Privacy policy-based permissions management method, electronic device, and storage medium

By using a privacy policy-based permission management system and employing a tiered and dynamic authorization mechanism to manage sensitive permissions for applications, the problem of data collection without user consent in mobile operating systems has been solved, thereby improving user privacy protection and compliance.

WO2026007594A1PCT designated stage Publication Date: 2026-01-08ZTE CORP
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/099001
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-06-30
Filing Date
2025-06-04
Publication Date
2026-01-08

AI Technical Summary

Technical Problem

Existing mobile operating system permission management mechanisms are inadequate in terms of user privacy protection and data collection compliance. Applications may collect data without explicit user consent, violating user privacy rights and laws and regulations.

Method used

A privacy policy-based access control system is adopted, including a main control module, a sensitive permission configuration policy library, a privacy permission extraction module, an access control module, a user consent mechanism monitoring module, and a dynamic authorization flag module. It manages the application's sensitive permissions through a hierarchical and dynamic authorization mechanism to ensure that data collection is only permitted after the user has given explicit consent.

Benefits of technology

It effectively solves the problem of data collection without the user's explicit consent, enhances user privacy protection, simplifies compliance processes, reduces compliance risks, and ensures the legal and compliant operation of the application.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025099001_08012026_PF_FP_ABST
    Figure CN2025099001_08012026_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure provides a privacy policy-based permissions management method, comprising: upon detecting that an application has started, acquiring a management and control mode of the application, wherein the management and control mode comprises a first management and control mode and a second management and control mode, the first management and control mode is configured to perform unified authorization on sensitive permissions of the application on the basis of a privacy policy, and the second management and control mode is configured to perform separate authorization on sensitive permissions of functional modules of the application on the basis of the privacy policy (S101); and managing the sensitive permissions of the application on the basis of the acquired management and control mode (S102). The present disclosure further provides an electronic device and a storage medium.
Need to check novelty before this filing date? Find Prior Art

Description

Privacy policy-based permission management method, electronic device, and storage medium

[0001] Cross-reference to Related Applications

[0002] This application claims priority to Chinese Patent Application No. 202410870218.6, filed on June 30, 2024, with the Chinese Patent Office, the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD

[0003] The present disclosure relates to, but is not limited to, the technical field of data security. BACKGROUND

[0004] In the related art, mobile operating systems such as Android and iOS provide permission management mechanisms to control application access to user data. For example, the Android operating system uses a permission request dialog to ask users to grant or deny specific permissions at runtime. However, these mechanisms mainly focus on the authorization of permissions, and pay insufficient attention to the preconditions of privacy policy compliance and user consent. In some cases, applications may collect data without the explicit consent of users, which not only violates the privacy rights of users, but also may violate relevant laws and regulations.

[0005] In addition, with the increasing strictness of regulatory agencies on personal privacy protection, such as the regulations of the China Ministry of Industry and Information Technology, applications must obtain explicit consent from users before collecting user data, and cannot collect data without the consent of the privacy policy. How to ensure user privacy rights and interests while reasonably collecting data and managing application permissions has become an important issue in this field. SUMMARY

[0006] Embodiments of the present disclosure provide a privacy policy-based permission management method, an electronic device, and a storage medium.

[0007] In a first aspect, embodiments of the present disclosure provide a privacy policy-based permission management method, including: in the case of monitoring the start of an application program, obtaining a management mode of the application program, wherein the management mode includes a first management mode and a second management mode, the first management mode is set to uniformly authorize sensitive permissions of the application program based on a privacy policy, and the second management mode is set to individually authorize sensitive permissions of each functional module of the application program based on the privacy policy; and based on the obtained management mode, managing the sensitive permissions of the application program.

[0008] In a second aspect, an electronic device is provided, which includes a memory and a processor. The memory stores a computer program executable by the processor. The computer program, when executed by the processor, implements the method for privacy policy based permission management according to any of the embodiments of the present disclosure.

[0009] In a third aspect, a computer readable storage medium is provided, which stores a computer program. The computer program, when executed by a processor, implements the method for privacy policy based permission management according to any of the embodiments of the present disclosure.

[0010] In a fourth aspect, a computer program product is provided, which includes a computer program. The computer program, when executed by a processor, implements the method for privacy policy based permission management according to any of the embodiments of the present disclosure. BRIEF DESCRIPTION OF DRAWINGS

[0011] In the drawings of the embodiments of the present disclosure:

[0012] FIG. 1 is a flowchart of a method for privacy policy based permission management according to an embodiment of the present disclosure;

[0013] FIG. 2 is a flowchart of an operation of managing sensitive permissions of an application according to an embodiment of the present disclosure;

[0014] FIG. 3 is a schematic diagram of an electronic device according to an embodiment of the present disclosure; and

[0015] FIG. 4 is a schematic diagram of a computer readable storage medium according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0016] In order for those skilled in the art to better understand the technical solutions of the present disclosure, the embodiments of the present disclosure will be described in detail below with reference to the drawings.

[0017] The embodiments of the present disclosure will be described more fully hereinafter with reference to the accompanying drawings, but the embodiments shown can be embodied in different forms and the present disclosure should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided so that the present disclosure will be thorough and complete, and will fully convey the scope of the present disclosure to those skilled in the art.

[0018] The accompanying drawings of the embodiments of the present disclosure are used to provide a further understanding of the embodiments of the present disclosure, and constitute a part of the specification, which together with the detailed embodiments, serve to explain the present disclosure, and do not constitute a limitation of the present disclosure. The above and other features and advantages will become more apparent to those skilled in the art by describing the detailed embodiments with reference to the accompanying drawings.

[0019] The present disclosure can be described with reference to plan views and / or cross-sectional views by virtue of the idealized schematic illustrations of the present disclosure. Thus, the example illustrations can be modified according to manufacturing techniques and / or tolerances.

[0020] The embodiments of the present disclosure and the features in the embodiments can be combined with each other without conflict.

[0021] The terms used in the present disclosure are only used to describe specific embodiments, and are not intended to limit the present disclosure. As used in the present disclosure, the term "and / or" includes any and all combinations of one or more of the associated listed items. As used in the present disclosure, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. The terms "comprises," "comprising," "includes," "including," "contains," "containing," "has," "having," or the like are intended to specify the presence of stated features, integers, steps, operations, elements, components, or the like, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, or groups thereof.

[0022] Unless otherwise defined, all terms (including technical and scientific terms) used in the present disclosure have the same meaning as commonly understood by one of ordinary skill in the art. It will be further understood that terms, such as those defined in commonly used dictionaries, should be interpreted as having a meaning that is consistent with their meaning in the context of the relevant art and the present disclosure, and will not be interpreted in an idealized or overly formal sense unless expressly so defined in the present disclosure.

[0023] The present disclosure is not limited to the embodiments shown in the drawings, but includes modifications of the configuration formed based on the manufacturing process. Therefore, the regions exemplified in the drawings have a schematic property, and the shape of the regions shown in the drawings exemplifies a specific shape of the region of the element, but is not intended to be restrictive.

[0024] There are two core problems in the field of data security, namely, whether the data collection authority is fully and explicitly disclosed to the user, and whether the operation of confirming all sensitive information occurs before the user's explicit consent. Whether the data collection authority is explicitly consented by the user only means that the collected data is consistent with the content of the explicit consent, but this does not automatically mean that the data collection will be performed after obtaining the explicit authorization of the user. For example, at present, the Ministry of Industry and Information Technology (MIIT) and the Office of the Central Cyberspace Administration (CAC) have implemented strict supervision and management on such issues. Traditionally, an application (App) attempts to ensure that all data collection authorities occur after the user's consent through internal logic design. However, this method of relying on a single application to self-restrict is not sufficient to fully prevent unauthorized data collection authorities. It is found in the process of regulatory review that there are still many applications that collect personal information without the explicit consent of the user, which significantly aggravates the uncertainty and risk at the regulatory level.

[0025] In modern mobile operating system permission management frameworks, permission control mechanisms have undergone significant evolution, aiming to balance user experience, privacy protection, and application functionality needs.

[0026] In view of this, the embodiments of the present disclosure aim to build a comprehensive management framework from the system level. In some embodiments of the present disclosure, centralized and systematic means are used to supervise and control all App permissions when attempting to obtain sensitive data. In this way, App developers can focus more on improving the performance and experience of the application itself, while the operating system side uniformly manages and controls the occurrence of data collection permissions. This approach not only significantly enhances the strength of user privacy protection, but also simplifies compliance procedures and avoids compliance risks caused by negligence of App developers, thereby laying a solid foundation for the healthy development of the entire industry. According to the embodiments of the present disclosure, unless the user has explicitly agreed to the privacy policy of the application, any sensitive permission, whether it is an application installation permission or a runtime permission, will not be granted. This mechanism ensures that data collection permissions can only be granted after obtaining legal authorization, effectively solving the problem of illegal collection of user privacy data without explicit consent.

[0027] One embodiment of the present disclosure provides a permission management system based on a privacy policy, which mainly includes a master control module, a sensitive permission configuration strategy library, a privacy permission extraction module, a permission control module, a user consent mechanism monitoring module, a dynamic authorization flag module, and a purpose method and sensitive permission mapping module.

[0028] The master control module is the controller of the entire permission management system based on the privacy policy, responsible for monitoring the cooperative work of each module. The master control module starts operating when the application starts, ensuring that information transmission and task scheduling between modules proceed in an orderly manner. The master control module interacts with the permission control module to obtain the current permission control level and decides the subsequent processing flow, such as whether to start sensitive permission extraction, permission granting or disabling, etc.

[0029] The sensitive permission configuration policy library stores preset sensitive permission configuration policies, i.e., preset sensitive permissions or sensitive behavior permissions, including but not limited to sensitive permissions such as making a call and reading location information. The sensitive permission configuration policy library can include default policies and manually configurable policies, containing not only default configurations conforming to general data security standards, but also allowing administrators or users to customize specific permission control rules according to actual needs. The role of the sensitive permission configuration policy library is to judge whether the application request meets the privacy protection requirements by comparing the requested permissions, and to guide the permission control module to perform corresponding operations. In an example, the content stored in the sensitive permission configuration policy library includes sensitive behaviors defined by the Ministry of Industry and Information Technology and problems reported by external regulatory agencies, which can include but are not limited to the following sensitive permissions: making a call, call forwarding, three-way calling, sending an SMS, sending an MMS, sending an email, data switch, WLAN switch, Bluetooth switch, NFC switch, positioning, call recording, local recording, background screenshot, background screen recording, taking a photo, video recording, receiving an SMS, networking, reading a phonebook, reading call records, reading an SMS, reading an MMS, reading Internet records, reading a calendar, reading photos, reading videos, reading audio, reading fingerprints, reading faces, reading IMEI, reading WLAN-MAC, reading BT-MAC, reading application software list, reading user's local number, reading Android ID, reading IMSI, reading SIM card's ICCID, reading clipboard, writing a phonebook, writing call records, writing an SMS, writing an MMS, writing a calendar, writing Internet records, writing a clipboard, monitoring a clipboard.

[0030] The privacy permission extraction module is configured to extract information related to data collection and sensitive permissions from the application's privacy policy document. Depending on the level of control (coarse or fine), the privacy permission extraction module can only extract the scope of sensitive permissions, or further extract the purpose, method, and scope of the permissions. The extracted information is then used to compare with the configurations in the policy library to decide whether to allow the application to request sensitive permissions under certain conditions.

[0031] The permission control module is the key to implementing dynamic permission management, and performs specific permission granting or disabling operations according to the instructions of the master control module. Permission control is divided into two control modes: coarse control and fine control. In the coarse control mode, only the overall sensitive permissions are controlled; while in the fine mode, not only the sensitive permissions are controlled, but also more detailed permission management is performed for specific purposes and methods. The permission control module, through cooperation with the dynamic authorization flag module, ensures the real-time and accuracy of permission granting or prohibition.

[0032] The user consent mechanism monitoring module is configured to monitor the privacy policy consent state of the user, including first-time consent, withdrawal of consent, and other permissions. By maintaining a consent flag, the user consent mechanism monitoring module can reflect the user's attitude towards the privacy policy in real time and accordingly convey instructions to the permission control module to determine whether the application can request sensitive permissions. The user consent mechanism monitoring module ensures that the application cannot start any sensitive data collection permissions without the user's explicit consent to the privacy policy.

[0033] The dynamic authorization flag module is configured to mark the authorization state under a certain method or function. When the application requests a permission, it dynamically decides whether to allow the application of the permission based on the current authorization flag. This allows the permission request under the related function to be automatically approved after the user agrees to the specific privacy policy without asking the user again.

[0034] The purpose method and sensitive permission mapping module is positioned to establish a mapping relationship between the specific purpose method (function module) in the application program and the required sensitive permissions under the fine-grained control mode. This module identifies the permission requirements related to specific methods or functions by analyzing the privacy policy and matches them with the sensitive permission configuration in the policy library, achieving precise permission control. For example, when the privacy policy specifies that a specific function needs to access location information, this module ensures that the function can only obtain location permission after the user agrees to the corresponding privacy policy.

[0035] In the embodiments of the present disclosure, the term "purpose method" refers to the code implementation approach that specifically implements a certain function or processing process in the application program. The purpose method is directly related to the specific operation or data processing task that the application program wants to perform. Therefore, a purpose method corresponds to a function module. In the context of privacy policy control permission management, the purpose method can refer to methods that need to access user sensitive permissions (such as accessing location, reading contacts, using camera, etc.) to complete specific functions. For example, if an application needs to call the camera when the user presses the shutter button, all code logic, API calls, and data processing processes related to this "shooting" function can be considered as "purpose methods".

[0036] In the embodiments of the present disclosure, the purpose method or function module is closely related to the sensitive permissions of the privacy policy, because the system needs to dynamically control whether these methods can be executed according to the user's consent to the specific purpose or function described in the privacy policy and the scope of permissions involved. By identifying and mapping the specific application code logic described in the privacy policy, the system can accurately manage the permissions of the application when requesting and using sensitive permissions, ensuring that the consent of the privacy policy becomes a prerequisite for executing these sensitive operations. In this way, even if the user agrees to the general permission request of the application, if there is no privacy policy consent for the specific purpose method, the function involving sensitive permissions will still be prevented from execution, thereby strengthening user privacy protection and complying with regulatory requirements.

[0037] In a first aspect, one embodiment of the present disclosure provides a privacy policy-based permission management method, as shown in FIG. 1, the method comprises:

[0038] S101, in the case of monitoring the application program startup, obtaining the management mode of the application program, wherein the management mode comprises a first management mode and a second management mode, the first management mode is set to uniformly authorize the sensitive permissions of the application program based on the privacy policy, and the second management mode is set to individually authorize the sensitive permissions of each function module of the application program based on the privacy policy; and

[0039] S102, based on the obtained management mode, managing the sensitive permissions of the application program.

[0040] The privacy policy-based permission management method according to the embodiments of the present disclosure adopts a permission management hierarchical mechanism, which can effectively balance the relationship between user privacy protection and different functions of the application program. The permission management hierarchical mechanism can accurately match the permission granting according to the specific consent of the user, avoiding both the violation of the excessive collection of user data and ensuring the user's autonomous choice between privacy protection and function use. The permission management can include a first management mode (also referred to as a coarse management) and a second management mode (also referred to as a fine management). The first management mode is set to uniformly authorize all sensitive permissions of the application program based on the privacy policy, and the second management mode is set to individually authorize the sensitive permissions of each function module of the application program based on the privacy policy.

[0041] Coarse management is a basic permission management mode, which is suitable for application scenarios with only one privacy policy or simple user preference control. In this mode, once the user agrees to the privacy policy, all predefined sensitive permissions can be uniformly granted, and if the user does not agree to the privacy policy, all sensitive permissions are considered not granted. This control method is simple and efficient.

[0042] Fine-grained control is a dynamic permission management method, which is particularly suitable for applications with multiple privacy policies or requiring different permissions for different functions. Fine-grained control allows independent permission management for each specific function or privacy policy item. When the application starts or runs a specific function, it will dynamically control the sensitive permissions related to the function according to the user's consent status for the function or corresponding privacy policy. For example, if the user agrees to the application's privacy policy on location services, the system will only open the location permission for this part of the function, and if the user disagrees, the location permission under this function will be prohibited, without affecting the running of other functions of the application.

[0043] In some embodiments, in the case of monitoring the start of an application, the operation of obtaining the control mode of the application (S101) includes: in the case of detecting that the application has only one privacy policy, determining that the control mode of the application is the first control mode; or the user sets the control mode level of the application to the first control mode.

[0044] In some embodiments, as shown in FIG. 2, based on the obtained control mode, the operation of managing the sensitive permissions of the application (S102) includes: S102-1, in the case of the control mode being the first control mode, obtaining the privacy policy flag bit of the application, and in the case of determining that the user agrees to the privacy policy based on the privacy policy flag bit, allowing the application to run the sensitive permissions described in the privacy policy, or in the case of determining that the user does not agree to the privacy policy based on the privacy policy flag bit, prohibiting the application to run the sensitive permissions described in the privacy policy.

[0045] When it is determined that the control mode of the application is the first control mode, i.e., coarse-grained control, the system will obtain the user's consent status for the privacy policy by checking the privacy policy flag bit of the application.

[0046] For example, the flag bit can be marked with 0 and 1, where 0 represents that the user has not agreed to the privacy policy, and 1 represents that the user has expressed agreement to the privacy policy. In the initial state of the application, the privacy policy flag bit is set to 0 by default, i.e., it is assumed that the user has not agreed to the privacy policy, and the activation of all sensitive permissions in the permission policy library is prohibited. Once the user starts the application and agrees to the privacy policy, the flag bit is immediately updated to 1, indicating that the user agrees to the terms of the privacy policy. If the user refuses the privacy policy or withdraws the consent after previous agreement, the privacy policy flag bit will be reset to 0. When the flag bit is 1, this state indicates that the user has accepted the privacy policy, and the application app will request the runtime permission through a pop-up window according to its internal logic. When the flag bit is 0, this state indicates that the user has not agreed or has withdrawn the consent to the privacy policy. In this case, the system will analyze the keywords in the privacy policy and convert them into specific permission configurations of the privacy policy. The system compares the permission configurations of the privacy policy with the permission policy library, and prohibits the dynamic activation of any unauthorized sensitive behavior permission. This can be achieved by blocking the process in the background when the application requests dynamic permission, preventing illegal operation of the permission. The user will receive a prompt box in this case, informing the user that the related permissions cannot be activated due to the user's non-agreement to the privacy policy. This design ensures the protection of the user's privacy by the application, and reasonably requests and uses the permission on the premise of the user's consent.

[0047] In some embodiments, as shown in FIG. 2, based on the obtained management mode, the operation of managing the sensitive permissions of the application (S102) includes: S102-2, in the case where the management mode is the second management mode, obtaining the privacy policy flag bit of each function module of the application, and in the case where it is determined based on the privacy policy flag bit of the first function module that the user agrees to the privacy policy, allowing the first function module of the application to run the sensitive permissions described in the privacy policy, or in the case where it is determined based on the privacy policy flag bit of the first function module that the user has not agreed to the privacy policy, prohibiting the first function module of the application from running the sensitive permissions described in the privacy policy.

[0048] In some embodiments, as shown in FIG. 2, based on the obtained management mode, the operation of managing the sensitive permissions of the application (S102) further includes: S102-3, in the case where the management mode is the second management mode, in the case where it is determined based on the privacy policy flag of the second function module that the user agrees to the privacy policy, allowing the second function module of the application to run the sensitive permissions described in the privacy policy, or, in the case where it is determined based on the privacy policy flag of the second function module that the user does not agree to the privacy policy, prohibiting the second function module of the application from running the sensitive permissions described in the privacy policy, wherein the second function module is different from the first function module.

[0049] In the case where it is determined that the management mode of the application is the second management mode, i.e., fine management, the system first defaults to prohibiting the start of all sensitive permissions in the permission policy library, and then obtains the user's agreement state to the privacy policy by checking the privacy policy flags of each function module of the application.

[0050] Exemplarily, in different function modules of the application app, if a permission request pop-up window appears, the system will use Activity (an interactive component of the user interface) to obtain the agreement state of the privacy policy of different function modules. For example, the privacy policy flags of different function modules (e.g., a first function module, a second function module, a third function module) can be represented as Priv1, Priv2, Priv3, etc. The privacy policy flags of different function modules can be obtained by analyzing the start logic interface of the application, which can be extracted through decompilation code or directly from the privacy policy declaration.

[0051] For example, when the flag bit Priv1 of the privacy policy of the first function module is set to 1, it indicates that the user has agreed to the privacy policy of the first function module. At this time, the system will accurately grant the corresponding sensitive permissions according to the description of the privacy policy. The application program requests the necessary running permissions through a pop-up window according to its internal logic, and allows the related functions to run automatically after the permissions are granted. If the flag bit Priv1 of the privacy policy of the first function module is 0, it indicates that the user has not agreed or has withdrawn the consent to the privacy policy of the first function module. In this case, the system will analyze the keywords in the privacy policy and convert them into specific permission configurations. Then, according to the permission configurations, the sensitive behavior permissions in the policy library within the function range described in the privacy policy of the first function module are disabled. Exemplarily, it can be determined whether the functions are the same by checking the class name or library file name of the code running and matching with the functions extracted in the privacy policy. The class file is also associated with the corresponding privacy policy by setting an identifier for the privacy policy and the corresponding function, so as to quickly determine by the identifier. When the application program attempts to apply for an unauthorized dynamic permission, the system will block the running of the permission in the background, and the user will not receive a prompt box for permission request. At this time, the system will display a prompt box to the user, informing that the related permissions cannot be run due to the non-agreement of the privacy policy.

[0052] In some embodiments, in the case where it is determined based on the privacy policy flag bit that the user has not agreed to the privacy policy, the application program is prohibited from running the sensitive permissions described in the privacy policy, comprising:

[0053] determining the permission configuration of the privacy policy;

[0054] comparing the permission configuration of the privacy policy with a sensitive permission configuration policy library; and

[0055] prohibiting the application program from running the sensitive permissions in the sensitive permission configuration policy library corresponding to the permission configuration description of the privacy policy.

[0056] Exemplarily, the system first determines the permission configuration of the privacy policy, thereby explicitly covering the permissions of the privacy policy. As described above, the system can analyze the keywords in the privacy policy, and then convert the analyzed keywords into specific permission configurations of the privacy policy. The system compares these permission configurations with a predefined sensitive permission configuration policy library, and then prohibits the application program from running the sensitive permissions in the sensitive permission configuration policy library corresponding to the permission configuration description of the privacy policy. The policy library contains the permission use criteria according to the laws and regulations, to ensure that the permissions requested by the application do not exceed the authorized range of the user's privacy policy.

[0057] In some embodiments, the sensitive permission configuration policy library is pre-configured and stores the sensitive permissions.

[0058] In some embodiments, determining the permission configuration of the privacy policy can include extracting keywords from the privacy policy and converting the keywords into permission configurations.

[0059] Exemplarily, extracting keywords from the privacy policy can identify and understand the relevant content of the privacy policy. For example, the keywords can include terms such as "location information", "contact list", "SMS", etc. related to sensitive permissions. By converting the keywords into permission configurations, the extracted keywords can be associated with the permissions of a specific application. For example, "location information" can be associated with the "access location" permission. If the user agrees to the privacy policy, the system will grant the application the corresponding permission according to the permission configuration, allowing the application to collect and use data in the way agreed by the user. If the user does not agree or withdraws the consent to the privacy policy, the system will limit or prohibit the corresponding permission according to the permission configuration, preventing the application from collecting or using related data. Assuming that an application's privacy policy mentions "accessing user location", the system will extract "location" as a keyword and convert it into a configuration for the "access location" permission. When the user agrees to the privacy policy, the system will grant the application the "access location" permission. If the user refuses or withdraws consent, the system will disable the "access location" permission and display a corresponding prompt to the user when the application attempts to access location information.

[0060] In some embodiments, determining the permission configuration of the privacy policy can include obtaining a tag of the application, the tag being used to identify the privacy policy associated with the application, and obtaining the permission configuration of the privacy policy based on the tag.

[0061] In Android application development, Act ivity refers to one of the application components, responsible for creating the user interface and handling user interactions. Each Act ivity corresponds to a separate interaction point in the application app. Act ivity can be used to determine which functional module of the application the user is currently interacting with, thereby allowing the system to grant or deny permissions according to the user's consent status for that part of the privacy policy. In embodiments of the present disclosure, the term "tag" is mainly used to quickly identify and count the number of privacy policies associated with the application when the application is started. Exemplarily, the tags are set on the Act ivity when the application is started. When the system extracts these tags, it can directly identify the Act ivity related to the privacy policy without the need to determine it through keyword extraction.

[0062] In some embodiments, in a case where it is determined, based on the privacy policy flag of the first function module, that the user does not agree to the privacy policy, the first function module of the application is prohibited from running a sensitive permission described in the privacy policy, including:

[0063] determining a permission configuration of the privacy policy of the first function module;

[0064] comparing the permission configuration of the privacy policy of the first function module with a sensitive permission configuration policy library; and

[0065] prohibiting the application from running a sensitive permission in the sensitive permission configuration policy library corresponding to the permission configuration description of the privacy policy of the first function module.

[0066] In some embodiments, determining the permission configuration of the privacy policy of the first function module includes: obtaining a tag of the first function module, the tag being used to identify the privacy policy associated with the first function module, and obtaining the permission configuration of the privacy policy based on the tag.

[0067] In some embodiments, in a case where it is determined, based on the privacy policy flag of the second function module, that the user does not agree to the privacy policy, the second function module of the application is prohibited from running a sensitive permission described in the privacy policy, including:

[0068] determining a permission configuration of the privacy policy of the second function module;

[0069] comparing the permission configuration of the privacy policy of the second function module with the sensitive permission configuration policy library; and

[0070] prohibiting the application from running a sensitive permission in the sensitive permission configuration policy library corresponding to the permission configuration description of the privacy policy of the second function module.

[0071] In some embodiments, determining the permission configuration of the privacy policy of the second function module includes: obtaining a tag of the second function module, the tag being used to identify the privacy policy associated with the second function module, and obtaining the permission configuration of the privacy policy based on the tag.

[0072] Exemplarily, when it is determined that the management manner of the application program is the second management manner, i.e., the fine management, the system first determines the permission configuration of the privacy policy corresponding to each function module, so as to determine the permission configuration of each function module. The system compares the permission configuration of each function module with a predefined sensitive permission configuration strategy library, and then prohibits the application program from running the sensitive permission in the sensitive permission configuration strategy library corresponding to the permission configuration description of the privacy policy of different function modules. The strategy library contains the permission use criteria according to laws and regulations, so as to ensure that the permissions requested by each function module of the application program do not exceed the authorized range of the user privacy policy.

[0073] In some embodiments, determining the permission configuration of the privacy policy of the first function module comprises: extracting a keyword from the privacy policy of the first function module, and converting the keyword into a permission configuration; and mapping the relationship among the privacy policy, the first function module and the permission configuration.

[0074] In some embodiments, determining the permission configuration of the privacy policy of the second function module comprises: extracting a keyword from the privacy policy of the second function module, and converting the keyword into a permission configuration; and mapping the relationship among the privacy policy, the second function module and the permission configuration.

[0075] When the management manner is the second management manner, i.e., the fine management, the application program app includes multiple function modules and multiple corresponding sensitive permissions, so it is necessary to map the privacy policy, the function module and the corresponding permission configuration. Based on the mapping result, the system can adjust the permission configuration of the application program in real time according to the consent state of the user, so as to ensure that different function modules of the application program access data only within the authorized range of the user. In the embodiments of the present disclosure, a label can be used to quickly identify and count the number of privacy policies associated with each function module when each function module of the application program is started. Exemplarily, a label is set on the Activity when each function module of the application program is started. When the system extracts these labels, it can directly identify the Activity related to the privacy policy without the need to determine through keyword extraction.

[0076] In some embodiments, the method further comprises:

[0077] dynamically marking the privacy policy flag bit of each function module; and

[0078] based on the dynamically marked privacy policy flag bit, dynamically managing the sensitive permission of each function module.

[0079] Here, the method according to the embodiments of the present disclosure provides a dynamic marking mechanism for finely managing the consent status of the privacy policy of each functional module within an application. The system assigns a privacy policy flag bit to each functional module within the application. These flag bits dynamically mark the user's consent or refusal status for the privacy policy of the corresponding functional module. When the user interacts with the application and performs a consent or refusal operation on the privacy policy of a specific functional module, the corresponding privacy policy flag bit is updated in real time to reflect the user's latest choice. The system dynamically manages the sensitive permissions of each functional module based on these dynamically updated privacy policy flag bits. Only when the user has explicitly consented to the privacy policy of a functional module, can the functional module obtain the necessary permissions to perform its functions.

[0080] In some embodiments, dynamically managing the sensitive permissions of the various functional modules based on the dynamically marked privacy policy flag bits includes:

[0081] In the case where it is determined based on the privacy policy flag bit of the first functional module that the user has consented to the privacy policy and based on the privacy policy flag bit of a second functional module that the user has not consented to the privacy policy, during the running of the second functional module, the second functional module of the application is prohibited from running the sensitive permissions described in the privacy policy, and during the running of the first functional module, the first functional module of the application is allowed to run the sensitive permissions prohibited by the second functional module.

[0082] According to the present embodiment, the method allows the system to perform personalized permission management according to the user's consent status for the privacy policies of different functional modules. If the user has consented to the privacy policy of a first functional module and refused to the privacy policy of a second functional module, the system will enable or disable the permissions accordingly, ensuring that each module only runs within the scope of user authorization. In addition, by allowing the first functional module of the application to run the sensitive permissions prohibited by the second functional module when running the first functional module, the permissions can be dynamically managed to ensure that the behavior of the application always aligns with the user's consent status for the privacy policy. Through dynamic permission management, not only is the user experience improved, but also the protection of user privacy is strengthened, ensuring the compliance and security of the application.

[0083] In an example, for the start and management of the privacy policy of different functional modules in the application app, the system determines that the management mode of the application is the second management mode. At this time, the system dynamically marks the privacy policy flag (such as Priv1 and Priv2) to track the user's consent state for each functional module. These flags ensure that the system can turn on or off the corresponding sensitive permissions in real time according to the user's consent state. For the privacy policy of different functional modules of the same application app, the system will dynamically manage the opening and closing of permissions according to the extracted privacy policy flag. If the second functional module has a different privacy policy consent state from the first functional module, the system will adjust the permission configuration in real time according to the dynamically marked flag (such as Priv2 and Priv1). For example, if the user only agrees to the privacy policy of the first functional module (for example, Priv1 = 1) and does not agree to the privacy policy of the second functional module (for example, Priv2 = 0), the system will disable all sensitive permissions related to the second functional module described in the privacy policy. When the user attempts to execute a functional module (such as the second functional module) that has not agreed to the privacy policy, the system will not only automatically disable the related sensitive permissions, but also explicitly prompt the user through a pop-up window that the permission is limited. Conversely, when the user executes a function (such as the first functional module) that has agreed to the privacy policy, the sensitive permissions of the previously disabled functional module (such as the second functional module) will be re-authorized through a pop-up window or automatically restored in the background.

[0084] The privacy policy-based permission management method according to the embodiments of the present disclosure adopts a dynamic permission management mechanism and a permission management hierarchical mechanism, ensuring the accuracy and compliance of data collection. This method can effectively balance the relationship between user privacy protection and different functions of the application. The permission management hierarchical mechanism can accurately match the permission granting according to the user's specific consent, avoiding both the violation of excessive collection of user data and ensuring the user's autonomous choice between privacy protection and function use. The dynamic permission management mechanism allows the system to implement a dynamic permission management strategy, ensuring that all sensitive data collection is activated only after the user explicitly agrees to the relevant privacy policy. For an application that includes multiple functional modules, the system allows the user to authorize the privacy policy of each module individually. In this way, even if the user does not agree to the privacy policy of a specific functional module in the application, it does not affect the normal operation of other functional modules of the application.

[0085] In a second aspect, as shown in FIG. 3, the embodiments of the present disclosure provide an electronic device, which includes a memory and a processor; the memory stores a computer program that can be executed by the processor, and the computer program is executed by the processor to implement any one of the privacy policy-based permission management methods of the embodiments of the present disclosure.

[0086] The processor is a device with data processing capability, including but not limited to a central processing unit (CPU) and the like; the memory is a device with data storage capability, including but not limited to a random access memory (RAM, such as SDRAM, DDR, etc.), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a flash memory (FLASH); the I / O interface (read-write interface) is connected between the processor and the memory, and can realize information interaction between the memory and the processor, including but not limited to a data bus (Bus) and the like.

[0087] Those of ordinary skill in the art can understand that all or some of the functional modules / units in the above disclosed steps, systems and devices can be implemented as software, firmware, hardware and appropriate combinations thereof.

[0088] In the hardware implementation, the division between the functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, one physical component can have multiple functions, or one function or step can be executed by several physical components in cooperation.

[0089] Some or all of the physical components can be implemented as software executed by a processor, such as a central processing unit (CPU), a digital signal processor or a microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, which can include computer storage media (or non-transitory media) and communication media (or transitory media). As is well known to those of ordinary skill in the art, the term computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storage of information such as computer readable instructions, data structures, program modules or other data. Computer storage media includes, but is not limited to, random access memory (RAM, such as SDRAM, DDR, etc.), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory (FLASH) or other magnetic disk storage; compact discs (CD-ROM), digital versatile discs (DVD) or other optical disk storage; magnetic cassettes, magnetic tapes, magnetic disk storage or other magnetic storage; any other medium that can be used to store desired information and can be accessed by a computer. Furthermore, as is well known to those of ordinary skill in the art, communication media typically includes computer readable instructions, data structures, program modules or other data in a modulated data signal such as a carrier wave or other transport mechanism, and can include any information delivery medium.

[0090] In a third aspect, as shown in FIG. 4, an embodiment of the present disclosure provides a computer-readable storage medium, having stored thereon a computer program, which, when executed by a processor, implements any of the privacy policy based permission management methods of the embodiments of the present disclosure.

[0091] In a fourth aspect, an embodiment of the present disclosure provides a computer program product, comprising a computer program, which, when executed by a processor, implements any of the privacy policy based permission management methods of the embodiments of the present disclosure.

[0092] The privacy policy based permission management method, the electronic device and the storage medium in the embodiments of the present disclosure can acquire the management mode of an application program when it is monitored to be started, and manage the sensitive permissions of the application program based on the acquired management mode. The privacy policy based permission management method, the electronic device and the storage medium according to the embodiments of the present disclosure adopt a permission management hierarchical mechanism, which can effectively balance the relationship between user privacy protection and different functions of an application program. The permission management hierarchical mechanism can accurately match the permission granting according to the specific consent of a user, avoiding the violation of the permission of excessive collection of user data, and ensuring the autonomous selection right of a user between privacy protection and function use.

[0093] The present disclosure has disclosed example embodiments, and although specific terms are employed, they are used in the broadest sense and only to only be interpreted as general descriptive purposes and not for limiting purposes. In some instances, it will be apparent to those skilled in the art that features, characteristics and / or elements described in connection with a particular embodiment can be used alone or in combination with other embodiments, unless explicitly stated otherwise. Therefore, those skilled in the art will understand that various changes in form and detail can be made without departing from the scope of the present disclosure as set forth in the appended claims.

Claims

1. A privacy policy based permission management method, comprising: in a case where an application program is monitored to be started, obtaining a management mode of the application program, wherein the management mode comprises a first management mode and a second management mode, the first management mode is set to uniformly authorize sensitive permissions of the application program based on a privacy policy, and the second management mode is set to individually authorize sensitive permissions of each function module of the application program based on a privacy policy; and based on the obtained management mode, managing the sensitive permissions of the application program.

2. The method of claim 1, wherein, Based on the obtained management mode, managing the sensitive permissions of the application program, comprises: in a case where the management mode is the first management mode, obtaining a privacy policy flag of the application program, and in a case where it is determined based on the privacy policy flag that the user has not agreed to the privacy policy, prohibiting the application program from running sensitive permissions described in the privacy policy.

3. The method of claim 1, wherein, Based on the obtained management mode, managing the sensitive permissions of the application program, comprises: in a case where the management mode is the second management mode, obtaining a privacy policy flag of each function module of the application program, and in a case where it is determined based on the privacy policy flag of a first function module that the user has not agreed to the privacy policy, prohibiting the first function module of the application program from running sensitive permissions described in the privacy policy.

4. The method of claim 2, wherein, In a case where it is determined based on the privacy policy flag that the user has not agreed to the privacy policy, prohibiting the application program from running sensitive permissions described in the privacy policy, comprises: determining a permission configuration of the privacy policy; comparing the permission configuration of the privacy policy with a sensitive permission configuration strategy library; and prohibiting the application program from running sensitive permissions in the sensitive permission configuration strategy library corresponding to the permission configuration description of the privacy policy.

5. The method of claim 4, wherein, Determining the permission configuration of the privacy policy comprises: extracting a keyword from the privacy policy, and converting the keyword into a permission configuration.

6. The method of claim 4, wherein, Determining the permission configuration of the privacy policy comprises: obtaining a tag of the application program, the tag being used to identify the privacy policy associated with the application program, and obtaining the permission configuration of the privacy policy based on the tag.

7. The method of claim 3, wherein, In a case where it is determined based on the privacy policy flag of a first function module that the user has not agreed to the privacy policy, prohibiting the first function module of the application program from running sensitive permissions described in the privacy policy, comprises: determining a permission configuration of the privacy policy of the first function module; comparing the permission configuration of the privacy policy of the first function module with a sensitive permission configuration strategy library; and prohibiting the application program from running sensitive permissions in the sensitive permission configuration strategy library corresponding to the permission configuration description of the privacy policy of the first function module.

8. The method of claim 7, wherein, Determining the permission configuration of the privacy policy of the first function module comprises: extracting a keyword from the privacy policy of the first function module, and converting the keyword into a permission configuration; and mapping a relationship of the privacy policy, the first function module and the permission configuration.

9. The method of claim 7, wherein, The permission configuration of the privacy policy of the first function module comprises: obtaining a tag of the first function module, the tag being used to identify the privacy policy associated with the first function module, and obtaining the permission configuration of the privacy policy based on the tag. 10.The method of claim 3, wherein based on the obtained management mode, the sensitive permissions of the application program are managed, comprising: in a case where the management mode is the second management mode and it is determined based on the privacy policy flag of the second function module that the user has not agreed to the privacy policy, the second function module of the application program is prohibited from running the sensitive permissions described in the privacy policy during running of the second function module, wherein the second function module is different from the first function module. 11.The method of claim 3, further comprising: dynamically marking the privacy policy flags of the respective function modules; and based on the dynamically marked privacy policy flags, dynamically managing the sensitive permissions of the respective function modules. based on the dynamically marked privacy policy flags, dynamically managing the sensitive permissions of the respective function modules, comprising:

12. The method of claim 11, wherein, in a case where it is determined based on the privacy policy flag of the first function module that the user has agreed to the privacy policy and it is determined based on the privacy policy flag of a second function module that the user has not agreed to the privacy policy, the second function module of the application program is prohibited from running the sensitive permissions described in the privacy policy during running of the second function module, and the first function module of the application program is allowed to run the sensitive permissions prohibited by the second function module during running of the first function module. in a case where it is monitored that the application program is started, the management mode of the application program is obtained, comprising: in a case where it is detected that the application program has only one privacy policy, it is determined that the management mode of the application program is a first management mode.

13. The method of claim 1, wherein, 14.An electronic device comprising a memory and a processor, wherein the memory stores a computer program executable by the processor, and the computer program is executed by the processor to implement the privacy policy based permission management method of any one of claims 1 to 13. 15.A computer readable storage medium having a computer program stored thereon, wherein the computer program is executed by a processor to implement the privacy policy based permission management method of any one of claims 1 to 13. 16.A computer program product comprising a computer program, wherein the computer program is executed by a processor to implement the privacy policy based permission management method of any one of claims 1 to 13. ​

Citation Information

Patent Citations

  • Android application classification authorization method for quantitative judgment of suspicious behaviors

    CN113326502A

  • Privacy compliance processing system, method and device, storage medium and program product

    CN114580020A

  • Privacy policy processing method, system and device, storage medium and program product

    CN114580021A

  • Information transmission method, system and device, storage medium and program product

    CN114580022A

  • Application starting method and display equipment

    CN116339844A