Authority management method, electronic device, readable medium and computer program product
By acquiring the current user's identity features under identity recognition conditions and updating the terminal device's permission information in case of mismatch, the problem of insufficient flexibility in existing permission management methods is solved, realizing the security of user data and the flexibility of permission management, and improving user experience and device security.
Patent Information
- Application Number
- CN202410799186.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-19
- Publication Date
- 2025-12-19
AI Technical Summary
Existing permission management methods are not flexible enough. Once user authorization information is configured, it cannot be changed adaptively, resulting in insufficient user data security, especially when terminal devices are used by different users and permissions cannot be updated in a timely manner.
If the identity recognition conditions are met, the system obtains the current user's identity feature information; if there is a mismatch, it updates the device permission information based on the user's identity feature information. If the identity recognition conditions are met, it updates the device permission information based on the user's authorization information.
This technology enables the updating of terminal device permission information based on user identity characteristics and user authorization information under user identification conditions, thereby improving the flexibility and security of permission management and ensuring the security of user data.
Smart Images

Figure CN121167705A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of data processing technology, and in particular to a permission management method, electronic device, readable medium, and computer program product. Background Technology
[0002] With the widespread adoption of various smart terminals such as smartphones, tablets, wearable devices, and in-vehicle computers, the types of applications and business functions supported by these terminals are becoming increasingly diverse. Some applications require access to data or interfaces within the terminal device during operation. For example, some applications need to access data such as contacts and SMS messages, or they need to call the terminal device's location, camera, and recording functions. Therefore, to ensure the security of user data, these applications must obtain user authorization before calling authorized data or interfaces.
[0003] In related technologies, authorized users (such as the device owner) can pre-configure user authorization information to determine the permissions of various applications based on this information. However, the above-mentioned permission management method has poor flexibility; once the user authorization information is configured, it cannot be changed adaptively. Summary of the Invention
[0004] This disclosure provides a permission management method, an electronic device, a readable medium, and a computer program product.
[0005] In a first aspect, embodiments of this disclosure provide a permission management method, which includes:
[0006] If the identity recognition conditions are met, obtain the current user's identity feature information on the terminal device;
[0007] If the current user's identity feature information does not match the pre-stored identity feature information of authorized users, the user authorization information of the current user is obtained;
[0008] Update the device permission information of the terminal device according to the user authorization information of the current user; wherein the initial state of the device permission information of the terminal device is configured according to the user authorization information of the authorized user.
[0009] Secondly, embodiments of this disclosure provide an electronic device, which includes a memory and a processor; the memory stores a computer program that can be executed by the processor, and when the computer program is executed by the processor, it implements the above-described permission management method.
[0010] Thirdly, embodiments of this disclosure provide a computer-readable medium having a computer program stored thereon, which, when executed by a processor, implements the aforementioned permission management method.
[0011] Fourthly, embodiments of this disclosure provide a computer program product, which includes a computer program that, when executed by a processor, implements the above-described permission management method.
[0012] The permission management method in this embodiment obtains the identity feature information of the current user of the terminal device when the identity recognition conditions are met; if the identity feature information of the current user does not match the pre-stored identity feature information of authorized users, it can update the device permission information of the terminal device according to the user authorization information of the current user. Normally, the initial state of the device permission information of the terminal device can be configured according to the user authorization information of authorized users. In this embodiment, when it is determined that the current user is different from the authorized user based on the user's identity feature information, the device permission information of the terminal device is automatically updated according to the user authorization information of the current user. Therefore, this method can automatically update the device permission information of the terminal device in a timely manner according to the authorization status of different users when users change, thereby ensuring the security of user data, improving the flexibility of permission management, and enabling flexible modification of user authorization information and device permission information. Attached Figure Description
[0013] In the accompanying drawings of the embodiments disclosed herein:
[0014] Figure 1 A flowchart illustrating a permission management method provided in an embodiment of this disclosure;
[0015] Figure 2 A flowchart illustrating a permission management method in one example of this disclosure is shown;
[0016] Figure 3 A schematic diagram of the structure of a terminal device in one example of this disclosure is shown; Figure 4 A schematic diagram of the overall process in one example of this disclosure is shown, taking into account the various modules contained in the terminal device.
[0017] Figure 5 This is a block diagram of an electronic device provided in an embodiment of the present disclosure. Detailed Implementation
[0018] To enable those skilled in the art to better understand the technical solutions of this disclosure, the embodiments of this disclosure will be described in detail below with reference to the accompanying drawings.
[0019] The present disclosure will be described more fully below with reference to the accompanying drawings; however, the embodiments shown may be embodied in different forms, and the present disclosure should not be construed as limited to the embodiments set forth below. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will enable those skilled in the art to fully understand the scope of the disclosure.
[0020] The accompanying drawings of the embodiments disclosed herein are provided to further illustrate the embodiments of this disclosure and form part of the specification. They are used together with the detailed embodiments to explain this disclosure and do not constitute a limitation thereof. The above and other features and advantages will become more apparent to those skilled in the art from the description of the detailed embodiments with reference to the accompanying drawings.
[0021] This disclosure may be described with reference to plan and / or cross-sectional views using the ideal schematic diagrams of this disclosure. Therefore, the example illustrations may be modified according to manufacturing techniques and / or tolerances.
[0022] Where there is no conflict, the various embodiments of this disclosure and the features thereof in the embodiments may be combined with each other.
[0023] The terminology used in this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the disclosure. The term "and / or" as used in this disclosure includes any and all combinations of one or more of the associated enumerated entries. The singular forms "a" and "the" as used in this disclosure are also intended to include the plural forms, unless the context clearly indicates otherwise. The terms "comprising," "made of," etc., as used in this disclosure specify the presence of the stated feature, integral, step, operation, element, and / or component, but do not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components, and / or groups thereof.
[0024] Unless otherwise specified, all terms used in this disclosure (including technical and scientific terms) have the same meaning as commonly understood by one of ordinary skill in the art. It will also be understood that terms such as those defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant art and this disclosure, and will not be interpreted as having an idealized or overly formal meaning, unless expressly so defined in this disclosure.
[0025] This disclosure is not limited to the embodiments shown in the accompanying drawings, but includes modifications to the configuration based on the manufacturing process. Therefore, the areas illustrated in the drawings are schematic, and the shapes of the areas shown illustrate specific shapes of the areas of an element, but are not intended to be limiting.
[0026] In some related technologies, authorized users (such as the computer owner) can pre-configure user authorization information to determine the permissions of various applications based on this information. However, the above-mentioned permission management methods are inflexible, and user authorization information cannot be easily changed once configured. To solve the above problems, this application provides a permission management method, an electronic device, a readable medium, and a computer program product.
[0027] Firstly, this disclosure provides a permission management method. Figure 1This is a flowchart illustrating a permission management method provided in an embodiment of this disclosure. Figure 1 As shown, the method includes the following steps:
[0028] Step S110: If the identity recognition conditions are met, obtain the current user's identity feature information on the terminal device.
[0029] The identity verification condition is a pre-configured condition used to trigger subsequent identity verification operations. The identity verification condition can be flexibly configured by those skilled in the art. For example, the identity verification condition can be: determining that the identity verification condition is met when a change in the user is detected. Another example is: determining that the identity verification condition is met whenever the interval between the current time and the time of the last identity verification operation reaches a preset period.
[0030] In one alternative implementation, the identity verification conditions include at least one of the following:
[0031] (1) The current user’s operation behavior is detected to be inconsistent with the pre-stored historical operation behavior of authorized users.
[0032] User operation behavior is used to represent various operation-related information such as user operating habits and geographical location. Any behavior related to user operation can be considered user operation behavior, and this application does not limit the specific connotation of user operation behavior. When it is detected that the current user's operation behavior does not match the pre-stored historical operation behavior of authorized users, it is generally considered that the current user is a different user from the authorized users, that is, the user using the terminal device has changed. Therefore, it is necessary to trigger an identity recognition operation to confirm the identity of the current user.
[0033] For example, artificial intelligence technology can be used to analyze users' usage habits, including but not limited to physical activities, frequently used functions, usage time periods, and location. If the usage habits of an authorized user (such as the device owner) are not met, the current user is considered to be an unauthorized user (such as a non-device owner).
[0034] Therefore, user actions can include actions related to physical activity, such as movement speed, movement trajectory, heart rate, blood pressure, and other physical activity information generated during runtime. Correspondingly, if a user's identity and activity information changes significantly compared to previously recorded data, it can be considered that the current user's actions do not match the pre-stored historical actions of authorized users.
[0035] In addition, user behavior can also include actions performed on frequently used applications, specifically including the types of frequently used applications, the usage time of frequently used applications, and the location information when frequently used applications are used. In short, by recording users' historical behavior, it is possible to determine whether to trigger identity verification based on abnormal behavior.
[0036] (2) The terminal device was detected to switch from a black screen state to a bright screen state.
[0037] When a terminal device switches from a black screen to a bright screen, it indicates that the user has just started using the terminal. At this time, the possibility of a user switching is relatively high. Therefore, identity recognition can be automatically triggered every time the terminal device switches from a black screen to a bright screen to avoid permission issues caused by user changes.
[0038] (3) The facial contour information of the current user does not match the facial contour information of the authorized user.
[0039] Specifically, it can continuously identify the current user's facial contour information to initially determine whether the user has changed through fuzzy recognition. If a mismatch is detected between the current user's facial contour information and that of an authorized user, it triggers the collection of identity feature information. The fuzzy recognition method focuses on recognizing the user's facial contour without considering detailed facial information, thus offering advantages such as low power consumption, simple computation, and fast processing speed.
[0040] The current user of the terminal device refers to the user currently operating the terminal device. Identity feature information is used to identify the user's identity and may specifically include facial feature information, fingerprint feature information, iris feature information, voiceprint feature information, etc. This application does not limit the specific types of identity feature information.
[0041] Step S120: If the current user's identity feature information does not match the pre-stored identity feature information of authorized users, obtain the current user's user authorization information.
[0042] The pre-stored identity information of authorized users typically refers to the identity information of the account holder. If the current user's identity information does not match the pre-stored identity information of authorized users, it means that the current user is a different user from the account holder.
[0043] Considering that different users have different security requirements for different data, in order to meet user needs, in this embodiment, different user authorization information can be configured for different users. This user authorization information is used to represent the application access permissions configured by the corresponding user for various applications on the terminal device.
[0044] Accordingly, this step requires obtaining the current user's authorization information. This authorization information can be configured by the current user. Alternatively, fixed authorization information can be pre-configured for the current user; this fixed authorization information typically differs from that of authorized users.
[0045] Step S130: Update the device permission information of the terminal device according to the user authorization information of the current user; wherein, the initial state of the device permission information of the terminal device is configured according to the user authorization information of the authorized user.
[0046] The device permission information of the terminal device is used to characterize the application access permissions of various applications on the terminal device. These applications include system applications, user applications, and other types. Application access permissions characterize whether an application can access various data or interfaces on the terminal device during operation.
[0047] Therefore, it is evident that device permission information will change based on different users' authorization information. For example, if an authorized user's authorization information contains more types of permissions, the application can access a wider range of data and interfaces on the terminal device during operation; conversely, if an unauthorized user's authorization information contains fewer types of permissions, the application can access fewer types of data and interfaces on the terminal device during operation. This differentiated setting helps protect the personal privacy data of unauthorized users and prevents its leakage.
[0048] In this embodiment, when the identity recognition conditions are met, the identity feature information of the current user of the terminal device is obtained; when the identity feature information of the current user does not match the pre-stored identity feature information of authorized users, the device permission information of the terminal device can be updated according to the user authorization information of the current user. Normally, the initial state of the device permission information of the terminal device can be configured according to the user authorization information of authorized users. In this embodiment, when it is determined that the current user is different from the authorized user based on the user's identity feature information, the device permission information of the terminal device is automatically updated according to the user authorization information of the current user. Therefore, this method can automatically and promptly update the device permission information of the terminal device according to the authorization status of different users when users change, thereby ensuring the security of user data, improving the flexibility of permission management, and enabling flexible modification of user authorization information and device permission information.
[0049] In addition, those skilled in the art can make various modifications and variations to the above embodiments:
[0050] In one optional implementation, the current user's authorization information is obtained as follows: if the current user's authorization information is not found in the pre-stored authorization data, a permission configuration prompt is displayed; in response to the permission configuration command triggered by the permission configuration prompt, the current user's authorization information is obtained and updated in the authorization data. The pre-stored authorization data stores authorization information for authorized users (e.g., the device owner) or unauthorized users (e.g., the device owner), and can be stored in various ways such as an authorization database or authorization data table. If the current user's authorization information is not found in the pre-stored authorization data, it indicates that the current user is using the terminal device for the first time and has not yet configured the terminal device's permission information; therefore, a permission configuration prompt is displayed. Correspondingly, the current user can trigger a permission configuration command through the permission configuration prompt, which allows for flexible configuration of access permissions for various applications on the terminal. Therefore, the current user's authorization information can be determined based on the user's configuration, and for ease of subsequent retrieval, the current user's authorization information can be stored in the authorization data.
[0051] In one optional implementation, permission configuration prompts can be displayed as follows: Retrieve the various data permissions included in the data permission set supported by the terminal device; display a permission configuration interface containing permission configuration entry points; where each permission configuration entry point corresponds to a data permission. The data permission set stores various data access permissions supported by the terminal device, such as microphone, camera, and location services. Additionally, the data permission set can store the correspondence between various data access permissions supported by the terminal device and applications. For example, for microphone permissions, it allows flexible settings of which applications can use the microphone and which cannot. Correspondingly, the permission configuration entry points configure the correspondence between applications and permissions. There can be multiple permission configuration entry points, and each set can correspond to a different data permission.
[0052] In one optional implementation, before displaying the permission configuration prompt, the following operations are further performed: In response to the received level setting instruction, the various data permissions contained in the data permission set are divided into at least two permission levels; correspondingly, the permission configuration entry includes at least two types of permission configuration entry corresponding to the at least two permission levels. By classifying data permissions into levels, it is convenient to configure different authorization management methods for different levels of permissions, thereby facilitating flexible management of permission information.
[0053] For example, in one optional implementation, at least two types of permission configuration entry points may include: a first type of configuration entry point for triggering permission configuration instructions upon detecting a triggering operation by the current user; and a second type of configuration entry point for triggering permission configuration instructions upon detecting an authorization operation by an authorized user. Thus, the first type of configuration entry point corresponds to data permissions at the first permission level. This type of data permission typically does not involve user privacy data; therefore, the first type of configuration entry point can directly trigger permission configuration instructions based on the current user's triggering operation, without requiring additional authorization from the authorized user. The second type of configuration entry point corresponds to data permissions at the second permission level. This type of data permission may involve some privacy data; therefore, to improve data security, the second type of configuration entry point can only trigger permission configuration instructions upon detecting an authorization operation by an authorized user. The authorization operation by the authorized user can be various identity verification operations such as facial verification or fingerprint verification. Therefore, because the data permissions at the second permission level have higher security, additional authorization from the device owner is required to ensure the device owner's control over the smart terminal and effectively protect user privacy.
[0054] In one optional implementation, before displaying the permission configuration prompt, the following operations are further performed: In response to the received type setting instruction, the various data permissions included in the data permission set are divided into at least two permission types; wherein, the at least two permission types include: a first type of data permission corresponding to authorized users, and a second type of data permission corresponding to unauthorized users; and the permission configuration entry corresponds to the second type of data permission. The first type of data permission typically refers to permissions that can only be enabled when an authorized user (i.e., the device owner) uses the terminal device; the second type of data permission typically refers to permissions that can be enabled when an unauthorized user (i.e., a non-device owner) uses the terminal device. Therefore, by dividing data permissions into at least two permission types, it can be ensured that some data permissions are only enabled during the device owner's use, avoiding data security issues caused by enabling such permissions for non-device owners. Thus, the permissions that can be configured through the permission configuration entry are limited to the second type of data permissions, excluding the first type of data permissions. Accordingly, the aforementioned first and second type configuration entry are for the second type of data permissions. In other words, the second type of data permissions can be further divided into two categories: one corresponding to the first type of configuration entry and the other corresponding to the second type of configuration entry.
[0055] Furthermore, the methods for classifying permission types and permission levels described above can be combined. For example, data permissions can be directly divided into three levels, where the first level corresponds to the first type of data permission mentioned above, and the second and third levels together correspond to the second type of data permission mentioned above. Moreover, the second and third levels correspond to the first and second type of configuration entry points, respectively. This application does not limit the specific implementation details.
[0056] In one optional implementation, to facilitate quick and easy permission configuration for special groups such as the elderly and children, the current user's authorization information can be obtained through the following method:
[0057] If the user type of the current user is determined to be a preset type based on the user's identity characteristics, pre-configured user authorization information corresponding to the preset type can be obtained. For example, if the user type of the current user is determined to be a preset type based on the user's identity characteristics, pre-configured user authorization information corresponding to the preset type can be obtained. The preset type can be a user type whose age is less than a first age threshold and / or whose age is greater than a second age threshold, where the first age threshold is less than the second age threshold. For example, the first age threshold can be 8, and the second age threshold can be 60. Considering that the elderly and children usually do not set permission information themselves, in order to simplify the operation costs for the elderly and children and to improve their data security and prevent user data leakage, user authorization information corresponding to the preset type can be pre-configured. For example, in the user authorization information corresponding to the preset type, certain permissions that may lead to the leakage of user personal data, such as photo-taking permission, can be permanently disabled to avoid personal safety issues caused by the leakage of a child's portrait information.
[0058] In one optional implementation, the current user's authorization information includes at least one of the following: access permissions for preset applications on the terminal device, terminal location access permission, device data access permission for the terminal device, and user data access permission. For example, the access permissions for preset applications are used to limit whether various applications on the phone support access to various data permissions. Terminal location access permission is used to authorize applications to locate the terminal. Device data access permission is used to authorize applications to access various types of data stored on the device, such as contact data and camera data. User data access permission is used to authorize applications to access the user's personal data, such as the user's exercise data and heart rate data.
[0059] To facilitate understanding, an example is used below to describe the permission management method in this embodiment.
[0060] With the widespread adoption of smart devices such as smartphones, tablets, wearable devices, and in-vehicle computers, authorized users (users who own these devices) consent to certain privacy permissions. These permissions allow the smart devices to collect and use the user's private information, including but not limited to facial recognition, fingerprints, body movement, location data, audio recording, photography, and video recording. However, when a smart device is temporarily lent to family, friends, or colleagues, they may not consent to these permissions. However, current technologies often maintain the same level of privacy permissions regardless of the user, potentially leading to the leakage of personal information by non-users like family, friends, or colleagues.
[0061] For example, some related technologies do not adequately protect the privacy of non-owner users. When non-owner users use smart terminals, there are no intelligent prompts for them to authorize privacy permissions; instead, their private information is directly collected and used, including but not limited to facial recognition, fingerprints, body movements, location, audio recording, photography, and video recording, which can easily lead to the leakage of non-owner users' privacy. Therefore, it is evident that there is currently a lack of privacy and security protection solutions specifically for non-owner users.
[0062] To address the aforementioned issues, this example pre-collects the facial features or other identity characteristics of the device owner. During use of the smart terminal, if a face other than the owner's is detected, the user is prompted again for authorization, and the authorization status is recorded. Until the user changes, privacy permissions are controlled according to the current user's privacy authorization. This solution avoids legal risks related to privacy security, protects the privacy of non-owners, improves the user experience for non-owners, demonstrates the superiority of smart terminals, and enhances the product's market competitiveness. Privacy is a fundamental right for everyone, and protecting personal privacy helps safeguard individual rights. With the widespread adoption of smart terminals such as mobile phones, tablets, wearable devices, and in-vehicle computers, it is crucial to ensure that people enjoy the convenience of technology without being troubled by privacy violations. In the information age, data has become a vital resource, making the protection of personal privacy a crucial aspect of data security and information protection. Furthermore, protecting privacy is a means of upholding personal dignity; everyone has the right to protect their privacy from infringement. Privacy violations can lead to embarrassment, anxiety, or discrimination. Privacy protection helps maintain healthy social relationships. Respect for others' privacy is the foundation of interpersonal relationships based on trust and respect. Protecting privacy helps maintain boundaries between individuals and their families, friends, and colleagues. The Ministry of Industry and Information Technology's new network access standards are increasingly setting higher requirements for privacy protection and security of smart devices, and are gradually developing more comprehensive regulations.
[0063] This example protects the privacy of non-owners, preventing their private information from being directly collected and used, thus avoiding privacy leaks and making up for the previous lack of privacy protection for non-owners.
[0064] In this example, identity verification needs to be automatically triggered at an appropriate time to intelligently identify whether the current user is not the owner of the device. The timing for triggering identity verification can be: when the screen of the mobile phone or other smart terminal is turned on. During the screen-on process, when the front-facing camera detects a face entering directly in front and the face distance reaches a threshold, recognition is performed. The threshold is defined to avoid interference from the surrounding environment, ensuring that the face being recognized is that of a valid user of the smart terminal.
[0065] In addition, to control power consumption, facial recognition and other identification methods can also adopt a timed triggering method, allowing users to customize the time interval. Besides facial recognition, smart terminals can also use other biometrics for identification, with the basic process being the same. Examples include voiceprints and fingerprints; smartwatches can use heart rate and blood pressure readings.
[0066] In addition, artificial intelligence technology can be used to analyze users' usage habits, including but not limited to physical activities, frequently used functions, usage time, and location. If the usage does not match the user's habits, it can be assumed that the user is not the owner and an identity verification operation can be automatically triggered.
[0067] In addition, in this example, privacy permissions are pre-categorized into three levels, with different levels corresponding to different authorization and management methods. This ensures the owner's control over the smart terminal and protects their privacy.
[0068] The first level of permissions allows authorization only for the phone's owner. This level is designed to ensure the owner's basic control and privacy, preventing the leakage of critical information when used by someone other than the owner. First-level permissions include, but are not limited to: obtaining phone identification information and accessing the calendar. These permissions relate to the security of personal data within the phone; therefore, they can be set to allow authorization only for the phone's owner, corresponding to the first type of data permissions mentioned above.
[0069] Level Two: Authorization is possible for non-owner users, but requires authorization from the owner. The authorization process involves monitoring the owner's face or fingerprint information. This level ensures that the owner can selectively control the smart device's status while the user is not directly involved. Level Two permissions include, but are not limited to: location, call logs, SMS, and MMS. The privacy of these permissions is lower than Level One; therefore, authorization can be granted to non-owner users, but for data security reasons, authorization from the owner is required. Level Two permissions correspond to the permissions in the second category of data permissions mentioned above, specifically the permissions associated with the second category of configuration entry points.
[0070] Level 3: Authorization is granted by non-owners. This level of permissions primarily concerns non-owner behaviors that the owner does not need to concern themselves with or control. Non-owners can independently authorize privacy permissions for data generated during use. Level 3 permission information includes, but is not limited to: face, fingerprint, body movement, audio recording, photography, video recording, nearby connected devices (WLAN, Bluetooth, car, etc.), browser history, images, audio, and video. Level 3 permission information corresponds to the permissions in the first type of configuration entry point within the second type of data permissions mentioned above.
[0071] Additionally, when a child or elderly person is detected as a non-owner user, a default recommended privacy permission combination can be provided for them. If such users need to change the permission combination later, it can be dynamically adjusted. Furthermore, the owner user can flexibly adjust the permission level division method to avoid non-owners being unable to use certain functions due to restrictions on some privacy permissions.
[0072] In addition, to facilitate easier use of the terminal device for non-owner users, this example also supports owner change operations. This allows a non-owner user to be temporarily authorized as the new owner. For example, during an owner change, a non-owner user, with the original owner's authorization, can update the owner's facial information, effectively becoming the new owner. Furthermore, when temporarily authorizing an owner, the non-owner user needs to create a temporary owner user with the original owner's privacy permissions and record their facial information. This temporary owner user can be deleted later as needed.
[0073] Figure 2 The flowchart of this access control method is shown, as follows: Figure 2 As shown, this permission management method includes the following steps:
[0074] Step S201: If the identity recognition conditions are met, obtain the current user's identity feature information on the terminal device.
[0075] The identification criteria can be any of the conditions mentioned above. In this example, the user's facial information is collected in advance after informing the user and obtaining their consent. Then, feature extraction and analysis are performed on the user's facial information, and the data is stored in the user's facial data storage module.
[0076] In daily use, the system initially determines whether the current user is the owner of the device based on facial contours. If it is determined that the current user is not the owner, the system prompts the user to collect and store facial information. If the user agrees, facial information is collected; if the user does not agree, facial information is not collected, and no further authorization of various privacy permissions is granted.
[0077] Step S202: Determine whether the current user's identity feature information matches the pre-stored identity feature information of authorized users.
[0078] If the user agrees, the collected facial information will be matched with the owner's facial information. If the matching degree threshold is met, the person is considered to be the owner; otherwise, the person is considered not to be the owner.
[0079] Step S203: If there is no match, query the pre-stored authorization data to see if the current user's authorization information exists.
[0080] If the person is not the owner of the device, the system can query the facial data and privacy permission storage module of the non-owner to determine whether the user's authorization information exists in the pre-stored authorization data.
[0081] Furthermore, if a match is found, the process will proceed directly based on the user authorization information already set by the authorized user. Consequently, the device permission information of the terminal device will remain unchanged and will not require updating. Therefore, if it is the owner of the device, the user can continue to use it according to the privacy permissions already agreed upon by the owner.
[0082] Step S204: If it does not exist, display permission configuration prompt information, respond to the permission configuration instruction triggered by the permission configuration prompt information, obtain the current user's user authorization information, and update the current user's user authorization information into the authorization data.
[0083] If the user is not the non-owner user whose privacy permissions have been recorded, the user will be prompted to authorize the privacy permissions, and the authorization result will be recorded in the non-owner's facial data and privacy permission storage module for subsequent matching.
[0084] Step S205: If it exists, retrieve the current user's authorization information from the pre-stored authorization data.
[0085] If the current user's identity characteristics meet the matching threshold with the pre-stored identity characteristics of non-owner users, then the user is considered a non-owner user whose privacy permissions have been recorded, and the privacy permissions that the non-owner user has agreed to are taken into account.
[0086] Step S206: Update the device permission information of the terminal device according to the current user's user authorization information.
[0087] Specifically, the device permission information of the terminal device is updated to match the current user's authorization information. For example, based on the correspondence between various applications and permissions contained in the user authorization information, access to certain types of permissions for certain applications can be disabled or enabled for certain applications.
[0088] Therefore, this example demonstrates that when a smart device is temporarily lent to relatives, friends, or colleagues, the privacy permissions of the non-owner can be managed to protect their privacy. Its application scenarios can include at least the following two:
[0089] Scenario 1: A child at home is using an adult's mobile phone.
[0090] In this scenario, the child using the phone is not the owner. When it's detected that a child is using the phone, a pop-up window is displayed to re-authorize their privacy permissions. This allows the user to disable privacy permissions such as recording, taking photos, and recording videos, preventing unauthorized applications from obtaining the child's voiceprint, facial features, and other characteristic information. Otherwise, based on this characteristic information, artificial intelligence could synthesize it, potentially leading criminals to falsely claim the child has been kidnapped or impersonate the child to defraud parents. This scenario seriously threatens the safety of family members and their property. This invention avoids such risks by protecting the child's privacy. In this scenario, the child can be directly identified as a user of a preset type, automatically obtaining pre-configured user authorization information corresponding to that preset type. This facilitates configuring preset privacy permission combinations for special groups such as children and the elderly.
[0091] Scenario 2: Borrowing a friend's smartwatch
[0092] Smartwatches generate numerous records for outdoor activities, including activity tracking (speed, steps, calories burned, activity trajectory, etc.) and health monitoring (heart rate, blood pressure, blood oxygen saturation, etc.). However, this information falls under the category of personal privacy and is related to two privacy permissions: physical activity and location. If paired with a phone via Bluetooth, it may also involve the following privacy permission: nearby connected devices (Bluetooth). Location permission requires authorization from the owner, indicating that the owner agrees not to record the location of non-owners. This allows the borrower to prevent the owner from seeing their personal activity records, preserving necessary privacy and providing a more user-friendly experience for non-owners, increasing the likelihood of them purchasing the smartwatch after experiencing it.
[0093] For ease of understanding, Figure 3 This example shows a schematic diagram of the structure of a terminal device (such as a smart terminal). Figure 3 As shown, the terminal device in this example includes the following modules:
[0094] (1) Face acquisition module 31: calls the front camera of the smart terminal to collect the user's facial feature data.
[0095] (2) Owner data storage module 32: Stores the collected facial feature data of the owner user. For example, the owner data storage module can be a facial data and privacy permission storage module for the owner, used to store the collected facial data of the owner and the authorized privacy permissions.
[0096] (3) User face data comparison module 33: The collected user face data is matched with the user face data.
[0097] (4) Non-owner data storage module 34: For example, it can be a non-owner face data and privacy permission storage module, used to store the collected non-owner face data and its authorized privacy permissions.
[0098] (5) Non-owner face data comparison module 35: Matches the collected non-owner user face data with the non-owner user face data whose privacy permissions have been recorded.
[0099] Figure 4 The overall flowchart of the above example is shown, combining the various modules included in the terminal device. Figure 4 As shown, the above example specifically includes the following steps:
[0100] Step S401: Collect the current user's facial data through the face acquisition module.
[0101] Step S402: Compare the current user's facial data with the owner user's facial data stored in the owner's facial data storage module.
[0102] Step S403: If the comparison result determines that the current user is the owner user, then proceed with subsequent processing based on the privacy permissions authorized by the owner in the owner data storage module.
[0103] Step S404: If the comparison result determines that the current user is not the owner of the device, then the current user's facial data is compared with the facial data of non-owner users stored in the non-owner facial data storage module.
[0104] Step S405: If the comparison result determines that the current user is a non-owner user whose privacy permissions have been recorded, then proceed with subsequent processing based on the corresponding non-owner authorized privacy permissions in the non-owner data storage module.
[0105] Step S406: If the comparison results determine that the current user is a non-owner user whose privacy permissions have not been recorded, then display a permission configuration prompt message to prompt the current user to configure privacy permissions.
[0106] Step S407: Perform subsequent processing based on the privacy permissions configured by the current user, and store the configured privacy permissions in the non-owner data storage module. In summary, this example, based on facial recognition technology, provides better protection for the privacy of non-owner users in an era where privacy protection is increasingly important, demonstrating significant effectiveness and value. This example is applicable to smart terminals such as mobile phones, tablets, and wearable devices, and is also suitable for in-vehicle computers. This example can protect user privacy, mitigate legal risks, and promote product market penetration.
[0107] Secondly, embodiments of this disclosure provide an electronic device, which includes a memory and a processor; the memory stores a computer program that can be executed by the processor, and when the computer program is executed by the processor, it implements any of the permission management methods of embodiments of this disclosure.
[0108] Figure 5 This is a block diagram of an electronic device provided in an embodiment of the present disclosure.
[0109] Reference Figure 5 This disclosure provides an electronic device, which includes: at least one processor 101; at least one memory 102; and one or more I / O interfaces 103 connected between the processor 101 and the memory 102; wherein the memory 102 stores one or more computer programs that can be executed by the at least one processor 101, and the one or more computer programs are executed by the at least one processor 101 to enable the at least one processor 101 to perform the above-described permission management method.
[0110] Among them, the processor is a device with data processing capabilities, including but not limited to the central processing unit (CPU); the memory is a device with data storage capabilities, including but not limited to random access memory (RAM, more specifically SDRAM, DDR, etc.), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), and flash memory (FLASH); the I / O interface (read-write interface) is connected between the processor and the memory, enabling information exchange between the memory and the processor, including but not limited to the data bus (Bus).
[0111] This disclosure also provides a computer-readable medium having a computer program stored thereon, which, when executed by a processor, implements the above-described permission management method.
[0112] This disclosure also provides a computer program product, which includes a computer program that, when executed by a processor, implements the above-described permission management method.
[0113] Those skilled in the art will understand that all or some of the steps, systems, and devices disclosed above, as functional modules / units, can be implemented as software, firmware, hardware, or suitable combinations thereof.
[0114] In hardware implementations, the division between functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be executed by several physical components working together.
[0115] Some or all of the physical components may be implemented as software executed by a processor, such as a central processing unit (CPU), digital signal processor, or microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit (ASIC). Such software may be distributed on a computer-readable medium, which may include computer storage media (or non-transitory media) and communication media (or transient media). As is known to those skilled in the art, the term computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technique for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media include, but are not limited to, random access memory (RAM, more specifically SDRAM, DDR, etc.), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory (FLASH) or other disk storage; read-only optical disc (CD-ROM), digital versatile disc (DVD) or other optical disc storage; magnetic cartridges, magnetic tapes, disk storage or other magnetic storage; and any other media that can be used to store desired information and can be accessed by a computer. Furthermore, as is known to those skilled in the art, communication media typically contain computer-readable instructions, data structures, program modules, or other data in modulated data signals such as carrier waves or other transmission mechanisms, and may include any information delivery medium.
[0116] This disclosure has disclosed exemplary embodiments, and although specific terminology has been used, it is for general illustrative purposes only and should not be construed as limiting. In some instances, it will be apparent to those skilled in the art that features, characteristics, and / or elements described in conjunction with particular embodiments may be used alone, or in combination with features, characteristics, and / or elements described in conjunction with other embodiments, unless otherwise expressly indicated. Therefore, those skilled in the art will understand that various changes in form and detail may be made without departing from the scope of this disclosure as set forth by the appended claims.
Claims
1. A method for managing access permissions, comprising: If the identity recognition conditions are met, obtain the current user's identity feature information on the terminal device; If the current user's identity feature information does not match the pre-stored identity feature information of authorized users, the user authorization information of the current user is obtained; Update the device permission information of the terminal device according to the user authorization information of the current user; wherein the initial state of the device permission information of the terminal device is configured according to the user authorization information of the authorized user.
2. The method according to claim 1, wherein, The identity verification conditions include at least one of the following: The current user's operation behavior is detected to be inconsistent with the pre-stored historical operation behavior of authorized users; The terminal device was detected to switch from a black screen state to a bright screen state. The facial contour information of the current user does not match the facial contour information of the authorized user.
3. The method according to claim 1, wherein, The process of obtaining the current user's authorization information includes: If the user authorization information of the current user is not found in the pre-stored authorization data, a permission configuration prompt message will be displayed; In response to the permission configuration instruction triggered by the permission configuration prompt information, the user authorization information of the current user is obtained and updated to the authorization data.
4. The method according to claim 3, wherein, The display permission configuration prompt information includes: Obtain multiple data permissions included in the set of data permissions supported by the terminal device; Display a permission configuration interface that includes a permission configuration entry; wherein, the permission configuration entry corresponds to the data permission.
5. The method according to claim 4, wherein, Before displaying the permission configuration prompt, the method further includes: in response to the received level setting instruction, dividing the various data permissions contained in the data permission set into at least two permission levels; The permission configuration entry includes at least two types of permission configuration entry corresponding to the at least two permission levels.
6. The method according to claim 5, wherein, The at least two types of permission configuration entry points include: A first type of configuration entry used to trigger permission configuration instructions when the current user's triggering operation is detected; The second type of configuration entry is used to trigger permission configuration instructions when the authorization operation of the authorized user is detected.
7. The method according to claim 4, wherein, Before displaying the permission configuration prompt information, the method further includes: in response to the received type setting instruction, dividing the various data permissions contained in the data permission set into at least two permission types; The at least two permission types include: a first type of data permission corresponding to authorized users, and a second type of data permission corresponding to unauthorized users; and the permission configuration entry corresponds to the second type of data permission.
8. The method according to any one of claims 1-7, wherein, The process of obtaining the current user's authorization information includes: If the user type of the current user is determined to be a preset type based on the current user's identity feature information, the user authorization information of the current user corresponding to the preset type is obtained in advance.
9. The method according to any one of claims 1-7, wherein, The current user's authorization information includes at least one of the following: Access permissions for preset applications on the terminal device, terminal location access permissions, terminal device data access permissions, and user data access permissions.
10. An electronic device comprising a memory and a processor; the memory storing a computer program executable by the processor, wherein the computer program, when executed by the processor, implements the access control method according to any one of claims 1 to 9.
11. A computer-readable medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the access control method according to any one of claims 1 to 9.
12. A computer program product comprising a computer program that, when executed by a processor, implements the access control method according to any one of claims 1 to 9.