Information processing method and device, intelligent household appliance debugging device and storage medium
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-21
- Publication Date
- 2026-08-11
AI Technical Summary
[0003]本申请提供了一种信息处理方法、装置、智能家电调试设备和存储介质,以解决截图传播导致敏感信息泄露的问题
[0014]Compared with the prior art, the technical solution provided in this application has the following advantages: When a screenshot operation is detected in the application interface, the method provided in this application generates a new screenshot image based on the content information in the application interface. Sensitive information in the application interface is displayed in the screenshot image using indicator information, so even if the screenshot image is disseminated, sensitive information will not be directly exposed. Only when an access request for the indicator information in the screenshot image is received will permission verification be performed based on the identity information in the access request. This determines the authorized information that the target account can view from the sensitive information, and then a new visual image is regenerated based on the authorized information and non-sensitive information. The visual image is then sent back to the login terminal of the target account, ensuring that the user corresponding to the target account can only see the information they are authorized to see, preventing the leakage of sensitive information that they are not authorized to view, and solving the problem of sensitive information leakage caused by screenshot dissemination.
Smart Images

Figure CN122548764A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information processing, and more particularly to an information processing method, apparatus, smart home appliance debugging device, and storage medium. Background Technology
[0002] In the current debugging and maintenance of smart home devices, a large amount of sensitive information is involved, including device barcodes, core control and operating parameters, customer addresses, and identity information. This information is typically viewed, recorded, or analyzed using debugging software. However, in existing technologies, when users take screenshots of the debugging interface, the system cannot identify and protect the sensitive information in the screenshots, leading to the potential for unauthorized access and leakage of sensitive information. Furthermore, traditional screenshot operations lack access control mechanisms, failing to authenticate and determine the permissions of those accessing the screenshots, resulting in frequent unauthorized access issues. Simultaneously, the lack of operation logs and traceability mechanisms makes it difficult to trace the responsible party once information leakage occurs. These problems severely restrict the security and compliance of smart home devices in collaborative debugging and remote maintenance. Summary of the Invention
[0003] This application provides an information processing method, apparatus, smart home appliance debugging device, and storage medium to solve the problem of sensitive information leakage caused by the dissemination of screenshots.
[0004] In a first aspect, this application provides an information processing method, the method comprising: When a screenshot operation is detected in the application interface, a screenshot image is generated based on the content information in the application interface. The screenshot image includes non-sensitive information and indication information corresponding to sensitive information. Upon receiving an access request associated with the indication information, the access permissions of the target account to the sensitive information are determined based on the identity information in the access request, wherein the access request is a request initiated by the target account; Authorization information is determined in the sensitive information according to the access permissions, wherein the authorization information is the information that the target account is entitled to access in the sensitive information; Based on the authorization information and the non-sensitive information, a visual image is output to the login terminal of the target account.
[0005] Optionally, generating a screenshot image based on the content information in the application interface includes: Based on the sensitive information in the application interface, an index QR code is generated, wherein the indication information includes the index QR code; A screenshot image is generated and displayed based on the non-sensitive information in the application interface and the index QR code.
[0006] Optionally, upon receiving an access request associated with the indication information, determining access permissions to the sensitive information based on the identity information in the access request includes: When an access request associated with the index QR code in the screenshot is received, the request type of the access request is determined based on the access time of the access request and the number of times the index QR code has been accessed. When the access request is a valid request, the access permissions for the sensitive information are determined based on the identity information in the access request.
[0007] Optionally, determining the request type of the access request based on the access time of the access request and the number of times the index QR code has been accessed includes: If the access time of the access request is within the validity period of the index QR code, and the number of accesses to the index QR code is less than the number of accesses, the request type of the access request is determined to be a valid request. If the access request occurs outside the validity period of the index QR code, and / or the number of accesses to the index QR code is greater than or equal to the access threshold, the request type of the access request is determined to be an invalid request.
[0008] Optionally, based on the authorization information and the non-sensitive information, a visual image is output to the login terminal of the target account, including: When the authorized information is part of the sensitive information, the information in the sensitive information other than the authorized information is regarded as unauthorized access information; Generate an unauthorized access message based on the unauthorized access information; Based on the authorization information, the non-sensitive information, and the unauthorized notification information, a visual image is output to the login terminal of the target account.
[0009] Optionally, after outputting a visual image to the login terminal of the target account based on the authorization information and the non-sensitive information, the method further includes: Obtain the access records of the target account for different screenshot images; Based on the access records, determine the access status of the target account; When the access status of the target account is abnormal, the access permissions of the target account are updated to the minimum access permissions, and an information security warning is issued.
[0010] Optionally, determining the access status of the target account based on the access records includes: If the access frequency in the access record is greater than a preset frequency, and / or the access period is a preset illegal period, and / or the number of cross-permission accesses is greater than a preset number, the access status of the target account is determined to be abnormal. If the access frequency in the access record is less than or equal to a preset frequency, the access time period is a preset legal time period, and the number of cross-permission accesses is less than or equal to a preset number, the access status of the target account is determined to be normal.
[0011] Secondly, this application provides an information processing apparatus. The image generation module is used to generate a screenshot image based on the content information in the application interface when a screenshot operation is detected in the application interface. The screenshot image includes non-sensitive information and indication information corresponding to sensitive information. The permission determination module is used to determine the access permissions of the target account to the sensitive information based on the identity information in the access request when receiving an access request associated with the indication information, wherein the access request is a request initiated by the target account; An information processing module is used to determine authorized information in the sensitive information according to the access permissions, wherein the authorized information is information in the sensitive information that the target account has the right to access; The output module is used to output a visual image to the login terminal of the target account based on the authorization information and the non-sensitive information.
[0012] Thirdly, this application provides a smart home appliance debugging device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the above-mentioned information processing method.
[0013] Fourthly, this application also provides a computer storage medium storing computer-executable instructions for performing the above-described information processing method.
[0014] Compared with the prior art, the technical solution provided in this application has the following advantages: When a screenshot operation is detected in the application interface, the method provided in this application generates a new screenshot image based on the content information in the application interface. Sensitive information in the application interface is displayed in the screenshot image using indicator information, so even if the screenshot image is disseminated, sensitive information will not be directly exposed. Only when an access request for the indicator information in the screenshot image is received will permission verification be performed based on the identity information in the access request. This determines the authorized information that the target account can view from the sensitive information, and then a new visual image is regenerated based on the authorized information and non-sensitive information. The visual image is then sent back to the login terminal of the target account, ensuring that the user corresponding to the target account can only see the information they are authorized to see, preventing the leakage of sensitive information that they are not authorized to view, and solving the problem of sensitive information leakage caused by screenshot dissemination. Attached Figure Description
[0015] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.
[0016] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0017] One or more embodiments are illustrated by way of example with reference numerals in the accompanying drawings. These illustrations do not constitute a limitation on the embodiments. Elements with the same reference numerals in the drawings are denoted as similar elements. Unless otherwise stated, the figures in the drawings are not to be limited by scale.
[0018] Figure 1 A flowchart illustrating an information processing method provided in an embodiment of this application; Figure 2 A schematic diagram illustrating the generation effect of a screenshot image provided in an embodiment of this application; Figure 3 A schematic diagram of the scanning process of a screenshot image provided in an embodiment of this application; Figure 4 This is a schematic diagram illustrating the effect of a visual image provided in an embodiment of this application; Figure 5 A flowchart illustrating an information processing method provided in an embodiment of this application; Figure 6 A structural block diagram of an information processing device provided in an embodiment of this application; Figure 7This is a schematic diagram of the internal structure of a smart home appliance debugging device provided in an embodiment of this application. Detailed Implementation
[0019] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0020] The following disclosure provides numerous different embodiments or examples for implementing various structures of the invention. To simplify the disclosure, specific examples of components and arrangements are described below. These are merely examples and are not intended to limit the scope of the invention. Furthermore, reference numerals and / or letters may be repeated in different examples. Such repetition is for simplification and clarity and does not in itself indicate a relationship between the various embodiments and / or arrangements discussed.
[0021] In one embodiment, the information processing method is applied to an information processing system, which includes multiple interconnected smart home appliance debugging devices. Each smart home appliance debugging device is equipped with a debugging application for the smart home device and an information processing device. The debugging application can be a software application (APP) or a plug-in application (such as a mini-program). Specifically, the smart home device can be a smart air conditioner, a smart refrigerator, a smart washing machine, or a smart speaker, etc. The smart home appliance debugging device can be a terminal or a server. The terminal can be a desktop terminal or a mobile terminal, and the mobile terminal can be at least one of a mobile phone, tablet computer, or laptop computer. The server can be a standalone server or a server cluster composed of multiple servers.
[0022] In one embodiment, Figure 1 This is a flowchart illustrating an information processing method in one embodiment, with reference to... Figure 1 This provides an information processing method. This embodiment primarily applies this method to the aforementioned... Figure 1 Taking an information processing device as an example, the information processing method specifically includes the following steps: Step S210: When a screenshot operation is detected in the application interface, a screenshot image is generated based on the content information in the application interface. The screenshot image includes non-sensitive information and indication information corresponding to the sensitive information.
[0023] Specifically, the information processing device monitors the local debugging application's interface for screenshot operations, and the terminal equipped with the information processing device acts as the screenshot terminal. That is, when the information processing device in the screenshot terminal detects a monitoring operation in the local debugging application's interface, it generates a new screenshot based on the content information of the current application interface, displays the screenshot in the application interface, and saves the screenshot locally on the screenshot terminal. The screenshot only directly displays non-sensitive information and does not directly display sensitive information. Sensitive information is represented by indicator information, which can be in the form of a link, plugin, or QR code. The indicator information only stores the index identifier (denoted as index ID) corresponding to the sensitive information and does not contain any plaintext information.
[0024] Step S220: Upon receiving an access request associated with the indication information, determine the target account's access rights to the sensitive information based on the identity information in the access request, wherein the access request is a request initiated by the target account.
[0025] Specifically, the target account is the login account authorized for debugging the application, and the terminal that logs into the target account is the login terminal. The login terminal and the screenshot terminal can be the same terminal or different terminals. (See reference...) Figure 3 The terminal on the right is the login terminal. If the login terminal and the screenshot terminal are the same terminal, the login terminal can use the debugging application to click on the indicator information (the indicator information is a link or plugin) or scan the code (the indicator information is a QR code) in the locally stored screenshot image. If the login terminal and the screenshot terminal are different terminals, the scanning terminal can transmit the screenshot image to the login terminal. The login terminal can then use the debugging application to click on the indicator information (the indicator information is a link or plugin) or scan the code (the indicator information is a QR code) in the locally stored screenshot image. The login terminal can also use the debugging application to scan the indicator information (the indicator information is a QR code) in the screenshot image on the screenshot terminal, thereby triggering the generation of an access request.
[0026] Figure 5 The fact that the image in the screenshot was accessed by this system is used to determine whether the screenshot image was accessed by the debugging application. The screenshot image only supports access operations within the debugging application. If the instruction information in the screenshot image is accessed by other applications that are not the debugging application, only encrypted information that cannot be directly read can be obtained.
[0027] Access requests are used to request access to sensitive information. The target account's access permissions for the sensitive information are determined based on the identity information in the access request. This identity information specifically includes roles, years of service, and job levels. For example, roles could be ordinary customers, after-sales personnel, headquarters developers, or distributors. Access permissions are categorized as no permission, partial permission, and full permission. No permission means the target account cannot access any information within the sensitive information; partial permission means the target account can access some information within the sensitive information; and full permission means the target account can access all information within the sensitive information.
[0028] Step S230: Determine authorization information in the sensitive information according to the access permissions, wherein the authorization information is the information that the target account is authorized to access in the sensitive information.
[0029] Specifically, based on access permissions, determine the authorized information that the target account can access within the sensitive information. The authorized information may be part or all of the information in the sensitive information.
[0030] Step S240: Based on the authorization information and the non-sensitive information, output a visual image to the login terminal of the target account.
[0031] Specifically, a completely new visual image is generated based on the authorization information and non-sensitive information. When different accounts access the information indicated in the screenshot, different visual images with different display content are dynamically generated based on the account's access permissions. That is, different users triggering access requests for the same information in the screenshot may receive different visual images. The visual image is then sent back to the login terminal of the target account, ensuring that the user of the target account can only see the information they are authorized to see, preventing the leakage of sensitive information that they are not authorized to view, and solving the problem of sensitive information leakage caused by screenshot dissemination.
[0032] Users without access permissions can only see placeholder instructions and cannot access the plaintext of sensitive information. This prevents sensitive information from being leaked through the screenshot at its source. On the other hand, the system dynamically matches access permissions based on the target account's identity to generate corresponding visual images. This ensures that authorized users can access the information they need without having to redirect to the original application interface to query it. It also enables differentiated access to the same screenshot by displaying different content to users with different permissions, balancing information security with the convenience of debugging and collaboration. Furthermore, the instructions only store index identifiers and not sensitive plaintext. Even if the instructions are intercepted and cracked, sensitive information will not be directly leaked, significantly improving the storage security of sensitive information in screenshots.
[0033] In one embodiment, refer to Figure 2 The step of generating a screenshot image based on the content information in the application interface includes: Based on the sensitive information in the application interface, an index QR code is generated, wherein the indication information includes the index QR code; A screenshot image is generated and displayed based on the non-sensitive information in the application interface and the index QR code.
[0034] Specifically, refer to Figure 3 The system utilizes index QR codes to represent information. These QR codes contain only the index identifier corresponding to the sensitive information and do not include plaintext information. The specific steps for generating index QR codes from sensitive information within the application interface include: extracting and locating sensitive information from the application interface; using OCR text recognition combined with preset sensitive word rules and interface control attribute annotations to extract all content marked as sensitive; assigning a globally unique index identifier (index ID) to each piece of sensitive information; storing all sensitive information in a key-value pair format (index ID: sensitive information plaintext) in an encrypted storage area on the application backend, with the query interface only accessible to requests with legitimate access rights; concatenating the backend's interface address for querying sensitive information with all assigned sensitive information index IDs to generate a binary code stream for the QR code; and then calling a QR code generation library to render and output the index QR code image. This QR code only contains the interface address and index ID and does not store any sensitive information plaintext content. Create a blank canvas, replace the sensitive information areas in the original application interface with preset desensitized placeholders, retain the content and layout of all non-sensitive information, then scale the generated index QR code to the preset size and render it in the preset blank position on the canvas (such as the lower right corner of the interface) to obtain a complete screenshot image; or render the blank canvas according to the distribution requirements of the index QR code and non-sensitive information to obtain a screenshot image.
[0035] The index ID points to a record in the database with an encrypted signature and a dynamic timestamp. Any modification to the information will cause the signature verification to fail. Simultaneously, the database records the usage status of the index ID in real time or sets an expiration date. Once a scan is successful, the index is marked as consumed or expired, making it vulnerable to interception when attackers try to resend old data packets due to their invalidated state.
[0036] The above method ensures the normal display of non-sensitive content when sharing screenshots, meeting the actual needs of users' communication interfaces, while fundamentally avoiding the risk of information leakage caused by the leakage of sensitive plaintext information with screenshots. Even if the screenshot is obtained by an unauthorized entity, no sensitive plaintext content can be obtained from the image alone. At the same time, the backend encrypted storage combined with the permission verification query mechanism allows only the legitimate holder to obtain sensitive information by scanning the code, realizing a flexible permission separation between de-identified public sharing and authorized scanning for viewing. The capacity advantage of the QR code itself can also support the indexing of dozens of sensitive information in a single screenshot, adapting to the de-identification scenarios of most application interfaces. Compared with the full-interface encrypted sharing solution, the recipient does not need to decrypt the entire image, but only completes a lightweight verification when scanning the code to obtain sensitive information, significantly reducing the computational and operational costs for both parties sharing, and does not destroy the readability of the screenshot due to full-image encryption, thus balancing information security and user experience.
[0037] In one embodiment, upon receiving an access request associated with the indication information, determining access permissions to the sensitive information based on the identity information in the access request includes: When an access request associated with the index QR code in the screenshot is received, the request type of the access request is determined based on the access time of the access request and the number of times the index QR code has been accessed. When the access request is a valid request, the access permissions for the sensitive information are determined based on the identity information in the access request.
[0038] Specifically, the target account's login account triggers an access request by scanning the QR code in the screenshot. Upon receiving the access request, the terminal taking the screenshot determines its type based on the access time and the number of times the index QR code has been accessed. The request is classified as either valid or invalid. Only if the request is valid will further authorization verification be performed based on the user's identity information. Invalid requests are denied access to sensitive information. This method, through dual verification of access time and number of accesses, reduces the risk of unauthorized accounts maliciously accessing sensitive information after the screenshot is shared. Compared to solutions that only perform a single identity verification, this mechanism improves the interception rate of unauthorized access, ensuring the security of sensitive information transfer without causing a noticeable negative impact on the user experience of authorized access. It effectively balances the technical requirements of convenient information sharing and data access security.
[0039] In one embodiment, determining the request type of the access request based on the access time of the access request and the number of accesses to the index QR code includes: If the access time of the access request is within the validity period of the index QR code, and the number of accesses to the index QR code is less than the number of accesses, the request type of the access request is determined to be a valid request. If the access request occurs outside the validity period of the index QR code, and / or the number of accesses to the index QR code is greater than or equal to the access threshold, the request type of the access request is determined to be an invalid request.
[0040] Specifically, while generating the index QR code, the corresponding validity period is automatically configured. The validity period indicates the time from the time the index QR code is generated until the expiration time, after accumulating a preset duration. The preset duration can be adaptively configured based on the device type and debugging function of the smart home device. For example, the device type and debugging function of the smart home device currently being debugged in the debugging application are read from the access request, and the preset duration is matched through a pre-trained adaptive configuration decision tree model: the decision tree is based on the device type as the root node branch, and different device types are further divided into secondary branches based on the debugging function category. Each leaf node stores the baseline duration configuration for the corresponding scenario, and at the same time, there are built-in correction rules. If the device is a gateway device that needs to be debugged in the cloud and the debugging function involves firmware upgrades, an additional 15 to 30 minutes of fault tolerance time will be added on the baseline duration; if it is a basic network configuration debugging of a single-function sensor device, the baseline duration will be compressed to within 5 minutes. After completing the preset duration matching, the Unix timestamp interface is called to obtain the generation time T0 of the index QR code. The expiration time T1 is obtained by calculating T0 and adding the preset duration obtained by matching. T1 is then bound to the QR code identifier of the index QR code and stored in the Redis cache database. At the same time, the expiration time of the cache is set to be aligned with T1. When a user scans the index QR code to access the debugging interface, the backend of the screenshot terminal first queries the cached T1 based on the QR code indication information and compares the current access time with the time before and after T1: if the access time is greater than T1, a QR code expiration message is returned directly, and the corresponding cache record is deleted; if no timeout occurs, it continues to determine whether the number of accesses to the index QR code exceeds the access threshold. The access count is the cumulative number of times the index QR code has been scanned. The access threshold can be customized according to the debugging function. For example, if the debugging function is in the "customer acceptance" stage, the index QR code is only allowed to be scanned once, i.e., the access threshold is 1, and only the device operating status and customer signature information are displayed; if the debugging function is in the "debugging and testing" stage, scanning is allowed three times, i.e., the access threshold is 3, and some parameters can be viewed, but key control values (such as compressor start / stop thresholds) still require administrator approval before they can be viewed.
[0041] Access to sensitive information is only considered valid if the number of accesses is less than the threshold and the access time is within the validity period. If the number of accesses is greater than or equal to the threshold and / or the access time is outside the validity period, the access request is considered invalid, and access to sensitive information via the index QR code is denied.
[0042] The access control mechanism based on adaptive expiration and access count dual verification completely avoids the redundancy and waste of fixed expiration configurations. For short-cycle debugging scenarios, compressing the expiration period improves the storage space utilization of the Redis cache while reducing the overhead of automatic invalid cache cleanup, thus lowering the average memory usage and computational load of the screenshot terminal backend. Secondly, by aligning the cache expiration time with the expiration time of the index QR code, and leveraging Redis's native automatic expired key cleanup mechanism, the storage resources occupied by expired QR codes can be automatically reclaimed without the need for additional timed cleanup tasks. This avoids delays and omissions that may occur with manual task scheduling, improving the timeliness of storage resource reclamation. Flexible constraints on access permissions and durations for different debugging scenarios not only meet the temporary access needs of on-site debugging engineers but also technically eliminate the risk of unauthorized personnel scanning expired QR codes to steal sensitive debugging information, reducing the probability of sensitive information leakage in smart home remote debugging scenarios. Furthermore, the elimination of the need for administrators to manually revoke QR code permissions significantly reduces the management cost of the debugging process.
[0043] In one embodiment, outputting a visual image to the login terminal of the target account based on the authorization information and the non-sensitive information includes: When the authorized information is part of the sensitive information, the information in the sensitive information other than the authorized information is regarded as unauthorized access information; Generate an unauthorized access message based on the unauthorized access information; Based on the authorization information, the non-sensitive information, and the unauthorized notification information, a visual image is output to the login terminal of the target account.
[0044] Specifically, for sensitive information that the target account is not authorized to access, an access restriction message is generated. This message can be a notification, a link, plugin, or QR code. The notification informs the target account that there is content they are not authorized to view in the sensitive information and guides them to request access to the restricted information from the sharer or administrator account. Combining the authorization information, non-sensitive information, and the access restriction message, a visual image is generated, referencing... Figure 4 The terminal in the text is the login terminal, which displays a visual image after scanning the code.
[0045] When the unauthorized access message is a link, plugin, or QR code, the user corresponding to the target account can click or scan the unauthorized access message in the visual image through the debugging application in the login terminal. This triggers a corresponding access request for the unauthorized access information and sends the request to the administrator account or the sharer account. The access request is used to request the sharer account or the administrator account to provide the unauthorized access information to the target account, or to request the administrator account to adjust the target account's access permissions for the unauthorized access information to authorized. The sharer account is the login account of the debugging application in the screenshot terminal, which is the account that generated the screenshot image.
[0046] Based on the above method, the process of applying for access rights to sensitive information can be significantly shortened. Compared with the traditional model that requires cross-platform private message communication and offline application confirmation, the time spent initiating access requests can be reduced. At the same time, it can accurately bind unauthorized access information with the corresponding access request, avoiding the problem of mismatched information during communication. The technology of embedding unauthorized prompt information on a visual image carrier will not interfere with the normal display of non-sensitive information.
[0047] In one embodiment, refer to Figure 5 After outputting a visual image to the login terminal of the target account based on the authorization information and the non-sensitive information, the method further includes: Obtain the access records of the target account for different screenshot images; Based on the access records, determine the access status of the target account; When the access status of the target account is abnormal, the access permissions of the target account are updated to the minimum access permissions, and an information security warning is issued.
[0048] Specifically, every scan operation performed by different accounts on each screenshot image is automatically recorded as an access log. The access log includes identity information, scan time, device model, IP address, QR code index, access permissions, access result, access frequency, access time period, and number of cross-permission accesses. All access logs are immutable and support subsequent traceability and security auditing.
[0049] Based on the target account's access records for different screenshots, a comprehensive assessment is conducted to determine whether the target account's access behavior is abnormal. If the target account's access is determined to be abnormal, its access permissions are automatically reduced to the minimum allowed level. The minimum allowed level is either no access to sensitive information or only access to sensitive information related to the target account's own attributes. Specific configurations can be customized according to actual application needs. Simultaneously, an information security alert is issued to remind the administrator account of accounts exhibiting abnormal access behavior, preventing these accounts from continuously accessing sensitive information and potentially leading to its leakage.
[0050] In one embodiment, determining the access status of the target account based on the access records includes: If the access frequency in the access record is greater than a preset frequency, and / or the access period is a preset illegal period, and / or the number of cross-permission accesses is greater than a preset number, the access status of the target account is determined to be abnormal. If the access frequency in the access record is less than or equal to a preset frequency, the access time period is a preset legal time period, and the number of cross-permission accesses is less than or equal to a preset number, the access status of the target account is determined to be normal.
[0051] Specifically, access frequency refers to the number of times a target account scans each index QR code within a preset time period; access time period refers to the time period during which the target account frequently accesses sensitive information; and cross-permission access count refers to the number of times the target account accesses information it does not have permission to access. If at least one of the following occurs: access frequency greater than the preset frequency (e.g., 5 scans within 10 minutes); access time period falls within a preset illegal time period (e.g., access time is between 2 AM and 3 AM); or cross-permission access count exceeds the preset number (e.g., a regular user repeatedly attempts to access administrator-level information), the target account's access status is determined to be abnormal. Only if none of the above occurs is the target account's access status determined to be normal. This judgment rule, by quantifying multi-dimensional access behavior characteristics, transforms abnormal access based on fuzzy human experience into a rigid judgment standard that can be automatically identified. Relying on preset thresholds, it can achieve second-level screening of access behavior for millions of accounts. It can promptly intercept malicious access behavior that steals sensitive information without causing additional obstacles to normal and legitimate access that conforms to the rules. It can effectively improve the access security protection capabilities of the QR code index information system without increasing system computing power.
[0052] Figure 1 and Figure 5 This is a flowchart illustrating an information processing method in one embodiment. It should be understood that, although... Figure 1 and Figure 5 The steps in the flowchart are shown sequentially as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order in which these steps are executed, and they can be performed in other orders. Figure 1 and Figure 5 At least some of the steps in the process may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed in turn or alternately with other steps or at least some of the sub-steps or stages of other steps.
[0053] In one embodiment, such as Figure 6 As shown, an information processing apparatus is provided, comprising: Image generation module 310 is used to generate a screenshot image based on the content information in the application interface when a screenshot operation is detected in the application interface. The screenshot image includes non-sensitive information and indication information corresponding to sensitive information. The permission determination module 320 is used to determine the access permissions of the target account to the sensitive information based on the identity information in the access request when receiving an access request associated with the indication information, wherein the access request is a request initiated by the target account; Information processing module 330 is used to determine authorization information in the sensitive information according to the access permissions, wherein the authorization information is information in the sensitive information that the target account has the right to access; The output module 340 is used to output a visual image to the login terminal of the target account based on the authorization information and the non-sensitive information.
[0054] In one embodiment, the image generation module 310 is further configured to: Based on the sensitive information in the application interface, an index QR code is generated, wherein the indication information includes the index QR code; A screenshot image is generated and displayed based on the non-sensitive information in the application interface and the index QR code.
[0055] In one embodiment, the permission determination module 320 is further configured to: When an access request associated with the index QR code in the screenshot is received, the request type of the access request is determined based on the access time of the access request and the number of times the index QR code has been accessed. When the access request is a valid request, the access permissions for the sensitive information are determined based on the identity information in the access request.
[0056] In one embodiment, the permission determination module 320 is further configured to: If the access time of the access request is within the validity period of the index QR code, and the number of accesses to the index QR code is less than the number of accesses, the request type of the access request is determined to be a valid request. If the access request occurs outside the validity period of the index QR code, and / or the number of accesses to the index QR code is greater than or equal to the access threshold, the request type of the access request is determined to be an invalid request.
[0057] In one embodiment, the output module 340 is further configured to: When the authorized information is part of the sensitive information, the information in the sensitive information other than the authorized information is regarded as unauthorized access information; Generate an unauthorized access message based on the unauthorized access information; Based on the authorization information, the non-sensitive information, and the unauthorized notification information, a visual image is output to the login terminal of the target account.
[0058] In one embodiment, the output module 340 is further configured to: Obtain the access records of the target account for different screenshot images; Based on the access records, determine the access status of the target account; When the access status of the target account is abnormal, the access permissions of the target account are updated to the minimum access permissions, and an information security warning is issued.
[0059] In one embodiment, the output module 340 is further configured to: If the access frequency in the access record is greater than a preset frequency, and / or the access period is a preset illegal period, and / or the number of cross-permission accesses is greater than a preset number, the access status of the target account is determined to be abnormal. If the access frequency in the access record is less than or equal to a preset frequency, the access time period is a preset legal time period, and the number of cross-permission accesses is less than or equal to a preset number, the access status of the target account is determined to be normal.
[0060] It should be noted that the examples and application scenarios implemented by the above modules and corresponding steps are the same, but are not limited to the content disclosed in the above embodiments. It should also be noted that the above modules, as part of a device, can operate in environments such as... Figure 1 The hardware environment shown can be implemented either through software or through hardware.
[0061] like Figure 7 As shown, this application embodiment provides an intelligent home appliance debugging device, including a processor 711, a communication interface 712, a memory 713, and a communication bus 714. The processor 711, the communication interface 712, and the memory 713 communicate with each other through the communication bus 714. The memory 713 is used to store computer programs. When the processor 711 executes the program stored in the memory 713, it implements the information processing method provided in any of the aforementioned method embodiments.
[0062] The memory and processor in the aforementioned electronic devices communicate with each other via a communication bus and a communication interface. The communication bus can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into an address bus, a data bus, a control bus, etc.
[0063] The memory may include random access memory (RAM) or non-volatile memory, such as at least one disk storage device. Optionally, the memory may also be at least one storage device located remotely from the aforementioned processor.
[0064] The processors mentioned above can be general-purpose processors, including central processing units (CPUs), network processors (NPs), etc.; they can also be digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0065] Those skilled in the art will understand that Figure 7 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the smart home appliance debugging device to which the present application is applied. The specific smart home appliance debugging device may include more or fewer components than shown in the figure, or combine certain components, or have different component arrangements.
[0066] According to another aspect of the embodiments of this application, a computer program product or computer program is also provided, which includes computer instructions stored in a computer-readable storage medium. A processor of a smart home appliance debugging device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the smart home appliance debugging device to perform the steps of any of the above embodiments.
[0067] In one embodiment, the information processing apparatus provided in this application can be implemented as a computer program, and the computer program can be implemented in such a way as... Figure 7 The device operates on the smart home appliance debugging equipment shown. The memory of the smart home appliance debugging equipment can store the various program modules that make up the information processing device, for example, Figure 6 The image generation module 310, permission determination module 320, information processing module 330, and output module 340 are shown. The computer program comprised of these modules causes the processor to execute the information processing methods of the various embodiments of this application described in this specification.
[0068] Figure 7 The smart home appliance debugging device shown can be used as follows Figure 6 The image generation module 310 in the information processing device, when a screenshot operation is detected in the application interface, generates a screenshot image based on the content information in the application interface. The screenshot image includes non-sensitive information and indication information corresponding to the sensitive information. The smart home appliance debugging device, through the permission determination module 320, determines the target account's access permissions to the sensitive information based on the identity information in the access request when it receives an access request associated with the indication information. The access request is initiated by the target account. The smart home appliance debugging device, through the information processing module 330, determines authorization information in the sensitive information according to the access permissions. The authorization information is the information in the sensitive information that the target account is authorized to access. The smart home appliance debugging device, through the output module 340, outputs a visual image to the target account's login terminal based on the authorization information and the non-sensitive information.
[0069] This application also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the information processing method provided in any of the foregoing method embodiments.
[0070] Optionally, in embodiments of this application, the computer-readable medium is configured to store program code for the processor to perform the following steps: When a screenshot operation is detected in the application interface, a screenshot image is generated based on the content information in the application interface. The screenshot image includes non-sensitive information and indication information corresponding to sensitive information. Upon receiving an access request associated with the indication information, the access permissions of the target account to the sensitive information are determined based on the identity information in the access request, wherein the access request is a request initiated by the target account; Authorization information is determined in the sensitive information according to the access permissions, wherein the authorization information is the information that the target account is entitled to access in the sensitive information; Based on the authorization information and the non-sensitive information, a visual image is output to the login terminal of the target account.
[0071] Optionally, specific examples in this embodiment can refer to the examples described in the above embodiments, and will not be repeated here.
[0072] It is understood that the embodiments described herein can be implemented in hardware, software, firmware, middleware, microcode, or a combination thereof. For hardware implementation, the processing unit can be implemented in one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers, microprocessors, other electronic units for performing the functions described herein, or combinations thereof.
[0073] For software implementation, the techniques described herein can be implemented by units that perform the functions described herein. The software code can be stored in memory and executed by a processor. The memory can be implemented in the processor or external to the processor.
[0074] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0075] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0076] In the embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For instance, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.
[0077] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0078] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0079] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented using software plus a general-purpose hardware platform, or of course, using hardware. Based on this understanding, the above technical solutions, in essence or the parts that contribute to the related technology, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as a USB flash drive, external hard drive, ROM, RAM, magnetic disk, or optical disk, or other media capable of storing program code. It includes several instructions to cause a smart home appliance debugging device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0080] It should be understood that the terminology used herein is for the purpose of describing particular exemplary embodiments only and is not intended to be limiting. Unless the context clearly indicates otherwise, the singular forms “a,” “an,” and “described” as used herein may also mean including the plural forms. The terms “comprising,” “including,” “containing,” and “having” are inclusive and therefore indicate the presence of the stated features, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, elements, components, and / or combinations thereof. The method steps, processes, and operations described herein are not construed as requiring them to be performed in a particular order described or illustrated unless the order of performance is explicitly indicated. It should also be understood that alternatives or substitutions may be used.
[0081] The above description is merely a specific embodiment of the present invention, enabling those skilled in the art to understand or implement the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the present invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features claimed herein.
Claims
1. An information processing method characterized by comprising: The method includes: When a screenshot operation is detected in the application interface, a screenshot image is generated based on the content information in the application interface. The screenshot image includes non-sensitive information and indication information corresponding to sensitive information. Upon receiving an access request associated with the indication information, the access permissions of the target account to the sensitive information are determined based on the identity information in the access request, wherein the access request is a request initiated by the target account; Authorization information is determined in the sensitive information according to the access permissions, wherein the authorization information is the information that the target account is entitled to access in the sensitive information; Based on the authorization information and the non-sensitive information, a visual image is output to the login terminal of the target account.
2. The method of claim 1, wherein, The step of generating a screenshot image based on the content information in the application interface includes: Based on the sensitive information in the application interface, an index QR code is generated, wherein the indication information includes the index QR code; A screenshot image is generated and displayed based on the non-sensitive information in the application interface and the index QR code.
3. The method of claim 2, wherein, Upon receiving an access request associated with the indication information, determining access permissions for the sensitive information based on the identity information in the access request includes: When an access request associated with the index QR code in the screenshot is received, the request type of the access request is determined based on the access time of the access request and the number of times the index QR code has been accessed. When the access request is a valid request, the access permissions for the sensitive information are determined based on the identity information in the access request.
4. The method of claim 3, wherein, The step of determining the request type of the access request based on the access time of the access request and the number of times the index QR code has been accessed includes: If the access time of the access request is within the validity period of the index QR code, and the number of accesses to the index QR code is less than the number of accesses, the request type of the access request is determined to be a valid request. If the access request occurs outside the validity period of the index QR code, and / or the number of accesses to the index QR code is greater than or equal to the access threshold, the request type of the access request is determined to be an invalid request.
5. The method according to claim 1, characterized in that, Based on the authorization information and the non-sensitive information, output a visual image to the login terminal of the target account, including: When the authorized information is part of the sensitive information, the information in the sensitive information other than the authorized information is regarded as unauthorized access information; Generate an unauthorized access message based on the unauthorized access information; Based on the authorization information, the non-sensitive information, and the unauthorized notification information, a visual image is output to the login terminal of the target account.
6. The method according to claim 1, characterized in that, After outputting a visual image to the login terminal of the target account based on the authorization information and the non-sensitive information, the method further includes: Obtain the access records of the target account for different screenshot images; Based on the access records, determine the access status of the target account; When the access status of the target account is abnormal, the access permissions of the target account are updated to the minimum access permissions, and an information security warning is issued.
7. The method according to claim 6, characterized in that, Based on the access records, the access status of the target account is determined, including: If the access frequency in the access record is greater than a preset frequency, and / or the access period is a preset illegal period, and / or the number of cross-permission accesses is greater than a preset number, the access status of the target account is determined to be abnormal. If the access frequency in the access record is less than or equal to a preset frequency, the access time period is a preset legal time period, and the number of cross-permission accesses is less than or equal to a preset number, the access status of the target account is determined to be normal.
8. An information processing apparatus, characterized by comprising: The device includes: The image generation module is used to generate a screenshot image based on the content information in the application interface when a screenshot operation is detected in the application interface. The screenshot image includes non-sensitive information and indication information corresponding to sensitive information. The permission determination module is used to determine the access permissions of the target account to the sensitive information based on the identity information in the access request when receiving an access request associated with the indication information, wherein the access request is a request initiated by the target account; An information processing module is used to determine authorized information in the sensitive information according to the access permissions, wherein the authorized information is information in the sensitive information that the target account has the right to access; The output module is used to output a visual image to the login terminal of the target account based on the authorization information and the non-sensitive information.
9. A smart home commissioning device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method of any one of claims 1 to 7.
10. A computer-readable storage medium having stored thereon a computer program, characterized in that, When the computer program is executed by a processor, it implements the method of any one of claims 1 to 7.