Authority control method and electronic equipment

By associating the application's permission control with the function usage scenario, permissions are granted only when the function is in use and revoked when it stops being used. This solves the problem of applications accessing resources without awareness in existing technologies, and achieves secure protection and informed control of user privacy.

CN120832686APending Publication Date: 2025-10-24HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410465707.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-04-17
Publication Date
2025-10-24

AI Technical Summary

Technical Problem

The existing permission management mechanism cannot effectively control applications from accessing or using the hardware and software resources of electronic devices without the user's knowledge, resulting in the risk of privacy information leakage.

Method used

Associate an application's access rights to hardware and software resources with the functions it provides, granting permissions only when the functions are in use and revoking them when they are no longer in use. The user is prompted with the current access status through the status bar.

Benefits of technology

Ensure the security of user privacy information, prevent applications from accessing or using related resources after not using specific functions, and improve users' awareness and control over the use of permissions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120832686A_ABST
    Figure CN120832686A_ABST
Patent Text Reader

Abstract

The invention discloses an authority control method and electronic equipment, relates to the technical field of electronic equipment, can realize an authority control mechanism taking a function use scene as granularity, and protects the safety of privacy information of a user. In the scheme, the electronic equipment can respond to a use operation of a first function of a first application, use the first function of the first application and grant the first application to the authority of calling a system service related to the first function, and the system service related to the first function is related to the security privacy of a user; then, during the run of the first application, the electronic device may cancel the authority granting the first application to call a system service related to the first function in response to the stop of use of the first function of the first application.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of electronic devices, and in particular to a permission control method and an electronic device. BACKGROUND

[0002] With the development of the Internet, more and more applications (APPs) can be installed on electronic devices. In order to implement some functions, an application often needs to access hardware resources and / or software resources of the electronic device. Since some hardware resources and / or software resources involve user privacy information, the electronic device performs permission management on the access operation of the application involving user privacy information, that is, the application can only be allowed to access the hardware resources and / or software resources corresponding to the permission when the application has the corresponding permission.

[0003] At present, an application generally requests a user to grant a permission through a pop-up window. After the user agrees to grant the permission, the application can obtain the permission to access the corresponding hardware resources and / or software resources, so that the application can successfully access the hardware resources and / or software resources of the electronic device. However, after the user authorizes the application to obtain the permission to access the corresponding hardware and / or software resources, the application may access the hardware and / or software resources of the electronic device without the user's awareness, thereby causing the risk of leakage of the user's privacy information. SUMMARY

[0004] The present application provides a permission control method and an electronic device, which can associate the access permission of the hardware resources and / or software resources of the electronic device with the function provided by the application, implement a fine-grained permission management mechanism with the use scenario of the function as the granularity, and protect the security of the user's privacy information.

[0005] To achieve the above object, the present application adopts the following technical solutions:

[0006] In a first aspect, a permission control method is provided, which is applied to an electronic device, and the method comprises: in response to a use operation of a first function of a first application, using the first function of the first application and granting the first application a permission to call a system service related to the first function, the system service related to the first function being related to the security privacy of a user; and in a running process of the first application, in response to a stop of use of the first function of the first application, canceling the permission granted to the first application to call the system service related to the first function.

[0007] The first function can be any one of a video call function, a voice call function, a remote control function, a navigation function, etc. The system service related to the first function can be at least one of a microphone service, a camera service, a keyboard and mouse injection service, and a location service.

[0008] The above-mentioned first aspect provides a solution that the electronic device can associate the authorization of the user to the first application to access or use the corresponding hardware resource or software resource (e.g., a microphone) with the first function provided by the first application, so that the first application is granted the permission to access or use the hardware resource or software resource related to the first function only when the user uses the first function, and the permission to access or use the hardware resource or software resource related to the first function previously granted to the first application is revoked when the user stops using the first function. In this way, the user can ensure that the authorization of the first application to access or use the related hardware resource or software resource is limited to the use scenario of a certain specific function provided by the first application. In the scenario where the specific function is not used, the first application does not have the permission to access or use the related hardware resource or software resource. Thus, the situation where the first application still accesses or uses the related hardware resource or software resource after the user ends using the specific function is avoided, and the security of the user's private information is ensured.

[0009] Optionally, when the user uses the first function of the first application, the electronic device has granted the first application the permission to call the system service related to the first function. Therefore, the first application can call the system service related to the first function at will during the use of the first function. At this time, in order to remind the user of the access behavior of the first application to the corresponding system service, the electronic device can display a prompt icon of the called system service in the status bar. When the user stops using the first function of the first application, the electronic device has revoked the permission to call the system service related to the first function previously granted to the first application. Therefore, the first application can no longer call the system service related to the first function at will. At this time, since the first application can no longer call the system service, the electronic device will not display the prompt icon of the called system service in the status bar. In this way, the user can know that the first application does not access the corresponding system service through the no longer displayed prompt icon.

[0010] In a possible implementation, the permission control method further includes: in response to a use operation of a second function of the first application, using the second function of the first application and granting the first application the permission to call a system service related to the second function, the system service related to the second function being related to the security and privacy of the user; and during the running of the first application, in response to a stop use of the second function of the first application, canceling the permission to call the system service related to the second function previously granted to the first application. In this way, when the first application provides multiple functions, the electronic device can grant the first application the permission to access or use the hardware resource or software resource related to the corresponding function in the use scenario of each function when the user uses different functions of the first application.

[0011] In a possible implementation, the revoking the permission of the first application to invoke the system service related to the first function in response to the first function of the first application being no longer used includes: in response to switching from the first function of the first application to a second function of the first application, revoking the permission of the first application to invoke the system service related to the first function. In this way, when the user switches to use a different function, since the function before the switch is no longer used, the electronic device can recover the permission of the application to invoke the system service related to the function before the switch.

[0012] In a possible implementation, the permission control method further includes: in response to the use of the first function of the first application, displaying a first icon in the status bar, the first icon being used to indicate that the system service related to the first function is invoked; and in response to switching from the first function of the first application to a second function of the first application, canceling the display of the first icon in the status bar.

[0013] It can be understood that when the user uses the first function of the first application, since the first application can invoke the system service related to the first function at will, the electronic device can display a prompt icon indicating that the system service is invoked in the status bar. When the user switches to use the second function of the first application, since the first function is no longer used, the first application cannot invoke the system service related to the first function, and therefore the electronic device does not display the prompt icon indicating that the system service is invoked in the status bar.

[0014] In a possible implementation, when there are a plurality of system services related to the first function, the revoking the permission of the first application to invoke the system service related to the first function in response to the first function of the first application being no longer used includes: in response to switching from the first function of the first application to a second function of the first application, revoking the permission of the first application to invoke part of the system services related to the first function, the part of the system services being irrelevant to the second function. In this way, when the user switches to use a different function, if the functions before and after the switch both need to invoke the same system service, since the function after the switch still needs the support of the same system service, the electronic device can not recover the permission of the first application to invoke the same system service, but only recover the permission of the application to invoke part of the system services related to the function before the switch, the part of the system services being irrelevant to the function after the switch.

[0015] In a possible implementation, the permission control method further includes: in response to the use of the first function of the first application, displaying a plurality of icons in the status bar, the plurality of icons being used to indicate that the system service related to the first function is invoked; and in response to switching from the first function of the first application to a second function of the first application, canceling the display of part of the icons in the status bar.

[0016] It can be understood that when the user uses the first function of the first application, the electronic device can display a plurality of prompt icons in the status bar, indicating that the plurality of system services related to the first function are called by the first application at will. When the user switches to use the second function of the first application, although the first function is no longer used, the second function still needs the support of XX system service in the plurality of system services, and does not need the support of the remaining other system services. Therefore, the first application can still call the XX system service at will, and cannot call the remaining other system services. Therefore, the electronic device does not display the prompt icons indicating that the remaining other system services are called in the status bar, but still displays the prompt icon indicating that the XX system service is called.

[0017] In a possible implementation, the foregoing canceling the permission of the first application to call the system service related to the first function in response to the stop of the use of the first function of the first application comprises: canceling the permission of the first application to call the system service related to the first function in response to the stop of the use of the first function of the first application. In this way, the electronic device can withdraw the permission of the first application to call the system service related to the first function as soon as the operation of the user for explicitly stopping the use of the first function is detected.

[0018] In a possible implementation, the stop of the use of the first function of the first application comprises: an operation on an application-level control in the first application; or an operation on a system-level control in the electronic device. In this way, the user can trigger the stop of the use of the first function through the control provided by the application or the control provided by the system of the electronic device.

[0019] In a possible implementation, the foregoing canceling the permission of the first application to call the system service related to the first function in response to the stop of the use of the first function of the first application comprises: canceling the permission of the first application to call the system service related to the first function in response to the pause of the use of the first function of the first application. In this way, when the user pauses the use of the first function of the first application, the first application does not have the permission to call the system service related to the first function.

[0020] In this case, the permission control method further comprises: continuing to grant the permission of the first application to call the system service related to the first function in response to the resumption of the use of the first function of the first application. In this way, when the user resumes the use of the first function of the first application, the first application can resume to have the permission to call the system service related to the first function.

[0021] In a possible implementation, the permission control method further includes: in response to the use of the first function of the first application, displaying a first icon in the status bar, the first icon being used to indicate that the system service related to the first function is invoked; in response to the suspension of the use of the first function of the first application, canceling the display of the first icon in the status bar; and in response to the resumption of the use of the first function of the first application, continuing to display the first icon in the status bar.

[0022] It can be understood that, when the user uses the first function of the first application, the first application can invoke the system service related to the first function at will, and thus the electronic device can display a prompt icon indicating that the system service is invoked in the status bar. When the user suspends the use of the first function of the first application, the first function is no longer used, and thus the first application cannot invoke the system service related to the first function, and thus the electronic device does not display the prompt icon indicating that the system service is invoked in the status bar. When the user resumes the use of the first function of the first application, the first application can again invoke the system service related to the first function at will, and thus the electronic device can continue to display the prompt icon indicating that the system service is invoked in the status bar.

[0023] In a possible implementation, the above-mentioned operation of responding to the use of the first function of the first application, using the first function of the first application, and granting the first application the permission to invoke the system service related to the first function, includes: in response to the use of the first function of the first application, outputting a first prompt at the system level, the first prompt being used to prompt the user to confirm the intention to use the first function of the first application; and in response to a confirmation operation on the first prompt, using the first function of the first application, and granting the first application the permission to invoke the system service related to the first function. In this way, the electronic device can provide a prompt controlled by the system to the user to confirm the intention of the user to use the first function of the first application, and can avoid the first application cheating the system that the user has confirmed the use of the first function.

[0024] Optionally, the first prompt can include risk prompt content when the first function is used, a confirmation control, and a cancel control. The confirmation operation on the first prompt can be a trigger operation on the confirmation control.

[0025] In a possible implementation, the permission control method further includes: in the use process of the first function of the first application, outputting a second prompt at the system level, the second prompt being used to prompt the user that the first function of the first application is in use, and / or prompt the user that the system service related to the first function is invoked. In this way, in the use process of the first function of the first application, the electronic device can provide a state prompt controlled by the system to the user, so that the user can view and manage the use state of the first function of the first application.

[0026] In a possible implementation, the second prompt comprises a system-level control for triggering the stopping of the use of the first function of the first application. In this way, the user can stop the use of the first function of the first application by one key through the system-level control provided by the electronic device, which is equivalent to canceling the authorization of the first application to call the system service related to the first function by one key.

[0027] In a possible implementation, the permission control method further comprises: in response to an operation on the system-level control, canceling the permission of the first application to call the system service related to the first function when the use of the first function of the first application is stopped and the permission of the first application to call the system service related to the first function is not canceled. In this way, when the use of the first function of the first application is stopped, if the first application still has the permission to call the system service related to the first function, the user can cancel the authorization of the first application to call the system service related to the first function by one key through the system-level control provided by the electronic device.

[0028] In a possible implementation, the above canceling the permission of the first application to call the system service related to the first function in response to the stopping of the use of the first function of the first application during the running of the first application comprises: canceling the permission of the first application to call the system service related to the first function in response to the stopping of the use of the first function of the first application during the foreground running of the first application. In this way, when the user stops the use of the first function of the first application during the foreground use of the first application, the first application no longer has the permission to call the system service related to the first function, and even if the user still uses the first application in the foreground, such as using other functions of the first application, the first application still does not have the permission to call the system service related to the first function.

[0029] In a possible implementation, the permission control method further comprises: in response to the switching of the first application from the foreground running to the background running, stopping the use of the first function of the first application and canceling the permission of the first application to call the system service related to the first function. In this way, when the first application is switched to the background during the use of the first function of the first application by the user, the electronic device withdraws the permission of the first application to call the system service related to the first function previously granted to the first application.

[0030] In a possible implementation, the permission control method further comprises: in response to the switching of the first application from the foreground running to the background running, using the first function of the first application in the background and displaying a third prompt of a system level, the third prompt comprising a system-level control, the third prompt being used to prompt the user that the first function of the first application is in use and / or prompt the user that the system service related to the first function is called; and in response to the triggering operation of the system-level control, stopping the use of the first function of the first application and canceling the permission of the first application to call the system service related to the first function.

[0031] Thus, when the user uses the first function of the first application, the electronic device can continue to use the first function of the first application in the background when the first application switches to the background, and the electronic device still continues to grant the first application the permission to call the system service related to the first function. At this time, the electronic device can reserve a state prompt in the foreground, so that the user can stop using the first function of the first application through a system-level control in the state prompt, which is equivalent to canceling the authorization of the first application to call the system service related to the first function.

[0032] In a possible implementation, the system service related to the first function can be a service of calling a hardware resource or a software resource of the electronic device. For example, it can be at least one of a microphone service, a camera service, a keyboard and mouse injection service, and a location service.

[0033] In a second aspect, a permission control apparatus is provided, which is included in an electronic device and has a function of implementing the first aspect or any possible implementation of the first aspect. The function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the above functions.

[0034] In a third aspect, an electronic device is provided, which includes a memory and one or more processors. The memory is configured to store a program, and when the processor executes the program, the electronic device executes the permission control method in any possible implementation of the first aspect.

[0035] In a fourth aspect, a chip system is provided. The chip system includes one or more interface circuits and one or more processors. The interface circuit and the processor are interconnected through a circuit. The interface circuit is configured to receive a signal from a memory of an electronic device and send the signal to the processor. The signal includes instructions stored in the memory. When the processor executes the instructions, the electronic device executes the permission control method in any possible implementation of the first aspect.

[0036] In a fifth aspect, a readable storage medium is provided, which includes computer readable instructions (or "programs"). When the instructions are run on an electronic device, the electronic device executes the permission control method in any possible implementation of the first aspect.

[0037] In a sixth aspect, a computer program product is provided, which includes computer readable instructions (or "programs"). When the computer program product is run on a computer, the computer executes the permission control method in any possible implementation of the first aspect.

[0038] It can be understood that the device of the second aspect, the electronic device of the third aspect, the chip system of the fourth aspect, the readable storage medium of the fifth aspect and the program product of the sixth aspect provided in the above can achieve the beneficial effects of the first aspect and any possible implementation thereof, which will not be repeated here. BRIEF DESCRIPTION OF DRAWINGS

[0039] Figure 1 A system structure diagram of a permission management mechanism in related technologies provided for an embodiment of the present application;

[0040] Figure 2 An interface schematic diagram provided for an embodiment of the present application;

[0041] Figure 3 A hardware structure schematic diagram of an electronic device provided for an embodiment of the present application;

[0042] Figure 4 A software structure schematic diagram of an electronic device provided for an embodiment of the present application;

[0043] Figure 5 A function module schematic diagram of a scenario service provided for an embodiment of the present application;

[0044] Figure 6 Another function module schematic diagram of a scenario service provided for an embodiment of the present application;

[0045] Figure 7 A system structure diagram of a permission control method provided for an embodiment of the present application;

[0046] Figure 8 Another system structure diagram of a permission control method provided for an embodiment of the present application;

[0047] Figure 9 Still another system structure diagram of a permission control method provided for an embodiment of the present application;

[0048] Figure 10 An interface schematic diagram provided for an embodiment of the present application Figure 1 ;

[0049] Figure 11 Still another system structure diagram of a permission control method provided for an embodiment of the present application;

[0050] Figure 12 A flowchart of a permission control method provided for an embodiment of the present application;

[0051] Figure 13 An interface schematic diagram provided for an embodiment of the present application Figure 2 ;

[0052] Figure 14Interface diagram provided for the embodiment of this application Figure 3 ;

[0053] Figure 15 A flowchart of another permission control method provided in an embodiment of the present application;

[0054] Figure 16 Interface diagram provided for the embodiment of this application Figure 4 ;

[0055] Figure 17 Interface diagram provided for the embodiment of this application Figure 5 . DETAILED DESCRIPTION

[0056] The technical solutions in the embodiments of the present application will be described clearly and in detail below with reference to the accompanying drawings.

[0057] In electronic devices, applications usually need to obtain permission to access or use the resources of the electronic device in order to implement certain functions. Among them, the resources of the electronic device include hardware resources and software resources. Hardware resources include sensors, detectors, memory, microphones, speakers, etc. on the electronic device. Software resources include screen display information, storage space, location information, applications (such as address book, SMS, calendar, phone, gallery, camera), floating windows, etc.

[0058] For example, if an application wants to implement video calling, it needs to obtain access permissions to the camera and microphone; if an application wants to implement screen sharing, it needs to obtain screen recording permissions; if an application wants to implement remote control, it needs to obtain screen recording permissions and injection permissions for input operations (such as keyboard and / or mouse-based input operations).

[0059] Currently, electronic devices generally manage various permissions of applications through permission management mechanisms. For example, when a user uses the video call feature provided by App A, App A needs to use the electronic device's camera and microphone. Therefore, App A first checks whether it has permission to use the camera and microphone. If App A has permission, it can directly use the camera and microphone to provide the video call feature. If App A does not have permission, it can request authorization from the user via a pop-up window. After the user agrees to the authorization, App A can use the camera and microphone to provide the video call feature.

[0060] Take the microphone usage permission as an example. Figure 1 FIG. 1 shows a flow chart of the related art in which the permission management mechanism manages the permission to use the microphone of application A. Figure 1As shown, when application A needs to use the microphone to implement the video call function, application A can call the service interface provided by the microphone service to implement the call of the underlying microphone service. The microphone service has the management control authority of the hardware microphone and can control the hardware microphone to collect sound data. The service interface is a communication interface provided by the underlying system service for the upper application, that is, the upper application calls the underlying system service through the corresponding service interface.

[0061] Since the use of the microphone involves the personal privacy of the user, when application A calls the service interface provided by the microphone service, the microphone service can determine whether application A has the permission to use the microphone through the permission management service. If application A has no permission, application A cannot call the microphone service and cannot provide the video call function. At this time, application A can call the authorization interface provided by the permission management service to request the user's authorization.

[0062] When application A calls the authorization interface provided by the permission management service, the permission management service can call the window management service to display the authorization window for the user to select whether to grant application A the permission to use the microphone in the authorization window. When detecting the operation of the user granting application A the permission to use the microphone, the permission management service can grant application A the permission to use the microphone.

[0063] At this time, application A can call the service interface provided by the microphone service again to implement the call of the underlying microphone service. When application A calls the service interface provided by the microphone service, since the microphone service can determine that application A has the permission to use the microphone through the permission management service at this time, application A can successfully call the microphone service to provide the video call function.

[0064] However, in the current permission management method, after the user authorizes the application to obtain the permission to access or use the corresponding hardware or software resource, the application can directly access or use the hardware and software resources of the electronic device without further interacting with the user to request authorization during the authorization period. That is, the process of the application accessing or using the hardware or software resource during the authorization period is invisible to the user. This makes the application possible to access or use the hardware and software resources of the electronic device without the user's awareness, thereby causing the risk of leakage of the user's private information and affecting the user's experience.

[0065] It can be understood that the current electronic device can support multiple authorization modes, including but not limited to some or all of the following authorization modes: always allowed, allowed during use, allowed for this run, prohibited, etc. When the electronic device displays the authorization window of the application, the authorization window can display the multiple authorization modes, such as Figure 2 as shown, for the user to grant the application different permissions for different lengths of time according to different needs.

[0066] The prohibition means that the application is denied the permission, and the application cannot provide the related function to the user. That is, in the above example, the application A has no permission to access the camera and microphone, and cannot provide the video call function.

[0067] The always permission means that after the application is granted the permission, the application always has the permission. That is, in the above example, the application A can continuously obtain the permission to access the camera and microphone, and can provide the video call function at any time. However, since the process of the application A accessing the camera and microphone is invisible to the user after the user grants the permission, the application A can obtain the image, sound and the like of the user without the user's awareness. For example, after the user ends the video call, the application A still continuously obtains the image, sound and the like of the user.

[0068] The during permission means that after the application is granted the permission, the application has the permission only during the use of the application by the user. That is, in the above example, the application A can obtain the permission to access the camera and microphone during the active period of the application A. Similarly, the application A can obtain the image, sound and the like of the user without the user's awareness.

[0069] The this-run permission means that after the application is granted the permission, the application has the permission only during the last use of the application by the user. That is, in the above example, the application A will request the user for the permission through a pop-up window every time the user uses the video call function provided by the application A, which is not good for the user experience. Meanwhile, once the user grants the this-run permission, the application A still has the permission to access the camera and microphone during the active period of the application A even after the user ends the video call. Similarly, the application A can obtain the image, sound and the like of the user without the user's awareness.

[0070] It can be seen that the current permission management mechanism takes the application as the control granularity, and it cannot control the behavior of the application maliciously accessing or using the hardware and software resources of the electronic device. Therefore, after the user grants the application the permission to access or use the corresponding hardware resource or software resource, the user cannot know and control the access or use of the application to the hardware resource or software resource at any time, and the user control granularity is relatively coarse. This can cause the application to access or use the hardware resource and software resource of the electronic device without the user's awareness, thereby causing the risk of leakage of the user's private information and affecting the user experience.

[0071] Based on the above problems, the application provides a permission control method and an electronic device. The electronic device can associate the authorization of the user to the application to access or use the corresponding hardware resources or software resources with the functions (such as the video call function, the voice call function, the screen sharing function, the remote control function, etc.) provided by the application, so that the permission of the application to access or use the hardware resources or software resources related to the function is authorized only when the user uses the function, and the permission of the application to access or use the hardware resources or software resources related to the function is cancelled when the user stops using the function. In this way, it can be ensured that the user grants the application the permission to access or use the related hardware resources or software resources, which is limited to the use scenario of a certain specific function provided by the application. In the scenario where the function is not used, the application does not have the permission to access or use the related hardware resources or software resources. Thus, the application can be prevented from accessing or using the related hardware resources or software resources after the user ends using a certain specific function, and the security of the user's private information is ensured.

[0072] In some embodiments, the hardware resources or software resources of the electronic device can be managed and controlled by the corresponding services / modules, that is, the hardware resources or software resources can open the corresponding hardware capabilities or software capabilities to the corresponding services / modules. Therefore, the permission of the application to access or use the corresponding hardware resources or software resources can also refer to the permission of the application to call the corresponding services / modules. The services / modules of the electronic device can be hardware services / modules, such as a microphone service / module, a camera service / module, etc., or software services / modules, such as a screen recording service / module, a location service / module, etc.

[0073] The hardware resources or software resources managed and controlled by the services / modules of the electronic device can be the hardware resources or software resources of the electronic device itself, or the hardware resources or software resources externally connected to the electronic device. The application embodiments do not limit the source of the resources managed and controlled by the services / modules of the electronic device.

[0074] In the application embodiments, the electronic device to which the permission control method is applied can be a mobile phone, a tablet computer (tablet for short), a (desktop, laptop, handheld) computer, a notebook computer, an ultra-mobile personal computer (UMPC), a netbook, a cellular phone, a personal digital assistant (PDA), an augmented reality (AR) / virtual reality (VR) device, etc. The application embodiments do not specially limit the specific form of the electronic device.

[0075] Exemplarily, Figure 31 shows a schematic structural diagram of the electronic device 100. Figure 3 As shown, the electronic device 100 may include a processor 110, a memory 120, an antenna, a communication module 130, a sensor module 140, a microphone 150, a camera 160, and a display screen 170. The sensor module 140 may include a touch sensor, a pressure sensor, a distance sensor, etc., and may also include other sensors such as a fingerprint sensor, a gyroscope sensor, an acceleration sensor, a proximity light sensor, etc. The embodiment of the present application does not limit the type and number of sensors included in the electronic device.

[0076] The touch sensor is also called a "touch panel." The touch sensor can be provided on the display screen 170. The touch sensor and the display screen 170 form a touch screen, also called a "touch screen." The touch sensor is used to detect touch operations applied thereto or in the vicinity thereof. The touch sensor can transmit the detected touch operation to the application processor to determine the type of touch event, and can also provide visual output related to the touch operation through the display screen 170. In other embodiments, the touch sensor can also be provided on the surface of the electronic device 100, at a location different from that of the display screen 170.

[0077] The pressure sensor is used to sense pressure signals and convert them into electrical signals. In some embodiments, the pressure sensor can be located on display screen 170. When a touch operation is performed on display screen 170, electronic device 100 detects the intensity of the touch operation using the pressure sensor. Electronic device 100 can also calculate the location of the touch based on the detection signal from the pressure sensor.

[0078] It is understood that the structures illustrated in the embodiments of the present application do not constitute a specific limitation on the electronic device 100. In other embodiments, the electronic device 100 may include more or fewer components than shown, or combine or separate certain components, or arrange the components differently. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware. For example, the electronic device 100 may also include a charging management module, a battery, buttons, a speaker, a receiver, a headphone jack, etc.

[0079] The processor 110 can include one or more processing units, for example: the processor 110 can include an application processor (AP), a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), etc. Among them, different processing units can be independent devices, or can be integrated in one or more processors. The processor 110 can run multiple tasks (such as application programs) at the same time to provide the user with a variety of services and functions. Among them, the controller can be the nerve center and command center of the electronic device 100. The controller can generate operation control signals according to instruction operation codes and timing signals to complete the control of fetching instructions and executing instructions.

[0080] The memory in the processor 110 can also be provided for storing instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. The memory can save instructions or data that the processor 110 has just used or recycled. If the processor 110 needs to use the instructions or data again, it can be directly called from the memory. Avoid repeated access and reduce the waiting time of the processor 110, thereby improving the efficiency of the system.

[0081] In some embodiments, the processor 110 can include one or more interfaces, such as a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a universal serial bus (USB) interface, etc. The processor 110 can be connected with other components through one or more of the above interfaces.

[0082] Among them, the USB interface can be used for the electronic device 100 to transmit data with the input / output device. The input device can be a wired mouse, a wired keyboard, etc.

[0083] In the embodiments of the present application, the processor 110 can obtain the input operation (such as click operation) of the user on the content displayed on the display screen 170 through the wired mouse through the USB interface, or obtain the input operation of the user on the content displayed on the display screen 170 through the wired keyboard.

[0084] The memory 120 can be used to implement the data storage function of the electronic device 100. For example, files such as images, videos, etc. are saved in the memory 120. The memory 120 can also be used to store computer executable program codes, which include instructions. The processor 110 executes various functional applications and data processing of the electronic device 100 by running the instructions stored in the memory 120. The memory 120 can include a program storage area and a data storage area. The program storage area can store an operating system, at least one application program (such as a camera application) required by a function, etc. The data storage area can store data (such as images taken) created during the use of the electronic device 100, etc. In addition, the memory 120 can include a high-speed random access memory, and can also include a non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, a universal flash storage (UFS), etc.

[0085] The communication module 130 and the antenna are used to implement the wireless communication function of the electronic device 100. The communication module 130 can provide a solution for wireless communication including 2G / 3G / 4G / 5G, etc. applied to the electronic device 100, and can also provide a solution for wireless communication including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) network), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared technology (IR), etc. applied to the electronic device 100.

[0086] In some embodiments, the electronic device 100 can interact with an input device based on wireless communication technology through the communication module 130 to receive a user input operation triggered by the input device, etc. The input device can be a wireless mouse, a wireless keyboard, etc. The user input operation can be an operation of the user clicking a certain control (button).

[0087] The electronic device 100 can implement an audio function through an audio module, a speaker, a receiver, a microphone 150, an earphone interface, and an application processor, etc. For example, music playing, recording, etc. Among them, the microphone 150 is also called a "microphone", "sounder", which is used to convert a sound signal into an electrical signal. When making a voice call or making a recording or sending a voice message or needing to trigger the electronic device 100 to perform certain functions through a voice assistant, the user can speak by approaching the microphone 150 with the mouth, inputting the sound signal into the microphone 150. The electronic device 100 can be provided with at least one microphone 150. In some embodiments, the electronic device 100 can be provided with two, four or more microphones 150, to realize the functions of collecting sound signals, noise reduction, sound source identification, directional recording, etc.

[0088] The electronic device 100 can implement a shooting function through an ISP, a camera 160, a GPU, a display screen 170, and an application processor, etc. The ISP is used to process the data fed back by the camera 160. In some embodiments, the ISP can be arranged in the camera 160. Among them, the camera 160 is used to capture a still image or a video. An object generates an optical image through a lens and projects it to a photosensitive element. The photosensitive element converts the optical signal into an electrical signal, and then transmits the electrical signal to the ISP to convert it into a digital image signal. The ISP outputs the digital image signal to the DSP for processing. The DSP converts the digital image signal into a standard RGB, YUV, etc. Format image signal. In some embodiments, the electronic device 100 can include one or N cameras 160, N being a positive integer greater than 1.

[0089] The electronic device 100 can implement a display function through a GPU, a display screen 170, and an application processor, etc. The GPU is a microprocessor for image processing, connected to the display screen 170 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. The processor 110 can include one or more GPUs that execute program instructions to generate or change display information.

[0090] The display screen 170 is configured to display images, videos, and the like. For example, the display screen 170 can display any one of a video call interface, a voice call interface, a screen sharing interface, and a remote control interface. The display screen 170 includes a display panel. The display panel can be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flex light-emitting diode (FLED), a Miniled, a MicroLed, a Micro-oLed, a quantum dot light emitting diode (QLED), or the like. In some embodiments, the electronic device 100 can include one or N display screens 170, where N is a positive integer greater than 1.

[0091] In the embodiments of the present application, if the electronic device 100 receives an application-in-video call request initiated by the opposite end in the chat application, the display screen 170 of the electronic device 100 can display a video call interface. If the electronic device 100 detects a user's on-hold confirmation operation, the display screen 170 of the electronic device 100 can display a risk prompt window, which can include risk prompt content, a confirmation control, and a cancel control.

[0092] After the user clicks the confirmation control, the chat application starts to provide the user with the video call function, and the chat application can obtain the access permission of the microphone and the camera. At this time, the display screen 170 of the electronic device 100 can display a video interface and a status prompt window. The status prompt window is configured to indicate that the chat application is supporting the video call function, and the status prompt window can display status prompt content and an end control. The video interface can display the video content sent by the opposite end and the video content collected by the electronic device 100 using the microphone and the camera.

[0093] In the embodiments of the present application, after the user clicks the end control, the chat application ends the provision of the video call function, and the chat application no longer obtains the access permission of the microphone and the camera.

[0094] It can be understood that the software system of the electronic device 100 can adopt a layered architecture, an event-driven architecture, a microkernel architecture, a microservice architecture, or a cloud architecture. The embodiments of the present application take the layered architecture as an example to illustrate the software structure of the electronic device 100.

[0095] Figure 4 is a software structure block diagram of the electronic device 100 of an embodiment of the present application. The layered architecture divides the software system into several layers, each of which has a clear role and division of labor. Layers communicate with each other through software interfaces. In some embodiments, the layered architecture divides the software into three layers, from top to bottom, the application layer (referred to as the application layer for short), the application framework layer (referred to as the framework layer for short), and the kernel layer.

[0096] The application layer can include a series of application packages. As shown in Figure 4 , the application package can include gallery, camera, music, video, short message, etc. For the convenience of description, the application is referred to as the application below. The application on the electronic device 100 can be a native application or a third-party application, which is not limited by the embodiments of the present application.

[0097] As an example, the application layer can include a chat application that provides a video call function and / or a voice call function, and can also include a device collaboration application that provides a screen sharing function and / or a remote control function.

[0098] The framework layer provides the application of the application layer with an application programming interface (API) and a programming framework. The framework layer includes some pre-defined functions (services), such as window management services, input event management services, resource management services, view systems, etc. The embodiments of the present application are not limited. Among them, the input event management service (IMS) can be used to translate, encapsulate, etc. The original input event is processed to obtain an input event containing more information, and is sent to the window management service. The window management service stores the position information of the clickable area (such as the control) of each application and the focus window. Therefore, the window management service can correctly distribute the input event to the specified control or focus window.

[0099] In the embodiments of the present application, the framework layer can also include system basic services. The system basic service can be understood as the minimum capability unit that the system provides and can run independently, which is a concept of abstract encapsulation of a single function / capability. Among them, the system basic service can be a hardware service, such as a camera service, a microphone service, etc., or a software service, such as a keyboard and mouse injection service, a screen recording service, a location service, etc.

[0100] It should be noted that the system basic service is only a word used in the embodiments of the present application, and the meaning represented thereby has been described in the embodiments of the present application, and the name thereof does not constitute any limitation on the embodiments of the present application. For example, in some other embodiments, the system basic service can also be referred to as a system basic function, a system function, a system service, an atomized service, a meta-ability, an atomic ability (Ability), an atomic service, a functional component, or other terms. In the embodiments of the present application, the system basic service is mainly described.

[0101] Optionally, the system basic service includes a permission management service, which can be used to manage the permission of each application in an application layer to access the system basic service. For example, to control the display of an authorization window, so that a user selects whether to grant the corresponding permission of the application in the authorization window; or to record the corresponding authorization information (for example, xx application has xx permission) after the user grants the corresponding permission of the application.

[0102] In the embodiments of the present application, each system basic service in the framework layer can provide a communication interface for the upper layer application, which can also be referred to as a system basic service interface, so that the upper layer application can call the lower layer system basic service by calling the corresponding interface. For example, a service interface of a location service, a service interface of a camera service, and the like.

[0103] In the embodiments of the present application, to implement the permission control method provided in the present application, a scenario-based service can be added in the framework layer, so as to associate the access permission of the system basic service with the use scenario of the function provided by the application through the scenario-based service.

[0104] As shown in Figure 4 The framework layer can include a scenario-based service, which can be a service provided by the system to control the permission in the use scenario of a certain function, to provide system basic service support for the use of the function, so as to normally use the function. The function can be a certain function provided by the upper layer application, and the implementation of the function needs at least one system basic service provided by the electronic device. For example, the screen sharing function provided by the device collaboration type application needs to access or use the screen recording service of the electronic device; the video call function provided by the chat type application needs to access or use the microphone service and the camera service of the electronic device; the navigation function provided by the map type application needs to access or use the location service of the electronic device, and the like.

[0105] As an example, as shown in Figure 4As shown in FIG. 1, the framework layer can include a plurality of scenario-based services, such as a video call service corresponding to a use scenario of a video call function, a remote control service corresponding to a use scenario of a remote control function, and the like. It can be understood that the framework layer can also include other scenario-based services, such as a screen sharing service, an audio call service, a navigation service, a live broadcast service, and the like, and the type of scenario-based service is not limited in the embodiments of the present application.

[0106] It should be noted that the scenario-based service is only a word used in the embodiments of the present application, and the meaning represented thereby has been described in the embodiments of the present application, and the name thereof does not constitute any limitation on the embodiments of the present application. For example, in other embodiments, the scenario-based service can also be referred to as a scenario-based function, a scenario function, a scenario service, a scenario-based business, a business function, and the like. In the embodiments of the present application, the scenario-based service is mainly described.

[0107] Since the application of the application layer can support one or more functions, each function can be selected and used by a user. Therefore, in the embodiments of the present application, when a user uses a certain function provided by an application, and the function needs the application to access or use a certain system basic service, the application can call a scenario-based service corresponding to a use scenario of the function, and determine the use state of the function by the scenario-based service, so as to determine whether to grant the application the permission to access or use the system basic service.

[0108] As shown in FIG. 1, each scenario-based service of the framework layer can provide a communication interface for the upper-layer application, which can also be referred to as a scenario-based service interface, so that the upper-layer application can call the lower-layer scenario-based service by calling the corresponding interface. Figure 4 In the embodiments of the present application, when a user uses a certain function provided by an application, and the function needs the application to access or use a certain system basic service, the application needs to call a scenario-based service interface corresponding to a use scenario of the function first, to determine the use state of the function. When it is confirmed that the user uses the function, the scenario-based service can grant the application the permission to access or use the system basic service. At this time, the application can call a corresponding system basic service interface to call the system basic service, so that the application can ensure the normal use of the function.

[0109] Each scenario-based service can be associated with a corresponding required system basic service, so that the scenario-based service can grant the application the corresponding system basic service permission.

[0110]

[0111] ​Optionally, the system base service required by the scenario service corresponds to a system base service interface, and the scenario service interface of the scenario service can be encapsulated in some manner, so that when an application wants to call the corresponding system base service, the above-mentioned judgment of the scenario service must be performed, thereby avoiding that the application directly calls the corresponding system base service.

[0112] In the embodiments of the present application, the scenario service can be used to realize state prompting of the use scenario of a function. Optionally, the scenario service can also realize risk prompting of the use scenario of the function, and / or state management of the use scenario of the function (such as suspending the use of the function or ending the use of the function).

[0113] In some embodiments, as shown in Figure 5 The scenario service can include a state prompting module, which is used to realize display of a state prompting window. The state prompting window is a window controlled by the system (not controlled by the application), and can display state prompting content when the corresponding function is used, such as that the xx application is currently supporting the xx function.

[0114] Optionally, the state prompting window can also include a state management control when the corresponding function is used, such as an end control for ending the use of the function. That is, the scenario service can interact with the user through the state prompting window to explicitly obtain the end use intention of the current user for the function (such as clicking the end control), which is equivalent to explicitly obtaining the cancel authorization of the current user for the application to use the system base service related to the function.

[0115] Optionally, as shown in Figure 6 The state prompting module can also be separated from the scenario service and serve as an independent function / service. The independent state prompting module can respectively interact with each scenario service to realize state prompting when the corresponding function is used for each scenario service.

[0116] Optionally, the independent state prompting module can also respectively interact with each system base service to realize display of a state prompting window when each system base service is called by an application. The state prompting window can display state prompting content when the corresponding system base service is called, such as that the xx application is currently calling the xx service.

[0117] Optionally, the scenario service can also include a risk prompting module, which is used to realize display of a risk prompting window. The risk prompting window is a window controlled by the system (not controlled by the application), and can display risk prompting content when the corresponding function is used, such as that the application will use the xx service when the function is used, and the application will access the xx data when the xx service is used.

[0118] Optionally, the risk warning window may also include a confirmation control and a cancel control. The confirmation control is used to ensure that the user is still determined to use the function after understanding the risk warning content, and the cancel control is used to ensure that the user can abandon the use of the function after understanding the risk warning content. In other words, the scenario-based service can interact with the user through the risk warning window to clearly understand the current user's intention to use the function, which is equivalent to clearly obtaining the current user's authorization to the application of the system basic services related to the use of the function.

[0119] Optionally, the risk warning module can be separated from the scenario-based service and used as an independent function / service. This independent risk warning module can interact with each scenario-based service to provide risk warnings when using the corresponding functions of each scenario-based service.

[0120] In some embodiments, when an application supports one or more functions, the application may also provide a corresponding status prompt window or corresponding function management controls, such as a prompt icon during a video call, a "hang up" control for ending a video call, etc. Therefore, the scenario-based service can optionally obtain the current user's intention to use or end the function through the user's operation events on the function management controls provided by the application, thereby correspondingly obtaining or revoking the current user's authorization for the application to use the system basic services related to the function.

[0121] In some embodiments, the application may also directly use the status prompt window or status management control managed by the above system, and no longer provide the status prompt window or corresponding function management control.

[0122] Optionally, when one or more applications provide a certain function, the scenario-based service corresponding to that function can be called by that application or applications. For example, if multiple applications all provide a video call function, then when a user uses the video call function provided by each application, each application can call the service interface of the video call service to call the underlying video call service and implement the permission control scheme provided in the embodiments of the present application. That is, the video call service determines the user's usage status of the video call function and thus determines whether to grant the application permission to access or use the microphone and camera of the electronic device.

[0123] In some scenarios, developers can develop different scenario-based services at the framework layer according to different usage scenarios, so that when users use a function provided by the application, the application can call the scenario-based service of the function accordingly to implement the permission control solution provided in the embodiment of this application.

[0124] The kernel layer is a layer between hardware and software. The kernel layer can include display drivers, input / output device drivers (such as touch screens), device nodes, audio drivers (such as microphones), camera drivers, and sensor drivers, and the like. A user inputs an operation through an input device, and the kernel layer can generate a corresponding operation event according to the input operation and report the operation event to an input event management service.

[0125] It should be understood that, Figure 4 , Figure 5 , Figure 6 The components included in the software structure shown do not constitute a specific limitation on the electronic device 100. In other embodiments, the electronic device 100 can include more or fewer components than shown, or combine certain components, or split certain components, or different arrangements of components. For example, in some scenarios, the layered architecture can also divide the software into four layers, from top to bottom, an application layer, a framework layer, a system layer (or system service layer), and a kernel layer. The scenario-based service can be arranged in the framework layer, and the system basic service can be arranged in the system layer (or system service layer).

[0126] The methods in the following embodiments can be implemented in the electronic device 100 with the hardware structure and software structure described above.

[0127] Based on the software modules described above, the embodiments of the present application provide a system flow diagram of a permission control method. The scenario-based service can continuously perceive the use state of the user for the corresponding function through the risk prompt module and / or the state prompt module, that is, continuously perceive the authorization state of the user for the corresponding permission of the application. Then the scenario-based service can communicate with the related system basic service, and pass the perceived authorization state of the user for the corresponding permission of the application to the related system basic service. Thus, the related system basic service can determine whether to respond to the call of the application.

[0128] As an example implementation, please refer to Figure 7 , the application layer includes an application A that provides a video call function (such as application). When the user uses the video call function of the application A, such as clicking the "video call" control provided by the application A to start the video call function, the application A needs to call the corresponding scenario-based service interface, that is, the service interface of the video call service, to realize the call of the lower layer video call service. Among them, the video call service has the management control permission of the microphone service and the camera service in the use scenario of the video call function.

[0129] At this time, the video call service can respond to the call of the application A, and display the risk prompt window through the risk prompt module. The risk prompt window can include risk prompt content, a confirmation control, and a cancel control. The risk prompt content can include a risk prompt about using the video call function, such as the use of the video call function requiring access to the microphone and the camera. The risk prompt content can also include a risk prompt about the device capability of the application A using the microphone and the camera, such as the application A requiring the use of the microphone and the camera of the device to obtain audio and images.

[0130] When the video call service detects that the user clicks the confirmation control in the risk prompt window, it can be determined that the user currently determines to use the video call function. At this time, the video call service can grant the application A the permission to access the microphone and the camera, and notify the microphone service and the camera service, and the upper-layer application A of the authorized information (indicating that the user has granted the application A the permission to access the microphone and the camera). The video call service can maintain communication with the microphone service and the camera service to timely deliver information about whether the user grants the application A the permission to access the microphone service and the camera service to the microphone service and the camera service.

[0131] Optionally, the risk prompt window can include a "no longer prompt" selection control to support the user selecting not to display the risk prompt window next time the user uses the video call function.

[0132] The application A can start to call the service interface of the microphone service and the service interface of the camera service after receiving the authorized information notified by the video call service. Since the microphone service and the camera service have determined that the application A has the permission to access the microphone and the camera through communication with the video call service, the application A can successfully call the underlying microphone service and the camera service, so as to drive the hardware microphone to collect sound and drive the camera to collect images. Then, the application A can obtain the sound information returned by the microphone service and the image information returned by the camera service.

[0133] Optionally, since the user triggers the use of the video call function, the application A considers that the user will probably grant the permission to access the microphone and the camera. Therefore, the application A can also call the service interface of the microphone service and the service interface of the camera service synchronously when calling the service interface provided by the video call service. In this way, the video call function of the application A can be quickly and normally used, reducing the waiting time of the user.

[0134] In this embodiment, the video call service can also display the status prompt window through the status prompt module after detecting that the user clicks the confirmation control in the risk prompt window. The status prompt window can include status prompt content and an end control. The status prompt content is used to indicate that the application A is supporting the video call function, and / or is used to indicate that the application A is using the microphone and the camera. The end control is used to end the video call function of the application A.

[0135] The video call service detects that the user clicks the confirmation control in the risk prompt window, and through communication with the microphone service and the camera service, the calling state of the microphone service and the camera service can be continuously perceived. When the microphone service and the camera service are perceived to be called by the application A, the video call service can display the corresponding status prompt content.

[0136] When the video call service detects that the user clicks the end control in the status prompt window, it can be determined that the user currently determines to stop using the video call function. At this time, the video call service can cancel the permission granted to the application A to access the microphone and the camera, and notify the microphone service and the camera service and the upper-layer application A of the cancellation of the authorization (indicating that the user has cancelled the permission granted to the application A to access the microphone and the camera). The application A can no longer call the underlying microphone service and the camera service through the service interface of the microphone service and the service interface of the camera service.

[0137] Even if the application A wants to continue to call the service interface of the microphone service and the service interface of the camera service, the microphone service and the camera service will refuse to respond to the call of the application A because the microphone service and the camera service have determined that the application A does not have the permission to access the microphone and the camera through communication with the video call service.

[0138] In this way, it is realized that when the user is using the video call function of the application A, the application A can obtain the permission to access the microphone and the camera related to the video call function. When the user stops using the video call function of the application A, even if the user is still using the application A such as browsing a page, the application A cannot obtain the permission to access the microphone and the camera related to the video call function. The user can at any time perceive the use of sensitive hardware resources by the application.

[0139] Based on the above software modules, the embodiment of the application provides a system flow diagram of another permission control method. Different from the above flow, the scenario service can pass the authorization state of the user to the application to the permission management service record, so that the related system basic service can judge whether to respond to the call of the application through the permission management service.

[0140] As another example implementation, an application B providing remote control function is taken as an example. As shown in FIG. 3, when a user uses the remote control function of the application B, such as clicking the "remote control" control provided by the application B to start the remote control function, the application B needs to call the corresponding scenario service interface, i.e., the service interface of the remote control service, to realize the calling of the underlying remote control service. The remote control service has the management control authority of the keyboard and mouse injection service in the use scenario of the remote control function. As shown in FIG. 3, when a user uses the remote control function of the application B, such as clicking the "remote control" control provided by the application B to start the remote control function, the application B needs to call the corresponding scenario service interface, i.e., the service interface of the remote control service, to realize the calling of the underlying remote control service. The remote control service has the management control authority of the keyboard and mouse injection service in the use scenario of the remote control function. Figure 8

[0141] Similarly, the remote control service can display the risk prompt window through the risk prompt module in response to the calling of the application B. The risk prompt window can display the risk prompt content, the confirmation control and the cancel control. When the remote control service detects that the user clicks the confirmation control in the risk prompt window, it can be judged that the user currently determines to use the remote control function. At this time, the remote control service can grant the application B the permission to control the screen of the electronic device, i.e., the permission to use the keyboard and mouse injection service, and notify the authorized information (indicating that the user has granted the application B the permission to use the keyboard and mouse injection service) to the permission management service and the upper application B. In this way, the application B can successfully call the service interface of the keyboard and mouse injection service to realize the calling of the underlying keyboard and mouse injection service.

[0142] It can be understood that when the application B calls the service interface of the keyboard and mouse injection service, the keyboard and mouse injection service can query the application A to have the permission to use the keyboard and mouse injection service through the permission management service, so that the application B can successfully call the keyboard and mouse injection service to realize the remote control function. That is, the application B can inject the keyboard and mouse input operation transmitted by other devices into the input event management service. The input event management service processes the keyboard and mouse input operation accordingly.

[0143] Similarly, the remote control service can also display the state prompt window through the state prompt module in response to the operation of the user clicking the confirmation control in the risk prompt window. The state prompt window can include the state prompt content and the end control. Optionally, the remote control service can also communicate with the keyboard and mouse injection service to perceive the calling state of the keyboard and mouse injection service. When the keyboard and mouse injection service is perceived to be called by the application B, the video call service can realize the display of the corresponding state prompt content.

[0144] ​Similarly, when the remote control service detects that the user clicks the end control in the status prompt window, it can be determined that the user currently determines to stop using the remote control function. At this time, the remote control service can cancel the permission granted to application B to control the screen of the electronic device, i.e., the permission to use the mouse and keyboard injection service, and notify the permission management service and the upper-layer application B of the cancellation of the permission (indicating that the user has cancelled the permission granted to application B to use the mouse and keyboard injection service). In this way, application B can no longer call the service interface of the mouse and keyboard injection service to call the underlying mouse and keyboard injection service. Even if application B wants to continue to call the service interface of the mouse and keyboard injection service, since the mouse and keyboard injection service can query, through the permission management service, that application B does not have the permission to use the mouse and keyboard injection service, the mouse and keyboard injection service will refuse to respond to the call of application B.

[0145] In this way, it is achieved that when the user is using the remote control function of application B, application B can obtain the permission to access the mouse and keyboard injection service related to the remote control function. When the user stops using the remote control function of application B, even if the user is still using application B, such as screen sharing with others, application B cannot obtain the permission to access the mouse and keyboard injection service related to the remote control function. In addition to hardware resources, the user can also be aware of the use of sensitive software resources by the application at any time.

[0146] Based on the above software modules, the embodiment of the present application provides another system flow diagram of a permission control method. Different from the above flow, the scenario service can perceive the use state of the user for the corresponding function through the function management control provided by the application, that is, perceive the authorization state of the user for the corresponding permission of the application.

[0147] As another example embodiment, as shown in FIG. 10, the application layer includes application C (such as a navigation application) that provides a navigation function. Figure 9 As another example embodiment, as shown in FIG. 10, the application layer includes application C (such as a navigation application) that provides a navigation function. Application C can be provided with a control for entering the navigation function and a control for exiting the navigation function. For example, as shown in FIG. 10(a), when the user searches for destination information on the home page of application C, application C can display a "navigation" control 1001 for entering the navigation function to provide the user with the navigation function to the destination. When the user intends to use the navigation function, the user can click the "navigation" control 1001. For another example, as shown in FIG. 10(b), when the user is using the navigation function, application C can display a "navigation" control 1002 for exiting the navigation function to provide the user with the function of exiting the navigation function. Figure 10 Figure 10 ​As shown in (c), when the user is using the navigation function of application C, application C may display an "Exit Navigation" control 1005 for exiting the navigation function. When the user intends to end the use of the current navigation function, the user may click the "Exit Navigation" control 1005. When the user operates the control for entering the navigation function, application C may call the corresponding scenario service interface, that is, the service interface of the navigation service, to implement the call of the lower-level navigation service. Application C may send the operation information of the user operating the control for entering the navigation function to the navigation service to notify the navigation service that the user has confirmed the use of the navigation function of application C. The navigation service has the management and control authority of the location service under the usage scenario of the navigation function.

[0148] The navigation service can respond to the call from application C and, based on the received information about the user operating the control for accessing the navigation function, confirm that the user currently wants to use the navigation function of application C. At this point, the navigation service can grant application C permission to access the location service and notify the location service and the upper-layer application C of the authorization information (indicating that the user has granted application C permission to access location information). In this way, application C can successfully call the underlying location service by calling the service interface of the location service. Optionally, the navigation service can also notify the permission management service of the authorization information; refer to the process of the aforementioned implementation plan.

[0149] Optionally, the navigation service may also respond to the call of application C and realize the display of the risk warning window through the risk warning module, so as to interact with the user through the risk warning window controlled by the system, and reconfirm the user's intention to use the navigation function of application C (that is, reconfirm the user's intention to authorize application C to access location information), which can prevent application C from deceiving the system that it has obtained user authorization. When the navigation service detects that the user clicks the confirmation control in the risk warning window, the navigation service can confirm that the user is still determined to use the navigation function after understanding the risks. At this time, the navigation service can grant application C permission to access location services.

[0150] like Figure 10 (a) and Figure 10 As shown in (b) of the figure, after the user clicks the "Navigation" control 1001, the electronic device may display a system pop-up window 1002 on the interface of application C to provide the user with a risk warning regarding the use of the navigation function of application C. When the user clicks the confirmation control in the system pop-up window 1002, the electronic device may confirm that the user has granted application C permission to access location information, allowing application C to successfully access the location information and implement navigation based on the accessed location information.

[0151] In the process of using the navigation function of the application C, if the user operates the control provided by the application C for exiting the navigation function, the application C can send operation information of the user operating the control for exiting the navigation function to the navigation service, to inform the navigation service that the user has confirmed to end the navigation function of the application C.

[0152] The navigation service can confirm that the user currently ends the use of the navigation function of the application C according to the received operation information of the user operating the control for exiting the navigation function. At this time, the navigation service can cancel the permission of the application C to access the location service, and notify the location service (or the permission management service) and the upper application C of the cancellation information (indicating that the user has cancelled the permission of the application C to access the location information). In this way, the application C can no longer call the service interface of the location service to realize the call of the underlying location service. Even if the application C wants to continue to call the service interface of the location service, the location service will refuse to respond to the call of the application C because the location service has learned the above-mentioned cancellation information in time.

[0153] Optionally, the navigation service can also display the state prompt window through the state prompt module in response to the operation of the user clicking the confirmation control in the risk prompt window, to interact with the user through the state prompt window controlled by the system, and continuously perceive the use intention of the user for the navigation function of the application C. Figure 10 (b) in FIG. 10B and Figure 10 After the user clicks the confirmation control in the system pop-up window 1002, the application C can enter the navigation interface, and the electronic device can display a system floating window 1003 on the navigation interface to reserve an obvious prompt information in the foreground, prompting the user that the application C is supporting the navigation function (or the application C is accessing the location information). The system floating window 1003 includes an "end" control 1004 for one-click ending of the use of the navigation function of the application C, which is equivalent to one-click ending of the authorization of the application C to access the location information under the current navigation function. Therefore, the user can one-click cancel the authorization of the application C to access the location information through the control provided by the application for exiting the navigation function or through the state prompt window, which can prevent the application C from continuing to access the location information after the navigation function ends.

[0154] In this way, it is realized that when the user clicks the control for entering the navigation function of the application C, the application C can obtain the permission to access the location service related to the navigation function. When the user clicks the control for exiting the navigation function of the application C, even if the user is still using the application C, such as browsing the pictures of the destination, the application C cannot obtain the permission to access the location service related to the navigation function. Therefore, the user's authorization operation on various permissions of the application is reduced, and the smoothness of the user experience is increased.

[0155] Based on the above software module, the embodiment of the present application provides another system flow diagram of a permission control method. Different from the above flow diagram, the state prompt module can be decoupled from the scenario module, and the state prompt module can keep communication with the system basic service to continuously perceive the calling state of the system basic service and the authorization state of the user to the application calling the system basic service.

[0156] As another example embodiment, taking an application A providing voice call function as an example, as shown in the following figure, when the user uses the voice call function of the application A, such as clicking the "voice call" control provided by the application A to start the voice call function, the application A needs to call the service interface of the voice call service first to realize the calling of the lower voice call service. The voice call service has the management control permission of the microphone service in the use scenario of the voice call function. Figure 11

[0157] Similarly, in response to the calling of the application A, the voice call service can determine that the user currently determines to use the voice call function of the application A. Referring to the flow diagram of the above embodiment. At this time, the voice call service can grant the application A the permission to access the microphone, and notify the authorized information (indicating that the user has granted the application A the permission to access the microphone) to the microphone service and the upper application A. In this way, the application A can successfully realize the calling of the lower microphone service by calling the service interface of the microphone service. The video call service can keep communication with the microphone service to timely deliver the information of whether the user grants the application A the permission to access the microphone service to the microphone service.

[0158] After the voice call service determines that the user currently determines to use the voice call function of the application A, the voice call service can instruct the state prompt module to realize the display of the state prompt window. The state prompt window can include state prompt content and an end control. The state prompt content is used to indicate that the application A is supporting the voice call function, and / or is used to indicate that the application A is using the microphone. The end control is used to end the voice call function of the application A.

[0159] Optionally, the voice call service can send the prompt information related to the voice call scenario, such as the function use scenario-voice call function, the application identifier-application A, the related system basic service-microphone service, the existing risk, etc., to the state prompt module, so that the state prompt module can realize the display of the state prompt information corresponding to the current function use scenario in the state prompt window.

[0160] ​Optionally, the voice call service can also notify the authorized information to the status prompt module or the permission management service, and the status prompt module or the permission management service can notify the authorized information to the microphone service. The status prompt module or the permission management service can keep communication with the microphone service to timely transmit the information of whether the user grants the microphone service permission to the application A to the microphone service.

[0161] Optionally, the microphone service can report the information that the microphone service is called by the application A to the status prompt module in response to the call of the application A. The status prompt module can display a status prompt window to prompt the user that the application A is using the microphone after receiving the reported information.

[0162] Optionally, the status prompt window can also include an end control. The end control can be used to end the voice call function of the application A, and the end control can also be used to end (cancel) the permission of the application A to access the microphone.

[0163] As one way, when the status prompt module detects that the user clicks the end control in the status prompt window, the status prompt module can send the operation information of the user operating the end control to the voice call service to notify the voice call service that the user has determined to end using the voice call function. The voice call service can cancel the permission of the application A to access the microphone, and notify the microphone service or the permission management service and the upper application A of the information of canceling the authorization (indicating that the user has canceled the permission of the application A to access the microphone). The application A cannot realize the call of the underlying microphone service and the camera service through the service interface of the microphone service.

[0164] As another way, when the status prompt module detects that the user clicks the end control in the status prompt window, the status prompt module can cancel the permission of the application A to access the microphone, and notify the microphone service and the voice call service of the information of canceling the authorization. The voice call service can further notify the upper application A. The application A cannot realize the call of the underlying microphone service and the camera service through the service interface of the microphone service. Optionally, the voice call service or the status prompt module can also notify the permission management service of the information of canceling the authorization, and the permission management service can notify the microphone service of the authorized information.

[0165] Even if the application A wants to continue to call the service interface of the microphone service, the microphone service will refuse to respond to the call of the application A because the microphone service has learned that the application A does not have the permission to access the microphone.

[0166] In some scenarios, the user uses the voice call function of the application A, and the application A can not call the service interface of the voice call service, but follow the procedure in the related art, such as Figure 1As shown in the flow, directly calling the service interface of the microphone, when the application A has no permission to access the microphone, the application A can request user authorization by calling the authorization interface of the permission management service. When the user grants the permission for a certain time length, the application A can successfully call the microphone service by itself within the time length.

[0167] In the embodiment, when the application A maliciously and secretly calls the service interface of the microphone service within the time length, although the microphone service queries that the application A has the permission through the permission management service, the microphone service can still report the information that the microphone is called by the application A to the state prompt module. The application A can display a state prompt window to prompt the user that the application A is using the microphone after receiving the reported information. The state prompt window includes an end control for one-key rejecting the call of the microphone service by the application A. In this way, even if the application A maliciously calls the microphone service, the user can be informed in time, and the user can directly end the malicious call of the microphone service by the application A through the end control of the state prompt window, thereby protecting the security of the user's private information.

[0168] Alternatively, the end control can also be used to one-key end (cancel) the permission of the application A to access the microphone. Through the state prompt window, the user can be informed in time that the application A maliciously calls the microphone service, and the user can directly cancel the permission of the application A to access the microphone through the end control of the state prompt window. At this time, the state prompt module can also notify the permission management service of the information that the authorization is cancelled (indicating that the user has cancelled the permission of the application A to access the microphone). The permission management service can update the original permission of the application A to access the microphone and the authorization time length to no permission to access the microphone. In this way, the application A cannot maliciously call the microphone service.

[0169] Next, a permission control method provided by an embodiment of the present application will be described in detail with reference to the accompanying drawings, which is applied to the electronic device described above. As shown in the figure, Figure 12 The method can include:

[0170] S1210, the electronic device detects a use operation of a user for a first function of a first application, and the running of the first function needs the support of a first system service.

[0171] In the embodiment of the present application, the first application is an application installed on the electronic device, which can be a native application (also called a system application) or a third-party application. For example, the first application can be one of the application A, the application B and the application C. The first application can provide at least one function, such as the video call function and the scan function of the application A, and the screen sharing function and the remote control function of the application B. The function provided by the first application can be selectively used by the user according to the demand.

[0172] Some functions of the first application need to be supported by at least one system service of the electronic device. That is, the first application needs to call at least one system service to implement the functions to be provided. For example, the application A needs to call the camera service to implement the scan function of the application A.

[0173] In the embodiments of the present application, the system service can be a service obtained by abstracting and encapsulating one or more functions / capabilities of the electronic device, which can be provided to the application. The system service can be a hardware service obtained by abstracting and encapsulating the hardware capabilities of the electronic device or the externally plugged hardware capabilities, or a software service obtained by abstracting and encapsulating the software functions of the electronic device or the externally plugged software functions.

[0174] Optionally, when a single function / capability of the electronic device is abstracted and encapsulated into a system service, the system service is also referred to as a system basic service. For example, the system service can be the microphone service, the camera service, the keyboard and mouse injection service, and the like.

[0175] Since the calling of some system services involves the user's private information, such as the calling of the camera service obtaining the image information of the user, the electronic device performs permission management on the calling operation of the system service involving the user's private information. That is, the first application can only be allowed to call the system service by the electronic device when the first application has the permission to call the system service. At present, the user usually grants the first application the permission to call the system service for a certain time length, but the user cannot know and control the calling of the system service by the first application during the authorization period. This may cause the first application to call the system service without the user's awareness, thereby causing the risk of leakage of the user's private information and affecting the user experience.

[0176] To solve the problem, the present application associates the user's authorization of the first application to call a certain system service with the use scenario of a certain function of the first application. When the user uses the function of the first application, the electronic device can grant the first application the permission to call the system service related to the function. When the user stops using the function of the first application, the electronic device can cancel the permission granted to the first application to call the system service related to the function. In this way, the time period during which the first application has the permission of the corresponding system service, i.e., the authorization time length, is limited to the use scenario of a certain function of the first application. In the scenario where the function is not used, the first application does not have the permission of the corresponding system service. Thus, the situation that the first application still calls the corresponding system service after the user ends using a certain function is avoided, and the safety of the user's private information is ensured.

[0177] The following will take at least one function provided by the first application, including the first function, as an example to specifically introduce the permission control method provided by this application.

[0178] Among them, the first function is related to the first system service of the electronic device. The relevance here means that the implementation of the first function of the first application requires the support of the first system service of the electronic device, that is, the first application needs to call the first system service to implement the first function. The first system service can be any of the various system services mentioned above. Optionally, the first system service can also be a service among the various system services mentioned above that has security risks, or privacy leakage risks, or requires user authorization, such as microphone service, camera service, keyboard and mouse injection service, etc.

[0179] In an embodiment of the present application, the electronic device may grant the first application the permission to call the first system service during the operation of the first function (also referred to as the use period), that is, the electronic device allows the first application to call the first system service during the operation of the first function. The operation period refers to a continuous period from the start of operation (also referred to as the start of use) to the stop of operation (also referred to as the stop of use) of the first function of the first application. In other words, after the first function of the first application stops running, the electronic device can revoke the permission granted to the first application to call the first system service.

[0180] The start of the first function of the first application may be triggered by the user, automatically by the first application, or in association with other applications.

[0181] In some embodiments, when the user intends to use the first function of the first application, the user can trigger the start of the first function of the first application by inputting a use operation (also referred to as a start operation) for the first function of the first application.

[0182] Among them, the user's operation for using the first function of the first application can be a touch operation (such as clicking the corresponding control) input by the user to turn on / switch to the first function of the first application, a voice command, a preset gesture (touch gesture or floating gesture), or a physical button operation, etc.

[0183] As an example, when the first function of the first application is the navigation function of application C, such as Figure 10 As shown in (a) of Figure 1, when a user searches for a destination on the homepage of Application C, Application C may provide a "Navigation" control 1001 for accessing the navigation function, thereby providing the user with navigation to the destination. In this case, the user's input operation for using the navigation function of Application C may be a click operation on "Navigation" control 1001.

[0184] In some scenarios, if the user has been using other functions provided by the first application, such as a second function, the user intends to use the first function of the first application at this time, which can be intended to use the first function and the second function of the first application simultaneously, or can be intended to stop using the second function of the first application to switch to use the first function of the first application.

[0185] As an example, the first function and the second function of the first application are the remote control function and the screen sharing function of the application B, as shown in (a) of FIG. 13A, the application B can also provide a "remote control" control 1301 for entering the remote control function in the process of supporting the screen sharing function to meet the user's demand for using the remote control function and the screen sharing function of the application B simultaneously. In this case, the use operation of the remote control function of the application B input by the user can be a click operation on the "remote control" control 1301. Figure 13

[0186] As another example, the first function and the second function of the first application are the voice call function and the video call function of the application A, as shown in (a) of FIG. 14A, the application A can also provide a "turn to voice" control 1401 for switching to the voice call function in the process of supporting the video call function to meet the user's demand for quickly switching from using the video call function of the application A to using the voice call function of the application A. In this case, the use operation of the voice call function of the application A input by the user can be a click operation on the "turn to voice" control 1401. Figure 14

[0187] In other embodiments, the first application can also automatically trigger the start of the first function of the first application when a preset condition (for example, a preset time) is reached. In yet other embodiments, the start of the first function of the first application can also be triggered in association with the running of other applications. The embodiments of the present application do not limit the manner of triggering the start of the first function of the first application.

[0188] S1220, the electronic device uses the first function of the first application in response to the use operation, and grants the first application the permission to call the first system service.

[0189] In the embodiments of the present application, when the electronic device detects the use operation of the first function of the first application input by the user, it can be considered that the user intends to use the first function of the first application. At this time, the electronic device can start running the first function of the first application in response to the use operation, and can grant the first application the permission to call the first system service, so that the first application can successfully call the first system service to support the normal running of the first function of the first application.

[0190] ​​In other words, when a user intends to use the first function of a first application, the device considers that the user has granted the first application permission to call the first system service related to the first function. Therefore, upon confirming that the user intends to use the first function of the first application, the electronic device can directly grant the first application permission to call the first system service related to the first function.

[0191] It can be understood that when a user grants the first application permission to call the first system service, it usually acts on the operation scenario (which can also be understood as the usage scenario) of a certain function provided by the first application, such as the operation scenario of the first function (which can also be understood as the scenario where the user is currently using the first function). Outside of this scenario, the first application should not have permission to call the first system service. Therefore, in the permission control method provided by the present application, when the electronic device confirms that the user intends to use the first function of the first application, the electronic device may grant the first application permission to call the first system service that is valid during the operation of the first function, that is, the first application has the permission to call the first system service during the operation of the first function.

[0192] As an example, Figure 10 As shown in (a), when the electronic device detects that the user clicks the "Navigation" control 1001 provided by application C, it can confirm that the user intends to use the navigation function of application C. At this time, the electronic device can respond to the click operation and start running the navigation function of application C. During the operation of the navigation function of application C, the electronic device grants application C the permission to call system services related to the navigation function, such as the permission to call location services, so that application C can successfully call related system services to support the normal operation of the navigation function. Optionally, when the navigation function of application C is operating normally, the electronic device can display the following Figure 10 The navigation interface shown in (c) in FIG.

[0193] It is understandable that before the user intends to use the first function of the first application, if the user is already using other functions provided by the first application, such as the second function, then similarly, the electronic device can grant the first application the permission to call the second system service effectively during the operation of the second function, that is, the first application has the permission to call the second system service during the operation of the second function. Among them, the second function is related to the second system service, that is, the implementation of the second function of the first application requires the support of the second system service of the electronic device. Optionally, the second system service can be the same as or different from the first system service.

[0194] In some scenarios, if a user has previously used a second function provided by a first application and now intends to use the first function of the first application simultaneously with the second function, the electronic device will not revoke the permission previously granted to the first application to call the second system service, because the user has not stopped using the second function of the first application. In addition, the electronic device may grant the first application permission to call the first system service while the first function is running. In this case, the first application has the permission to call system services related to both the first and second functions.

[0195] As an example, in the process of application B supporting the screen sharing function, such as Figure 13 As shown in (a), when the electronic device detects that the user clicks on the "remote control" control 1301 provided by application B, it can confirm that the user intends to use the remote control function of application B. At this time, the electronic device can respond to the click operation and start running the remote control function of application B while running the screen sharing function of application B. During the operation of the remote control function of application B, the electronic device grants application B the permission to call system services related to the remote control function, such as the permission to call the keyboard and mouse injection service. This enables application B to successfully call related system services to support the normal operation of the remote control function. Optionally, when the remote control function of application B is operating normally, the electronic device may display something like Figure 13 The remote control interface shown in (d) in FIG.

[0196] It is understandable that since the user has not stopped using the screen sharing function of application B, the electronic device will not revoke the permission previously granted to application B to call system services related to the screen sharing function, such as the permission to call the screen recording service. In other words, application B currently has the permission to call the keyboard and mouse injection service and the screen recording service.

[0197] In other scenarios, if a user has previously used a second function provided by a first application and now intends to stop using the second function of the first application and switch to using the first function of the first application, the electronic device may grant the first application the permission to call the first system service while the first function is running, and the electronic device will revoke the permission previously granted to the first application to call the second system service because the second function of the first application has stopped running. In this case, the first application only has the permission to call the system service related to the first function.

[0198] As an example, in the process of application A supporting the video call function, such as Figure 14As shown in (a) of FIG. 13, when the electronic device detects a click operation of the "convert to voice" control 1301 provided by the application A, it can be confirmed that the user intends to switch from using the video call function of the application A to using the voice call function of the application A. At this time, the electronic device can switch the video call function of the running application A to the voice call function of the running application A in response to the click operation, and during the running of the voice call function of the application A, the electronic device grants the application A the permission to call the system service related to the voice call function, such as the permission to call the microphone service. So that the application A can successfully call the related system service to support the normal running of the voice call function. Alternatively, when the application A switches from supporting the video call function to supporting the voice call function, the electronic device can switch from displaying the video interface as shown in (a) of FIG. 13 to displaying the voice interface as shown in (b) of FIG. 13. Figure 14 Figure 14

[0199] It can be understood that since the user has stopped using the video call function of the application A, the electronic device will withdraw the permission previously granted to the application A to call the system service related to the video call function, such as the permission to call the camera service.

[0200] Alternatively, when the second system service is the same as the first system service, that is, the implementation of the first function and the second function requires calling the same system service, the electronic device can not have to recover the permission previously granted to the application A to call the same system service. For example, the implementation of the video call function and the voice call function both require calling the microphone service, so when the application A switches from supporting the video call function to supporting the voice call function, the electronic device does not have to recover the permission previously granted to the application A to call the microphone service, but will recover the permission previously granted to the application A to call the camera service. This is because the implementation of the voice call function does not require the support of the camera service. That is, the application A no longer has the permission to call the camera service, but still has the permission to call the microphone service.

[0201] S1230, the electronic device detects the stop of the first function of the first application.

[0202] In the embodiments of the present application, after the first function of the first application stops running, the electronic device can recover the permission granted to the first application to call the first system service. Wherein, the stop of the first function of the first application can be triggered by the user, can also be automatically triggered by the first application, and can also be triggered by other applications.

[0203] In some embodiments, the user can trigger the stop of the first function of the first application by inputting a stop use operation for the first function of the first application.

[0204] ​​The user's operation to stop using the first function of the first application may be a touch operation (such as clicking a corresponding control), a voice command, a preset gesture (a touch gesture or a hover gesture), or a physical button operation input by the user to stop (end) the first function of the first application. The stop may be a complete stop or a temporary stop.

[0205] As an example, Figure 10 As shown in (c) of FIG, while the user is using the navigation function of application C, application C may display an "Exit Navigation" control 1005 for exiting the navigation function. The user input for stopping the navigation function of application C may be a click operation on the "Exit Navigation" control 1005.

[0206] In some scenarios, if the current user is using the first function of the first application while also using other functions of the first application, such as the second function, the user's intention to stop using the first function of the first application at this time may be to stop using the first function and the second function of the first application at the same time, such as the user directly closing the operation of the first application, which can end the operation of all functions of the first application with one click; or the user's intention may be to only stop using the first function of the first application, but continue to use the second function of the first application.

[0207] As an example, Figure 14 As shown in (b), when the user is using the voice call function of application A, the user slides up at the bottom of the screen to enter the Figure 14 The application management interface shown in (c) of FIG. 1 is used to display all activated applications. This application management interface may display a delete control 1403 for closing any or all applications. The user input operation to stop using the voice call function of application A may be to drag the window of application A toward the delete control 1403 to directly close the operation of application A. In this case, it is equivalent to ending the operation of all functions of application A with a single click.

[0208] As another example, Figure 13 As shown in (e), while application B supports both screen sharing and remote control functions, it can also provide an "end" control 1305 for ending the remote control function, to satisfy the user's need to stop using only the remote control function of application B. In this case, the user input to stop using the remote control function of application B can be a click operation on the "end" control 1305.

[0209] In some scenarios, if the current user intends to use another function of the first application, such as a second function, the user at this time intends to stop using the first function of the first application, which can be that the user intends to switch from using the first function of the first application to using the second function of the first application.

[0210] As an example, the first function and the second function of the first application are a video call function and a voice call function of an application A, and as shown in (a) of FIG. 14, the application A provides a "switch to voice" control 1401 for switching to the voice call function during the process of supporting the video call function, to meet the user's demand for quickly switching from using the video call function of the application A to using the voice call function of the application A. In this case, the stop using operation of the user input for the video call function of the application A can be a click operation on the "switch to voice" control 1401. Figure 14

[0211] In other embodiments, the first application can also automatically trigger the end of the running of the first function of the first application when a preset condition (for example, a preset time) is reached. In yet other embodiments, the end of the running of the first function of the first application can also be triggered in the process of running another application. The embodiments of the present application do not limit the manner of triggering the end of the running of the first function of the first application.

[0212] S1240, in response to the stop using of the first function of the first application, the electronic device cancels the granted permission of the first application to call the first system service.

[0213] In some embodiments, when the electronic device detects the above-mentioned user input stop using operation of the first function of the first application, it can be considered that the user intends to stop using the first function of the first application. At this time, the electronic device can stop running the first function of the first application in response to the above-mentioned stop using operation, and can cancel the granted permission of the first application to call the first system service, so that the first application can no longer successfully call the first system service, effectively avoiding the first application from calling the first system service without the user's awareness, and ensuring the security of the user's private information.

[0214] That is, when the user intends to stop using the first function of the first application, in the view of the device, it is equivalent to that the user has canceled the granted permission of the first application to call the first system service related to the first function. Therefore, when the electronic device confirms that the user intends to stop using the first function of the first application, it can directly revoke the previously granted permission of the first application to call the first system service related to the first function. That is, when the first function of the first application stops running, the first application no longer has the permission to call the first system service.

[0215] As an example, as shown in (a) of FIG. 14, the application A provides a "switch to voice" control 1401 for switching to the voice call function during the process of supporting the video call function, to meet the user's demand for quickly switching from using the video call function of the application A to using the voice call function of the application A. In this case, the stop using operation of the user input for the video call function of the application A can be a click operation on the "switch to voice" control 1401. Figure 10 ​As shown in (c) of FIG, when the electronic device detects that the user clicks the "Exit Navigation" control 1005 provided by application C, it can confirm that the user intends to stop using the navigation function of application C. In response to the click operation, the electronic device can stop running the navigation function of application C and revoke the permission granted to application C to call system services related to the navigation function, such as the permission to call location services, so that application C can no longer successfully call related system services.

[0216] In some scenarios, when a user is using the first function of a first application while also using other functions of the first application, such as the second function, and the user intends to stop using only the first function of the first application, the electronic device may only revoke the permission previously granted to the first application to call the first system service, and will not revoke the permission previously granted to the first application to call the second system service, because the second function of the first application is still running. In this case, the first application only has the permission to call the system service related to the second function.

[0217] As an example, in the process of application B supporting both screen sharing function and remote control function, such as Figure 13 As shown in (e), when the electronic device detects that the user clicks the "End" control 1305 provided by Application B, it can confirm that the user intends to stop using the remote control function of Application B. At this time, the electronic device can respond to the click operation, stop running the remote control function of Application B, and revoke the permission granted to Application B to call system services related to the remote control function, such as the permission to call the keyboard and mouse injection service, so that Application B can no longer successfully call the relevant system services. Even if the user is still using the screen sharing function of Application B, Application A no longer has the permission to call the keyboard and mouse injection service.

[0218] It is understandable that since the user has not stopped using the screen sharing function of application B, the electronic device will not revoke the permission previously granted to application B to call system services related to the screen sharing function, such as the permission to call the screen recording service. In other words, application B currently only has the permission to call the screen recording service and no longer has the permission to call the keyboard and mouse injection service.

[0219] In other scenarios, when a user is using the first function of a first application while also using other functions of the first application, such as the second function, if the user intends to stop using the first function and the second function of the first application at the same time, such as directly closing the operation of the first application, the user can end the operation of all functions of the first application with one click, and the electronic device can revoke the permission previously granted to the first application to call the first system service and the second system service.

[0220] As an example, in the process of application A supporting the voice call function, such as Figure 14As shown in (b) of the figure, the user slides up from the bottom of the screen to enter the Figure 14 When the application management interface for displaying all started applications is shown in (c), the electronic device detects that the user performs a drag operation on the window of application A toward the delete control 1403, and can confirm the user's intention. Figure 1 The electronic device can then respond to the drag operation by closing Application A and revoking all permissions previously granted to Application A to call related system services, such as the permission previously granted to the microphone service related to the voice call function. This prevents Application A from successfully calling related system services.

[0221] It can be understood that since the user has stopped using application A, it is equivalent to stopping all functions of application A with one click. Therefore, the electronic device will revoke all permissions previously granted to application A to call system services.

[0222] In some scenarios, the discontinuation of the first function of the first application may be due to the current user's intention to switch from using the first function of the first application to using another function of the first application, such as the second function. In this case, in response to the switch from the first function of the first application to the second function of the first application, the electronic device may revoke the permission previously granted to the first application to call the first system service.

[0223] As an example, Figure 14 As shown in (a) of FIG, while application A supports the video call function, when the electronic device detects a user clicking on the "Switch to Voice" control 1401 provided by application A, it can confirm that the user intends to quickly switch from using application A's video call function to using application A's voice call function. In response to the switch from application A's video call function to application A's voice call function, the electronic device can revoke all permissions previously granted to application A to call system services related to the video call function, such as the permission to call the camera service.

[0224] Alternatively, since the permission previously granted to Application A to call system services related to the video call function includes the microphone service, which is related to the voice call function that is switched to use, the electronic device does not need to revoke the permission previously granted to Application A to call the microphone service, and only revokes the permissions for system services unrelated to the voice call function.

[0225] That is, since the implementation of the video call function and the voice call function both need to invoke the microphone service, when the application A switches to support the voice call function in the process of supporting the video call function, the electronic device does not have to recover the permission previously granted to the application A to invoke the microphone service, but will recover the permission previously granted to the application A to invoke the camera service. This is because the implementation of the voice call function does not need the support of the camera service. That is, the application A no longer has the permission to invoke the camera service, but still continuously has the permission to invoke the microphone service.

[0226] Optionally, the electronic device can also first recover the permission previously granted to the application A to invoke all system services related to the video call function. Then, the permission is re-granted to the application A to invoke the system services related to the voice call function.

[0227] In some embodiments, the electronic device can detect the stop of use of the first function of the first application during the running of the first application. Thus, during the running of the first application, the electronic device can cancel the permission granted to the first application to invoke the first system service in response to the stop of use of the first function of the first application. Thus, even if the first application is still running, the first application no longer has the permission to invoke the first system service related to the first function.

[0228] In one scenario, the running of the first application described above can be the process in which the first application runs in the foreground. Thus, during the use of the first application in the foreground, when the user stops using the first function of the first application, the electronic device can cancel the permission granted to the first application to invoke the first system service related to the first function. Even if the user is still using the first application in the foreground at this time, the first application no longer has the permission to the first system service related to the first function.

[0229] In another scenario, the running of the first application described above can also be the process in which the first application runs in the background. Thus, during the use of the first application in the background, when the user stops using the first function of the first application, the electronic device can cancel the permission granted to the first application to invoke the first system service related to the first function.

[0230] Optionally, during the use of the first function of the first application in the foreground, when the user switches the first application running in the foreground to the background, it can be considered that the user intends to stop using the first function of the first application, and at this time the electronic device can cancel the permission granted to the first application to invoke the first system service related to the first function.

[0231] For example, when an electronic device is using the recording function of application E in the foreground, if the user switches application E to the background, the electronic device can stop using the recording function of application E and revoke the permission previously granted to application E to call system services related to the recording function, such as revoking the permission for the camera service.

[0232] Optionally, if the user switches the first application running in the background back to the foreground, it can also be considered that the user intends to continue using the first function of the first application. At this time, the electronic device can continue to grant the first application permission to call the first system service related to the first function.

[0233] In one scenario, when the first function of the first application is used in the foreground, in order to avoid obstruction caused by the related interface of the first function, the user switches the first application running in the foreground to run in the background. This can be considered that the user intends to continue using the first function of the first application in the background. Since the first function has not stopped being used, the electronic device does not need to revoke the permission previously granted to the first application to call the first system service related to the first function. Thereafter, when the user intends to stop using the first function of the first application in the background, the electronic device can cancel the permission granted to the first application to call the first system service in response to the cessation of the use of the first function of the first application.

[0234] For example, if an electronic device is using the navigation function of application C in the foreground and the user switches application C to the background, the electronic device can continue to use the navigation function of application C in the background while displaying the desktop interface in the foreground. At this point, since application C's navigation function has not been deactivated, the electronic device does not need to revoke the permissions previously granted to application C to access system services related to the navigation function, such as location services.

[0235] Optionally, when the electronic device is using the navigation function of application C in the background, it may retain a status prompt window 1003 displayed in the foreground. This status prompt window 1003 includes an "end" control 1004 for stopping the use of the navigation function of application C with one click. When the user intends to stop using the navigation function of application C, they can click the "end" control 1004. At this time, in response to the click operation, the electronic device stops using the navigation function of application C and revokes the permission previously granted to application C to call system services related to the navigation function, such as the permission to use location services.

[0236] The permission control method provided in the embodiments of the present application associates the authorization of the user to the first application to call a certain system service with the use scenario of a certain function of the first application. When the user uses the function of the first application, the electronic device can grant the first application the permission to call the system service related to the function. When the user stops using the function of the first application, the electronic device can cancel the permission granted to the first application to call the system service related to the function. Thus, the application can obtain the permission to call the system service related to the function only when the user uses the function provided by the application. When the user no longer uses the function provided by the application, even if the user still uses the application, the application does not have the permission to call the system service related to the function. Thus, the first application cannot call the corresponding system service after the user stops using the function, and the security of the user's private information is ensured.

[0237] Please refer to Figure 15 , Figure 15 Another permission control method provided in the embodiments of the present application is shown, which is applied to the electronic device described above. Unlike the method described above, the electronic device provides a corresponding interface to interact with the user through the system to ensure the use intention of the user to a certain function of the application. As shown in Figure 15 , the method can include:

[0238] S1510, the electronic device detects the use operation of the user to the first function of the first application.

[0239] In some embodiments, the electronic device can display a first interface. The first interface is an interface that can start the first function of the first application, which can be an application interface of the first application, a desktop, or other interfaces that can quickly start the first function of the first application, such as a control center interface, which is not limited in the present application.

[0240] The first interface can include one or more function controls, which are used to trigger the start of a certain function in the application. When the first interface displays a plurality of function controls, the plurality of function controls can be used to trigger the start of different functions. The different functions can be functions of the same application or functions of different applications. In some scenarios, the function control can also be referred to as a card or a module, etc., which is not limited in the embodiments of the present application.

[0241] The following will take the function control in the first interface as an example, which includes a first control used to trigger the start of the first function of the first application, to specifically introduce the permission control method provided in the present application.

[0242] The first function usage operation (also referred to as an opening operation) of the user for the first application can be a touch operation, a voice operation, a hovering gesture operation, a physical key operation, or the like input by the user for the first control on the first interface. When the electronic device detects the opening operation of the user for the first function of the first application, it can be considered that the user intends to use the first function of the first application.

[0243] As an example, the first interface is an address search interface of an application C shown in (a) of FIG. 10, and the first control is a "navigation" control 1001 provided by the application C in the address search interface. When the electronic device detects an operation of the user clicking the "navigation" control 1001, it can be considered that the user intends to use the navigation function of the application C. Figure 10

[0244] As another example, the first interface is a screen sharing interface shown in (a) of FIG. 13, and the first control is a "remote control" control 1301 provided by the application B. When the electronic device detects an operation of the user clicking the "remote control" control 1301, it can be considered that the user intends to use the navigation function of the application C on the basis of using the screen sharing function of the application B. Figure 13

[0245] As yet another example, the first interface is a video interface shown in (a) of FIG. 14, and the first control is a "convert to voice" control 1401 provided by the application A. When the electronic device detects an operation of the user clicking the "convert to voice" control 1401, it can be considered that the user intends to quickly switch from using the video call function of the application A to using the voice call function of the application A. Figure 14

[0246] S1520, the electronic device displays a first system prompt in response to the usage operation, the first system prompt being used to indicate a risk existing when the first function is used, and the first system prompt including a confirmation control.

[0247] When the user inputs the opening operation for the first function of the first application, that is, when the user intends to use the first function of the first application, the electronic device can display the first system prompt in response to the opening operation to prompt the user about the risk that can exist when the first function is opened.

[0248] ​​​The first system prompt may also provide a confirmation control and a cancel control. The confirmation control is used to ensure that the user still decides to use the first function of the first application after understanding the risk warning content, and the cancel control is used to ensure that the user can give up using the first function of the first application after understanding the risk warning content. Thus, the electronic device can interact with the user through the first system prompt controlled by the system to clearly obtain the current user's intention to use the function, which is equivalent to clearly obtaining the current user's authorization for the first application to use the system service related to the first function, thereby preventing the first application from deceiving the electronic device that it has obtained the user's authorization.

[0249] It should be noted that the first system prompt displayed in the embodiment of this application is a system-level prompt defined and controlled by the operating system of the electronic device. It is not an application-level prompt defined and controlled by the application and is not subject to application control. This can prevent the first application from maliciously circumventing the risk prompt, thereby preventing the user from being aware of the risks caused by enabling the first function of the first application.

[0250] Optionally, when the first application provides an application-level prompt similar to the first system prompt, such as the first application prompt, when the first application triggers the electronic device to display the first application prompt, the electronic device may hide the first system prompt to avoid excessive risk prompts affecting the user interaction experience.

[0251] Optionally, the first system prompt may include risk warning content regarding the use of the first function.

[0252] As an example, in the case where the user intends to use the navigation function of application C, in response to the user's Figure 10 By clicking the "Navigation" control 1001 shown in (a), the electronic device can display Figure 10 The risk warning window 1002 shown in (b) can show the user the risks of using the navigation function, such as "After turning on navigation, application C can access your location information", as well as "Confirm" and "Cancel" controls.

[0253] As another example, in the case where the user intends to use the remote control function of application B, in response to the user's Figure 13 By clicking the "remote control" control 1301 shown in (a), the electronic device can display Figure 13 In response to the user's selection operation on the participant 22 in the selection window 1302, the electronic device may display Figure 13The risk prompt window 1303 shown in (c) in FIG. 13B can show the user that there is a risk of using the remote control function, such as "After agreeing to remote control, the participant 22 can remotely control your device", and a "Confirm" control and a "Cancel" control.

[0254] Optionally, the first system prompt can also include risk prompt content about the first application using the related system service. For example, in the case where the user intends to use the video call function of the application A, the first system prompt displayed by the electronic device can be "Whether to allow the application A to access the microphone and camera of the electronic device, which can obtain your image and audio information at any time".

[0255] As one way, the first system prompt can be displayed in the form of a pop-up window, which can show complete risk prompt content or be folded to display partial information. When the user clicks on the folded partial information, the electronic device can unfold and display the complete risk prompt content.

[0256] As another way, the first system prompt can also be displayed in the form of a warning icon in the status bar. When the user clicks on the warning icon, the electronic device can display a risk prompt window to completely or partially display the corresponding risk prompt content. Optionally, the risk prompt content in the first system prompt can also be displayed by jumping to a specified page through a link, which is used to display the complete risk prompt content.

[0257] Optionally, the first system prompt can provide a check box for no longer prompting, so that the user can choose not to display it next time. In this way, when the user can easily associate the relationship between the first function and the first system service, such as the video call must use the microphone and camera, or when the user actively triggers the use of the first function of the first application, the user can choose not to display it next time, improving the user interaction experience.

[0258] In some scenarios, before the user intends to use the first function of the first application, if the user is already using other functions provided by the first application, such as a second function, then similarly, the electronic device can display the first system prompt in the use scenario of the current second function in response to the user's opening operation for the second function of the first application. The first system prompt is used to indicate the risk existing when the first function is started.

[0259] The first system prompt in the use scenario of the second function can also include a confirmation control and a cancel control. The confirmation control is used to ensure that the user still determines to use the first function of the first application after understanding the risk prompt content, and the cancel control is used to ensure that the user can give up using the first function of the first application after understanding the risk prompt content.

[0260] Optionally, in the case that the first function and the second function need to invoke the same system service for normal operation, if the user intends to use the first function of the first application, since the risk prompt content of the same system service has been previously displayed to the user through the first system prompt in the use scenario of the second function, the electronic device can no longer display the first system prompt in the use scenario of the first function, or can no longer display the risk prompt content of the same system service through the first system prompt in the use scenario of the first function.

[0261] As an example, when the user intends to use the video call function of the application A, the electronic device can display the related risk prompt content, such as "whether to allow the application A to access the microphone and camera of the electronic device, which may obtain your image and audio information at any time", when the user still intends to use the video call function of the application A after understanding the risk prompt content, the electronic device can start running the video call function and display the video interface shown in (a) of FIG. 14. Figure 14 Thereafter, when the user intends to switch to use the voice call function of the application A, since the voice call function still needs to use the microphone of the electronic device, and the user has previously understood the risk prompt content of the application A using the microphone, the related risk prompt content can no longer be displayed. The electronic device can directly respond to the click operation of the user on the "switch to voice" control 1401, and the electronic device starts running the voice call function of the application A and displays the voice interface shown in (b) of FIG. 14. Figure 14

[0262] In some scenarios, in order to implement the first function, the first application will request to invoke the first system service related to the first function to support the normal operation of the first function. Since the first system service has a security / privacy risk, the electronic device can control the invocation of the first system service by the first application through the permission control method provided by the embodiments of the present application, to ensure that the invocation is under the explicit authorization of the user, and the user can revoke the authorization at any time.

[0263] Optionally, when the electronic device detects the request of the first application to invoke the first system service related to the first function, the electronic device can instruct the first application to first invoke the first scenario service related to the first function. The first scenario service is used to provide an interface for interacting with the user, to explicitly perceive the use state of the first function of the first application by the user through the interaction result of the user and the interface, which is equivalent to explicitly obtaining the authorization of the current user to the first application to invoke the first system service related to the first function.

[0264] ​That is, in response to the user's activation of the first function of the first application, the first application of the electronic device may initiate a request to invoke the first scenario-based service corresponding to the first function. In response to the invocation request of the first application, the first scenario-based service of the electronic device may trigger the electronic device to display a first system prompt. The first scenario-based service may then determine whether to grant the first application permission to invoke the first system service related to the first function based on the user's interaction with the first system prompt.

[0265] Optionally, when the first application provides a first application prompt similar to the first system prompt, when the first application triggers the electronic device to display the first application prompt, the first application may also send the result of the user's interaction with the first application prompt to the first scenario-based service. The first scenario-based service may then determine whether to grant the first application permission to call the first system service related to the first function based on the interaction result.

[0266] Optionally, when providing corresponding system functions / capabilities, the first system service can communicate with the first scenario-based service to perceive the user's authorization status for the first application to call the first system service related to the first function, and determine whether to agree to the call of the first application based on the authorization status.

[0267] In some scenarios, the first scenario service may also send information on whether the first application is granted permission to call the first system service related to the first function to the permission management service, so that when the first system service provides the corresponding system function / capability, it can communicate with the permission management service to perceive the user's authorization status for the first application to call the first system service related to the first function, and determine whether to agree to the call of the first application based on the authorization status.

[0268] S1530: The electronic device detects a user triggering operation on a confirmation control in the first system prompt.

[0269] If the user still decides to use the first function of the first application after understanding the risk warning, the user can input a trigger operation for the confirmation control in the first system prompt. The trigger operation can be a touch operation, voice operation, floating gesture operation, physical button operation, etc.

[0270] As an example, Figure 10 As shown in (b) in FIG, when the user understands the risks of using the navigation function of application C and still determines to use the navigation function of application C, the user can click the “Confirm” control in the risk warning window 1002 .

[0271] As another example, Figure 13As shown in (c) of FIG. 13, when the user determines to use the remote control function of application B after learning the risk of using the remote control function of application B, the user can click the "Confirm" control in the risk prompt window 1303.

[0272] Optionally, when the first system prompt is displayed in the form of a pre-warning icon in the status bar, in response to the user clicking the pre-warning icon, the electronic device can expand and display the first system prompt. The expanded and displayed first system prompt includes a confirmation control and a cancellation control. Thus, the user can input a trigger operation for the confirmation control in the first system prompt.

[0273] In some embodiments, when the user intends to give up using the first function of the first application after learning the risk prompt content, the user can input a trigger operation for the cancellation control in the first system prompt. The trigger operation can be a touch operation, a voice operation, a hovering gesture operation, a physical key operation, etc. At this time, the electronic device can consider that the user has given up granting the first application the permission to call the first system service related to the first function.

[0274] Optionally, after the first scenario-based service corresponding to the first function instructs the electronic device to display the first system prompt, if it is detected that the user inputs a trigger operation for the cancellation control in the first system prompt, it can be confirmed that the user currently does not have the intention to use the first function of the first application, and thus the first application can not be granted the permission to call the first system service related to the first function.

[0275] As an example, as shown in (b) of FIG. 10, when the user intends to give up determining to use the navigation function of application C after learning the risk of using the navigation function of application C, the user can click the "Cancel" control in the risk prompt window 1002. At this time, the electronic device can not grant application C the permission to call the location service. Thus, application C cannot call the location service by itself to obtain the location information of the user. Figure 10

[0276] S1540, in response to the trigger operation for the confirmation control in the first system prompt, the electronic device grants the first application the permission to call the first system service, and uses the first function of the first application and displays a second system prompt containing a stop control.

[0277] ​In the embodiments of the present application, when the electronic device detects the triggering operation of the confirmation control in the first system prompt, it can be considered that the user determines to use the first function of the first application after understanding the risk prompt content. Since the normal operation of the first function requires the support of the first system service, it can be considered that the user grants the first application the permission to call the first system service related to the first function. Therefore, the electronic device can directly respond to the triggering operation of the confirmation control in the first system prompt, start running the first function of the first application, and grant the first application the permission to call the first system service.

[0278] Specifically, after the first scenario service corresponding to the first function instructs the electronic device to display the first system prompt, if the triggering operation of the confirmation control in the first system prompt input by the user is detected, the use intention of the user to the first function of the first application at present can be explicitly obtained, that is, the authorization of the user to the first application to call the first system service related to the first function can be explicitly obtained. Then the first scenario service can notify the authorization information to the first system service related to the first function, so that the first system service can respond to the call of the first application. In this way, the first application can call the first system service at any time to realize the first function.

[0279] In some embodiments, when the first system prompt supports the user to select not to be prompted next time, or the user has understood the risk prompt content of the first application using the related system service for a short time, when the electronic device detects the opening operation of the user to the first function of the first application, it can be considered that the user determines to use the first function of the first application after understanding the risk prompt content. Therefore, the electronic device can directly respond to the opening operation of the user to the first function of the first application, start running the first function of the first application, and grant the first application the permission to call the first system service.

[0280] Alternatively, in response to the above opening operation of the user to the first function of the first application, the first application of the electronic device can initiate a request to call the first scenario service corresponding to the first function, and send the operation information of the opening operation of the user to the first function of the first application to the first scenario service. The first scenario service can confirm the use intention of the user to the first function of the first application at present according to the operation information, that is, confirm the authorization of the user to the first application to call the first system service related to the first function. Therefore, the first scenario service can respond to the call request of the first application, notify the authorization information to the first system service related to the first function, so that the first system service can respond to the call of the first application. In this way, the first application can call the first system service at any time to realize the first function.

[0281] In the embodiments of the present application, when the first function of the first application starts running, the electronic device can display a second system prompt to prompt the user about the use state of the first function of the first application or to prompt the user about the calling state of the first application to the first system service.

[0282] Specifically, after the first scenario service corresponding to the first function instructs the electronic device to display the first system prompt, if a triggering operation of the user input to the confirmation control in the first system prompt is detected, it can be determined that the user authorizes the first application to call the first system service related to the first function. Then the first scenario service can instruct the electronic device to display a second system prompt according to the current first function use scenario of the first application.

[0283] The second system prompt displayed in the embodiments of the present application is a system-level prompt defined and controlled by the operating system of the electronic device, which is not an application-level prompt defined and controlled by the application. In this way, when the first application starts the first function by itself or calls the first system service by itself, the situation of maliciously avoiding the use state prompt of the first function or the calling prompt of the first application to the first system service can be avoided, and thus the situation that the user cannot know at any time that the first application starts the first function by itself or calls the corresponding system service can be avoided.

[0284] It can be understood that even if the first application secretly runs the first function or secretly calls the first system service without the user's knowledge, the electronic device can display a second system prompt in response to the running of the first function of the first application or in response to the calling of the first system service, to inform the user that the first application is supporting the running of the first function or to inform the user that the first application is calling the first system service. In this way, the user can know at any time the running state of the first function of the first application or the calling state of the first system service of the first application.

[0285] The second system prompt can also provide a system-level control such as a stop control. The stop control is used to trigger the stop running of the first function of the first application, which is equivalent to canceling the user's previous authorization of the first application to call the first system service. Thus, the user can stop using the first function of the first application by one key through the stop control. It can be understood that the user sees on the interface is to stop using the first function of the first application, but actually cancels the authorization of the first application to call the first system service at the same time, so that the first application cannot maliciously call the first system service, thereby ensuring the information security of the electronic device and avoiding the leakage of user privacy data.

[0286] In this way, the electronic device can interact with the user through the second system prompt controlled by the system to clearly obtain the current user's intention to stop using the first function of the first application, which is equivalent to clearly obtaining the current user's cancellation of the authorization for the first application to use the system service related to the first function, and can prevent the first application from deceiving the electronic device that it still has user authorization.

[0287] Optionally, the stop control may be a control for completely stopping the operation of the first function of the first application, or may be a control for temporarily stopping the operation of the first function of the first application.

[0288] Optionally, when the first application provides an application-level prompt similar to the second system prompt, such as the second application prompt, when the first application triggers the electronic device to display the second application prompt, the electronic device may hide the second system prompt; when the electronic device does not display the second application prompt, the electronic device will display the second system prompt again to avoid too many prompts affecting the user interaction experience.

[0289] In some scenarios, when the user stops using the first function of the first application with one click through the stop control in the second application prompt, even if the first application maliciously deceives the electronic device user to continue using the first function in an attempt to continue to secretly run the first function or secretly call the first system service, the electronic device can display the second system prompt controlled by the system based on the operation of the first function of the first application or the call of the first system service, so that an obvious prompt is always retained in the foreground to inform the user that the first application is supporting the operation of the first function or informing the user that the first application is calling the first system service. Therefore, in the method provided in the embodiment of the present application, the user can directly stop using the first function of the first application with one click through the stop control in the second system prompt, that is, cancel the user's previous authorization for the first application to call the first system service with one click.

[0290] For example, Figure 16 As shown in (a) in the figure, when application A calls the microphone service on its own, the electronic device may display a status prompt window 1601 to prompt the user that application A is accessing the microphone. The status prompt window 1601 includes a "Do not allow" control 1602 for canceling the user's previous authorization for the first application to call the first system service with one click. In this way, the user can know the call of the microphone service by application A at any time through the status prompt window 1601, and can directly stop or refuse to grant application A the permission to access the microphone by operating the "Do not allow" control 1602, so that application A can no longer call the microphone service on its own.

[0291] That is, in the embodiments of the present application, whether the first application runs the first function or calls the first system service with the user's knowledge or not, the electronic device will display the second system prompt when the first application runs the first function or calls the first system service. In this way, the user can know the running status of the first function of the first application at any time, or know the calling status of the first system service of the first application at any time. The information security of the electronic device is ensured, and the leakage of user privacy data is avoided.

[0292] Optionally, the second system prompt can include at least one of the following state prompt content: the application identifier (such as the application icon, the application name, etc.) of the first application; the first function currently running (such as the video call function currently being performed, the navigation function, etc.); the first system service currently being called (such as accessing the microphone, the camera, etc.); the risk prompt content about using the first function (the use of the video call function will obtain the image and sound information of the user); the risk prompt content about the first application using the related system service (such as the application A is accessing the microphone and the camera, and the application A can obtain the image and audio information of the user at any time).

[0293] As a way, the second system prompt can be displayed in the form of a floating window, which can display complete state prompt content or folded state prompt content. When the user clicks on the folded state prompt content, the electronic device can display the complete state prompt content.

[0294] As another way, the second system prompt can also be displayed in the form of a prompt icon in the status bar. When the user clicks on the prompt icon, the electronic device can display a state prompt window to completely or partially display the corresponding state prompt content. Optionally, the state prompt content in the second system prompt can also be displayed by jumping to a specified page through a link, and the specified page is used to display the complete state prompt content.

[0295] Optionally, the electronic device can always display the second system prompt on the screen to ensure that it will not be covered by various applications. It can also support setting a certain transparency of the second system prompt, such as being in a semi-transparent state, to avoid disturbing the user's operation. It can also support setting a certain hiding rule for the second system prompt, such as when the second system prompt is displayed in the form of a floating window, it can be folded into a strip prompt at the edge of the screen, or a floating ball prompt at the edge of the screen, or hidden for a certain period of time, such as 15 minutes, or set to be hidden before the next user interaction with the electronic device. The display mode of the second system prompt in the embodiments of the present application is not limited.

[0296] Optionally, the electronic device can also use other ways that can explicitly prompt the user without being covered by the application, such as a hardware physical light, or display a corresponding status card on the slide-down notification bar, to prompt the user about the use state of the first function of the first application, or prompt the user about the calling state of the first application to the first system service. For example, if the first application is calling the microphone, a microphone status card can be displayed on the slide-down notification bar, and the card displays a stop control.

[0297] As an example, as shown in (b) of FIG. 10A, when the electronic device detects a click operation of the user on the "Confirm" control in the risk prompt window 1002, it can be confirmed that the user still intends to use the navigation function of the application C after learning the risk prompt content, at which time the electronic device can start running the navigation function of the application C in response to the click operation, and display the navigation interface provided by the application C as shown in (c) of FIG. 10B. During the running of the navigation function of the application C, the electronic device grants the application C the permission to call the system service related to the navigation function, such as the permission to call the location service, so that the application C can successfully call the related system service to support the normal running of the navigation function. Figure 10 Figure 10 As shown in (c) of FIG. 10B, the electronic device can display a status prompt window 1003 on the currently displayed interface when the navigation function of the application C starts running, which can show the user what application is currently running and what function scenario is being supported, such as "application icon of application C + navigation", and an "End" control 1004. The "End" control 1004 is used to completely stop the running of the navigation function of the application C.

[0298] As shown in (c) of FIG. 10B, the electronic device can display a status prompt window 1003 on the currently displayed interface when the navigation function of the application C starts running, which can show the user what application is currently running and what function scenario is being supported, such as "application icon of application C + navigation", and an "End" control 1004. The "End" control 1004 is used to completely stop the running of the navigation function of the application C. Figure 10 The user can one-click stop using the navigation function of the application C through the "End" control 1004, that is, one-click cancel the user's previous authorization of the application C to call the system service related to the navigation function.

[0299] Optionally, the application C can also provide a "Quit Navigation" control 1005 for completely stopping the running of the navigation function. The user can one-click stop using the navigation function of the application C through the "Quit Navigation" control 1005, that is, one-click cancel the user's previous authorization of the application C to call the system service related to the navigation function.

[0300] Optionally, the electronic device can also hide the status prompt window 1003 when the navigation interface of the application C is displayed. Or, the electronic device can also hide the "End" control 1004 when the application C displays the "Quit Navigation" control 1005.

[0301] Optionally, as shown in (c) of FIG. 10B, the electronic device can also display a "Quit Navigation" control 1005 on the navigation interface of the application C, which can be used to completely stop the running of the navigation function of the application C.

[0302] Figure 10 ​​As shown in (d) of FIG. 1C, when the C application is running in the background, the electronic device can display the state prompt window 1003 in the foreground. Thus, the user can directly stop using the navigation function of the C application by one click, i.e., cancel the authorization of the user to the C application to call the system service related to the navigation function, without entering the navigation interface of the C application and clicking the "exit navigation" control 1005.

[0303] As another example, in the process of supporting the screen sharing function of the B application, as shown in (c) of FIG. 1B, when the electronic device detects a click operation of the user on the "confirm" control in the risk prompt window 1303, it can confirm that the user still intends to use the remote control function of the B application after learning the risk prompt content. At this time, the electronic device can respond to the click operation, start running the remote control function of the B application while running the screen sharing function of the B application, and display the remote control interface provided by the B application as shown in (d) of FIG. 1B. Figure 13 Figure 13 As shown in (d) of FIG. 1B, when the remote control function of the B application starts running, the electronic device can display a state prompt window 1304 on the currently displayed interface, which can show the user that "B application-remote control in progress". The user can view and manage the current state through the state prompt window 1304.

[0304] As shown in (d) of FIG. 1B, when the remote control function of the B application starts running, the electronic device can display a state prompt window 1304 on the currently displayed interface, which can show the user that "B application-remote control in progress". The user can view and manage the current state through the state prompt window 1304. Figure 13 As shown in (d) of FIG. 1B, when the user clicks the state prompt window 1304, the electronic device can expand and display the state management control. As shown in (e) of FIG. 1B, the state management control includes an "end" control 1305 and a "pause" control 1306. The "end" control 1305 is used to completely stop the running of the remote control function of the B application, and the "pause" control 1306 is used to temporarily stop the running of the remote control function of the B application.

[0305] Figure 13 The user can stop using the remote control function of the B application by one click through the "end" control 1305, i.e., cancel the authorization of the user to the B application to call the system service related to the remote control function. At this time, since the screen sharing function of the B application is still running, the electronic device can display the screen sharing interface provided by the B application as shown in (f) of FIG. 1B. Figure 13

[0306] The user can stop using the remote control function of the B application by one click through the "end" control 1305, i.e., cancel the authorization of the user to the B application to call the system service related to the remote control function. At this time, since the screen sharing function of the B application is still running, the electronic device can display the screen sharing interface provided by the B application as shown in (f) of FIG. 1B. Figure 13

[0307] ​​​​Optionally, the user can temporarily stop using the remote control function of the application B through the "pause" control 1306, that is, the user can temporarily cancel the authorization of the application B to call the system service related to the remote control function. Then the user can resume using the remote control function of the application B through the "continue" control or the "resume" control displayed in the status prompt window 1304, that is, the user can resume the authorization of the application B to call the system service related to the remote control function.

[0308] As a further example, in the process of supporting the video call function of the application, as shown in (a) of Figure 14 , the electronic device can grant the application the permission to call the system service related to the video call function when the video call function of the application starts running, such as the permission to call the microphone and camera services, and display a status prompt window 1404 on the currently displayed interface, which can show the user that there is an "application icon + video call" and an "end" control 1405. The "end" control 1405 is used to completely stop the running of the video call function of the application. When the user clicks the "turn to voice" control 1401 provided by the application, the electronic device can respond to the click operation to switch the running video call function of the application to run the voice call function of the application, and during the running of the voice call function of the application, the electronic device grants the application the permission to call the system service related to the voice call function, such as the permission to call the microphone service. So that the application can successfully call the related system service to support the normal running of the voice call function.

[0309] It can be understood that since the video call function has stopped running and the currently running voice call function does not need to use the camera, the electronic device can revoke the permission granted to the application to call the camera service in addition. As shown in (b) of , the electronic device can switch to display a status prompt window 1406 on the currently displayed interface when switching to run the voice call function of the application, which can show the user that there is an "application icon + voice call" and an "end" control 1407. The "end" control 1407 is used to completely stop the running of the voice call function of the application.

[0310] It can be understood that since the video call function has stopped running and the currently running voice call function does not need to use the camera, the electronic device can revoke the permission granted to the application to call the camera service in addition.

[0311] As shown in (b) of Figure 14 , the electronic device can switch to display a status prompt window 1406 on the currently displayed interface when switching to run the voice call function of the application, which can show the user that there is an "application icon + voice call" and an "end" control 1407. The "end" control 1407 is used to completely stop the running of the voice call function of the application. ​​​​​​​​The application icon of the application + voice call in progress, and the "end" control 1407. The "end" control 1407 is used to completely stop the call. The voice call function of the application is running.

[0312] Alternatively, as Figure 14 As shown in (c), when the electronic device enters the application management interface, the status prompt window 1406 can always remain displayed in the foreground.

[0313] In some embodiments, when the status prompt window is used to prompt the user of the calling status of the first application on the system service related to the first function, the stop control can also be a control used to stop or refuse to grant the first application permission to call a certain system service.

[0314] As an example, in When the application supports the video call function, Figure 16 As shown in (c) of FIG, the electronic device may display a status prompt window 1607 on the currently displayed interface, and the status prompt window 1607 may show the user that The application is currently calling various system services, such as Application icon + using microphone", " The application icon of the application + using the camera. The user can use this status prompt window to understand which capabilities of the electronic device are used by the current application.

[0315] Optionally, the electronic device may provide corresponding management controls for each system service. Figure 16 As shown in (c) in In the process of applying the video call function, when the user intends to turn off the microphone, the user can click the "off" control 1608 to stop using the microphone service. At this time, the "off" control 1608 can be switched to the "on" control, and the electronic device can cancel the microphone service. When the user intends to turn off the camera, the user can click the "off" control 1609 to stop using the camera service. At this time, the "off" control 1609 can be switched to the "on" control, and the electronic device can cancel the previous The application is authorized to call the camera service. When the application supports the video call function, if the user intends to use the microphone or camera again, the user can use the "Open" control to resume the use of the microphone or camera. Correspondingly, the electronic device can resume the previous use of the microphone or camera. Authorization for the application to call the camera service.

[0316] Alternatively, as Figure 16 As shown in (b), The application may also provide a "hang up" control 1605 for completely stopping the video call function. The user can use the "hang up" control 1605 to stop using the video call function with one click. The video call function of the application, that is, one-click cancellation of the user's previous Authorization for the app to call system services related to the video call function.

[0317] Similarly, in When the application supports the video call function, The application may also provide controls for pausing and resuming certain system capabilities, such as a microphone on / off control 1603 for pausing and resuming microphone use, and a camera on / off control 1604 for pausing and resuming camera use. There may also be a "switch to voice" control 1606 for completely ending camera use. The electronic device can determine the user's intention to use these system capabilities through the user's operation of these controls, and thus determine whether to grant the user permission to use these system capabilities. The permission for the application to call related system services.

[0318] S1550: The electronic device detects a user triggering operation of a stop control in the second system prompt.

[0319] In an embodiment of the present application, when the user intends to stop using the first function of the first application, the user can input a trigger operation for the stop control in the second system prompt. The trigger operation can be a touch operation, a voice operation, a floating gesture operation, a physical button operation, etc.

[0320] As an example, Figure 10 As shown in (c) and (d) in FIG, when the user intends to stop using the navigation function of application C, the user can click the “end” control 1004 in the status prompt window 1003 .

[0321] As another example, Figure 13 As shown in (e) in FIG, when the user intends to temporarily stop using the remote control function of application B, the user can click the “Pause” control 1306 in the status prompt window 1304 .

[0322] In some embodiments, when the first application provides a stop control for triggering the stop of the first function of the first application, the user can also input a trigger operation for the stop control provided by the first application to stop the first function of the first application with one click.

[0323] As an example, Figure 14 As shown in (b) in the figure, when the user intends to temporarily stop using When using the video call function of the application, the user can click the "end" control 1407 in the status prompt window 1406, or click An application-provided "Hang Up" control 1402.

[0324] S1560: In response to the triggering operation of the stop control in the second system prompt, the electronic device stops using the first function of the first application and cancels the permission granted to the first application to call the first system service.

[0325] In an embodiment of the present application, when the electronic device detects that the user has triggered the stop control in the second system prompt, it may be deemed that the user intends to stop using the first function of the first application. In this case, it may be deemed that the user intends to revoke the permission previously granted to the first application to call the first system service related to the first function. Therefore, the electronic device may directly respond to the triggering operation of the stop control in the second system prompt by stopping the first function of the first application and revoking the permission granted to the first application to call the first system service.

[0326] Specifically, after the first scenario-based service corresponding to the first function instructs the electronic device to display the second system prompt, if it detects a user input triggering an operation for the stop control in the second system prompt, it can clearly obtain the user's cancellation of authorization for the first application to call the first system service related to the first function. The first scenario-based service can then notify the first system service related to the first function of the cancellation of authorization information, so that the first system service can refuse to respond to the call of the first application. In this way, the first application can no longer successfully call the first system service.

[0327] As an example, Figure 10 As shown in (c) and (d), when the user clicks the "End" control 1004 in the status prompt window 1003, the electronic device can respond to the click operation, stop running the navigation function of application C, and revoke the permission previously granted to application C to call system services related to the navigation function, such as revoking the permission to call location services.

[0328] As another example, Figure 13As shown in (e), when the user clicks the "Pause" control 1306 in the status prompt window 1304, the electronic device can, in response to the click operation, pause the running of the navigation function of application C and temporarily revoke the permission previously granted to application C to call system services related to the navigation function, such as temporarily revoking the permission to call location services, during which application C can no longer call location services. At this time, the "Pause" control 1306 in the status prompt window 1304 can be switched to a "Continue" control. When the user clicks the "Continue" control, the electronic device can, in response to the click operation, continue to run the navigation function of application C and continue to grant application C the permission to call system services related to the navigation function, such as restoring application C's permission to call location services, and application C can continue to call location services.

[0329] In some scenarios, when the electronic device detects that the first system service is successfully called, it may display a corresponding indicator icon on the status bar to indicate that the first system service is currently being called.

[0330] Take application D that supports recording function as an example. Since the recording function requires application D to call microphone service, Figure 17 As shown in (a) of FIG, in response to the user clicking the "recording" control 1701, the electronic device can start the recording function and grant application D permission to call the microphone service. At this time, because application D continues to call the microphone service to obtain the user's audio information, the electronic device can detect that the microphone service has been successfully called and can display a microphone icon 1702 on the status bar to prompt the user that the electronic device's microphone is in use.

[0331] When the user needs to pause the recording, Figure 17 As shown in (b) of FIG, the electronic device can temporarily stop the recording function in response to the user clicking the "pause" control 1703, and temporarily revoke the permission previously granted to application D to call the microphone service. At this time, since application D can no longer call the microphone service to obtain the user's audio information, the electronic device can detect that the microphone service has not been successfully called, and thus Figure 17 As shown in (b) in FIG. 1 , the microphone icon 1702 is cancelled on the status bar to remind the user that the microphone of the electronic device is not in use.

[0332] When the user needs to continue recording, such as Figure 17 As shown in (b) of FIG, the electronic device can continue to run the recording function in response to the user clicking the "Continue" control 1704, and continue to grant the application D the permission to call the microphone service. At this time, since application D can continue to call the microphone service to obtain the user's audio information, the electronic device can detect that the microphone service has been successfully called again, so that Figure 17(c) in the state bar, the microphone icon 1702 is restored to display, prompting the user that the microphone of the electronic device is being used.

[0333] The permission control method provided by the embodiments of the present application can enable the electronic device to grant the first application the permission to call the system service related to the first function when detecting that the first function of the first application is running, and synchronously display a second system prompt to inform the user of the function scenario currently supported by the first application or to inform the user of the system service currently used by the first application. In addition, a one-key stop function of the first function can also be synchronously provided to the user, and the one-key stop function is equivalent to a one-key cancelation of the permission granted to the first application to call the system service related to the first function, so that the user can know and control the behavior of the first application to access the system service, thereby enhancing the protection of the user's private data.

[0334] It can be understood that, in order to implement the above functions, the electronic device comprises hardware and / or software modules corresponding to each function. The algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is implemented in hardware or computer software driven hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application in conjunction with the embodiments, but such implementation should not be considered beyond the scope of the present application.

[0335] The embodiments can divide the functional modules of the electronic device according to the above method examples. For example, each functional module can be divided according to each function, and each functional module can exist physically alone or two or more functions can be integrated in one processing module. The integrated module can be implemented in the form of hardware or in the form of a software functional unit. The integrated unit, if implemented in the form of a software functional unit and sold or used as an independent product, can be stored in a readable storage medium.

[0336] As an example, the electronic device can include a processing module configured to use a first function of a first application in response to a use operation of the first function of the first application, and grant the first application a permission to call a system service related to the first function, the system service related to the first function being related to the user's security privacy. The processing module is further configured to cancel the permission granted to the first application to call the system service related to the first function in response to a stop use of the first function of the first application during running of the first application.

[0337] Optionally, the processing module is further configured to, in response to a use operation of the second function of the first application, use the second function of the first application and grant the first application a permission to call a system service related to the second function, the system service related to the second function being related to the security privacy of the user; and in response to a stop use of the second function of the first application during running of the first application, cancel the permission granted to the first application to call the system service related to the second function.

[0338] Optionally, the processing module is further configured to, in response to switching from the first function of the first application to the second function of the first application, cancel the permission granted to the first application to call the system service related to the first function.

[0339] Optionally, the electronic device can further include a display module configured to, in response to the use of the first function of the first application, display a first icon in a status bar, the first icon being used to indicate that the system service related to the first function is called; and in response to switching from the first function of the first application to the second function of the first application, cancel the display of the first icon in the status bar.

[0340] Optionally, when the system service related to the first function is multiple, the processing module is further configured to, in response to switching from the first function of the first application to the second function of the first application, cancel the permission granted to the first application to call part of the system services related to the first function, the part of the system services being irrelevant to the second function.

[0341] Optionally, the display module is further configured to, in response to the use of the first function of the first application, display multiple icons in the status bar, the multiple icons being used to indicate that the system service related to the first function is called; and in response to switching from the first function of the first application to the second function of the first application, cancel the display of part of the multiple icons in the status bar.

[0342] Optionally, the processing module is further configured to, in response to a stop use operation of the first function of the first application, cancel the permission granted to the first application to call the system service related to the first function.

[0343] Optionally, the processing module is further configured to, in response to a pause use of the first function of the first application, cancel the permission granted to the first application to call the system service related to the first function; and in response to a continue use of the first function of the first application, continue to grant the first application the permission to call the system service related to the first function.

[0344] Optionally, the display module is further configured to, in response to the use of the first function of the first application, display a first icon in a status bar, the first icon being used to indicate that the system service related to the first function is called; in response to a pause use of the first function of the first application, cancel the display of the first icon in the status bar; and in response to a continue use of the first function of the first application, continue to display the first icon in the status bar.

[0345] Optionally, the electronic device can further include a prompt module configured to output a first prompt at a system level in response to a use operation of the first function of the first application, the first prompt being configured to prompt a user whether to confirm use of the first function of the first application. The processing module is further configured to use the first function of the first application and grant the first application a permission to invoke a system service related to the first function in response to a confirmation operation for the first prompt.

[0346] Optionally, the prompt module is further configured to output a second prompt at the system level during use of the first function of the first application, the second prompt being configured to prompt the user that the first function of the first application is in use and / or prompt the user that the system service related to the first function is invoked.

[0347] Optionally, the processing module is further configured to cancel the permission granted to the first application to invoke the system service related to the first function in response to an operation on a system-level control when use of the first function of the first application is stopped and the permission granted to the first application to invoke the system service related to the first function is not cancelled.

[0348] Optionally, the processing module is configured to cancel the permission granted to the first application to invoke the system service related to the first function in response to a stop of use of the first function of the first application when the first application is in a foreground.

[0349] Those skilled in the art can clearly understand the technical solutions of the above embodiments through the description of the above embodiments. For the convenience and brevity of description, only the division of the above functional modules is taken as an example for description. In actual application, the above functions can be completed by different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.

[0350] It should be noted that all related contents of each step involved in the above method embodiments can be referred to the function description of the corresponding functional module, which will not be repeated here. The electronic device provided by the embodiments of the present application is used to execute the above permission control method, and thus can achieve the same effect as the above implementation method.

[0351] The embodiments of the present application further provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the electronic device implements each function or step executed by the electronic device in each method embodiment.

[0352] The embodiments of the present application further provide a permission control device, which can be applied to the above electronic device. The device is used to execute each function or step executed by the electronic device in the above method embodiments.

[0353] The embodiment of the present application further provides a chip system, which comprises at least one processor and at least one interface circuit. The processor and the interface circuit can be interconnected through a line. The interface circuit can read instructions stored in a memory and send the instructions to the processor. When the instructions are executed by the processor, the electronic device can perform various functions or steps performed by the electronic device in the method embodiments. Of course, the chip system can also include other discrete devices, which are not limited in the embodiment of the present application.

[0354] The embodiment of the present application further provides a computer readable storage medium, which comprises computer instructions. When the computer instructions are run on the electronic device, the electronic device can perform various functions or steps performed by the electronic device in the method embodiments.

[0355] The embodiment of the present application further provides a computer program product, which can make the electronic device perform various functions or steps performed by the electronic device in the method embodiments when the computer program product is run on the electronic device.

[0356] The electronic device, the permission control apparatus, the computer readable storage medium, the computer program product or the chip provided by the embodiment of the present application are all used to execute the corresponding method provided above, so the beneficial effects achieved thereby can refer to the beneficial effects of the corresponding method provided above, which will not be repeated here.

[0357] In addition, unless otherwise specified, " / " in the present application represents that the objects before and after the " / " are in an "or" relationship, for example, A / B can represent A or B; "and / or" in the present application is a description of the association between the associated objects, which means that there can be three kinds of relationships, for example, A and / or B, which can represent: A exists alone, A and B exist together, and B exists alone, of which A and B can be singular or plural. "Multiple" in the present application means two or more than two. "At least one of the following" or similar expressions means any combination of these objects. For example, at least one of a, b, or c can represent: a, b, c, a and b, a and c, b and c, a and b and c, of which a, b, and c can be singular or plural.

[0358] The terms "first", "second", and the like in the specification and claims of this application are used for distinguishing between similar elements and not necessarily for describing a sequential or chronological order. The terms are not necessarily used in a "first", "second", "third", etc. order of importance, preference, or chronology, but are merely used to distinguish one element from another, unless otherwise indicated by the context of their usage.

[0359] The features, structures, or characteristics of the application can be combined in one or more embodiments. In various embodiments of the application, the sequence of the processes does not mean the order of execution, and the execution order of the processes should be determined according to their functions and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the application.

[0360] Some optional features in the embodiments of the application can be implemented independently in some scenarios without relying on other features, solve corresponding technical problems, and achieve corresponding effects. In the application, the same or similar parts of each embodiment can be mutually referred to, unless otherwise specified. In the application, the terms and / or descriptions of different embodiments are consistent with each other and can be mutually referred to, unless otherwise specified and logically conflicted. The technical features of different embodiments can be combined to form new embodiments according to their inherent logical relationship. The implementation manners of the application do not constitute a limitation on the protection scope of the application.

[0361] In several embodiments provided by the application, the disclosed device and method can be implemented by other means. For example, the above-described multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the shown or discussed elements can be indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms. The units described as separate components above can or can not be physically separated, and the components shown as units can be one physical unit or multiple physical units, which can be located in one place or distributed in multiple different places. According to actual needs, some or all of the units can be selected to achieve the purpose of the embodiment scheme.

[0362] Based on this understanding, the technical solutions of the embodiments of the present application, or the portion that contributes to the prior art, or all or part of the technical solutions, can be embodied in the form of a software product, which is stored in a storage medium and includes a number of instructions for causing a device (which may be a single-chip microcomputer, chip, etc.) or a processor to execute all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes: a USB flash drive, a mobile hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, and other media that can store program code.

[0363] The above content is only a specific embodiment of this application, but the scope of protection of this application is not limited to this. Any changes or replacements within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A method of controlling rights, characterized by, The method is applied to an electronic device, and the method comprises: in response to a use operation of a first function of a first application, using the first function of the first application, and granting the first application a permission to call a system service related to the first function, the system service related to the first function being related to a user's security privacy; during running of the first application, in response to a stop use of the first function of the first application, canceling the permission granted to the first application to call the system service related to the first function.

2. The method of claim 1, wherein, The method further comprises: in response to a use operation of a second function of the first application, using the second function of the first application, and granting the first application a permission to call a system service related to the second function, the system service related to the second function being related to a user's security privacy; during running of the first application, in response to a stop use of the second function of the first application, canceling the permission granted to the first application to call the system service related to the second function.

3. The method according to claim 1 or 2, characterized in that, The canceling the permission granted to the first application to call the system service related to the first function in response to the stop use of the first function of the first application comprises: in response to switching from the first function of the first application to a second function of the first application, canceling the permission granted to the first application to call the system service related to the first function.

4. The method of claim 3, wherein, The method further comprises: in response to the use of the first function of the first application, displaying a first icon in a status bar, the first icon being used to indicate that the system service related to the first function is called; in response to switching from the first function of the first application to the second function of the first application, canceling the display of the first icon in the status bar.

5. The method according to claim 1 or 2, characterized in that, The system service related to the first function is multiple, and the canceling the permission granted to the first application to call the system service related to the first function in response to the stop use of the first function of the first application comprises: in response to switching from the first function of the first application to a second function of the first application, canceling the permission granted to the first application to call part of the system service related to the first function, the part of the system service being irrelevant to the second function.

6. The method of claim 5, wherein, The method further comprises: in response to the use of the first function of the first application, displaying multiple icons in a status bar, the multiple icons being used to indicate that the system service related to the first function is called; in response to switching from the first function of the first application to the second function of the first application, canceling the display of part of the multiple icons in the status bar.

7. The method according to claim 1 or 2, characterized in that, The canceling the permission granted to the first application to call the system service related to the first function in response to the stop use of the first function of the first application comprises: in response to a stop use operation of the first function of the first application, canceling the permission granted to the first application to call the system service related to the first function.

8. The method of claim 7, wherein, The stop use operation of the first function of the first application comprises: an operation on an application-level control in the first application; or an operation on a system-level control in the electronic device.

9. The method according to any one of claims 1 to 8, characterized in that, The revoking the permission of the first application to invoke the system service related to the first function in response to the stop use of the first function of the first application comprises: The revoking the permission of the first application to invoke the system service related to the first function in response to the pause use of the first function of the first application comprises: The method further comprises: The continuing the permission of the first application to invoke the system service related to the first function in response to the continue use of the first function of the first application comprises:

10. The method of claim 9, wherein, The method further comprises: The displaying the first icon in the status bar in response to the use of the first function of the first application, the first icon being used to indicate that the system service related to the first function is invoked; The canceling the display of the first icon in the status bar in response to the pause use of the first function of the first application; The continuing the display of the first icon in the status bar in response to the continue use of the first function of the first application.

11. The method according to any one of claims 1 to 10, characterized in that, The using the first function of the first application and granting the permission of the first application to invoke the system service related to the first function in response to the use operation of the first function of the first application comprises: The outputting a first prompt of a system level in response to the use operation of the first function of the first application, the first prompt being used to prompt a user whether to confirm the use of the first function of the first application; The using the first function of the first application and granting the permission of the first application to invoke the system service related to the first function in response to a confirmation operation on the first prompt.

12. The method according to any one of claims 1 to 11, characterized in that, The method further comprises: The outputting a second prompt of a system level in a use process of the first function of the first application, the second prompt being used to prompt a user that the first function of the first application is in use, and / or prompt a user that the system service related to the first function is invoked.

13. The method of claim 12, wherein, The second prompt comprises a system-level control, the system-level control being used to trigger the stop use of the first function of the first application.

14. The method of claim 13, wherein, The method further comprises: The revoking the permission of the first application to invoke the system service related to the first function in response to an operation on the system-level control when the first function of the first application is stopped and the permission of the first application to invoke the system service related to the first function is not revoked.

15. The method according to any one of claims 1 to 14, characterized in that, The revoking the permission of the first application to invoke the system service related to the first function in response to the stop use of the first function of the first application in a running process of the first application comprises: The revoking the permission of the first application to invoke the system service related to the first function in response to the stop use of the first function of the first application in a foreground running process of the first application.

16. The method according to any one of claims 1 to 15, characterized in that, The system service related to the first function comprises at least one of a microphone service, a camera service, a keyboard and mouse injection service, and a location service.

17. An electronic device, comprising: The electronic device comprises a processor and a memory, the memory is used for storing instructions, and the processor is used for calling the instructions in the memory, so that the electronic device executes the method as claimed in any one of claims 1 to 16.

18. A chip system, characterized by The chip system is applied to an electronic device; the chip system comprises an interface circuit and a processor; the interface circuit and the processor are interconnected through a line; the interface circuit is used for receiving a signal from a memory of the electronic device and sending a signal to the processor, the signal comprising instructions stored in the memory; when the processor executes the instructions, the chip system executes the method as claimed in any one of claims 1 to 16.

19. A readable storage medium, characterized by, A program is included, when the program runs on an electronic device, so that the electronic device executes the method as claimed in any one of claims 1 to 16.