the application. Partial permissions can be functions corresponding to permissions that require authorization to be implemented.
[0031] Different permissions correspond to different functions. For example, the camera permission corresponds to using the camera to capture images. The microphone permission corresponds to using the microphone to capture sound.
[0032] This operation does not limit the form of permission control information. It can be a natural language sentence entered by the user or text entered by the user. A natural language sentence can be considered a statement expressed in natural language. A natural language sentence is a statement that controls the permissions of an application.
[0033] Different forms of permission control information may correspond to different acquisition methods. This operation can obtain permission control information through components of the terminal device, such as this operation can obtain natural language sentences collected by a microphone.
[0034] This operation may be that a control module in a system for allocating permissions on a terminal device obtains permission control information, and after obtaining the permission control information, controls permissions of applications on the terminal device by parsing the permission control information.
[0035] Among them, the control module can be the core part of the system for allocating permissions, and is responsible for coordinating and managing various modules of the system.
[0036] S120: Determine, based on the permission control information, a permission control policy corresponding to the permission control information, where the permission control policy includes applicable scenarios associated with the permission.
[0037] A permission control policy can be considered a policy for controlling permissions. Applicable scenarios can be scenarios where permissions are applicable, such as permission authorization or permission disabling.
[0038] The permissions and applicable scenarios in the permission control policy can be determined by parsing the permission control information. The permission control policy can be used to characterize the applicable scenarios of permissions and serve as data support for subsequent permission allocation.
[0039] Whether the applicable scenario is a disabled scenario or an authorized scenario can be associated with the intent represented by the permission control information. For example, when the permission control information indicates a scenario where the restricted permission cannot be used, the applicable scenario included in the permission control policy can be a scenario where the permission is disabled. When the permission control information indicates a scenario where the permission can be used, the applicable scenario included in the permission control policy can be a scenario where the permission can be used.
[0040] Applicable scenarios can also be scenarios where permissions can be used, also known as authorized scenarios. When the permission control information is intended to limit the scenarios where permissions are disabled, the scenarios that are not disabled can be used as applicable scenarios for permission authorization.
[0041] In this application, the control module can have natural language recognition capabilities. By parsing the permission control information, the control module can identify the intention of permission control expressed in natural language sentences. Based on the intention, the required permission and the applicable scenario of the permission are determined, thereby forming a permission control strategy.
[0042] In one example, a natural language statement may be "Microphone permission can only be enabled when I speak to the phone screen." The corresponding permission may be permission to use the microphone. Applicable scenarios may include using a microphone to capture sound and using a camera to capture images.
[0043] In this operation, the control module can determine the intent. After the intent is determined, the permission control policy can be distributed to other modules in the system for determination, or transmitted to the server for determination. For example, the control module can determine the intent expressed in a natural language sentence using a model for intent recognition.
[0044] This operation can be performed by parsing the permission control information through the control module to obtain the permission control policy. This process can be implemented through the model, such as inputting the permission control information into the model and outputting the permission control policy.
[0045] S130: Determine the usage scenario of the terminal device.
[0046] The usage scenario can be considered the scenario in which the terminal device is used. For example, the current usage scenario of the terminal device determines how permissions are allocated in that scenario based on the current usage scenario. The current scenario can be the usage scenario of the terminal device when the usage scenario is determined.
[0047] This application can classify usage scenarios, which may include work and entertainment scenarios.
[0048] This operation can identify the usage scenario by identifying environmental information. Environmental information indicates one or more associated environments between the terminal device and the application. It can also obtain the usage scenario input by the user. The determination of the usage scenario is not limited here.
[0049] When identifying the use scenario by identifying the environmental information, the system can use the scene recognition module to identify the environment, or the scene recognition module and the control module can work together to achieve identification. The scene recognition module can obtain the environmental information, and the control module can identify the environmental information to determine the use scenario.
[0050] S140: Determine the permissions of the application program in the usage scenario based on a matching result between the usage scenario of the terminal device and the applicable scenario.
[0051] The matching result can be considered as a result that characterizes whether the usage scenario and the applicable scenario match.
[0052] After determining the usage scenario, this operation can match the usage scenario with the applicable scenario in the permission control policy. For example, if the usage scenario is an entertainment scenario, the applicable scenario is a scenario where a microphone is used to capture sound and a camera is used to capture images. The usage scenario and the applicable scenario are matched. Determine whether the usage scenario matches the applicable scenario. If so, the allocation of permissions corresponding to the applicable scenario can be determined based on the permission control policy. If the permission control policy indicates that the corresponding permission is authorized under the applicable scenario, the permission can be authorized for the usage scenario; otherwise, the permission is disabled for the usage scenario.
[0053] In the case that the applicable scenarios in the permission control policy are all permission authorization scenarios, and in the case that the usage scenario and the applicable scenario match, the permission corresponding to the applicable scenario can be authorized.
[0054] The permission control policy of the present application can represent the applicable scenarios associated with different permissions. After determining the usage scenario, the applicable scenarios in the permission control policy can be traversed to assign permissions to the application to determine the permissions of the application scenario under the usage scenario, including the first permission that allows the application to be used in the application scenario, and the second permission that limits the application to be applicable in the application scenario.
[0055] Each permission in this application can have a corresponding permission control policy, and each permission control policy can have a corresponding applicable scenario. This operation can traverse all corresponding permission control policies for each permission, determine the matching results between the usage scenario and all applicable scenarios of the permission, and assign permissions for the usage scenario to the application.
[0056] This operation can match the usage scenario with the applicable scenario in the permission control policy through the control module to determine the permissions that the application is allowed to use and the permissions that the application is not allowed to use.
[0057] This application provides a permission allocation method that obtains and parses permission control information to obtain a permission control policy. This method implements the determination of permission control policies through natural language statements, simplifying the user's permission configuration operations. After determining the permission configuration policy, the application is assigned permissions for the usage scenario based on the usage scenario. This increases the flexibility of permission allocation, making the assigned permissions more consistent with the user's intentions expressed through natural language statements, and improving the accuracy of permission allocation.
[0058] Based on the above embodiment, a modified embodiment of the above embodiment is proposed. It should be noted that, in order to simplify the description, only the differences from the above embodiment are described in the modified embodiment.
[0059] In one embodiment, obtaining permission control information includes:
[0060] In response to the permission request of the application, a natural language statement for controlling the permission of the application is obtained.
[0061] A permission request can be considered a request for permission initiated by an application. There are no restrictions on when a permission request may be triggered. Examples include triggering a permission request during application launch, during application installation, or during application download.
[0062] In this embodiment, a permission request of an application is obtained, and then a natural language sentence input by a user for controlling the permission of the application is obtained to achieve a response to the permission request.
[0063] In this embodiment, natural language sentences can be obtained through the control module.
[0064] In one embodiment, determining the permission control policy corresponding to the permission control information based on the permission control information includes:
[0065] identifying a control condition for the permission based on the natural language statement;
[0066] Matching the control condition with an applicable scenario identifiable by the terminal device;
[0067] The authority and the applicable scenario are determined as the authority control policy.
[0068] This embodiment refines the operation of determining the authority control policy. When determining the control condition based on a natural language statement, the natural language statement can be identified to determine the control condition expressed by the natural language statement.
[0069] For example, we can determine the intent information of a natural language sentence and then identify control conditions from the intent information. Intent information can be considered as information that represents the intention, such as the desired goal expressed in a natural language sentence. Control conditions can be considered as the conditions that determine whether control permissions are granted.
[0070] This embodiment can parse natural language sentences, understand the natural language sentences and determine the intention information. This operation can be achieved through a model.
[0071] After determining the intent information, the user-specified condition can be identified from the intent information and used as a control condition. The control condition can be "speaking to the phone screen" or "being at a certain address."
[0072] In this embodiment, natural language sentences may also be parsed to directly identify control conditions.
[0073] After determining the control conditions, they can be mapped to applicable scenarios recognized by the terminal device. This means matching the control conditions with the applicable scenarios recognized by the terminal device. This facilitates matching with the identified usage scenarios. For example, "facing the phone screen" may involve a microphone capturing voice and a camera detecting images. The corresponding applicable scenario could be a scenario where the microphone captures voice and the camera detects images, such as an entertainment scenario.
[0074] After determining the applicable scenarios, you can store the permissions and corresponding applicable scenarios in the permission control policy. When storing applicable scenarios, you can directly store them in the form of scenarios where microphones are used for voice capture and cameras are used for image capture. You can also list specific scenarios for microphones and cameras, such as entertainment scenarios.
[0075] When storing data in the form of scenarios where a microphone is used to capture voice and a camera is used to capture images, the matching process can determine whether the usage scenario uses a microphone to capture voice and a camera to capture images. If so, the usage scenario and the applicable scenario are considered to match. Otherwise, the two do not match. When storing data in the form of specific scenarios, it can be directly determined whether the usage scenario is a specific scenario. If so, the applicable scenario and the applicable scenario match; otherwise, the two do not match.
[0076] In one embodiment, determining the usage scenario of the terminal device includes:
[0077] Obtaining environmental information, the environmental information indicating an environment associated with one or more of the terminal device and the application;
[0078] Based on the environmental information, determine the usage scenario of the terminal device.
[0079] The environmental information associated with a terminal device can include the external scene in which the terminal device is located, i.e., the scene outside the terminal device, such as the ambient noise outside the terminal device collected by a microphone. The environmental information associated with a terminal device can also include the terminal's location, which can be rough location information, such as the number of the communicating base station. The environmental information associated with an application can include the application's status, also known as the application state, which can be a state associated with the application's operation. The environmental information associated with an application can also include the application's historical operations.
[0080] In this embodiment, environmental information corresponding to one or more of the terminal and application is obtained, and then the environmental information is identified to determine the usage scenario of the terminal device. The identification method is not limited here, and it can be implemented through a model. This embodiment also does not limit the method for obtaining environmental information. Different environmental information corresponds to different acquisition methods.
[0081] In one example, the environment information is acquired through a scene recognition module in the system, and the use scene is obtained by recognizing the environment information through a scene recognition model in the scene recognition model.
[0082] The scene recognition module can be considered a module that performs usage scenario recognition. The scene recognition model can be a deep learning model based on the self-attention mechanism. The scene recognition model can recognize information from multiple modalities, such as sensors, GPS, cameras, microphones, and other data sources.
[0083] In this embodiment, the scene recognition module may include a scene recognition model and may also include data pre-processing and post-processing operations. The scene recognition module may also be a scene recognition model that obtains environmental information and outputs a usage scenario.
[0084] In one embodiment, determining the permissions of the application in the usage scenario based on a matching result between the usage scenario of the terminal device and the applicable scenario includes:
[0085] Determining a matching result between a usage scenario of the terminal device and the applicable scenario, the matching result indicating whether the usage scenario matches the applicable scenario;
[0086] A first permission that is permitted for the application program and a second permission that is restricted for the application program are determined based on the matching result.
[0087] The first permission may be a permission that allows the application to use, such as an authorized permission. The second permission may be a permission that restricts the application from using, such as a disabled permission.
[0088] In this embodiment, permissions can be allocated based on usage scenarios and applicable scenarios. In this embodiment, matching results can be determined by a model and permissions can be allocated to the application. The model for determining matching results and permission allocation can be a single model or different models.
[0089] In one example, the control module may match the usage scenario with the applicable scenario to obtain a matching result, and then determine whether the permission corresponding to the matching result is allowed to be used by the application program based on the matching result, thereby obtaining the first permission and the second permission.
[0090] If the matching result indicates a match, the first permission may include permissions authorized by the applicable scenario, and the second permission may be permissions other than the first permission.
[0091] In one embodiment, the permission allocation method further includes:
[0092] The second permission is run in a sandbox environment, where the sandbox environment has an independent operating system and an independent storage space, and virtual data associated with the second permission exists in the sandbox environment.
[0093] In this embodiment, the second permission can be run in a sandbox environment to ensure the normal operation of the application. The sandbox environment can be an isolated operating environment. The independent operating system can be an operating system isolated from the operating system of the terminal device. The independent storage space can be an isolated storage space that can be isolated from the storage space of the operating system. Virtual data associated with the second permission can exist in the sandbox environment. Virtual data can be considered as virtual data, such as data simulated, generated, or synthesized by a computer, rather than real data.
[0094] In this embodiment, during the execution of the second permission, virtual data associated with the second permission can be obtained from the sandbox environment to ensure normal operation of the application.
[0095] There are no restrictions on how to build a sandbox environment. You can use virtual machines, containers, cloud services, or work profiles to build a sandbox environment. The sandbox environment can be deployed on the terminal device or in the cloud.
[0096] While various security technologies exist, they lack intelligent thinking capabilities and present certain limitations. Illegal software, such as Trojans, viruses, phishing, and scams, is currently identified from a single perspective and through verification, lacking comprehensive, progressive cognitive judgment. Illegal applications constantly shift disguises to penetrate security. Furthermore, given the increasingly subtle and complex nature of illegal applications, users lack the expertise to determine their legitimacy. This application dynamically detects anomalies within applications and identifies illegal applications.
[0097] In one embodiment, the permission allocation method further includes:
[0098] Acquiring multimodal data during the running of the application;
[0099] Performing feature extraction on the multimodal data to obtain key features;
[0100] Anomaly detection is performed on the application based on the key features to determine a detection result.
[0101] Multimodal data can be considered to include multiple different types of data. Multimodal data can come from different sources and can have at least two modalities, such as text, images, audio, and video. Key features can be considered valuable features in multimodal data, such as those that characterize the data. Valuable features can be considered features that have an impact on anomaly detection. Detection results can be considered the results of anomaly detection in an application.
[0102] This embodiment can obtain multimodal data during the running of the application. This embodiment can perform comprehensive detection of the application by fusing data of different modalities.
[0103] In this embodiment, the multimodal data during the running of the application program can be acquired through the application detection and data acquisition module. The application detection and data acquisition module can be considered as a module that collects data during the running of the application program.
[0104] This embodiment can analyze multimodal data to extract key features from the multimodal data, and then analyze the key features to perform anomaly detection on the application.
[0105] In this embodiment, feature extraction and anomaly detection can be implemented through models. For example, feature extraction can be implemented through a multimodal model, and anomaly detection can be implemented through a control module.
[0106] A multimodal model can be considered a model for multimodal data processing, also known as a multimodal processing model. Multimodal models enable feature extraction. They extract features from each modality within the multimodal data, obtaining key features for each modality. The multimodal model transmits these key features to the control module. After obtaining these key features, the control module integrates the key features from each modality to perform anomaly detection on the application and generate detection results. The control module can then use the model to perform anomaly detection.
[0107] In one embodiment, the multimodal data includes one or more of the following:
[0108] Text data; image data; audio data; video data; network data; sensor data; resource data of resources in the terminal device.
[0109] Text data can be considered as data in text form. Image data can refer to visual information represented in two-dimensional or three-dimensional form. Audio data can refer to sound represented in the form of a time series. Video data can refer to dynamic visual information composed of a series of image frames. Network data refers to data related to the network, such as network traffic and network requests. Sensor data can refer to data generated by sensors. Resource data can refer to data related to the resources of the terminal device, such as memory-related information (such as information related to memory usage) and battery-related information (such as information related to battery consumption).
[0110] In one embodiment, the resource allocation method further includes:
[0111] Determining risk measurement information corresponding to the detection result;
[0112] When the risk metric information is less than a set threshold, the restriction degree of the second permission is adjusted, where the second permission includes a permission to restrict use of the application.
[0113] Risk metric information can be considered as a measure of risk, such as a risk score. The lower the risk metric value, the lower the risk of the application. The threshold can be considered a critical value for determining whether an application is risky. If the risk metric value is less than the threshold, the application is considered risk-free. If the risk metric value is greater than or equal to the threshold, the application is considered risky.
[0114] When the risk measurement information and the set threshold have different size relationships, different operations may correspond to them. The operations may include adjusting the degree of restriction of the second permission, maintaining the degree of restriction of the second permission, and outputting prompt information to instruct the user. The content of the prompt information is not limited here.
[0115] In this embodiment, the control module or other models in the system scheduled by the control module can determine risk measurement information for this anomaly detection based on the detection results. The risk measurement information can be determined by the model. The detection results are input into the model, and the risk measurement information is output.
[0116] When the risk measurement information is less than the set threshold, the degree of restriction of the second permission can be adjusted. For example, the degree of restriction of the second permission can be reduced. In the process of reducing the degree of restriction, the degree of restriction of the application can be reduced in stages. For example, in different anomaly detections, if the risk measurement information is continuously less than the set threshold, the degree of restriction of the second permission will be gradually reduced until the second permission is fully authorized. Among them, gradually reducing the degree of restriction of the second permission can be considered as reducing the scope, duration, scenario, etc. of the restriction of the second permission. Gradually reducing can be reducing the restriction of the second permission according to the set amplitude. The amplitude of each reduction can be the same or different, and the amplitudes corresponding to different permissions can be the same or different.
[0117] In the process of adjusting the restriction degree of the second permission, the restriction degree of all or part of the second permission may be adjusted.
[0118] In the process of adjusting the restriction degree of some second permissions, the adjusted second permissions may be second permissions that affect the value of the risk measurement information. Influencing the value of the risk measurement information may be causing the risk measurement information to take a value in a direction where there is risk, such as increasing the risk measurement information.
[0119] In one embodiment, when the risk metric information is less than a set threshold, adjusting the restriction degree of the second permission includes:
[0120] When the risk measurement information is less than a set threshold, the restriction degree of the second authority is adjusted from at least one dimension.
[0121] The dimension may be a dimension for performing a second permission adjustment. The dimension includes one or more of a time dimension, a space dimension, and a scenario dimension. Among them, the time dimension may be a dimension based on time division, such as the permission can be managed from the available time or duration, or the limited time or duration. The space dimension may be a dimension based on storage space division, where files can be stored, and the file access scope of the permission can be characterized from the space dimension. The file access scope can be considered as the scope of the accessed files. The scenario dimension can characterize the applicable scenario corresponding to the permission. The dimensions corresponding to different permissions may be the same or different.
[0122] This embodiment adjusts the permissions of all second permissions, and all second permissions are gradually moved out of the sandbox environment and run in a real environment.
[0123] The permissions opened in this application can be considered as a phased approach. Each time the risk metric falls below a set threshold, it corresponds to a phase. The magnitude of each phase can be the same or increase gradually.
[0124] This embodiment gradually opens up permissions to reduce the degree of restriction on the second permission.
[0125] In one embodiment, the permission allocation method further includes:
[0126] Determining a third permission associated with the risk metric information, the third permission including the permission in the second permission to cause the risk metric information to take a value in a direction that increases risk; accordingly, when the risk metric information is less than a set threshold, adjusting the degree of restriction of the second permission, including:
[0127] If the risk metric information is less than a set threshold, perform at least one of the following steps:
[0128] Setting the permissions in the second permission except the third permission to be allowed to be used by the application program;
[0129] The restriction degree of the third permission is adjusted from at least one dimension.
[0130] The third permission may be a portion of the second permission. The increasing risk direction may be considered to be the direction in which the risk metric information value increases. The third permission may be a permission that affects the risk metric information value in the increasing risk direction, such as the second permission that causes the risk metric information to be non-zero.
[0131] In this embodiment, when adjusting the restriction level, the second permission, except for the third permission, can be considered safe permissions and can be set to allow the application to use them, removing them from the sandbox environment. During the application's operation, it can access actual data and operate in a real environment. The third permission can be opened up along at least one dimension. The restriction level of the third permission can be reduced by the corresponding degree of opening up in this round.
[0132] In one embodiment, adjusting the degree of restriction of permissions from at least one dimension includes:
[0133] When the risk metric information is smaller than the set threshold value for a continuous number of times reaching a set number, the permission for adjusting the restriction degree is set to be allowed to be used by the application program.
[0134] The number of consecutive times may be the number of times the risk metric information determined each time is continuously less than a set threshold. The set number of times may be a pre-set number of times. If the average risk metric information of an application is less than the set threshold for the set number of consecutive times, the second permission may be deemed to be highly secure, and the gradually released third permission or all second permissions may be set to allow the application to use them, halting the gradual release of permissions. The permission for which the restriction level is adjusted may be a permission that is gradually released, such as the third permission or all second permissions.
[0135] If the risk metric information is less than the set threshold for a consecutive number of times, the permission restriction level can be adjusted again, with the restriction level adjusted by the magnitude corresponding to the current adjustment. The magnitude can be considered the range of the permission restriction adjustment. The magnitudes corresponding to different adjustments can be the same or different.
[0136] In one embodiment, the dimension includes at least one of the following:
[0137] Time dimension, where the adjustment method corresponding to the time dimension includes extending the available time of the permission;
[0138] Spatial dimension, wherein the adjustment method corresponding to the spatial dimension includes extending the file access scope of the permission;
[0139] Scenario dimension, the adjustment method corresponding to the scenario dimension includes the applicable scenarios of the extended permissions.
[0140] The available time period can be the length of time that the permission is considered available. When granting permissions based on time, adjustments to the permissions can include extending the available time period. The extension can be by an amount corresponding to the time period, for example, extending the 9:00-12:00 period to 9:00-24:00.
[0141] The scope of a file can be represented as a directory hierarchy, with different hierarchies corresponding to different file access scopes. When the dimension is spatial, adjusting permissions can include expanding the file access scope of the permission, such as by narrowing the directory hierarchy. The extent of the expansion can be the extent corresponding to the access scope, such as expanding from a secondary directory to a primary directory.
[0142] When adjusting permissions based on scenarios, the adjustment can include expanding the applicable scenarios. This expansion can be done by opening up one scenario at a time or multiple scenarios at a time, such as expanding from work-only to entertainment scenarios.
[0143] In one embodiment, the permission allocation method further includes:
[0144] Determining risk measurement information corresponding to the detection result;
[0145] When the risk measurement information is greater than or equal to a set threshold, a first prompt message is output, wherein the first prompt message prompts to re-acquire the permission control information and continue to allocate permissions to the application based on the re-acquired permission control information.
[0146] The method of determining risk measurement information is as described in the above embodiment and will not be described in detail here.
[0147] The first prompt information can be considered as information that triggers re-allocation of permissions when an exception occurs in the application.
[0148] If the risk measurement information is greater than or equal to the set threshold, it can be considered that there is an abnormality in the application, and the restricted state of the second permission can be maintained. The second permission can be maintained to run in a sandbox environment, access to virtual data, and prohibit access to real resources.
[0149] If the risk metric information is greater than or equal to the set threshold, it can be considered that there is a risk during the sandbox phase. A first prompt message can be output to prompt the user to reconfigure permissions. For example, the first prompt message can prompt the user to re-enter a natural language statement in the form of voice or text to configure the application's permissions. The reconfigured permissions can be all permissions of the application, or permissions that cause the risk metric information value to be greater than or equal to the set threshold. The first prompt message can also include suggestions for permission configuration.
[0150] This embodiment may return to S110 to reacquire the permission control information, and then continue to execute S120 and S130 to reassign permissions to the application based on the reacquired permission control information.
[0151] In one embodiment, the permission allocation method further includes:
[0152] Determining risk measurement information corresponding to the detection result;
[0153] When the risk measurement information is greater than or equal to a set threshold, second prompt information is output, where the second prompt information includes the risk measurement information, the analysis conclusion associated with the detection result, and evidence information corresponding to the analysis conclusion.
[0154] The method of determining risk measurement information is as described in the above embodiment and will not be described in detail here.
[0155] This embodiment provides another scenario where the risk metric information is greater than or equal to a set threshold. The second prompt information can be considered as information describing the risk. The analysis conclusion can be considered as the conclusion drawn after analyzing the application anomaly. This analysis conclusion can be a conclusion drawn after summarizing the detection results over a set period of time. The evidence information can be considered as information that serves as evidence for the analysis conclusion.
[0156] In one example, risk metric information can be considered a risk score, i.e., a risk score. Analysis conclusions can include information describing anomalies within the application, such as the presence of a hidden button in an interface. Evidence information can be considered evidence of the anomaly, such as the specific interface that displays the hidden button.
[0157] The second prompt information may be determined by the terminal device or by the server, which is not limited here.
[0158] For example, the control module in the terminal device system determines and outputs the second prompt information through the model.
[0159] In this application, when the risk measurement information is greater than or equal to the set threshold, one or more of the first prompt information and the second prompt information can be output. In addition, information suggesting uninstallation can also be output for the user to select.
[0160] In one embodiment, the permission allocation method further includes:
[0161] generating a risk report based on the second prompt information;
[0162] outputting the risk report;
[0163] Obtaining a processing instruction triggered by a user in response to the risk report;
[0164] If the processing instruction includes new permission control information, return to continue execution Figure 1 The permission allocation method returns to continue the operations of obtaining the permission control policy, determining the usage scenario, and allocating permissions to the application.
[0165] A risk report can be considered a risk-specific report output to a user. It can be written in natural language to facilitate user understanding and decision-making. Actions can be considered user-triggered instructions based on a risk report to address the risks indicated in the risk report.
[0166] In this embodiment, the second prompt information can be converted into a risk report through a model to summarize the second prompt information and obtain an easy-to-understand risk report. For example, the risk report can be generated through a model in the control module.
[0167] For example, the risk report may indicate that the risk measurement information of application A is x points and there is an image anomaly, specifically displaying a hidden button in the interface.
[0168] This embodiment can output the risk report to the user, such as playing the risk report or displaying the risk report through an interface.
[0169] In this embodiment, the risk report may also include a response suggestion, such as "Please confirm whether to uninstall application A or continue using it and set restrictions." When suggesting restrictions, the response suggestion may also specify the restrictions to be set, allowing users to configure permissions in a targeted manner.
[0170] The type of processing instruction in this embodiment is not limited; any instruction entered in response to a risk report will suffice. This could be an instruction to trigger the uninstallation of an application or an instruction to reallocate permissions. The new permission control information can be considered permission control information re-entered by the user in response to a risk report, and is used to reallocate permissions based on the risks associated with the risk report.
[0171] In the case where the processing instruction is new permission control information, S120 and S130 may be returned and re-executed based on the new permission control information to allocate permissions to the application program based on the new permission control information.
[0172] The following is an illustrative description of this application. Current technologies have limitations in both the use of application permission management and the accuracy of application exception determination. To address these issues, this application provides a permission allocation method, namely, an intelligent application permission management method based on intent and scenario awareness.
[0173] This application uses artificial intelligence (AI) technology to identify the working scenarios of terminal devices, also known as usage scenarios, detect the execution of application software, and use the logical judgment capabilities of the Internet AI large model to identify illegal application behavior. This application is applicable to pure software methods or combined software and hardware implementation scenarios.
[0174] With the development of technology, illegal software is also constantly changing. This application proposes a method of using AI technology to conduct a progressive identification of illegal software. The intelligent permission management method proposed in this application realizes dynamic control of application behavior by building a progressive risk assessment system: first, based on the user's natural language instructions, that is, instructions triggered by natural language sentences (such as "only enable the microphone in entertainment scenes"), dangerous permissions are forced to run in a sandbox environment, and real resources are isolated and behavior detection is implemented through virtual data (empty contacts / simulated locations); secondly, a 0-100 point risk scoring mechanism (threshold 50 points) is adopted to dynamically adjust the permission opening strategy according to the execution content analysis (API call anomalies) and execution rule analysis (high-frequency sensor access at night). When the standards are met, the permission opening strategy is adjusted by time (time period), space (directory level), scene (single scene) and so on. Permissions are gradually released along three dimensions (e.g., expansion) while continuously recording permission adjustment logs. Thirdly, behavioral profiles are constructed through multimodal data collection (text logs / UI screenshots / audio and video streams / network traffic). Unusual patterns (such as interface phishing / data exfiltration) are identified by combining unsupervised learning algorithms for anomaly detection with models for solving classification and regression problems. Finally, for applications judged to be high-risk (risk score, also known as risk measurement information, ≥50 points), features are automatically extracted and malicious features are matched against a cross-modal evidence chain and a cloud-based knowledge base, also known as a threat signature library (including online public opinion / official announcements). Once the risk is confirmed, sandbox-enhanced isolation is implemented or uninstallation is recommended. Dynamic updates to the threat signature library are also supported to respond to new attacks. The threat signature library can include a signature library for potential threats within the application and can store threat-related features internally. This approach implements the "minimum necessary" principle through quantitative assessment, combines progressive openness to reduce user interference, and forms a complete closed loop from intent identification to threat response.
[0175] Figure 2 This is a schematic diagram of a system architecture provided by an embodiment of the present application, see Figure 2 The system for implementing permission allocation in this application includes a control module (such as the AI Agent main control module), a scene recognition module (such as the scene recognition AI module, which is a model that implements scene recognition through AI technology), an application detection and data acquisition module, a dynamic permission allocation and sandbox management module, a multimodal processing module, and a model knowledge base and automatic learning update module. The following describes each module:
[0176] 1.AIAgent main control module
[0177] Function: Parses natural language input and identifies permissions management intent. It possesses reasoning, decision-making, and task decomposition capabilities. As the core control module, it coordinates and manages other modules within the system, such as the dynamic permissions allocation and sandbox management modules, enabling coordinated permissions management and sandbox technology applications.
[0178] Technical implementation: A small end-side running model based on Large Language Models (LLM). Combined with a deep learning model for natural language understanding and intent recognition. Among them, the small end-side running model can be considered a lightweight model running on the terminal device. Lightweight can be to optimize and compress the model for permission allocation so that the model can be used for permission allocation. LLM can be a model based on artificial intelligence technology with a huge data scale. The huge amount of data is not limited here and can be greater than the set value, such as reaching billions or even trillions of parameters. For example, it is composed of billions to trillions of neural network parameters.
[0179] 2. Scene Recognition Module
[0180] Function: Detects the usage scenario of terminal devices, i.e., whether the terminal device is being used, such as rest or work, to provide a basis for permission control. The scenario recognition module can identify various environmental information to determine the usage scenario.
[0181] Technical Implementation: Adopts a multimodal Transformer architecture (which can handle information fusion of different modalities through self-attention mechanism). Processes information from sensors, GPS, cameras, microphones and other data sources.
[0182] 3. Permission management and storage module
[0183] Function: Stores set permission control rules, also known as permission control policies, including permission grant, permission denial, and permission use when conditions are met. It also stores permission usage information for different applications and supports dynamic rule updates.
[0184] Technical implementation: Structured database storage permission control rules. Combined with local storage and cloud synchronization update mechanism.
[0185] 4. Dynamic permission allocation and sandbox management module
[0186] Function: Dynamically assign app permissions based on intent and scenarios. Use sandbox technology (virtual environment) to isolate restricted permissions, ensuring that app functions are available without accessing real data.
[0187] Technical Implementation: Lightweight virtual machines or container technology enable independent operating environments. Work Profiles provide storage and permission isolation. API hooks intercept permission requests and return virtual data.
[0188] 5. Application detection and data collection module
[0189] Function: Detect the running status of the application in sandbox and non-sandbox modes.
[0190] Collect multimodal data, such as API calls, UI screenshots, audio and video recordings, network traffic, etc.
[0191] Technical Implementation: Data is collected through a combination of system logs, network traffic detection, UI screen recording, microphone acquisition, etc. The above data is obtained with user authorization and stored in encrypted form.
[0192] 6. Multimodal processing module
[0193] Function: Extract features from collected text, images, audio, and video data.
[0194] Technical Implementation: Natural Language Processing (NLP) is used to analyze API call logs. Computer vision is used to analyze UI interfaces and detect phishing attempts. Speech recognition is used to analyze audio data.
[0195] In addition, the AIAgent main control module can also perform anomaly detection to identify whether applications have malicious behaviors such as data theft, phishing interfaces, and privacy violations. It can use unsupervised and supervised learning to detect malicious patterns.
[0196] 7. Model knowledge base and automatic learning update module
[0197] Function: Updates and identifies characteristics of malicious applications through channels such as online public opinion and official announcements.
[0198] Continuously optimize the supervised learning model to improve recognition accuracy.
[0199] Technical Implementation: Obtain official security notices and user feedback data to automatically update the model knowledge base for model updates. The model knowledge base can be deployed in the cloud, also known as a cloud knowledge base. Incremental learning mechanisms are used to dynamically adjust the anomaly detection model, such as the model in the AIAgent main control module.
[0200] This application uses the AI agent (Agent) main control module in combination with natural language processing technology to accurately identify personalized needs in permission management and automatically generate permission control rules. At the same time, the system performs multimodal processing through the multimodal processing module to provide a more accurate basis for permission decision-making. When an application permission request occurs, the AI Agent main control module dynamically determines the permission grant based on user intention and usage scenario, and can implement permission isolation through virtual machines, containers, cloud environments or work profiles, thereby improving privacy and security while protecting application functions. In addition, the method also includes application detection and anomaly detection mechanisms, which collect multimodal data (text, visual, audio, video, network traffic, etc.) in sandbox mode and non-sandbox mode, and use the multimodal processing module to extract features to identify malicious or abnormal behavior. Based on the results of multimodal processing, the AI Agent main control module can apply anomaly detection, and the system can further generate risk scores and analysis reports. The system gradually reduces the isolation level based on the risk score, and finally removes the restricted permissions from the sandbox when the security conditions are met. It also interacts with users through the AIAgent main control module to dynamically adjust permission restriction policies to ensure system security. At the same time, it continuously updates the model knowledge base to adapt to new malware threats and achieve more intelligent and adaptive permission management.
[0201] This application is applicable to the intelligent identification of various types of illegal software, including but not limited to "viruses, phishing, Trojans, and fraudulent software". The terminal devices are not limited to mobile phones or computers, and the operating system is not limited.
[0202] The following describes the steps for assigning permissions and detecting applications for this application:
[0203] Step 1: Determine the terminal usage scenario and the intention of assigning application permissions
[0204] The usage scenario of the perception terminal can provide a basis for the application's permission limitation. This application provides an automated permission control system for applications. The control of application permissions is based on the automation of user intentions, which are identified from the natural language conversation with the user. For example:
[0205] For example, when an application is launched and requests microphone permission, the user can say that the microphone permission can only be enabled when I speak to the phone screen. That is, in response to the application's permission request, a natural language statement for controlling the application's permissions is obtained.
[0206] Example 2: When an app is launched and requests GPS location information, the user can tell any app not to obtain my location information at one or more addresses.
[0207] Example 3: When an app is launched and requests contact information, the user can say that the contact information of relatives and friends cannot be shared.
[0208] The AI Agent main control module and scene recognition module implement user intent recognition and scene recognition in this step. For example, the AI Agent main control module can perform intent recognition and scene recognition, while the scene recognition module collects the necessary scene information. Alternatively, the AI Agent main control module can perform intent recognition, while the scene recognition module performs scene recognition.
[0209] The AIAgent main control module has natural language recognition, reasoning and decision-making capabilities, and task decomposition capabilities. It can be a small, on-device model based on the LLM. The scene recognition module can be a multimodal model, implemented using an open-source model based on the Transformer architecture.
[0210] To achieve permission control in various situations, the scenario perception described in this application is multifaceted and includes the following environmental information:
[0211] 1. Awareness of application status (including but not limited to: whether the application is in the foreground or background, the activities started by the application, and the various states of the activity)
[0212] 2. The location of the terminal (including but not limited to: GPS coordinates, current Wi-Fi hotspot, wireless location area, base station number and cell information)
[0213] 3. The user's location, such as driving, running, etc. (including but not limited to: air pressure sensor values, acceleration sensor values, geomagnetic sensor values, GPS coordinates.)
[0214] 4. The external scene of the terminal device (including but not limited to: ambient noise collected by the microphone, images collected by the camera, and GPS location information)
[0215] 5. Historical application operations (including but not limited to: application call status and probability statistics in each time period).
[0216] Among the above information, sensitive information involving user privacy (such as GPS coordinates, sound, video, etc.) should be avoided. If it must be used, the user's authorization will be obtained in advance. If the user does not authorize, it will not be used.
[0217] When an application launches and requests permissions (such as microphone, GPS, and contact information), the system triggers natural language recognition. The system prompts the user for input through natural language dialogue. The user can say, "Microphone permission is enabled only when I speak into the phone screen," or "No apps should collect my location information at a certain address," or "Friends and family contact information cannot be shared." This user input enters the AIAgent main control module, which performs the following steps: Natural language understanding: Parsing the natural language sentence to extract intent; Condition extraction: Identifying user-specified conditions (i.e., identifying control conditions for the permission based on the natural language sentence), such as "speaking into the phone screen" or "at a certain address." Scenario mapping (matching the control conditions with applicable scenarios recognizable by the terminal device): Mapping the conditions to scenarios recognizable by the terminal device. For example, "speaking into the phone screen" might involve detecting voice through the microphone and imagery through the camera. Rule storage: The system stores permission control rules, also known as permission control policies, which include permission identification information (used to identify the corresponding permission) and applicable scenario conditions (the scenarios to which the permission applies). The permissions and applicable scenarios are then defined as the permission control policy.
[0218] This step will provide a basis for the permission control in the next step.
[0219] Step 2: Dynamic allocation of application permissions and running in sandbox mode (or sandbox mode)
[0220] After the first step is executed, the permission management of the application will be divided into three categories: permissions that are fully allowed to be executed, permissions that are completely not allowed to be executed, and permissions that can be used in certain scenarios set by the user. Permissions that are fully allowed to be executed and permissions that can be used in certain scenarios set by the user also include dangerous permissions. However, the normal execution of the application must rely on certain necessary permissions. In order to ensure the correct execution of the application and protect the privacy and security of the user, a sandbox mode is provided to ensure the execution of the application. The sandbox mode defined in this application refers to providing a virtual, isolated operating system, or isolated memory, file storage space for a specific application. For operations that you do not want the application to perform on the local operating system, they are executed on the virtual operating system, or the isolated memory or file storage space is read.
[0221] Typically, a terminal operating system has hundreds of permissions, which are classified into: normal permissions, which are automatically granted during installation; dangerous permissions, which are authorized at runtime; signature permissions, which are limited to applications with the same signature; and special permissions, which are controlled at the system level.
[0222] The sandbox mode is used for the a priori execution of dangerous permissions. During the a priori period, function calls of dangerous permissions of the application are detected in the sandbox, and abnormal behavior of the application is examined. This provides a basis for the subsequent gradual removal of permission execution from the sandbox mode and dynamic allocation to the real execution environment.
[0223] The dynamically allocated permissions controlled by this application are dangerous permissions, including but not limited to the following:
[0224] 1. Calendar read and write permissions;
[0225] 2. Camera usage rights;
[0226] 3. Contact read, write and quantity access permissions;
[0227] 4. Access to location;
[0228] 5. Microphone usage permissions
[0229] 6. Telephone Access
[0230] 7. Access to various sensors;
[0231] 8. Permission to read, send, and receive text messages;
[0232] 9. Access the mobile phone file storage system and read the user's multimedia pictures, videos, and audio data;
[0233] 10. Allow permission to install apps;
[0234] 11. Permission to switch airplane mode;
[0235] 12. Permissions for floating windows;
[0236] 13. Manage Bluetooth permissions;
[0237] 14. Modify the authority of system security;
[0238] 15. Allow the permission to start the system;
[0239] 16. Permission to send broadcasts within the system.
[0240] When the user's permission control intention is identified as described in the first step, the user's intention will be formed into a permission control rule and stored in the system. When the application is executed and applies for permission, the AIAgent main control module matches the permission control policy according to the current terminal usage scenario, and finds the permissions that can be allowed (i.e., the first permission) and the permissions that cannot be allowed (i.e., the second permission). That is, based on the matching results between the terminal device usage scenario and the applicable scenario, the permissions of the application in the usage scenario are determined. For permissions that cannot be allowed, sandbox technology is used to allow the application to continue running (i.e., running the second permission in a sandbox environment). If the permission is related to calling a related device and the related device cannot run in the sandbox, the permission is denied and the user is notified.
[0241] The sandbox mode uses the following technical means:
[0242] 1. Use lightweight virtual machines to establish an independent operating system environment and storage space;
[0243] 2. Use container technology to establish a system and storage space isolated from the original system, or an isolated process space;
[0244] 3. Deploy cloud services and establish a virtual system in the cloud for each user, using the virtual space as a sandbox environment;
[0245] 4. You can use a work profile (WorkProfile) to implement an isolated environment.
[0246] The permissions suitable for using sandbox technology are:
[0247] 1. Calendar read and write permissions;
[0248] 2. Contact read, write, and quantity access permissions;
[0249] 3. Access to location;
[0250] 4. Permission to read, send, and receive text messages;
[0251] 5. Read the mobile phone file storage system;
[0252] 6. Allow permission to install apps;
[0253] 7. Permission to switch airplane mode;
[0254] 8. Modify the permissions of system security;
[0255] 9. Allow the permission to start the system;
[0256] 10. Permission to send broadcasts within the system.
[0257] The application implementation of the sandbox can be:
[0258] 1. If the app's calendar read permission is restricted, the app reads a virtual calendar database or storage that contains no user-related schedules. The restricted app can only read another virtual calendar database or storage.
[0259] 2. If the app's contact read permission is restricted, the app reads a virtual contact database or storage, which does not contain the user's contact information. The restricted app can only read another set of virtual contact database or storage.
[0260] 3. If you want to restrict an app's SMS permissions, you can create a dedicated SMS storage space for the app and allow the app to only read this isolated SMS storage space.
[0261] 4. If the application's permission to read and write the phone's file storage system is restricted, an isolated virtual storage space is provided.
[0262] In these situations, sandbox mode uses a work profile to implement an isolated environment. Apps run in the work profile and access isolated storage space, which can be preset with empty or dummy data. For example, the calendar database contains no user schedules, the contact database contains no real contact information, and the SMS storage contains only dummy messages. Apps run normally, but cannot access real data, protecting privacy.
[0263] 5. If you restrict an app's location permissions, provide obfuscated or fake location information based on user intent, such as a fixed coordinate or a randomly generated location.
[0264] 6. If you restrict an app's installation permissions, system security permissions, airplane mode permissions, startup permissions, and system broadcast permissions, you can allow the app to run in a virtual, independent operating system, transmit the app's execution instructions and results through a secure pipeline, and restore the UI display of the app on the original operating system.
[0265] Step 3: Collect multimodal data about application execution
[0266] Acquire multimodal data from applications running in sandbox and non-sandbox modes. This is performed by the application instrumentation and data collection module.
[0267] In sandbox mode: the application runs with restricted permissions, and the sandbox provides virtual data (such as an empty contact list and simulated locations). In this mode, the operation of the application can be detected.
[0268] In non-sandbox mode: the application runs with the granted permissions and calls the real system modules. In this mode, the application operation is detected.
[0269] The information involved in this process should be notified to the user in advance and the user's authorization should be obtained. In addition, the detection of applications does not include all applications, but can be suspicious applications with the user's consent and designation.
[0270] In the above two modes, the multimodal data of the mobile phone includes but is not limited to the following:
[0271] Text data: Get text logs of API calls, system interactions, error messages, and application output. You can also get the application package name, size, etc.
[0272] Visual data: Capture UI screenshots at key points, such as when permissions are requested or sensitive information is displayed.
[0273] Audio data: If the app uses the microphone or generates sound, capture the audio and check for unauthorized recordings or suspicious content.
[0274] Video data: Record screen activity, capture dynamic operations and user interactions, and identify automated operations or abnormal behavior.
[0275] Network data: Detects network traffic, including destination addresses, protocols, and data volumes, and detects communications with known malicious servers.
[0276] Resource usage data: Detect changes in CPU, memory, and battery consumption over time to identify unusual usage patterns such as cryptocurrency mining.
[0277] Sensor data: If the app accesses sensors (such as GPS, accelerometer, barometer, geomagnetic information, etc.), store the access data to ensure consistency with the app's functionality.
[0278] Step 4: Feature extraction and anomaly detection for multimodal data
[0279] The multimodal processing module can process different types of data, such as text, images, audio, and video, and achieve comprehensive reasoning and generation through cross-modal alignment and fusion techniques. The model in this application has cross-modal understanding capabilities and generates text descriptions based on images, audio, and video. The multimodal processing module can be deployed in the cloud or locally.
[0280] Extract relevant features from the multimodal data collected in the previous steps to facilitate the identification of potential abnormal or suspicious patterns.
[0281] Multimodal data can be categorized into text, image, audio, and video data. The multimodal processing module in the system performs the following preprocessing operations on the received data to extract key features:
[0282] Text data: For example, text logs or network request records, semantic features are extracted through natural language processing technology and converted into vector representations for subsequent analysis.
[0283] Image data: For example, screenshots of an application interface are first resized to a uniform resolution, and then visual features are extracted using a convolutional neural network.
[0284] Audio data: For example, conversation recordings are transcribed into text using a speech recognition model, and then analyzed for key information using natural language processing technology.
[0285] Video data: For example, screen recordings, use video analysis models to extract dynamic features. Dynamic features can be features of objects or people in the video that change over time.
[0286] In terms of content, the data executed by an application includes the following types (corresponding to the previous step). The AIAgent main control module can analyze and detect anomalies for each type:
[0287] Text Data Analysis:
[0288] Use natural language processing (NLP) technology to analyze logs, identify API call sequences, and detect patterns of malicious behavior that violates rules or is illogical, such as unauthorized access to sensitive data.
[0289] Visual Data Analysis:
[0290] Use computer vision algorithms to analyze UI screenshots and detect signs of phishing, such as interfaces that mimic legitimate apps. Identify hidden or suspicious UI elements that may be used for malicious purposes.
[0291] Audio data analysis:
[0292] Use speech recognition to transcribe text and analyze content for phrases associated with privacy violations or social engineering. Compare audio activity to user interactions and detect unauthorized recordings.
[0293] Video data analysis:
[0294] Use action recognition models to detect automated behaviors or sequences that indicate malicious intent, such as automatic clicking or navigation without user input.
[0295] Network data analysis:
[0296] Analyze network traffic to check for connections to known malicious IP addresses or domains. Detect unusual data transmission patterns that may indicate a data breach.
[0297] Resource usage analysis:
[0298] Apply statistical methods to identify spikes or sustained high consumption in resource usage that deviate from normal application behavior and may indicate malicious activity such as cryptocurrency mining.
[0299] Sensor data analysis:
[0300] Verify that sensor data access is consistent with the app's declared capabilities and user consent.
[0301] Table 1 is a schematic table of multimodal data provided in an embodiment of the present application. Referring to Table 1, different types of data correspond to different analysis methods and to different malicious behaviors.
[0302] Table 1
[0303]
[0304] Multimodal data analysis can use LLM to identify malicious behaviors of applications using unsupervised learning and supervised learning models to obtain detection results.
[0305] Unsupervised learning: Preliminary screening of potential anomalies:
[0306] The system first uses unsupervised learning methods to identify cross-modal outliers that are inconsistent with the behavior of most applications (in multimodal data scenarios, outliers caused by abnormal correlation or semantic conflict between modalities, that is, some data shows significant inconsistency or anomalies between modalities). These outliers represent potentially abnormal behaviors, such as:
[0307] 1. "Ads are displayed on the interface but there are no corresponding network requests" may indicate advertising fraud or data falsification.
[0308] 2. "Frequent camera calls at night when there is no user interaction" may indicate unauthorized surveillance.
[0309] Unsupervised learning does not require pre-labeled data and can discover new, unknown abnormal patterns.
[0310] Supervised learning: Rapidly identifying known malicious behavior
[0311] For known malicious behavior patterns, the system uses a pre-trained classification model to quickly predict the illegitimate nature of an application based on a large amount of labeled sample data of both malicious and legitimate applications. This labeled data comes from security expert analysis, user feedback, or historical malware databases. This approach is highly effective in detecting common malicious behaviors, such as "an application continuously accessing the contact list in the background," which is already flagged as data theft.
[0312] The detection results may include the above-mentioned abnormal behaviors or malicious behaviors.
[0313] Step 5: Gradually remove dangerous permissions from the sandbox
[0314] Methods for gradually moving dangerous permissions out of the sandbox:
[0315] The AIAgent main control module performs detection and risk assessment based on the application's running status in the sandbox, implementing a fine-grained strategy for gradually removing dangerous permissions from the sandbox:
[0316] The evaluation of gradually moving dangerous permissions out of the sandbox is as follows:
[0317] Analysis of execution content: Detecting whether the application has abnormal behavior (such as unauthorized file access and communication with overseas servers).
[0318] Execution pattern analysis: Determine the rationality of behavior patterns (such as camera calls and high-frequency network requests at night when there is no interaction).
[0319] The content analysis may be performed once to determine whether the application has abnormal behavior, and the pattern analysis may be performed multiple times to determine the rationality.
[0320] The application risk scoring rules are as follows:
[0321] The system presets a scoring range (0-100 points) and the threshold is set at 50 points.
[0322] Scenarios for score improvement may include the following:
[0323] Frequently calling the camera API and not matching the usage scenario (such as rest);
[0324] Access the local file system when the user is not operating;
[0325] The application accesses overseas servers without reasonable business needs.
[0326] The gradual permission adjustment strategy is as follows:
[0327] The risk score (i.e., risk measurement information) is lower than the threshold (<50 points), that is, the threshold is set:
[0328] Gradually open permissions: Based on the application's behavior (which can be measured by risk scoring), dangerous permissions are removed from the sandbox in stages. The stages can be divided into the following dimensions.
[0329] Time dimension: Expand the duration of permissions by time period (e.g. 9:00-12:00 → 9:00-24:00). This means the permissions are adjusted according to the magnitude of this adjustment.
[0330] Spatial dimension: Expand file access scope by directory hierarchy (e.g., / app / cache → / data / app).
[0331] Scenario dimension: Expanding from a single scenario (such as entertainment) to multiple scenarios (such as work and entertainment).
[0332] Continuous monitoring: Maintain real-time monitoring of steps 1-4 and record permission adjustment logs (e.g., "2025-03-31 14:00, storage permissions opened to / data").
[0333] Risk score above the threshold (≥50 points):
[0334] Keep it restricted: Maintain sandbox isolation or virtual data, and prohibit access to real resources.
[0335] The risks in the sandbox stage (such as the risks corresponding to when the risk score is higher than the threshold) can be prompted to the user and it is recommended to uninstall the application, or further restrict permissions according to user instructions (that is, output the first prompt information to allocate permissions based on the new permission control information). The user can again provide natural language statements through dialogue with the AI Agent main control module to determine the application restriction intention and permission control rules, and then re-control the application permissions.
[0336] If the application runs stably and without anomalies in sandbox mode: If the risk score consistently meets the requirement (e.g., <50 points for 7 consecutive days), the application will be fully authorized and will exit sandbox mode. This can be determined by whether the risk score consistently meets the requirement a set number of times or for a set duration.
[0337] After all permissions are removed from the sandbox, you can still continue to apply steps 3-4 to ensure the security of the application.
[0338] Step 6: Update the model knowledge base based on online public opinion or official announcements of illegal software features
[0339] A supervised learning model is a model that analyzes multimodal data based on pre-training or knowledge base learning to identify illegal behavior. The model of this application, such as the model in the control module, has the ability to learn online public opinion and official announcements of illegal software features. It can automatically acquire relevant knowledge and improve the model's ability to identify illegal applications in real time.
[0340] Step 7. Comprehensive evaluation and report generation
[0341] The control module analyzes the multimodal data to generate a risk score for the application (ranging from 0 to 100). The control module also uses a generative model to generate a detailed analysis report, which is the first prompt information. The generative model can be considered a machine learning model that learns the data distribution and generates new samples. The report includes:
[0342] Risk score: For example, "92" indicates high risk.
[0343] Analysis conclusions: For example, "The app frequently calls GPS at night when there is no user operation (abnormal behavior), there is a hidden button in the interface (abnormal image), and the audio mentions 'Please authorize access to contacts' (abnormal audio)" and "The app continuously accesses the contact list in the background in the middle of the night, which is consistent with known malicious behavior and further investigation is recommended."
[0344] Evidence information, such as the chain of evidence: for example, "the interface screenshot shows a hidden button," or "the audio recording contains 'Please authorize access to contacts'."
[0345] The control module can complete risk scoring and reporting by itself, or control the rest of the modules in the system to complete risk scoring and reporting, or complete risk scoring and reporting through the server.
[0346] After the analysis is complete, the results are stored in the cloud database in JSON format. When the server completes the risk scoring and reporting, it is transmitted to the terminal device through a secure channel for the AIAgent main control module to make decisions.
[0347] Step 8: Task decomposition and supervision of the AIAgent master control module
[0348] The AIAgent main control module, acting as an intelligent decision-making center, receives the risk analysis results from step 7, including the risk score, evidence, and analysis conclusions. It then interacts with the user through natural language to determine the next steps. By default, if an app exhibits suspicious behavior, the AIAgent main control module reports it to the user. If the behavior is considered highly dangerous, it directly recommends or initiates an uninstall. However, users may wish to continue using the app despite being aware of the suspicious behavior and impose specific restrictions. To this end, the AIAgent main control module communicates with the user through natural language, breaking down user instructions into actionable tasks, implementing these tasks, and continuously monitoring the implementation to ensure that the app's behavior meets user expectations. Furthermore, the risk analysis results from step 7 may include recommendations requiring further investigation, such as "The app continuously accesses the contact list in the background at night, which is consistent with known malicious behavior. Further investigation is recommended." The AIAgent main control module then decomposes the risk analysis results into further tasks, such as continuing to observe to detect patterns or directly prohibiting the app from accessing contacts in the background based on the user's instructions.
[0349] 1. Receive and present risk assessment
[0350] Step 8 begins with the AIAgent master module analyzing the risk results from step 7, including the application's risk score, analysis conclusions (specific descriptions of suspicious behavior), and evidence. The AIAgent master module converts this information into a natural language report (i.e., a risk report) for user understanding and decision-making. For example, the following report might be generated:
[0351] "App 'A' has a risk score of 85 out of 100. App 'A' frequently accesses location data when not in use, which may pose a privacy risk."
[0352] The AIAgent main control module then asks the user to choose:
[0353] "Do you want to uninstall this app, or continue using it and set limits?"
[0354] Analyze and process the instructions. If the user chooses to uninstall, the AIAgent main control module will immediately perform the uninstall operation. However, if the user chooses to keep the app, the AIAgent main control module will further instruct the user to specify the specific restriction requirements.
[0355] 2. Talk to users and collect their instructions
[0356] When the user decides to continue using the app, the AIAgent main control module will ask the user for permission restrictions in a dialogue, for example:
[0357] "Please tell me what restrictions you'd like to place on app 'A'. You can choose to prevent it from automatically launching in the background, block background access to GPS, block ads, or restrict it from connecting to certain servers."
[0358] The user may respond in natural language, i.e., new permission control information, such as:
[0359] “I want to continue using this app without it running in the background and without pop-up ads.”
[0360] The AIAgent master module uses natural language processing (NLP) technology to parse these instructions (i.e., new permission control information, also known as retrieved permission control information), identify keywords and intents, and map them to permissions supported by the system. Permissions, for example:
[0361] "Do not start in the background" is mapped to prohibit automatic background startup.
[0362] "No pop-up ads" is mapped to blocking advertising content.
[0363] This step ensures that the AIAgent main control module can accurately understand the user's intentions.
[0364] 3. Break down instructions into tasks
[0365] After understanding the user's instructions, the AIAgent main control module will break them down into specific, actionable tasks. These tasks are the technical means to implement user restrictions. For example:
[0366] Prevent automatic background launch: Adjust the app's system permissions or settings to disable its ability to launch without user interaction.
[0367] Ad blocking: This is achieved by intercepting network requests to the ad server or modifying the application interface to hide ad elements.
[0368] After the decomposition is completed, the AIAgent master module will directly execute these tasks or delegate them to relevant modules in the system, such as the system or network filter that implements permission management.
[0369] 4. Perform tasks and monitor results
[0370] After the task is executed, the AIAgent main control module will continue to mobilize the application detection and data collection module and the multimodal processing module to monitor the running status of the application and ensure that the restriction measures are effective. For example:
[0371] Check if the app is still trying to launch in the background.
[0372] Verify that ads are blocked successfully, or if ad content is still being displayed.
[0373] If the restriction is found to be incomplete (for example, the app still displays ads in some way), the AIAgent main control module will take further action:
[0374] Adjust task strategies, such as strengthening network filtering rules.
[0375] Report a problem to a user: "We try to block ads, but some ads may still appear. Would you like to try another method or uninstall the app?"
[0376] This real-time monitoring mechanism ensures that the user's security goals are implemented.
[0377] 5. Recording and Optimization
[0378] Throughout the entire process, the AIAgent control module records all actions in detail: user instructions, decomposed tasks, specific measures executed, and the application's performance under restrictions. This record not only provides transparent feedback to users but also provides data support for the AI Agent control module's self-optimization. For example, if a user repeatedly requests to block ads, the AIAgent control module may proactively recommend this restriction or improve the ad blocking strategy.
[0379] The AIAgent Master Control module not only provides recommendations based on risk assessments but also communicates with users through natural language, understanding and executing complex and personalized instructions. From report generation to task breakdown, execution, and oversight, the AIAgent Master Control module ensures that users can access application functionality while maintaining security controls. This continuous, context-sensitive interaction allows users to easily manage application behavior, while the AIAgent Master Control module continuously improves its service quality through supervision and learning.
[0380] This application uses AI technology based on multimodal data to achieve dynamic protection of the entire chain of application installation security verification. By using environmental information for scene recognition, this application can determine the current usage scenario (such as work, entertainment, rest, etc.) in real time, providing accurate contextual basis for subsequent permission allocation and risk assessment, thereby intelligently allocating initial permissions in different scenarios, making up for the shortcomings of traditional technology in protecting unofficial application downloads. In the initial permission allocation and sandbox observation stage, the system uses a virtualized operating environment to detect application behavior, dynamically analyzes the application's permission requests through AI, identifies potential sensitive permissions, and based on risk scoring, gradually opens permissions or maintains restrictions, effectively preventing abnormal permission applications and illegal resource access. Through continuous detection and behavioral pattern recognition, this application obtains and analyzes long-term behavioral data, combines a model that implements multimodal analysis to conduct in-depth fusion analysis of text, image, audio and video data, captures abnormal behavior in a timely manner, and generates detailed analysis reports, thereby greatly improving the timeliness and accuracy of security warnings. Ultimately, the AIAgent main control module organically combines the risk analysis results with the user's security policy to achieve intelligent decomposition and supervisory processing of risky applications, enabling the system to actively respond to user processing instructions (such as uninstalling or setting restrictions), ensuring that the security of the entire application download, installation and operation process is significantly improved.
[0381] To sum up, this application organically integrates scene recognition, dynamic permission management, behavior monitoring and multimodal in-depth analysis to form a complete protection system that comprehensively covers all aspects from application download to installation to subsequent operation, significantly improving the overall security protection capabilities.
[0382] The following lists all possible applications of this application in the current and future technological environments, as well as possible expanded application areas in combination with other known or potential technologies:
[0383] 1. Provide security protection for mobile terminals
[0384] Implement app store security verification: As a security detection module for app stores, third-party markets, or internal enterprise application platforms, it provides full-chain security detection before and after the application is launched, including permission analysis and behavior monitoring, to prevent malicious or tampered APKs.
[0385] Real-time terminal security protection: Integrated into mobile devices such as smartphones and tablets, it detects application behavior and permission requests in real time, intelligently adjusts permissions based on usage scenarios, and prevents privacy leaks and data theft.
[0386] 2. Enterprise-level mobile security management
[0387] Enterprise Mobile Device Management (EMM) system: As part of the EMM or mobile security management system, it performs dynamic risk assessments on the installation, update, and operation of enterprise applications to prevent information leakage or system compromise caused by permission abuse or malicious behavior.
[0388] Customized risk warning and response platform: Integrates with the company's security strategy to proactively prevent potential threats and provide detailed risk reports and emergency response recommendations.
[0389] 3. Internet of Things (IoT) and Smart Home Security
[0390] IoT device application security monitoring: In smart homes, wearable devices, or industrial IoT devices, similar technologies are used to perform security verification on device-side software to ensure that sensor data, network requests, and permission calls comply with preset security policies.
[0391] Smart home unified security platform: Integrates data from various terminal devices, analyzes abnormal operations through multimodal data analysis models, and prevents hackers from using home devices as a springboard for attacks.
[0392] 4. Cloud and edge computing security applications
[0393] Cloud security monitoring platform: Deployed in the cloud, it performs large-scale data integration and in-depth analysis of multimodal data of applications uploaded from terminals, providing security risk assessment and early warning services for users of different sizes.
[0394] Edge computing security node: Combined with the low latency characteristics of 5G, it is deployed on the edge server as a security detection module to achieve real-time, local application security verification, improving user experience and response speed.
[0395] 5. Cross-platform and cross-modal security protection
[0396] Security modules applicable to multiple operating systems: applicable to multiple operating systems, not limited to desktop applications and embedded systems, and enabling more extensive security verification through the integration of multimodal data (such as images, audio, and logs).
[0397] Combined with blockchain technology: Use blockchain to achieve tamper-proof records of application authenticity and enhance the credibility of security verification.
[0398] 6. Security Big Data and Threat Intelligence Platform
[0399] Risk trend and behavior pattern analysis: By aggregating multimodal data from applications and combining it with machine learning and deep analysis models, we can predict cross-scenario risk trends and use them as a basis for decision-making.
[0400] Intelligent Security Consulting Services: Provides customers with customized security reports and recommendations to proactively prevent potential threats.
[0401] 7. Support for standard setting
[0402] Security standard testing tools: Provide standardized tools for application security testing, and assist in the development and promotion of application security testing standards.
[0403] Public security information sharing platform: realize cross-organizational and cross-domain security collaborative protection.
[0404] 8. Integration with artificial intelligence and other emerging technologies
[0405] Adaptive security policy system: Combined with adaptive AI-based strategies, it enables dynamic adjustment and optimization of security policies.
[0406] Virtualization and simulation testing platform: Combining virtualization, sandbox, and simulation technologies, it conducts pre-tests on the security of new applications, verifies their permission calls and behavior in various usage scenarios, and identifies potential risks in advance.
[0407] In summary, this application not only offers significant advantages in the security protection of mobile applications (e.g., software applications running on mobile devices), but also forms a comprehensive, multi-layered security protection system through the organic integration of multiple technologies, including enterprise-level management, the Internet of Things, cloud / edge computing, big data analysis, blockchain, and standard setting. This not only enhances the security experience but also provides solid technical support for building a more secure network ecosystem.
[0408] In today's increasingly digital security landscape, users are increasingly concerned about privacy and data protection. This application's full-process security verification system significantly improves security.
[0409] When downloading and installing an APK, you can be prompted that the application uses the permission allocation method of this application to allocate permissions and detect application security. The technical solution of this application can achieve more accurate risk identification, more intelligent dynamic permission management, and more timely threat warnings.
[0410] This application uses AI technology to collect and analyze multimodal data, which can effectively identify abnormal behaviors and potential risks.
[0411] The solution of the present invention can dynamically adjust permission settings according to the behavior of the application in different usage scenarios by collecting and analyzing data in real time, making permission adjustments more timely.
[0412] This application can integrate source verification, dynamic permission adjustment, sandbox monitoring and multimodal in-depth analysis, forming a security protection chain from application download, installation to operation.
[0413] This application can not only identify known threats, but also has the ability to intelligently predict and analyze unknown abnormal behaviors, providing users with a higher level of security.
[0414] Figure 3 This is a flowchart of a permission allocation provided by an embodiment of the present application, see Figure 3 This embodiment determines the usage scenario of a terminal (also known as a terminal device) and the control conditions corresponding to a natural language statement to obtain a permission control policy. Based on the usage scenario and the permission control policy, application permissions are dynamically allocated, and a second permission with limited usage is run in a sandbox model.
[0415] During the operation of the sandbox mode, a sandbox technology may be selected to establish a sandbox environment, which may also be pre-established. The second permission is run in the sandbox environment to implement control over the second permission.
[0416] Running in sandbox mode can be considered as running in a sandbox environment, and risk measurement information is determined by detecting the running status inside and outside the sandbox. When the risk measurement information is less than the set threshold, permissions are gradually opened. And the running status inside and outside the application sandbox is continuously detected. When the risk measurement information is greater than or equal to the set threshold, the restricted state of the second permission can be maintained, and the user can be prompted, such as outputting a risk report after the second prompt information is converted. When the user enters new permission control information, the new permission control information is obtained, and the control conditions of the permission are determined based on the new permission control information. In combination with the usage scenario, a new permission control policy is determined. When the processing instruction indicates to uninstall the application, the application is uninstalled.
[0417] During the sandbox operation status detection process, multimodal data of application execution can be collected, including multimodal data collection inside and outside the sandbox. Feature extraction and anomaly detection are then performed on the collected multimodal data to determine risk measurement information.
[0418] In this application, the control module can perform task decomposition, execution, and supervision during the process of assigning permissions based on permission control information. If the permissions are adjusted and invalid, the task strategy can be adjusted; otherwise, the task strategy can be recorded and optimized.
[0419] In an exemplary embodiment, the present application further provides a rights allocation device, which can be integrated into a terminal device. Figure 4 This is a schematic diagram of the structure of a permission allocation device provided in an embodiment of the present application; see Figure 4 , the authority allocation device includes:
[0420] An acquisition module 410 is configured to acquire permission control information, wherein the permission control information includes a natural language statement for controlling permissions of an application program;
[0421] A policy determination module 420 is configured to determine, based on the permission control information, a permission control policy corresponding to the permission control information, wherein the permission control policy includes applicable scenarios associated with the permission;
[0422] A scenario determination module 430 is configured to determine a usage scenario of the terminal device;
[0423] The allocation module 440 is configured to determine the permission of the application in the usage scenario based on the matching result between the usage scenario of the terminal device and the applicable scenario.
[0424] The rights allocation device provided in this embodiment is used to implement the following Figure 1 The rights allocation method of the embodiment shown in the figure, the rights allocation device provided in this embodiment implements the principle and technical effects similar to those of Figure 1 The permission allocation method of the illustrated embodiment is similar and will not be described again here.
[0425] Based on the above embodiment, a modified embodiment of the above embodiment is proposed. It should be noted that, in order to simplify the description, only the differences from the above embodiment are described in the modified embodiment.
[0426] In one embodiment, the acquisition module 410 is specifically configured to:
[0427] In response to the permission request of the application, a natural language statement for controlling the permission of the application is obtained.
[0428] In one embodiment, the policy determination module 420 is specifically configured to:
[0429] identifying a control condition for the permission based on the natural language statement;
[0430] Matching the control condition with an applicable scenario identifiable by the terminal device;
[0431] The authority and the applicable scenario are determined as the authority control policy.
[0432] In one embodiment, the scene determination module 430 is specifically configured to:
[0433] Obtaining environmental information, the environmental information indicating an environment associated with one or more of the terminal device and the application;
[0434] Based on the environmental information, determine the usage scenario of the terminal device.
[0435] In one embodiment, the allocation module 440 is specifically configured to:
[0436] Determining a matching result between a usage scenario of the terminal device and the applicable scenario, the matching result indicating whether the usage scenario matches the applicable scenario;
[0437] A first permission that is permitted for the application program and a second permission that is restricted for the application program are determined based on the matching result.
[0438] In one embodiment, the device further includes an operation module configured to:
[0439] The second permission is run in a sandbox environment, where the sandbox environment has an independent operating system and an independent storage space, and virtual data associated with the second permission exists in the sandbox environment.
[0440] In one embodiment, the device further includes a detection module configured to:
[0441] Acquiring multimodal data during the running of the application;
[0442] Performing feature extraction on the multimodal data to obtain key features;
[0443] Anomaly detection is performed on the application based on the key features to determine a detection result.
[0444] In one embodiment, the apparatus further includes a first adjustment module, comprising:
[0445] A first determining unit, configured to determine risk measurement information corresponding to the detection result;
[0446] The first adjustment unit is configured to adjust the restriction degree of the second permission when the risk measurement information is less than a set threshold, where the second permission includes a permission to restrict use of the application.
[0447] In one embodiment, the first adjustment unit is specifically configured to:
[0448] When the risk measurement information is less than a set threshold, the restriction degree of the second authority is adjusted from at least one dimension.
[0449] In one embodiment, the first adjustment module further includes a second determining unit configured to:
[0450] Determine a third permission associated with the risk metric information, where the third permission includes permission in the second permission to enable the risk metric information to take a value in a direction that increases risk; accordingly, the first adjustment unit is specifically configured to:
[0451] If the risk metric information is less than a set threshold, perform at least one of the following steps:
[0452] Setting the permissions in the second permission except the third permission to be allowed to be used by the application program;
[0453] The restriction degree of the third permission is adjusted from at least one dimension.
[0454] In one embodiment, the first adjustment unit is specifically configured to:
[0455] When the risk metric information is smaller than the set threshold value for a continuous number of times reaching a set number, the permission for adjusting the restriction degree is set to be allowed to be used by the application program.
[0456] In one embodiment, the dimension includes at least one of the following:
[0457] Time dimension, where the adjustment method corresponding to the time dimension includes extending the available time of the permission;
[0458] Spatial dimension, wherein the adjustment method corresponding to the spatial dimension includes extending the file access scope of the permission;
[0459] Scenario dimension, the adjustment method corresponding to the scenario dimension includes the applicable scenarios of the extended permissions.
[0460] In one embodiment, the device further includes a second adjustment module configured to:
[0461] Determining risk measurement information corresponding to the detection result;
[0462] When the risk measurement information is greater than or equal to a set threshold, a first prompt message is output, wherein the first prompt message prompts to re-acquire the permission control information and continue to allocate permissions to the application based on the re-acquired permission control information.
[0463] In one embodiment, the device further includes a third adjustment module configured to:
[0464] Determining risk measurement information corresponding to the detection result;
[0465] When the risk measurement information is greater than or equal to a set threshold, second prompt information is output, where the second prompt information includes the risk measurement information, the analysis conclusion associated with the detection result, and evidence information corresponding to the analysis conclusion.
[0466] In one embodiment, the apparatus further includes a generating module configured to:
[0467] generating a risk report based on the second prompt information;
[0468] outputting the risk report;
[0469] Obtaining a processing instruction triggered by a user in response to the risk report;
[0470] In the case where the processing instruction includes new permission control information, the following permission allocation method is continued:
[0471] Obtaining permission control information, wherein the permission control information includes a natural language statement for controlling permissions of the application program;
[0472] Determining, based on the permission control information, a permission control policy corresponding to the permission control information, wherein the permission control policy includes applicable scenarios associated with the permission;
[0473] Determine the usage scenario of the terminal device;
[0474] Based on the matching result between the usage scenario of the terminal device and the applicable scenario, the permission of the application program in the usage scenario is determined.
[0475] In one embodiment, the multimodal data includes one or more of the following:
[0476] Text data; image data; audio data; video data; network data; sensor data; resource data of resources in the terminal device.
[0477] In an exemplary embodiment, the present application also provides a terminal device, Figure 5 This is a schematic diagram of the structure of a terminal device provided in an embodiment of the present application. Figure 5 As shown, the terminal device provided by the present application includes one or more processors 51 and a storage device 52; the processor 51 in the terminal device can be one or more, Figure 5 Take a processor 51 as an example; the storage device 52 is used to store one or more programs; the one or more programs are executed by the one or more processors 51, so that the one or more processors 51 implement the permission allocation method as described in the embodiment of the present application.
[0478] The terminal device further includes: a communication device 53 , an input device 54 and an output device 55 .
[0479] The processor 51, storage device 52, communication device 53, input device 54 and output device 55 in the terminal device can be connected through a bus or other means. Figure 5 The bus connection is taken as an example.
[0480] The input device 54 may be used to receive input digital or character information and generate key signal input related to user settings and function control of the terminal device. The output device 55 may include a display device such as a display screen.
[0481] The communication device 53 may include a receiver and a transmitter. The communication device 53 is configured to perform information transmission and reception communication according to the control of the processor 51.
[0482] The storage device 52, as a computer-readable storage medium, can be configured to store software programs, computer executable programs, and modules, such as program instructions / modules corresponding to the permission allocation method described in the embodiment of the present application (for example, the acquisition module 410, the policy determination module 420, the determination module 430, and the allocation module 440 in the permission allocation device). The storage device 52 may include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function; and the data storage area may store data created according to the use of the terminal device, etc. In addition, the storage device 52 may include a high-speed random access memory and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other non-volatile solid-state storage device. In some instances, the storage device 52 may further include a memory remotely arranged relative to the processor 51, and these remote memories may be connected to the terminal device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0483] In an exemplary embodiment, the present application further provides a storage medium storing a computer program that, when executed by a processor, implements any of the methods described herein. The storage medium stores a computer program that, when executed by a processor, implements the permission allocation method described in the embodiments of the present application. The permission allocation method includes: obtaining permission control information, the permission control information including a natural language statement for controlling the permissions of an application;
[0484] Determining, based on the permission control information, a permission control policy corresponding to the permission control information, wherein the permission control policy includes applicable scenarios associated with the permission;
[0485] Determine the usage scenario of the terminal device;
[0486] Based on the matching result between the usage scenario of the terminal device and the applicable scenario, the permission of the application program in the usage scenario is determined.
[0487] The computer storage medium of the embodiment of the present application can adopt any combination of one or more computer-readable media.Computer-readable media can be computer-readable signal media or computer-readable storage media.Computer-readable storage media can be, for example, but not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices or devices, or any combination of the above.More specific examples (non-exhaustive list) of computer-readable storage media include: electrical connection with one or more wires, portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM), flash memory, optical fibers, portable CD-ROMs, optical storage devices, magnetic storage devices, or any suitable combination of the above.Computer-readable storage media can be any tangible medium containing or storing a program, which can be used by an instruction execution system, device or device or used in combination with it.
[0488] A computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such a propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0489] The program code contained on the computer-readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wire, optical cable, radio frequency (RF), etc., or any suitable combination of the foregoing.
[0490] The computer program code for performing the operations of the present application can be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and also conventional procedural programming languages such as "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (e.g., using an Internet service provider to connect via the Internet).
[0491] The present application also provides a computer program product, including a computer program, which implements the permission allocation method provided by the present application when executed by a processor. Figure 1 The permission allocation method of the illustrated embodiment is similar and will not be described again here.
[0492] The above description is merely an exemplary embodiment of the present application and is not intended to limit the scope of protection of the present application.
[0493] It will be understood by those skilled in the art that the term terminal equipment covers any suitable type of wireless user equipment, such as a mobile phone, a portable data processing device, a portable web browser or a car-mounted mobile station.
[0494] In general, various embodiments of the present application may be implemented in hardware or dedicated circuits, software, logic, or any combination thereof. For example, some aspects may be implemented in hardware, while other aspects may be implemented in firmware or software that can be executed by a controller, microprocessor, or other computing device, although the present application is not limited thereto.
[0495] Embodiments of the present application may be implemented by executing computer program instructions by a data processor of a mobile device, for example, in a processor entity, or by hardware, or by a combination of software and hardware. The computer program instructions may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages.
[0496] The block diagram of any logic flow in the drawings of the present application may represent program steps, or may represent interconnected logic circuits, modules and functions, or may represent a combination of program steps and logic circuits, modules and functions. The computer program may be stored on a memory. The memory may be of any type suitable for the local technical environment and may be implemented using any suitable data storage technology, such as, but not limited to, read-only memory (ROM), random access memory (RAM), optical memory devices and systems (digital versatile discs (DVD) or compact disks (CD)), etc. Computer-readable media may include non-transient storage media. The data processor may be of any type suitable for the local technical environment, such as, but not limited to, a general-purpose computer, a special-purpose computer, a microprocessor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), and a processor based on a multi-core processor architecture.
[0497] The above description of exemplary embodiments of the present application has been provided by way of exemplary and non-limiting examples. However, various modifications and adjustments to the above embodiments will be apparent to those skilled in the art when considered in conjunction with the accompanying drawings and claims without departing from the scope of the present disclosure.
Claims
1. A method for allocating permissions, characterized in that: include: Obtaining permission control information, wherein the permission control information includes a natural language statement for controlling permissions of the application program; Determining, based on the permission control information, a permission control policy corresponding to the permission control information, wherein the permission control policy includes applicable scenarios associated with the permission; Determine the usage scenario of the terminal device; Based on the matching result between the usage scenario of the terminal device and the applicable scenario, the permission of the application program in the usage scenario is determined.
2. The method according to claim 1, characterized in that The obtaining of permission control information includes: In response to the permission request of the application, a natural language statement for controlling the permission of the application is obtained.
3. The method according to claim 1, characterized in that The determining, based on the permission control information, a permission control policy corresponding to the permission control information includes: identifying a control condition for the permission based on the natural language statement; Matching the control condition with an applicable scenario identifiable by the terminal device; The authority and the applicable scenario are determined as the authority control policy.
4. The method according to claim 1, wherein Determining the usage scenario of the terminal device includes: Obtaining environmental information, the environmental information indicating an environment associated with one or more of the terminal device and the application; Based on the environmental information, determine the usage scenario of the terminal device.
5. The method according to claim 1, wherein The determining, based on a matching result between the usage scenario of the terminal device and the applicable scenario, the permission of the application program in the usage scenario includes: Determining a matching result between a usage scenario of the terminal device and the applicable scenario, the matching result indicating whether the usage scenario matches the applicable scenario; A first permission that is permitted for the application program and a second permission that is restricted for the application program are determined based on the matching result.
6. The method according to claim 5, characterized in that Also includes: The second permission is run in a sandbox environment, where the sandbox environment has an independent operating system and an independent storage space, and virtual data associated with the second permission exists in the sandbox environment.
7. The method according to claim 1, characterized in that Also includes: Acquiring multimodal data during the running of the application; Performing feature extraction on the multimodal data to obtain key features; Anomaly detection is performed on the application based on the key features to determine a detection result.
8. The method according to claim 7, characterized in that Also includes: Determining risk measurement information corresponding to the detection result; When the risk metric information is less than a set threshold, the restriction degree of the second permission is adjusted, where the second permission includes a permission to restrict use of the application.
9. The method according to claim 8, characterized in that When the risk measurement information is less than a set threshold, adjusting the restriction degree of the second authority includes: When the risk measurement information is less than a set threshold, the restriction degree of the second authority is adjusted from at least one dimension.
10. The method according to claim 8, characterized in that Also includes: Determining a third permission associated with the risk metric information, the third permission including the permission in the second permission to cause the risk metric information to take a value in a direction that increases risk; accordingly, when the risk metric information is less than a set threshold, adjusting the degree of restriction of the second permission, including: If the risk metric information is less than a set threshold, perform at least one of the following steps: Setting the permissions in the second permission except the third permission to be allowed to be used by the application program; The restriction degree of the third permission is adjusted from at least one dimension.
11. The method according to claim 9 or 10, characterized in that Adjust the degree of restriction of permissions along at least one dimension, including: When the risk metric information is smaller than the set threshold value for a continuous number of times reaching a set number, the permission for adjusting the restriction degree is set to be allowed to be used by the application program.
12. The method according to claim 9 or 10, characterized in that The dimensions include at least one of the following: Time dimension, where the adjustment method corresponding to the time dimension includes extending the available time of the permission; Spatial dimension, wherein the adjustment method corresponding to the spatial dimension includes extending the file access scope of the permission; Scenario dimension, the adjustment method corresponding to the scenario dimension includes the applicable scenarios of the extended permissions.
13. The method according to claim 7, characterized in that Also includes: Determining risk measurement information corresponding to the detection result; When the risk measurement information is greater than or equal to a set threshold, a first prompt message is output, wherein the first prompt message prompts to re-acquire the permission control information and continue to allocate permissions to the application based on the re-acquired permission control information.
14. The method according to claim 7, wherein: Also includes: Determining risk measurement information corresponding to the detection result; When the risk measurement information is greater than or equal to a set threshold, second prompt information is output, where the second prompt information includes the risk measurement information, the analysis conclusion associated with the detection result, and evidence information corresponding to the analysis conclusion.
15. The method according to claim 14, characterized in that Also includes: generating a risk report based on the second prompt information; outputting the risk report; Obtaining a processing instruction triggered by a user in response to the risk report; In a case where the processing instruction includes new permission control information, the method according to claim 1 is continued to be executed.
16. The method according to claim 7, characterized in that The multimodal data includes one or more of the following: Text data; image data; audio data; video data; network data; sensor data; resource data of resources in the terminal device.
17. A terminal device, characterized in that: include: one or more processors; a storage device for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 16.
18. A storage medium, characterized in that The storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 16 is implemented.
19. A computer program product comprising a computer program, which, when executed by a processor, implements the method according to any one of claims 1 to 16.