Mobile terminal authority control method, device, equipment, medium and product
By collecting the user's biological characteristics and identification information in a confidential area for dual authentication and controlling the security mode of the mobile terminal, the problem of inconvenience in users carrying mobile terminals is solved, and convenient confidentiality control and security improvement are achieved.
Patent Information
- Application Number
- CN202510862655.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-25
- Publication Date
- 2025-10-03
AI Technical Summary
In the prior art, in a confidential area, users need to place their daily mobile terminals outside the area, which causes inconvenience in use and is difficult to effectively prevent illegal users from impersonating others to use their mobile phone permissions.
By collecting the user's biological characteristics on the server side for identity recognition, obtaining permission information, and interacting with the mobile terminal through the identification collection end, sending permission control instructions to switch its security mode, dual authentication and permission control are achieved.
It enables convenient switching of users' mobile terminals in confidential areas, improves the accuracy and convenience of confidentiality control, and avoids intrusion by illegal users.
Smart Images

Figure CN120751383A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of security technology, and in particular to methods, devices, equipment, media and products for mobile terminal authority control. Background Art
[0002] In some places, such as laboratories, confidential units, production factories, etc., for confidentiality reasons, people are usually not allowed to bring mobile terminals such as mobile phones. Or, people are only allowed to bring specially configured mobile terminals, and it is inconvenient to place mobile terminals such as mobile phones used daily outside the area. Summary of the Invention
[0003] In view of the above problems, a method, apparatus, device, medium and product for mobile terminal permission control are proposed to overcome the above problems or at least partially solve the above problems, including:
[0004] A method for controlling permissions of a mobile terminal, applied to a server, comprising:
[0005] Obtain user biological characteristics collected for the current user;
[0006] Performing user identification based on the user's biological characteristics to obtain user identity information, and determining permission information corresponding to the user identity information;
[0007] When the permission information indicates that the current user has permission to enter the current area, acquiring identification information from the mobile terminal through the first identification collection end;
[0008] When the identification information matches the user identity information, a permission control instruction is sent to the mobile terminal according to the permission information to control the mobile terminal to enter the security mode corresponding to the permission control instruction, and some functions of the mobile terminal are set to disabled in the security mode.
[0009] Optionally, it also includes:
[0010] When the identification information is acquired from the mobile terminal through the second identification acquisition terminal, a permission restoration instruction is sent to the mobile terminal to control the mobile terminal to exit the security mode.
[0011] Optionally, sending an authority control instruction to the mobile terminal according to the authority information includes:
[0012] Determining a permission control policy corresponding to the permission information; different permission control policies correspond to different security modes, and different functions of the mobile terminal are set to be disabled in different security modes;
[0013] According to the permission control policy, a permission control instruction is sent to the mobile terminal.
[0014] Optionally, the authority control policy includes at least: a first authority control policy, a second authority control policy, and a third authority control policy;
[0015] In the security mode corresponding to the first permission control policy, all functions of the mobile terminal except the call function are set to be disabled;
[0016] In the security mode corresponding to the second permission control policy, other functions of the mobile terminal except the calling function and the photo taking function are set to be disabled;
[0017] In the security mode corresponding to the third authority control policy, other functions of the mobile terminal except the calling function, the photo taking function, and the designated network connection function are set to be disabled.
[0018] Optionally, it also includes:
[0019] When the user identity information cannot be obtained, or the authority information indicates that the current user does not have the authority to enter the current area, or the identification information does not match the user identity information, a prompt message indicating that the current user is an illegal user is fed back.
[0020] Optionally, the identification information is acquired from the mobile terminal via near field communication, and the permission control instruction and the permission restoration instruction are sent to the mobile terminal via near field communication.
[0021] A method for controlling permissions of a mobile terminal, applied to a mobile terminal, comprising:
[0022] Sending identification information to the service end through the first identification collection end; wherein the identification information is collected when the permission information corresponding to the user identity information indicates that the current user has permission to enter the current area, and the user identity information is obtained by obtaining a user biometric feature collected for the current user and performing user identity recognition based on the user biometric feature;
[0023] Receiving the permission control instruction sent by the server; wherein the permission control instruction is generated according to the permission information when the identification information matches the user identity information;
[0024] In response to the permission control instruction, a security mode corresponding to the permission control instruction is entered, and some functions of the mobile terminal are set to a disabled state in the security mode.
[0025] Optionally, it also includes:
[0026] Sending identification information to the server through the second identification collection terminal;
[0027] Receiving a permission restoration instruction sent by the server;
[0028] In response to the permission restoration instruction, exit the security mode.
[0029] A mobile terminal authority control device, applied to a server, comprising:
[0030] A user biological feature acquisition module is used to acquire the user biological features collected for the current user;
[0031] an authority information determination module, configured to identify a user based on the user's biological characteristics, obtain user identity information, and determine authority information corresponding to the user identity information;
[0032] an identification information acquisition module, configured to acquire identification information from the mobile terminal via a first identification acquisition terminal when the permission information indicates that the current user has permission to enter the current area;
[0033] The permission control module is used to send a permission control instruction to the mobile terminal according to the permission information when the identification information matches the user identity information, so as to control the mobile terminal to enter the security mode corresponding to the permission control instruction, and some functions of the mobile terminal are set to be disabled in the security mode.
[0034] A mobile terminal authority control device, applied to a mobile terminal, comprising:
[0035] A first identification information sending module, configured to send identification information to a server via a first identification collection terminal; wherein the identification information is collected when permission information corresponding to the user identity information indicates that the current user has permission to enter the current area, and the user identity information is obtained by obtaining a user biometric feature collected for the current user and performing user identity recognition based on the user biometric feature;
[0036] an authority control instruction receiving module, configured to receive an authority control instruction sent by the server; wherein the authority control instruction is generated according to the authority information when the identification information matches the user identity information;
[0037] The authority control instruction response module is used to respond to the authority control instruction and enter the security mode corresponding to the authority control instruction, and some functions of the mobile terminal are set to be disabled in the security mode.
[0038] An electronic device includes a processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein the computer program implements the method described above when executed by the processor.
[0039] A computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method described above is implemented.
[0040] A computer program product comprises a computer program, wherein when the computer program is executed by a processor, the computer program implements the method described above.
[0041] The embodiments of the present invention have the following advantages:
[0042] In an embodiment of the present invention, by acquiring user biometric features collected for the current user, user identity recognition is performed based on the user biometric features to obtain user identity information, and permission information corresponding to the user identity information is determined. When the permission information indicates that the current user has permission to enter the current area, identification information is obtained from the mobile terminal through the first identification acquisition end. When the identification information matches the user identity information, a permission control instruction is sent to the mobile terminal based on the permission information to control the mobile terminal to enter the security mode corresponding to the permission control instruction. Some functions of the mobile terminal are set to a disabled state in the security mode, thereby realizing that the mobile terminal carried by the user is switched to a security mode when the user enters some places, thereby allowing the user to carry the mobile terminal used daily into the confidential area and use the same mobile terminal in the confidential area and the non-confidential area, thereby improving the convenience of confidentiality control. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] In order to more clearly illustrate the technical solution of the present invention, the following briefly introduces the drawings required for use in the description of the present invention. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0044] Figure 1 This is a flowchart of the steps of a method for controlling permissions of a mobile terminal provided by some embodiments of the present invention;
[0045] Figure 2 is a flowchart of another method for mobile terminal authority control provided by some embodiments of the present invention;
[0046] Figure 3 This is a flowchart of the steps of another method for mobile terminal authority control provided by some embodiments of the present invention;
[0047] Figure 4 This is a flowchart of the steps of another method for mobile terminal authority control provided by some embodiments of the present invention;
[0048] Figure 5 is a flowchart of the steps of a method for controlling permissions of a mobile terminal provided by some embodiments of the present invention;
[0049] Figure 6 This is a structural block diagram of a mobile terminal authority control device provided by some embodiments of the present invention;
[0050] Figure 7 This is a structural block diagram of another device for mobile terminal authority control provided by some embodiments of the present invention. DETAILED DESCRIPTION
[0051] To make the above-mentioned objects, features, and advantages of the present invention more clearly understood, the present invention is further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the embodiments described are only a portion of the embodiments of the present invention, not all of them. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present invention without inventive effort are also within the scope of protection of the present invention.
[0052] In an embodiment of the present invention, different confidentiality authority settings are pre-installed in mobile terminals such as mobile phones, and the authority is not manually controlled. Then, the switch is automatically turned on according to the authority control instruction. With the help of face recognition and NFC (Near Field Communication) communication functions, dual authentication is performed at the access control entrance of the confidential area. After the dual authentication is completed, the corresponding confidentiality authority control instruction is transmitted to the mobile terminal such as the mobile phone according to the pre-set confidentiality authority range. The mobile terminal forcibly starts the corresponding confidentiality setting. When the card is swiped to go out, the access control gives an authority recovery instruction to restore the normal use of the mobile terminal, thereby realizing the normal and confidential dual use of mobile terminals such as mobile phones. The same mobile terminal is used in confidential areas and non-confidential areas, and the use authority is automatically switched according to the authority requirements, while avoiding impersonating others' mobile phone authority.
[0053] Reference Figure 1 , shows a flowchart of the steps of a method for mobile terminal authority control provided by some embodiments of the present invention, which can be applied to a server. In some examples, the server can be an access control system.
[0054] Specifically, the following steps may be included:
[0055] Step 101: Obtain user biological characteristics collected for the current user.
[0056] When the current user wants to enter the current area (such as the current area is a confidential area), the user's biological characteristics can be collected through sensors such as cameras. In some examples, the user's biological characteristics can be facial features, iris features, fingerprint features, etc.
[0057] In some examples, the server may be an access control system, which has a user biological feature collection terminal, such as a camera, at the door leading to the current area. When the current user wants to enter the current area, the user biological feature collection terminal may collect the user biological feature of the current user.
[0058] Step 102: Perform user identification based on the user's biological characteristics to obtain user identity information, and determine permission information corresponding to the user identity information.
[0059] In actual applications, user biological characteristics, user identity information, and corresponding permission information of multiple users can be collected in advance and stored on the server.
[0060] After obtaining the user biological features of the current user collected in real time, the real-time collected user biological features can be matched with the pre-collected features. If the match is successful, the user identity information corresponding to the real-time collected user biological features can be determined, and the permission information corresponding to the user identity information can be obtained.
[0061] The permission information may include whether the user has permission to enter the current area, and which security mode the user's mobile terminal should be set to after entering the current area.
[0062] Step 103: When the permission information indicates that the current user has permission to enter the current area, the first identification acquisition terminal obtains identification information from the mobile terminal.
[0063] As an example, the mobile terminal may be a smart phone, or a smart watch, a tablet computer, a laptop computer, or other portable smart devices.
[0064] The first identification collection terminal may be provided at the entrance of the confidential area, and is used to collect identification information (ID) of the user's mobile terminal when the user enters the confidential area.
[0065] In actual applications, identification information used by multiple users can be pre-set, and the identification information can be associated and stored on the server with the user's biometric characteristics, user identity information, and corresponding permission information. The identification information can also be pre-entered into the mobile terminal used by the user. In some examples, the mobile terminal supports NFC function, and the identification information can be entered into the NFC system of the mobile terminal.
[0066] After obtaining the permission information, it can be determined whether the current user has permission to enter the current area based on the permission information. If the permission information indicates that the current user has permission to enter the current area, the first identification acquisition terminal can obtain identification information from the mobile terminal. The identification information can be used to verify whether the mobile terminal belongs to the current user, thereby ensuring the accuracy of permission control.
[0067] In some examples, the mobile terminal has NFC functionality, and the identification information is obtained from the mobile terminal via near-field communication. For example, if the permission information indicates that the current user has permission to enter the current area, the user can be prompted to swipe the NFC card via voice or other means. When the current user brings the mobile terminal close to the first identification acquisition terminal, the first identification acquisition terminal can read the identification information from the mobile terminal via NFC technology. The identification information can be specific information pre-set in the mobile terminal.
[0068] Step 104, when the identification information matches the user identity information, sends an authorization control instruction to the mobile terminal according to the authorization information to control the mobile terminal to enter the security mode corresponding to the authorization control instruction, and some functions of the mobile terminal are set to disabled in the security mode.
[0069] Since the association between the identification information and the user's biological characteristics, user identity information, and corresponding permission information is pre-stored on the server side, it is possible to determine whether the identification information matches the user identity information based on the association. If the identification information matches the user identity information, it means that the current user is a legitimate user and the mobile terminal he carries is a mobile terminal of a legitimate user. At this time, a permission control instruction can be sent to the mobile terminal based on the permission information. The permission control instruction can carry the security mode information that the mobile terminal should be set to. After receiving the permission control instruction, the mobile terminal can automatically enter the security mode.
[0070] After entering the safe mode, the mobile terminal automatically enters the corresponding permission interface and settings according to the permission control instruction. Some functions of the mobile terminal are set to disabled in this safe mode to avoid the risk of information leakage in the confidential area.
[0071] In the embodiment of the present invention, user identity is identified by collecting user biological characteristics and identification information is obtained through the mobile terminal to achieve dual identification, thereby improving the accuracy and security of permission control and effectively avoiding the situation of impersonating others to use mobile phone permissions.
[0072] In some embodiments of the present invention, sending a permission control instruction to the mobile terminal based on the permission information includes: determining a permission control policy corresponding to the permission information; different permission control policies correspond to different security modes, and in different security modes, the functions of the mobile terminal set to a disabled state are different; sending a permission control instruction to the mobile terminal based on the permission control policy.
[0073] In actual applications, different users may have different permission control policies. For example, high-level users may have more access rights, while low-level users may have only limited access rights.
[0074] After determining the permission information, the server can determine the corresponding permission control policy based on the permission information. The permission control policy defines which security mode the user's mobile terminal should be set to after entering the confidential area, and which functions are disabled in this security mode.
[0075] For example, for high-level users, it may be necessary to only disable the photo and video recording functions, while for low-level users, more functions may need to be disabled, such as network connection, Bluetooth, etc.
[0076] Based on the determined permission control policy, the server sends a permission control instruction containing the corresponding security mode information to the mobile terminal. After receiving the permission control instruction, the mobile terminal automatically enters the corresponding permission interface and settings based on the security mode information in the instruction, ensuring the security of information within the confidential area.
[0077] As an example, the permission control instruction may carry a list of functions that should be disabled on the mobile terminal. After receiving the permission control instruction, the mobile terminal may disable the functions in the function list. For example, if the permission control instruction indicates that the mobile terminal should be set to the security mode corresponding to the first permission control policy, the mobile terminal may disable functions other than the call function; if the permission control instruction indicates that the mobile terminal should be set to the security mode corresponding to the second permission control policy, the mobile terminal may disable functions other than the call function and the photo-taking function; if the permission control instruction indicates that the mobile terminal should be set to the security mode corresponding to the third permission control policy, the mobile terminal may disable functions other than the call function, the photo-taking function, and the Internet access function. Through such settings, different degrees of permission control can be performed on the mobile terminal according to the different areas or places entered by the user to meet the needs of different confidentiality levels.
[0078] In some embodiments of the present invention, the authority control policy includes at least: a first authority control policy, a second authority control policy, and a third authority control policy;
[0079] In the security mode corresponding to the first permission control policy, all functions of the mobile terminal except the call function are set to be disabled;
[0080] In the security mode corresponding to the second permission control policy, other functions of the mobile terminal except the calling function and the photo taking function are set to be disabled;
[0081] In the security mode corresponding to the third authority control policy, other functions of the mobile terminal except the calling function, the photo taking function, and the designated network connection function are set to be disabled.
[0082] In actual applications, multiple permissions can be pre-set in the operating system settings of the mobile terminal, such as permission 1: only call function is allowed (corresponding to the first permission control strategy); permission 2: call function and photo-taking function (corresponding to the second permission control strategy); permission 3: call function, photo-taking function, factory-specific Wi-Fi (corresponding to the third permission control strategy). Among them, confidentiality permissions and normal use permissions are independent of each other, and each permission startup instruction is forcibly bound to the permission control instruction.
[0083] In some embodiments of the present invention, the present invention further includes:
[0084] When the user identity information cannot be obtained, or the authority information indicates that the current user does not have the authority to enter the current area, or the identification information does not match the user identity information, a prompt message indicating that the current user is an illegal user is fed back.
[0085] In actual applications, if the server cannot successfully identify the user's biological characteristics and thus cannot obtain the user's identity information, or the permission information obtained based on the user's identity information indicates that the current user does not have the permission to enter the current area, or the identification information obtained from the mobile terminal does not match the user's identity information, then it means that the current user is an illegal user. A prompt message indicating that the current user does not have the right to enter the current area can be fed back to intercept illegal users and prevent them from entering confidential areas, further improving the accuracy and security of confidentiality control.
[0086] In some embodiments of the present invention, the present invention further includes:
[0087] When the identification information is acquired from the mobile terminal through the second identification acquisition terminal, a permission restoration instruction is sent to the mobile terminal to control the mobile terminal to exit the security mode.
[0088] The second identification collection terminal may be provided at the exit of the confidential area, and is used to collect identification information of the user's mobile terminal when the user leaves the confidential area.
[0089] When the user leaves the current area, the second identification acquisition terminal can retrieve identification information from the mobile terminal again. After obtaining the identification information, the server can verify the legitimacy of the identification information. If so, it can send a permission restoration instruction to the mobile terminal. The permission restoration instruction is used to instruct the mobile terminal to exit the current security mode and return to normal use. After the user leaves the confidential area, their mobile terminal can automatically resume normal use without the user having to manually configure it, improving user convenience.
[0090] In some examples, the mobile terminal has an NFC function, and the permission control instructions and permission recovery instructions are sent to the mobile terminal through near-field communication. For example, when the user leaves a confidential area, the user can be prompted to swipe the NFC card through voice or other means. When the user carries the mobile terminal close to the second identification collection end, the second identification collection end can read the identification information from the mobile terminal through NFC technology. After verification, the server sends a permission recovery instruction to the mobile terminal. After receiving the permission recovery instruction, the mobile terminal automatically exits the security mode and returns to normal use.
[0091] In an embodiment of the present invention, by acquiring user biometric features collected for the current user, user identity recognition is performed based on the user biometric features to obtain user identity information, and permission information corresponding to the user identity information is determined. When the permission information indicates that the current user has permission to enter the current area, identification information is obtained from the mobile terminal through the first identification acquisition end. When the identification information matches the user identity information, a permission control instruction is sent to the mobile terminal based on the permission information to control the mobile terminal to enter the security mode corresponding to the permission control instruction. Some functions of the mobile terminal are set to a disabled state in the security mode, thereby realizing that the mobile terminal carried by the user is switched to a security mode when the user enters some places, thereby allowing the user to carry the mobile terminal used daily into the confidential area and use the same mobile terminal in the confidential area and the non-confidential area, thereby improving the convenience of confidentiality control.
[0092] The following combination Figure 2 The present invention is exemplified as follows:
[0093] 1. Collect user identity information, facial information (user biological characteristics) and corresponding permission information in the access control system (server);
[0094] 2. Enter your personal ID (identification information) into the NFC system of your mobile phone (mobile terminal);
[0095] 3. Perform facial recognition in access control systems;
[0096] 4. Determine whether you have access permission;
[0097] 5. If the user does not have access permission, entry is prohibited. If the user has access permission, the user is prompted to swipe the NFC card on the phone to obtain the personal ID.
[0098] 6. Retrieve user identity information based on ID;
[0099] 7. Determine whether the user identity information and ID information are consistent;
[0100] 8. If the user identity information and ID information are inconsistent, entry will be prohibited. If the user identity information and ID information are consistent, a permission control instruction will be sent to the mobile phone;
[0101] 9. The phone automatically enters the corresponding security mode according to the permission control instructions.
[0102] Reference Figure 3 , shows a flowchart of another method for mobile terminal authority control provided by some embodiments of the present invention, which is applied to the server and may specifically include the following steps:
[0103] Step 301: Obtain user biological characteristics collected for the current user.
[0104] Step 302: Perform user identification based on the user's biological characteristics to obtain user identity information, and determine permission information corresponding to the user identity information.
[0105] Step 303: When the permission information indicates that the current user has permission to enter the current area, the first identification acquisition terminal obtains identification information from the mobile terminal.
[0106] Step 304, when the identification information matches the user identity information, sends a permission control instruction to the mobile terminal according to the permission information to control the mobile terminal to enter the security mode corresponding to the permission control instruction, and some functions of the mobile terminal are set to disabled in the security mode.
[0107] Step 305: When the identification information is obtained from the mobile terminal through the second identification acquisition terminal, a permission restoration instruction is sent to the mobile terminal to control the mobile terminal to exit the security mode.
[0108] Reference Figure 4 , shows a step flow chart of another method for mobile terminal permission control provided by some embodiments of the present invention, which is applied to a mobile terminal. For example, the mobile terminal can be a smart phone, a smart watch, a tablet computer, a laptop computer or other portable smart device.
[0109] Specifically, the following steps may be included:
[0110] Step 401: Send identification information to the server through the first identification collection end; wherein, the identification information is collected when the permission information corresponding to the user identity information indicates that the current user has the permission to enter the current area, and the user identity information is obtained by obtaining the user biological characteristics collected for the current user and performing user identity identification based on the user biological characteristics.
[0111] When the current user wants to enter the current area (such as the current area is a confidential area), the user's biological characteristics can be collected through sensors such as cameras. In some examples, the user's biological characteristics can be facial features, iris features, fingerprint features, etc.
[0112] In some examples, the server may be an access control system, which has a user biological feature collection terminal, such as a camera, at the door leading to the current area. When the current user wants to enter the current area, the user biological feature collection terminal may collect the user biological feature of the current user.
[0113] In actual applications, user biological characteristics, user identity information, and corresponding permission information of multiple users can be collected in advance and stored on the server.
[0114] After obtaining the user biological features of the current user collected in real time, the real-time collected user biological features can be matched with the pre-collected features. If the match is successful, the user identity information corresponding to the real-time collected user biological features can be determined, and the permission information corresponding to the user identity information can be obtained.
[0115] The permission information may include whether the user has permission to enter the current area, and which security mode the user's mobile terminal should be set to after entering the current area.
[0116] In actual applications, identification information used by multiple users can be pre-set, and the identification information can be associated and stored on the server with the user's biometric characteristics, user identity information, and corresponding permission information. The identification information can also be pre-entered into the mobile terminal used by the user. In some examples, the mobile terminal supports NFC function, and the identification information can be entered into the NFC system of the mobile terminal.
[0117] After obtaining the permission information, it can be determined whether the current user has permission to enter the current area based on the permission information. If the permission information indicates that the current user has permission to enter the current area, the first identification acquisition terminal can obtain identification information from the mobile terminal. The identification information can be used to verify whether the mobile terminal belongs to the current user, thereby ensuring the accuracy of permission control.
[0118] In some examples, the mobile terminal has NFC functionality, and the identification information is obtained from the mobile terminal via near-field communication. For example, if the permission information indicates that the current user has permission to enter the current area, the user can be prompted to swipe the NFC card via voice or other means. When the current user brings the mobile terminal close to the first identification acquisition terminal, the first identification acquisition terminal can read the identification information from the mobile terminal via NFC technology. The identification information can be specific information pre-set in the mobile terminal.
[0119] Step 402: Receive the permission control instruction sent by the server; wherein the permission control instruction is generated according to the permission information when the identification information matches the user identity information.
[0120] Because the server pre-stores the association between the identification information and the user's biometric features, user identity information, and corresponding permission information, it can determine whether the identification information matches the user identity information based on this association. If the identification information matches the user identity information, it indicates that the current user is a legitimate user and the mobile terminal they are carrying is a mobile terminal of a legitimate user. At this time, permission control instructions can be sent to the mobile terminal based on the permission information.
[0121] In the embodiment of the present invention, user identity is identified by collecting user biological characteristics and identification information is obtained through the mobile terminal to achieve dual identification, thereby improving the accuracy and security of permission control and effectively avoiding the situation of impersonating others to use mobile phone permissions.
[0122] Step 403: In response to the permission control instruction, enter a security mode corresponding to the permission control instruction, and some functions of the mobile terminal are set to be disabled in the security mode.
[0123] The permission control instruction may carry information about the security mode that the mobile terminal should be set to. After receiving the permission control instruction, the mobile terminal may automatically enter the security mode.
[0124] After entering the safe mode, the mobile terminal automatically enters the corresponding permission interface and settings according to the permission control instruction. Some functions of the mobile terminal are set to disabled in this safe mode to avoid the risk of information leakage in the confidential area.
[0125] In actual applications, different users may have different permission control policies. For example, high-level users may have more access rights, while low-level users may have only limited access rights.
[0126] After determining the permission information, the server can determine the corresponding permission control policy based on the permission information. The permission control policy defines which security mode the user's mobile terminal should be set to after entering the confidential area, and which functions are disabled in this security mode.
[0127] For example, for high-level users, it may be necessary to only disable the photo and video recording functions, while for low-level users, more functions may need to be disabled, such as network connection, Bluetooth, etc.
[0128] Based on the determined permission control policy, the server sends a permission control instruction containing the corresponding security mode information to the mobile terminal. After receiving the permission control instruction, the mobile terminal automatically enters the corresponding permission interface and settings based on the security mode information in the instruction, ensuring the security of information within the confidential area.
[0129] As an example, the permission control instruction may carry a list of functions that should be disabled on the mobile terminal. After receiving the permission control instruction, the mobile terminal may disable the functions in the function list. For example, if the permission control instruction indicates that the mobile terminal should be set to the security mode corresponding to the first permission control policy, the mobile terminal may disable functions other than the call function; if the permission control instruction indicates that the mobile terminal should be set to the security mode corresponding to the second permission control policy, the mobile terminal may disable functions other than the call function and the photo-taking function; if the permission control instruction indicates that the mobile terminal should be set to the security mode corresponding to the third permission control policy, the mobile terminal may disable functions other than the call function, the photo-taking function, and the Internet access function. Through such settings, different degrees of permission control can be performed on the mobile terminal according to the different areas or places entered by the user to meet the needs of different confidentiality levels.
[0130] In some embodiments of the present invention, the authority control policy includes at least: a first authority control policy, a second authority control policy, and a third authority control policy;
[0131] In the security mode corresponding to the first permission control policy, all functions of the mobile terminal except the call function are set to be disabled;
[0132] In the security mode corresponding to the second permission control policy, other functions of the mobile terminal except the calling function and the photo taking function are set to be disabled;
[0133] In the security mode corresponding to the third authority control policy, other functions of the mobile terminal except the calling function, the photo taking function, and the designated network connection function are set to be disabled.
[0134] In actual applications, multiple permissions can be pre-set in the operating system settings of the mobile terminal, such as permission 1: only call function is allowed (corresponding to the first permission control strategy); permission 2: call function and photo-taking function (corresponding to the second permission control strategy); permission 3: call function, photo-taking function, factory-specific Wi-Fi (corresponding to the third permission control strategy). Among them, confidentiality permissions and normal use permissions are independent of each other, and each permission startup instruction is forcibly bound to the permission control instruction.
[0135] In an embodiment of the present invention, identification information is sent to a server through a first identification collection end. The identification information is collected when the permission information corresponding to the user identity information indicates that the current user has the permission to enter the current area. The user identity information is obtained by obtaining the user biometric characteristics collected for the current user and performing user identity recognition based on the user biometric characteristics. Then, a permission control instruction sent by the server is received. The permission control instruction is generated based on the permission information when the identification information matches the user identity information. In response to the permission control instruction, a security mode corresponding to the permission control instruction is entered. Some functions of the mobile terminal are set to a disabled state in the security mode, so that the mobile terminal carried by the user is switched to a security mode when the user enters some places, thereby allowing the user to carry the mobile terminal used daily into the confidential area and use the same mobile terminal in the confidential area and the non-confidential area, thereby improving the convenience of confidentiality control.
[0136] Reference Figure 5 , shows a flowchart of another method for mobile terminal authority control provided by some embodiments of the present invention, which is applied to a mobile terminal and may specifically include the following steps:
[0137] Step 501: Send identification information to the server through the first identification collection end; wherein, the identification information is collected when the permission information corresponding to the user identity information indicates that the current user has the permission to enter the current area, and the user identity information is obtained by obtaining the user biological characteristics collected for the current user and performing user identity identification based on the user biological characteristics.
[0138] Step 502: Receive the permission control instruction sent by the server; wherein the permission control instruction is generated according to the permission information when the identification information matches the user identity information.
[0139] Step 503: In response to the permission control instruction, enter a security mode corresponding to the permission control instruction, and some functions of the mobile terminal are set to be disabled in the security mode.
[0140] Step 504: Send identification information to the server through the second identification collection terminal.
[0141] Step 505: Receive the permission restoration instruction sent by the server.
[0142] Step 506: Exit the safe mode in response to the permission restoration instruction.
[0143] It should be noted that for the sake of simplicity, the method embodiments are described as a series of actions. However, those skilled in the art should be aware that the embodiments of the present invention are not limited by the order of the actions described, because according to the embodiments of the present invention, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all preferred embodiments, and the actions involved are not necessarily required by the embodiments of the present invention.
[0144] Reference Figure 6 , shows a schematic structural diagram of a mobile terminal authority control device provided by some embodiments of the present invention, which is applied to a server and may specifically include the following modules:
[0145] User biometric feature acquisition module 601, used to acquire user biometric features collected for the current user;
[0146] The permission information determination module 602 is configured to perform user identity recognition based on the user's biological characteristics, obtain user identity information, and determine permission information corresponding to the user identity information;
[0147] The identification information acquisition module 603 is configured to acquire identification information from the mobile terminal via the first identification acquisition terminal when the permission information indicates that the current user has permission to enter the current area;
[0148] The permission control module 604 is used to send a permission control instruction to the mobile terminal according to the permission information when the identification information matches the user identity information, so as to control the mobile terminal to enter the security mode corresponding to the permission control instruction, and some functions of the mobile terminal are set to disabled state in the security mode.
[0149] In some embodiments of the present invention, the present invention further includes:
[0150] The permission recovery module is used to send a permission recovery instruction to the mobile terminal when the identification information is obtained from the mobile terminal through the second identification acquisition terminal, so as to control the mobile terminal to exit the security mode.
[0151] In some embodiments of the present invention, sending a permission control instruction to the mobile terminal according to the permission information includes:
[0152] Determining a permission control policy corresponding to the permission information; different permission control policies correspond to different security modes, and different functions of the mobile terminal are set to be disabled in different security modes;
[0153] According to the permission control policy, a permission control instruction is sent to the mobile terminal.
[0154] In some embodiments of the present invention, the authority control policy includes at least: a first authority control policy, a second authority control policy, and a third authority control policy;
[0155] In the security mode corresponding to the first permission control policy, all functions of the mobile terminal except the call function are set to be disabled;
[0156] In the security mode corresponding to the second permission control policy, other functions of the mobile terminal except the calling function and the photo taking function are set to be disabled;
[0157] In the security mode corresponding to the third authority control policy, other functions of the mobile terminal except the calling function, the photo taking function, and the designated network connection function are set to be disabled.
[0158] In some embodiments of the present invention, the present invention further includes:
[0159] The prompt message feedback module is used to feedback a prompt message that the current user is an illegal user when the user identity information cannot be obtained, or the permission information indicates that the current user does not have the permission to enter the current area, or the identification information does not match the user identity information.
[0160] In some embodiments of the present invention, the identification information is acquired from the mobile terminal via near field communication, and the permission control instruction and the permission restoration instruction are sent to the mobile terminal via near field communication.
[0161] In an embodiment of the present invention, by acquiring user biometric features collected for the current user, user identity recognition is performed based on the user biometric features to obtain user identity information, and permission information corresponding to the user identity information is determined. When the permission information indicates that the current user has permission to enter the current area, identification information is obtained from the mobile terminal through the first identification acquisition end. When the identification information matches the user identity information, a permission control instruction is sent to the mobile terminal based on the permission information to control the mobile terminal to enter the security mode corresponding to the permission control instruction. Some functions of the mobile terminal are set to a disabled state in the security mode, thereby realizing that the mobile terminal carried by the user is switched to a security mode when the user enters some places, thereby allowing the user to carry the mobile terminal used daily into the confidential area and use the same mobile terminal in the confidential area and the non-confidential area, thereby improving the convenience of confidentiality control.
[0162] Reference Figure 7 , which shows a schematic structural diagram of a mobile terminal authority control device provided by some embodiments of the present invention, applied to a mobile terminal, and specifically includes the following modules:
[0163] A first identification information sending module 701 is configured to send identification information to a server via a first identification collection terminal; wherein the identification information is collected when the permission information corresponding to the user identity information indicates that the current user has permission to enter the current area, and the user identity information is obtained by obtaining a user biometric feature collected for the current user and performing user identity recognition based on the user biometric feature;
[0164] The permission control instruction receiving module 702 is used to receive the permission control instruction sent by the server; wherein the permission control instruction is generated according to the permission information when the identification information matches the user identity information;
[0165] The authority control instruction response module 703 is configured to respond to the authority control instruction and enter a security mode corresponding to the authority control instruction, wherein some functions of the mobile terminal are set to be disabled in the security mode.
[0166] In some embodiments of the present invention, the present invention further includes:
[0167] A second identification information sending module, configured to send identification information to the server via a second identification collection terminal;
[0168] A permission restoration instruction receiving module, configured to receive the permission restoration instruction sent by the server;
[0169] The permission restoration instruction response module is used to exit the security mode in response to the permission restoration instruction.
[0170] In an embodiment of the present invention, identification information is sent to a server through a first identification collection end. The identification information is collected when the permission information corresponding to the user identity information indicates that the current user has the permission to enter the current area. The user identity information is obtained by obtaining the user biometric characteristics collected for the current user and performing user identity recognition based on the user biometric characteristics. Then, a permission control instruction sent by the server is received. The permission control instruction is generated based on the permission information when the identification information matches the user identity information. In response to the permission control instruction, a security mode corresponding to the permission control instruction is entered. Some functions of the mobile terminal are set to a disabled state in the security mode, so that the mobile terminal carried by the user is switched to a security mode when the user enters some places, thereby allowing the user to carry the mobile terminal used daily into the confidential area and use the same mobile terminal in the confidential area and the non-confidential area, thereby improving the convenience of confidentiality control.
[0171] Some embodiments of the present invention further provide an electronic device, comprising a processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein the computer program implements the above method when executed by the processor.
[0172] Some embodiments of the present invention further provide a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the above method is implemented.
[0173] Some embodiments of the present invention further provide a computer program product, including a computer program, which implements the above method when executed by a processor.
[0174] As for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0175] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0176] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.
[0177] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, apparatus, or computer program products. Thus, embodiments of the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, embodiments of the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0178] The embodiments of the present invention are described with reference to the flowcharts and / or block diagrams of the methods, terminal devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of the processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal device generate instructions for implementing the process in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0179] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing terminal device to operate in a specific manner, so that the instructions stored in the computer readable memory produce a manufactured product including an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0180] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device so that a series of operating steps are executed on the computer or other programmable terminal device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable terminal device to implement the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0181] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they are aware of the basic creative concepts. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present invention.
[0182] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "includes," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that includes a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or terminal device. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of additional identical elements in the process, method, article, or terminal device that includes the above elements.
[0183] The above is a detailed introduction to the methods, devices, equipment, media and products for mobile terminal permission control. Specific examples are used in this article to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core ideas. At the same time, for those skilled in the art, according to the ideas of the present invention, there will be changes in the specific implementation methods and application scopes. In summary, the contents of this specification should not be understood as limiting the present invention.
Claims
1. A method for controlling permissions of a mobile terminal, characterized in that: Applied to the server, including: Obtain user biological characteristics collected for the current user; Performing user identification based on the user's biological characteristics to obtain user identity information, and determining permission information corresponding to the user identity information; When the permission information indicates that the current user has permission to enter the current area, acquiring identification information from the mobile terminal through the first identification collection end; When the identification information matches the user identity information, a permission control instruction is sent to the mobile terminal according to the permission information to control the mobile terminal to enter the security mode corresponding to the permission control instruction, and some functions of the mobile terminal are set to disabled in the security mode.
2. The method according to claim 1, characterized in that Also includes: When the identification information is acquired from the mobile terminal through the second identification acquisition terminal, a permission restoration instruction is sent to the mobile terminal to control the mobile terminal to exit the security mode.
3. The method according to claim 1 or 2, characterized in that Sending a permission control instruction to the mobile terminal according to the permission information includes: Determining a permission control policy corresponding to the permission information; different permission control policies correspond to different security modes, and different functions of the mobile terminal are set to be disabled in different security modes; According to the permission control policy, a permission control instruction is sent to the mobile terminal.
4. The method according to claim 3, characterized in that The authority control policy includes at least: a first authority control policy, a second authority control policy, and a third authority control policy; In the security mode corresponding to the first permission control policy, all functions of the mobile terminal except the call function are set to be disabled; In the security mode corresponding to the second permission control policy, other functions of the mobile terminal except the calling function and the photo taking function are set to be disabled; In the security mode corresponding to the third authority control policy, other functions of the mobile terminal except the calling function, the photo taking function, and the designated network connection function are set to be disabled.
5. The method according to claim 1 or 2, characterized in that Also includes: When the user identity information cannot be obtained, or the authority information indicates that the current user does not have the authority to enter the current area, or the identification information does not match the user identity information, a prompt message indicating that the current user is an illegal user is fed back.
6. The method according to claim 2, characterized in that The identification information is acquired from the mobile terminal through near field communication, and the permission control instruction and the permission restoration instruction are sent to the mobile terminal through near field communication.
7. A method for controlling permissions of a mobile terminal, characterized in that: Applied to mobile terminals, including: Sending identification information to the service end through the first identification collection end; wherein the identification information is collected when the permission information corresponding to the user identity information indicates that the current user has permission to enter the current area, and the user identity information is obtained by obtaining a user biometric feature collected for the current user and performing user identity recognition based on the user biometric feature; Receiving the permission control instruction sent by the server; wherein the permission control instruction is generated according to the permission information when the identification information matches the user identity information; In response to the permission control instruction, a security mode corresponding to the permission control instruction is entered, and some functions of the mobile terminal are set to a disabled state in the security mode.
8. The method according to claim 7, characterized in that Also includes: Sending identification information to the server through the second identification collection terminal; Receiving a permission restoration instruction sent by the server; In response to the permission restoration instruction, exit the security mode.
9. A device for controlling permissions of a mobile terminal, characterized in that: Applied to the server, including: A user biological feature acquisition module is used to acquire the user biological features collected for the current user; an authority information determination module, configured to identify a user based on the user's biological characteristics, obtain user identity information, and determine authority information corresponding to the user identity information; an identification information acquisition module, configured to acquire identification information from the mobile terminal via a first identification acquisition terminal when the permission information indicates that the current user has permission to enter the current area; The permission control module is used to send a permission control instruction to the mobile terminal according to the permission information when the identification information matches the user identity information, so as to control the mobile terminal to enter the security mode corresponding to the permission control instruction, and some functions of the mobile terminal are set to be disabled in the security mode.
10. A device for controlling permissions of a mobile terminal, characterized in that: Applied to mobile terminals, including: A first identification information sending module, configured to send identification information to a server via a first identification collection terminal; wherein the identification information is collected when permission information corresponding to the user identity information indicates that the current user has permission to enter the current area, and the user identity information is obtained by obtaining a user biometric feature collected for the current user and performing user identity recognition based on the user biometric feature; an authority control instruction receiving module, configured to receive an authority control instruction sent by the server; wherein the authority control instruction is generated according to the authority information when the identification information matches the user identity information; The authority control instruction response module is used to respond to the authority control instruction and enter the security mode corresponding to the authority control instruction, and some functions of the mobile terminal are set to be disabled in the security mode.
11. An electronic device, characterized in that: The method comprises a processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein the computer program implements the method according to any one of claims 1 to 8 when executed by the processor.
12. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 8 is implemented.
13. A computer program product, characterized in that The invention comprises a computer program which, when executed by a processor, implements the method according to any one of claims 1 to 8.