Data sharing method and related device

By implementing system-level file encryption and sharing controls, as well as access control, the system addresses the issue of poor security in user data sharing, enabling flexible permission settings and identity authentication, thereby improving both user experience and security.

WO2025260886A1PCT designated stage Publication Date: 2025-12-26HUAWEI TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/085715
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-06-19
Filing Date
2025-03-28
Publication Date
2025-12-26

AI Technical Summary

Technical Problem

In existing technologies, when users share data through verbal instructions, security is poor. User 2 can freely forward, print, copy, or take screenshots, resulting in a poor user experience.

Method used

It provides system-level file encryption control and sharing functions, allowing users to set permissions and send files through electronic devices. It supports flexible file sharing and permission settings within the system or applications, and the receiving device controls the application's access permissions according to the permissions set in the file.

Benefits of technology

It improves the security and ecosystem friendliness of data sharing, enhances the user experience, supports multiple permission settings and identity authentication, prevents secondary forwarding, copying, screenshotting and other operations of files, and improves the support for various scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025085715_26122025_PF_FP_ABST
    Figure CN2025085715_26122025_PF_FP_ABST
Patent Text Reader

Abstract

The present application discloses a data sharing method and a related device. For a sender, a sender device provides system-level file encryption, governance, and sharing functionality, without relying on the sender device having to install a certain application; the sender can select, by means of the sender device, a file to be shared from a system, set a permission control policy, and send the file to a receiver device in one or more different manners; for a receiver, a receiver device provides data governance functionality, the receiver can receive and open the shared file by means of the receiver device, and the system can dynamically adjust permissions for an application to access different system functions based on the permission control policy set in the file. For example, by controlling and preventing the receiver from performing certain operations on the file such copying, taking screen shots, or printing, attackers would also be prevented from performing said operations on the file even if attacking an application that opens the file. This results in improvements in areas such as scenario support, security, eco-friendliness, and the like, while also offering a better user experience.
Need to check novelty before this filing date? Find Prior Art

Description

Data sharing method and related device

[0001] The present application claims priority to the Chinese patent application No. 202410798118.7, filed on June 19, 2024, and entitled "Data sharing method and related device", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD

[0002] The present application relates to the technical field of terminals, and in particular to a data sharing method and related device. BACKGROUND

[0003] With the rapid development of terminal technology, a user 1 can share data such as documents and pictures to a terminal device of a user 2 through a terminal device such as a smart phone or a tablet computer. Some data may not be intended to be leaked by the user 2, and the user 1 usually orally instructs the user 2 not to forward these data. However, the oral instruction has limited effect, and the user 2 can still randomly forward, print, copy, and screen capture the data, which is poor in security and user experience. SUMMARY

[0004] Embodiments of the present application provide a data sharing method and related device, which can provide system-level file encryption management and sharing function and data management function, and improve scene support, security, ecological friendliness, and user experience.

[0005] In a first aspect, embodiments of the present application provide a data sharing method applied to a first electronic device, the method comprising: determining, by the first electronic device, that a first file is selected; in response to an operation of sharing the first file on a first interface, sending, by the first electronic device, the first file to a second electronic device associated with a first user; wherein the first electronic device is configured to set a first permission for the first file, and the first permission is effective for a plurality of applications on the first electronic device when the first file is sent, and the first permission is used to indicate one or more operations authorized to be performed on the first file by the first user.

[0006] The first electronic device can be, for example, an electronic device 100 (a sender device), the second electronic device can be, for example, an electronic device 200 (a receiver device), the first file is a file to be shared, which can include but is not limited to pictures, documents, and audio and video, the first interface can be, for example, an interface shown in FIG. 3B or FIG. 3C or FIG. 10C, and the first user is a receiver, which can be an individual or a group.

[0007] By implementing the method of the first aspect, the electronic device can support the user to configure who to send the file to and what permissions (e.g., read-only permission, editable permission, etc.) the file recipient has using the system function, without the upper-layer application needing to be aware, improving the ecological friendliness and the user experience will be better.

[0008] In a possible implementation, the method further includes: before the first electronic device sends the first file to the second electronic device associated with the first user, the first electronic device displays at least one of a device list, an application list, and a user list on an interface, the interface being the first interface or the second interface; and the first electronic device sends the first file to the second electronic device associated with the first user, specifically including: in response to an operation of selecting the second electronic device in the device list, the first electronic device sends the first file to the second electronic device associated with the first user; or, in response to an operation of selecting the first application in the application list, the first electronic device sends the first file to the second electronic device associated with the first user through the first application; or, in response to an operation of selecting the first user in the user list, the first electronic device sends the first file to the second electronic device associated with the first user.

[0009] The second interface may, for example, be the interface shown in FIG. 5F, the device list may include options of one or more devices (e.g., Yun’s Mate 50 shown in FIG. 5F), the application list may include options of one or more applications (e.g., Huawei Share, Freely, Chat shown in FIG. 5F), and the user list may include options of one or more users (e.g., Alice, Alee shown in FIG. 5F).

[0010] The first electronic device sending the first file to the second electronic device associated with the first user through the first application may include two ways: the first way is that the first application first determines the first user, then determines the device associated with the first user based on the first user, and finally sends the first file to the device; and the second way is that the first application directly determines the recipient device and sends the first file to the device.

[0011] In this way, the electronic device can support the user to share files in different ways, with strong flexibility and improved user experience.

[0012] In a possible implementation, the first electronic device sends the first file to the second electronic device associated with the first user, specifically including: in response to an operation of sharing the first file triggered by the interface, the first electronic device sends the first file to the second electronic device associated with the first user, the interface being an interface for a session with the first user.

[0013] The interface may, for example, be the interface shown in FIG. 10A or FIG. 10C.

[0014] In this way, the electronic device can support the user to share the file set with the system permission within the application (for example, a communication application), so as to solve the problem that the permission setting must be implemented by the application if the permission setting is initiated within the application, and if other applications want to control the file, the problem of repeated implementation needs to be solved.

[0015] In a possible implementation, the first file is set with the first permission before the operation of sharing the first file; or, the first file is set with the first permission after the operation of sharing the first file, and is sent to the second electronic device associated with the first user.

[0016] That is, the electronic device can support the user to set the permission for the file first, and then perform the sharing operation, and can also support the user to perform the sharing operation first, which can trigger the electronic device to set the permission for the file and send the file.

[0017] In a possible implementation, the method further includes: in response to the operation of sharing the first file on the first interface, the first electronic device sends the first file to a third electronic device associated with a second user; wherein the first electronic device is configured to set a second permission for the first file, the second permission is effective for multiple applications on the first electronic device when the first file is sent, and the second permission is used to indicate one or more operations authorized to be performed on the first file by the second user.

[0018] The second permission can be the same as or different from the first permission.

[0019] In this way, for the same file, the electronic device can set corresponding permissions for multiple users respectively.

[0020] In a possible implementation, the method further includes: the first electronic device determines that the second file is selected; in response to the operation of sharing the second file on the first interface, the first electronic device sends the second file to the second electronic device associated with the first user; wherein the first electronic device is configured to set a third permission for the second file, the third permission is effective for multiple applications on the first electronic device when the second file is sent, and the third permission is used to indicate one or more operations authorized to be performed on the second file by the first user.

[0021] The third permission can be the same as or different from the first permission.

[0022] In this way, for different files, the electronic device can set corresponding permissions for the same user respectively.

[0023] In a possible implementation, the first user belongs to a first group, and the first group further includes a third user. The method further includes: in response to the operation of sharing the first file on the first interface, the first electronic device sends the first file to a fourth electronic device associated with the third user, and the first permission is further used to indicate that the third user is authorized to perform one or more operations on the first file; or, in response to the operation of sharing the first file on the first interface, the first electronic device sends the first file to the fourth electronic device associated with the third user; and the first electronic device is further configured to set a fourth permission for the first file, the fourth permission is effective for all the applications on the first electronic device when the first file is sent, and the fourth permission is used to indicate that the third user is authorized to perform one or more operations on the first file.

[0024] In this way, when the receiving party belongs to a certain group, the electronic device can set permissions for group members in the group uniformly, or set permissions for group members in the group respectively.

[0025] In a possible implementation, before the first electronic device sends the first file to the second electronic device associated with the first user, the method further includes: the first electronic device logs in a first account, and the first account belongs to an account of a fourth user.

[0026] The fourth user is the sender, so that after logging in the account, the receiving party can know who the sender of the first file is.

[0027] In a possible implementation, before the first electronic device sends the first file to the second electronic device associated with the first user, the method further includes: the first electronic device obtains a credential corresponding to the first user; and the first electronic device encrypts the first file based on the credential.

[0028] In this way, the electronic device can encrypt the file before sending the file, thereby improving security.

[0029] In a possible implementation, the credential is obtained by the first electronic device on a server, or the credential is obtained by the first electronic device locally, or the credential is obtained by the first electronic device on the second electronic device.

[0030] In a possible implementation, the first electronic device is configured to set the first permission for the first file, and specifically includes: the first electronic device is configured to write field information of the first permission in the first file; or the first electronic device is configured to send a first message to a server, the first message including the field information of the first permission and identification information of the first file, and the first message being used to indicate that the server saves an association relationship between the field information of the first permission and the identification information of the first file.

[0031] In a possible implementation, the first permission comprises a read-only permission, or an editable permission, or a forwarding permission, and the editable permission comprises one or more of an edit permission, a save-as permission, a screenshot permission, a screen recording permission, a print permission, and a copy permission.

[0032] In the embodiments of the present application, the forwarding permission can or can not belong to the definition range of the first permission (i.e., the forwarding permission can be parallel to the first permission).

[0033] In a possible implementation, the first file comprises sensitive information.

[0034] In a possible implementation, the credential corresponding to the first user is associated with an identity corresponding to the first user, and the identity corresponding to the first user is manually input by the user, or is selected by the user from a contact list of the first electronic device, or is obtained by the first electronic device from the second electronic device.

[0035] In a possible implementation, the first electronic device sets the first permission for the first file, specifically comprising: the first electronic device displays first prompt information, the first prompt information being used to prompt whether the user agrees to set the first permission for the first file; and in the case where it is confirmed that the user agrees to set the first permission for the first file, the first electronic device sets the first permission for the first file.

[0036] The first prompt information can be, for example, the prompt information shown in FIG. 7B.

[0037] In a second aspect, the embodiments of the present application provide a data sharing method, applied to a second electronic device, comprising: receiving, by the second electronic device, a first file sent by a first electronic device, the first file being controlled by a first permission, the first permission being effective when a plurality of applications on the second electronic device perform operations within a first permission control range of the first file, and the plurality of applications comprising a first application; obtaining, by the second electronic device, a first operation on the first file in the first application; and in response to the first operation, if the second electronic device determines that the first operation is one or more operations authorized for the first file by a first user indicated by the first permission, the second electronic device responds to the first operation.

[0038] The first application can be a system application or a third-party application.

[0039] By implementing the method provided in the second aspect, the electronic device can provide data management functions, the recipient can receive and open the shared file through the electronic device, and the system can dynamically adjust the permissions of the application to access different functions of the system based on the permission control policy set in the file. For example, the recipient cannot perform secondary forwarding, copying, screen capturing, printing, and other operations on the file, and even if the attacker attacks the application that opens the file, the attacker cannot perform the above operations on the file. In this way, the scene support, security, ecological friendliness, and other aspects are improved, and the user experience is better.

[0040] In a possible implementation, before the second electronic device determines that the first operation is one or more operations that the first user with the first permission indication is authorized to perform on the first file, the method further includes: determining, by the second electronic device, that the user performing the first operation is the first user who is authenticated to have operation permissions on the first file.

[0041] That is, when the user associated with the account logged in by the recipient device is the recipient of the first file specified by the sender, the recipient device can further determine whether the first operation is one or more operations that the first user with the first permission indication is authorized to perform on the first file.

[0042] In a possible implementation, the second electronic device determines that the user performing the first operation is the first user who is authenticated to have operation permissions on the first file, and specifically includes: determining, by the second electronic device, that the account logged in by the second electronic device is the account of the first user; or, determining, by the second electronic device, that the biometric feature of the user performing the first operation matches the biometric feature of the first user; or, receiving, by the second electronic device, a first message sent by a third electronic device, the first message being used to indicate that the user performing the first operation is the first user who is authenticated to have operation permissions on the first file, and the third electronic device is associated with the second electronic device.

[0043] In this way, the electronic device can authenticate the identity of the recipient in different ways, which is convenient and flexible and improves the user experience.

[0044] In a possible implementation, the method further includes: in a case where the second electronic device determines that the first operation does not belong to one or more operations that the first user with the first permission indication is authorized to perform on the first file, displaying, by the second electronic device, first prompt information, the first prompt information being used to prompt the user that the second electronic device refuses to respond to the first operation.

[0045] The first prompt information may, for example, be the prompt information shown in FIG. 11G, FIG. 11H, or FIG. 11I.

[0046] In a possible implementation, the method further includes: in response to the operation of sharing the first file, the second electronic device sends the first file to a third electronic device associated with the first user.

[0047] In this way, the electronic device can support the user to forward the first file to other electronic devices associated with the user.

[0048] In a possible implementation, the method further includes: in response to the operation of sharing the first file, the second electronic device sends the first file to a fourth electronic device associated with the second user.

[0049] In this way, the electronic device can support the user to forward the first file to electronic devices associated with other users.

[0050] In a possible implementation, when the first file is forwarded by the second electronic device, the first file is set to a third permission, and an authorization range of the third permission is not more than an authorization range of the first permission.

[0051] That is, in the case of twice forwarding the file, the authorization range of the permission set for the file can be smaller than the authorization range of the permission in the first forwarding, for example, read-only permission can be set in the second forwarding. In this way, the security can be improved.

[0052] In a possible implementation, the method further includes: the second electronic device sends a second message to the first electronic device, the second message being used to instruct the first electronic device to authorize a second operation performed by the first user on the first file, the second operation not belonging to one or more operations performed by the first user on the first file and authorized by the first permission.

[0053] In this way, the receiving device can notify the sending device to re-authorize in the case of performing an operation on the file that is not authorized to be performed.

[0054] In a possible implementation, the method further includes: the second electronic device sends a third message to the first electronic device, the third message being used to instruct the first electronic device to authorize a forwarding operation performed by the first user on the first file.

[0055] In this way, the receiving device can notify the sending device to authorize the receiving device to perform the forwarding operation on the file when the receiving device performs the forwarding operation on the first file.

[0056] In a possible implementation, the first file is an encrypted file, and before the second electronic device responds to the first operation, the method further includes: the second electronic device obtains a credential corresponding to the first user; and the second electronic device decrypts the first file based on the credential.

[0057] In a possible implementation, the second electronic device displays a first identifier, and the first identifier is used to indicate that the first file is an encrypted file.

[0058] The first identifier may be, for example, the identifier of the document 1 shown in FIG. 11A (i.e., the icons of all encrypted files are the same encrypted icon), or may be, for example, the identifier of the document 1 shown in FIG. 11B (i.e., the encrypted icon is superimposed on the exclusive icon).

[0059] In a possible implementation, the first permission is obtained by the second electronic device in the first file, or the first permission is obtained by the second electronic device from the server.

[0060] In a possible implementation, the first permission includes a read-only permission, or an editable permission, or a forwarding permission, and the editable permission includes one or more of a save permission, a screenshot permission, a screen recording permission, a print permission, and a copy permission.

[0061] In a third aspect, an electronic device is provided, which includes one or more processors and one or more memories; the one or more memories are coupled to the one or more processors, and are configured to store computer program codes, the computer program codes include computer instructions, when the one or more processors execute the computer instructions, the electronic device is caused to perform the method in any possible implementation of the first aspect or the second aspect.

[0062] In a fourth aspect, a computer storage medium is provided, which stores a computer program, the computer program includes program instructions, when the program instructions are executed on an electronic device, the electronic device is caused to perform the method in any possible implementation of the first aspect or the second aspect.

[0063] In a fifth aspect, a computer program product is provided, when the computer program product is executed on a computer, the computer is caused to perform the method in any possible implementation of the first aspect or the second aspect. BRIEF DESCRIPTION OF DRAWINGS

[0064] FIG. 1 is a schematic diagram of a software structure according to an embodiment of the present application;

[0065] FIG. 2A is a schematic diagram of an architecture of a communication system according to an embodiment of the present application;

[0066] FIG. 2B is a schematic diagram of a software architecture of an electronic device 100 according to an embodiment of the present application;

[0067] FIG. 2C is a schematic diagram of a software architecture of an electronic device 200 according to an embodiment of the present application;

[0068] FIGS. 3A-3C are a set of schematic diagrams of user interfaces involved in a scenario of initiating data sharing by a system according to an embodiment of the present application;

[0069] FIGS. 4A-4C are another set of schematic diagrams of user interfaces involved in a scenario of initiating data sharing by a system according to an embodiment of the present application;

[0070] FIGS. 5A-5F are another set of schematic diagrams of user interfaces involved in a scenario of initiating data sharing by a system according to an embodiment of the present application;

[0071] FIGS. 6A-6C are a set of schematic diagrams of an electronic device 100 obtaining credentials of a receiving party according to an embodiment of the present application;

[0072] FIGS. 7A-7B are another set of schematic diagrams of user interfaces involved in a scenario of initiating data sharing by a system according to an embodiment of the present application;

[0073] FIGS. 8A-8J are another set of schematic diagrams of user interfaces involved in a scenario of initiating data sharing by a system according to an embodiment of the present application;

[0074] FIGS. 9A-9D are another set of schematic diagrams of user interfaces involved in a scenario of initiating data sharing by a system according to an embodiment of the present application;

[0075] FIGS. 10A-10D are a set of schematic diagrams of user interfaces involved in a scenario of initiating data sharing by a communication application according to an embodiment of the present application;

[0076] FIGS. 11A-11I are a set of schematic diagrams of user interfaces involved in a scenario of receiving and opening a shared file by a system according to an embodiment of the present application;

[0077] FIG. 12 is a schematic diagram of a flow of controlling a network, Bluetooth, etc. according to an embodiment of the present application;

[0078] FIG. 13 is a schematic diagram of a flow of controlling a print, copy, etc. according to an embodiment of the present application;

[0079] FIG. 14 is a schematic diagram of a flow of controlling a screen capture, etc. according to an embodiment of the present application;

[0080] FIGS. 15A-15B are a set of schematic diagrams of user interfaces involved in a scenario of receiving and opening a shared file by a communication application according to an embodiment of the present application;

[0081] FIG. 16 is a schematic diagram of a flow of a data sharing method according to an embodiment of the present application;

[0082] FIG. 17 is a flow diagram of another method for sharing data according to an embodiment of the present application;

[0083] FIG. 18 is a schematic diagram of an electronic device 100 according to an embodiment of the present application. DETAILED DESCRIPTION

[0084] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. In the description of the embodiments of the present application, unless otherwise specified, “ / ” means or, for example, A / B can mean A or B; “and / or” in the text only means a description of the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B, which means that there are three cases of A alone, A and B together, and B alone. In addition, in the description of the embodiments of the present application, “multiple” means two or more than two.

[0085] It should be understood that the terms “first”, “second” and the like in the specification and claims of the present application and the drawings are used to distinguish different objects, and are not used to describe a specific order. In addition, the terms “include” and “have” and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units is not limited to the listed steps or units, but can optionally include steps or units not listed or can optionally include other steps or units inherent to the process, method, product or device.

[0086] In the present application, the phrase “embodiment” means that the specific features, structures or characteristics described in conjunction with the embodiment can be included in at least one embodiment of the present application. The phrase appears at various places in the specification does not necessarily mean the same embodiment, nor is it an independent or alternative embodiment to other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described in the present application can be combined with other embodiments.

[0087] The term "user interface (UI)" in the embodiments of the present application is a medium interface for interaction and information exchange between an application or an operating system and a user, which realizes conversion between an internal form of information and a form acceptable by the user. The user interface is source code written in a specific computer language such as Java, extensible markup language (XML), and the like. The interface source code is parsed and rendered on an electronic device, and finally presented as content recognizable by the user. A commonly used form of the user interface is a graphic user interface (GUI), which refers to a user interface related to computer operation displayed in a graphical manner. It can be a visual interface element such as text, icons, buttons, menus, tabs, text boxes, dialog boxes, status bars, navigation bars, Widgets, and the like displayed in the display screen of the electronic device.

[0088] Currently, a controlled sharing function of a file can be implemented in some office document applications. Generally, a sending device can perform encryption processing on a file to be shared in the office document application, specify that a specific receiving device can decrypt the file, and set specific permissions (for example, read-only, editable, and the like) of the file. The receiving device can open the shared file in the office document application, the application can parse the file content, and the application can execute the permissions set for the file.

[0089] Exemplarily, referring to FIG. 1, the above-mentioned office document application can be one of a plurality of applications installed on an electronic device. The application can include a controlled sharing software development kit, which can include a credential management module and a policy analysis module. The credential management module can be used to acquire and save credentials of a user, and the policy analysis module can be used to analyze permission policies of a file.

[0090] The controlled sharing of a file by the above-mentioned office document application also has some problems. For example, in terms of scene support, only specific document encryption sharing scenarios are usually supported, which is relatively limited. For example, in terms of security (for example, credential management and permission management), when the application is Hooked, the credentials of the user can be leaked through the credential management module. In addition, the permissions set for the file are analyzed by the policy analysis module, and the permission control depends on the application deep customization interception. When the application is Hooked, the permission control point can be invalid. For example, in terms of ecological friendliness, the controlled sharing function is strongly dependent on the adaptation of various applications. The receiving device can only use one application to open the shared file (for example, the permission control method implemented in an application is not adapted to other applications, so only this application can open the file with the permission settings added), and the experience is poor.

[0091] Based on the above problems, the embodiment of the application provides a data sharing method. For a sender, the electronic device 100 (sender device) can provide a system-level file encryption management and control sharing function, and does not depend on the electronic device 100 necessarily installing an application. The sender can select a file (for example, a picture, a document, etc.) to be shared from the system through the electronic device 100, set a permission control policy, and send the file to a receiver device through one or more different sending modes. For a receiver, the electronic device 200 (receiver device) can provide a data management and control function. The receiver can receive and open the shared file through the electronic device 200. The system can dynamically adjust the permission of an application to access different functions of the system based on the permission control policy set in the file. For example, the receiver cannot perform operations such as secondary forwarding, copying, screen capturing, and printing on the file. Even if an attacker attacks the application that opens the file, the attacker cannot perform the above operations on the file. In this way, the scene support, security, and ecological friendliness are improved, and the user experience is better.

[0092] Next, a communication system provided by the embodiment of the application is introduced.

[0093] FIG. 2A exemplarily shows a communication system provided by the embodiment of the application.

[0094] Referring to FIG. 2A, the communication system can include an electronic device 100 (sender device), an electronic device 200 (receiver device), and a server 300.

[0095] The electronic device 100 and the electronic device 200 are both terminal devices, which can be various types, and the embodiment of the application does not limit this.

[0096] For example, the electronic device 100, that is, the sender device (or the sharing device), can be a mobile phone, a large screen, a tablet, a personal computer (PC), a car machine, a watch, a bracelet, a virtual reality device (VR) / augmented reality device (AR), and the like.

[0097] In the embodiment of the application, the electronic device 100 can provide a system-level file encryption management and control sharing function, and does not depend on the electronic device 100 necessarily installing an application. For details, reference can be made to related contents in subsequent embodiments.

[0098] For example, the electronic device 200, that is, the receiver device, can be a mobile phone, a large screen, a tablet, a PC, a car machine, a watch, a bracelet, a VR / AR, and the like.

[0099] In the embodiments of the present application, the electronic device 200 can provide a data management function. The system can dynamically adjust the permissions of the application to access different functions of the system based on the permission management strategy set in the shared file. For details, please refer to the related content in the subsequent embodiments.

[0100] The server 300 can be a traditional server or a cloud server, and the embodiments of the present application do not limit this.

[0101] In the embodiments of the present application, the server 300 can be used to store the mapping relationship table of the user's identity and credentials.

[0102] The electronic device 100 in the communication system can establish a wired connection, other wireless connection, such as Bluetooth communication connection, wireless local area network (WLAN) such as wireless fidelity point to point (Wi-Fi P2P) connection, near field communication (NFC) connection, infrared technology (IR) connection, remote connection (such as remote connection established through a server), etc., or can also be connected and communicated in combination with any of the above ways.

[0103] The electronic device 100 and the electronic device 200 in the communication system can be configured with different software operating systems (OS), including but not limited to , etc. Among them, Harmony system of Huawei. The electronic device 100 and the electronic device 200 can also be configured with the same software operating system, for example, can be configured with

[0104] It should be understood that FIG. 2A is only a schematic diagram of the architecture of the communication system, and should not be construed as a limitation of the present application. The number of electronic devices 100, electronic devices 200 and servers 300 included in the communication system is not limited in the embodiments of the present application.

[0105] The software architecture of the electronic device 100 provided in the embodiments of the present application will be introduced below.

[0106] FIG. 2B exemplarily shows the software architecture of the electronic device 100.

[0107] Referring to FIG. 2B, the electronic device 100 can include one or more applications (such as gallery / file management applications, etc.), a file permission management service module, a system sharing service module, and a Bluetooth / WIFI communication module.

[0108] The one or more applications can be system applications or third-party applications.

[0109] In some examples, the upper-layer application can not include a gallery / file management application, etc. For example, the upper-layer application can be an application capable of accessing, sharing, etc. a file in the gallery / file management application, etc.

[0110] In some other examples, the upper-layer application can also include a gallery / file management application, etc.

[0111] The gallery / file management application, etc. can be used to provide a file access entry, provide a file selector, receive a file selection event, provide a file path, display a file, etc.

[0112] The file permission management service module can be used to encrypt a file, generate a permission control policy of the file, etc.

[0113] The file permission management service module can include a file encryption module and a control policy generation module.

[0114] The file encryption module can be used to obtain a credential for a specified receiver identity, receive a permission control policy of a file, encrypt a content of the file and the permission control policy of the file using the credential, generate a file ciphertext with the permission control policy, etc.

[0115] The control policy generation module can be used to receive a permission control configuration operation of a file by a user, to generate a permission control policy of the file, etc.

[0116] The system sharing service module can be used to provide a system-level data sharing function.

[0117] The Bluetooth / WIFI communication module, etc. can be used to provide a communication function of the electronic device 100. For example, the electronic device 100 can send a file to be shared to the electronic device 200 through the Bluetooth / WIFI communication module, etc.

[0118] It can be understood that FIG. 2B is merely exemplary and should not impose any limitation on the software architecture of the electronic device 100 in the embodiments of the present application.

[0119] The software architecture of the electronic device 200 provided by the embodiments of the present application is introduced below.

[0120] FIG. 2C exemplarily shows the software architecture of the electronic device 200.

[0121] Referring to FIG. 2C, the electronic device 200 can include an upper-layer application (for example, an office document type application), a file management module, an application permission management service module, a file permission management service module, an application management module, a network / Bluetooth / storage, etc. service module, a screenshot / recording application, a print / copy, etc. service module, a window management service module.

[0122] The upper-layer application can be used to open a file (for example, a file shared by the electronic device 100). The upper-layer application can be a system application or a third-party application. For example, the upper-layer application can be an office document type application, or a gallery, file management, etc. application.

[0123] The file management module (for example, a file management application) can be used to provide a file path, determine a file attribute (for example, determine whether a file is a controlled sharing file), etc.

[0124] The application permission management service module can be used to provide a system common permission management capability, provide a permission management judgment capability when an application uses one or more functions, in the embodiments of the present application, can also be used to provide a dynamic permission setting capability when an application opens a file and a dynamic control capability when an application executes an operation, can also be used to receive a permission control policy configured by the application management module for a certain application identifier (for example, an application identifier 11), etc.

[0125] The file permission management service module can be used to decrypt a received file, perform operations such as parsing, configuring, storing, reading, etc. on a permission control policy of the file, etc.

[0126] The file permission management service module can include a file decryption module, a control policy parsing module, a control policy configuring module, a control policy storage module, and a control policy reading module.

[0127] The file decryption module can be used to obtain a credential for a receiver identity identifier, decrypt file ciphertext (for example, decrypt file content, decrypt a permission control policy of a file), etc.

[0128] The control policy parsing module can be used to parse a permission control policy of a decrypted file, generate a parsing result, etc.

[0129] The control policy configuring module can be used to provide a configuration capability of a parsing result, etc.

[0130] The control policy storage module can be used to provide a storage capability of a parsing result, etc.

[0131] The control policy reading module can be used to read a parsing result, provide a query capability of a parsing result, etc.

[0132] The application management module can be configured to start an application, configure permissions of the application, and the like.

[0133] The application management module can include an application starting module and an application permission configuration module.

[0134] The application starting module can be configured to start an application in an independent process based on a user-selected application result, assign an application identifier, and the like.

[0135] The application permission configuration module can be configured to determine whether a file is an encryption-controlled file, obtain a permission control policy for the file from a file permission management service module, and configure the permission control policy for the application identifier to the application permission management service module.

[0136] The network / Bluetooth / storage service module can be configured to determine whether to allow access based on a permission control policy when an application initiates access to the network / Bluetooth / storage service module, and the like. For example, when the current application is an application that does not open a controlled file (which can also be referred to as a normal application), the application can be controlled or passed through based on a conventional permission authorization record. For another example, when the current application is an application that opens a controlled file, the application can be controlled or passed through based on a dynamically configured permission control policy when the file is opened.

[0137] The screenshot / recording application can be configured to perform a screenshot operation or a recording operation on file content, and the like.

[0138] The print / copy service module can be configured to determine whether to allow access based on a permission control policy when an application initiates access to the print / copy service module. For example, when the current application is an application that does not open a controlled file, the application can be directly passed through when there is no special limitation in the system. For another example, when the current application is an application that opens a controlled file, the application can obtain a decision result of whether to allow passing through from the file permission management service module, and be controlled or passed through based on the decision result.

[0139] The window management service module can be configured to manage a window program. The window management service module can obtain a display screen size, and intercept a screen, and the like.

[0140] It can be understood that FIG. 2C is merely exemplary, and should not impose any limitation on the software architecture of the electronic device 200 in the embodiments of the present application.

[0141] The data sharing method provided in the embodiments of the present application will be described in detail below in combination with a series of exemplary user interfaces.

[0142] For a sender (or a sharer), in the embodiments of the present application, the electronic device 100 can support a user to initiate sharing through the system, and can also support the user to initiate sharing through a communication application.

[0143] For the receiver, in the embodiments of the present application, the electronic device 200 can support the user to receive and open the shared file through the system, and can also support the user to initiate sharing and open the shared file through the communication application.

[0144] Scenario one: initiating sharing through the system

[0145] Referring to FIG. 3A, the user interface 310 exemplarily shown in FIG. 3A can be a user interface for the user to select a file / folder in the system. The user interface 310 can include a file management list, one or more options (for example, a sharing option 311, a copy option, a move option, a delete option, a more option), wherein the file management list can include one or more files (for example, a document "appearance patent disclosure.txt", a picture "IMG_3392.jpg"), one or more folders (for example, folder 1), and the sharing option 311 can be used to directly share the selected file / folder.

[0146] In the embodiments of the present application, the electronic device 100 can support the user to select a file / folder in the system. The entry for selecting the file / folder can include but is not limited to an application entry that can display files, such as a gallery, file management, etc. The operation for selecting the file / folder can include but is not limited to a long press operation, a click operation, a drag operation, etc. The number of selected files / folders can be one or more.

[0147] Taking the electronic device 100 as a mobile phone for example, the electronic device 100 can support the user to select one or more files / folders through a long press operation. Exemplarily, continuing to refer to FIG. 3A, it can be seen that the document "appearance patent disclosure.txt" is in a selected state, that is, the user selects the document "appearance patent disclosure.txt" as the file to be shared.

[0148] It is easy to understand that if the electronic device 100 is a PC, one or more files / folders can be selected by using a mouse, a keyboard, and the like accessory devices.

[0149] Continuing to refer to FIG. 3A, the system of the electronic device 100 can display the sharing option 311 when it is perceived that the file / folder is in the selected state. The electronic device 100 can detect an operation (for example, a click operation) of the user on the sharing option 311. In response to the operation, the electronic device 100 can display the window 320 exemplarily shown in FIG. 3B.

[0150] Referring to FIG. 3B, the window 320 can include an encrypted sharing option 321.

[0151] It is easy to understand that the user can trigger the electronic device 100 to perform the data sharing method provided by the embodiments of the present application by operating (for example, clicking operation) the encrypted sharing option 321.

[0152] In some examples, referring to FIG. 3C, the system of the electronic device 100 can also directly display the encrypted sharing option 321 when it is perceived that the file / folder is in the selected state.

[0153] In other examples, if the electronic device 100 is a PC, the system of the electronic device 100 can also directly display the encrypted sharing option 321 when it is perceived that the file / folder is in the selected state, and can also support the user to display the encrypted sharing option 321 by clicking the right mouse button or other menu bar.

[0154] In the embodiments of the present application, after detecting that the user operates the encrypted sharing option 321, the electronic device 100 can perceive the login state of the local account. If the user has not logged in the account, the electronic device 100 can guide the user to log in the account by the interface display mode. If the user has logged in the account, the electronic device 100 can directly display the subsequent user interface for data sharing without displaying the user interface for guiding the user to log in the account.

[0155] For example, referring to FIG. 4A, when it is detected that the user has not logged in the account (for example, Huawei account), the electronic device 100 can display the window 410 shown in FIG. 4A, which can be used to support the user to log in the account by manually inputting the mobile phone number and SMS verification code.

[0156] In some examples, the electronic device 100 can also support the user to log in the account by using other ways, for example, the user can log in the account by using the fingerprint verification mode shown in FIG. 4B; for example, the user can log in the account by using the face verification mode shown in FIG. 4C; for example, the user can log in the account by using the account password login mode; for example, the user can log in the account by using the scan code login mode; and the like.

[0157] Optionally, if the user has been verified by the user account or the fingerprint / face biometric feature before the user performs the encrypted sharing operation, and it is considered that the identity is trusted, the user can also not be required to input the credential information after the user selects the encrypted sharing. Optionally, the user can also complete the cross-device authentication through other associated devices such as wearable devices, without the need to authenticate through the electronic device 100.

[0158] In the embodiments of the present application, after detecting that the user logs in the account, the electronic device 100 can display a user interface for guiding the user to select the identity of the receiver. The identity of the receiver can include, but is not limited to, a mobile phone number, an email address, an account ID, and the like of the receiver, which can be used to identify the identity of the user.

[0159] The way of selecting the identity of the receiver can include, but is not limited to, the following three ways:

[0160] Way 1: Manually inputting the identity of the receiver.

[0161] For example, referring to FIG. 5A, the electronic device 100 can display a window 510, which can include an input box 511. The electronic device 100 can support the user to input the mobile phone number of the receiver in the input box 511.

[0162] In some examples, after detecting that the user inputs the mobile phone number of the receiver, the electronic device 100 can identify whether the mobile phone number is bound to a Huawei account. If the mobile phone number is not bound to a Huawei account, the electronic device 100 can display a window 520 as shown in FIG. 5B, which can include a prompt information 521 (for example, “No Huawei account identified, please re-input”). The prompt information 521 can be used to prompt the user to re-input the mobile phone number bound to the Huawei account.

[0163] In the embodiments of the present application, the electronic device 100 can support the user to input the identity of one or more receivers.

[0164] Way 2: Selecting the identity of the receiver in the address book

[0165] Continuing to refer to FIG. 5A, the input box 511 can include an option 512, which can be used to trigger the electronic device 100 to display the related user interface of the address book, so as to support the user to select the identity of the receiver from the address book.

[0166] For example, the electronic device 100 can detect the operation (for example, a click operation) of the user on the option 512. In response to the operation, the electronic device 100 can display a window 530 as shown in FIG. 5C or a window 540 as shown in FIG. 5D. The window 530 or the window 540 can include a receiver list, which can include the information (for example, the name, the avatar, and the like) of one or more receivers. The user can select the identity of the receiver by operating (for example, a click operation) on the receiver list.

[0167] In the embodiments of the present application, the electronic device 100 can support the user to select the identity of one or more receivers. For example, referring to FIG. 5E, it can be seen that the user selects three receivers.

[0168] It should be noted that in the embodiments of the present application, the receiver can refer to a user or a group.

[0169] Method 3: Selecting the identity of the receiver in the near-field device

[0170] The electronic device 100 can discover the surrounding devices based on Bluetooth, WIFI or other near-field communication methods, and can display a device list 551 in a window 550 as shown in the example of FIG. 5F. The information displayed in the device list 551 can include, but is not limited to, one or more of the following: device name, user name, avatar. The electronic device 100 can support the user to select the user device (i.e., the receiver device) that needs to interact from the device list 551, and further, the electronic device 100 can obtain the identity of the receiver corresponding to the selected user device that needs to interact through the near-field communication method.

[0171] In the embodiments of the present application, after detecting that the user selects the identity of the receiver, the electronic device 100 can obtain the identity credential (public key or symmetric key) of the receiver based on the identity of the receiver selected by the user.

[0172] The method of obtaining the identity credential of the receiver can include, but is not limited to, the following three methods:

[0173] Method 1: Obtaining from the server

[0174] The server side (i.e., the cloud side) can store a mapping relationship table of the identity of the receiver and the credential (for example, the mapping relationship table shown in Table 1), the electronic device side (i.e., the terminal side) can upload the identity of the receiver to the server side, and the server side can determine the credential corresponding to the identity based on the mapping relationship table of the identity of the receiver and the credential, and then download the credential to the electronic device side.

[0175] For example, referring to FIG. 6A, the file permission management service module of the electronic device 100 can upload the identity 1 selected by the user to the file permission management service module of the server, and the file permission management service module of the server can determine that the credential corresponding to the identity 1 is the credential 1 based on the mapping relationship table of the identity of the receiver and the credential, and then download the credential 1 to the electronic device 100.

[0176] Table 1

[0177] Method 2: Obtaining locally

[0178] The electronic device side (i.e., the end side) can synchronize the mapping relationship table of the identity of the receiver and the credential on the server side (i.e., the cloud side) and store it locally, and obtain the identity credential of the receiver based on the identity selected by the user and the mapping relationship table of the identity of the receiver and the credential.

[0179] Exemplarily, referring to FIG. 6B, the file permission management service module of the server can issue the mapping relationship table of the identity of the receiver and the credential to the electronic device 100, and the file permission management service module of the electronic device 100 can store the mapping relationship table of the identity of the receiver and the credential, and further, the file permission management service module of the electronic device 100 can query the credential corresponding to the identity based on the identity selected by the user and the mapping relationship table of the identity of the receiver and the credential.

[0180] Method 3, obtaining in a near field device

[0181] The electronic device 100 (the sender device) can initiate a connection to the electronic device 200 through near field communication, and can obtain the identity of the receiver and the credential corresponding to the electronic device 200 (the receiver device) based on the connection.

[0182] Exemplarily, referring to FIG. 6C, the file permission management service module of the electronic device 100 can obtain the identity of the receiver and the credential corresponding to the electronic device 200 stored in the file permission management service module of the electronic device 200 based on the near field connection.

[0183] In the embodiment of the present application, after the electronic device 100 obtains the identity credential of the receiver, the electronic device 100 can protect the file selected by the user based on the credential. The method of permission protection can include but is not limited to the following three methods:

[0184] Method 1, only providing the "read-only" function of the file by default

[0185] The electronic device 100 can set the permission of the file selected by the user to "read-only" permission or the permission range pre-configured by the user by default, without the need for user confirmation. Exemplarily, referring to FIG. 7A, after the "read-only" permission is set, the electronic device 100 can display relevant prompt information (for example, "file encryption success") to prompt the user that the file selected by the user has been encrypted.

[0186] Method 2, prompting the user whether to confirm to add "read-only" permission, and waiting for the user to confirm to complete encryption

[0187] For example, referring to FIG. 7B, the electronic device 100 can display a window 710, which can be used to prompt the user to confirm whether to add the "read-only" permission to the selected file. After detecting that the user confirms to add the "read-only" permission to the selected file (for example, the user clicks the "Yes" option in the window 710), the electronic device 100 can add the "read-only" permission to the file selected by the user, and complete the encryption.

[0188] Mode 3, provide a permission setting panel to support the user to set the "read-only" permission and the "editable" permission independently, which can include but is not limited to the following two modes

[0189] Mode (1),

[0190] For example, referring to FIG. 8A, the electronic device 100 can display a window 810, which can include a "read-only" permission option 811 and an "editable" permission option 812. The "read-only" permission option 811 can be used to set the permission of the selected file to the "read-only" permission, and the "editable" permission option 812 can be used to set the permission of the selected file to the "editable" permission. The "editable" permission can include but is not limited to editing, saving, printing, transmitting, copying, screenshot, and screen recording.

[0191] In the embodiments of the present application, the same user cannot simultaneously configure the "read-only" permission and the "editable" permission for the file. For example, if the electronic device 100 detects that the user selects to set the permission of the file to the "read-only" permission (for example, the user clicks the "read-only" permission option 811), the electronic device 100 can disable all operations that can cause the file content to be leaked (for example, forwarding, copying, saving, screenshot, printing, etc.), and operations that can damage the integrity of the file content (for example, editing). In addition, the "editable" permission option 812 can also be automatically displayed in grayscale, and be in an unselectable state, without the need for the user to manually select.

[0192] Mode (2),

[0193] For example, referring to FIG. 8B, the electronic device 100 can display a window 820, which can include a "read-only" permission option 821 and one or more "editable" permission refinement configuration options (for example, a save option 822, a print option 823, a transmission option 824, and a copy option 825). The electronic device 100 can support the user to select the operation that the recipient device can perform on the file by performing an operation (for example, a click operation) on one or more "editable" permission refinement configuration options.

[0194] It is easy to understand that if there are multiple recipients, the permission of the file is uniformly set in the embodiments shown in FIG. 8A and FIG. 8B.

[0195] In some examples, if there are multiple recipients (e.g., multiple independent users, multiple group members in a group), the electronic device 100 can also set different permissions for the file for different recipients, i.e., both the "read-only" permission and the "editable" permission of the file can be set for specified users. In the case of independent multiple users as recipients, the electronic device 100 can set the permissions of the file for the independent multiple users respectively; in the case of a group as a recipient, the electronic device 100 can set the permissions of the file for multiple group members in the group respectively; in the case of a group as a recipient, the electronic device 100 can also set the permissions of the file for all group members of the group uniformly, in which case the group members can share the same credential, i.e., one group identifier corresponds to one credential, and the process of obtaining the credential can refer to the foregoing related content, which will not be described here.

[0196] Optionally, referring to FIG. 8C, the electronic device 100 can display a window 830, which can be used to prompt the user to input one or more recipient account information to specify the recipient of the encrypted file.

[0197] Exemplarily, referring to FIG. 8D, the electronic device can display a window 840, which can include an option 841 and an option 842, wherein the option 841 can be used to set the "read-only" permission of the file for the specified user, and the option 842 can be used to set the "editable" permission of the file for the specified user.

[0198] Exemplarily, referring to FIG. 8E, the electronic device can also display a window 850, which can include an option 851, an option 852, an option 853, an option 854, and an option 855, wherein the option 851 can be used to set the "read-only" permission of the file for the specified user, the option 852 can be used to set the save permission in the "editable" permission of the file for the specified user, the option 853 can be used to set the print permission in the "editable" permission of the file for the specified user, the option 854 can be used to set the transmission permission in the "editable" permission of the file for the specified user, and the option 855 can be used to set the copy permission in the "editable" permission of the file for the specified user.

[0199] For setting the specified user, taking the "read-only" permission of the specified user setting file as an example, the electronic device 100 can detect the operation (for example, the click operation) of the user on the option 841 shown in FIG. 8D or the option 851 shown in FIG. 8E, and in response to the operation, the electronic device 100 can display the window 860 shown in the example of FIG. 8F, in which the one or more recipients selected by the user can be displayed, and the electronic device 100 can support the user to select the one or more recipients for permission setting. For example, referring to FIG. 8G, it can be seen that the user Alice and the group family are in the selected state, that is, the user Alice and the group family are selected as the specified user of the "read-only" permission of the file, and the user Alice and the group family have the "read-only" permission of the file. It can be easily understood that the "editable" permission of the specified user setting file is similar to the "read-only" permission of the specified user setting file, and details are not described herein.

[0200] It can be easily understood that in the embodiment shown in FIG. 8G, for the group family, the permissions set for each group member of the group are the same. In some examples, the electronic device 100 can also support the user to set the corresponding permission for each group member in the group individually. Continuing to refer to FIG. 8F, also taking the "read-only" permission as an example, the electronic device 100 can detect the operation (for example, the click operation) of the user on the option 861, and in response to the operation, the electronic device 100 can display the window 870 shown in the example of FIG. 8H, which can include one or more group members (for example, group member 1, group member 2, group member 3, group member 4) in the group family, and the electronic device 100 can support the user to select one or more group members for permission setting. For example, referring to FIG. 8I, it can be seen that the group member 1 is in the selected state, that is, the group member 1 is selected as the specified user of the "read-only" permission of the file, and the group member 1 has the "read-only" permission of the file.

[0201] In the embodiment of the present application, for the case that the user has selected multiple files, the electronic device 100 can support the user to protect the permissions of the multiple files respectively, or can support the user to merge the multiple files into an independent file and then protect the permissions uniformly.

[0202] In some examples, the same type of file can be protected in the same way, so that the user can set the permissions for multiple files of the same type, simplifying user operations. For example, referring to FIG. 8J, the user has selected files that can be divided into two types (e.g., type 1 files and type 2 files). The user can trigger the electronic device 100 to protect the permissions of the files by clicking on the type 1 files or the type 2 files. The specific process can refer to the foregoing related content of the permission protection, which will not be repeated here.

[0203] Next, a possible specific implementation mechanism of the permission protection is introduced.

[0204] After detecting that the user selects the permission protection attribute (e.g., read-only, editable, etc.) of the file, the electronic device 100 can encapsulate the permission protection attribute configured by the user as a field description, as the permission definition of the file. Further, the electronic device 100 can encrypt the file content and the above permission definition based on the identity credential of the recipient. The encryption method can include but is not limited to the following two methods:

[0205] Method 1,

[0206] Insert the permission definition into the file content, and encrypt the entire result (i.e., the file content and the permission definition as a whole) after insertion. The ciphertext is the new file content.

[0207] Method 2,

[0208] Encrypt the permission definition and the file content respectively, and the ciphertext is the new file content. The ciphertext of the permission definition is written into the metadata of the file.

[0209] In some examples, the above permission definition can not follow the file associated therewith. For example, the electronic device 100 can upload the above permission definition and the ID of the file associated therewith to the server, and the server can save the mapping relationship table of the permission definition and the file ID. The recipient can obtain the permission definition corresponding to the file from the server after receiving the file.

[0210] For the encrypted file, the suffix of the file name can be changed or not changed.

[0211] In the case of changing the suffix of the file name, a special suffix name (e.g.,.a) can be set. For example, the original file can be file1.docx, and the encrypted file content and permission definition of the file can be file1.docx.a. It is easy to understand that the above suffix name.a is only an example and should not be construed as a limitation.

[0212] In the case of not changing the suffix of the file name, the original file can be file1.docx, and the encrypted file can still be file1.docx. The encrypted file content can include the file permission definition ciphertext and the file content ciphertext.

[0213] After the encryption is completed, an encryption result can be generated, and the encryption result can include an encrypted file and an index corresponding to the encrypted file. The index corresponding to the encrypted file can include, but is not limited to, a file path, a file address, a file handle, and the like, which can be used to obtain file information.

[0214] In the embodiments of the present application, after the encryption is completed, the electronic device 100 can display the window 910 shown in FIG. 9A, which can include prompt information 911 and an option 912. The prompt information 911 can be used to prompt the user that the file has been encrypted and completed, and the file can be stored to a specified path. The option 912 can be used to store the file to the specified path. After the user clicks the option 912, the electronic device 100 can display a storage path, and the user can manually select a new storage path to trigger the electronic device 100 to store the file with the set permission protection to the path.

[0215] In some examples, after the encryption is completed, the electronic device 100 can also store the file to a default path, for example, an XXX path, and can display the window 920 shown in FIG. 9B, which can include related prompt information to prompt the user that the file has been stored in the XXX path.

[0216] In the embodiments of the present application, after the file with the permission protection (i.e., the encrypted file) is stored, the electronic device 100 can support the user to perform a sharing operation on the file. The sharing operation can include, but is not limited to, the following two ways:

[0217] Way 1:

[0218] After the file with the permission protection is stored, the electronic device 100 can directly obtain the path or other types of indexes of the file in the local, and initiate sharing. The sharing way can include, but is not limited to, the following two ways:

[0219] Way (1), near-field sharing based on the system self-sharing service

[0220] For example, referring to FIG. 5F, the electronic device 100 can display a device list 551, support the user to select a device in the device list 551 as a receiver device, and thus can send the above-mentioned file with the permission protection to the receiver device, and complete the sharing.

[0221] Way (2), sharing through an application

[0222] For example, with reference to FIG. 5F, the electronic device 100 can display an application list 552, which can include one or more applications capable of file sharing, and the electronic device 100 can support the user selecting an application in the application list 552 to share the file to the receiving device.

[0223] It is to be understood that the above two sharing manners are merely exemplary, and the sharing manner of the file that has been permission-protected can be consistent with the sharing manner of the common file, and the embodiments of the present application do not limit this.

[0224] Manner 2:

[0225] After the file that has been permission-protected is stored, the electronic device 100 can support the user reselecting the file in the new storage path corresponding to the file to initiate sharing. It is to be understood that the method of selecting and sharing the file that has been permission-protected can be consistent with the method of selecting and sharing the common file, and the embodiments of the present application do not limit this.

[0226] For example, with reference to FIG. 9C, it can be seen that the document "Appearance Patent Disclosure Document.txt" displayed in the user interface 930 is a file that has been permission-protected after being saved, and is in a selected state. The user can click the sharing option in FIG. 9C to trigger the electronic device 100 to share the file.

[0227] In some examples, the electronic device 100 can display the window 940 shown in FIG. 9D when detecting that the file that has been permission-protected is in the selected state, and the window 940 can be used to display the authorized users of the file and the permissions of the authorized users (for example, the user A has the "read-only" permission, and the user B has the "editable" permission).

[0228] In some examples, with reference to FIG. 9D, the electronic device 100 can support the user adding a new authorized user to the file that has been permission-protected. For example, the user can click the "add new authorized user" option to trigger the electronic device 100 to perform the related steps of adding a new authorized user. The process of adding a new authorized user can refer to the foregoing related content of selecting a receiving party identity and performing permission protection, and will not be described herein.

[0229] From the above scenario one, it can be seen that by implementing the method provided in the embodiments of the present application, the encryption setting of the file can be initiated in the application, and the user can select the file in the system application entrance with the preview function such as file management and gallery, and the system triggers the file encryption sharing (for example, displays the encryption sharing option), and the electronic device can support the user to use the system function to configure who to send the file and what permissions (for example, “read-only” permission and “editable” permission) the file receiver has, and the upper application does not need to perceive the encryption of the file, the ecological friendliness is improved, and the user experience is better.

[0230] Scenario two: initiating sharing through a communication application

[0231] In the embodiments of the present application, the electronic device 100 can support the user to select the file in the communication tool (for example, a chat, a mail and the like) with the sending function to initiate the file sharing.

[0232] For example, referring to FIG. 10A, the user interface 1010 shown in FIG. 10A can be a chat interface provided by a chat application, which can be a chat interface between the user of the electronic device 100 and a user Lily. It is easy to understand that the user Lily can be a file receiver. The electronic device 100 can support the user to select an option for sending a picture, a document and the like, which can be in any form, and the embodiments of the present application do not limit it.

[0233] For example, for sending a picture, continue to refer to FIG. 10A, if the user wants to send a picture to Lily, the electronic device 100 can detect the operation of the user on the album option, and in response to the operation, the electronic device 100 can display the user interface 1020 shown in FIG. 10B, which can include a preview picture list 1021, and the preview picture list 1021 can include one or more pictures (for example, picture 1 and picture 2).

[0234] In the embodiments of the present application, the system can provide the file selection function for the application, and the system can display the encryption sharing option on the interface when it is perceived that the file is in the selected state. The option can be displayed at any position on the interface, and the embodiments of the present application do not limit it.

[0235] For example, continue to refer to FIG. 10B, the electronic device 100 can detect the operation of the user selecting one or more pictures (for example, the operation of clicking picture 1), and in response to the operation, the electronic device 100 can display the encryption sharing option 1022 shown in FIG. 10C.

[0236] It is easy to understand that the function of supporting the user to select one or more pictures can be a function in the application, and the function of displaying the encryption sharing option 1022 can be a function in the system.

[0237] In the embodiments of the present application, after detecting the operation (e.g., a click operation) of the user on the encrypted sharing option 1022, the electronic device 100 can start to perform the process of setting the permission, and the process of setting the permission can refer to the related content in the aforementioned scenario one (including the selection of the identity of the receiver, the related content of the permission protection), which will not be repeated here.

[0238] In some examples, on the basis that the current communication type application provides a user identity reading function, the electronic device 100 can obtain the identity of the receiver in the current interface, and further, can obtain the corresponding credential based on the identity, and protect the file selected by the user based on the credential, and the specific process can refer to the related content in the aforementioned scenario one, which will not be repeated here.

[0239] After completing the permission setting of the file, the electronic device 100 can support the user to send the file to the receiver device. Illustratively, continuing to refer to FIG. 10C, the electronic device 100 can detect the operation (e.g., a click operation) of the user on the sending option, and in response to the operation, the electronic device 100 can send the picture 1 with the set permission to the receiver device (e.g., the device of Lily).

[0240] In some examples, the system can perceive the selected state of the file, and in the case that the file is in the selected state, the system can scan the file after obtaining the authorization of the user, so as to obtain the information contained in the file, and in the case that the file contains personal information (e.g., portrait, ID number, bank card number, etc.), the electronic device 100 displays the encrypted sharing option. Illustratively, referring to FIG. 10B, assuming that the picture 1 does not contain personal information and the picture 2 contains personal information, if the user selects the picture 1 but not the picture 2, the electronic device 100 can not display the encrypted sharing option, and referring to FIG. 10D, if the user selects the picture 1 and then selects the picture 2, the electronic device 100 can display the encrypted sharing option. Alternatively, the control of encrypted sharing can also be located in the same level as the controls of the album, video call, etc., and when the user clicks the encrypted sharing control, the selection of the file and the encrypted sharing are triggered; wherein the path for selecting the file to be encrypted and shared can be a special path for encrypted sharing of the file, or a selection path commonly used for general files, and after the user selects the encrypted sharing, the encryption operation is completed in a user-unaware manner and the sharing is performed.

[0241] As can be seen from the above scenario two, by implementing the method provided in the embodiments of the present application, after selecting a file in an application (system application or third-party application), the system triggers file encryption sharing (for example, displays an encryption sharing option), and the electronic device can support the user using the system function to configure who to send the file to and what permissions (for example, "read-only" permission and "editable" permission) the file receiver has, and the upper application does not need to perceive the encryption of the file, which improves the ecological friendliness and provides a better user experience. In this way, the problem that if other applications want to control the permissions of the file, the application needs to be repeatedly implemented when initiating data encryption and permission setting in the upper application can be solved.

[0242] Scenario three: receiving and opening a shared file through the system

[0243] In the embodiments of the present application, the electronic device 200 can receive the encrypted file shared by the electronic device 100 through different receiving channels (for example, near-field sharing and communication application sharing).

[0244] Referring to FIG. 11A, the user interface 1110 exemplarily shown in FIG. 11A can be used for a user interface for a user to select a file / folder in the system. The user interface 1110 can include a file management list, and the file management list can include one or more files (for example, document 1, document 2, and document 3) and one or more folders. The user interface for the user to select a file / folder in the system can be provided by an application with a file display function, such as a file management application or a gallery application.

[0245] In some examples, the encrypted file can have an icon for identifying that it is an encrypted file, and the display mode of the icon can include but is not limited to the following two modes:

[0246] Mode 1:

[0247] The icons of encrypted files in all formats (for example, doc, jpg, and the like) are the same encrypted icon, for example, the icon of document 1 shown in FIG. 11A is a lock icon.

[0248] Mode 2:

[0249] Encrypted files in different formats display original format-specific icons, and an encrypted icon is superimposed on the specific icon, for example, the icon of the doc file of document 1 shown in FIG. 11B superimposes a lock icon.

[0250] In the embodiments of the present application, the operation of the user selecting a file / folder can include but is not limited to a long-press operation, a click operation, and the like, and the number of selected files / folders can be one or multiple.

[0251] Exemplarily, referring to FIG. 11B, the user can select the encrypted file of document 1 by a click operation.

[0252] In the embodiment of the present application, after detecting that the user selects the file, the system of the electronic device 200 can perceive that the file is in a selected state, and further, the system can analyze the type of the file and determine whether the file is a controlled encrypted sharing file (which can also be referred to as an encrypted file or a controlled file).

[0253] Exemplarily, in the case that the file has a suffix of a specific file name, the system can analyze whether the file is a controlled encrypted sharing file based on the suffix.

[0254] Exemplarily, in the case that the file does not have a suffix of a specific file name, the system can analyze the file content and determine the “controlled encrypted sharing file attribute” feature of the file. The analysis of the file content can include but is not limited to: analyzing the permission configuration field from the file content and analyzing the permission configuration field from the file metadata.

[0255] In the embodiment of the present application, after detecting that the user selects the file, the system of the electronic device 200 can determine the current login state of the account of the user. If the user has not logged in the account, the electronic device 200 can guide the user to log in the account by an interface display mode. Exemplarily, referring to FIG. 11C, the electronic device 200 can support the user to log in the account by manually inputting a mobile phone number and a short message verification code in the window 1120. However, the account can also be logged in by other manners (such as face verification, fingerprint verification, etc.).

[0256] In the embodiment of the present application, after detecting that the user logs in the account, the electronic device 200 can obtain the decryption credential associated with the account. The obtaining method can include but is not limited to the following two manners:

[0257] Manner 1: Obtaining from a server

[0258] The server can store a mapping relationship table of an identity (associated with the above-mentioned logged-in account) and a credential. The electronic device 200 can upload the identity of the user of the electronic device 200 (i.e., the user of the logged-in account) to the server. The server can determine the credential corresponding to the identity based on the mapping relationship table of the identity and the credential, and deliver the credential to the electronic device 200.

[0259] Manner 2: Obtaining locally

[0260] The electronic device 200 can synchronize the mapping relationship table of the identity and the credential with the server and store it locally. The credential can be obtained based on the mapping relationship table of the identity and the credential locally.

[0261] In the embodiments of the present application, if the logged-in user is consistent with the specified receiver of the controlled encrypted sharing file, the electronic device 200 can open the file, for example, display the user interface 1130 after opening the file as shown in FIG. 11D; if the logged-in user is not consistent with the specified receiver of the controlled encrypted sharing file, the electronic device 200 cannot open the file, and the electronic device 200 can display the window 1140 as shown in FIG. 11E, which can include relevant prompt information to prompt the user that the user has no permission to open the file.

[0262] In the embodiments of the present application, for the user who has the permission to open the controlled encrypted sharing file, the system of the electronic device 200 can determine which application to use to open the file.

[0263] In some examples, the electronic device 200 can use a default application to open the file without the user manually selecting which application to use to open the file. For example, after detecting that the user selects to open the file, the electronic device 200 can directly use the default application to open the file and display the file content, for example, as shown in FIG. 11D.

[0264] In other examples, the electronic device 200 can provide an application list display panel installed by the system to support the user to independently select which application to use to open the file. For example, referring to FIG. 11F, after detecting that the user selects to open the file, the electronic device 200 can display the window 1150, which can include an application list, and the application list can include one or more applications (for example, application 1, application 2, application 3, and application 4), and the user can manually select an application to trigger the electronic device 200 to launch the application and open the file in the application to display the file content. The one or more applications described above can be system applications or third-party applications installed by the user.

[0265] It is easy to understand that if the user-selected application itself does not have the opening capability of the original document type (for example, the user selects to use a picture editing application to open an encrypted.doc file), the electronic device 200 can display relevant prompt information to prompt the user that the application cannot open the file (for example, display error information “Cannot open.doc file”).

[0266] In the embodiments of the present application, if the controlled encryption sharing file is configured with "read-only" permission, the user can only read the file after opening the file, and cannot initiate other operations (such as printing, saving, screenshot, etc.) on the file. As a possible implementation, the user device can provide system-level interception, which can enhance data control without worrying about the capabilities and control range of third-party applications. The system-level interception can include but is not limited to the following three ways:

[0267] Way 1, the system displays prompt information (or error information), and the system intercepts the above operations (such as printing, saving, screenshot, etc.)

[0268] For example, in the case of detecting that the user performs a copy operation on the file, the electronic device 200 can display the window 1160 shown in FIG. 11G, which can include prompt information 1161, prompting the user that he can only read the file and cannot initiate a copy operation on the file.

[0269] For example, in the case of detecting that the user performs a save operation on the file, the electronic device 200 can display the window 1170 shown in FIG. 11H, which can include prompt information 1171, prompting the user that he can only read the file and cannot initiate a save operation on the file.

[0270] For example, in the case of detecting that the user performs a screenshot operation on the file, the electronic device 200 can display the window 1180 shown in FIG. 11I, which can include prompt information 1181, prompting the user that he can only read the file and cannot initiate a screenshot operation on the file.

[0271] Way 2, the system does not display prompt information (or error information), and the system only intercepts the above operations (such as printing, saving, screenshot, etc.) in the background

[0272] Way 3, the system does not display prompt information (or error information), the system intercepts the above operations (such as printing, saving, screenshot, etc.) in the background, and the system provides interception notification, which is realized by the application

[0273] It is easy to understand that when the user opens other files that are not protected by permission using the same application and performs the above copy, print, etc. operations, the electronic device 200 can not perform the interception operation.

[0274] For example, for different control functions, the following three different modes of functions can be divided, which can be referred to the content in Table 2 below.

[0275] Table 2

[0276] The following describes the control flow when the functions of the above three different modes are executed.

[0277] I. Network and Bluetooth control flow

[0278] FIG. 12 exemplarily shows a specific flow of controlling network, Bluetooth and the like according to an embodiment of the present application.

[0279] As shown in FIG. 12, the flow can be applied to the electronic device 200. The electronic device 200 can include a file management module, a controlled application (i.e., an application that opens a controlled file), an application management module, a file permission management service module, a network service module, a Bluetooth service module, and an application permission management service module. The following describes the specific steps in detail.

[0280] S1201, the file management module requests the application management module to open a controlled file and starts a controlled application.

[0281] S1202, the application management module instructs the file permission management service module to load the controlled file.

[0282] S1203, the file permission management service module decrypts the controlled file and the permission control policy, parses the application permission policy set by the controlled file, including disallowing access to network and Bluetooth.

[0283] S1204, the file permission management service module sends the decrypted controlled file path to the application management module.

[0284] S1205, the application management module allocates a controlled ID of the controlled application to the file permission management service module.

[0285] In some examples, the controlled ID can be an application identifier 11.

[0286] S1206, the application management module sends the set permission control policy, including disallowing access to network and Bluetooth, to the application permission management service module.

[0287] It is easy to understand that the application management module can obtain the permission control policy of the controlled file under the path after receiving the decrypted controlled file path sent by the file permission management service module.

[0288] S1207, the application permission management service module records that the controlled application is disallowed to access network and Bluetooth.

[0289] S1208, the application management module starts the controlled application and allocates the controlled ID.

[0290] In some examples, the application management module can start the controlled application in the manner of an independent process.

[0291] S1209, the controlled application requests networking from the network service module.

[0292] S1210, the network service module requests the permission control policy of the controlled application from the application permission management service module.

[0293] S1211, the application permission management service module sends the permission control policy of the controlled application to the network service module, including that the controlled application is not allowed to access the network.

[0294] S1212, the network service module rejects the controlled application to access the network.

[0295] Specifically, after receiving the permission control policy of the controlled application sent by the application permission management service module, the network service module can reject the controlled application to access the network in the case that it is determined that the controlled application is not allowed to access the network based on the permission control policy.

[0296] In some examples, the above steps S1209-S1212 are optional.

[0297] S1213, the controlled application requests Bluetooth connection from the Bluetooth service module.

[0298] S1214, the Bluetooth service module requests the permission control policy of the controlled application from the application permission management service module.

[0299] S1215, the application permission management service module sends the permission control policy of the controlled application to the Bluetooth service module, including that the controlled application is not allowed to access Bluetooth.

[0300] S1216, the Bluetooth service module rejects the controlled application to access Bluetooth.

[0301] Specifically, after receiving the permission control policy of the controlled application sent by the application permission management service module, the Bluetooth service module can reject the controlled application to access Bluetooth in the case that it is determined that the controlled application is not allowed to access Bluetooth based on the permission control policy.

[0302] In some examples, the above steps S1213-S1216 are optional.

[0303] It should be noted that the execution time sequence of the steps S1209-S1212 and the steps S1213-S1216 is not limited in the embodiments of the present application. For example, the steps S1209-S1212 can be executed before the steps S1213-S1216; for another example, the steps S1209-S1212 can be executed after the steps S1213-S1216.

[0304] It is easy to understand that the storage control procedure of the controlled file is similar to the network and Bluetooth control procedures, and the application is not allowed to access the file storage, and the specific procedure can refer to the related content of the network and Bluetooth control procedures, which will not be described here.

[0305] II. Print and copy control procedure

[0306] FIG. 13 exemplarily shows a specific procedure for controlling the print and copy functions provided by the embodiments of the present application.

[0307] As shown in FIG. 13, the procedure can be applied to the electronic device 200. The electronic device 200 can include a file management module, a controlled application (i.e., an application that opens a controlled file), an application management module, a file permission management service module, a print service module, and a clipboard service module. The specific steps are described in detail as follows:

[0308] S1301, the file management module requests the application management module to open a controlled file and starts a controlled application.

[0309] S1302, the application management module instructs the file permission management service module to load the controlled file.

[0310] S1303, the file permission management service module decrypts the controlled file and the permission control policy, parses the application permission policy set by the controlled file, including not allowing printing and copying.

[0311] S1304, the file permission management service module sends the decrypted controlled file path to the application management module.

[0312] S1305, the application management module allocates a controlled ID of the controlled application to the file permission management service module.

[0313] In some examples, the controlled ID can be the application identifier 11.

[0314] S1306, the file permission management service module records that the controlled application is not allowed to print and copy.

[0315] S1307, the application management module starts the controlled application and allocates the controlled ID.

[0316] In some examples, the application management module can start the controlled application in the manner of an independent process.

[0317] S1308, the controlled application requests printing to the print service module.

[0318] S1309, the print service module requests the permission control policy of the controlled application from the file permission management service module.

[0319] S1310, the file permission management service module sends the permission control policy of the controlled application to the print service module, including that the controlled application is not allowed to print.

[0320] S1311, the print service module rejects the controlled application to print.

[0321] Specifically, after receiving the permission control policy of the controlled application sent by the file permission management service module, in the case that it is determined that the controlled application is not allowed to perform the printing operation based on the permission control policy, the print service module can reject the controlled application to print the controlled file.

[0322] In some examples, the above steps S1308-S1311 are optional.

[0323] S1312, the controlled application requests copying to the clipboard service module.

[0324] S1313, the clipboard service module requests the permission control policy of the controlled application from the file permission management service module.

[0325] S1314, the file permission management service module sends the permission control policy of the controlled application to the clipboard service module, including that the controlled application is not allowed to copy.

[0326] S1315, the clipboard service module rejects the controlled application to copy.

[0327] Specifically, after receiving the permission control policy of the controlled application sent by the file permission management service module, in the case that it is determined that the controlled application is not allowed to perform the copying operation based on the permission control policy, the clipboard service module can reject the controlled application to copy the controlled file.

[0328] In some examples, the above steps S1312-S1315 are optional.

[0329] It should be noted that the execution time sequence of the steps S1308-S1311 and the steps S1312-S1315 is not limited in the embodiments of the present application. For example, the steps S1308-S1311 can be executed before the steps S1312-S1315; for another example, the steps S1308-S1311 can be executed after the steps S1312-S1315.

[0330] III. Screenshot control flow

[0331] FIG. 14 exemplarily shows a specific flow of controlling a screenshot function and the like according to an embodiment of the present application.

[0332] As shown in FIG. 14, the flow can be applied to the electronic device 200. The electronic device 200 can include a file management module, a screenshot application, a controlled application (i.e., an application that opens a controlled file), an application management module, a file permission management service module, and a window management service module. The specific steps are described in detail as follows.

[0333] S1401, the file management module requests the application management module to open a controlled file and starts a controlled application.

[0334] S1402, the application management module requests the file permission management service module for a screenshot permission control policy associated with the controlled application.

[0335] It should be understood that before the step S1402 is executed, the application management module can instruct the file permission management service module to load the controlled file and obtain the permission control policy of the controlled file.

[0336] S1403, the file permission management service module determines that the controlled application is not allowed to take a screenshot.

[0337] It should be understood that the file permission management service module can determine whether the controlled application is allowed to perform a screenshot operation on the controlled file based on the obtained permission control policy of the controlled file.

[0338] S1404, the file permission management service module sends the application management module a screenshot permission control policy, including that the controlled application is not allowed to take a screenshot.

[0339] S1405, the application management module sends the window management service module a set SecurityFlag of the controlled application.

[0340] It should be understood that in the case that the controlled application is not allowed to perform a screenshot operation on the controlled file, the application management module can set the SecurityFlag of the controlled application.

[0341] S1406, the application management module starts the controlled application and assigns a controlled ID.

[0342] S1407, the window management service module records the SecurityFlag of the controlled application.

[0343] S1408, the screenshot application detects that the user initiates a screenshot.

[0344] S1409, the screenshot application requests the window management service module for a screenshot.

[0345] S1410, the window management service module determines that there is a record of the SecurityFlag of the controlled application.

[0346] S1411, the window management service module denies the screenshot application to perform a screenshot operation on the content of the controlled file displayed in the controlled application.

[0347] Specifically, in the case where the window management service module determines that there is a record of the SecurityFlag of the controlled application, the window management service module can deny the screenshot application to perform a screenshot operation on the content of the controlled file displayed in the controlled application.

[0348] It is easy to understand that the screen recording control process for the controlled file is similar to the aforementioned network and Bluetooth control processes, and the specific process can refer to the related content of the aforementioned screenshot control process, which will not be described here.

[0349] Scenario four: receiving and opening the shared file through a communication application

[0350] The electronic device 200 can support the user to receive the encrypted file shared by the electronic device 100 through a communication application (such as a chat, email, etc. Application).

[0351] For example, referring to FIG. 15A, the user interface 1510 shown in FIG. 15A can be a chat interface provided by a chat application, which can be a chat interface between the user of the electronic device 200 and the user Ann. As can be seen, the document XXX.doc is an encrypted file, and the sender of the file is Ann. The user can perform a click operation on the encrypted file to trigger the electronic device 200 to open the file.

[0352] In the embodiments of the present application, after detecting that the user clicks the encrypted file, the electronic device 200 can determine whether the user has logged in the account specified by the receiver range of the file. If the user has not logged in the account specified by the receiver range of the file, the electronic device 200 can prompt the user to log in the account, for example, the electronic device 200 can display the window shown in FIG. 11C to prompt the user to log in the account. If the user has logged in the account specified by the receiver range of the file, the electronic device 200 can determine which application to use to open the file. Similar to the third scenario described above, the electronic device 200 can use the default application to open the file, or can provide an application list panel installed by the system to support the user to select which application to use to open the file. In some examples, if the communication application itself has a file browsing function, the electronic device 200 can directly open the file in the application.

[0353] It should be noted that the account specified by the receiver range of the encrypted file can be different from or the same as the account system used in the communication application. In some examples, if the account defined in the encrypted file is a specified account of the account system 2 (for example, a Huawei account), when the user uses an account of the account system 1 (for example, a chat account used by a chat application), the electronic device 200 can prompt the user to log in the account of the account system 2 when the user wants to open the file. In other examples, if the account of the account system 1 (for example, a chat account used by a chat application) is associated with the specified account of the account system 2 (for example, a Huawei account), when the user wants to open the file, the electronic device 200 can directly obtain the account association information of the user logged in, so as to further obtain the specified account of the account system 2. In this way, the electronic device 200 does not need to prompt the user to log in the account of the account system 2.

[0354] In some examples, referring to FIG. 15A, after detecting that the user clicks the encrypted file, the electronic device 200 can automatically store the encrypted file locally. The subsequent way of opening the file can refer to the description of the first opening of the file in the foregoing related content, which will not be described here again. Alternatively, after the first opening of the file, subsequent openings comply with the relevant business rules, for example, the file can be directly opened again within a preset time, and authentication is required again if the preset time is exceeded.

[0355] In other examples, referring to FIG. 15B, the electronic device 200 can display a receiving option 1511 and a saving option 1512 in a user interface 1510. The receiving option 1511 can be used to receive the file and store the file in a default path of the local device. The saving option 1512 can be used to receive the file and store the file in a user-specified path of the local device. The subsequent way of opening the file can refer to the foregoing related content, which will not be described here again.

[0356] Similar to the third preceding scenario, if the encrypted file is configured with "read-only" permission, the user can only read the file after opening the file, and cannot initiate other operations (such as printing, saving, screenshot, etc.) on the file.

[0357] In the embodiments of the present application, the manner in which the electronic device 100 (i.e., the sender device) encrypts the file and the electronic device 200 (i.e., the receiver device) decrypts the file can include, but is not limited to, the four manners in Table 3 below:

[0358] Table 3

[0359] In the embodiments of the present application, it can also be limited which devices of the receiver can open the file shared by the sender. The specific strategies can include, but are not limited to, the following three:

[0360] Strategy 1:

[0361] As long as the device is logged in to the account specified in the receiver range, the device can open the file. For example, after the receiver receives the file on the electronic device 200, the receiver can forward the file to other devices of the receiver, and open the file on the other devices.

[0362] Strategy 2:

[0363] Only one device of the receiver (which is logged in to the account specified in the receiver range) is allowed to open the file; or, in the case where the number of devices of the receiver is less than a certain preset threshold, the receiver is allowed to open the file on multiple devices (which are all logged in to the same account specified in the receiver range).

[0364] Strategy 3:

[0365] The device is logged in to the account specified in the receiver range, and the device can only open the file when the device meets the corresponding security conditions (such as setting a lock screen, the device having a trusted execution environment, the device not being rooted, etc.).

[0366] In the embodiments of the present application, in the case where the sender of the file grants the receiver "editable" permission of the file, it can also be limited whether the receiver can perform a forwarding operation on the file. The specific strategies can include, but are not limited to, the following four:

[0367] Strategy 1:

[0368] The receiver device can use the manner of the first preceding scenario or the second preceding scenario to share the file with one or more users after receiving and storing the file locally, or directly forward the file.

[0369] Strategy 2:

[0370] The receiving device can only view or edit the file, and cannot share the file to one or more users in the manner of scenario one or scenario two.

[0371] Strategy 3:

[0372] The receiving device can view or edit the file, and can also forward it, but the receiving device after forwarding only has "read-only" permission for the file, and if it wants to obtain "editable" permission, it needs to contact the sender to make relevant settings.

[0373] Strategy 4:

[0374] The receiving device can view or edit the file, and can also forward it, but before forwarding, the sender needs to be notified to reinitiate authorization, and after authorization, the receiving device can forward the file.

[0375] FIG. 16 illustrates a specific flow of a data sharing method provided by an embodiment of the application.

[0376] As shown in FIG. 16, the method can be applied to a first electronic device. The specific steps of the method are described in detail as follows:

[0377] S1601, the first electronic device determines that a first file is selected.

[0378] S1602, in response to an operation of sharing the first file on a first interface, the first electronic device sends the first file to a second electronic device associated with a first user; wherein the first electronic device is configured to set a first permission for the first file, the first permission is effective for a plurality of applications on the first electronic device when the first file is sent, and the first permission is used to indicate one or more operations authorized for the first user to perform on the first file.

[0379] The first electronic device is a sender device (for example, the electronic device 100), the second electronic device is a receiving device (for example, the electronic device 200), and the first file is a file to be shared, which can include but is not limited to pictures, documents, audio and video.

[0380] In a possible implementation, the method further includes: before the first electronic device sends the first file to the second electronic device associated with the first user, the first electronic device displays at least one of a device list, an application list, or a user list on an interface, the interface being the first interface or the second interface; and the first electronic device sends the first file to the second electronic device associated with the first user, specifically including: in response to an operation of selecting the second electronic device in the device list, the first electronic device sends the first file to the second electronic device associated with the first user; or, in response to an operation of selecting the first application in the application list, the first electronic device sends the first file to the second electronic device associated with the first user through the first application; or, in response to an operation of selecting the first user in the user list, the first electronic device sends the first file to the second electronic device associated with the first user.

[0381] In a possible implementation, the first electronic device sends the first file to the second electronic device associated with the first user, specifically including: in response to an operation of sharing the first file triggered on an interface, the first electronic device sends the first file to the second electronic device associated with the first user, the interface being an interface for a session with the first user (for example, the interface shown in FIG. 10A).

[0382] In a possible implementation, the first file is set with the first permission before the operation of sharing the first file; or the first file is set with the first permission after the operation of sharing the first file and is sent to the second electronic device associated with the first user.

[0383] In a possible implementation, the method further includes: in response to an operation of sharing the first file on the first interface, the first electronic device sends the first file to a third electronic device associated with a second user; and the first electronic device is configured to set a second permission for the first file, the second permission being effective for the first file when sent by multiple applications on the first electronic device, the second permission being used to indicate one or more operations authorized to be performed on the first file by the second user.

[0384] In a possible implementation, the method further includes: the first electronic device determines that a second file is selected; in response to an operation of sharing the second file on the first interface, the first electronic device sends the second file to the second electronic device associated with the first user; and the first electronic device is configured to set a third permission for the second file, the third permission being effective for the second file when sent by multiple applications on the first electronic device, the third permission being used to indicate one or more operations authorized to be performed on the second file by the first user.

[0385] In a possible implementation, the first user belongs to a first group, and the first group further includes a third user. The method further includes: in response to the operation of sharing the first file on the first interface, the first electronic device sends the first file to a fourth electronic device associated with the third user, and the first permission is further used to indicate that the third user is authorized to perform one or more operations on the first file; or, in response to the operation of sharing the first file on the first interface, the first electronic device sends the first file to the fourth electronic device associated with the third user; and the first electronic device is further configured to set a fourth permission for the first file, the fourth permission is effective for all applications on the first electronic device when the first file is sent, and the fourth permission is used to indicate that the third user is authorized to perform one or more operations on the first file.

[0386] In a possible implementation, before the first electronic device sends the first file to the second electronic device associated with the first user, the method further includes: the first electronic device logs in a first account, and the first account belongs to an account of a fourth user.

[0387] In a possible implementation, before the first electronic device sends the first file to the second electronic device associated with the first user, the method further includes: the first electronic device obtains a credential corresponding to the first user; and the first electronic device encrypts the first file based on the credential.

[0388] In a possible implementation, the credential is obtained by the first electronic device on a server, or the credential is obtained by the first electronic device locally, or the credential is obtained by the first electronic device on the second electronic device.

[0389] In a possible implementation, the first electronic device is configured to set the first permission for the first file, and specifically includes: the first electronic device is configured to write field information of the first permission into the first file; or, the first electronic device is configured to send a first message to a server, and the first message includes the field information of the first permission and identification information of the first file, and the first message is used to indicate that the server saves an association relationship between the field information of the first permission and the identification information of the first file.

[0390] In a possible implementation, the first permission includes a read-only permission, an editable permission, or a forwarding permission, and the editable permission includes one or more of a save permission, a screenshot permission, a screen recording permission, a print permission, and a copy permission.

[0391] In the embodiment of the application, the forwarding permission can be within the definition range of the first permission, or can be outside the definition range of the first permission (i.e., the forwarding permission and the first permission can be parallel).

[0392] In a possible implementation, the first file includes sensitive information (for example, a portrait, an ID number, a bank card number, and the like).

[0393] FIG. 17 exemplarily shows a specific flow of another data sharing method provided by the embodiment of the application.

[0394] As shown in FIG. 17, the method can be applied to the second electronic device. The specific steps of the method are described in detail as follows.

[0395] S1701, the second electronic device receives a first file sent by a first electronic device, the first file is controlled by a first permission, the first permission takes effect when a plurality of applications on the second electronic device perform an operation (for example, an opening operation) within a first permission control range of the first file, and the plurality of applications include a first application.

[0396] S1702, the second electronic device obtains a first operation on the first file in the first application.

[0397] S1703, in response to the first operation, if the second electronic device determines that the first operation is one or more operations that a first user indicated by the first permission is authorized to perform on the first file, the second electronic device responds to the first operation.

[0398] The second electronic device is a receiver device (for example, the electronic device 200), the first electronic device is a sender device (for example, the electronic device 100), the first file is a shared file, which can include but is not limited to a picture, a document, an audio, and a video. The first operation can include but is not limited to viewing, saving, screen capturing, screen recording, printing, copying, and forwarding.

[0399] In a possible implementation, before the second electronic device determines that the first operation is one or more operations that the first user indicated by the first permission is authorized to perform on the first file, the method further includes: the second electronic device determines that a user performing the first operation is the first user who is authenticated to have an operation permission on the first file.

[0400] In a possible implementation, the second electronic device determines that the user performing the first operation is the first user who is authenticated to have the operation permission on the first file, specifically including: the second electronic device determines that an account logged in the second electronic device is an account of the first user; or, the second electronic device determines that a biological feature of the user performing the first operation is consistent with a biological feature of the first user; or, the second electronic device receives a first message sent by a third electronic device, the first message is used to indicate that the user performing the first operation is the first user who is authenticated to have the operation permission on the first file, and the third electronic device is associated with the second electronic device.

[0401] In a possible implementation, the method further includes: in a case where the second electronic device determines that the first operation does not belong to one or more operations that the first user is authorized to perform on the first file as indicated by the first permission, the second electronic device displays first prompt information, the first prompt information being used to prompt the user that the second electronic device rejects the response to the first operation.

[0402] In a possible implementation, the method further includes: in response to the operation of sharing the first file, the second electronic device sends the first file to a third electronic device associated with the first user.

[0403] In a possible implementation, the method further includes: in response to the operation of sharing the first file, the second electronic device sends the first file to a fourth electronic device associated with the second user.

[0404] In a possible implementation, when the first file is forwarded by the second electronic device, the first file is set to a third permission, an authorization range of the third permission does not exceed an authorization range of the first permission.

[0405] In a possible implementation, the method further includes: the second electronic device sends a second message to the first electronic device, the second message being used to instruct the first electronic device to authorize a second operation performed by the first user on the first file, the second operation not belonging to one or more operations that the first user is authorized to perform on the first file as indicated by the first permission.

[0406] In a possible implementation, the method further includes: the second electronic device sends a third message to the first electronic device, the third message being used to instruct the first electronic device to authorize a forwarding operation performed by the first user on the first file.

[0407] In a possible implementation, the first file is an encrypted file, and before the second electronic device responds to the first operation, the method further includes: the second electronic device obtains a credential corresponding to the first user; and the second electronic device decrypts the first file based on the credential.

[0408] In a possible implementation, the second electronic device displays a first identifier, the first identifier being used to indicate that the first file is an encrypted file.

[0409] In a possible implementation, the first permission is obtained by the second electronic device in the first file, or the first permission is obtained by the second electronic device from a server.

[0410] In a possible implementation, the first permission includes a read-only permission, or an editable permission, or a forwarding permission, the editable permission including one or more of a save-as permission, a screenshot permission, a screen recording permission, a print permission, and a copy permission.

[0411] The following introduces a structural schematic diagram of an electronic device 100 provided in an embodiment of the present application.

[0412] FIG. 18 exemplarily shows a structure of an electronic device 100 provided in an embodiment of the present application.

[0413] As shown in FIG. 18, the electronic device 100 can include a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a loudspeaker 170A, a receiver 170B, a microphone 170C, a headset interface 170D, a sensor module 180, a key 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and a subscriber identification module (SIM) card interface 195, etc. The sensor module 180 can include a pressure sensor 180A, a gyroscope sensor 180B, a barometric pressure sensor 180C, a magnetic sensor 180D, an acceleration sensor 180E, a distance sensor 180F, a proximity light sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, etc.

[0414] It can be understood that the structure illustrated in the embodiments of the present application does not constitute a specific limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 can include more or fewer components than illustrated, or combine certain components, or split certain components, or different arrangement of components. The illustrated components can be implemented in hardware, software, or a combination of software and hardware.

[0415] The processor 110 can include one or more processing units, for example: the processor 110 can include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Different processing units can be independent devices, or can be integrated in one or more processors.

[0416] The controller can be the nerve center and command center of the electronic device 100. The controller can generate operation control signals according to instruction operation codes and timing signals, and complete the control of instruction fetching and instruction execution.

[0417] The processor 110 can also be provided with a memory for storing instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. The memory can store instructions or data that have just been used or recycled by the processor 110. If the processor 110 needs to use the instructions or data again, it can be directly called from the memory. This avoids repeated access and reduces the waiting time of the processor 110, thereby improving the efficiency of the system.

[0418] In some embodiments, the processor 110 can include one or more interfaces. The interfaces can include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface, etc.

[0419] The I2C interface is a bidirectional synchronous serial bus, including a serial data line (SDA) and a serial clock line (SCL). In some embodiments, the processor 110 can contain multiple sets of I2C buses. The processor 110 can be coupled to the touch sensor 180K, the charger, the flash, the camera 193, etc. through different I2C bus interfaces, respectively. For example: the processor 110 can be coupled to the touch sensor 180K through the I2C interface, so that the processor 110 and the touch sensor 180K communicate through the I2C bus interface, realizing the touch function of the electronic device 100.

[0420] The USB interface 130 is an interface conforming to the USB standard specification, and can be a Mini USB interface, a Micro USB interface, a USB Type C interface, etc. The USB interface 130 can be used to connect a charger to charge the electronic device 100, and can also be used to transmit data between the electronic device 100 and a peripheral device. It can also be used to connect a headset to play audio through the headset. The interface can also be used to connect other terminal devices, such as an AR device, etc.

[0421] It can be understood that the interface connection relationship between the modules shown in the embodiments of the present application is only illustrative and does not constitute a structural limitation of the electronic device 100. In some other embodiments of the present application, the electronic device 100 can also use different interface connection modes or combinations of multiple interface connection modes in the above embodiments.

[0422] The wireless communication function of the electronic device 100 can be realized by the antenna 1, the antenna 2, the mobile communication module 150, the wireless communication module 160, the modem processor, and the baseband processor, etc.

[0423] The antenna 1 and the antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in the electronic device 100 can be used to cover a single or multiple communication frequency bands. Different antennas can also be multiplexed to improve the utilization rate of the antennas. For example, the antenna 1 can be multiplexed as a diversity antenna of a wireless local area network. In some other embodiments, the antenna can be used in combination with a tuning switch.

[0424] The mobile communication module 150 can provide a solution including 2G / 3G / 4G / 5G wireless communication applied to the electronic device 100. The mobile communication module 150 can include at least one filter, a switch, a power amplifier, a low noise amplifier (LNA), etc. The mobile communication module 150 can receive electromagnetic waves from the antenna 1, and perform filtering, amplification, etc. on the received electromagnetic waves, and transmit the processed electromagnetic waves to the modem processor for demodulation. The mobile communication module 150 can also amplify the signals modulated by the modem processor, and convert the signals into electromagnetic waves to be radiated through the antenna 1. In some embodiments, at least part of the functional modules of the mobile communication module 150 can be arranged in the processor 110. In some embodiments, at least part of the functional modules of the mobile communication module 150 and at least part of the modules of the processor 110 can be arranged in the same device.

[0425] The modem processor can include a modulator and a demodulator. The modulator is configured to modulate a low-frequency baseband signal to be transmitted into a medium-high frequency signal. The demodulator is configured to demodulate a received electromagnetic wave signal into a low-frequency baseband signal. The demodulator then transmits the demodulated low-frequency baseband signal to the baseband processor for processing. The low-frequency baseband signal processed by the baseband processor is transmitted to the application processor. The application processor outputs a sound signal through an audio device (not limited to a speaker 170A, a microphone 170B, etc.), or displays an image or a video through the display 194. In some embodiments, the modem processor can be a separate device. In other embodiments, the modem processor can be independent of the processor 110 and disposed in the same device as the mobile communication module 150 or other functional modules.

[0426] The wireless communication module 160 can provide a wireless communication solution including a wireless local area network (WLAN) (such as a wireless fidelity (Wi-Fi) network), Bluetooth (BT), a global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared (IR) technology, and the like, which are applied to the electronic device 100. The wireless communication module 160 can be one or more devices that integrate at least one communication processing module. The wireless communication module 160 receives an electromagnetic wave via the antenna 2, performs frequency modulation and filtering processing on the electromagnetic wave signal, and transmits the processed signal to the processor 110. The wireless communication module 160 can also receive a signal to be transmitted from the processor 110, perform frequency modulation and amplification thereon, and radiate the signal as an electromagnetic wave via the antenna 2.

[0427] In some embodiments, the antenna 1 and the mobile communication module 150 of the electronic device 100 are coupled, and the antenna 2 and the wireless communication module 160 are coupled, so that the electronic device 100 can communicate with a network and other devices through wireless communication technology. The wireless communication technology can include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technology, etc. The GNSS can include a global positioning system (GPS), a global navigation satellite system (GLONASS), a beidou navigation satellite system (BDS), a quasi-zenith satellite system (QZSS), and / or a satellite based augmentation systems (SBAS).

[0428] In the embodiments of the present application, the electronic device 100 can communicate with other electronic devices (for example, the electronic device 200) through Bluetooth communication, WIFI communication, etc. For example, the electronic device 100 can send a file that wants to be encrypted and shared to the electronic device 200 through Bluetooth communication, WIFI communication, etc.

[0429] The electronic device 100 realizes the display function through the GPU, the display screen 194, and the application processor, etc. The GPU is a microprocessor for image processing, which is connected to the display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. The processor 110 can include one or more GPUs, which execute program instructions to generate or change display information.

[0430] The display screen 194 is used to display images, videos, etc. The display screen 194 includes a display panel. The display panel can adopt a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light emitting diode (AMOLED), a flex light-emitting diode (FLED), a Miniled, a MicroLed, a Micro-oLed, a quantum dot light emitting diodes (QLED), etc. In some embodiments, the electronic device 100 can include 1 or N display screens 194, N being a positive integer greater than 1.

[0431] The digital signal processor is used to process digital signals, in addition to being able to process digital image signals, it can also process other digital signals. For example, when the electronic device 100 selects a frequency point, the digital signal processor is used to perform Fourier transform on the frequency point energy, etc.

[0432] The video codec is used to compress or decompress digital videos. The electronic device 100 can support one or more video codecs. In this way, the electronic device 100 can play or record videos in multiple encoding formats, such as: moving picture experts group (MPEG) 1, MPEG 2, MPEG 3, MPEG 4, etc.

[0433] The external memory interface 120 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the electronic device 100. The external memory card communicates with the processor 110 through the external memory interface 120 to realize the data storage function. For example, save music, video, etc. Files in the external memory card.

[0434] The internal memory 121 can be used to store computer executable program codes including instructions. The processor 110 performs various functional applications and data processing of the electronic device 100 by running the instructions stored in the internal memory 121. The internal memory 121 can include a program storage area and a data storage area. The program storage area can store an operating system, at least one application program (such as a sound playing function, an image playing function, etc.) required by a function, etc. The data storage area can store data (such as audio data, a phone book, etc.) created during the use of the electronic device 100, etc. In addition, the internal memory 121 can include a high-speed random access memory, and can further include a non-volatile memory such as at least one magnetic disk storage device, a flash memory device, a universal flash storage (UFS), etc.

[0435] The pressure sensor 180A is used to sense a pressure signal and can convert the pressure signal into an electrical signal. In some embodiments, the pressure sensor 180A can be disposed on the display screen 194. There are many types of pressure sensors 180A, such as a resistive pressure sensor, an inductive pressure sensor, a capacitive pressure sensor, etc. The capacitive pressure sensor can include at least two parallel plates with conductive material. When a force is applied to the pressure sensor 180A, the capacitance between the electrodes changes. The electronic device 100 determines the intensity of the pressure according to the change in capacitance. When a touch operation is applied to the display screen 194, the electronic device 100 detects the intensity of the touch operation according to the pressure sensor 180A. The electronic device 100 can also calculate the position of the touch according to the detection signal of the pressure sensor 180A. In some embodiments, touch operations applied to the same touch position but with different touch operation intensities can correspond to different operation instructions. For example, when a touch operation with a touch operation intensity less than a first pressure threshold is applied to a short message application icon, an instruction to view a short message is executed. When a touch operation with a touch operation intensity greater than or equal to the first pressure threshold is applied to the short message application icon, an instruction to create a new short message is executed.

[0436] The fingerprint sensor 180H is used to collect a fingerprint. The electronic device 100 can use the characteristics of the collected fingerprint to implement fingerprint unlocking, access to an application lock, fingerprint photographing, fingerprint answering a call, etc.

[0437] The touch sensor 180K, also referred to as a "touch panel". The touch sensor 180K can be disposed on the display screen 194, and the touch sensor 180K and the display screen 194 form a touch screen, also referred to as a "touch panel". The touch sensor 180K is configured to detect a touch operation applied thereto or in the vicinity thereof. The touch sensor can transmit the detected touch operation to the application processor to determine the touch event type. Visual output related to the touch operation can be provided through the display screen 194. In other embodiments, the touch sensor 180K can also be disposed on the surface of the electronic device 100, which is different from the position where the display screen 194 is located.

[0438] The keys 190 include a power key, a volume key, and the like. The keys 190 can be mechanical keys. Alternatively, the keys 190 can be touch keys. The electronic device 100 can receive key input and generate key signal input related to user settings and function control of the electronic device 100.

[0439] The motor 191 can generate a vibration prompt. The motor 191 can be used for incoming call vibration prompts and also for touch vibration feedback. For example, touch operations applied to different applications (such as taking pictures, playing audio, and the like) can correspond to different vibration feedback effects. Touch operations applied to different regions of the display screen 194 can also correspond to different vibration feedback effects. Different application scenarios (such as time reminders, received messages, alarms, games, and the like) can also correspond to different vibration feedback effects. The touch vibration feedback effect can also be customizable.

[0440] The indicator 192 can be an indicator light, which can be used to indicate a charging state, a power change, and can also be used to indicate a message, a missed call, a notification, and the like.

[0441] It should be understood that the electronic device 100 shown in FIG. 18 is only an example, and the electronic device 100 can have more or fewer components than those shown in FIG. 18, can combine two or more components, or can have a different component configuration. The various components shown in FIG. 18 can be implemented in hardware, software, or a combination of hardware and software, including one or more signal processing and / or application specific integrated circuits.

[0442] The structure of the electronic device 200 can be the same as or similar to that of the electronic device 100, and the related content about the structure of the electronic device 200 can be referred to the related description of the structure of the electronic device 100 shown in FIG. 18, which will not be described here.

[0443] The chip system provided in the embodiments of the present application comprises a processor and a memory coupled with the processor, wherein the memory is configured to store a program or an instruction, and when the program or the instruction is executed by the processor, the chip system implements the method in any one of the method embodiments.

[0444] Optionally, the processor in the chip system can be one or more. The processor can be implemented by hardware or software. When implemented by hardware, the processor can be a logic circuit, an integrated circuit, etc. When implemented by software, the processor can be a general-purpose processor, which is implemented by reading software code stored in a memory.

[0445] Optionally, the memory in the chip system can also be one or more. The memory can be integrated with the processor or arranged separately from the processor, and the embodiments of the present application do not limit the arrangement. For example, the memory can be a non-transient processor, such as a read-only memory (ROM), which can be integrated on the same chip as the processor or arranged on different chips respectively, and the embodiments of the present application do not limit the type of memory or the arrangement of the memory and the processor.

[0446] For example, the chip system can be a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on chip (SoC), a central processing unit (CPU), a network processor (NP), a digital signal processor (DSP), a micro controller unit (MCU), a programmable logic device (PLD), or other integrated chips.

[0447] It should be understood that each step in the above method embodiments can be completed by the integrated logic circuit of hardware in the processor or the instructions in the form of software. The method steps disclosed in conjunction with the embodiments of the present application can be directly embodied as hardware processor execution or executed by a combination of hardware and software modules in the processor.

[0448] In the above embodiments, all or part of the processes can be implemented by software, hardware, firmware, or any combination thereof. When implemented by software, all or part of the processes can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes described in the present application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions can be transferred from one website, computer, server or data center to another website, computer, server or data center through wired (such as coaxial cable, optical fiber, digital subscriber line) or wireless (such as infrared, wireless, microwave, etc.) manner. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. that includes one or more available media sets. The available media can be magnetic media (such as floppy disks, hard disks, magnetic tapes), optical media (such as DVDs), or semiconductor media (such as solid state disks (SSD)), etc.

[0449] Those of ordinary skill in the art can understand that all or part of the processes in the above embodiments can be instructed by a computer program to complete the relevant hardware, and the program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the above-mentioned embodiments. The storage medium includes ROM or random access memory (RAM), magnetic disks or optical disks, and various media that can store program codes.

[0450] The above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that they can modify the technical solutions described in the above embodiments, or make equivalent replacements for part of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present application.

Claims

1. A data sharing method applied to a first electronic device, characterized in that, The method includes: The first electronic device determines that the first file has been selected; In response to the operation of sharing the first file on the first interface, the first electronic device sends the first file to a second electronic device associated with the first user; The first electronic device is used to set a first permission for the first file. The first permission is effective when multiple applications on the first electronic device send the first file. The first permission is used to indicate that the first user is authorized to perform one or more operations on the first file.

2. The method according to claim 1, characterized in that, The method further includes: Before the first electronic device sends the first file to the second electronic device associated with the first user, the first electronic device displays at least one of a device list, an application list, and a user list on an interface, wherein the interface is either the first interface or the second interface. The first electronic device sends the first file to a second electronic device associated with the first user, specifically including: In response to the operation of selecting the second electronic device in the device list, the first electronic device sends the first file to the second electronic device associated with the first user; or, In response to the operation of selecting a first application in the application list, the first electronic device sends the first file to the second electronic device associated with the first user through the first application; or, In response to the operation of selecting the first user in the user list, the first electronic device sends the first file to the second electronic device associated with the first user.

3. The method according to claim 1, characterized in that, The first electronic device sends the first file to a second electronic device associated with the first user, specifically including: In response to an operation triggered on the interface to share the first file, the first electronic device sends the first file to a second electronic device associated with the first user, the interface being an interface for conversing with the first user.

4. The method according to any one of claims 1-3, characterized in that, The first file has the first permission set before the operation of sharing the first file is performed; or, The first file is given the first permission after the operation of sharing the first file, and is sent to the second electronic device associated with the first user.

5. The method according to any one of claims 1-4, characterized in that, The method further includes: In response to the operation of sharing the first file on the first interface, the first electronic device sends the first file to a third electronic device associated with the second user; The first electronic device is used to set a second permission for the first file. The second permission is effective when multiple applications on the first electronic device send the first file. The second permission is used to indicate that the second user is authorized to perform one or more operations on the first file.

6. The method according to any one of claims 1-5, characterized in that, The method further includes: The first electronic device determines that the second file has been selected; In response to the operation of sharing the second file on the first interface, the first electronic device sends the second file to a second electronic device associated with the first user; The first electronic device is used to set a third permission for the second file. The third permission is effective when multiple applications on the first electronic device send the second file. The third permission is used to indicate that the first user is authorized to perform one or more operations on the second file.

7. The method according to any one of claims 1-6, characterized in that, The first user belongs to a first group, which also includes a third user. The method further includes: In response to the operation of sharing the first file on the first interface, the first electronic device sends the first file to a fourth electronic device associated with the third user, and the first permission is further used to instruct the third user to perform one or more operations on the first file; or, In response to the operation of sharing the first file on the first interface, the first electronic device sends the first file to the fourth electronic device associated with the third user; wherein, the first electronic device is further configured to set a fourth permission for the first file, the fourth permission being effective when multiple applications on the first electronic device send the first file, the fourth permission being used to instruct the third user to be authorized to perform one or more operations on the first file.

8. The method according to any one of claims 1-7, characterized in that, Before the first electronic device sends the first file to a second electronic device associated with the first user, the method further includes: The first electronic device logs into the first account, which belongs to the fourth user.

9. The method according to any one of claims 1-8, characterized in that, Before the first electronic device sends the first file to a second electronic device associated with the first user, the method further includes: The first electronic device obtains the credentials corresponding to the first user; The first electronic device encrypts the first file based on the credentials.

10. The method according to any one of claims 1-9, characterized in that, The credentials are obtained by the first electronic device on the server, or the credentials are obtained by the first electronic device locally, or the credentials are obtained by the first electronic device on the second electronic device.

11. The method according to any one of claims 1-10, characterized in that, The first electronic device is used to set a first permission for the first file, specifically including: The first electronic device is used to write the field information of the first permission into the first file; or, The first electronic device is used to send a first message to the server. The first message includes field information of the first permission and identification information of the first file. The first message is used to instruct the server to save the association between the field information of the first permission and the identification information of the first file.

12. The method according to any one of claims 1-11, characterized in that, The first permission includes read-only permission, or editable permission, or forwarding permission. The editable permission includes one or more of the following: edit permission, save as permission, screenshot permission, screen recording permission, print permission, and copy permission.

13. The method according to any one of claims 1-12, characterized in that, The first file contains sensitive information.

14. A data sharing method applied to a second electronic device, characterized in that, The method includes: The second electronic device receives a first file sent by the first electronic device. The first file is controlled by a first permission. The first permission is effective when multiple applications on the second electronic device perform operations on the first file within the scope of the first permission control. The multiple applications include the first application. The second electronic device acquires a first operation on the first file in the first application; In response to the first operation, if the second electronic device determines that the first operation is one or more operations authorized by the first user indicated by the first permission to perform on the first file, then the second electronic device responds to the first operation.

15. The method according to claim 14, characterized in that, Before the second electronic device determines that the first operation is an instruction of the first permission and the first user is authorized to perform one or more operations on the first file, the method further includes: The second electronic device determines that the user performing the first operation is the first user who has been authenticated and has operation rights to the first file.

16. The method according to claim 15, characterized in that, The second electronic device determines that the user performing the first operation is the first user who has been authenticated and has operation permissions for the first file, specifically including: The second electronic device determines that the account logged in by the second electronic device is the account of the first user; or, The second electronic device determines that the biometrics of the user performing the first operation match the biometrics of the first user; or, The second electronic device receives a first message from the third electronic device, the first message indicating that the user performing the first operation is the first user who is authenticated and has operation rights to the first file, and the third electronic device is associated with the second electronic device.

17. The method according to any one of claims 14-16, characterized in that, The method further includes: If the second electronic device determines that the first operation does not fall under one or more operations authorized by the first user to perform on the first file as indicated by the first permission, the second electronic device displays a first prompt message, which prompts the user that the second electronic device refuses to respond to the first operation.

18. The method according to any one of claims 14-17, characterized in that, The method further includes: In response to the operation of sharing the first file, the second electronic device sends the first file to a third electronic device associated with the first user.

19. The method according to any one of claims 14-17, characterized in that, The method further includes: In response to the operation of sharing the first file, the second electronic device sends the first file to a fourth electronic device associated with the second user.

20. The method according to any one of claims 14-19, characterized in that, When the first file is forwarded by the second electronic device, the first file is set to third permission, and the scope of authorization of the third permission does not exceed the scope of authorization of the first permission.

21. The method according to any one of claims 14-20, characterized in that, The method further includes: The second electronic device sends a second message to the first electronic device, the second message being used to instruct the first electronic device to authorize the first user to perform a second operation on the first file, the second operation not being one or more operations authorized by the first permission to be performed on the first file by the first user.

22. The method according to any one of claims 14-21, characterized in that, The method further includes: The second electronic device sends a third message to the first electronic device, the third message being used to instruct the first electronic device to authorize the first user to perform a forwarding operation on the first file.

23. The method according to any one of claims 14-22, characterized in that, The first file is an encrypted file. Before the second electronic device responds to the first operation, the method further includes: The second electronic device obtains the credentials corresponding to the first user; The second electronic device decrypts the first file based on the credentials.

24. The method according to any one of claims 14-23, characterized in that, The second electronic device displays a first identifier, which is used to indicate that the first file is an encrypted file.

25. The method according to any one of claims 14-24, characterized in that, The first permission is obtained by the second electronic device from the first file; or, the first permission is obtained by the second electronic device from the server.

26. The method according to any one of claims 14-25, characterized in that, The first permission includes read-only permission, or editable permission, or forwarding permission. The editable permission includes one or more of the following: edit permission, save as permission, screenshot permission, screen recording permission, print permission, and copy permission.

27. An electronic device, characterized in that, The electronic device includes one or more processors and one or more memories; wherein the one or more memories are coupled to the one or more processors, and the one or more memories are used to store computer program code, the computer program code including computer instructions, which, when executed by the one or more processors, cause the electronic device to perform the method as described in any one of claims 1-13 or 14-26.

28. A computer storage medium, characterized in that, The computer storage medium stores a computer program, which includes program instructions that, when executed on an electronic device, cause the electronic device to perform the method as described in any one of claims 1-13 or 14-26.

29. A computer program product, when run on a computer, causes the computer to perform the method as described in any one of claims 1-13 or 14-26.

Citation Information

Patent Citations

  • Data sharing method and related equipment

    CN121188819A

  • File sharing management method, device and storage medium

    CN109408476A

  • File sharing method and electronic equipment

    CN114328423A

  • Access control method and system, sending end equipment and receiving end equipment

    CN118114284A

  • Data sharing method and related equipment

    CN119442305A