Permissions control method and electronic device
By associating application permission control with function usage scenarios, granting permissions only when the function is used and revoking them when the function is no longer used, the problem of applications accessing resources without awareness in existing technologies is solved, thus improving user privacy protection.
Patent Information
- Application Number
- PCT/CN2024/139668
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-17
- Filing Date
- 2024-12-16
- Publication Date
- 2025-10-23
AI Technical Summary
Existing access control mechanisms cannot effectively control applications from accessing or using the hardware and software resources of electronic devices without the user's knowledge, leading to the risk of leakage of user privacy information.
By associating an application's access permissions to hardware and software resources with the functions it provides, permissions can be granted only when a user uses a specific function and revoked when the user stops using the function, achieving fine-grained access control.
To ensure the security of user privacy information, prevent applications from accessing or using related resources after certain functions are no longer used, and improve user privacy protection.
Smart Images

Figure CN2024139668_23102025_PF_FP_ABST
Abstract
Description
A permission control method and electronic device
[0001] The present application claims priority from the Chinese patent application No. 202410465707.3 filed on April 17, 2024, and entitled "A permission control method and electronic device", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD
[0002] The present application relates to the technical field of electronic devices, and in particular to a permission control method and electronic device. BACKGROUND
[0003] With the development of the Internet, more and more applications (APPs) can be installed on electronic devices. In order to realize some functions, an application often needs to access hardware resources and / or software resources of the electronic device. Since some hardware resources and / or software resources involve user privacy information, the electronic device performs permission management on the access operation of the application involving user privacy information, that is, the application can only be allowed to access the hardware resources and / or software resources corresponding to the permission when the application has the corresponding permission.
[0004] Currently, an application generally requests the user to grant permission through a pop-up window. After the user agrees to grant permission, the application can obtain the permission to access the corresponding hardware resources and / or software resources, so that the application can successfully access the hardware resources and / or software resources of the electronic device. However, after the user authorizes the application to obtain the permission to access the corresponding hardware and / or software resources, the application may access the hardware and / or software resources of the electronic device without the user's awareness, thereby causing the risk of leakage of the user's privacy information. SUMMARY
[0005] The present application provides a permission control method and electronic device, which can associate the access permission of the hardware resources and / or software resources of the electronic device with the function provided by the application, implement a fine-grained permission management mechanism with the use scenario of the function as the granularity, and protect the security of the user's privacy information.
[0006] To achieve the above object, the present application adopts the following technical solutions:
[0007] In a first aspect, a permission control method is provided, applied to an electronic device. The method comprises: in response to a use operation of a first function of a first application, using the first function of the first application, and granting the first application a permission to call a system service related to the first function, the system service related to the first function being related to a user's security privacy; during running of the first application, in response to a stop use of the first function of the first application, canceling the permission granted to the first application to call the system service related to the first function.
[0008] The first function can be any one of a video call function, a voice call function, a remote control function, a navigation function, etc. The system service related to the first function can be at least one of a microphone service, a camera service, a keyboard and mouse injection service, and a location service.
[0009] The above-mentioned first aspect provides a solution. The electronic device can associate the user's authorization of the first application to access or use a corresponding hardware resource or software resource (such as a microphone) with the first function provided by the first application, so that the permission of the first application to access or use the hardware resource or software resource related to the first function is granted only when the user uses the first function, and the permission of the first application to access or use the hardware resource or software resource related to the first function is revoked when the user stops using the first function. In this way, the user's authorization of the first application to access or use the hardware resource or software resource can be limited to the use scenario of a certain specific function provided by the first application. In the scenario where the specific function is not used, the first application does not have the permission to access or use the related hardware resource or software resource. Thus, the situation where the first application still accesses or uses the related hardware resource or software resource after the user ends using the specific function is avoided, and the security of the user's private information is ensured.
[0010] Optionally, when the user uses the first function of the first application, the electronic device has granted the first application the permission to call the system service related to the first function. Therefore, the first application can arbitrarily call the system service related to the first function during use of the first function. At this time, in order to remind the user of the access behavior of the first application to the corresponding system service, the electronic device can display a prompt icon of the system service being called in the status bar. When the user stops using the first function of the first application, the electronic device has revoked the permission granted to the first application to call the system service related to the first function. Therefore, the first application can no longer arbitrarily call the system service related to the first function. At this time, since the first application can no longer call the system service, the electronic device will not display the prompt icon of the system service being called in the status bar. In this way, the user can know that the first application does not access the corresponding system service through the prompt icon that is no longer displayed.
[0011] In a possible implementation, the permission control method further includes: in response to the use operation of the second function of the first application, using the second function of the first application, and granting the first application the permission to call the system service related to the second function, the system service related to the second function being related to the security and privacy of the user; and in response to the stop of the use of the second function of the first application during the running of the first application, canceling the permission granted to the first application to call the system service related to the second function. In this way, when the first application provides multiple functions, the electronic device can grant the first application the permission to access or use the hardware resource or software resource related to each function respectively in the use scenario of each function when the user uses different functions of the first application.
[0012] In a possible implementation, the permission control method further includes: in response to the stop of the use of the first function of the first application, canceling the permission granted to the first application to call the system service related to the first function, including: in response to the switching from the first function of the first application to the second function of the first application, canceling the permission granted to the first application to call the system service related to the first function. In this way, when the user switches to use different functions, the electronic device can withdraw the permission granted to the application to call the system service related to the function before the switching because the function before the switching is no longer used.
[0013] In a possible implementation, the permission control method further includes: in response to the use of the first function of the first application, displaying a first icon in the status bar, the first icon being used to indicate that the system service related to the first function is called; and in response to the switching from the first function of the first application to the second function of the first application, canceling the display of the first icon in the status bar.
[0014] It can be understood that when the user uses the first function of the first application, the electronic device can display the prompt icon indicating that the system service is called in the status bar because the first application can call the system service related to the first function at will. When the user switches to use the second function of the first application, the electronic device does not display the prompt icon indicating that the system service is called in the status bar because the first function is no longer used, and the first application cannot call the system service related to the first function.
[0015] In a possible implementation, when the system services related to the first function are multiple, the revoking the permission of the first application to invoke the system services related to the first function in response to the stopping of the use of the first function of the first application comprises: in response to switching from the first function of the first application to a second function of the first application, revoking the permission of the first application to invoke part of the system services related to the first function, the part of the system services being irrelevant to the second function. In this way, when the user switches to use different functions, if the functions before and after the switching both need to invoke the same system service, since the function after the switching still needs the support of the same system service, the electronic device can not revoke the permission of the first application to invoke the same system service before the switching, but only revoke the permission of the first application to invoke part of the system services related to the function before the switching, the part of the system services being irrelevant to the function after the switching.
[0016] In a possible implementation, the permission control method further comprises: in response to the use of the first function of the first application, displaying a plurality of icons in the status bar, the plurality of icons being used to indicate that the system services related to the first function are invoked; and in response to switching from the first function of the first application to a second function of the first application, canceling the display of part of the icons in the status bar.
[0017] It can be understood that when the user uses the first function of the first application, since the first application can invoke multiple system services related to the first function at will, the electronic device can display a plurality of prompt icons in the status bar, the plurality of prompt icons being used to indicate that the multiple system services are invoked. When the user switches to use the second function of the first application, although the first function is no longer used, since the second function still needs the support of XX system service in the multiple system services and does not need the support of the remaining other system services, the first application can still invoke the XX system service at will and cannot invoke the remaining other system services. Therefore, the electronic device does not display prompt icons indicating that the remaining other system services are invoked in the status bar, but still displays a prompt icon indicating that the XX system service is invoked.
[0018] In a possible implementation, the revoking the permission of the first application to invoke the system services related to the first function in response to the stopping of the use of the first function of the first application comprises: in response to the stopping operation of the first function of the first application, revoking the permission of the first application to invoke the system services related to the first function. In this way, the electronic device can revoke the permission of the first application to invoke the system services related to the first function in response to the operation of the user for explicitly stopping the use of the first function.
[0019] In a possible implementation, the stopping use operation of the first function of the first application includes: an operation on an application-level control in the first application; or an operation on a system-level control in the electronic device. In this way, the user can trigger the stopping use of the first function through the control provided by the application or the control provided by the system of the electronic device.
[0020] In a possible implementation, the foregoing canceling the permission of the first application to call the system service related to the first function in response to the stopping use of the first function of the first application includes: canceling the permission of the first application to call the system service related to the first function in response to the pausing use of the first function of the first application. In this way, when the user pauses the use of the first function of the first application, the first application also does not have the permission to call the system service related to the first function.
[0021] In this case, the permission control method further includes: continuing to grant the first application the permission to call the system service related to the first function in response to the resuming use of the first function of the first application. In this way, when the user resumes the use of the first function of the first application, the first application can also resume the permission to call the system service related to the first function.
[0022] In a possible implementation, the permission control method further includes: displaying a first icon in the status bar in response to the use of the first function of the first application, the first icon being used to indicate that the system service related to the first function is called; canceling the display of the first icon in the status bar in response to the pausing use of the first function of the first application; and continuing to display the first icon in the status bar in response to the resuming use of the first function of the first application.
[0023] It can be understood that when the user uses the first function of the first application, the first application can call the system service related to the first function at will, and therefore the electronic device can display a prompt icon indicating that the system service is called in the status bar. When the user pauses the use of the first function of the first application, the first function is stopped, and the first application cannot call the system service related to the first function, and therefore the electronic device does not display the prompt icon indicating that the system service is called in the status bar. When the user continues to use, that is, resumes the use of the first function of the first application, the first application can call the system service related to the first function at will again, and therefore the electronic device can continue to display the prompt icon indicating that the system service is called in the status bar.
[0024] In a possible implementation, the response to the use operation of the first function of the first application, the use of the first function of the first application, and the granting of the permission for the first application to call the system service related to the first function, includes: in response to the use operation of the first function of the first application, outputting a first prompt at a system level, the first prompt being used to prompt a user whether to confirm the use of the first function of the first application; and in response to a confirmation operation for the first prompt, using the first function of the first application and granting the permission for the first application to call the system service related to the first function. In this way, the electronic device can provide a prompt controlled by the system to the user to confirm the intention of the user to use the first function of the first application, and the first application can be prevented from cheating the system that the user has confirmed the use of the first function.
[0025] Optionally, the first prompt can include risk prompt content when the first function is used, a confirmation control, and a cancel control. The confirmation operation for the first prompt can be a triggering operation on the confirmation control.
[0026] In a possible implementation, the permission control method further includes: during the use of the first function of the first application, outputting a second prompt at a system level, the second prompt being used to prompt the user that the first function of the first application is in use, and / or prompt the user that the system service related to the first function is called. In this way, during the use of the first function of the first application, the electronic device can provide a status prompt controlled by the system to the user, so that the user can view and manage the use status of the first function of the first application.
[0027] In a possible implementation, the second prompt includes a system-level control used to trigger the stop of the use of the first function of the first application. In this way, the user can stop the use of the first function of the first application by using the system-level control provided by the electronic device, which is equivalent to canceling the authorization for the first application to call the system service related to the first function.
[0028] In a possible implementation, the permission control method further includes: when the use of the first function of the first application is stopped and the permission for the first application to call the system service related to the first function is not canceled, in response to an operation on the system-level control, canceling the permission for the first application to call the system service related to the first function. In this way, when the use of the first function of the first application is stopped and the first application still has the permission to call the system service related to the first function, the user can cancel the authorization for the first application to call the system service related to the first function by using the system-level control provided by the electronic device.
[0029] In a possible implementation, the method further includes: in response to the first application switching from the foreground running to the background running, stopping using the first function of the first application, and canceling the permission of the first application to invoke the system service related to the first function.
[0030] In a possible implementation, the method further includes: in response to the first application switching from the foreground running to the background running, stopping using the first function of the first application, and canceling the permission of the first application to invoke the system service related to the first function.
[0031] In a possible implementation, the method further includes: in response to the first application switching from the foreground running to the background running, continuing to use the first function of the first application in the background, and displaying a third prompt of the system level, the third prompt including a system-level control, the third prompt being used to prompt the user that the first function of the first application is in use, and / or prompt the user that the system service related to the first function is invoked; and in response to a triggering operation of the system-level control, stopping using the first function of the first application, and canceling the permission of the first application to invoke the system service related to the first function.
[0032] In this way, when the first application switches to the background running while the user is using the first function of the first application, the electronic device can continue to use the first function of the first application in the background, and the electronic device still continues to grant the permission of the first application to invoke the system service related to the first function. At this time, the electronic device can keep a status prompt in the foreground, so that the user can stop using the first function of the first application through the system-level control in the status prompt, which is equivalent to canceling the permission of the first application to invoke the system service related to the first function.
[0033] In a possible implementation, the system service related to the first function can be a service of invoking a hardware resource or a software resource of the electronic device. For example, the system service related to the first function can be at least one of a microphone service, a camera service, a keyboard and mouse injection service, and a location service.
[0034] In a second aspect, a device is provided, which is included in an electronic device, and has the functions of the first aspect or any possible implementation thereof. The functions can be implemented by hardware, or by executing corresponding software by hardware. The hardware or software includes one or more modules or units corresponding to the functions.
[0035] In a third aspect, an electronic device is provided, which includes a memory and one or more processors; the memory is configured to store a program, and when the processor executes the program, the electronic device executes the permission control method in any possible implementation of the first aspect.
[0036] In a fourth aspect, a chip system is provided. The chip system includes one or more interface circuits and one or more processors. The interface circuit and the processor are interconnected by a circuit. The interface circuit is configured to receive a signal from the memory of the electronic device and send the signal to the processor, the signal including instructions stored in the memory. When the processor executes the instructions, the electronic device executes the permission control method in any possible implementation of the first aspect.
[0037] In a fifth aspect, a readable storage medium is provided, which includes computer readable instructions (or "programs"), when the instructions are run on an electronic device, the electronic device executes the permission control method in any possible implementation of the first aspect.
[0038] In a sixth aspect, a computer program product is provided, which includes computer readable instructions (or "programs"), when the computer program product is run on a computer, the computer executes the permission control method in any possible implementation of the first aspect.
[0039] It can be understood that the beneficial effects achieved by the device of the second aspect, the electronic device of the third aspect, the chip system of the fourth aspect, the readable storage medium of the fifth aspect, and the program product of the sixth aspect can refer to the beneficial effects of the first aspect and any possible implementation thereof, which will not be repeated here. BRIEF DESCRIPTION OF DRAWINGS
[0040] FIG. 1 is a system structure diagram of a permission management mechanism in the related art provided by the embodiments of the present application;
[0041] FIG. 2 is a schematic diagram of an interface provided by the embodiments of the present application;
[0042] FIG. 3 is a schematic diagram of the hardware structure of an electronic device provided by the embodiments of the present application;
[0043] FIG. 4 is a schematic diagram of the software structure of an electronic device provided by the embodiments of the present application;
[0044] Fig. 5 is a functional module diagram of a scenario-based service according to an embodiment of the present application;
[0045] Fig. 6 is a functional module diagram of another scenario-based service according to an embodiment of the present application;
[0046] Fig. 7 is a system structure diagram of a permission control method according to an embodiment of the present application;
[0047] Fig. 8 is a system structure diagram of another permission control method according to an embodiment of the present application;
[0048] Fig. 9 is a system structure diagram of yet another permission control method according to an embodiment of the present application;
[0049] Fig. 10 is a user interface diagram according to an embodiment of the present application;
[0050] Fig. 11 is a system structure diagram of still another permission control method according to an embodiment of the present application;
[0051] Fig. 12 is a flowchart of a permission control method according to an embodiment of the present application;
[0052] Fig. 13 is a user interface diagram according to an embodiment of the present application;
[0053] Fig. 14 is a user interface diagram according to an embodiment of the present application;
[0054] Fig. 15 is a flowchart of another permission control method according to an embodiment of the present application;
[0055] Fig. 16 is a user interface diagram according to an embodiment of the present application;
[0056] Fig. 17 is a user interface diagram according to an embodiment of the present application. DETAILED DESCRIPTION
[0057] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings.
[0058] In an electronic device, an application usually needs to obtain a permission to access or use a resource of the electronic device in order to implement some functions. The resource of the electronic device includes hardware resources and software resources. The hardware resources include sensors, detectors, memories, microphones, speakers, etc. on the electronic device. The software resources include screen display information, storage space, location information, application programs (e.g., address book, short message, calendar, telephone, gallery, camera), floating windows, etc.
[0059] For example, if an application wants to implement video calling, it needs to obtain access permissions to the camera and microphone; if an application wants to implement screen sharing, it needs to obtain screen recording permissions; if an application wants to implement remote control, it needs to obtain screen recording permissions and injection permissions for input operations (such as keyboard and / or mouse-based input operations).
[0060] Currently, electronic devices generally manage various permissions of applications through permission management mechanisms. For example, when a user uses the video call feature provided by App A, App A needs to use the electronic device's camera and microphone. Therefore, App A first checks whether it has permission to use the camera and microphone. If App A has permission, it can directly use the camera and microphone to provide the video call feature. If App A does not have permission, it can request authorization from the user via a pop-up window. After the user agrees to the authorization, App A can use the camera and microphone to provide the video call feature.
[0061] Taking the permission to use a microphone as an example, Figure 1 shows a flow chart of the process involved in managing the permission to use the microphone of Application A in the relevant technology. As shown in Figure 1, when Application A needs to use the microphone to implement the video call function, Application A can call the service interface provided by the microphone service to implement the call of the underlying microphone service. Among them, the microphone service has the management and control permission of the hardware microphone and can control the hardware microphone to collect sound data. The service interface is the communication interface provided by the underlying system service to the upper-level application, that is, the upper-level application calls the underlying system service through the corresponding service interface.
[0062] Because microphone usage affects user privacy, when App A calls the microphone service's API, the service can verify whether App A has permission to use the microphone through the Permission Management Service. If App A lacks permission, it cannot call the microphone service and thus cannot provide the video call function. App A can then request user authorization by calling the authorization API provided by the Permission Management Service.
[0063] When application A calls the authorization interface provided by the rights management service, the rights management service can call the window management service to display an authorization window, in which the user can choose whether to grant application A microphone usage permission. Upon detecting that the user has granted application A microphone usage permission, the rights management service can grant application A microphone usage permission.
[0064] At this time, the application A can again call the service interface provided by the microphone service to realize the calling of the underlying microphone service. When the application A calls the service interface provided by the microphone service, since the microphone service can determine that the application A has the use permission through the permission management service at this time, the application A can successfully call the microphone service to provide the video call function.
[0065] However, in the current permission management method, after the user authorizes the application to obtain the permission to access or use the corresponding hardware or software resource, the application can directly access or use the hardware and software resources of the electronic device without further interacting with the user to request authorization during the authorization period. That is, the process of the application accessing or using the hardware or software resource during the authorization period is invisible to the user. This makes the application possible to access or use the hardware and software resources of the electronic device without the user's awareness, thereby causing the risk of leakage of the user's private information and affecting the user experience.
[0066] It can be understood that the current electronic device can support multiple authorization modes, including but not limited to some or all of the following authorization modes: always allow, allow during use, allow this time, prohibit, and the like. When the electronic device displays the authorization window of the application, the authorization window can display the multiple authorization modes, as shown in FIG. 2, so that the user can grant the application with different permissions for different lengths of time according to different needs.
[0067] Among them, the prohibition means refusing to grant the application with the permission, and the application cannot provide the related function to the user. That is, in the above example, the application A has no permission to access the camera and microphone, and cannot provide the video call function.
[0068] The always allow means that after the application is granted with the permission, the application always has the permission. That is, in the above example, the application A can continuously obtain the permission to access the camera and microphone, and can provide the video call function at any time. However, since the process of the application A accessing the camera and microphone is invisible to the user after the user's authorization, the application A can obtain the user's image, sound and the like information without the user's awareness. For example, after the user ends the video call, the application A still continuously obtains the user's image, sound and the like information.
[0069] The allow during use means that after the application is granted with the permission, only during the process that the user uses the application, the application has the permission. That is, in the above example, the application A can obtain the permission to access the camera and microphone during its own active period. Similarly, the application A can also obtain the user's image, sound and the like information without the user's awareness.
[0070] The this-run permission refers to that after the application is granted the permission, the application only has the permission in the process that the user last uses the application. That is, in the above example, the user uses the video call function provided by the application A each time, and the application A will request the authorization from the user through the pop-up window, which is not good for the user experience. At the same time, once the user authorizes the this-run permission, even if the user ends the video call, the application A still has the permission to access the camera and the microphone during the this active period. Similarly, the application A can also obtain the image, sound and other information of the user without the user's awareness.
[0071] It can be seen that the current permission management mechanism takes the application as the control granularity, which cannot control the behavior that the application maliciously accesses or uses the hardware and software resources of the electronic device. Therefore, after the user authorizes the application to obtain the permission to access or use the corresponding hardware resource or software resource, the user cannot know and control the access or use of the application to the hardware resource or software resource at any time, and the user control granularity is relatively coarse. This makes the application may access or use the hardware resource and software resource of the electronic device without the user's awareness, thereby causing the risk of leakage of the user's private information and affecting the user experience.
[0072] Based on the above problems, the present application provides a permission control method and an electronic device. The electronic device can associate the user's authorization of the application to access or use the corresponding hardware resource or software resource with the function (such as the video call function, the voice call function, the screen sharing function, the remote control function, etc.) provided by the application, so as to authorize the application to access or use the hardware resource or software resource related to the function only when the user uses the function, and cancel the authorization of the application to access or use the hardware resource or software resource related to the function when the user stops using the function. In this way, the user can grant the application the permission to access or use the related hardware resource or software resource, which is limited to the use scenario of a certain specific function provided by the application. In the scenario where the function is not used, the application does not have the permission to access or use the related hardware resource or software resource. Thus, the application can be prevented from accessing or using the related hardware resource or software resource after the user ends the use of a certain specific function, and the safety of the user's private information is ensured.
[0073] In some embodiments, the hardware resource or software resource of the electronic device can be managed and controlled by the corresponding service / module, that is, the hardware resource or software resource can open the corresponding hardware capability or software capability to the corresponding service / module. Therefore, the above-mentioned permission of the application to access or use the corresponding hardware resource or software resource can also refer to the permission of the application to call the corresponding service / module. The service / module of the electronic device can be a hardware service / module, such as a microphone service / module, a camera service / module, etc., or a software service / module, such as a screen recording service / module, a location service / module, etc.
[0074] The hardware resources or software resources managed and controlled by the services / modules of the electronic device can be hardware resources or software resources of the electronic device itself, or hardware resources or software resources externally connected to the electronic device. The embodiments of the present application do not limit the source of the resources managed and controlled by the services / modules of the electronic device.
[0075] In the embodiments of the present application, the electronic device to which the permission control method is applied can be a mobile phone, a tablet computer (tablet for short), a (desktop, laptop, handheld) computer, a notebook computer, an ultra-mobile personal computer (UMPC), a netbook, a cellular phone, a personal digital assistant (PDA), an augmented reality (AR) / virtual reality (VR) device, and the like. The embodiments of the present application do not specially limit the specific form of the electronic device.
[0076] For example, FIG. 3 shows a structural schematic diagram of the electronic device 100. As shown in FIG. 3, the electronic device 100 can include a processor 110, a memory 120, an antenna, a communication module 130, a sensor module 140, a microphone 150, a camera 160, and a display screen 170, etc. The sensor module 140 can include a touch sensor, a pressure sensor, a distance sensor, etc., and can also include other sensors such as a fingerprint sensor, a gyroscope sensor, an acceleration sensor, a proximity light sensor, etc. The embodiments of the present application do not limit the types and quantities of sensors included in the electronic device.
[0077] The touch sensor, also known as a touch panel, can be disposed on the display screen 170, and the touch sensor and the display screen 170 can form a touch screen, also known as a touch screen. The touch sensor is used to detect touch operations applied to or near it. The touch sensor can pass the detected touch operation to the application processor to determine the touch event type, or can provide visual output related to the touch operation through the display screen 170. In other embodiments, the touch sensor can also be disposed on the surface of the electronic device 100, which is different from the position of the display screen 170.
[0078] The pressure sensor is used to sense a pressure signal and can convert the pressure signal into an electrical signal. In some embodiments, the pressure sensor can be disposed on the display screen 170. When a touch operation is applied to the display screen 170, the electronic device 100 detects the intensity of the touch operation according to the pressure sensor. The electronic device 100 can also calculate the position of the touch according to the detection signal of the pressure sensor.
[0079] It can be understood that the structure illustrated in the embodiments of the present application does not constitute a specific limitation on the electronic device 100. In other embodiments, the electronic device 100 can include more or fewer components than illustrated, or combine certain components, or split certain components, or different arrangement of components. The illustrated components can be implemented in hardware, software, or a combination of software and hardware. The electronic device 100 can also include a charging management module, a battery, a key, a speaker, a microphone, a headset interface, and the like.
[0080] The processor 110 can include one or more processing units, for example: the processor 110 can include an application processor (AP), a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), and the like. Among them, different processing units can be independent devices, or can be integrated in one or more processors. The processor 110 can run multiple tasks (such as application programs) at the same time to provide users with a variety of services and functions. Among them, the controller can be the nerve center and command center of the electronic device 100. The controller can generate operation control signals according to instruction operation codes and timing signals to complete the control of fetching instructions and executing instructions.
[0081] The memory in the processor 110 can also be provided for storing instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. The memory can save instructions or data that the processor 110 has just used or repeatedly uses. If the processor 110 needs to use the instructions or data again, it can be directly called from the memory. Avoiding repeated access reduces the waiting time of the processor 110, thus improving the efficiency of the system.
[0082] In some embodiments, the processor 110 can include one or more interfaces, such as a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a universal serial bus (USB) interface, and the like. The processor 110 can be connected with other components through the one or more interfaces.
[0083] The USB interface can be used to transmit data between the electronic device 100 and an input / output device. The input device can be a wired mouse, a wired keyboard, etc.
[0084] In the embodiments of the present application, the processor 110 can obtain an input operation (such as a click operation) of the user on the content displayed on the display screen 170 through the wired mouse via the USB interface, or obtain an input operation of the user on the content displayed on the display screen 170 through the wired keyboard.
[0085] The memory 120 can be used to implement the data storage function of the electronic device 100. For example, files such as images and videos are saved in the memory 120. The memory 120 can also be used to store computer executable program codes, which include instructions. The processor 110 executes various functional applications and data processing of the electronic device 100 by running the instructions stored in the memory 120. The memory 120 can include a program storage area and a data storage area. The program storage area can store an operating system, at least one application program (such as a camera application) required by a function, etc. The data storage area can store data (such as images taken) created during the use of the electronic device 100, etc. In addition, the memory 120 can include a high-speed random access memory, and can also include a non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, a universal flash memory (UFS), etc.
[0086] The communication module 130 and the antenna are used to implement the wireless communication function of the electronic device 100. The communication module 130 can provide a solution for wireless communication including 2G / 3G / 4G / 5G, etc. applied to the electronic device 100, and can also provide a solution for wireless communication including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) network), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared technology (IR), etc. applied to the electronic device 100.
[0087] In some embodiments, the electronic device 100 can interact with the input device for information, such as receiving the input operation triggered by the user through the input device, etc. based on the wireless communication technology through the communication module 130. The input device can be a wireless mouse, a wireless keyboard, etc. The user input operation can be the operation of the user clicking a certain control (button).
[0088] The electronic device 100 can realize the audio function through the audio module, the speaker, the receiver, the microphone 150, the earphone interface, and the application processor, etc. For example, music playing, recording, etc. The microphone 150 is also called "microphone", "sound transducer", which is used to convert the sound signal into an electrical signal. When making a voice call or making a recording or sending a voice message or needing to trigger the electronic device 100 to execute certain functions through a voice assistant, the user can make a sound by putting the mouth close to the microphone 150, and input the sound signal into the microphone 150. The electronic device 100 can be provided with at least one microphone 150. In some embodiments, the electronic device 100 can be provided with two, four or more microphones 150 to realize the functions of collecting sound signals, noise reduction, sound source identification, directional recording, etc.
[0089] The electronic device 100 can realize the shooting function through the ISP, the camera 160, the GPU, the display screen 170, and the application processor, etc. The ISP is used to process the data feedback by the camera 160. In some embodiments, the ISP can be provided in the camera 160. The camera 160 is used to capture still images or videos. The object generates an optical image through the lens and projects it to the photosensitive element. The photosensitive element converts the optical signal into an electrical signal, and then transmits the electrical signal to the ISP to convert it into a digital image signal. The ISP outputs the digital image signal to the DSP for processing. The DSP converts the digital image signal into a standard RGB, YUV, etc. format image signal. In some embodiments, the electronic device 100 can include one or N cameras 160, N being a positive integer greater than 1.
[0090] The electronic device 100 can realize the display function through the GPU, the display screen 170, and the application processor, etc. The GPU is a microprocessor for image processing, which is connected to the display screen 170 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. The processor 110 can include one or more GPUs, which execute program instructions to generate or change display information.
[0091] The display screen 170 is configured to display images, videos, and the like. For example, the display screen 170 can display any one of a video call interface, a voice call interface, a screen sharing interface, and a remote control interface. The display screen 170 includes a display panel. The display panel can be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flex light-emitting diode (FLED), a Miniled, a MicroLed, a Micro-oLed, a quantum dot light emitting diodes (QLED), or the like. In some embodiments, the electronic device 100 can include one or N display screens 170, where N is a positive integer greater than 1.
[0092] In the embodiments of the present application, if the electronic device 100 receives an application-in-video call request initiated by the opposite end in the chat application, the display screen 170 of the electronic device 100 can display a video call interface. If the electronic device 100 detects a user's on-hold confirmation operation, the display screen 170 of the electronic device 100 can display a risk prompt window, which can include risk prompt content, a confirmation control, and a cancel control.
[0093] After the user clicks the confirmation control, the chat application starts to provide the user with the video call function, and the chat application can obtain the access permission of the microphone and the camera. At this time, the display screen 170 of the electronic device 100 can display a video interface and a status prompt window. The status prompt window is configured to indicate that the chat application is supporting the video call function, and the status prompt window can display status prompt content and an end control. The video interface can display the video content sent by the opposite end and the video content collected by the electronic device 100 using the microphone and the camera.
[0094] In the embodiments of the present application, after the user clicks the end control, the chat application ends the provision of the video call function, and the chat application no longer obtains the access permission of the microphone and the camera.
[0095] It can be understood that the software system of the electronic device 100 can adopt a layered architecture, an event-driven architecture, a microkernel architecture, a microservice architecture, or a cloud architecture. The embodiments of the present application take the layered architecture as an example to illustrate the software structure of the electronic device 100.
[0096] FIG. 4 is a software structure block diagram of the electronic device 100 according to an embodiment of the present application. The layered architecture divides the software system into several layers, each of which has a clear role and division of labor. The layers communicate with each other through software interfaces. In some embodiments, the layered architecture divides the software into three layers, from top to bottom, the application layer (referred to as the application layer), the application framework layer (referred to as the framework layer), and the kernel layer.
[0097] The application layer can include a series of application packages. As shown in FIG. 4, the application packages can include gallery, camera, music, video, short message, etc. For the convenience of description, the application is referred to as the application below. The application on the electronic device 100 can be a native application or a third-party application, and the embodiments of the present application are not limited.
[0098] As an example, the application layer can include a chat application that provides a video call function and / or a voice call function, and can also include a device collaboration application that provides a screen sharing function and / or a remote control function.
[0099] The framework layer provides the application of the application layer with an application programming interface (API) and a programming framework. The framework layer includes some pre-defined functions (services), such as window management services, input event management services, resource management services, view systems, etc. The embodiments of the present application are not limited. Among them, the input event management service (IMS) can be used to translate, package, etc. The original input event is processed to obtain an input event containing more information, and is sent to the window management service. The window management service stores the position information of the clickable area (such as the control) of each application and the focus window. Therefore, the window management service can correctly distribute the input event to the specified control or focus window.
[0100] In the embodiments of the present application, the framework layer can also include system basic services. The system basic service can be understood as the minimum capability unit that the system provides and can run independently, which is a concept of abstract encapsulation of a single function / capability. Among them, the system basic service can be a hardware service, such as a camera service, a microphone service, etc., or a software service, such as a keyboard and mouse injection service, a screen recording service, a location service, etc.
[0101] It should be noted that the system basic service is only a term used in the embodiments of the present application, and the meaning represented thereby has been described in the embodiments of the present application, and the name thereof does not constitute any limitation on the embodiments of the present application. For example, in some other embodiments, the system basic service can also be referred to as a system basic function, a system function, a system service, an atomized service, a meta-ability, an atomic ability, an atomic service, a functional component, or other terms. In the embodiments of the present application, the system basic service is mainly described.
[0102] Optionally, the system basic service includes a permission management service, which can be used to manage the permission of each application in the application layer to access the system basic service. For example, to control the display of an authorization window, so that the user selects whether to grant the corresponding permission of the application in the authorization window; or for example, to record the corresponding authorization information (such as xx application has xx permission) after the user grants the corresponding permission of the application.
[0103] In the embodiments of the present application, each system basic service of the framework layer can provide a communication interface for the upper layer application, which can also be referred to as a system basic service interface, so that the upper layer application can call the lower layer system basic service by calling the corresponding interface. For example, a service interface of a location service, a service interface of a camera service, and the like.
[0104] In the embodiments of the present application, to implement the permission control method provided by the present application, a scenario-based service can be added to the framework layer, so as to associate the access permission of the system basic service with the use scenario of the function provided by the application through the scenario-based service.
[0105] As shown in FIG. 4, the framework layer can include a scenario-based service, which can be a service provided by the system to control the permission in the use scenario of a certain function, to provide system basic service support for the use of the function, so as to ensure the normal use of the function. The function can be a certain function provided by the upper layer application, and the implementation of the function needs at least one system basic service provided by the electronic device. For example, the screen sharing function provided by the device collaboration application needs to access or use the screen recording service of the electronic device; the video call function provided by the chat application needs to access or use the microphone service and the camera service of the electronic device; the navigation function provided by the map application needs to access or use the location service of the electronic device, and the like.
[0106] As an example, as shown in FIG. 4, the framework layer can include a plurality of scenario-based services, such as a video call service corresponding to the use scenario of the video call function, a remote control service corresponding to the use scenario of the remote control function, and the like. It can be understood that the framework layer can also include other scenario-based services, such as a screen sharing service, an audio call service, a navigation service, a live broadcast service, and the like, and the type of the scenario-based service is not limited in the embodiments of the present application.
[0107] It should be noted that the scenario service is only a word used in the embodiments of the present application, and its meaning has been described in the embodiments of the present application, and the name does not constitute any limitation on the embodiments of the present application. For example, in some other embodiments, the scenario service can also be referred to as a scenario function, a scenario service, a scenario service, a scenario service, a service function, or other terms. In the embodiments of the present application, the scenario service is mainly described.
[0108] Since the application layer application can support one or more functions, each function can be selected by the user for use. Therefore, in the embodiments of the present application, when the user uses a certain function provided by the application, and the function needs the application to access or use a certain system basic service, the application can call a scenario service corresponding to the use scenario of the function, and the scenario service judges the use state of the function by the user, so as to judge whether to grant the application the permission to access or use the system basic service.
[0109] As shown in FIG. 4, each scenario service of the framework layer can provide a communication interface for the upper layer application, which can also be referred to as a scenario service interface, so that the upper layer application can call the lower layer scenario service by calling the corresponding interface.
[0110] In the embodiments of the present application, when the user uses a certain function provided by the application, and the function needs the application to access or use a certain system basic service, the application needs to call a scenario service interface corresponding to the use scenario of the function first, to judge the use state of the function by the user. When it is confirmed that the user uses the function, the scenario service can grant the application the permission to access or use the system basic service. At this time, the application can call a corresponding system basic service interface to call the system basic service, so that the application can ensure the normal use of the function.
[0111] Each scenario service can be associated with a corresponding required system basic service, so that the scenario service can grant the application the corresponding system basic service permission.
[0112] Optionally, the system basic service required by the scenario service corresponds to a system basic service interface, which can be encapsulated with the scenario service interface of the scenario service, so that when the application wants to call the corresponding system basic service, the above judgment of the scenario service must be passed, to avoid the application from calling the corresponding system basic service by itself.
[0113] In the embodiments of the present application, the scenario service can be used to realize the state prompt of the use scenario of the function. Optionally, the scenario service can also realize the risk prompt of the use scenario of the function, and / or the state management of the use scenario of the function (such as suspending the use of the function, ending the use of the function).
[0114] In some embodiments, as shown in FIG. 5, the scenario service can include a state prompt module for implementing display of a state prompt window, which is a window controlled by the system (not controlled by the application) and can show state prompt content when the corresponding function is used, such as that the xx application is currently supporting the xx function.
[0115] Optionally, the state prompt window can also include a state management control when the corresponding function is used, such as an end control for ending use of the function, etc. That is, the scenario service can interact with the user through the state prompt window to explicitly obtain the current user's intention to end use of the function (such as clicking the end control), which is equivalent to explicitly obtaining the current user's cancellation of authorization of the system basic service used by the application for the function.
[0116] Optionally, as shown in FIG. 6, the state prompt module can also be separated from the scenario service and serve as an independent function / service. The independent state prompt module can respectively interact with each scenario service to implement state prompting when the corresponding function is used for each scenario service.
[0117] Optionally, the independent state prompt module can also respectively interact with each system basic service to implement display of a state prompt window when each system basic service is called by the application. The state prompt window can show state prompt content when the corresponding system basic service is called, such as that the xx application is currently calling the xx service.
[0118] Optionally, the scenario service can also include a risk prompt module for implementing display of a risk prompt window, which is a window controlled by the system (not controlled by the application) and can show risk prompt content when the corresponding function is used, such as that the application will use the xx service when the function is used and the application will access the xx data when the xx service is used.
[0119] Optionally, the risk prompt window can also include a confirmation control and a cancellation control. The confirmation control is used to ensure that the user still determines to use the function after learning the risk prompt content, and the cancellation control is used to ensure that the user can give up using the function after learning the risk prompt content. That is, the scenario service can interact with the user through the risk prompt window to explicitly obtain the current user's intention to use the function, which is equivalent to explicitly obtaining the current user's authorization of the system basic service used by the application for the function.
[0120] Optionally, the risk prompt module can also be separated from the scenario service and serve as an independent function / service. The independent risk prompt module can interact with each scenario service to provide risk prompts for the use of the corresponding functions of each scenario service.
[0121] In some embodiments, the application can also provide a corresponding status prompt window or a corresponding function management control when supporting one or more functions, such as a prompt icon in a video call, a "hang up" control for ending a video call function, and the like. Therefore, optionally, the scenario service can obtain the use intention or end intention of the current user for the function through the operation event of the function management control provided by the application, to obtain the authorization or de-authorization of the current user for the system basic service related to the use of the function by the application.
[0122] In some embodiments, the application can also directly use the status prompt window or the status management control managed by the system, and no longer provide a status prompt window or a corresponding function management control.
[0123] Optionally, when an application or multiple applications provide a function, the scenario service corresponding to the function can be called by the application or the multiple applications. For example, if multiple applications can provide a video call function, when the user uses the video call function provided by each application, each application can call the service interface of the video call service to implement the calling of the underlying video call service and execute the permission control scheme provided in the embodiments. That is, the video call service determines the use state of the video call function by the user, to determine whether to grant the application the permission to access or use the microphone and the camera of the electronic device.
[0124] In some scenarios, the developer can develop different scenario services at the framework layer according to different use scenarios, so that when the user uses a function provided by an application, the application can correspondingly call the scenario service of the function to implement the permission control scheme provided in the embodiments.
[0125] The kernel layer is the layer between hardware and software. The kernel layer can include a display driver, an input / output device driver (such as a touch screen), a device node, an audio driver (such as a microphone), a camera driver, and a sensor driver, and the like. The user performs an input operation through an input device, and the kernel layer can generate a corresponding operation event according to the input operation and report the operation event to the input event management service.
[0126] It should be understood that the software structure shown in FIG. 4, FIG. 5, and FIG. 6 includes components, which do not constitute a specific limitation on the electronic device 100. In other embodiments, the electronic device 100 can include more or fewer components than shown, or combine certain components, or split certain components, or different arrangement of components. For example, in some scenarios, the layered architecture can also divide the software into four layers, from top to bottom, an application layer, a framework layer, a system layer (or system service layer), and a kernel layer. The scenario-based service can be arranged in the framework layer, and the system basic service can be arranged in the system layer (or system service layer).
[0127] The methods in the following embodiments can be implemented in the electronic device 100 with the hardware structure and software structure described above.
[0128] Based on the software modules described above, the embodiments of the present application provide a system flow diagram of a permission control method. The scenario-based service can continuously perceive the use state of the user for the corresponding function through the risk prompt module and / or the state prompt module, that is, continuously perceive the authorization state of the user for the corresponding permission of the application. Then the scenario-based service can communicate with the related system basic service, and transmit the perceived authorization state of the user for the corresponding permission of the application to the related system basic service. Thus, the related system basic service can determine whether to respond to the call of the application.
[0129] As an example embodiment, please refer to FIG. 7. Taking an application layer including an application A providing a video call function as an example (such as When the user uses the video call function of the application A, such as clicking the "video call" control provided by the application A to start the video call function, the application A needs to call the corresponding scenario-based service interface, that is, the service interface of the video call service, to realize the call of the lower layer video call service. Among them, the video call service has the management control permission of the microphone service and the camera service in the use scenario of the video call function.
[0130] At this time, the video call service can respond to the call of the application A, and realize the display of the risk prompt window through the risk prompt module. The risk prompt window can include risk prompt content, a confirmation control, and a cancel control. The risk prompt content can include risk prompt about using the video call function, such as the use of the video call function needs to access the microphone and the camera. The risk prompt content can also include risk prompt about the device capability of the application A using the microphone and the camera, such as the application A needs to use the microphone and the camera of the device to obtain audio and image.
[0131] When the video call service detects that the user clicks the confirmation control in the risk prompt window, it can be determined that the user currently determines to use the video call function. At this time, the video call service can grant the application A the permission to access the microphone and the camera, and notify the microphone service and the camera service and the upper-layer application A of the authorized information (indicating that the user has granted the application A the permission to access the microphone and the camera). Among them, the video call service can keep communication with the microphone service and the camera service to timely deliver the information of whether the user grants the application A the permission to access the microphone service and the camera service to the microphone service and the camera service.
[0132] Optionally, the risk prompt window can include a "no longer prompt" selection control to support the user to select not to display the risk prompt window next time when using the video call function.
[0133] The application A can start to call the service interface of the microphone service and the service interface of the camera service when receiving the authorized information notified by the video call service. Since the microphone service and the camera service have determined that the application A has the permission to access the microphone and the camera through the communication with the video call service, the application A can successfully realize the calling of the underlying microphone service and the camera service, so as to drive the hardware microphone to collect sound and drive the camera to collect image. Then the application A can obtain the sound information returned by the microphone service and the image information returned by the camera service.
[0134] Optionally, since the user triggers the use of the video call function, the application A considers that the user will probably grant the permission to access the microphone and the camera. Therefore, the application A can also call the service interface of the microphone service and the service interface of the camera service when calling the service interface provided by the video call service. In this way, the video call function of the application A can be quickly and normally used, reducing the waiting time of the user.
[0135] In the embodiment, after the video call service detects that the user clicks the confirmation control in the risk prompt window, the display of the state prompt window can also be realized through the state prompt module. The state prompt window can include state prompt content and an end control. Among them, the state prompt content is used to indicate that the application A is supporting the video call function, and / or is used to indicate that the application A is using the microphone and the camera. The end control is used to end the video call function of the application A.
[0136] Among them, after the video call service detects that the user clicks the confirmation control in the risk prompt window, the calling state of the microphone service and the camera service can be continuously perceived through the communication with the microphone service and the camera service. When the microphone service and the camera service are perceived to be called by the application A, the video call service can realize the display of the corresponding state prompt content.
[0137] When the video call service detects that the user clicks the end control in the status prompt window, it can be determined that the user currently determines to stop using the video call function. At this time, the video call service can cancel the granted permission of application A to access the microphone and camera, and notify the microphone service and the camera service, and the upper-layer application A of the cancellation of the authorization (indicating that the user has cancelled the permission of application A to access the microphone and camera). Application A can no longer call the underlying microphone service and camera service by calling the service interface of the microphone service and the service interface of the camera service.
[0138] Even if application A wants to continue to call the service interface of the microphone service and the service interface of the camera service, because the microphone service and the camera service have determined that application A has no permission to access the microphone and the camera through communication with the video call service, the microphone service and the camera service will refuse to respond to the call of application A.
[0139] In this way, it is realized that when the user is using the video call function of application A, application A can obtain the permission to access the microphone and the camera related to the video call function. When the user stops using the video call function of application A, even if the user is still using application A such as browsing a page, application A cannot obtain the permission to access the microphone and the camera related to the video call function. It is convenient for the user to perceive the use of sensitive hardware resources by the application at any time.
[0140] Based on the above software module, the embodiment of the application provides another system flow diagram of the permission control method. Different from the above flow, the scenario service can pass the authorization state of the user to the application to the permission management service record, so that the related system basic service can judge whether to respond to the call of the application through the permission management service.
[0141] As another example embodiment, taking an application layer including an application B (such as application) providing a remote control function as an example, as shown in FIG. 8, when the user uses the remote control function of application B, such as clicking the “remote control” control provided by application B to start the remote control function, application B needs to call the corresponding scenario service interface, that is, the service interface of the remote control service, to realize the call of the underlying remote control service. Among them, the remote control service has the management control permission of the keyboard and mouse injection service in the use scenario of the remote control function.
[0142] Similarly, the remote control service can display the risk prompt window in response to the application B calling the risk prompt module. The risk prompt window can display risk prompt content, a confirmation control, and a cancel control. When the remote control service detects that the user clicks the confirmation control in the risk prompt window, it can determine that the user currently determines to use the remote control function. At this time, the remote control service can grant the application B the permission to control the screen of the electronic device, i.e., the permission to use the mouse and keyboard injection service, and notify the permission management service and the upper-layer application B of the information indicating that the user has granted the application B the permission to use the mouse and keyboard injection service. In this way, the application B can successfully call the underlying mouse and keyboard injection service by calling the service interface of the mouse and keyboard injection service.
[0143] It can be understood that when the application B calls the service interface of the mouse and keyboard injection service, the mouse and keyboard injection service can query that the application A has the permission to use the mouse and keyboard injection service through the permission management service. Therefore, the application B can successfully call the mouse and keyboard injection service to implement the remote control function. That is, the application B can inject the mouse and keyboard input operation transmitted by the other device into the input event management service. The input event management service processes the mouse and keyboard input operation accordingly.
[0144] Similarly, the remote control service can also display the state prompt window in response to the user clicking the confirmation control in the risk prompt window. The state prompt window can include state prompt content and an end control. Alternatively, the remote control service can also communicate with the mouse and keyboard injection service to perceive the calling state of the mouse and keyboard injection service. When the remote control service perceives that the mouse and keyboard injection service is called by the application B, it can display the corresponding state prompt content.
[0145] Similarly, when the remote control service detects that the user clicks the end control in the state prompt window, it can determine that the user currently determines to stop using the remote control function. At this time, the remote control service can cancel the permission to control the screen of the electronic device, i.e., the permission to use the mouse and keyboard injection service, and notify the permission management service and the upper-layer application B of the information indicating that the user has canceled the permission to use the mouse and keyboard injection service. In this way, the application B cannot call the underlying mouse and keyboard injection service by calling the service interface of the mouse and keyboard injection service. Even if the application B wants to continue to call the service interface of the mouse and keyboard injection service, the mouse and keyboard injection service will refuse to respond to the call of the application B because the mouse and keyboard injection service can query that the application B does not have the permission to use the mouse and keyboard injection service through the permission management service.
[0146] Thus, when the user is using the remote control function of the application B, the application B can obtain the permission to access the keyboard / mouse injection service related to the remote control function. When the user stops using the remote control function of the application B, even if the user is still using the application B, such as screen sharing with others, the application B cannot obtain the permission to access the keyboard / mouse injection service related to the remote control function. In addition to the hardware resources, the user can also be aware of the use of sensitive software resources by the application at any time.
[0147] Based on the above software module, the embodiment of the present application provides another system flow diagram of the permission control method. Different from the above flow, the scenario service can perceive the use state of the user on the corresponding function through the function management control provided by the application, that is, perceive the authorization state of the user on the corresponding permission of the application.
[0148] As another example embodiment, as shown in FIG. 9, taking the application layer including the application C (such as application) providing navigation function as an example, the application C can be provided with a control for entering the navigation function and a control for exiting the navigation function. For example, as shown in (a) of FIG. 10, when the user searches for destination information on the home page of the application C, the application C can display the "navigation" control 1001 for entering the navigation function to provide the user with the navigation function to the destination. When the user intends to use the navigation function, the user can click the "navigation" control 1001. For another example, as shown in (c) of FIG. 10, when the user is using the navigation function of the application C, the application C can display the "exit navigation" control 1005 for exiting the navigation function. When the user intends to end the use of the current navigation function, the user can click the "exit navigation" control 1005. When the user operates the control for entering the navigation function, the application C can call the corresponding scenario service interface, that is, the service interface of the navigation service, to realize the calling of the underlying navigation service. And the application C can issue the operation information of the user operating the control for entering the navigation function to the navigation service to notify the navigation service that the user has confirmed to use the navigation function of the application C. Wherein, the navigation service has the management control permission of the location service in the use scenario of the navigation function.
[0149] The navigation service can respond to the calling of the application C, and according to the received operation information of the user operating the control for entering the navigation function, confirm that the user currently wants to use the navigation function of the application C. At this time, the navigation service can grant the application C the permission to access the location service, and notify the authorized information (indicating that the user has granted the application C the permission to access the location information) to the location service and the upper application C. Thus, the application C can successfully realize the calling of the underlying location service by calling the service interface of the location service. Optionally, the navigation service can also notify the authorized information to the permission management service, refer to the flow of the above embodiment.
[0150] Optionally, the navigation service can also respond to the call of the application C to realize the display of the risk prompt window through the risk prompt module to interact with the user through the risk prompt window controlled by the system, and to confirm the use intention of the user for the navigation function of the application C again (that is, to confirm the authorization intention of the user for the application C to access the location information) to prevent the application C from cheating the system that it has obtained the authorization of the user. When the navigation service detects that the user clicks the confirmation control in the risk prompt window, the navigation service can confirm that the user still determines to use the navigation function after understanding the risk. At this time, the navigation service can grant the application C the permission to access the location service.
[0151] As shown in (a) of FIG. 10 and (b) of FIG. 10, after the user clicks the “navigation” control 1001, the electronic device can display a system pop-up window 1002 on the interface of the application C to show the user the risk prompt about using the navigation function of the application C. After the user clicks the confirmation control in the system pop-up window 1002, the electronic device can confirm that the user grants the application C the permission to access the location information, so that the application C can successfully access the location information and realize the navigation function based on the accessed location information.
[0152] During the use of the navigation function of the application C by the user, if the user operates the control provided by the application C for exiting the navigation function, the application C can deliver the operation information of the user operating the control for exiting the navigation function to the navigation service to notify the navigation service that the user has confirmed to end the navigation function of the application C.
[0153] The navigation service can confirm that the user currently ends the use of the navigation function of the application C according to the received operation information of the user operating the control for exiting the navigation function. At this time, the navigation service can cancel the permission granted to the application C to access the location service, and notify the location service (or the permission management service) and the upper-layer application C of the cancellation authorization information (indicating that the user has cancelled the permission granted to the application C to access the location information). In this way, the application C can no longer realize the call of the underlying location service by calling the service interface of the location service. Even if the application C wants to continue to call the service interface of the location service, the location service will refuse to respond to the call of the application C because the location service has learned the above-mentioned cancellation authorization information in time.
[0154] Optionally, the navigation service can also display the state prompt window through the state prompt module in response to the user clicking the confirmation control in the risk prompt window, so as to interact with the user through the state prompt window controlled by the system and continuously perceive the user's use intention for the navigation function of the application C. As shown in (b) of FIG. 10 and (c) of FIG. 10, after the user clicks the confirmation control in the system pop-up window 1002, the application C can enter the navigation interface, and the electronic device can display a system floating window 1003 on the navigation interface to keep a clear prompt information in the foreground, prompting the user that the application C is supporting the navigation function (or the application C is accessing the location information). The system floating window 1003 includes an "end" control 1004 for one-click ending of the use of the navigation function of the application C, which is equivalent to one-click ending of the authorization of the application C to access the location information under the current navigation function. Thus, the user can cancel the authorization of the application C to access the location information through the control provided by the application for exiting the navigation function or through the state prompt window, which can prevent the application C from continuing to access the location information after the navigation function is ended.
[0155] In this way, when the user clicks the control for entering the navigation function of the application C, the application C can obtain the permission to access the location service related to the navigation function. When the user clicks the control for exiting the navigation function of the application C, even if the user is still using the application C, such as browsing the pictures of the destination, the application C cannot obtain the permission to access the location service related to the navigation function. Thus, the user's authorization operation for various permissions of the application is reduced, and the smoothness of the user experience is increased.
[0156] Based on the above software modules, the embodiment of the present application provides a system flow diagram of another permission control method. Different from the above flow, the state prompt module can be decoupled from the scenario module, and the state prompt module can maintain communication with the system basic service to continuously perceive the calling state of the system basic service by the application and the authorization state of the user for the application to call the system basic service.
[0157] As another example embodiment, taking the application layer including the application A providing the voice call function as an example, as shown in FIG. 11, when the user uses the voice call function of the application A, such as clicking the "voice call" control provided by the application A to start the voice call function, the application A needs to first call the service interface of the voice call service to realize the calling of the lower-layer voice call service. The voice call service has the management control permission of the microphone service in the use scenario of the voice call function.
[0158] Similarly, in response to the call of the application A, the voice call service can determine that the user currently determines to use the voice call function of the application A. Refer to the flow of the foregoing embodiment. At this time, the voice call service can grant the application A the permission to access the microphone, and notify the microphone service and the upper-layer application A of the authorized information (indicating that the user has granted the application A the permission to access the microphone). In this way, the application A can successfully realize the call of the underlying microphone service by calling the service interface of the microphone service. The video call service can maintain communication with the microphone service to timely deliver the information about whether the user grants the application A the permission to access the microphone service to the microphone service.
[0159] After determining that the user currently determines to use the voice call function of the application A, the voice call service can instruct the state prompt module to realize the display of the state prompt window. The state prompt window can include state prompt content and an end control. The state prompt content is used to indicate that the application A is supporting the voice call function, and / or is used to indicate that the application A is using the microphone. The end control is used to end the voice call function of the application A.
[0160] Optionally, the voice call service can send the prompt information related to the voice call scene, such as the function use scene-voice call function, the application identifier-application A, the related system basic service-microphone service, and the existing risk, to the state prompt module, so that the state prompt module can realize the display of the state prompt information corresponding to the current function use scene in the state prompt window.
[0161] Optionally, the voice call service can also notify the state prompt module or the permission management service of the authorized information, and the state prompt module or the permission management service can notify the microphone service of the authorized information. The state prompt module or the permission management service can maintain communication with the microphone service to timely deliver the information about whether the user grants the application A the permission to access the microphone service to the microphone service.
[0162] Optionally, the microphone service can report the information that the microphone service is called by the application A to the state prompt module in response to the call of the application A. The state prompt module can display the state prompt window to prompt the user that the application A is using the microphone after receiving the reported information.
[0163] Optionally, the state prompt window can also include an end control. The end control can be used to end the voice call function of the application A, and the end control can also be used to end (cancel) the permission granted to the application A to access the microphone.
[0164] As a manner, when the state prompt module detects that the user clicks the end control in the state prompt window, the state prompt module can send the operation information of the user operating the end control to the voice call service to inform the voice call service that the user has determined to end using the voice call function currently. The voice call service can cancel the permission of granting the application A to access the microphone, and inform the microphone service or the permission management service and the upper application A of the information of canceling the permission (indicating that the user has canceled the permission of granting the application A to access the microphone). The application A cannot realize the calling of the underlying microphone service and the camera service through the service interface of calling the microphone service any more.
[0165] As another manner, when the state prompt module detects that the user clicks the end control in the state prompt window, the state prompt module can cancel the permission of granting the application A to access the microphone, and inform the microphone service and send the information of canceling the permission to the voice call service, and the voice call service informs the upper application A. The application A cannot realize the calling of the underlying microphone service and the camera service through the service interface of calling the microphone service any more. Alternatively, the voice call service or the state prompt module can also inform the permission management service of the information of canceling the permission, and the permission management service informs the microphone service of the information of granting the permission.
[0166] Even if the application A wants to continue to call the service interface of the microphone service, since the microphone service has learned that the application A has no permission to access the microphone, the microphone service will refuse to respond to the calling of the application A.
[0167] In some scenarios, when the user uses the voice call function of the application A, the application A can not call the service interface of the voice call service, but directly call the service interface of the microphone according to the flow in the related art, as shown in FIG. 1. When the application A has no permission to access the microphone, the application A can call the authorization interface of the permission management service to request the user to grant the permission. When the user grants the permission for a certain time length, the application A can successfully call the microphone service in the time length.
[0168] In the embodiment, when the application A maliciously calls the service interface of the microphone service in the time length, although the microphone service queries that the application A has the permission through the permission management service, the microphone service can still report the information that the microphone is called by the application A to the state prompt module. The application A can display the state prompt window to prompt the user that the application A is using the microphone after receiving the reported information. The state prompt window includes an end control for one-click rejecting the calling of the microphone service by the application A. In this way, even if the application A maliciously calls the microphone service, the user can be informed in time, and the user can directly end the malicious calling of the microphone service by the application A through the end control of the state prompt window, so that the security of the private information of the user is protected.
[0169] Optionally, the end control can also be used to one-key end (cancel) the permission of application A to access the microphone. Through the state prompt window, the behavior of application A secretly calling the microphone service can be known by the user in time, and the user can directly cancel the permission of application A to access the microphone through the end control of the state prompt window. At this time, the state prompt module can also notify the permission management service of the cancellation of the authorization (indicating that the user has cancelled the permission of application A to access the microphone). The permission management service can update the original permission of application A to access the microphone and the authorization duration to no permission to access the microphone. In this way, application A cannot maliciously call the microphone service again.
[0170] The following will specifically introduce a permission control method provided by an embodiment of the application, which is applied to the electronic device described above. As shown in FIG. 12, the method can include the following steps.
[0171] S1210, the electronic device detects a use operation of a user on a first function of a first application, and the running of the first function needs the support of a first system service.
[0172] In the embodiment of the application, the first application is an application installed on the electronic device, which can be a native application (also referred to as a system application) or a third-party application. For example, the first application can be one of the applications A, B and C described above. The first application can provide at least one function, such as the video call function and the scan function of application A, and the screen sharing function and the remote control function of application B. The function provided by the first application can be selectively used by the user according to the needs.
[0173] In the embodiment of the application, the implementation of some functions of the first application needs the support of at least one system service of the electronic device. That is, the first application needs to call at least one system service to implement the function to be provided. For example, application A needs to call the camera service to implement the scan function of application A.
[0174] In the embodiment of the application, the system service can be a service obtained by abstracting and encapsulating one or more functions / capabilities of the electronic device, which can be provided to the application. The system service can be a hardware service obtained by abstracting and encapsulating the hardware capability of the electronic device or the externally plugged hardware capability, or a software service obtained by abstracting and encapsulating the software function of the electronic device or the externally plugged software function.
[0175] Optionally, when a single function / capability of the electronic device is abstracted and encapsulated as a system service, the system service is also referred to as a system basic service. For example, the system service can be the microphone service, the camera service, the keyboard and mouse injection service and the like.
[0176] Since some system service calls involve user privacy information, such as the call of the camera service, the image information of the user is obtained, therefore, the electronic device performs permission management on the call operation of the system service involving user privacy information. That is, the first application can only be allowed to call the system service by the electronic device when it has the permission to call the system service. At present, the user usually grants the first application the permission to call the system service for a certain period of time, but the user cannot know and control the call of the system service by the first application during the authorization period. Therefore, the first application may call the system service without the user's awareness, which may lead to the risk of leakage of the user's privacy information and affect the user experience.
[0177] To solve this problem, the present application associates the user's authorization of the first application to call a certain system service with the use scenario of a certain function of the first application. So that when the user uses the function of the first application, the electronic device can grant the first application the permission to call the system service related to the function. When the user stops using the function of the first application, the electronic device can cancel the permission granted to the first application to call the system service related to the function. In this way, the time period during which the first application has the permission of the corresponding system service, that is, the authorization period, is limited to the use scenario of a certain function provided by the first application. In the scenario where the function is not used, the first application does not have the permission of the corresponding system service. Therefore, the situation that the first application still calls the corresponding system service after the user ends using a certain function is avoided, and the safety of the user's privacy information is ensured.
[0178] The following will take at least one function provided by the first application as an example, including the first function, to specifically introduce the permission control method provided by the present application.
[0179] Among them, the first function is related to the first system service of the electronic device. Here, related means that the implementation of the first function of the first application needs the support of the first system service of the electronic device, that is, the first application needs to call the first system service to implement the first function. The first system service can be any of the various system services described above. Alternatively, the first system service can also be a service that has a security risk, or a privacy leakage risk, or needs to be authorized by the user, such as the microphone service, the camera service, the keyboard and mouse injection service, etc.
[0180] In the embodiments of this application, the electronic device can grant the first application the permission to call the first system service during the running period (also referred to as the use period) of the first function of the first application, that is, the electronic device allows the first application to call the first system service during the running period of the first function. The running period refers to a continuous time period from the start of the first function of the first application (also referred to as the start of use) to the stop of the running of the first function (also referred to as the stop of use). That is, after the first function of the first application stops running, the electronic device can revoke the permission to call the first system service granted to the first application.
[0181] The start of the first function of the first application can be triggered by the user, triggered automatically by the first application, or triggered by association of other applications.
[0182] In some embodiments, when the user intends to use the first function of the first application, the user can trigger the start of the first function of the first application by inputting a use operation (also referred to as an opening operation) for the first function of the first application.
[0183] The use operation of the user for the first function of the first application can be a touch operation (such as clicking a corresponding control), a voice instruction, a preset gesture (a touch gesture or a hovering gesture), or a physical key operation, etc. input by the user to open / switch to the first function of the first application.
[0184] As an example, when the first function of the first application is the navigation function of the application C, as shown in (a) of FIG. 10, when the user searches for destination information on the home page of the application C, the application C can provide a "navigation" control 1001 for entering the navigation function to provide the user with the navigation function to reach the destination. In this case, the use operation of the user for the navigation function of the application C can be a click operation on the "navigation" control 1001.
[0185] In some scenarios, if the user has been using other functions such as the second function provided by the first application, the user's intention to use the first function of the first application at this time can be to use the first function and the second function of the first application simultaneously, or to stop using the second function of the first application to switch to using the first function of the first application.
[0186] As an example, when the first function and the second function of the first application are a remote control function and a screen sharing function of application B, as shown in (a) of FIG. 13, application B can also provide a "remote control" control 1301 for entering the remote control function in the process of supporting the screen sharing function, to meet the user's demand for simultaneously using the remote control function and the screen sharing function of application B. In this case, the use operation of the remote control function of application B input by the user can be a click operation on the "remote control" control 1301.
[0187] As another example, when the first function and the second function of the first application are a voice call function and a video call function of application A, as shown in (a) of FIG. 14, application A can also provide a "turn to voice" control 1401 for switching to the voice call function in the process of supporting the video call function, to meet the user's demand for quickly switching from using the video call function of application A to using the voice call function of application A. In this case, the use operation of the voice call function of application A input by the user can be a click operation on the "turn to voice" control 1401.
[0188] In other embodiments, the first application can also automatically trigger the start of the first function of the first application when a preset condition (for example, a preset time) is reached. In yet other embodiments, the start of the first function of the first application can also be triggered in the process of running other applications. The embodiments of the present application do not limit the manner of triggering the start of the first function of the first application.
[0189] S1220, the electronic device uses the first function of the first application in response to the use operation, and grants the first application the permission to call the first system service.
[0190] In the embodiments of the present application, when the electronic device detects the above-mentioned use operation of the first function of the first application input by the user, it can be considered that the user intends to use the first function of the first application. At this time, the electronic device can start running the first function of the first application in response to the above-mentioned use operation, and can grant the first application the permission to call the first system service, so that the first application can successfully call the first system service to support the normal running of the first function of the first application.
[0191] That is, when the user intends to use the first function of the first application, in the view of the device, it is equivalent to the user having granted the first application the permission to call the first system service related to the first function. Therefore, when the electronic device confirms that the user intends to use the first function of the first application, it can directly grant the first application the permission to call the first system service related to the first function.
[0192] It can be understood that when the user grants the first application the permission to call the first system service, it is usually in the running scenario (also understood as the use scenario) of a certain function provided by the first application, such as the running scenario of the first function (also understood as the scenario in which the user is currently using the first function). Outside this scenario, the first application should not have the permission to call the first system service. Therefore, in the permission control method provided in the present application, when the electronic device confirms that the user intends to use the first function of the first application, the electronic device can grant the first application the permission to call the first system service during the running of the first function, that is, the first application has the permission to call the first system service during the running of the first function.
[0193] As an example, as shown in (a) of FIG. 10, when the electronic device detects the click operation of the user on the "navigation" control 1001 provided by the application C, it can confirm that the user intends to use the navigation function of the application C. At this time, the electronic device can start running the navigation function of the application C in response to the click operation, and during the running of the navigation function of the application C, the electronic device grants the application C the permission to call the system service related to the navigation function, such as the permission to call the location service, so that the application C can successfully call the related system service to support the normal running of the navigation function. Alternatively, when the navigation function of the application C is running normally, the electronic device can display the navigation interface as shown in (c) of FIG. 10.
[0194] It can be understood that before the user intends to use the first function of the first application, if the user has been using other functions provided by the first application, such as the second function, then by analogy, the electronic device can grant the first application the permission to call the second system service during the running of the second function, that is, the first application has the permission to call the second system service during the running of the second function. The second function is related to the second system service, that is, the implementation of the second function of the first application needs the support of the second system service of the electronic device. Alternatively, the second system service can be the same as or different from the first system service.
[0195] In some scenarios, in the case where the user has been using the second function provided by the first application, if the user intends to use the first function of the first application at the same time on the basis of the use of the second function at this time, the electronic device will not revoke the permission previously granted to the first application to call the second system service, because the user has not stopped using the second function of the first application, and the electronic device can also grant the first application the permission to call the first system service during the running of the first function. In this case, the first application has the permission to call the system services related to the first function and the second function.
[0196] As an example, in a process in which the application B supports the screen sharing function, as shown in (a) of FIG. 13, when the electronic device detects a click operation of the user on the "remote control" control 1301 provided by the application B, it can be confirmed that the user intends to use the remote control function of the application B. At this time, the electronic device can start running the remote control function of the application B while running the screen sharing function of the application B in response to the click operation, and during the running of the remote control function of the application B, the electronic device grants the application B the permission to call the system service related to the remote control function, such as the permission to call the keyboard / mouse injection service. This enables the application B to successfully call the related system service to support the normal running of the remote control function. Alternatively, when the remote control function of the application B is normally running, the electronic device can display the remote control interface as shown in (d) of FIG. 13.
[0197] It can be understood that, since the user does not stop using the screen sharing function of the application B, the electronic device does not revoke the permission previously granted to the application B to call the system service related to the screen sharing function, such as the permission to call the screen recording service, that is, the application B currently has the permission to call the keyboard / mouse injection service and the screen recording service.
[0198] In other scenarios, in a case where the user has been using the second function provided by the first application, if the user intends to stop using the second function of the first application at this time to switch to using the first function of the first application, the electronic device can grant the first application the permission to call the first system service valid during the running of the first function, and the electronic device will revoke the permission previously granted to the first application to call the second system service because the second function of the first application has stopped running. In this case, the first application only has the permission to call the system service related to the first function.
[0199] As an example, in a process in which the application A supports the video call function, as shown in (a) of FIG. 14, when the electronic device detects a click operation of the user on the "switch to voice" control 1401 provided by the application A, it can be confirmed that the user intends to switch from using the video call function of the application A to using the voice call function of the application A. At this time, the electronic device can switch from running the video call function of the application A to running the voice call function of the application A in response to the click operation, and during the running of the voice call function of the application A, the electronic device grants the application A the permission to call the system service related to the voice call function, such as the permission to call the microphone service. This enables the application A to successfully call the related system service to support the normal running of the voice call function. Alternatively, when the application A switches from supporting the video call function to supporting the voice call function, the electronic device can switch from displaying the video interface as shown in (a) of FIG. 14 to displaying the voice interface as shown in (b) of FIG. 14.
[0200] It can be understood that, since the user has stopped using the video call function of the application A, the electronic device will withdraw the permission previously granted to the application A to invoke the system service related to the video call function, such as the permission to invoke the camera service.
[0201] Optionally, when the second system service is the same as the first system service, that is, the implementation of the first function and the second function requires invoking the same system service, the electronic device can not have to withdraw the permission previously granted to the application A to invoke the same system service. For example, the implementation of the video call function and the voice call function both require invoking the microphone service, so when the application A switches to supporting the voice call function in the process of supporting the video call function, the electronic device does not have to withdraw the permission previously granted to the application A to invoke the microphone service, but withdraws the permission previously granted to the application A to invoke the camera service. This is because the implementation of the voice call function does not require the support of the camera service. That is, the application A no longer has the permission to invoke the camera service, but continues to have the permission to invoke the microphone service.
[0202] S1230, the electronic device detects that the first function of the first application is stopped.
[0203] In the embodiments of the present application, after the first function of the first application is stopped, the electronic device can withdraw the permission granted to the first application to invoke the first system service. Wherein, the stop of the first function of the first application can be triggered by the user, can also be triggered automatically by the first application, and can also be triggered by other applications.
[0204] In some embodiments, the user can trigger the stop of the first function of the first application by inputting a stop using operation for the first function of the first application.
[0205] Wherein, the stop using operation for the first function of the first application input by the user can be a touch operation (such as clicking the corresponding control), voice instruction, preset gesture (touch gesture or hovering gesture), or physical key operation input by the user to stop (end) the first function of the first application. Wherein, the stop can be complete stop or temporary stop.
[0206] As an example, as shown in (c) of FIG. 10, when the user is using the navigation function of the application C, the application C can display a "quit navigation" control 1005 for quitting the navigation function. The stop using operation for the navigation function of the application C input by the user can be a click operation on the "quit navigation" control 1005.
[0207] In some scenarios, if the current user is using the first function of the first application while also using another function of the first application, such as a second function, the user intends to stop using the first function of the first application, which can mean that the user intends to stop using both the first function and the second function of the first application, such as directly closing the first application, or can mean that the user intends to stop using only the first function of the first application while continuing to use the second function of the first application.
[0208] As an example, as shown in (b) of FIG. 14, the user is using the voice call function of application A, and the user performs an upward swipe operation at the bottom of the screen to enter the application management interface for displaying all started applications, as shown in (c) of FIG. 14. The application management interface can display a delete control 1403 for closing any or all applications. The stop using operation of the user for the voice call function of application A can be a drag operation of dragging the window of application A to the delete control 1403 to directly close the running of application A. In this case, it is equivalent to one-key ending the running of all functions of application A.
[0209] As another example, as shown in (e) of FIG. 13, application B supports the screen sharing function and the remote control function at the same time, and application B can also provide an “end” control 1305 for ending the remote control function to meet the user’s demand of stopping using only the remote control function of application B. In this case, the stop using operation of the user for the remote control function of application B can be a click operation on the “end” control 1305.
[0210] In some scenarios, if the current user intends to use another function of the first application, such as a second function, the user intends to stop using the first function of the first application, which can mean that the user intends to switch from using the first function of the first application to using the second function of the first application.
[0211] As an example, when the first function and the second function of the first application are the video call function and the voice call function of application A, as shown in (a) of FIG. 14, application A supports the video call function, and application A can also provide a “turn to voice” control 1401 for switching to the voice call function to meet the user’s demand of quickly switching from using the video call function of application A to using the voice call function of application A. In this case, the stop using operation of the user for the video call function of application A can be a click operation on the “turn to voice” control 1401.
[0212] In some embodiments, the first application can also automatically trigger the end of the first function of the first application when a preset condition (e.g., a preset time) is reached. In yet some embodiments, the end of the first function of the first application can also be triggered in association with the running of other applications. The present embodiments do not limit the manner of triggering the end of the first function of the first application.
[0213] In response to the stopping of the use of the first function of the first application, the electronic device cancels the granted permission of the first application to call the first system service.
[0214] In some embodiments, when the electronic device detects the above-mentioned user input of the stopping use operation of the first function of the first application, it can be considered that the user intends to stop using the first function of the first application. At this time, the electronic device can stop running the first function of the first application in response to the above-mentioned stopping use operation, and can cancel the granted permission of the first application to call the first system service, so that the first application can no longer successfully call the first system service, effectively avoiding the first application from calling the first system service without the user's awareness, and ensuring the security of the user's private information.
[0215] That is, when the user intends to stop using the first function of the first application, it is equivalent to that the user has canceled the granted permission of the first application to call the first system service related to the first function from the perspective of the device. Therefore, when the electronic device confirms that the user intends to stop using the first function of the first application, it can directly withdraw the previously granted permission of the first application to call the first system service related to the first function. That is, when the first function of the first application stops running, the first application no longer has the permission to call the first system service.
[0216] As an example, as shown in (c) of FIG. 10, when the electronic device detects the user's click operation on the "exit navigation" control 1005 provided by the application C, it can be confirmed that the user intends to stop using the navigation function of the application C. At this time, the electronic device can stop running the navigation function of the application C in response to the click operation, and cancel the granted permission of the application C to call the system service related to the navigation function, such as the permission to call the location service, so that the application C can no longer successfully call the related system service.
[0217] In some scenarios, when the user is using the first function of the first application, and is also using other functions of the first application, such as the second function, if the user intends to stop using only the first function of the first application at this time, the electronic device can only withdraw the previously granted permission of the first application to call the first system service, and will not withdraw the previously granted permission of the first application to call the second system service, because the second function of the first application is still running. In this case, the first application only has the permission to call the system service related to the second function.
[0218] As an example, in the process of application B supporting the screen sharing function and the remote control function at the same time, as shown in FIG. 13(e), when the electronic device detects a click operation of the user on the "end" control 1305 provided by application B, it can be confirmed that the user intends to stop using the remote control function of application B. At this time, the electronic device can stop running the remote control function of application B in response to the click operation, and revoke the permission of application B to call the system service related to the remote control function, such as the permission to call the keyboard and mouse injection service, so that application B can no longer successfully call the related system service. Even if the user is still using the screen sharing function of application B, application A no longer has the permission to call the keyboard and mouse injection service.
[0219] It can be understood that since the user has not stopped using the screen sharing function of application B, the electronic device will not revoke the permission of application B to call the system service related to the screen sharing function, such as the permission to call the screen recording service, that is, application B currently only has the permission to call the screen recording service, and no longer has the permission to call the keyboard and mouse injection service.
[0220] In other scenarios, when the user is using the first function of the first application, and is also using other functions of the first application, such as the second function, if the user intends to stop using the first function and the second function of the first application at the same time at this time, such as directly closing the running of the first application, the electronic device can revoke the permission of the first application to call the first system service and the second system service.
[0221] As an example, in the process of application A supporting the voice call function, as shown in FIG. 14(b), when the user enters the application management interface for displaying all started applications by performing an upward sliding operation at the bottom of the screen, as shown in FIG. 14(c), the electronic device detects a drag operation of the user on the window of application A to the delete control 1403. When the electronic device detects a drag operation of the user on the window of application A to the delete control 1403, it can be confirmed that the user intends to one-key end the running of all functions of application A. At this time, the electronic device can close the running of application A in response to the drag operation, and cancel all permissions previously granted to application A to call related system services, such as the permission of the microphone service related to the voice call function previously granted. So that application A can no longer successfully call the related system service.
[0222] It can be understood that since the user has stopped using application A, which is equivalent to one-key stopping using all functions of application A, the electronic device will revoke all permissions previously granted to application A to call system services.
[0223] In some scenarios, the stopping of the use of the first function of the first application can be the current user's intention to switch from using the first function of the first application to using another function, such as a second function, of the first application. In this case, the electronic device can revoke the permission previously granted to the first application to invoke the first system service in response to the switching from the first function of the first application to the second function of the first application.
[0224] As an example, as shown in (a) of FIG. 14, when the electronic device detects a user's click operation on the "switch to voice" control 1401 provided by the application A in the process of the application A supporting the video call function, it can be confirmed that the user's intention is to quickly switch from using the video call function of the application A to using the voice call function of the application A. At this time, the electronic device can cancel all the permissions previously granted to the application A to invoke the system services related to the video call function, such as the permission to invoke the camera service, in response to the switching from the video call function of the application A to the voice call function of the application A.
[0225] Alternatively, since the permission previously granted to the application A to invoke the system services related to the video call function includes the microphone service, which is also related to the voice call function being used, the electronic device can not necessarily revoke the permission previously granted to the application A to invoke the microphone service, but only revoke the permission to invoke the system services irrelevant to the voice call function.
[0226] That is, since the implementation of the video call function and the voice call function both need to invoke the microphone service, the electronic device does not necessarily revoke the permission previously granted to the application A to invoke the microphone service when the application A switches from supporting the video call function to supporting the voice call function, but revokes the permission previously granted to the application A to invoke the camera service. This is because the implementation of the voice call function does not need the support of the camera service. That is, the application A no longer has the permission to invoke the camera service, but still has the permission to invoke the microphone service.
[0227] Alternatively, the electronic device can first revoke the permission previously granted to the application A to invoke all the system services related to the video call function, and then grant the permission to the application A to invoke the system services related to the voice call function.
[0228] In some embodiments, the electronic device can detect the stopping of the use of the first function of the first application during the running of the first application. Thus, during the running of the first application, the electronic device can revoke the permission granted to the first application to invoke the first system service in response to the stopping of the use of the first function of the first application. Thus, even if the first application is still running, the first application no longer has the permission to invoke the first system service related to the first function.
[0229] In one scenario, the running of the first application can be a process in which the first application runs in the foreground. In this way, when the user stops using the first function of the first application in the process of using the first application in the foreground, the electronic device can cancel the permission granted to the first application to call the first system service related to the first function. Even if the user is still using the first application in the foreground at this time, the first application no longer has the permission of the first system service related to the first function.
[0230] In another scenario, the running of the first application can also be a process in which the first application runs in the background. In this way, when the user stops using the first function of the first application in the process of using the first application in the background, the electronic device can cancel the permission granted to the first application to call the first system service related to the first function.
[0231] Optionally, in the process of using the first function of the first application in the foreground, when the user switches the first application running in the foreground to the background, it can be considered that the user intends to stop using the first function of the first application, and at this time the electronic device can cancel the permission granted to the first application to call the first system service related to the first function.
[0232] For example, when the electronic device uses the video recording function of the application E in the foreground, if the user switches the application E to run in the background, the electronic device can stop using the video recording function of the application E, and revoke the permission granted to the application E to call the system service related to the video recording function, such as the permission of the camera service.
[0233] Optionally, if the user switches the first application running in the background back to the foreground, it can also be considered that the user intends to continue using the first function of the first application, and at this time the electronic device can continue to grant the first application the permission to call the first system service related to the first function.
[0234] In one scenario, in the process of using the first function of the first application in the foreground, in order to avoid the related interface of the first function causing obstruction, when the user switches the first application running in the foreground to the background, it can be considered that the user intends to continue using the first function of the first application in the background. Since the first function is not stopped, at this time the electronic device does not need to revoke the permission granted to the first application to call the first system service related to the first function. Thereafter, in the process of using the first function of the first application in the background, when the user intends to stop using the first function of the first application, at this time the electronic device can cancel the permission granted to the first application to call the first system service in response to the stop of the first function of the first application.
[0235] For example, when the electronic device is using the navigation function of the application C in the foreground, if the user switches the application C to run in the background, the electronic device can use the navigation function of the application C in the background and display the desktop interface in the foreground. At this time, since the navigation function of the application C is still being used, the electronic device does not need to revoke the permission of the application C to call the system service related to the navigation function, such as the permission of the location service.
[0236] Optionally, when the electronic device is using the navigation function of the application C in the background, the electronic device can keep displaying the state prompt window 1003 in the foreground, which includes an "end" control 1004 for one-key stopping using the navigation function of the application C. When the user intends to stop using the navigation function of the application C, the "end" control 1004 can be clicked. At this time, in response to the clicking operation, the electronic device stops using the navigation function of the application C and revokes the permission of the application C to call the system service related to the navigation function, such as the permission of the location service.
[0237] The permission control method provided by the embodiments of the present application associates the user's authorization of the first application to call a certain system service with the use scenario of a certain function of the first application. When the user is using the function of the first application, the electronic device can grant the first application the permission to call the system service related to the function. When the user stops using the function of the first application, the electronic device can revoke the permission of the first application to call the system service related to the function. Thus, the application can obtain the permission to call the system service related to the function only when the user is using the function provided by the application. When the user no longer uses the function provided by the application, even if the user is still using the application, the application does not have the permission to call the system service related to the function. Thus, the situation that the first application still calls the corresponding system service after the user ends using a certain function is avoided, and the security of the user's privacy information is ensured.
[0238] Please refer to FIG. 15, which shows another permission control method provided by the embodiments of the present application and applied to the above-mentioned electronic device. Different from the above-mentioned method, the electronic device interacts with the user through a system to ensure the user's intention to use a certain function of an application. As shown in FIG. 15, the method can include:
[0239] S1510, the electronic device detects a use operation of the user on the first function of the first application.
[0240] In some embodiments, the electronic device can display a first interface. The first interface is an interface that can start the first function of the first application, which can be an application interface of the first application, a desktop, or other interfaces that can quickly start the first function of the first application, such as a control center interface, which is not limited in the present application.
[0241] The first interface can include one or more function controls for triggering the start of a function in the application. When the first interface displays a plurality of function controls, the plurality of function controls can be used to trigger the start of different functions. The different functions can be functions of the same application or functions of different applications. In some scenarios, the function control can also be referred to as a card or a module, and the embodiments of the present application do not make any limitation in this regard.
[0242] The following will take the function control in the first interface as an example, that is, the first control is used to trigger the start of the first function of the first application, to specifically introduce the permission control method provided by the present application.
[0243] The user's use operation (which can also be referred to as a start operation) for the first function of the first application can be a touch operation, a voice operation, a hovering gesture operation, a physical key operation, etc. input by the user for the first control on the first interface. When the electronic device detects the user's start operation for the first function of the first application, it can be considered that the user intends to use the first function of the first application.
[0244] As an example, the first interface is the address search interface of application C shown in (a) of FIG. 10, and the first control is the "navigation" control 1001 provided by application C in the address search interface. When the electronic device detects the user's operation of clicking the "navigation" control 1001, it can be considered that the user intends to use the navigation function of application C.
[0245] As another example, the first interface is the screen sharing interface shown in (a) of FIG. 13, and the first control is the "remote control" control 1301 provided by application B. When the electronic device detects the user's operation of clicking the "remote control" control 1301, it can be considered that the user intends to use the navigation function of application C on the basis of using the screen sharing function of application B.
[0246] As another example, the first interface is the screen sharing interface shown in (a) of FIG. 13, and the first control is the "remote control" control 1301 provided by application B. When the electronic device detects the user's operation of clicking the "remote control" control 1301, it can be considered that the user intends to use the navigation function of application C on the basis of using the screen sharing function of application B.
[0247] S1520, the electronic device displays a first system prompt in response to the use operation, the first system prompt indicating a risk existing when the first function is used, and the first system prompt including a confirmation control.
[0248] When the user inputs an opening operation for the first function of the first application, i.e., when the user intends to use the first function of the first application, the electronic device can display a first system prompt in response to the opening operation to prompt the user about the risk that may exist in opening the first function.
[0249] The first system prompt can also provide a confirmation control and a cancel control. The confirmation control is used to ensure that the user still determines to use the first function of the first application after learning the risk prompt content, and the cancel control is used to ensure that the user can give up using the first function of the first application after learning the risk prompt content. Thus, the electronic device can interact with the user through the first system prompt controlled by the system to explicitly obtain the use intention of the current user for the function, which is equivalent to explicitly obtaining the authorization of the current user for the system service related to the use of the first function of the first application, and can prevent the first application from cheating the electronic device that the user has obtained the authorization.
[0250] It should be noted that the first system prompt displayed in the embodiments of the present application is a system-level prompt defined and controlled by the operating system of the electronic device, and is not an application-level prompt defined and controlled by the application, and is not controlled by the application. In this way, the first application can be prevented from maliciously avoiding the risk prompt, and the user can be unaware of the risk that the opening of the first function of the first application will cause.
[0251] Optionally, when the first application provides an application-level prompt similar to the first system prompt, such as a first application prompt, the electronic device can hide the display of the first system prompt when the first application triggers the electronic device to display the first application prompt, so as to avoid too many risk prompts affecting the user interaction experience.
[0252] Optionally, the first system prompt can include risk prompt content about using the first function.
[0253] As an example, in the case where the user intends to use the navigation function of the application C, in response to the user's click operation on the "navigation" control 1001 shown in (a) of FIG. 10, the electronic device can display the risk prompt window 1002 shown in (b) of FIG. 10, which can show the user that there is a risk in using the navigation function, such as "after opening navigation, application C can access your location information", and "confirm" control and "cancel" control.
[0254] As another example, in the case that the user intends to use the remote control function of application B, in response to a click operation of the user on the "remote control" control 1301 shown in (a) of FIG. 13, the electronic device can display a selection window 1302 shown in (b) of FIG. 13 for the user to select the opposite end user of the electronic device to be remotely controlled. In response to a selection operation of the user on the participant 22 in the selection window 1302, the electronic device can display a risk prompt window 1303 shown in (c) of FIG. 13, which can show the user the risks of using the remote control function, such as "After agreeing to remote control, participant 22 can remotely control your device", and "Confirm" and "Cancel" controls.
[0255] Optionally, the first system prompt can also include risk prompt content about the use of the first application related system service. For example, in the case that the user intends to use the video call function of application A, the first system prompt displayed by the electronic device can be "Whether to allow application A to access the microphone and camera of the electronic device, which can obtain your image and audio information at any time".
[0256] As a way, the first system prompt can be displayed in the form of a pop-up window, which can show complete risk prompt content or be folded to display partial information. When the user clicks on the folded partial information, the electronic device can unfold and display the complete risk prompt content.
[0257] As another way, the first system prompt can also be displayed in the form of a warning icon in the status bar. When the user clicks on the warning icon, the electronic device can display a risk prompt window to fully or partially display the corresponding risk prompt content. Optionally, the risk prompt content in the first system prompt can also be displayed by jumping to a specified page through a link, which is used to display the complete risk prompt content.
[0258] Optionally, the first system prompt can provide a check box for no longer prompting, so that the user can choose not to display it next time. In this way, when the user can easily associate the relationship between the first function and the first system service, such as the video call must use the microphone and camera, or when the user actively triggers the use of the first function of the first application, the user can choose not to display it next time, improving the user interaction experience.
[0259] In some scenarios, before the user intends to use the first function of the first application, if the user is already using other functions provided by the first application, such as a second function, then similarly, in response to a start operation of the user on the second function of the first application, the electronic device can display a first system prompt in the use scenario of the current second function, which indicates the risks existing when the first function is started.
[0260] The first system prompt in the use scenario of the second function can also include a confirmation control and a cancel control. The confirmation control is used to ensure that the user determines to use the first function of the first application after understanding the risk prompt content, and the cancel control is used to ensure that the user can give up using the first function of the first application after understanding the risk prompt content.
[0261] Optionally, in the case that the first function and the second function need to call the same system service during normal operation, if the user intends to use the first function of the first application, because the risk prompt content of the same system service has been previously displayed to the user through the first system prompt in the use scenario of the second function, the electronic device can no longer display the first system prompt in the use scenario of the first function, or can no longer display the risk prompt content of the same system service through the first system prompt in the use scenario of the first function.
[0262] As an example, when the user intends to use the video call function of application A, the electronic device can display the related risk prompt content, such as "whether to allow application A to access the microphone and camera of the electronic device, which may obtain your image and audio information at any time", and when the user still intends to use the video call function of application A after understanding the risk prompt content, the electronic device can start running the video call function and display the video interface shown in (a) of FIG. 14. Thereafter, when the user intends to switch to use the voice call function of application A, because the voice call function still needs to use the microphone of the electronic device, and the user has previously understood the risk prompt content of application A using the microphone, the related risk prompt content can no longer be displayed. The electronic device can directly respond to the click operation of the user on the "switch to voice" control 1401, and the electronic device starts running the voice call function of application A and displays the voice interface shown in (b) of FIG. 14.
[0263] In some scenarios, in order to implement the first function, the first application requests to call a first system service related to the first function to support the normal operation of the first function. Because the first system service has a security / privacy risk, the electronic device can control the call of the first application to the first system service through the permission control method provided by the embodiments of the present application, to ensure that the call is under the explicit authorization of the user, and the user can revoke the authorization at any time.
[0264] Optionally, when the electronic device detects a request of the first application to invoke the first system service related to the first function, the electronic device can instruct the first application to first invoke a first contextual service related to the first function. The first contextual service is configured to provide an interface for interaction with the user, so as to explicitly perceive the current use state of the first function of the first application by the user, which is equivalent to explicitly obtaining the authorization of the current user to the first application to invoke the first system service related to the first function.
[0265] That is, in response to the above-mentioned opening operation of the user on the first function of the first application, the first application of the electronic device can initiate a request to invoke the first contextual service corresponding to the first function. The first contextual service of the electronic device can trigger the electronic device to display a first system prompt in response to the invocation request of the first application. Then the first contextual service can determine whether to grant the first application the permission to invoke the first system service related to the first function according to the interaction result of the user with the first system prompt.
[0266] Optionally, when the first application provides a first application prompt similar to the first system prompt, the first application can also send the interaction result of the user with the first application prompt to the first contextual service when the first application triggers the electronic device to display the first application prompt. Then the first contextual service can determine whether to grant the first application the permission to invoke the first system service related to the first function according to the interaction result.
[0267] Optionally, when providing the corresponding system function / capability, the first system service can communicate with the first contextual service to perceive the authorization state of the user to the first application to invoke the first system service related to the first function, so as to determine whether to agree with the invocation of the first application according to the authorization state.
[0268] In some scenarios, the first contextual service can also send information of whether to grant the first application the permission to invoke the first system service related to the first function to the permission management service, so that when providing the corresponding system function / capability, the first system service can communicate with the permission management service to perceive the authorization state of the user to the first application to invoke the first system service related to the first function, so as to determine whether to agree with the invocation of the first application according to the authorization state.
[0269] S1530, the electronic device detects a trigger operation of the user on the confirmation control in the first system prompt.
[0270] When the user still determines to use the first function of the first application after understanding the risk prompt content, the user can input a trigger operation on the confirmation control in the first system prompt. The trigger operation can be a touch operation, a voice operation, a hovering gesture operation, a physical key operation, etc.
[0271] As an example, as shown in (b) of FIG. 10, when the user determines to use the navigation function of application C after learning of the risk of using the navigation function of application C, the user can click the "Confirm" control in the risk prompt window 1002.
[0272] As another example, as shown in (c) of FIG. 13, when the user determines to use the remote control function of application B after learning of the risk of using the remote control function of application B, the user can click the "Confirm" control in the risk prompt window 1303.
[0273] Optionally, when the first system prompt is displayed in the form of a pre-warning icon in the status bar, in response to the user clicking the pre-warning icon, the electronic device can expand and display the first system prompt. The expanded and displayed first system prompt includes a confirmation control and a cancellation control. Thus, the user can input a trigger operation for the confirmation control in the first system prompt.
[0274] In some embodiments, when the user intends to give up using the first function of the first application after learning of the risk prompt content, the user can input a trigger operation for the cancellation control in the first system prompt. The trigger operation can be a touch operation, a voice operation, a hovering gesture operation, a physical key operation, etc. At this time, the electronic device can consider that the user has given up granting the first application the permission to call the first system service related to the first function.
[0275] Optionally, after the first scenario-based service corresponding to the first function instructs the electronic device to display the first system prompt, if it is detected that the user inputs a trigger operation for the cancellation control in the first system prompt, it can be confirmed that the user currently has no intention to use the first function of the first application, and thus the first application can not be granted the permission to call the first system service related to the first function.
[0276] As an example, as shown in (b) of FIG. 10, when the user intends to give up determining to use the navigation function of application C after learning of the risk of using the navigation function of application C, the user can click the "Cancel" control in the risk prompt window 1002. At this time, the electronic device can not grant application C the permission to call the location service. Thus, application C cannot call the location service by itself to obtain the location information of the user.
[0277] S1540, in response to the trigger operation for the confirmation control in the first system prompt, the electronic device grants the first application the permission to call the first system service, and uses the first function of the first application and displays a second system prompt containing a stop control.
[0278] In the embodiments of the present application, when the electronic device detects the triggering operation of the confirmation control in the first system prompt, it can be considered that the user determines to use the first function of the first application after understanding the risk prompt content. Since the normal operation of the first function requires the support of the first system service, it can be considered that the user grants the first application the permission to call the first system service related to the first function. Therefore, the electronic device can directly respond to the triggering operation of the confirmation control in the first system prompt, start running the first function of the first application, and grant the first application the permission to call the first system service.
[0279] Specifically, after the first scenario service corresponding to the first function instructs the electronic device to display the first system prompt, if the triggering operation of the confirmation control in the first system prompt input by the user is detected, the use intention of the user to the first function of the first application at present can be explicitly obtained, that is, the authorization of the user to the first application to call the first system service related to the first function can be explicitly obtained. Then the first scenario service can notify the authorization information to the first system service related to the first function, so that the first system service can respond to the call of the first application. In this way, the first application can call the first system service at any time to realize the first function.
[0280] In some embodiments, when the first system prompt supports the user to select not to be prompted next time, or the user has understood the risk prompt content of the first application using the related system service for a short time, when the electronic device detects the opening operation of the user to the first function of the first application, it can be considered that the user determines to use the first function of the first application after understanding the risk prompt content. Therefore, the electronic device can directly respond to the opening operation of the user to the first function of the first application, start running the first function of the first application, and grant the first application the permission to call the first system service.
[0281] Alternatively, in response to the above opening operation of the user to the first function of the first application, the first application of the electronic device can initiate a request to call the first scenario service corresponding to the first function, and send the operation information of the opening operation of the user to the first function of the first application to the first scenario service. The first scenario service can confirm the use intention of the user to the first function of the first application at present according to the operation information, that is, confirm the authorization of the user to the first application to call the first system service related to the first function. Therefore, the first scenario service can respond to the call request of the first application, notify the authorization information to the first system service related to the first function, so that the first system service can respond to the call of the first application. In this way, the first application can call the first system service at any time to realize the first function.
[0282] In the embodiments of the present application, when the first function of the first application starts running, the electronic device can display a second system prompt to prompt the user about the use state of the first function of the first application or to prompt the user about the calling state of the first application to the first system service.
[0283] Specifically, after the first scenario service corresponding to the first function instructs the electronic device to display the first system prompt, if a triggering operation of the user input to the confirmation control in the first system prompt is detected, it can be determined that the user authorizes the first application to call the first system service related to the first function. Then the first scenario service can instruct the electronic device to display a second system prompt according to the current first function use scenario of the first application.
[0284] The second system prompt displayed in the embodiments of the present application is a system-level prompt defined and controlled by the operating system of the electronic device, which is not an application-level prompt defined and controlled by the application. In this way, when the first application starts the first function by itself or calls the first system service by itself, the situation of maliciously avoiding the use state prompt of the first function or the calling prompt of the first application to the first system service can be avoided, and thus the situation that the user cannot know at any time that the first application starts the first function by itself or calls the corresponding system service can be avoided.
[0285] It can be understood that even if the first application secretly runs the first function or secretly calls the first system service without the user's knowledge, the electronic device can display a second system prompt in response to the running of the first function of the first application or in response to the calling of the first system service, to inform the user that the first application is supporting the running of the first function or to inform the user that the first application is calling the first system service. In this way, the user can know at any time the running state of the first function of the first application or the calling state of the first system service of the first application.
[0286] The second system prompt can also provide a system-level control such as a stop control. The stop control is used to trigger the stop running of the first function of the first application, which is equivalent to canceling the user's previous authorization of the first application to call the first system service. Thus, the user can stop using the first function of the first application by one key through the stop control. It can be understood that the user sees on the interface is to stop using the first function of the first application, but actually cancels the authorization of the first application to call the first system service at the same time, so that the first application cannot maliciously call the first system service, thereby ensuring the information security of the electronic device and avoiding the leakage of user privacy data.
[0287] In this way, the electronic device can obtain the current user's intention to stop using the first function of the first application through the second system prompt of the system control, which is equivalent to obtaining the current user's authorization cancellation of the system service related to the first function of the first application, and can prevent the first application from cheating the electronic device that the user still has authorization.
[0288] Optionally, the stop control can be a control for completely stopping the running of the first function of the first application, or can be a control for temporarily stopping the running of the first function of the first application.
[0289] Optionally, when the first application provides an application-level prompt similar to the second system prompt, such as a second application prompt, the electronic device can hide the display of the second system prompt when the first application triggers the electronic device to display the second application prompt; and the electronic device displays the second system prompt again when the electronic device does not display the second application prompt, so as to avoid too many prompts affecting the user interaction experience.
[0290] In some scenarios, when the user stops using the first function of the first application through the stop control in the second application prompt, even if the first application maliciously cheats the electronic device that the user is still using the first function in order to continue to secretly run the first function or secretly call the first system service, the electronic device can display the second system prompt controlled by the system based on the running of the first function of the first application or the calling of the first system service, so that the foreground always retains a clear prompt to inform the user that the first application is running the first function or to inform the user that the first application is calling the first system service. Therefore, in the method provided in the embodiments of the present application, the user can directly stop using the first function of the first application through the stop control in the second system prompt, that is, directly cancel the user's previous authorization of the first application to call the first system service.
[0291] Exemplarily, as shown in (a) of FIG. 16, when the application A calls the microphone service by itself, the electronic device can display a status prompt window 1601 to prompt the user that the application A is accessing the microphone. The status prompt window 1601 includes a “not allowed” control 1602 for directly canceling the user's previous authorization of the first application to call the first system service. In this way, the user can know the calling of the microphone service by the application A at any time through the status prompt window 1601, and can directly stop or refuse to grant the application A the permission to access the microphone through the operation of the “not allowed” control 1602, so that the application A cannot call the microphone service by itself again.
[0292] That is, in the embodiments of the present application, whether the first application runs the first function or calls the first system service with the user's knowledge or not, the electronic device will display the second system prompt when the first application runs the first function or calls the first system service. In this way, the user can know the running status of the first function of the first application at any time, or know the calling status of the first system service of the first application at any time. The information security of the electronic device is ensured, and the leakage of user privacy data is avoided.
[0293] Optionally, the second system prompt can include at least one of the following state prompt content: the application identifier (such as the application icon, the application name, etc.) of the first application; the first function currently running (such as the video call function currently being performed, the navigation function, etc.); the first system service currently being called (such as accessing the microphone, the camera, etc.); the risk prompt content about using the first function (the use of the video call function will obtain the image and sound information of the user); the risk prompt content about the first application using the related system service (such as the application A is accessing the microphone and the camera, and the application A can obtain the image and audio information of the user at any time).
[0294] As a way, the second system prompt can be displayed in the form of a floating window, which can display complete state prompt content or folded state prompt content. When the user clicks on the folded state prompt content, the electronic device can display the complete state prompt content.
[0295] As another way, the second system prompt can also be displayed in the form of a prompt icon in the status bar. When the user clicks on the prompt icon, the electronic device can display a state prompt window to completely or partially display the corresponding state prompt content. Optionally, the state prompt content in the second system prompt can also be displayed by jumping to a specified page through a link, and the specified page is used to display the complete state prompt content.
[0296] Optionally, the electronic device can always display the second system prompt on the screen to ensure that it will not be covered by various applications. It can also support setting a certain transparency of the second system prompt, such as being in a semi-transparent state, to avoid disturbing the user's operation. It can also support setting a certain hiding rule for the second system prompt, such as when the second system prompt is displayed in the form of a floating window, it can be folded into a strip prompt at the edge of the screen, or a floating ball prompt at the edge of the screen, or hidden for a certain period of time, such as 15 minutes, or set to be hidden before the next user interaction with the electronic device. The display mode of the second system prompt is not limited in the embodiments of the present application.
[0297] Optionally, the electronic device can also use other ways that can explicitly prompt the user without being covered by the application, such as a hardware physical light, or display a corresponding state card on the sliding notification bar, to prompt the user about the use state of the first function of the first application, or prompt the user about the calling state of the first application to the first system service. For example, if the first application is calling the microphone, a microphone state card can be displayed on the sliding notification bar, and the card displays a stop control.
[0298] As an example, as shown in (b) of FIG. 10, when the electronic device detects a click operation of the user on the "Confirm" control in the risk prompt window 1002, it can be confirmed that the user still intends to use the navigation function of the application C after learning the risk prompt content, at which time the electronic device can start running the navigation function of the application C in response to the click operation, and display the navigation interface provided by the application C as shown in (c) of FIG. 10. And during the running of the navigation function of the application C, the electronic device grants the application C the permission to call the system service related to the navigation function, such as the permission to call the location service, so that the application C can successfully call the related system service to support the normal running of the navigation function.
[0299] As shown in (c) of FIG. 10, the electronic device can display a state prompt window 1003 on the currently displayed interface when the navigation function of the application C starts running, which can show the user what application is currently running and what function scenario is being supported, such as "application icon of application C + navigation", and an "end" control 1004. The "end" control 1004 is used to completely stop the running of the navigation function of the application C.
[0300] The user can use the "end" control 1004 to one-click stop using the navigation function of the application C, that is, one-click cancel the user's previous authorization of the application C to call the system service related to the navigation function.
[0301] Optionally, the application C can also be provided with a "quit navigation" control 1005 for completely stopping the running of the navigation function. The user can use the "quit navigation" control 1005 to one-click stop using the navigation function of the application C, that is, one-click cancel the user's previous authorization of the application C to call the system service related to the navigation function.
[0302] Optionally, the electronic device can also hide the state prompt window 1003 when the navigation interface of the application C is displayed. Or, the electronic device can also hide the "end" control 1004 when the application C displays the "quit navigation" control 1005.
[0303] Optionally, as shown in (d) of FIG. 10, when the application C navigation interface is displayed in the background, the electronic device can keep the display state prompt window 1003 in the foreground. Thus, the user can directly stop using the navigation function of the application C by one key, that is, cancel the authorization of the user to the application C to call the system service related to the navigation function, without the need to enter the navigation interface of the application C and click the "exit navigation" control 1005.
[0304] As another example, in the process of supporting the screen sharing function of the application B, as shown in (c) of FIG. 13, when the electronic device detects the click operation of the user on the "confirm" control in the risk prompt window 1303, it can confirm that the user still intends to use the remote control function of the application B after learning the risk prompt content. At this time, the electronic device can respond to the click operation, start running the remote control function of the application B while running the screen sharing function of the application B, and display the remote control interface provided by the application B as shown in (d) of FIG. 13. And during the running of the remote control function of the application B, the electronic device grants the application B the permission to call the system service related to the remote control function, such as the permission to call the keyboard and mouse injection service. So that the application B can successfully call the related system service to support the normal running of the remote control function.
[0305] As shown in (d) of FIG. 13, when the remote control function of the application B starts running, the electronic device can display a state prompt window 1304 on the currently displayed interface, which can show the user that "application B-remote control in progress". The user can view and manage the current state through the state prompt window 1304.
[0306] As shown in (d) of FIG. 13, when the user clicks the state prompt window 1304, the electronic device can expand and display the state management control. As shown in (e) of FIG. 13, the state management control includes an "end" control 1305 and a "pause" control 1306. The "end" control 1305 is used to completely stop the running of the remote control function of the application B, and the "pause" control 1306 is used to temporarily stop the running of the remote control function of the application B.
[0307] The user can stop using the remote control function of the application B by one key through the "end" control 1305, that is, cancel the authorization of the user to the application B to call the system service related to the remote control function. At this time, since the screen sharing function of the application B is still running, the electronic device can display the screen sharing interface provided by the application B as shown in (f) of FIG. 13.
[0308] Optionally, the user can temporarily stop using the remote control function of application B through the "pause" control 1306, i.e., the user's previous authorization for application B to invoke the system service related to the remote control function can be temporarily cancelled. Then the user can resume using the remote control function of application B through the "continue" control or the "resume" control shown in the status prompt window 1304, i.e., the user's previous authorization for application B to invoke the system service related to the remote control function can be resumed.
[0309] As a further example, in application supporting the video call function, as shown in (a) of FIG. 14, the electronic device can display a status prompt window 1404 on the currently displayed interface of the application, which can show the user "application icon + video call in progress" and an "end" control 1405. The "end" control 1405 is used to completely stop the running of the video call function of the application. application icon + video call in progress" and an "end" control 1405. The "end" control 1405 is used to completely stop the running of the video call function of the application. application icon + video call in progress" and an "end" control 1405. The "end" control 1405 is used to completely stop the running of the video call function of the application. application icon + video call in progress" and an "end" control 1405. The "end" control 1405 is used to completely stop the running of the video call function of the application. application icon + video call in progress" and an "end" control 1405. The "end" control 1405 is used to completely stop the running of the video call function of the application.
[0310] When the user clicks the "switch to voice" control 1401 provided by the application, the electronic device can respond to the click operation to switch the running video call function of the application to run the voice call function of the application, and during the running of the voice call function of the application, the electronic device grants the application the permission to invoke the system service related to the voice call function, such as the permission to invoke the microphone service. This enables the application to successfully invoke the related system service to support the normal running of the voice call function. application icon + video call in progress" and an "end" control 1405. The "end" control 1405 is used to completely stop the running of the video call function of the application. application icon + video call in progress" and an "end" control 1405. The "end" control 1405 is used to completely stop the running of the video call function of the application. application icon + video call in progress" and an "end" control 1405. The "end" control 1405 is used to completely stop the running of the video call function of the application. application icon + video call in progress" and an "end" control 1405. The "end" control 1405 is used to completely stop the running of the video call function of the application. application icon + video call in progress" and an "end" control 1405. The "end" control 1405 is used to completely stop the running of the video call function of the application. application icon + video call in progress" and an "end" control 1405. The "end" control 1405 is used to completely stop the running of the video call function of the application.
[0311] It can be understood that since the video call function has stopped running and the currently running voice call function does not need to use the camera, the electronic device can revoke the permission granted to the application to invoke the camera service. application icon + video call in progress" and an "end" control 1405. The "end" control 1405 is used to completely stop the running of the video call function of the application.
[0312] As shown in (b) of FIG. 14, the electronic device can switch to display a status prompt window 1406 on the currently displayed interface when switching to run the voice call function of the application, which can show the user "application icon + voice call in progress" and an "end" control 1405. The "end" control 1405 is used to completely stop the running of the voice call function of the application. application icon + video call in progress" and an "end" control 1405. The "end" control 1405 is used to completely stop the running of the video call function of the application. The application icon of the application + voice call in progress, and the "end" control 1407. The "end" control 1407 is used to completely stop the call. The voice call function of the application is running.
[0313] Optionally, as shown in (c) of FIG. 14 , when the electronic device enters the application management interface, the status prompt window 1406 may always remain displayed in the foreground.
[0314] In some embodiments, when the status prompt window is used to prompt the user of the calling status of the first application on the system service related to the first function, the stop control can also be a control used to stop or refuse to grant the first application permission to call a certain system service.
[0315] As an example, in During the process of applying the video call function, as shown in (c) of FIG16 , the electronic device may display a status prompt window 1607 on the currently displayed interface, and the status prompt window 1607 may show the user that there is a video call function. The application is currently calling various system services, such as Application icon + using microphone", " The application icon of the application + using the camera. The user can use this status prompt window to understand which capabilities of the electronic device are used by the current application.
[0316] Optionally, the electronic device may provide corresponding management controls for each system service. As shown in (c) of FIG16 , In the process of applying the video call function, when the user intends to turn off the microphone, the user can click the "off" control 1608 to stop using the microphone service. At this time, the "off" control 1608 can be switched to the "on" control, and the electronic device can cancel the microphone service. When the user intends to turn off the camera, the user can click the "off" control 1609 to stop using the camera service. At this time, the "off" control 1609 can be switched to the "on" control, and the electronic device can cancel the previous The application is authorized to call the camera service. When the application supports the video call function, if the user intends to use the microphone or camera again, the user can use the "Open" control to resume the use of the microphone or camera. Correspondingly, the electronic device can resume the previous use of the microphone or camera. Authorization for the application to call the camera service.
[0317] Alternatively, as shown in (b) of FIG16 , The application can also provide a "hang up" control 1605 for completely stopping the video call function from running. The user can use the "hang up" control 1605 to one-click stop using the video call function of the application The video call function of the application, i.e., the one-click cancelation of the user's previous use of the video call function of the application, The application calls the authorization of the system service related to the video call function.
[0318] Similarly, in the process of the application supporting the video call function, In the process of the application supporting the video call function, The application can also provide controls for pausing and resuming certain system capabilities, such as the microphone on / off control 1603 for pausing and resuming the use of the microphone, and the camera on / off control 1604 for pausing and resuming the use of the camera. There can also be a "turn to voice" control 1606 for completely ending the use of the camera. The electronic device can determine the user's use intention for these system capabilities through the user's operation of these controls, and then determine whether to grant The application calls the authorization of the system service.
[0319] S1550, the electronic device detects a triggering operation of the user on the stop control in the second system prompt.
[0320] In the embodiments of the present application, when the user intends to stop using the first function of the first application, the user can input a triggering operation on the stop control in the second system prompt. The triggering operation can be a touch operation, a voice operation, a hovering gesture operation, a physical key operation, etc.
[0321] As an example, as shown in (c) and (d) of FIG. 10, when the user intends to stop using the navigation function of the application C, the user can click the "end" control 1004 in the state prompt window 1003.
[0322] As another example, as shown in (e) of FIG. 13, when the user intends to temporarily stop using the remote control function of the application B, the user can click the "pause" control 1306 in the state prompt window 1304.
[0323] In some embodiments, when the first application is provided with a stop control for triggering the stop of the first function of the first application, the user can also input a triggering operation on the stop control provided by the first application to one-click stop the first function of the first application.
[0324] As an example, as shown in (b) of FIG. 14, when the user intends to temporarily stop using the video call function of the application, the user can click the "end" control 1407 in the state prompt window 1406, or click the The video call function of the application The application provides a "hang up" control 1402.
[0325] S1560, the electronic device stops using the first function of the first application and cancels the permission of the first application to call the first system service in response to the triggering operation of the stop control in the second system prompt.
[0326] In the embodiment of the application, when the electronic device detects the triggering operation of the stop control in the second system prompt by the user, it can be considered that the user intends to stop using the first function of the first application, and at this time, it can be considered that the user intends to withdraw the permission of the first application to call the first system service related to the first function. Therefore, the electronic device can directly stop running the first function of the first application and cancel the permission of the first application to call the first system service in response to the triggering operation of the stop control in the second system prompt.
[0327] Specifically, after the first scenario-based service corresponding to the first function instructs the electronic device to display the second system prompt, if the triggering operation of the stop control in the second system prompt input by the user is detected, it can be explicitly obtained that the user cancels the authorization of the first application to call the first system service related to the first function. Then the first scenario-based service can notify the first system service related to the first function of the cancellation of authorization, so that the first system service can refuse to respond to the call of the first application. In this way, the first application can no longer successfully call the first system service.
[0328] As an example, as shown in (c) and (d) of FIG. 10, when the user clicks the "end" control 1004 in the status prompt window 1003, the electronic device can stop running the navigation function of the application C and withdraw the permission of the application C to call the system service related to the navigation function, such as the permission to call the location service, in response to the clicking operation.
[0329] As another example, as shown in (e) of FIG. 13, when the user clicks the "pause" control 1306 in the status prompt window 1304, the electronic device can pause running the navigation function of the application C and temporarily withdraw the permission of the application C to call the system service related to the navigation function, such as the permission to call the location service, in response to the clicking operation. During this period, the application C can no longer call the location service. At this time, the "pause" control 1306 in the status prompt window 1304 can be switched to a "continue" control. When the user clicks the "continue" control, the electronic device can continue running the navigation function of the application C and continue granting the permission of the application C to call the system service related to the navigation function, such as the permission of the application C to call the location service, in response to the clicking operation. At this time, the application C can continue to call the location service.
[0330] In some scenarios, the electronic device can display a corresponding indication icon on the status bar to indicate that the first system service is currently being invoked when it is detected that the first system service is successfully invoked.
[0331] Taking the application D supporting the recording function as an example, since the recording function needs the application D to invoke the microphone service, as shown in (a) of FIG. 17, the electronic device can start running the recording function and grant the application D the permission to invoke the microphone service in response to the user's operation of clicking the "recording" control 1701. At this time, since the application D continuously invokes the microphone service to obtain the user's audio information, the electronic device can detect that the microphone service is successfully invoked, so that the microphone icon 1702 can be displayed on the status bar to prompt the user that the microphone of the electronic device is being used.
[0332] When the user needs to pause the recording, as shown in (b) of FIG. 17, the electronic device can temporarily stop running the recording function and temporarily revoke the permission previously granted to the application D to invoke the microphone service in response to the user's operation of clicking the "pause" control 1703. At this time, since the application D cannot invoke the microphone service to obtain the user's audio information, the electronic device can detect that the microphone service is not successfully invoked, so that the microphone icon 1702 can be removed from the status bar as shown in (b) of FIG. 17 to prompt the user that the microphone of the electronic device is not being used.
[0333] When the user needs to continue recording, as shown in (b) of FIG. 17, the electronic device can continue running the recording function and continue granting the application D the permission to invoke the microphone service in response to the user's operation of clicking the "continue" control 1704. At this time, since the application D can continue to continuously invoke the microphone service to obtain the user's audio information, the electronic device can detect that the microphone service is successfully invoked again, so that the microphone icon 1702 can be restored to be displayed on the status bar as shown in (c) of FIG. 17 to prompt the user that the microphone of the electronic device is being used.
[0334] The permission control method provided by the embodiments of the present application can enable the electronic device to grant the first application the permission to invoke the system service related to the first function when the first function of the first application is running, and synchronously display a second system prompt to inform the user of the function scenario currently supported by the first application or the system service currently used by the first application. In addition, a one-key stop function of the first function can also be synchronously provided to the user, which is equivalent to a one-key revocation of the permission granted to the first application to invoke the system service related to the first function, so that the user can know and control the behavior of the first application accessing the system service, thereby enhancing the protection of the user's private data.
[0335] It can be understood that, in order to realize the above functions, the electronic device comprises hardware and / or software modules corresponding to the respective functions. The algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in hardware or a combination of hardware and computer software. Whether a certain function is implemented in hardware or computer software driven hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application in conjunction with the embodiments, but such implementation should not be considered beyond the scope of the present application.
[0336] The embodiments can divide the functional modules of the electronic device according to the above method examples. For example, each functional module can be divided according to each function. Each functional module can exist physically alone, or two or more functions can be integrated into one processing module. The integrated module can be implemented in the form of hardware or in the form of a software functional unit. If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium.
[0337] As an example, the electronic device can include a processing module configured to, in response to a use operation of a first function of a first application, use the first function of the first application and grant the first application a permission to call a system service related to the first function, the system service related to the first function being related to a user's security privacy. The processing module is further configured to, during execution of the first application, in response to a stop use of the first function of the first application, cancel the permission granted to the first application to call the system service related to the first function.
[0338] Optionally, the processing module is further configured to, in response to a use operation of a second function of the first application, use the second function of the first application and grant the first application a permission to call a system service related to the second function, the system service related to the second function being related to the user's security privacy; during execution of the first application, in response to a stop use of the second function of the first application, cancel the permission granted to the first application to call the system service related to the second function.
[0339] Optionally, the processing module is further configured to, in response to switching from the first function of the first application to a second function of the first application, cancel the permission granted to the first application to call the system service related to the first function.
[0340] Optionally, the electronic device can further include a display module configured to, in response to the use of the first function of the first application, display a first icon in a status bar, the first icon being used to indicate that the system service related to the first function is called; and in response to switching from the first function of the first application to the second function of the first application, cancel the display of the first icon in the status bar.
[0341] Optionally, when the system services related to the first function are multiple, the processing module is further configured to, in response to switching from the first function of the first application to a second function of the first application, cancel the permission of the first application to invoke the part of the system services related to the first function, the part of the system services being irrelevant to the second function.
[0342] Optionally, the display module is further configured to, in response to the use of the first function of the first application, display a plurality of icons in the status bar, the plurality of icons being used to indicate that the system services related to the first function are invoked; and in response to switching from the first function of the first application to a second function of the first application, cancel the display of part of the plurality of icons in the status bar.
[0343] Optionally, the processing module is further configured to, in response to the stop of the use of the first function of the first application, cancel the permission of the first application to invoke the system services related to the first function.
[0344] Optionally, the processing module is further configured to, in response to the pause of the use of the first function of the first application, cancel the permission of the first application to invoke the system services related to the first function; and in response to the resumption of the use of the first function of the first application, continue to grant the permission of the first application to invoke the system services related to the first function.
[0345] Optionally, the display module is further configured to, in response to the use of the first function of the first application, display a first icon in the status bar, the first icon being used to indicate that the system services related to the first function are invoked; in response to the pause of the use of the first function of the first application, cancel the display of the first icon in the status bar; and in response to the resumption of the use of the first function of the first application, continue to display the first icon in the status bar.
[0346] Optionally, the electronic device can further include a prompt module configured to, in response to the use of the first function of the first application, output a first system-level prompt, the first prompt being used to prompt a user whether to confirm the use of the first function of the first application. The processing module is further configured to, in response to a confirmation operation on the first prompt, use the first function of the first application and grant the permission of the first application to invoke the system services related to the first function.
[0347] Optionally, the prompt module is further configured to, during the use of the first function of the first application, output a second system-level prompt, the second prompt being used to prompt the user that the first function of the first application is in use and / or prompt the user that the system services related to the first function are invoked.
[0348] Optionally, the processing module is further configured to, in response to an operation on the system-level control, cancel the permission of the first application to invoke the system service related to the first function of the first application when the first function of the first application is stopped from being used and the permission of the first application to invoke the system service related to the first function of the first application is not cancelled.
[0349] Optionally, the processing module is configured to, in response to the first function of the first application being stopped from being used, cancel the permission of the first application to invoke the system service related to the first function of the first application when the first application is in a foreground running process.
[0350] Those skilled in the art can clearly understand the above-mentioned method embodiments through the description of the above-mentioned embodiments. For the convenience and brevity of description, only the division of the above-mentioned functional modules is taken as an example. In actual application, the above-mentioned functions can be completed by different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.
[0351] It should be noted that all related contents of each step involved in the above method embodiments can be referred to the function description of the corresponding functional module, which will not be repeated here. The electronic device provided by the embodiments of the present application is used to execute the above permission control method, so as to achieve the same effect as the above implementation method.
[0352] The embodiments of the present application further provide an electronic device, which includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the electronic device implements each function or step performed by the electronic device in each method embodiment.
[0353] The embodiments of the present application further provide a permission control device, which can be applied to the above-mentioned electronic device. The device is used to execute each function or step performed by the electronic device in the above-mentioned method embodiments.
[0354] The embodiments of the present application further provide a chip system, which includes at least one processor and at least one interface circuit. The processor and the interface circuit can be interconnected through a circuit. The interface circuit can read instructions stored in the memory and send the instructions to the processor. When the instructions are executed by the processor, the electronic device can execute each function or step performed by the electronic device in the above-mentioned method embodiments. Of course, the chip system can also include other discrete devices, which are not limited in the embodiments of the present application.
[0355] The embodiments of the present application further provide a computer readable storage medium, which includes computer instructions. When the computer instructions are executed on the above-mentioned electronic device, the electronic device executes each function or step performed by the electronic device in the above-mentioned method embodiments.
[0356] The embodiment of the present application further provides a computer program product, which, when running on an electronic device, enables the electronic device to perform each function or step of the method embodiment described above.
[0357] The electronic device, the permission control apparatus, the computer readable storage medium, the computer program product or the chip provided by the embodiment of the present application are all used for executing the corresponding method provided above, and thus the beneficial effects achieved thereby can refer to the beneficial effects of the corresponding method provided above, which will not be described here again.
[0358] In addition, unless otherwise specified, " / " in the present application represents an "or" relationship between the objects before and after the " / " symbol, for example, A / B can represent A or B; "and / or" in the present application is a description of the association between the objects, which means that there can be three relationships, for example, A and / or B, which can represent: A alone, A and B together, B alone, of which A and B can be singular or plural. "Multiple" in the present application means two or more than two. "At least one of the following" or similar expressions means any combination of these objects. For example, at least one of a, b, or c can represent: a, b, c, a and b, a and c, b and c, a and b and c, of which a, b, and c can be singular or plural.
[0359] The present application uses "first", "second", and the like to distinguish the same items or similar items with basically the same function and role, and those skilled in the art can understand that "first", "second", and the like do not limit the quantity and execution order, and "first", "second", and the like do not necessarily mean different. The words "exemplarily" or "for example" and the like in the present application are used to represent an example, illustration or description. Any embodiment or design described as "exemplarily" or "for example" should not be interpreted as more preferred or more advantageous than other embodiments or design solutions. Rather, the words "exemplarily" or "for example" are used to present the relevant concept in a specific way and facilitate understanding.
[0360] The features, structures or characteristics in the present application can be combined in any suitable manner in one or more embodiments. In various embodiments of the present application, the size of the serial number of each process does not mean the execution order, and the execution order of each process should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0361] Some optional features in the embodiments of the present application can be implemented independently in some scenarios without relying on other features to solve corresponding technical problems and achieve corresponding effects, or can be combined with other features according to needs in some scenarios. Identical or similar parts among various embodiments in the present application can be mutually referred to, unless otherwise specified. The terms and / or descriptions in different embodiments in the present application are consistent and can be mutually referred to, unless otherwise specified and in conflict with logic, and technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship. The implementation manners of the present application do not constitute a limitation on the protection scope of the present application.
[0362] In several embodiments provided in the present application, the disclosed apparatus and method can be implemented in other manners. For example, the above described units or components can be combined or integrated into another apparatus, or some features can be ignored or not executed. In addition, the displayed or discussed coupling or direct coupling or communication connection between units can be indirect coupling or communication connection through some interface, device or unit, and can be electrical, mechanical or in other forms. The units described as separate components may or can not be physically separate, and the components displayed as units may be located in one place or distributed on multiple places. Some or all of the units can be selected according to actual needs to achieve the purposes of the embodiments of the present application.
[0363] Based on such understanding, the technical solutions of the embodiments of the present application, essentially or in other words, the part of the technical solutions that make contributions to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions to make a device (which can be a single chip, a chip, etc.) or a processor execute all or part of the steps of the methods described in the various embodiments of the present application. The storage medium mentioned above includes: a U disk, a mobile hard disk, a read only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various program code storage media.
[0364] The above only describes specific implementation manners of the present application, but the protection scope of the present application is not limited thereto, and any changes or replacements within the technical scope disclosed in the present application should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A method of controlling rights, characterized by, The method is applied to an electronic device, and the method comprises: in response to a use operation of a first function of a first application, using the first function of the first application, and granting the first application a permission to call a system service related to the first function, the system service related to the first function being related to a user's security privacy; during running of the first application, in response to a stop use of the first function of the first application, canceling the permission granted to the first application to call the system service related to the first function.
2. The method of claim 1, wherein, The method further comprises: in response to a use operation of a second function of the first application, using the second function of the first application, and granting the first application a permission to call a system service related to the second function, the system service related to the second function being related to a user's security privacy; during running of the first application, in response to a stop use of the second function of the first application, canceling the permission granted to the first application to call the system service related to the second function.
3. The method according to claim 1 or 2, characterized in that, The canceling the permission granted to the first application to call the system service related to the first function in response to the stop use of the first function of the first application comprises: in response to switching from the first function of the first application to a second function of the first application, canceling the permission granted to the first application to call the system service related to the first function.
4. The method of claim 3, wherein, The method further comprises: in response to the use of the first function of the first application, displaying a first icon in a status bar, the first icon being used to indicate that the system service related to the first function is called; in response to switching from the first function of the first application to the second function of the first application, canceling the display of the first icon in the status bar.
5. The method according to claim 1 or 2, characterized in that, The system service related to the first function is multiple, and the canceling the permission granted to the first application to call the system service related to the first function in response to the stop use of the first function of the first application comprises: in response to switching from the first function of the first application to a second function of the first application, canceling the permission granted to the first application to call part of the system service related to the first function, the part of the system service being irrelevant to the second function.
6. The method of claim 5, wherein, The method further comprises: in response to the use of the first function of the first application, displaying multiple icons in a status bar, the multiple icons being used to indicate that the system service related to the first function is called; in response to switching from the first function of the first application to the second function of the first application, canceling the display of part of the multiple icons in the status bar.
7. The method according to claim 1 or 2, characterized in that, The canceling the permission granted to the first application to call the system service related to the first function in response to the stop use of the first function of the first application comprises: in response to a stop use operation of the first function of the first application, canceling the permission granted to the first application to call the system service related to the first function.
8. The method of claim 7, wherein, The stop use operation of the first function of the first application comprises: an operation on an application-level control in the first application; or an operation on a system-level control in the electronic device.
9. The method according to any one of claims 1 to 8, characterized in that, The revoking the permission of the first application to invoke the system service related to the first function in response to the stop use of the first function of the first application comprises: The revoking the permission of the first application to invoke the system service related to the first function in response to the pause use of the first function of the first application comprises: The method further comprises: The continuing the permission of the first application to invoke the system service related to the first function in response to the continue use of the first function of the first application comprises:
10. The method of claim 9, wherein, The method further comprises: The displaying the first icon in the status bar in response to the use of the first function of the first application, the first icon being used to indicate that the system service related to the first function is invoked; The canceling the display of the first icon in the status bar in response to the pause use of the first function of the first application; The continuing the display of the first icon in the status bar in response to the continue use of the first function of the first application.
11. The method according to any one of claims 1 to 10, characterized in that, The using the first function of the first application and granting the permission of the first application to invoke the system service related to the first function in response to the use operation of the first function of the first application comprises: The outputting a first prompt of a system level in response to the use operation of the first function of the first application, the first prompt being used to prompt a user whether to confirm the use of the first function of the first application; The using the first function of the first application and granting the permission of the first application to invoke the system service related to the first function in response to a confirmation operation on the first prompt.
12. The method according to any one of claims 1 to 11, characterized in that, The method further comprises: The outputting a second prompt of a system level in a use process of the first function of the first application, the second prompt being used to prompt a user that the first function of the first application is in use, and / or prompt a user that the system service related to the first function is invoked.
13. The method of claim 12, wherein, The second prompt comprises a system-level control, the system-level control being used to trigger the stop use of the first function of the first application.
14. The method of claim 13, wherein, The method further comprises: The revoking the permission of the first application to invoke the system service related to the first function in response to an operation on the system-level control when the first function of the first application is stopped and the permission of the first application to invoke the system service related to the first function is not revoked.
15. The method according to any one of claims 1 to 14, characterized in that, The revoking the permission of the first application to invoke the system service related to the first function in response to the stop use of the first function of the first application in a running process of the first application comprises: The revoking the permission of the first application to invoke the system service related to the first function in response to the stop use of the first function of the first application in a foreground running process of the first application.
16. The method according to any one of claims 1 to 15, characterized in that, The system service related to the first function comprises at least one of a microphone service, a camera service, a keyboard and mouse injection service, and a location service.
17. An electronic device, comprising: The electronic device comprises a processor and a memory, the memory is used for storing instructions, and the processor is used for calling the instructions in the memory, so that the electronic device executes the method as claimed in any one of claims 1 to 16.
18. A chip system, characterized by The chip system is applied to an electronic device; the chip system comprises an interface circuit and a processor; the interface circuit and the processor are interconnected through a line; the interface circuit is used for receiving a signal from a memory of the electronic device and sending a signal to the processor, the signal comprising instructions stored in the memory; when the processor executes the instructions, the chip system executes the method as claimed in any one of claims 1 to 16.
19. A readable storage medium, characterized by, A program is included, when the program runs on an electronic device, so that the electronic device executes the method as claimed in any one of claims 1 to 16.
Citation Information
Patent Citations
Application permission management method and device
CN113032766A
Authority control method and device for application page
CN114547676A
Permission setting method and apparatus and electronic device
US20230195298A1
Sensitive application behavior reminding method, related apparatus, and communication system
WO2024037369A1