Application permission management method and device, electronic equipment and storage medium
By restricting application interactions through application permission mapping, the problem of leakage of sensitive user information in terminal applications is solved, thereby achieving a secure and reliable application environment and improving the user experience.
Patent Information
- Application Number
- CN202410962326.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-17
- Publication Date
- 2026-01-20
AI Technical Summary
In existing technologies, terminal applications engage in irregular practices when acquiring users' sensitive personal information, leading to a reduction in user data privacy and security. Existing user data security and privacy mechanisms cannot fully cover all possible acquisition methods.
By using application permission mapping relationships, interactions between applications are restricted. In particular, when the permission status of the second application is invisible or not installed, the first application is not allowed to interact with the second application. This includes displaying a prompt window for interaction requests to obtain user authorization, and automatically setting the permission status to visible in specific application cases.
It effectively reduces the possibility of unauthorized applications obtaining users' sensitive personal information, improves user data transparency, creates a safe and trustworthy application environment, and enhances user experience.
Smart Images

Figure CN121365408A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of terminals, and in particular, to an application permission management method and device, an electronic device, and a storage medium. BACKGROUND
[0002] With the continuous development of terminal technology, the number and types of terminal applications are becoming more and more abundant, making it difficult to guarantee the standardization of terminal applications. In order to create a safe and reliable application use environment for users and reduce the possibility of non-standard applications obtaining user personal sensitive information, it is necessary to continue to improve the user data security and privacy mechanism of terminal devices. SUMMARY
[0003] To overcome the problems in the related art, the present disclosure provides an application permission management method and device, an electronic device, and a storage medium.
[0004] According to a first aspect of an embodiment of the present disclosure, an application permission management method is provided, the method comprising:
[0005] receiving an interaction request of a first application, the interaction request being used to request interaction with a second application, and the interaction request being any one of a plurality of types of interaction requests;
[0006] obtaining a permission state of the second application to the first application according to an application permission mapping relationship, the application permission mapping relationship comprising a permission state of the second application to each of other installed applications;
[0007] if the permission state of the second application to the first application is an invisible state, or the second application is not included in the application permission mapping relationship, the first application is not allowed to interact with the second application.
[0008] In an exemplary embodiment, when the first application is not allowed to interact with the second application, the method further comprises:
[0009] if the permission state of the second application to the first application is an invisible state, determining a target processing strategy according to a type of the interaction request.
[0010] In an exemplary embodiment, the determining of the target processing strategy according to the type of the interaction request comprises:
[0011] if the type of the interaction request is starting an application interface of the second application, displaying a first window, the first window comprising an allow option and a reject option;
[0012] in response to receiving a selection instruction of the user for the allow option, starting the application interface of the second application.
[0013] In an example embodiment, the determining the target processing strategy according to the type of the interaction request comprises:
[0014] If the type of the interaction request is to acquire application information of the second application, a second window is displayed, the second window comprising an allow option and a reject option;
[0015] In response to receiving a selection instruction of the user for the allow option, the first application is allowed to acquire the application information of the second application;
[0016] The application information comprises at least one of application service, application data, application package information and application permission information.
[0017] In an example embodiment, the determining the target processing strategy according to the type of the interaction request comprises:
[0018] If the type of the interaction request is to send a broadcast to the second application, the first application is allowed to send the broadcast to the second application.
[0019] In an example embodiment, the method further comprises:
[0020] If the permission state of the second application to the first application is a visible state, the first application is allowed to interact with the second application.
[0021] In an example embodiment, the method further comprises:
[0022] If a third application that has been installed is a target application, the permission state of the third application to other installed applications in the application permission mapping relationship is set to a visible state.
[0023] The target application is one of a system application, a system signature application and a third-party application with a high correlation usage rate.
[0024] According to a second aspect of the embodiments of the present disclosure, an application permission management apparatus is provided, the apparatus comprising:
[0025] A detection module configured to receive an interaction request of a first application, the interaction request being used to request interaction with a second application, and the interaction request being any one of a plurality of types of interaction requests;
[0026] An acquisition module configured to acquire a permission state of the second application to the first application according to an application permission mapping relationship, the application permission mapping relationship comprising a permission state of a second application to each installed application;
[0027] The management module is configured to disallow the first application to interact with the second application if the second application has an invisible state for the first application or the second application is not included in the application permission mapping relationship.
[0028] According to a third aspect of an embodiment of the present disclosure, an electronic device is provided, comprising:
[0029] a processor;
[0030] a memory for storing processor-executable instructions;
[0031] The processor is configured to perform the method as described in the first aspect of the embodiments of the present disclosure.
[0032] According to a fourth aspect of an embodiment of the present disclosure, a non-transitory computer-readable storage medium is provided, when instructions in the storage medium are executed by a processor of an electronic device, the electronic device is enabled to perform the method as described in the first aspect of the embodiments of the present disclosure.
[0033] The above method of the present disclosure has the following beneficial effects: the application permission mapping relationship is used to limit the interaction between applications, and when the second application has an invisible state for the first application and the electronic device does not install the second application, the first application is disallowed to interact with the second application, so that the first application cannot directly or indirectly obtain any information of the second application without permission, the possibility of non-standard application obtaining user's personal sensitive information is reduced, the user data transparency is improved, a safe and reliable application using environment is created for the user, and the user experience is improved.
[0034] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF DRAWINGS
[0035] The accompanying drawings, which are incorporated into the specification and constitute a part of the specification, illustrate embodiments consistent with the present disclosure and, together with the specification, serve to explain the principles of the present disclosure.
[0036] Figure 1 is a flowchart of an application permission management method according to an exemplary embodiment;
[0037] Figure 2 is a schematic diagram of system components according to an exemplary embodiment;
[0038] Figure 3 is a schematic diagram of a first window and a second window according to an exemplary embodiment;
[0039] Figure 4is a block diagram of an application permission management apparatus according to an exemplary embodiment;
[0040] Figure 5 is a block diagram of an electronic device according to an exemplary embodiment. DETAILED DESCRIPTION
[0041] The exemplary embodiments will be described in detail below with reference to the attached drawings. In the following description, the same numbers are used to denote the same elements, and a repeated description will be omitted. The embodiments described in the following exemplary embodiments do not represent all the embodiments consistent with the present disclosure. Rather, they are merely examples of devices and methods consistent with some aspects of the present disclosure as detailed in the appended claims.
[0042] In some embodiments, in order to achieve better and more accurate advertising pushing effect, the terminal application usually analyzes the user's preferences by continuously labeling user behavior, but since the user behavior that can be labeled by a single application platform is limited, in order to obtain more user behavior, it is usually selected to obtain user behavior from other application platforms, for example, a certain third-party application usually analyzes user preferences by obtaining the application list installed by the user on the device, if it is found that the user has installed multiple game applications, it can be inferred that the user may like to play games, etc. However, the way of obtaining user behavior from other application platforms can cause user personal sensitive information leakage, resulting in poor user data privacy and reduced security.
[0043] In related technologies, in order to prevent an application from obtaining user personal sensitive information from other application platforms, the user data security and privacy mechanism in the terminal device includes the following aspects: building a terminal application detection platform to automatically detect terminal applications to detect the data collection, permission acquisition and other behaviors of terminal applications; terminal hardware security mechanism, such as using high-performance system on chip (SoC) and trusted execution environment (TEE) technology to enhance the security of user data; secure and private local deployment, such as edge computing, privacy computing, etc., to complete the collection and processing of data as much as possible on the terminal local, without data backhaul.
[0044] However, the user data security and privacy mechanism in the related technologies cannot cover all possible application behaviors that obtain user personal sensitive information, and there are still some non-standard applications that obtain user personal sensitive information through various indirect ways, therefore, it is necessary to continue to improve the user data security and privacy mechanism of the terminal device.
[0045] In the exemplary embodiments of the present disclosure, in order to overcome the problem of user personal sensitive information leakage in the related art, an application permission management method is provided, including: receiving an interaction request of a first application, the interaction request being used to request interaction with a second application, and the interaction request being any one of a plurality of types of interaction requests; obtaining a permission state of the second application to the first application according to an application permission mapping relationship, the application permission mapping relationship including a permission state of the second application to each of other installed applications; and if the permission state of the second application to the first application is an invisible state, or the second application is not included in the application permission mapping relationship, the first application is not allowed to interact with the second application. In the method, the first application cannot directly or indirectly obtain any information of the second application without permission, which can reduce the possibility of non-standard application obtaining user personal sensitive information, improve user data transparency, create a safe and reliable application use environment for users, and improve user experience.
[0046] In the exemplary embodiments of the present disclosure, an application permission management method is provided, Figure 1 is a flowchart of an application permission management method according to an exemplary embodiment, as shown in Figure 1 including the following steps:
[0047] Step S101, receiving an interaction request of a first application, the interaction request being used to request interaction with a second application, and the interaction request being any one of a plurality of types of interaction requests;
[0048] Step S102, obtaining a permission state of the second application to the first application according to an application permission mapping relationship, the application permission mapping relationship including a permission state of the second application to each of other installed applications;
[0049] Step S103, if the permission state of the second application to the first application is an invisible state, or the second application is not included in the application permission mapping relationship, the first application is not allowed to interact with the second application.
[0050] The application permission management method in the embodiments of the present disclosure is applied to electronic devices, including smart phones, tablets, personal computers, smart wearable devices, smart screens, smart Internet of Things devices, smart car machines, and electronic devices with application running functions. In some possible implementations, the application permission management method in the embodiments of the present disclosure is applied to the operating system of the electronic device.
[0051] In step S101, the first application is any application installed in the electronic device, and the second application is any application, which can be an application installed in the electronic device or an application not installed in the second application, and the second application is different from the first application. The interaction request of the first application is used to request interaction with the second application. The interaction request can be any request capable of interacting with the second application, and the type of the interaction request is not limited. The interaction request can be direct interaction with the second application or can be obtaining relevant information of the second application through the operating system. For example, the interaction request can be calling a service from the second application, or obtaining data from the second application, or requesting the operating system to start an application interface of the second application, or obtaining network connection information of the second application from the operating system, etc. The second application can be a single application, for example, obtaining application data of application B; or the second application can be multiple applications, for example, obtaining application list information of all installed applications on other electronic devices. In some possible implementation manners, the first application interacts with the second application by calling an interface provided by the operating system of the electronic device. Therefore, when the electronic device detects that the first application calls a system interface capable of interacting with the second application, it is determined that the interaction request of the first application is received.
[0052] In an example, the operating system detects that the first application calls the system interface startActivity to start an application interface of the second application, or detects that the first application calls the system interface ContentResolver#query to query data of the second application, or detects that the first application calls the system interface queryIntentContentProviders to query a network connection provider to indirectly obtain application list information of installed applications, and it is determined that the interaction request of the first application is received.
[0053] In some possible implementation manners, Figure 2 is a schematic diagram of system components according to an example embodiment, as Figure 2 As shown in the figure, the system interface called by each application is checked and filtered by the application filter MiuiAppsFilter component in the system application management (System Apps) core operating system service (Core OS Services). If the system interface involves direct interaction with other applications or involves processing operations on information of other applications, it is determined that the interaction request of the current application is received.
[0054] In step S102, the application permission mapping relationship includes the permission state of each installed application to the second application, which can be default or set by the user, and the application permission mapping relationship is updated in real time according to the user operation, such as listening to the user's authorization or revocation of permission operation, the user's installation or uninstallation of the application operation. The permission state includes a visible state and an invisible state, the visible state means that the opposite application can interact, and the invisible state means that the opposite application cannot interact. The application permission mapping relationship can be a mapping relationship table for recording the permission state of each installed application to the second application, as shown in Table 1, the column is the application initiating the interaction request, that is, the first application, and the column is the application whose behavior is requested to interact, that is, the second application, one of the applications 2-6 or other applications.
[0055] Application 1 Application 2 Application 3 Application 4 Application 5 Application 6 Application 1 Visible Not visible Not visible Not visible Not visible Not visible
[0056] Table 1
[0057] In order to improve the running speed, the application permission mapping relationship can also be a mapping relationship table for recording the permission state of each installed application to the second application, as shown in Table 2, the column is the application initiating the interaction request, that is, one of the applications 1-5, and the column is the application whose behavior is requested to interact, that is, the second application, one of the applications 2-6 or other applications. The permission state of the second application to the first application is matched from the application permission mapping relationship.
[0058] Application 1 Application 2 Application 3 Application 4 Application 5 Application 6 Application 1 Visible Not visible Not visible Not visible Not visible Not visible Application 2 Not visible Visible Not visible Not visible Not visible Not visible Application 3 Visible Visible Visible Visible Visible Visible Application 4 Visible Not visible Not visible Visible Visible Not visible Application 5 Visible Not visible Not visible Visible Visible Not visible
[0059] Table 2
[0060] In some possible embodiments, such as Figure 2As shown, the permission state of the second application to the first application is saved and adjusted by an application behavior service AppOpsService component and a permission management service PermissionManagerService component in an application management (Apps) core service, the permission state of each installed application to other installed applications is saved by an application behavior service AppOpsServiceImpl component in a core operating system service, and the permission state of the second application to the first application is queried by an application filter MiuiAppsFilter component in the core operating system service from the application behavior service AppOpsService component in the core service or the application behavior service AppOpsServiceImpl component in the core operating system service. The authorization or de-authorization operation of the user, the operation of installing or uninstalling the application is listened to by the application behavior service AppOpsService component in the core service and the application behavior service AppOpsServiceImpl component in the core operating system service, so as to dynamically update the application permission mapping relationship and ensure that the application permission mapping relationship is the latest.
[0061] In step S103, if the permission state of the second application to the first application is queried from the permission state mapping relationship and is in an invisible state, the first application is not allowed to interact with the second application, for example, an application interface of the second application is not allowed to be started or relevant information of the second application is not allowed to be returned to the first application; if the second application does not exist in the permission state mapping relationship, it means that the second application is not installed in the electronic device, and the first application is also not allowed to interact with the second application. When the permission state of the second application to the first application is in the invisible state and the second application is not installed in the electronic device, the first application is not allowed to interact with the second application, so the first application cannot directly or indirectly obtain any information of the second application, and the possibility of obtaining personal sensitive information of the user by an unstandard application can be reduced.
[0062] In some embodiments, if the permission state of the second application to the first application is in a visible state, the first application is allowed to interact with the second application. If the permission state of the second application to the first application is queried from the permission state mapping relationship and is in the visible state, the first application is allowed to interact with the second application, for example, an application interface of the second application is allowed to be started or relevant information of the second application is allowed to be returned to the first application.
[0063] In an example, as shown in Table 2, if the first application is application 4 and the second application is application 2, it is obtained from the permission state mapping relationship that the permission state of application 2 to application 4 is invisible state, and then application 4 is not allowed to interact with application 1; if the first application is application 4 and the second application is application 8, the permission state mapping relationship does not exist application 8, and then application 8 is not allowed to interact with application 1; if the first application is application 4 and the second application is application 1, it is obtained from the permission state mapping relationship that the permission state of application 1 to application 4 is visible state, and then application 4 is allowed to interact with application 1.
[0064] In some embodiments, when the first application is not allowed to interact with the second application, a prompt information is displayed, the prompt information is used to indicate that the second application cannot be interacted with, the prompt information provides visual feedback for the user that the first application is not allowed to interact with the second application, and the content of the prompt information can be the same as the content of the interaction request. For example, the content of the interaction request is to request to obtain data of the second application, and the content of the prompt information can be that the data of the second application cannot be obtained.
[0065] In the exemplary embodiments of the present disclosure, when any interaction request of the first application initiated to interact with the second application is received, the interaction between the applications is limited by the application permission mapping relationship, the permission state of the second application to the first application is obtained from the application permission mapping relationship, and when the permission state of the second application to the first application is invisible state and the electronic device does not install the second application, the first application is not allowed to interact with the second application, that is, in the case of no permission, whether the second application is installed in the electronic device or not, the feedback result of the interaction request is the same. Therefore, the first application cannot directly or indirectly obtain any information of the second application in the case of no permission, the possibility of non-standard application obtaining user personal sensitive information can be reduced, the user data transparency can be improved, a safe and reliable application use environment can be created for the user, and the user use experience can be improved.
[0066] In some embodiments, when the first application is not allowed to interact with the second application, the above embodiments further include the following steps:
[0067] If the permission state of the second application to the first application is invisible state, a target processing strategy is determined according to the type of the interaction request.
[0068] The system interface of the plurality of interaction functions is pre-set in the operating system of the electronic device, the type of the interaction request is determined according to the function of the system interface called by the first application, one type of interaction request can correspond to one system interface, or one type of interaction request can correspond to a plurality of system interfaces, and the actual demand is set. When the permission state of the second application to the first application is the invisible state, the processing strategies corresponding to the system interfaces called by the second application are the same or different, for example, a plurality of system interfaces with the same processing strategy are determined as the same type of interaction request.
[0069] In some embodiments, according to the type of the interaction request, the target processing strategy is determined, including the following three cases:
[0070] First, if the type of the interaction request is to start the application interface of the second application, a first window is displayed, the first window includes an allow option and a reject option; in response to receiving a selection instruction of the user for the allow option, the application interface of the second application is started.
[0071] If the function of the system interface called by the first application is to start the application interface of the second application, for example, the system interface startactivity or startActivityForResult is called, the request is jumped from the application interface of the first application to the application interface of the second application, and the first window is displayed. The first window can be a pop-up window on the upper layer of the first application, the first window is used to prompt the user whether to authorize the first application to start the application interface of the second application, and the first window includes the allow option and the reject option for the user to select whether to authorize. If a selection instruction of the user for the allow option is received, the application interface of the second application is started; if a selection instruction of the user for the reject option is received, prompt information is displayed, and the prompt information is used to indicate that the application interface of the second application cannot be started. The selection instruction can be any one of a click operation, a voice operation, or other user operations.
[0072] Second, if the interaction request is to obtain the application information of the second application, a second window is displayed, the second window includes an allow option and a reject option; in response to receiving a selection instruction of the user for the allow option, the first application is allowed to obtain the application information of the second application.
[0073] The application information includes at least one of application service, application data, application package information, and application permission information.
[0074] If the function of the system interface called by the first application is to obtain application information of the second application, the second window is displayed, and the second window can be a pop-up window on the upper layer of the first application. The first window is used to prompt the user whether to authorize the first application to obtain the application information of the second application, and the second window includes an allow option and a reject option for the user to select whether to authorize. If a selection instruction of the user for the allow option is received, the application information of the second application is allowed to be obtained. If a selection instruction of the user for the reject option is received, prompt information is displayed, and the prompt information is used to indicate that the application information of the second application cannot be obtained.
[0075] The selection instruction can be any one of a click operation, a voice operation or other user operations.
[0076]
[0077]
[0078] Table 3
[0079] In an example, the system interfaces shown in Table 3 are different in specific functions, but the functions of each system interface are to obtain application information of the second application, and the application information includes at least one of application services, application data, application package information and application permission information.
[0080] For the above two cases, in some possible implementations, in response to receiving a selection instruction of the user for the allow option, the first window or the second window further includes a single-time allow option and an always allow option. In response to receiving a selection instruction of the user for the always allow option, the application permission mapping relationship is updated, and the permission state of the second application to the first application is modified to a visible state. In response to receiving a selection instruction of the user for the single-time allow option, when the interaction request of the first application is received again, the processing manner is the same as this time.
[0081] In an example, if the function of the system interface called by the application A is to start the application interface of the application B, and the permission state of the application B to the application A in the application permission mapping relationship is an invisible state, Figure 3 is a schematic view of the first window and the second window according to an example embodiment, as Figure 3As shown, the first window and the second window are both pop-up windows displayed on the upper layer of the application A. The pop-up content of the first window in Figure a displays the text information "whether to allow the application A to start the application B", and the allow option and the reject option. The pop-up content of the first window in Figure b displays the text information "whether to allow the application A to obtain the application information of the application B", and the allow option and the reject option. When the user clicks the allow option, both the windows display the single-time allow option and the always allow option, and the single-time allow option is selected by default. If the user clicks the always allow option, the first window corresponds to jump to the application B, and the second window corresponds to obtain the application information of the application B. At the same time, both the windows correspond to modify the permission state of the application B to the application A in the application permission mapping relationship to the visible state.
[0082] In some possible implementation manners, in the above two cases, in response to the selection instruction of the user for the reject option, a prompt information is displayed. The prompt information is used to indicate that the interaction with the second application cannot be performed. The prompt information provides visual feedback for the user that the first application is not allowed to interact with the second application. For example, the content of the prompt information in the first case can be that the second application cannot be started, and the content of the prompt information in the second case can be that the application information of the second application cannot be obtained.
[0083] In this embodiment, the user is provided with a quick control mode of the application permission through the first window or the second window in the case where the user is not authorized, which can avoid affecting the normal use of the application.
[0084] Thirdly, if the interaction request is to send a broadcast to the second application, the first application is allowed to send the broadcast to the second application.
[0085] If the function of the system interface called by the first application is to send a broadcast to the second application, for example, the system interface sendBroadcast is called, the request occurs to the second application, and at this time, the function is not affected, and the first application is allowed to send the broadcast to the second application.
[0086] In this embodiment, the broadcast sending is not affected in the case where the user is not authorized, which can avoid affecting the normal use of the application.
[0087] In some possible implementation manners, as Figure 2As shown, all application installation information, i.e. application list information, is saved by an application management service PackageManagerService component in the application management core service, application interaction, such as page jump, broadcast sending, and pulling up a background service, is performed by an activity management service ActivityManagerService component in the application management core service, and a confirmation popup window in a permission controller PermissionController component in a Cloud core application service (Core Apps) is started by an associated start check service WakePathChecker component in the core operating system service, as a first window or a second window.
[0088] In some embodiments, if the installed third application is the target application, the permission state of the third application to other installed applications in the application permission mapping relationship is set to a visible state.
[0089] The target application is one of a system application, a system signature application, and a third-party application with a high associated usage rate.
[0090] The third application is any installed application in the electronic device, the target application can be a system application, i.e. an application provided by the operating system, such as a system camera, a system clock, etc., can be a system signature application, i.e. a signature application of the operating system, or can be a third-party application with a high associated usage rate, i.e. an application that needs to be frequently associated with and started, such as a payment application. If the third application is the target application, the permission state of the third application to other installed applications in the permission mapping relationship is set to a visible state when the user does not set the permission state. This embodiment can avoid affecting the normal use of the application when the user does not timely set the permission state.
[0091] In some possible implementation manners, as shown in Figure 2 As shown, a rule management RuleManager component in the core application service sets the permission state of a specific application to other installed applications in the application filter MiuiAppsFilter component in the core operating system service through a security management service SecurityManagerService component in the core operating system service.
[0092] In an exemplary embodiment of the present disclosure, an application permission management apparatus is provided, Figure 4 is a block diagram of an application permission management apparatus according to an exemplary embodiment, as shown in Figure 4 As shown, the application permission management apparatus comprises:
[0093] The detection module 401 is configured to receive an interaction request of a first application, the interaction request being used to request an interaction with a second application, and the interaction request being any one of a plurality of types of interaction requests.
[0094] The acquisition module 402 is configured to acquire a permission state of the second application to the first application according to an application permission mapping relationship, the application permission mapping relationship including a permission state of the second application to each of other installed applications.
[0095] The management module 403 is configured to, if the permission state of the second application to the first application is an invisible state, or the second application is not included in the application permission mapping relationship, disallow the first application to interact with the second application.
[0096] In an example embodiment, when the first application is disallowed to interact with the second application, the management module 403 is further configured to:
[0097] If the permission state of the second application to the first application is the invisible state, determine a target processing strategy according to a type of the interaction request.
[0098] In an example embodiment, the management module 403 is further configured to:
[0099] If the type of the interaction request is to start an application interface of the second application, display a first window, the first window including an allow option and a reject option.
[0100] In response to receiving a selection instruction of the user for the allow option, start the application interface of the second application.
[0101] In an example embodiment, the management module 403 is further configured to:
[0102] If the type of the interaction request is to acquire application information of the second application, display a second window, the second window including an allow option and a reject option.
[0103] In response to receiving a selection instruction of the user for the allow option, allow the first application to acquire the application information of the second application.
[0104] The application information includes at least one of application service, application data, application package information, and application permission information.
[0105] In an example embodiment, the management module 403 is further configured to:
[0106] If the type of the interaction request is to send a broadcast to the second application, allow the first application to send the broadcast to the second application.
[0107] In an example embodiment, the management module 403 is further configured to:
[0108] If the permission state of the second application to the first application is the visible state, the first application is allowed to interact with the second application.
[0109] In an example embodiment, the obtaining module 402 is further configured to:
[0110] If the third application that has been installed is the target application, the permission state of the third application to other installed applications in the application permission mapping relationship is set to the visible state.
[0111] The target application is one of a system application, a system signature application, and a third-party application with a high correlation usage rate.
[0112] As to the apparatus in the above embodiments, the specific manners in which various modules perform operations have been described in detail in the embodiments of the method, and thus will not be described in detail here.
[0113] Figure 5 is a block diagram of an electronic device 500 according to an example embodiment.
[0114] Referring to Figure 5 , the electronic device 500 can include one or more of the following components: a processing component 502, a memory 504, a power supply component 506, a multimedia component 508, an audio component 510, an input / output (I / O) interface 512, a sensor component 514, and a communication component 516.
[0115] The processing component 502 generally controls the overall operation of the electronic device 500 such as the operations associated with display, phone calls, data communications, camera operations, and recording operations. The processing component 502 can include one or more processors 520 to execute instructions and manipulate data to perform all or a subset of the steps described in the above methods. Moreover, the processing component 502 can include one or more modules to facilitate interaction between the processing component 502 and other components. For example, the processing component 502 can include a multimedia module to facilitate the interaction between the multimedia component 508 and the processing component 502.
[0116] The memory 504 is configured to store various types of data to support operations of the electronic device 500. Examples of these data include instructions for any application or method operating on the electronic device 500, contact data, phonebook data, messages, pictures, videos, and so on. The memory 504 can be implemented by any type of volatile or non-volatile storage devices or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk, or optical disk.
[0117] Power component 506 provides power to various components of the electronic device 500. Power component 506 can include a power management system, one or more power sources, and other components associated with generating, managing, and distributing power for the electronic device 500.
[0118] Multimedia component 508 includes a screen providing an output interface between the electronic device 500 and a user. In some embodiments, the screen can include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen can be implemented as a touch screen to receive an input signal from a user. The touch panel includes one or more touch sensors to sense a touch, a slide, and a gesture on the touch panel. The touch sensor can not only sense a boundary of a touching or a sliding action, but also detect duration and pressure related to the touching or sliding action. In some embodiments, the multimedia component 508 includes a front camera and / or a rear camera. When the electronic device 500 is in an operating mode, such as a shooting mode or a video mode, the front camera and / or the rear camera can receive external multimedia data. Each of the front camera and the rear camera can be a fixed optical lens system or have a focal length and optical zoom capability.
[0119] Audio component 510 is configured to output and / or input audio signals. For example, the audio component 510 includes a microphone (MIC) configured to receive external audio signals when the electronic device 500 is in an operating mode, such as a call mode, a recording mode, and a voice recognition mode. The received audio signals can be further stored in the memory 504 or transmitted via the communication component 516. In some embodiments, the audio component 510 also includes a speaker for outputting audio signals.
[0120] I / O interface 512 provides an interface between the processing component 502 and peripheral interface modules, which can be a keyboard, a click wheel, a button, and the like. The buttons can include, but are not limited to, a home button, a volume button, a start button, and a lock button.
[0121] The sensor component 514 includes one or more sensors for providing status assessments for various aspects of the electronic device 500. For example, the sensor component 514 can detect an open / closed position of the electronic device 500, relative positioning of components of the electronic device 500, such as a display and a keypad of the electronic device 500, a change in position of the electronic device 500 or a component of the electronic device 500, presence or absence of user contact with the electronic device 500, orientation or acceleration / deceleration / g-force and temperature of the electronic device 500. The sensor component 514 can include an optical sensor for detecting ambient light, a proximity sensor configured to detect proximity of an object, a motion sensor configured to detect motion of the electronic device 500, a temperature sensor configured to detect temperature of the electronic device 500, a humidity sensor configured to detect humidity of the electronic device 500, an acceleration sensor configured to detect an acceleration of the electronic device 500, a gyroscope sensor configured to detect a rotation of the electronic device 500, a magnetic sensor configured to detect a magnetic field of the electronic device 500, a pressure sensor configured to detect pressure of the electronic device 500, or a chemical sensor configured to detect a chemical of the electronic device 500.
[0122] The communication component 516 is configured to facilitate wired or wireless communication between the electronic device 500 and other devices. The electronic device 500 can access a wireless network based on a communication standard, such as WiFi, 2G, or 3G, or a combination thereof. In an example embodiment, the communication component 516 receives a broadcast signal or broadcast related information from an external broadcast management system via a broadcast channel. In an example embodiment, the communication component 516 further includes a Near Field Communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented based on Radio Frequency Identification (RFID) techniques, Infrared Data Association (IrDA) techniques, Ultra-WideBand (UWB) techniques, Bluetooth (BT) techniques, and other techniques.
[0123] In an example embodiment, the electronic device 500 can be implemented using one or more Application Specific Integrated Circuits (ASICs), Digital Signal Processors (DSPs), Digital Signal Processing Devices (DSPDs), Programmable Logic Devices (PLDs), Field Programmable Gate Arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic elements to perform the above-described methods.
[0124] In an example embodiment, a non-transitory computer-readable storage medium including instructions, such as the memory 504 including instructions, is also provided, which can be executed by the processor 520 of the electronic device 500 to perform the above-described methods. For example, the non-transitory computer-readable storage medium can be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disc, and an optical data storage device, etc.
[0125] A non-transitory computer-readable storage medium, when instructions in the storage medium are executed by a processor of an electronic device, enable the electronic device to perform an application permission management method, the application permission management method including any of the above-described methods.
[0126] Other embodiments of the disclosure will be apparent to those skilled in the art from consideration of the specification and practice of the features disclosed herein. It is intended that the specification and examples be considered as exemplary only, with the true scope and spirit of the disclosure being indicated by the following claims.
[0127] It should be understood that the present disclosure is not limited to the precise structures herein described and illustrated in the drawings, and that various modifications and changes can be made without departing from its scope. The scope of the present disclosure is limited only by the claims that follow.
Claims
1. An application permission management method, characterized by, The method comprises: receiving an interaction request of a first application, the interaction request being used to request interaction with a second application, and the interaction request being any one of a plurality of types of interaction requests; obtaining a permission state of the second application to the first application according to an application permission mapping relationship, the application permission mapping relationship comprising a permission state of the second application to each of other installed applications; if the permission state of the second application to the first application is an invisible state, or the second application is not included in the application permission mapping relationship, the first application is not allowed to interact with the second application.
2. The application permission management method of claim 1, wherein, When the first application is not allowed to interact with the second application, the method further comprises: if the permission state of the second application to the first application is an invisible state, determining a target processing strategy according to a type of the interaction request.
3. The application permission management method of claim 2, wherein, The determining of the target processing strategy according to the type of the interaction request comprises: if the type of the interaction request is starting an application interface of the second application, displaying a first window, the first window comprising an allow option and a reject option; in response to receiving a selection instruction of the user for the allow option, starting the application interface of the second application.
4. The application permission management method of claim 2, wherein, The determining of the target processing strategy according to the type of the interaction request comprises: if the type of the interaction request is obtaining application information of the second application, displaying a second window, the second window comprising an allow option and a reject option; in response to receiving a selection instruction of the user for the allow option, allowing the first application to obtain the application information of the second application; wherein the application information comprises at least one of application services, application data, application package information and application permission information.
5. The application permission management method of claim 2, wherein, The determining of the target processing strategy according to the type of the interaction request comprises: if the type of the interaction request is sending a broadcast to the second application, allowing the first application to send the broadcast to the second application.
6. The application permission management method of claim 1, wherein, The method further comprises: if the permission state of the second application to the first application is a visible state, allowing the first application to interact with the second application.
7. The application permission management method of claim 1, wherein, The method further comprises: if a third application that has been installed is a target application, setting a permission state of the third application to other installed applications in the application permission mapping relationship to a visible state; wherein the target application is one of a system application, a system signature application and a third-party application with a high correlation usage rate.
8. An application authority management apparatus characterized by comprising: The apparatus comprises: a detection module configured to receive an interaction request of a first application, the interaction request being used to request interaction with a second application, and the interaction request being any one of a plurality of types of interaction requests; an obtaining module configured to obtain a permission state of the second application to the first application according to an application permission mapping relationship, the application permission mapping relationship comprising a permission state of the second application to each of other installed applications; The management module is configured to, if the permission state of the second application to the first application is an invisible state or the second application is not included in the application permission mapping relationship, disallow the first application to interact with the second application.
9. An electronic device, comprising: Comprise: a processor; a memory for storing processor-executable instructions; wherein the processor is configured to perform the method of any one of claims 1-7.
10. A non-transitory computer-readable storage medium, comprising: When the instructions in the storage medium are executed by the processor of the electronic device, the electronic device can perform the method of any one of claims 1-7.