Display method for encrypted file, and electronic device
By setting DLP controls and sandbox clone technology on the user interface of the communication application, the problems of low efficiency and poor user experience of electronic devices when processing encrypted files are solved, efficient encrypted file display and management are achieved, and data security is improved.
Patent Information
- Application Number
- PCT/CN2025/071742
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-29
- Filing Date
- 2025-01-10
- Publication Date
- 2025-10-02
AI Technical Summary
In the prior art, electronic devices have problems with low efficiency and poor user experience when processing encrypted files, especially in terms of rights management and data leakage prevention, which makes it difficult to efficiently display and process encrypted files.
By setting DLP controls on the user interface of the communication application, the decryption or encryption results of the encrypted files can be directly displayed according to the permissions of the user account. By using sandbox clone technology and link files to map virtual plaintext and ciphertext of encrypted files, efficient display and management of encrypted files can be achieved.
It improves the display and processing efficiency of encrypted files, enhances data security, reduces user operations, and improves user experience.
Smart Images

Figure CN2025071742_02102025_PF_FP_ABST
Abstract
Description
Method and electronic device for displaying encrypted files
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on March 29, 2024, with application number 202410382646.4 and invention name “Method and electronic device for displaying encrypted files”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of terminal device software, and in particular, to a method for displaying encrypted files and an electronic device. Background Art
[0003] With the development of information technology, computers and the Internet have become essential tools and channels for daily office work, communication, and collaborative interaction. It is worth considering how to improve data security such as storage security and transmission security while improving the efficiency of computers, mobile phones and other electronic devices in processing encrypted data and encrypted files, and enhancing users' experience with encrypted data and encrypted files. Summary of the Invention
[0004] The present application provides a method for displaying an encrypted file and an electronic device. A control for determining the display mode of the encrypted file can be provided on the user interface of a communication application. The electronic device can directly display the decryption result or encryption result of the encrypted image (or encrypted video) according to whether the user account has the permission to view the encrypted image (or encrypted video). In this way, users who have the permission to view the encrypted file can directly view the content of the encrypted file on the user interface of the communication application, and users who do not have the permission to view the encrypted file can directly be informed on the user interface of the communication application that they cannot view the file. The processing of the encrypted file by the electronic device can meet the requirements of data leakage prevention, and the efficiency of displaying and processing the encrypted file is higher.
[0005] In a first aspect, a method for displaying an encrypted file is provided, which is applied to an electronic device, comprising: receiving an encrypted file through a communication application, wherein the user interface of the communication application includes a data leakage prevention (DLP) control, and the encrypted file includes an image file and / or a video file; if the account has viewing permission for the encrypted file, displaying the decryption result of the encrypted file in the DLP control; or, if the account does not have viewing permission for the encrypted file, displaying the encryption result of the encrypted file in the DLP control.
[0006] In one possible implementation, the encrypted file may be a DLP file, the encrypted image may be a DLP image, and the encrypted video may be a DLP video. DLP files, DLP images, and DLP videos can all be understood as data files protected by the DLP solution.
[0007] In some scenarios, displaying the decryption result of an encrypted file in the DLP control can also be understood as displaying the contents of the encrypted file normally on the user interface of the communication application, and displaying the encryption result of an encrypted file in the DLP control can also be understood as not displaying the contents of the encrypted file on the user interface of the communication application.
[0008] In a possible implementation, there may be multiple encrypted files, and the electronic device may display the decryption results or encryption results of the multiple encrypted files on the user interface of the communication application.
[0009] In some scenarios, whether an account has the permission to view the encrypted file or not can be understood as whether the user indicated by the account has the permission to view the encrypted file or not.
[0010] In a possible implementation, the communication application may include an instant messaging application or a mailbox application.
[0011] In one possible implementation, the DLP control can be used to determine how encrypted files are displayed based on the permissions granted to the communication app account. For example, the electronic device can launch a permissions management application process within the DLP control and use this permissions management application process to determine whether the communication app login account has permission to view encrypted files, thereby determining how the encrypted files are displayed.
[0012] In this technical solution, a control that can determine the permission of the communication application's login account to view encrypted files is directly set on the communication application's user interface. With the help of this control, the electronic device can directly display the decrypted content or encrypted content of the encrypted file on the communication application's user interface based on whether the communication application's login account has permission to view the encrypted file. In other words, the electronic device can complete the authentication of the communication application's login account and display the encrypted file based on the permission without jumping from the communication application to other applications. The display efficiency of encrypted files is high, and the user's operations are reduced from receiving the encrypted file to displaying the authentication result of the encrypted file, and the user experience of using encrypted files is better.
[0013] In some scenarios, the above technical solution can also be understood as the decryption result or encryption result of the encrypted file can be embedded and displayed on the user interface of the communication application through the DLP control.
[0014] In this technical solution, the decryption result of the encrypted file can be embedded in the user interface of the communication application in the form of an interface component, and the electronic device has higher display efficiency and management efficiency for the encrypted file.
[0015] In combination with the first aspect, in certain implementations of the first aspect, displaying the decryption result of the encrypted file in the DLP control also includes: creating a sandbox clone of the file display application; and displaying the decryption result of the encrypted file in the DLP control through the sandbox clone of the file display application.
[0016] In a possible implementation, if the encrypted file is an encrypted picture or an encrypted video, the file display application in this solution can be a picture display application or a video display application. In other words, the file display application has the ability to display picture files and / or video files.
[0017] File display applications can only use the resources provided by the sandbox. The implementation of this technical solution is conducive to improving the display efficiency of encrypted files while managing and controlling encrypted files, preventing the leakage of encrypted files, and improving the data security of encrypted files.
[0018] In combination with the first aspect, in some implementations of the first aspect, displaying the decryption result of the encrypted file in the DLP control further includes: creating a link file, the link file being used to map the virtual plaintext of the encrypted file to the ciphertext of the encrypted file.
[0019] In a possible implementation, the link file may be a DLP link, and the link file may be generated based on a file system (fuse) in a user space.
[0020] By linking files to map the virtual plaintext of encrypted files and the ciphertext of encrypted files, electronic devices can share or operate encrypted files by sharing virtual plaintext or operating virtual plaintext. The implementation of this technical solution is conducive to achieving data security of encrypted files and preventing data leakage of encrypted files during sharing or use.
[0021] In one possible implementation, the method further includes: in response to an operation on the virtual plaintext of the encrypted file, displaying a processing control in the DLP control, the processing control including an entry for one or more functions applied to the encrypted file.
[0022] In a possible implementation, the processing control may include a function entry for saving an encrypted file, a function entry for editing an encrypted file, or a function entry for sharing an encrypted file.
[0023] In this technical solution, the electronic device can also directly display and process the functional controls of the encrypted file on the user interface of the communication application. The electronic device can edit, save and other processes the encrypted file without jumping between applications. The implementation of this technical solution is conducive to improving the processing efficiency of the electronic device for encrypted files.
[0024] In combination with the first aspect, in some implementations of the first aspect, displaying the encryption result of the encrypted file in the DLP control includes: displaying an indication in the DLP control that the account does not have permission to view the encrypted file.
[0025] This technical solution displays a prompt message in the user interface of the communication application that the user does not have permission to view the encrypted file to explain the reason why the encrypted file cannot be displayed normally. After knowing the reason, the user can take corresponding measures. The implementation of this technical solution is conducive to reducing the inconvenience caused by the use of encrypted files, improving the processing efficiency of electronic devices for encrypted files, and improving the user experience of using encrypted files.
[0026] In a second aspect, a method for displaying an encrypted file is provided, which is applied to an electronic device, including: a process of a communication application receives an encrypted file, the communication application is logged in through an account, and the encrypted file includes an image file and / or a video file; a data leakage prevention DLP permission management process receives the encrypted file sent by the process of the communication application; the DLP permission management process determines whether the account has permission to view the encrypted file; if the account does not have permission to view the encrypted file, the DLP permission management process displays the encryption result of the encrypted file on the user interface of the communication application; or, if the account has permission to view the encrypted file, the DLP permission management process creates a sandbox clone of the file display application, and the process of the sandbox clone of the file display application displays the decryption result of the encrypted file on the user interface of the communication application.
[0027] In one possible implementation, the communication application process and the DLP rights management process receive the encrypted file through inter-process communication, such as pipes, message queues, sockets, shared memory, or memory mapping.
[0028] In a possible implementation, if the encrypted file is an encrypted picture or an encrypted video, the file display application in this solution can be a picture display application or a video display application. In other words, the file display application has the ability to display picture files and / or video files.
[0029] In a possible implementation, the encrypted file may be a DLP file, the encrypted picture may be a DLP picture, and the encrypted video may be a DLP video.
[0030] In some scenarios, displaying the decryption result of an encrypted file on the user interface of a communication application can also be understood as displaying the contents of the encrypted file normally on the user interface of the communication application, and displaying the encryption result of an encrypted file on the user interface of a communication application can also be understood as not displaying the contents of the encrypted file on the user interface of the communication application.
[0031] In a possible implementation, there may be multiple encrypted files, and the electronic device may display the decryption results or encryption results of the multiple encrypted files on the user interface of the communication application.
[0032] In some scenarios, whether an account has or does not have the permission to view the encrypted file can be understood as whether the user indicated by the account has or does not have the permission to view the encrypted file.
[0033] In a possible implementation, the communication application may include an instant messaging application or a mailbox application.
[0034] File display applications can only use the resources provided by the sandbox. The implementation of this technical solution is conducive to improving the display efficiency of encrypted files while managing and controlling encrypted files, preventing the leakage of encrypted files, and improving the data security of encrypted files.
[0035] In this technical solution, the decryption results and encryption results of the encrypted file can be directly displayed on the user interface of the communication application through different processes. On the one hand, directly displaying on the user interface of the communication application can improve the display efficiency of the electronic device for encrypted files. On the other hand, different processes process the decryption results and encryption results respectively, which is conducive to reducing the risk of encrypted file data leakage.
[0036] In combination with the second aspect, in certain implementations of the second aspect, the user interface of the communication application includes a DLP control, and the process of the DLP permission management application displays the encryption result of the encrypted file on the user interface of the communication application, including: the process of the DLP permission management application displays the encryption result of the encrypted file in the DLP control; the process of the sandbox clone of the file display application displays the decryption result of the encrypted file on the user interface of the communication application, including: the process of the sandbox clone of the file display application displays the decryption result of the encrypted file in the DLP control.
[0037] In some scenarios, the above technical solution can also be understood as the decryption result or encryption result of the encrypted file can be embedded and displayed on the user interface of the communication application through the DLP control.
[0038] In this technical solution, the decryption result of the encrypted file can be embedded in the user interface of the communication application in the form of an interface component, and the electronic device has higher display efficiency and management efficiency for the encrypted file.
[0039] In combination with the second aspect, in certain implementations of the second aspect, before the process of the sandbox clone of the file display application displays the decryption result of the encrypted file on the user interface of the communication application, the method also includes the DLP permission management application process creating a link file, the link file is used to map the virtual plaintext of the encrypted file and the ciphertext of the encrypted file; the DLP permission management application process sends the virtual plaintext of the encrypted file to the process of the sandbox clone of the file display application, and the virtual plaintext is used to indicate the decryption result of the encrypted file.
[0040] In a possible implementation, the link file may be a DLP link, and the link file may be generated based on a file system (fuse) in a user space.
[0041] By linking files to map the virtual plaintext of encrypted files and the ciphertext of encrypted files, electronic devices can share or operate encrypted files by sharing virtual plaintext or operating virtual plaintext. The implementation of this technical solution is conducive to achieving data security of encrypted files and preventing data leakage of encrypted files during sharing or use.
[0042] In combination with the second aspect, in certain implementations of the second aspect, the DLP permission management application process determines whether an account has permission to view encrypted files, including: the DLP permission management application process obtains an authorization policy, and the authorization policy includes information indicating whether the account has permission to view encrypted files.
[0043] In one possible implementation, the authorization policy is used to indicate the permissions of different users or accounts of different communication applications to the encrypted file.
[0044] In one possible implementation, the DLP rights management application process may obtain the authorization policy from the DLP rights management service.
[0045] In this technical solution, the DLP permission management application process can determine the permissions of the communication application's login account to the encrypted file by obtaining the authorization policy. The authorization policy can be managed by other applications or services. This technical solution will check that different links of the encrypted file are managed by different applications or services, which is conducive to improving the data security of the encrypted file.
[0046] In combination with the second aspect, in certain implementations of the second aspect, the DLP permission management application process displays the encryption result of the encrypted file on the user interface of the communication application, including: the DLP permission management application process displays an indication that the account does not have permission to view the encrypted file on the user interface of the communication application.
[0047] In this technical solution, a prompt message indicating that the user does not have permission to view the encrypted file is displayed in the user interface of the communication application to explain the reason why the encrypted file cannot be displayed normally. After the user knows the reason, he can take corresponding measures. The implementation of this technical solution is conducive to reducing the inconvenience caused by the use of encrypted files, improving the processing efficiency of electronic devices for encrypted files, and improving the user experience of using encrypted files.
[0048] The relevant explanations and descriptions in the following technical solutions can refer to the relevant descriptions in the first and second aspects. For the sake of brevity, they are not repeated below.
[0049] According to a third aspect, a method for displaying an encrypted image is provided, which is applied to an electronic device, including: receiving a first encrypted image through a communication application logged in through an account, the communication application including a data leakage prevention DLP control for displaying the encrypted image; creating a gallery sandbox clone for viewing the first encrypted image through a DLP permission management application; the DLP permission management application determining that the account has permission to view the first encrypted image; the gallery sandbox clone displaying a first interface in the first DLP control, the first interface including the decrypted first encrypted image.
[0050] In combination with the third aspect, in certain implementations of the third aspect, before displaying the first interface of the gallery sandbox clone in the DLP control, the method also includes: the communication application sends the first encrypted image to the DLP rights management application; the DLP rights management application sends the virtual plaintext of the first encrypted image to the gallery sandbox clone, and the virtual plaintext is used to indicate the decrypted first encrypted image.
[0051] In combination with the third aspect, in certain implementations of the third aspect, the method further includes: receiving a second encrypted image through a communication application; the DLP permission management application determining that the account does not have permission to view the second encrypted image; and the DLP permission management application displaying the encrypted second encrypted image in a second DLP control.
[0052] In combination with the third aspect, in certain implementations of the third aspect, the method further includes: in response to exiting the communication application, destroying the gallery sandbox clone.
[0053] In this technical solution, when the electronic device exits the communication application, it can promptly destroy the gallery sandbox clone used to display the decryption result of the encrypted image, which is beneficial to reducing the chance of data leakage.
[0054] In a fourth aspect, a device for displaying encrypted files is provided, which includes an acquisition module and a processing module. The acquisition module is used to: receive encrypted files through a communication application, the user interface of the communication application includes a data leakage prevention DLP control, and the encrypted files include image files and / or video files; the processing module is used to: display the decryption result of the encrypted file in the DLP control when the account has viewing permission for the encrypted file; or display the encryption result of the encrypted file in the DLP control when the account does not have viewing permission for the encrypted file.
[0055] In combination with the fourth aspect, in certain implementations of the fourth aspect, the specific processing module is used to: create a sandbox clone of the file display application; and display the decryption result of the encrypted file through the sandbox clone of the file display application in the DLP control.
[0056] In combination with the fourth aspect, in some implementations of the fourth aspect, the processing module is further used to: create a link file, where the link file is used to map the virtual plaintext of the encrypted file and the ciphertext of the encrypted file.
[0057] In a possible implementation, the processing module is further configured to: in response to an operation on the virtual plaintext of the encrypted file, display a processing control in the DLP control, where the processing control includes an entry for one or more functions applied to the encrypted file.
[0058] In combination with the fourth aspect, in certain implementations of the fourth aspect, the processing module is specifically used to: display in the DLP control an indication that the account does not have permission to view the encrypted file.
[0059] In a fifth aspect, a display device for an encrypted file is provided, the display device comprising a functional module for implementing the method in the second aspect and any possible implementation manner thereof.
[0060] In a sixth aspect, a display device for an encrypted image is provided, the display device including a processing module, the processing module being used to: receive a first encrypted image through a communication application logged in through an account, the communication application including a data leakage prevention DLP control for displaying the encrypted image; create a gallery sandbox clone for viewing the first encrypted image through a DLP permission management application; the DLP permission management application determines that the account has permission to view the first encrypted image; the gallery sandbox clone displays a first interface in the first DLP control, the first interface including the decrypted first encrypted image.
[0061] In combination with the sixth aspect, in certain implementations of the sixth aspect, before displaying the first interface of the gallery sandbox clone in the DLP control, the processing module is also used to: the communication application sends the first encrypted image to the DLP rights management application; the DLP rights management application sends the virtual plaintext of the first encrypted image to the gallery sandbox clone.
[0062] In combination with the sixth aspect, in certain implementations of the sixth aspect, the processing module is further used to: receive a second encrypted image through a communication application; the DLP permission management application determines that the account does not have permission to view the second encrypted image; and the DLP permission management application displays the encrypted second encrypted image in a second DLP control.
[0063] In combination with the sixth aspect, in certain implementations of the sixth aspect, the processing module is further used to: in response to exiting the communication application, destroy the gallery sandbox clone.
[0064] In a seventh aspect, an electronic device is provided, which includes a processor and a memory, the memory being used to store program instructions, the processor being used to: receive an encrypted file through a communication application, the user interface of the communication application including a data leakage prevention DLP control, and the encrypted file including an image file and / or a video file; the processor is also used to: display a decryption result of the encrypted file in the DLP control when the account has viewing permission for the encrypted file; or display an encryption result of the encrypted file in the DLP control when the account does not have viewing permission for the encrypted file.
[0065] In combination with the seventh aspect, in certain implementations of the seventh aspect, the processor is specifically used to: create a sandbox clone of the file display application; and display the decryption result of the encrypted file through the sandbox clone of the file display application in the DLP control.
[0066] In combination with the seventh aspect, in some implementations of the seventh aspect, the processor is further used to: create a link file, where the link file is used to map the virtual plaintext of the encrypted file and the ciphertext of the encrypted file.
[0067] In one possible implementation, the processor is further configured to: in response to an operation on the virtual plaintext of the encrypted file, display a processing control in the DLP control, where the processing control includes an entry for one or more functions applied to the encrypted file.
[0068] In combination with the seventh aspect, in certain implementations of the seventh aspect, the processor is specifically used to: display an indication in the DLP control that the account does not have permission to view the encrypted file.
[0069] In an eighth aspect, an electronic device is provided, comprising a processor and a memory, wherein the memory is used to store program instructions, and the processor is used to execute the program instructions stored on the memory to implement the method in the second aspect and any possible implementation thereof.
[0070] In a ninth aspect, an electronic device is provided, comprising a processor and a memory, the memory being used to store program instructions, the processor being used to: receive a first encrypted picture through a communication application logged in through an account, the communication application comprising a data leakage prevention DLP control for displaying the encrypted picture; create a gallery sandbox clone for viewing the first encrypted picture through a DLP permission management application; the DLP permission management application determines that the account has permission to view the first encrypted picture; the gallery sandbox clone displays a first interface in the first DLP control, the first interface comprising the decrypted first encrypted picture.
[0071] In combination with the ninth aspect, in certain implementations of the ninth aspect, before displaying the first interface of the gallery sandbox clone in the DLP control, the processor is also used to: the communication application sends the first encrypted image to the DLP rights management application; the DLP rights management application sends the virtual plaintext of the first encrypted image to the gallery sandbox clone, and the virtual plaintext is used to indicate the decrypted first encrypted image.
[0072] In combination with the ninth aspect, in certain implementations of the ninth aspect, the processor is further used to: receive a second encrypted image through a communication application; the DLP permission management application determines that the account does not have permission to view the second encrypted image; and the DLP permission management application displays the encrypted second encrypted image in a second DLP control.
[0073] In combination with the ninth aspect, in certain implementations of the ninth aspect, the processor is further configured to: in response to exiting the communication application, destroy the gallery sandbox clone.
[0074] In the tenth aspect, a computer program product is provided, which includes computer program code. When the computer program code is run on a computer, the method in the first aspect and any possible implementation thereof is executed, or the method in the second aspect and any possible implementation thereof is executed, or the method in the third aspect and any possible implementation thereof is executed.
[0075] In the eleventh aspect, a computer-readable storage medium is provided, which stores a computer program code. When the computer program code is run on a computer, the method in the first aspect and any possible implementation thereof is executed, or the method in the second aspect and any possible implementation thereof is executed, or the method in the third aspect and any possible implementation thereof is executed.
[0076] In the twelfth aspect, a chip is provided, comprising a processor for reading instructions stored in a memory, wherein when the processor executes the instructions, the chip implements the method in the first aspect and any possible implementation thereof, or the chip implements the method in the second aspect and any possible implementation thereof, or the chip implements the method in the third aspect and any possible implementation thereof. BRIEF DESCRIPTION OF THE DRAWINGS
[0077] FIG1 is a schematic diagram of a hardware architecture of an electronic device provided in an embodiment of the present application.
[0078] FIG2 is a schematic diagram of a software architecture of an electronic device provided in an embodiment of the present application.
[0079] 3 to 9 are schematic diagrams of user interfaces of the encrypted file management method provided in an embodiment of the present application.
[0080] 10 to 12 are schematic diagrams of user interfaces of the encrypted file sharing method provided in an embodiment of the present application.
[0081] 13 to 17 are schematic diagrams of a method for displaying an encrypted file in an instant messaging application according to an embodiment of the present application.
[0082] 18 to 20 are schematic diagrams of a method for displaying an encrypted file in an email application according to an embodiment of the present application.
[0083] 21 and 22 are schematic diagrams of a user interface of another method for displaying encrypted files provided in an embodiment of the present application.
[0084] FIG23 is a schematic diagram of a method for displaying an encrypted file provided in an embodiment of the present application.
[0085] FIG24 is a schematic diagram of another method for displaying an encrypted file provided in an embodiment of the present application.
[0086] Figure 25 is a schematic diagram of a system architecture provided in an embodiment of the present application.
[0087] FIG26 is a schematic diagram of a display device for an encrypted file provided in an embodiment of the present application.
[0088] Figure 27 is a schematic diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0089] The terms used in the following embodiments are only for the purpose of describing specific embodiments and are not intended to limit the present application. As used in the specification of this application and the appended claims, the singular expressions "a", "an", "said", "above", "the" and "this" are intended to also include expressions such as "one or more", unless there is a clear contrary indication in the context. It should also be understood that in the following embodiments of the present application, "at least one", "one or more" refer to one, two or more. The term "and / or" is used to describe the association relationship of associated objects, indicating that three relationships can exist; for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. The character " / " generally indicates that the previous and subsequent associated objects are in an "or" relationship.
[0090] References to "one embodiment" or "some embodiments" in this specification mean that a particular feature, structure, or characteristic described in conjunction with that embodiment is included in one or more embodiments of the present application. Thus, phrases such as "in one embodiment," "in some embodiments," "in other embodiments," and "in yet other embodiments" appearing in various places in this specification do not necessarily refer to the same embodiment, but rather mean "one or more but not all embodiments," unless otherwise specifically emphasized. The terms "including," "comprising," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.
[0091] 1 shows a schematic structural diagram of an electronic device 100. The electronic device 100 may include a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, an earphone interface 170D, a sensor module 180, a button 190, a motor 191, an indicator 192, a camera 193, a display 194, and a subscriber identification module (SIM) card interface 195. The sensor module 180 may include a pressure sensor 180A, a gyroscope sensor 180B, an air pressure sensor 180C, a magnetic sensor 180D, an acceleration sensor 180E, a distance sensor 180F, a proximity light sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, etc.
[0092] It should be understood that the structures illustrated in the embodiments of the present application do not constitute a specific limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 may include more or fewer components than shown, or may combine or separate certain components, or arrange the components differently. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.
[0093] The processor 110 may include one or more processing units. For example, the processor 110 may include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU). The different processing units may be independent devices or integrated into one or more processors.
[0094] The controller may be the nerve center and command center of the electronic device 100. The controller may generate an operation control signal according to the instruction operation code and the timing signal to complete the control of fetching and executing instructions.
[0095] Processor 110 may also include a memory for storing instructions and data. In some embodiments, the memory in processor 110 is a cache memory. This memory can store instructions or data that have just been used or are being recycled by processor 110. If processor 110 needs to use the same instruction or data again, it can directly access the memory. This avoids duplicate accesses, reduces processor 110 latency, and thus improves system efficiency.
[0096] In some embodiments, the processor 110 may include one or more interfaces. The interfaces may include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface.
[0097] The MIPI interface can be used to connect the processor 110 to peripheral devices such as the display 194 and the camera 193. MIPI interfaces include the camera serial interface (CSI) and the display serial interface (DSI). In some embodiments, the processor 110 and the camera 193 communicate via the CSI interface to implement the camera function of the electronic device 100. The processor 110 and the display 194 communicate via the DSI interface to implement the display function of the electronic device 100.
[0098] The USB interface 130 is an interface that complies with USB standards and may be a Mini USB interface, a Micro USB interface, a USB Type-C interface, or the like. The USB interface 130 can be used to connect a charger to charge the electronic device 100, or to transfer data between the electronic device 100 and peripheral devices. It can also be used to connect headphones to play audio. This interface can also be used to connect other electronic devices, such as augmented reality devices.
[0099] It is understood that the interface connection relationship between the modules illustrated in the embodiments of the present application is merely an illustrative illustration and does not constitute a structural limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 may also adopt different interface connection methods from the above embodiments, or a combination of multiple interface connection methods.
[0100] The wireless communication function of the electronic device 100 can be implemented through the antenna 1, the antenna 2, the mobile communication module 150, the wireless communication module 160, the modem processor and the baseband processor.
[0101] Electronic device 100 implements display functionality through a GPU, display screen 194, and an application processor. A GPU is a microprocessor for image processing that connects display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. Processor 110 may include one or more GPUs that execute program instructions to generate or modify display information.
[0102] Display screen 194 is used to display images, videos, and the like. Display screen 194 includes a display panel. The display panel can be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a MiniLED, a MicroLED, a Micro-oLed, or a quantum dot light-emitting diode (QLED). In some embodiments, electronic device 100 may include one or N display screens 194, where N is a positive integer greater than one.
[0103] Electronic device 100 can implement a camera function using an ISP, camera 193, a video codec, a GPU, a display 194, and an application processor. The ISP processes data fed back by camera 193. Camera 193 is used to capture still images or video. The digital signal processor processes digital signals, and can process not only digital image signals but also other digital signals. The video codec compresses or decompresses digital video.
[0104] NPU is a neural-network (NN) computing processor. By drawing on the structure of biological neural networks, such as the transmission mode between neurons in the human brain, it can quickly process input information and can also continuously self-learn.
[0105] The external memory interface 120 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the electronic device 100. The external memory card communicates with the processor 110 through the external memory interface 120 to implement a data storage function.
[0106] The internal memory 121 can be used to store computer executable program codes, which include instructions. The processor 110 executes various functional applications and data processing of the electronic device 100 by running the instructions stored in the internal memory 121. The internal memory 121 may include a program storage area and a data storage area. Among them, the program storage area can store an operating system, an application required for at least one function (such as a sound playback function, an image playback function, etc.), etc. The data storage area can store data created during the use of the electronic device 100 (such as audio data, a phone book, etc.), etc. In addition, the internal memory 121 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), etc.
[0107] The electronic device 100 can implement audio functions such as music playback and recording through the audio module 170, the speaker 170A, the receiver 170B, the microphone 170C, the headphone jack 170D, and the application processor.
[0108] The buttons 190 include a power button, a volume button, and the like. The buttons 190 may be mechanical buttons or touch buttons. The electronic device 100 may receive key inputs and generate key signal inputs related to user settings and function control of the electronic device 100.
[0109] Motor 191 can generate vibration prompts. Motor 191 can be used for incoming call vibration prompts, and can also be used for touch vibration feedback.
[0110] The indicator 192 may be an indicator light, which may be used to indicate the charging status, power level changes, messages, missed calls, notifications, etc.
[0111] The software system of the electronic device 100 can adopt a layered architecture, an event-driven architecture, a micro-kernel architecture, a micro-service architecture, or a cloud architecture. In the embodiment of the present application, the Android system with a layered architecture is used as an example to illustrate the software structure of the electronic device 100.
[0112] It is understood that the interface connection relationship between the modules illustrated in the embodiments of the present application is merely an illustrative illustration and does not constitute a structural limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 may also adopt different interface connection methods from the above embodiments, or a combination of multiple interface connection methods.
[0113] Figure 2 is a software structure diagram of the electronic device 100 according to an embodiment of the present application. The layered architecture divides the software into several layers, each with clear roles and division of labor. The layers communicate with each other through software interfaces. In some embodiments, the Android system is divided into four layers: the application (app) layer, the application framework layer, the Android runtime (Android runtime) and system libraries, and the kernel layer. The application layer may include a series of application packages.
[0114] As shown in FIG2 , the application package may include applications such as camera, gallery, calendar, call, map, navigation, WLAN, Bluetooth, music, video, and short message.
[0115] The application framework layer provides an application programming interface (API) and programming framework for applications in the application layer. The application framework layer includes some predefined functions.
[0116] As shown in FIG2 , the application framework layer may include a window manager, an activity manager, a package manager, a resource manager, a view system, a telephony manager, a notification manager, and the like.
[0117] Resource Manager, also known as Resource Management Service (RMS), provides various resources for applications, such as localized strings, icons, images, layout files, video files, and so on.
[0118] A window manager, also known as a window management service (WMS), manages windowed programs. It can determine the display size, determine whether a status bar is present, lock the screen, and take screenshots.
[0119] The component manager, also known as the component management service (CMS), manages and schedules various application components in the system.
[0120] The package manager, also known as the package manager service (PMS) or bundle manager service (BMS), is responsible for functions such as application installation and uninstallation, component query and matching, and permission management.
[0121] The view system includes visual controls, such as those for displaying text and images. The view system is used to build applications. A display interface can consist of one or more views. For example, a display interface containing a text notification icon might include a view for displaying text and a view for displaying images.
[0122] The Notification Manager allows applications to display notifications in the status bar. These messages can be displayed briefly and then disappear automatically without user interaction. For example, the Notification Manager is used to notify users of completed downloads and message reminders. The Notification Manager can also display notifications in the top status bar of the system as icons or scrolling text, such as notifications from background applications, or as dialog windows on the screen. Examples include text messages in the status bar, beeps, vibrations on electronic devices, and flashing indicator lights.
[0123] The system library can include multiple functional modules, such as a surface manager, media libraries, a 3D graphics processing library (such as OpenGL ES), and a 2D graphics engine (such as SGL).
[0124] The surface manager is used to manage the display subsystem and provide fusion of 2D and 3D layers for multiple applications.
[0125] The media library supports playback and recording of a variety of common audio and video formats, as well as static image files. The media library can support a variety of audio and video encoding formats, such as MPEG4, H.264, MP3, AAC, AMR, JPG, PNG, etc.
[0126] The 3D graphics processing library is used to implement 3D graphics drawing, image rendering, compositing, and layer processing.
[0127] A 2D graphics engine is a drawing engine for 2D drawings.
[0128] The kernel layer is the layer between hardware and software. The kernel layer includes at least display driver, camera driver, audio driver, and sensor driver.
[0129] Before formally introducing the embodiments of the present application, some terms that may be used in the following embodiments are first explained and illustrated.
[0130] Data loss prevention (DLP) is a solution comprised of a set of technologies, centered around identifying and classifying data content. This data can exist in the form of emails, files, data packages, applications, or data stores. Data can be detected regardless of whether it is stored, in use, or in transit across the network. DLP can also provide logging, tagging, encryption, permission control, and blocking of sensitive information based on established policies.
[0131] In computing, sandbox technology is a security mechanism used to isolate running programs, limiting the access rights of untrusted processes or code at runtime. Programs running in a sandbox can only access the resources loaded by the sandbox, without affecting external applications, systems, or platforms, preventing them from permanently changing other programs or data on the computer.
[0132] Communication apps, also known as messaging applications, are software programs used for communication between different users. Users can use these apps to exchange messages, voice messages, videos, and other forms of communication. Common communication apps include instant messaging (IM), voice calling, video calling, email, and social media.
[0133] In order to improve the efficiency of encrypted data processing by electronic devices such as computers and mobile phones while improving data security such as storage security and transmission security, the present application provides a file management method. This file management method can be used to encrypt and manage image and / or video files to achieve efficient transmission of image and / or video files between different electronic devices and efficient processing of these files by different electronic devices.
[0134] The above-mentioned file management method can be applied to portable electronic devices such as mobile phones and tablet computers (such as the electronic device 100 described above), wearable devices such as smart watches and smart glasses, or computer devices such as servers or server clusters. For ease of explanation, these devices are collectively referred to as electronic devices below. It should be noted that this application does not limit the type of electronic devices.
[0135] In some examples, the image file described in the present application can be one or more of the following formats: Joint Photographic Experts Group (JPEG / JPG) format, Portable Network Graphics (PNG) format, bitmap (BMP) format, Graphics Interchange Format (GIF), Tag Image File Format (TIFF), raw format or high efficiency image file format (HEIF), etc.
[0136] In some examples, the video file described in this application can be one or more of the following format files: Moving Picture Experts Group (MPEG)-4 format, Audio Video Interleaved (AVI), Windows Media Video (WMV) or Streaming Media Video (FLV), etc.
[0137] For ease of explanation, the following embodiments use image files as an example to illustrate the file management method provided by this application, and the video file management method can be implemented for reference.
[0138] Figure 3 exemplarily provides a user interface of a picture processing application. For example, the user interface can be called a first user interface 10. The first user interface 10 can be composed of multiple display controls. For example, the first user interface 10 can include a picture information display control 11 and a picture processing control 12.
[0139] In some examples, the picture information display control 11 can be used to display the picture itself in the first display area of the first user interface 10, and the picture information display control 11 can also be used to display picture-related information in the second display area of the first user interface 10, such as the time and location where the picture was saved.
[0140] In some examples, the image processing control 12 can be used to display portals for functions related to the image displayed in the first user interface 10. For example, the image processing control 12 can display portals for a "share" function, a "favorite" function, an "edit" function, a "delete" function, and a "more" function. In one possible implementation, these multiple function portals can be displayed in the form of icons and / or text.
[0141] For example, in response to the user clicking on the icon corresponding to the entry of the “delete” function, the electronic device may delete the picture currently displayed on the first user interface 10 .
[0142] Exemplarily, in response to the user clicking on the icon corresponding to the entrance of the "more" function, the electronic device can display the "more functions" display control 13 as shown in Figure 3, and the "more functions" display control 13 can display the entrances of some functions supported by the picture currently displayed by the first user interface 10 that are not displayed on the picture processing control 12.
[0143] For example, the picture currently displayed on the first user interface 10 is moved to the entry of the existing encrypted album function. For another example, the entry of the new encrypted album function is created according to the picture currently displayed on the first user interface 10 .
[0144] In a possible implementation, the multiple function entries displayed on the "more functions" display control 13 may be displayed in the form of icons and / or text.
[0145] In some examples, in response to a user selecting the "Move to Encrypted Album ABC" function entry 14 on the "More Functions" display control 13, the electronic device may move the image currently displayed on the first user interface 10 to the already created encrypted album ABC. Alternatively, the electronic device may configure an authorization policy for the image currently displayed on the first user interface 10, where the authorization policy is consistent with the authorization policy for the images and / or videos in the encrypted album ABC.
[0146] For example, the above authorization policy may refer to the permissions of different users to view, edit, etc. the pictures and / or videos in the encrypted album ABC.
[0147] In some examples, in response to the user selecting the “move and create a new encrypted album” function entry 15 on the “more functions” display control 13 , the electronic device may create a new authorization policy for the picture currently displayed on the first user interface 10 .
[0148] Exemplarily, in response to the user selecting the "Move and create a new encrypted album" function entry 15 on the "More functions" display control 13, the electronic device can create a new encrypted album, which can include pictures displayed by the aforementioned first user interface 10. The electronic device can configure an authorization policy for the encrypted album to implement the configuration of an authorization policy for the pictures and / or videos contained in the album.
[0149] In one possible implementation, the name of the newly created encrypted album can be determined based on the content of the image displayed on the first user interface 10. For example, if the image displayed on the first user interface 10 is of a yoga workout, the name of the newly created encrypted album can be "Fitness." In another possible implementation, the electronic device can also provide a function entry for modifying the name of the newly created encrypted album.
[0150] In some examples, in response to a user selecting the "Move and Create New Encrypted Album" function entry 15 on the "More Functions" display control 13, the electronic device may display an album password setting interface 18 as shown in FIG4 . This album password setting interface 18 may include a password input control 19A, a password confirmation control 19B, and password prompt information 19C. The password input control 19A may be used by the user to enter the encrypted album password for the first time, the password confirmation control 19B may be used by the user to enter the encrypted album password for the second time, and the password prompt information 19C may be used to indicate how to set the album password.
[0151] In some examples, in response to a user confirming an operation on encrypted album password setting interface 18, the electronic device may display a second user interface, as shown in FIG5 or FIG6 , which can be used to select users authorized to access the newly created encrypted album. For ease of explanation, the user interface shown in FIG5 is hereinafter referred to as second user interface 20A, and the user interface shown in FIG6 is hereinafter referred to as second user interface 20B.
[0152] As shown in Figure 5, the second user interface 20A can be used to display identification information 21 of multiple users that can be selected. For example, the user's identification information can refer to the user's name or contact information. In other words, the second user interface 20A can be used to display multiple selectable user names or user contact information.
[0153] As shown in FIG6 , the second user interface 20B may be used to display identification information 22 of a plurality of selectable user groups, such as a “family” group, a “colleague” group, or a “classmate” group.
[0154] The user can select one or more users or user groups in the second user interface 20A or the second user interface 20B. In response to the user's selection, the electronic device can grant the one or more users or user groups selected by the user permission to access the newly created encrypted album.
[0155] For example, in response to a user selecting one or more users on the second user interface 20A, the electronic device may display a first authorization prompt control 25 as shown in FIG7 . This first authorization prompt control 25 may be used to request the user to confirm whether to grant the selected users permission to view the encrypted album. In response to the user's confirmation operation, the electronic device may record the authorized user information in the authorization policy of the encrypted album for subsequent management of the encrypted album. In response to the user's cancellation operation, the electronic device may display the second user interface 20A as shown in FIG5 .
[0156] For example, in response to the user selecting one or more users or user groups on the second user interface 20B, the electronic device may display a second authorization prompt control 26 as shown in FIG8 . The second authorization prompt control 26 may be used to request the user to confirm the type of permission granted to the selected user for the encrypted album or encrypted pictures. For example, the second authorization prompt control 26 may be used to request confirmation whether to grant the selected user permission to view pictures in the encrypted album. The second authorization prompt control 26 may also be used to request confirmation whether to grant the selected user permission to use pictures in the encrypted album. Here, the permission to use pictures in the encrypted album may include viewing permission, saving permission, editing permission, and forwarding permission, etc. Therefore, when the user confirms granting the selected user permission to use pictures in the encrypted album, the user also grants the selected user permission to view pictures in the encrypted album.
[0157] In some examples, for the same encrypted image or the same encrypted album, users can be roughly divided into three categories based on their permissions: first-category users, second-category users, and third-category users. First-category users may refer to users with permission to use the encrypted image or images in the encrypted album, second-category users may refer to users with permission to view the encrypted image or images in the encrypted album, and third-category users may refer to users without permission to view the encrypted image or images in the encrypted album.
[0158] For example, referring to Figure 7 , in response to a user confirming the first authorization prompt control 25, the electronic device may set the selected user as a second-category user of the encrypted album. Referring to Figure 8 , in response to a user granting the selected user permission to use pictures in the encrypted album, the electronic device may set the selected user as a first-category user of the encrypted album.
[0159] In some scenarios, the second user interface 20A may also be referred to as a contact selection interface, and the second user interface 20B may also be referred to as a group selection interface. In one possible implementation, each of the second user interface 20A and the second user interface 20B may be provided with an interface control for switching between user interfaces. In response to a user operating the interface control, the electronic device may switch between the second user interface 20A and the second user interface 20B.
[0160] For example, as shown in Figures 5 and 6, the second user interface 20A and the second user interface 20B may be provided with a "contact selection interface" switching control 23 and a "group selection interface" switching control 24. In response to the user selecting the "group selection interface" switching control 24 in the second user interface 20A, the electronic device may display the second user interface 20B as shown in Figure 6. In response to the user selecting the "contact selection interface" switching control 23 in the second user interface 20B, the electronic device may display the second user interface 20A as shown in Figure 5.
[0161] In some examples, in response to user operations, the electronic device can encrypt multiple pictures or multiple videos simultaneously.
[0162] FIG9 exemplarily provides a user interface for an electronic device to manage multiple pictures, for example, referred to as a third user interface 30 .
[0163] One or more pictures can be displayed on the third user interface 30. In response to the user's operation on the picture displayed on the third user interface 30 (for example, long press, hard press, etc.), the electronic device can display one or more check box controls 31 on the third user interface 30. The check box 31 can be used to achieve simultaneous selection of multiple pictures.
[0164] In some examples, in response to a user long pressing a picture on the third user interface 30, the electronic device can display a check box control 31 in the lower right corner of all pictures displayed on the third user interface 30. In response to a user clicking one or more of the multiple check box controls 31, the electronic device can determine that the picture corresponding to the clicked check box control 31 is the picture selected by the user.
[0165] The third user interface 30 may also be provided with an image processing control 12. In some examples, the image processing control 12 may be used to display portals for functions related to the image displayed in the third user interface 30. For example, the image processing control 12 may display portals for a "share" function, a "favorite" function, an "edit" function, a "delete" function, and a "more" function. In one possible implementation, these multiple function portals may be displayed in the form of icons and / or text.
[0166] In response to the user selecting a plurality of pictures on the third user interface 30 and then selecting a function entry displayed by the picture processing control 12 , the electronic device may execute corresponding functions for the plurality of pictures selected by the user.
[0167] Exemplarily, in response to the user selecting three pictures on the third user interface 30 and then selecting the icon corresponding to the entrance of the "more" function displayed on the picture processing control 12, the electronic device can display the "more functions" display control 13 as shown in Figure 9. The "more functions" display control 13 can display the entrances of some functions supported by the picture currently displayed on the third user interface 30 that are not displayed on the picture processing control 12.
[0168] In some examples, in response to a user selecting the "Move to Encrypted Album ABC" function entry 14 on the "More Functions" display control 13, the electronic device may move the image currently displayed on the first user interface 10 to the already created encrypted album ABC. Alternatively, the electronic device may configure an authorization policy for the image currently displayed on the first user interface 10, where the authorization policy is consistent with the authorization policy for the images and / or videos in the encrypted album ABC.
[0169] In some examples, in response to the user selecting the “move and create a new encrypted album” function entry 15 on the “more functions” display control 13 , the electronic device may create a new authorization policy for the picture currently displayed in the first user interface 10 .
[0170] For the related descriptions of the “Move to Encrypted Album ABC” function entry 14 and the “Move and Create New Encrypted Album” function entry 15 , please refer to the related descriptions in FIG3 , which will not be repeated here.
[0171] For encrypted pictures or videos on electronic devices, the electronic devices can perform decryption, sharing, and other operations based on the user's operations. When encrypted pictures or encrypted videos are sent to users who are not authorized to view them, the electronic devices can prompt the user to perform corresponding processing, thereby reducing the risk of data leakage.
[0172] FIG10 exemplarily provides a user interface of a communication application. In some examples, the communication application may include instant messaging software such as Changlian. This application does not impose any restrictions on this. For ease of explanation, the instant messaging software will be referred to as an IM application below.
[0173] For example, the user interface of the IM application in FIG. 10 may be referred to as a fourth user interface 40 , and the fourth user interface 40 may include a plurality of display controls.
[0174] For example, the fourth user interface 40 may include a title display control 41 , a dialogue display control 42 , and a tool display control 43 .
[0175] In some examples, the title display control 41 can be used to display the title of the communication content on the fourth user interface 40. For example, the title display control 41 can be used to display information: "Conversation with User A", "Conversation with Group X", etc., or, the title display control 41 can also display the information "User A", "Group X" to respectively represent the conversation between the current user and User A, and the conversation between the current user and Group X.
[0176] In some examples, the conversation display control 42 can be used to display detailed information of the user conversation on the fourth user interface 40. For example, the conversation display control 42 can display text information, picture information, video information, encrypted picture information or encrypted video information of the user conversation.
[0177] In some examples, the tool display control 43 can be used to display input controls of an IM application, such as an input box, a send button, a voice message send button, and the like.
[0178] In some examples, the tool display control 43 can be used to display one or more functions supported by the IM application, such as a picture sending function, an emoticon sending function, a location sending function, or a file sending function.
[0179] Exemplarily, in response to the user selecting the icon 44 of the picture sending function in the tool display control 43 , the electronic device may display a picture selection interface 50 as shown in FIG. 11 , or the fifth user interface 50 .
[0180] One or more picture selection controls may be displayed on the fifth user interface 50 , and the picture selection controls may be used to indicate entrances for selecting pictures from different sources.
[0181] For example, the fifth user interface 50 may display a first picture selection control 51, a second picture selection control 52, and a third picture selection control 53. The first picture selection control 51 is used to indicate a function entry for retaking a picture using the electronic device. In other words, in response to a user selecting the first picture selection control 51, the electronic device may display a shooting preview interface. In response to the user's shooting operation, the electronic device may determine that the picture just taken by the user is the selected picture to be sent. The second picture selection control 52 may be used to indicate a function entry for selecting a picture locally stored on the electronic device. For example, in response to a user selecting the second picture selection control 52, the electronic device may display a user interface for a "Gallery" application. In response to a user selecting one or more pictures in the user interface, the electronic device may determine that the picture selected by the user is the selected picture to be sent.
[0182] The third picture selection control 53 can be used to indicate a selection entry for an encrypted picture. For example, in response to a user selecting the third picture selection control 53 , the electronic device can display a user interface for selecting an encrypted picture.
[0183] In some examples, the user interface for selecting encrypted pictures can be used to display one or more encrypted pictures, and the user interface for selecting encrypted pictures can also be used to indicate relevant information of each encrypted picture, such as the name of the album described in the encrypted picture, the user authorized to access the encrypted picture, or the source of the encrypted picture, etc.
[0184] In one possible implementation, for multiple encrypted images contained in the same album, the user interface for selecting an encrypted image can be displayed on an album-by-album basis. In other words, the aforementioned user interface for selecting an encrypted image can also display one or more encrypted albums, each of which can contain one or more encrypted images, and each of these encrypted images can use the same authorization policy. In response to the user selecting an encrypted album, the electronic device can display the one or more encrypted images contained in the encrypted album for further selection by the user.
[0185] In response to the user selecting one or more encrypted pictures on the user interface for selecting encrypted pictures, the electronic device may determine that these pictures are selected pictures that need to be sent.
[0186] Before sending the encrypted image, the electronic device may first determine the recipient's permission to view the encrypted image to be sent. For example, the electronic device may first determine whether the recipient has permission to view the encrypted image to be sent. If the recipient has permission to view the encrypted image to be sent, the electronic device sends the encrypted image to the recipient. If the recipient does not have permission to view the encrypted image to be sent, in some examples, the electronic device may display a third authorization prompt control 54 as shown in FIG. 12 . This third authorization prompt control 54 may be used to prompt the recipient to grant permission to view the encrypted image to be sent.
[0187] For example, the third authorization prompt control 54 may include one or more options that may be used to indicate different authorization methods or schemes. For example, the authorization prompt control 54 may include a first option 55A, a second option 55B, and a third option 55C. The third option 55C may also be referred to as a "cancel send" option or a "relinquish authorization" option. In response to the user selecting the third option 55C, the electronic device may cancel the sending of the user-selected encrypted image and prompt the user to reselect an image.
[0188] In some scenarios, first option 55A may also be referred to as a "decrypt this time only" option or a "single authorization" option. In some examples, in response to the user selecting first option 55A, the electronic device may set a valid access time for the encrypted image to be sent. The receiving user may view the contents of the encrypted image only within the valid access time. After the valid access time expires, the receiving user may no longer view the contents of the encrypted image.
[0189] In some scenarios, the second option 55B may also be referred to as an "always decrypt" option or a "long-term authorization" option. In some examples, in response to the user selecting the second option 55B, the electronic device may add the receiving user to a list of users authorized to view the encrypted image to be sent, or in other words, the electronic device may update the authorization policy for the encrypted image to be sent so that the authorization policy indicates that the receiving user has permission to view the encrypted image to be sent.
[0190] In some examples, the encrypted pictures to be sent may be all pictures from the same encrypted album. In response to the user selecting the second option 55B, the electronic device may update the authorization policy of the encrypted album.
[0191] Continuing with FIG11 , the fifth user interface 50 may also display one or more pictures, which may be arranged in the order in which they were sent or shared by the user. These pictures may be encrypted or non-encrypted. In some scenarios, these pictures for user selection may be called "recently used" pictures.
[0192] In response to the user selecting a non-encrypted picture, the electronic device may send the non-encrypted picture selected by the user to a receiving user.
[0193] In response to the user's operation of selecting an encrypted picture, the electronic device may first determine the receiving user's authority to the encrypted picture to be sent. Exemplarily, the electronic device may determine whether the receiving user has the authority to view the encrypted picture to be sent. If the receiving user has the authority to view the encrypted picture to be sent, the electronic device will send the encrypted picture to the receiving user. In the case where the receiving user does not have the authority to view the encrypted picture to be sent, in some examples, the electronic device may display a third authorization prompt control 54 as shown in Figure 12, which may be used to prompt the receiving user to grant permission to view the encrypted picture to be sent. For the description of the third authorization prompt control 54, please refer to the relevant content in the previous text and will not be repeated here.
[0194] In order to improve the display efficiency of encrypted files such as encrypted pictures and encrypted videos in communication applications, the embodiment of the present application also provides a method for displaying encrypted pictures and encrypted videos. The following is an explanation using the method for displaying encrypted pictures as an example, and the method for displaying encrypted videos can be used as a reference.
[0195] The electronic device can display different image content on the user interface of an application such as a communication application depending on whether the receiving user has the authority to view the encrypted image. If the receiving user has the authority to view the encrypted image, the electronic device can directly display the content of the encrypted image on the user interface, or in other words, the electronic device can display the content of the encrypted image normally; if the receiving user does not have the authority to view the encrypted image, the electronic device may not display the content of the encrypted image, or in other words, the electronic device can display the encrypted image in an encrypted manner.
[0196] In some examples, user C may send the first encrypted picture P1 to user A and user B respectively through an instant messaging application (eg, an IM application), wherein user A has permission to view the first encrypted picture P1, and user B does not have permission to view the first encrypted picture P1.
[0197] Figure 13 shows the user interface of an IM application in which user A and user C are chatting. The user avatar icon on the left represents user C, and the user avatar icon on the right represents user A. As shown, the first encrypted image P1 is displayed normally in this user interface. In other words, user A can view the content of the first encrypted image P1 sent by user C normally.
[0198] Figure 14 shows the user interface of an IM application in which users B and C are chatting. The user avatar icon on the left represents user C, and the user avatar icon on the right represents user B. As shown in the figure, the first encrypted image P1 is displayed encrypted in this user interface. In other words, user B cannot view the content of the first encrypted image P1 sent by user C.
[0199] In some examples, user C can send the first encrypted picture P1 to a user group (e.g., group X) via the aforementioned IM application. Group X may include users who have permission to view the first encrypted picture, and may also include users who do not have permission to view the first encrypted picture. For example, group X may include user A, user B, and user C, where user A has permission to view the first encrypted picture P1, and user B does not have permission to view the first encrypted picture P1.
[0200] FIG15 shows a user interface in which user A logs into his or her IM application account and views a conversation in group X. As shown in the figure, the first encrypted picture P1 is displayed normally in the user interface. In other words, user A can view the content of the first encrypted picture P1 sent by user C normally.
[0201] FIG16 shows a user interface in which user B logs into his or her IM application account and views a conversation in group X. As shown in the figure, the first encrypted image P1 is displayed encrypted in the user interface. In other words, user B cannot view the content of the first encrypted image P1 sent by user C.
[0202] In some examples, for the situation in Figure 14 or Figure 16, the receiving user cannot view the first encrypted picture P1 or there are users in the user group who cannot view the first encrypted picture P1, the electronic device can display a prompt message 201 in the user conversation interface of the IM application of the sending user (C user) of the first encrypted picture P1. The prompt message 201 can be used to prompt the receiving user that the first encrypted picture P1 cannot be viewed or there are users in the user group who cannot view the first encrypted picture P1.
[0203] For example, as shown in FIG17 , the prompt information 201 may be: “The sent picture has been encrypted, and the other party has no permission to view it” or “The sent picture has been encrypted, and some users in the group have no permission to view it”, etc.
[0204] In some examples, as shown in FIG17 , user C may also send a second encrypted image P2 to user B or users in group X. This second encrypted image P2 may be an image that user B or all users in group X have permission to view. In this way, upon receiving the second encrypted image P2, user B or users in group X can all view the second encrypted image P2 normally.
[0205] In the above Figures 14 and 16, the example in which user B is unable to view the first encrypted image P1 may occur when user C mistakenly sends the first encrypted image P1 to user B or group X. By setting protection for the viewing permission of the first encrypted image P1, the risk of data leakage can be reduced and the user's sharing and control needs for encrypted files can be met.
[0206] Figures 18 and 19 illustrate how the aforementioned encrypted image and video display methods may be used in another communication application (email-based application). For example, user C sends a first encrypted image P1 to users A and B via an email-based application (e.g., an NM application). User A has permission to view the first encrypted image P1, but user C does not. It should be noted that user C can send the first encrypted image P1 to users A and B separately, or simultaneously to both.
[0207] Figure 18 shows the user interface of user A logging into an NM application account to view an email sent by user C. As shown in the figure, the first encrypted image P1 can be displayed normally, or in other words, user A can view the first encrypted image P1 normally. Figure 19 shows the user interface of user B logging into an NM application account to view an email sent by user C. As shown in the figure, the first encrypted image P1 is displayed encrypted, or in other words, user B cannot view the content of the first encrypted image P1.
[0208] In some examples, if user B does not have permission to view the first encrypted image P1 in the email sent by user C, the electronic device may display a prompt message 202 on the user interface of the sending user's NM application. This prompt message 202 may be used to indicate that the sent email contains images and / or videos that the receiving user does not have permission to view. For example, as shown in FIG20 , this prompt message 202 may be: "The email contains an encrypted image, and the other party does not have permission to view it."
[0209] In some examples, users who have permission to view encrypted images may also have permission to edit, forward, and save encrypted images. In other words, some users who have permission to view encrypted images may belong to the first category of users mentioned above, while others may belong to the second category of users mentioned above.
[0210] In some examples, for the same encrypted image, the electronic device may provide different encrypted image processing functions to the receiving user depending on the permissions of the receiving user.
[0211] For example, in conjunction with Figures 13 and 21, if user A is a second-category user, or in other words, user A only has permission to view encrypted images, when user A operates on the first encrypted image P1 in the conversation interface of the IM application in Figure 13, the electronic device will not respond to user A's operation. If user A is a first-category user, or in other words, user A has permission to use encrypted images, in response to user A's operation (e.g., clicking) on the first encrypted image P1 in the conversation interface in Figure 13, the electronic device can maximize the display of the first encrypted image P1, as shown in Figure 21.
[0212] In some examples, the electronic device may further display an encrypted image usage control 60 (or processing control 60), which may include one or more function entries applicable to the encrypted image, such as a "share" or "forward" function entry 61, an "edit" function entry 62, a "save" function entry 63, etc. In response to the user selecting one or more of these function entries, the electronic device may correspondingly display a user interface for forwarding, editing, or saving the encrypted image.
[0213] For example, in conjunction with Figures 18 and 22, if user A is a second-category user, or in other words, user A only has the permission to view encrypted images, when user A operates on the first encrypted image P1 of the NM application in Figure 18, the electronic device will not respond to user A's operation. If user A is a first-category user, or in other words, user A has the permission to use encrypted images, in response to user A's operation on the first encrypted image P1 (e.g., long press), the electronic device can display an encrypted image usage control 60 (or processing control 60) as shown in Figure 22. The encrypted image usage control 60 may include one or more function entries applicable to encrypted images, such as a "share" or "forward" function entry 61, an "edit" function entry 62, a "save" function entry 63, etc. In response to the user selecting one or more of these function entries, the electronic device can correspondingly display a user interface for forwarding, editing, or saving the encrypted image.
[0214] It should be noted that the above example is described with the first encrypted picture P1 or the second encrypted picture P2 as one picture. In the case where there are multiple encrypted pictures, the electronic device can display the decryption result or encryption result of each encrypted picture on the user interface of the IM application or NM application according to whether the user has viewing permission or use permission for each encrypted picture.
[0215] In the above example, the encrypted image content corresponding to the receiving user's permissions can be directly displayed in the user interface of the IM application and the NM application. The receiving user with viewing permission can directly view the decryption result of the encrypted image without jumping to other applications. The receiving user without viewing permission can be informed that the image cannot be viewed without jumping to other applications. The receiving user with usage permission can also forward, edit or save the encrypted image without jumping to other applications. The display efficiency of encrypted images is higher and the user experience is better.
[0216] In one possible implementation, if the receiving user has permission to view the encrypted image, the user interface for displaying the encrypted image in the aforementioned IM application and NM application may include a DLP control. This DLP control can be used to display the user interface of an encrypted image display application (e.g., a gallery sandbox clone), which can be used to display the decrypted content of the encrypted image. The following describes, in conjunction with Figures 23 and 24, how this functionality is implemented in an embodiment of the present application.
[0217] Figure 23 exemplarily provides an implementation method for displaying encrypted images directly in an encrypted manner on the user interface of a communication application for a receiving user who does not have permission to view the encrypted images. In other words, Figure 23 exemplarily provides an implementation method for implementing the display method of Figures 14, 16 and 19.
[0218] S101, the communication application receives the DLP file.
[0219] A communication application can refer to software used to send and receive messages between different users. For example, a communication application can refer to the IM application or NM application mentioned above. Different users can log in to a communication application using their application accounts. The process of sending and receiving messages between different users using a communication application can be understood as the process of sending and receiving messages between different application accounts.
[0220] For example, the communication application receiving the DLP file may refer to the IM application logged into the application account of user A or user B in the aforementioned text receiving the encrypted image sent by the IM application logged into the application account of user C.
[0221] For another example, the communication application receiving the DLP file may also refer to the NM application logged in to the application account of user A or user B in the previous text receiving the encrypted image sent by the NM application logged in to the application account of user C.
[0222] Here, DLP files or data leakage protection files may refer to files protected using a data leakage protection solution, such as the first encrypted image P1 and the second encrypted image P2 mentioned above.
[0223] S102: The communication application calls the DLP control.
[0224] In response to the communication application receiving the DLP file, the communication application may call a DLP control to process the received DLP file. The DLP control may be understood as a control set on the user interface of the communication application for processing the DLP file.
[0225] In some examples, the user interface of a communication application may include a DLP control that can determine, through the permission application management process, whether the communication application login account has permission to view DLP files. In some scenarios, the DLP control can also be understood as being able to determine how DLP files are displayed based on the permissions of the communication application login account.
[0226] S103: The communication application launches a rights management application process within the DLP control.
[0227] Here, the permission management application can also be called a DLP permission management application. The application can determine the permissions applicable to the DLP file for the current account based on the user's account and the authorization policy of the DLP file, and perform corresponding processing on the DLP file based on the permissions.
[0228] In some examples, the rights management application may determine that the DLP file received by the communication application is a picture or video file.
[0229] S104: The rights management application obtains the authorization policy of the DLP file from the rights management service.
[0230] In some scenarios, rights management services may also be referred to as DLP rights management services.
[0231] In some examples, the rights management application can parse the DLP file, obtain the encryption credentials, and send the encrypted credentials to the rights management service. The rights management service can obtain information such as the authorization policy and encryption key from the encrypted credentials and send this information to the rights management application.
[0232] For example, the rights management service may send the encrypted credentials to the cloud docking module, and the cloud docking module may upload the encrypted credentials to the cloud for identity authentication, credential verification, and policy resolution.
[0233] For example, for the aforementioned DLP rights management application and DLP rights management service, one possible scenario is that the DLP rights management application may include the DLP rights management service. In actual operation scenarios, the DLP rights management application and the DLP rights management service may run in two relatively independent processes, or the DLP rights management application and the DLP rights management service may run in the same process.
[0234] S105: The rights management application determines that the current account does not have the rights to view the DLP file.
[0235] The rights management application can determine, based on the obtained authorization policy, that the login account of the communication application that received the DLP file does not have the permission to view the DLP file.
[0236] S106 , the rights management application displays the encryption result of the encrypted image on the user interface of the communication application.
[0237] When it is determined that the account currently logged into the communication application does not have permission to view the DLP file, the permission management application can display the encryption result of the DLP file in the user interface of the communication application, for example, the encryption result of the first encrypted image P1 shown in Figure 14 or Figure 19.
[0238] In the above technical solutions, the processing of DLP files by communication applications, rights management applications, and rights management services can be understood as the processing of files by the processes corresponding to these applications or services.
[0239] For example, the communication application can correspond to the first process, the permission management application can correspond to the second process, and the permission management service can correspond to the fourth process. Data exchange or information transmission and reception between different applications can be achieved through inter-process communication, such as: pipes, message queues, sockets, shared memory or memory mapping, etc.
[0240] For example, in S106 , the rights management application displays the encryption result of the encrypted image on the user interface of the communication application, which can be understood as the second process displaying the encryption result of the encrypted image on the user interface of the communication application.
[0241] For another example, the operation of launching the rights management application process within the DLP control in S103 may include the first process sending the DLP file to the second process through inter-process communication.
[0242] For another example, the process in S104 where the rights management application obtains the authorization policy for the DLP file from the rights management service may include the second process sending the encryption credentials of the DLP file to the fourth process, and the fourth process sending information such as the authorization policy and encryption key to the second process.
[0243] In the above technical solution, by calling the DLP control within the communication application and launching the permission management application process within the DLP control to verify the permissions of the user's account, the electronic device can display the result that the user has no permission to view the encrypted image without executing the application jump, which makes the use of encrypted images more efficient and provides a better user experience.
[0244] Figure 24 exemplarily provides an implementation method for displaying encrypted images directly in a normal manner on the user interface of a communication application for a receiving user who has permission to view the encrypted images. In other words, Figure 24 exemplarily provides an implementation method for implementing the display methods of Figures 13, 15 and 18.
[0245] S201: The communication application receives a DLP file.
[0246] A communication application can refer to software used to send and receive messages between different users. For example, a communication application can refer to the IM application or NM application mentioned above. Different users can log in to a communication application using their application accounts. The process of sending and receiving messages between different users using a communication application can be understood as the process of sending and receiving messages between different application accounts.
[0247] In other examples, the application account may include a device account, such as a Huawei account, and the user can log in to the communication application through the device account.
[0248] For example, a communication application receiving a DLP file may refer to an IM application logged into the application account of user A or user B in the aforementioned text receiving an encrypted image sent by an IM application logged into the application account of user C.
[0249] For another example, a communication application receiving a DLP file may also refer to the NM application logged in to the application account of user A or user B in the previous text receiving an encrypted image sent by the NM application logged in to the application account of user C.
[0250] Here, DLP files or data leakage protection files may refer to files protected using a data leakage protection solution, such as the first encrypted image P1 and the second encrypted image P2 mentioned above.
[0251] S202: The communication application calls the DLP control.
[0252] In response to the communication application receiving the DLP file, the communication application may call a DLP control to process the received DLP file. The DLP control may be understood as a control set on the user interface of the communication application for the user to process the DLP file.
[0253] S203: The communication application launches a rights management application process within the DLP control.
[0254] Here, the permission management application can also be called a DLP permission management application. The application can determine the permissions applicable to the DLP file for the current account based on the user's account and the authorization policy of the DLP file, and perform corresponding processing on the DLP file based on the permissions.
[0255] S204: Optionally, the rights management application determines that the DLP file is a picture or video file.
[0256] The rights management application can verify the DLP file received by the communication application, determine the type of the DLP file, and thus determine how the DLP file is displayed.
[0257] S205: The rights management application obtains the DLP file authorization policy from the rights management service.
[0258] In some scenarios, rights management services may also be referred to as DLP rights management services.
[0259] In some examples, the rights management application can parse the DLP file, obtain the encryption credentials, and send the encrypted credentials to the rights management service. The rights management service can obtain information such as the authorization policy and encryption key from the encrypted credentials and send this information to the rights management application.
[0260] For example, the rights management service may send the encrypted credentials to the cloud docking module, and the cloud docking module may upload the encrypted credentials to the cloud for identity authentication, credential verification, and policy resolution.
[0261] S206: The rights management application determines that the current account has the rights to view or use the DLP file, and creates a DLP link file.
[0262] The rights management application can determine, based on the obtained authorization policy, that the login account of the communication application that received the DLP file has the permission to view the DLP file. If it is determined that the login account of the communication application has the permission to view the DLP file, the rights management application can create a DLP link file.
[0263] The DLP link file here can be understood as a mapping mechanism between plaintext and ciphertext. For example, this mapping mechanism can be implemented based on a user space file system (fuse). The rights management application can send the plaintext indicated by the DLP link file (e.g., virtual plaintext) to the application clone in the sandbox. The user can operate on the ciphertext indicated by the DLP link file by operating the virtual plaintext in the application clone in the sandbox. In other words, the virtual plaintext allows the decryption result of the DLP file to be presented to the user. On the other hand, displaying the decryption result of the DLP file in virtual plaintext can prevent data leakage of the DLP file.
[0264] S207, the permission management application creates a gallery sandbox clone in the sandbox.
[0265] In some scenarios, the gallery application clone in the sandbox can also be called the sandbox clone of the gallery application or the gallery sandbox clone, which can be understood as the gallery application clone running in the DLP sandbox. The gallery sandbox clone can only access the limited resource environment provided by the DLP sandbox.
[0266] In some examples, the rights management application can call the package management service to create a gallery sandbox clone, which can be used to display encrypted images.
[0267] Here, the gallery sandbox clone can be regarded as one of multiple file display applications. In some examples, the permission management application can also create other sandbox clones of applications for viewing or editing encrypted images. The aforementioned gallery sandbox clone is only an example.
[0268] S208: The rights management application sends a virtual plaintext file of the DLP file to the gallery sandbox clone.
[0269] In some examples, the rights management application can send a virtual plaintext file of the DLP file to the gallery sandbox clone through the component management service. The virtual plaintext file can be used to indicate the decryption result of the DLP file.
[0270] S209: The rights management application calls the extension component.
[0271] The extension component can be used to display the decryption results of the DLP file in the aforementioned DLP control. The aforementioned DLP control can be embedded in the user interface of the communication application. In some examples, the rights management application can call the extension component through the activity management service.
[0272] Exemplarily, the extension component may be a UIExtensionAbility component.
[0273] In some examples, the aforementioned DLP control can be embedded in the user interface of a communication application and used to provide the ability to display the user interfaces of other applications in the user interface of the communication application.
[0274] In some examples, the ability of the DLP control to display the user interfaces of other applications in the user interface of a communication application can be achieved by creating a corresponding sandbox clone process and mounting the component tree of the sandbox clone process into the component tree of the communication application.
[0275] For example, a rights management application can use the component management service to create and launch a sandbox clone process that displays the corresponding information within the DLP control. For images, this sandbox clone can be a gallery sandbox clone. The gallery sandbox clone process (including the aforementioned extension component process) can be used to display the gallery sandbox clone's user interface, which can include decrypted encrypted images or videos.
[0276] Compared with the method of launching the main process of the gallery sandbox clone, the process of the aforementioned extension component can load the necessary independent resources, does not rely on the main process of the gallery sandbox clone and its resources, and thus consumes less power.
[0277] In one possible implementation, in response to starting the process of the gallery sandbox clone, the electronic device can start the picture (or video) display service of the gallery sandbox clone. After the picture display service of the gallery sandbox clone is started, the electronic device can render, load and construct a graphic node tree according to the set encrypted picture display interface, and then mount the drawn display interface on the graphic node tree of the DLP control of the communication application. The electronic device can thus directly display the decrypted display interface of the encrypted picture or encrypted video in the user interface of the communication application.
[0278] Exemplarily, the graphic node tree of the user interface of the communication application may include multiple graphic node tree identifiers, which may include the identifier of the DLP control. During the display of the user interface of the communication application, the electronic device may mount the node of the user interface of the gallery sandbox clone on the graphic node tree of the communication application based on the identifier of the DLP control, and load the display interface of the encrypted picture into the gallery sandbox clone according to the graphic node tree of the user interface of the mounted gallery sandbox clone.
[0279] The content of the decrypted encrypted image can be displayed directly in the DLP control created in the user interface of the communication application, without the need to jump from the communication application to the image display application. This reduces the energy consumption of electronic devices, makes the display of encrypted images more efficient, and provides a better user experience.
[0280] S210: The gallery sandbox clone displays the decryption result of the encrypted image in the DLP control.
[0281] The Gallery Sandbox clone can display encrypted images normally in the display area where the DLP control is located.
[0282] In the above technical solutions, the processing of DLP files by communication applications, rights management applications, and rights management services can be understood as the processing of files by the processes of these applications or services.
[0283] For example, the communication application can correspond to the first process, the permission management application can correspond to the second process, the gallery application clone in the sandbox can correspond to the third process, and the permission management service can correspond to the fourth process. Data exchange or information reception and transmission between different applications can be achieved through inter-process communication, such as: pipes, message queues, sockets, shared memory or memory mapping, etc.
[0284] For example, the display of the decryption result of the encrypted image in the DLP control by the gallery sandbox clone in S210 can be understood as the display of the decryption result of the encrypted image in the DLP control on the user interface of the communication application by the third process.
[0285] For another example, in S203 , the rights management application launches the rights management application process within the DLP control, which may include the first process sending the DLP file to the second process through inter-process communication.
[0286] For example, the process in S205 in which the rights management application obtains the authorization policy of the DLP file from the rights management service may include the second process sending the encryption credentials of the DLP file to the fourth process, and the fourth process sending information such as the authorization policy and encryption key to the second process.
[0287] For another example, the process of the rights management application sharing the virtual plaintext file with the gallery application clone in S208 may include the process of the second process sending the virtual plaintext file to the third process.
[0288] In this technical solution, by invoking a DLP control within a communication app and launching a permissions management application process within the DLP control to verify the user's account permissions, and then displaying the decrypted encrypted image through an extended component, the electronic device can display the encrypted image content without having to jump to the app, resulting in more efficient use of encrypted images and a better user experience. Furthermore, using a separate process to display the decryption results of encrypted files facilitates the management and control of encrypted files, preventing their leakage.
[0289] FIG25 is a schematic diagram showing a system architecture applicable to an embodiment of the present application.
[0290] System services refer to programs or processes provided by the operating system of an electronic device that support normal system operation or provide necessary functions. System services can be automatically started when the operating system of the electronic device is started, or they can be started in response to user operations. The operation of system services does not need to rely on user interaction.
[0291] Applications can include both system applications and third-party applications. Among them, system applications refer to applications that can be used to provide basic services. System applications are usually integrated into the operating system of the electronic device and are used to implement the core functions of the operating system or provide basic services. Generally speaking, users cannot uninstall system applications. In other words, under normal circumstances, the operating system may not provide a functional entry for uninstalling system applications. Third-party applications generally refer to applications developed by unofficial or native platform developers. Third-party applications running on electronic devices can provide users with more functions.
[0292] The server can be used to provide data, resources, or capabilities support for applications on electronic devices. The server and the applications on the electronic devices can coordinate their work through a network interface to implement relevant functions of the applications.
[0293] In the embodiments of this application, the communication application may refer to an instant messaging application (such as the IM application mentioned above) or an email application (such as the NM application mentioned above). It should be noted that the methods for processing, managing, and displaying encrypted files provided in this application can also be applied to more third-party applications, and this application does not limit this. As mentioned above, the gallery application clone running in the sandbox in the system application can display the decryption results of encrypted pictures or encrypted videos in a manner embedded in the communication application.
[0294] The communication application account server can be used to provide data services for the communication application account application and the DLP server. For example, the DLP server can obtain the account information of user A, user B or user C of the IM application or NM application from the communication application account server. For another example, the communication application account application can verify the account information of user A, user B or user C based on the communication application account server.
[0295] The password management server can be used to manage the passwords of encrypted files, such as the passwords of the first encrypted image P1 or the second encrypted image P2 mentioned above. The password management server can also provide the password information of the encrypted files to the DLP server in response to the request of the DLP server.
[0296] The DLP server can verify the permissions of different users for encrypted files based on the different user accounts obtained from the communication application account server and the password information of the encrypted files obtained from the password management server. The DLP server can also generate access credentials for the encrypted files based on the verification results and send the access credentials to the DLP credential management service for management.
[0297] The communication application account application can collaborate with the communication application account server to verify and manage the account information of different users' communication applications and provide account services.
[0298] The DLP Rights Management application, as described in the previous examples, can be used to parse encrypted files (or DLP files), obtain encryption credentials, and send them to the DLP Rights Management Service. In some examples, the DLP Rights Management application can also be used to install or create a DLP sandbox clone of the Gallery application and grant authorized testing restricted sandbox permissions, including but not limited to network, printing, and clipboard permissions.
[0299] The DLP sandbox clone of the gallery app can be understood as a gallery app clone running in the DLP sandbox, which only has access to the limited resources and environment provided by the DLP sandbox. In embodiments of the present application, the gallery app clone can be used to display decrypted encrypted images or videos embedded in the user interface of a communication app.
[0300] The DLP Rights Management Service can determine the access permissions of different user accounts based on the access credentials provided by the DLP Credential Management Service and the user accounts provided by the Account Service. For example, it can determine that user A's account has permission to view the first encrypted image P1, but user B's account does not. The DLP Rights Management Service can also provide the user account's access permissions to the DLP Rights Management application.
[0301] Figure 26 shows an apparatus 2600 for displaying encrypted files, provided in an embodiment of the present application. This apparatus 2600 may have the functions of the electronic device in the aforementioned method embodiment and may be used to execute the steps performed by the functions of the electronic device in the aforementioned method embodiment. This function may be implemented in hardware, or in software or hardware executing corresponding software implementations. The hardware or software may include one or more modules corresponding to the aforementioned functions.
[0302] In a possible implementation, the apparatus 2600 for displaying an encrypted file may include an acquisition module 2610 and a processing module 2620 , and the acquisition module 2610 and the processing module 2620 are coupled to each other.
[0303] In some examples, the acquisition module 2610 can be used to support the electronic device in the aforementioned embodiments in acquiring user input, such as acquiring the user's operation on the first encrypted picture P1.
[0304] The processing module 2620 is used to support the electronic device in executing the processing actions in the above method embodiment, such as determining whether user A or user B has the authority to view the encrypted image.
[0305] Optionally, the apparatus 2600 for displaying an encrypted file may further include a storage unit 2630 for storing program codes and data of the apparatus 2600 for displaying an encrypted file.
[0306] FIG27 illustrates an electronic device 2700 provided in an embodiment of the present application. As shown in the figure, the electronic device 2700 includes at least one processor 2710 and a transceiver 2720. The processor 2710 is coupled to a memory and is configured to execute instructions stored in the memory to control the transceiver 2720 to send and / or receive signals.
[0307] Optionally, the electronic device 2700 further includes a memory 2730 for storing instructions.
[0308] In some embodiments, the processor 2710 and memory 2730 may be combined into a processing device, and the processor 2710 is configured to execute program codes stored in the memory 2730 to implement the aforementioned functions. In specific implementations, the memory 2730 may also be integrated into the processor 2710 or independent of the processor 2710.
[0309] In some embodiments, the transceiver 2720 may include a receiver (or receiver) and a transmitter (or transmitter).
[0310] The transceiver 2720 may further include an antenna, and the number of antennas may be one or more. The transceiver 2720 may be a communication interface or an interface circuit.
[0311] When the electronic device 2700 is a chip, the chip includes a transceiver module and a processing module. The transceiver module may be an input / output circuit or a communication interface; the processing module may be a processor, microprocessor, or integrated circuit integrated on the chip.
[0312] This embodiment also provides a computer-readable storage medium, which stores computer instructions. When the computer instructions are executed on an electronic device, the electronic device executes the above-mentioned related method steps to implement the method for displaying encrypted files in the above-mentioned embodiment.
[0313] This embodiment further provides a computer program product. When the computer program product is run on a computer, the computer is caused to execute the above-mentioned related steps to implement the method for displaying encrypted files in the above-mentioned embodiment.
[0314] In addition, embodiments of the present application further provide a device, which may be a chip, component, or module, and may include a processor and memory connected thereto. The memory is configured to store computer-executable instructions. When the device is in operation, the processor executes the computer-executable instructions stored in the memory, causing the chip to perform the encrypted file display method described in each of the above method embodiments.
[0315] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0316] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0317] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0318] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0319] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0320] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0321] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
Claims
1. A method for displaying an encrypted file, applied to an electronic device, characterized in that: include: Receiving an encrypted file through a communication application, wherein the user interface of the communication application includes a data leakage prevention (DLP) control, the communication application is logged in through an account, and the encrypted file includes an image file and / or a video file; If the account has viewing permission for the encrypted file, display the decryption result of the encrypted file in the DLP control; or When the account does not have viewing authority for the encrypted file, the encryption result of the encrypted file is displayed in the DLP control.
2. The display method according to claim 1, wherein: The displaying the decryption result of the encrypted file in the DLP control includes: Create a file displaying a sandbox clone of the application; The decryption result of the encrypted file is displayed in the DLP control through the sandbox clone of the file display application.
3. The display method according to claim 1 or 2, characterized in that: Displaying the decryption result of the encrypted file in the DLP control further includes: A link file is created, wherein the link file is used to map the virtual plaintext of the encrypted file and the ciphertext of the encrypted file.
4. The display method according to claim 1, wherein: The displaying the encryption result of the encrypted file in the DLP control includes: Indication information indicating that the account does not have permission to view the encrypted file is displayed in the DLP control.
5. A method for displaying an encrypted file, applied to an electronic device, characterized in that: include: The process of the communication application receives the encrypted file, the communication application is logged in through the account, and the encrypted file includes an image file and / or a video file; The data leakage prevention DLP rights management process receives the encrypted file sent by the communication application process; The DLP rights management process determines whether the account has the right to view the encrypted file; In the case where the account does not have the permission to view the encrypted file, the DLP permission management process displays the encryption result of the encrypted file on the user interface of the communication application; or When the account has permission to view the encrypted file, the DLP rights management process creates a sandbox clone of the file display application, and the process of the sandbox clone of the file display application displays the decryption result of the encrypted file on the user interface of the communication application.
6. The display method according to claim 5, characterized in that: The user interface of the communication application includes a DLP control, The DLP rights management process displays the encryption result of the encrypted file on the user interface of the communication application, including: The DLP rights management process displays the encryption result of the encrypted file in the DLP control; The process of the sandbox clone of the file display application displays the decryption result of the encrypted file on the user interface of the communication application, including: The process of the sandbox clone of the file display application displays the decryption result of the encrypted file in the DLP control.
7. The method according to claim 5 or 6, characterized in that Before the sandbox clone process of the file display application displays the decryption result of the encrypted file on the user interface of the communication application, the method further includes: The DLP rights management process creates a link file, wherein the link file is used to map the virtual plaintext of the encrypted file to the ciphertext of the encrypted file; The DLP rights management process sends the virtual plaintext of the encrypted file to the process of the sandbox clone of the file display application, where the virtual plaintext is used to indicate the decryption result of the encrypted file.
8. The display method according to any one of claims 5 to 7, characterized in that: The DLP rights management process determines whether the account has the right to view the encrypted file, including: The DLP rights management process obtains an authorization policy, where the authorization policy includes information indicating whether the account has permission to view the encrypted file.
9. The display method according to claim 5, wherein: The DLP rights management process displays the encryption result of the encrypted file on the user interface of the communication application, including: The DLP rights management process displays, on the user interface of the communication application, an indication that the account does not have the right to view the encrypted file.
10. A method for displaying an encrypted image, applied to an electronic device, characterized in that: include: A communication application logged in through an account receives a first encrypted image, wherein the communication application includes a data leakage prevention DLP control for displaying the encrypted image; Creating a gallery sandbox clone for viewing the first encrypted image through a DLP rights management application; The DLP rights management application determines that the account has permission to view the first encrypted image; The gallery sandbox clone displays a first interface in a first DLP control, where the first interface includes the decrypted first encrypted image.
11. The display method according to claim 10, wherein: Before displaying the first interface of the gallery sandbox clone in the DLP control, the method further includes: The communication application sends the first encrypted image to the DLP rights management application; The DLP rights management application sends the virtual plaintext of the first encrypted image to the gallery sandbox clone, where the virtual plaintext is used to indicate the decrypted first encrypted image.
12. The display method according to claim 10 or 11, characterized in that: The method further comprises: receiving a second encrypted image via the communication application; The DLP rights management application determines that the account does not have permission to view the second encrypted image; The DLP rights management application displays the encrypted second encrypted image in a second DLP control.
13. The display method according to any one of claims 10 to 12, characterized in that: The method further comprises: In response to exiting the communication application, destroying the gallery sandbox clone.
14. An electronic device, characterized in that: The method comprises a processor and a memory, wherein the memory is used to store program instructions, and the processor is used to call the program instructions to execute the method according to any one of claims 1 to 4, claims 5 to 9, or claims 10 to 13.
15. A computer-readable storage medium, characterized in that A computer program is stored thereon, and when the computer program is executed by a computer, the method according to any one of claims 1 to 4, claims 5 to 9, or claims 10 to 13 is implemented.
Citation Information
Patent Citations
Attribute-based dynamic access control and encryption method for files in security sandbox
CN115935390A
Data protection method and device for data leakage prevention system
CN116150796A
File opening method and electronic equipment
CN117131533A
Method and system for secure document exchange
US20100268934A1