File access control method, and electronic device

By detecting the risks associated with the device access permissions of electronic devices and adjusting file access permissions to address security risks in different scenarios, this approach solves the problem of a single file access control scheme in existing technologies, achieving more efficient file security and flexible access control.

WO2026108581A1PCT designated stage Publication Date: 2026-05-28HUAWEI TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
HUAWEI TECH CO LTD
Filing Date
2025-10-31
Publication Date
2026-05-28

AI Technical Summary

Technical Problem

Existing file access control schemes are relatively simple and cannot effectively prevent file leakage risks in different scenarios. Users can open files after entering the correct password, and the security of the environment cannot be guaranteed.

Method used

By detecting risks associated with device access permissions on electronic devices, including risks related to unauthorized access, connection status, network environment, and geographical location, file access permissions can be adjusted to restrict access when risks escalate, thereby ensuring file security.

Benefits of technology

When a file is open, promptly adjust file access permissions to address increased risks, improve the security and flexibility of file access, and prevent file leaks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025131921_28052026_PF_FP_ABST
    Figure CN2025131921_28052026_PF_FP_ABST
Patent Text Reader

Abstract

The present application provides a file access control method, and an electronic device. In the method, in response to a first operation performed by a user on an opened first file, a device usage permission risk of a first electronic device is detected, and first security status information of the first electronic device is determined. The device usage permission risk comprises at least one of a device privilege-escalation risk, a connection status risk, a network environment risk, or a geographic location risk. When the device usage permission risk of the first electronic device indicated by the first security status information increases, a file access permission of the first file is adjusted to a restricted file access permission, the restricted file access permission being restricted compared to the file access permission of the first file before the user performs the first operation. By means of the described solution, when a file is opened, if the device usage risk of the electronic device increases, the file access permission of the file can be promptly adjusted, thereby ensuring the security of the file.
Need to check novelty before this filing date? Find Prior Art

Description

A file access control method and electronic device

[0001] Cross-references to related applications

[0002] This application claims priority to Chinese Patent Application No. 202411693432.5, filed on November 22, 2024, entitled "A File Access Control Method and Electronic Device", the entire contents of which are incorporated herein by reference. Technical Field

[0003] This application relates to the field of Internet technology, and in particular to a file access control method and electronic device. Background Technology

[0004] In corporate office settings, file security is of paramount importance. The leakage of important files can have serious consequences, and setting file access control permissions is an important means of ensuring file security.

[0005] In some scenarios, users can set file access permissions, such as adding a password. When other users open the file, they need to enter the password. After the electronic device confirms the correct password, it can display the file content. However, while this method allows users to open the file simply by entering the correct password, it doesn't guarantee the security of the current environment, and the risk of file leakage remains significant. For another example, users can set a file to read-only mode, allowing other users to only view the file and not modify its content. However, this access control method is relatively simple and cannot prevent file leakage risks in different scenarios.

[0006] In summary, current file access control schemes are relatively simple and lack sufficient ability to prevent risks. Summary of the Invention

[0007] This application provides a file access control method and an electronic device to improve the security of file access.

[0008] Firstly, this application provides a file access control method, which can be executed by a first electronic device. The method includes: in response to a user's first operation on an already opened first file, detecting a device access permission risk of the first electronic device and determining first security status information of the first electronic device; the device access permission risk includes at least one of device unauthorized access risk, connection status risk, network environment risk, or geographical location risk; when the device access permission risk of the first electronic device indicated by the first security status information is increased, adjusting the file access permission of the first file to a restricted file access permission, wherein the restricted file access permission is less restrictive than the file access permission of the first file before the user performed the first operation.

[0009] In the above method, when a user performs the first operation on the first opened file, the electronic device can detect the risk of device access permissions to determine the current security status of the electronic device. If the risk of device access increases, the file access permissions of the first file will be adjusted to more restricted file access permissions. This ensures that if the risk of device access increases while the file is open, the file access permissions can be adjusted in a timely manner to ensure file security.

[0010] In one possible design, after adjusting the file access permission of the first file to restricted file access permission, while the first file is still open, the method further includes: when the device usage permission risk of the first electronic device indicated by the first security status information decreases, adjusting the file access permission of the first file to upgraded file access permission. With this design, if the first electronic device detects a decrease in the device usage permission risk when the first file is open, the first electronic device can relax the file access permission of the first file to ensure a better file access experience for the user.

[0011] In one possible design, the first file remaining open includes either the open first file not being closed, or the open first file being closed and then reopened. Through this design, this application can adjust the file access permissions for a first file that remains open and unclosed, as well as the file access permissions for a first file that has been closed and then reopened, thereby providing file access permission control schemes for various scenarios.

[0012] In one possible design, if the file access permission of the first file is restricted to allow read-only access before the user performs the first operation, the restricted file access permission is to prohibit opening the file; or if the file access permission of the first file is restricted to allow editing before the user performs the first operation, the restricted file access permission is to allow read-only access or prohibit opening the file; or if the file access permission of the first file is restricted to allow screen casting, screen recording, or screen sharing before the user performs the first operation, the restricted file access permission is to prohibit screen casting, screen recording, or screen sharing.

[0013] In one possible design, when the restricted file access permission is set to "prohibit opening files," after adjusting the file access permission of the first file to restricted file access permission, the method further includes: performing at least one of the following response actions: closing the first file, displaying a risk warning message, or displaying a mask on the display interface; wherein the risk warning message is used to remind the user that the first electronic device currently poses a risk and suggests that the user close the first file. Through this design, when the first electronic device needs to adjust the file access permission of the first file to "prohibit opening files," it can perform at least one of the following response actions: closing the first file, displaying a risk warning message, or displaying a mask, to promptly manage the opened first file and prevent file leakage.

[0014] In one possible design, the method further includes: responding to a second user operation, obtaining second security status information of the second electronic device, wherein the second operation is an operation performed on the first file and associated with the second electronic device, and the second security status information is used to indicate the device access permission risk of the second electronic device; determining, based on the second security status information, that the device access permission risk of the second electronic device meets the device security status requirements of the receiving electronic device; and executing a response action corresponding to the second operation, wherein the response action is a response action used to manage the first file. Through this design, when a user performs a second operation related to the second electronic device on the first file, the first electronic device can verify the device access permission risk of the second electronic device. After determining that the device access permission risk of the second electronic device meets the device security status requirements of the receiving electronic device, the response action corresponding to the second operation is executed, thereby confirming the security of the receiving device before file sharing, further ensuring the security of file access.

[0015] In one possible design, the second operation is used to send the first file to the second electronic device, or the second operation is used to project the screen to the second electronic device while displaying the first file, or the second operation is used to share the screen to the second electronic device while displaying the first file.

[0016] In one possible design, the response action corresponding to performing the second operation includes: sending the first file to the second electronic device; or projecting the screen to the second electronic device while displaying the first file; or sharing the screen to the second electronic device while displaying the first file.

[0017] With the above design, when a user triggers the sending of a first file to a second electronic device, or when the first file is displayed and the user projects or shares the screen to the second electronic device, the first electronic device can first verify the device access rights risk of the second electronic device before executing the response action corresponding to the second operation, so as to ensure the security of the shared file.

[0018] In one possible design, the method further includes: in response to a third operation by the user on an already opened second file, when the device access risk of the first electronic device indicated by the first security status information is increased, adjusting the file access permission of the second file to a restricted file access permission. The adjusted file access permission of the second file is different from the restricted file access permission of the second file before the user performed the third operation, and the adjusted file access permission of the second file is different from the adjusted file access permission of the first file. Through this design, the first electronic device can adjust the file access permission for different files differently, thereby achieving differentiated management of different files to meet the user's risk control needs for various types of files.

[0019] In one possible design, the file access permissions for the first file include at least one of the following: prohibiting opening the file, prohibiting file transfer, allowing read-only access to the file, allowing file editing, allowing access to the file after successful authentication, prohibiting screen mirroring, prohibiting screen recording, and prohibiting screen sharing. Through this design, this application provides multiple configurable file access permissions to meet the file risk management needs in different scenarios.

[0020] Secondly, this application also provides a file access control method, which can be executed by a first electronic device. The method includes: in response to a fourth operation by a user, detecting a device privilege escalation risk of the first electronic device and determining third security status information of the first electronic device, wherein the fourth operation is used to open a first file, and the device privilege escalation risk includes the risk of exceeding the scope of the first device's usage permissions, the scope of the first device's usage permissions being the scope of device usage permissions authorized to the user account logged in on the first electronic device; when the third security status information indicates that the first electronic device has a device privilege escalation risk, adjusting the file access permission of the first file to a restricted file access permission, the restricted file access permission being more restricted than the file access permission of the first file before the user performed the fourth operation.

[0021] In the above method, when a user triggers the opening of the first file on the first electronic device, the first electronic device can perform device privilege escalation risk detection to determine whether the first electronic device is trustworthy. If the first electronic device has a device privilege escalation risk, the first electronic device can adjust the file access permission of the first file to a restricted file access permission to ensure file security.

[0022] In one possible design, the third security status information further includes the detection result of at least one of the following risk detection methods: connection status risk detection, network environment risk detection, or geographical location risk detection. The restricted file access permissions are determined based on the detection result of at least one of these risk detection methods. Through this design, the first electronic device can also perform at least one of these risk detection methods, thereby detecting device access permission risks from multiple risk factors and further ensuring the security of file access.

[0023] In one possible design, after adjusting the file access permissions of the first file to restricted file access permissions, the method further includes: detecting the device usage permission risks of the first electronic device at a preset period to determine a fourth security status information of the first electronic device; the device usage permission risks include at least one of device unauthorized access risks, connection status risks, network environment risks, or geographical location risks; and adjusting the file access permissions of the first file when the security status of the first electronic device changes based on the fourth security status information. Through this design, the first electronic device can continuously detect device usage permission risks while the first file is open. When the security status of the first electronic device changes, it can promptly adjust file access permissions, ensuring that the first electronic device can respond to security events in a timely manner and further improving the security of file access.

[0024] In one possible design, after adjusting the file access permissions of the first file, the method further includes: performing at least one of the following response actions: closing the first file, displaying a risk warning message, or displaying a mask on the display interface; wherein the risk warning message is used to remind the user that the first electronic device is currently at risk and to suggest that the user close the first file. With this design, if the security status of the first electronic device changes, the first electronic device can perform at least one of the following response actions: closing the first file, displaying a risk warning message, or displaying a mask, to promptly manage the opened first file and prevent file leakage.

[0025] In one possible design, the method further includes: in response to a second operation by a user, obtaining second security status information of the second electronic device, the second operation being an operation performed on the file and associated with the second electronic device, the second security status information being used to indicate the device usage permission risk of the second electronic device; determining, based on the second security status information, that the device usage permission risk of the second electronic device meets the device security status requirements for the receiving electronic device; and executing a response action corresponding to the second operation, the response action being a response action used to manage the first file.

[0026] In one possible design, the second operation is used to send the first file to the second electronic device, or the second operation is used to project the screen to the second electronic device while displaying the first file, or the second operation is used to share the screen to the second electronic device while displaying the first file.

[0027] In one possible design, the response action corresponding to performing the second operation includes: sending the first file to the second electronic device; or projecting the screen to the second electronic device while displaying the first file; or sharing the screen to the second electronic device while displaying the first file.

[0028] In one possible design, the file access permissions for the first file include at least one of the following: prohibiting opening the file, prohibiting file transfer, allowing read-only access to the file, allowing file editing, allowing access to the file after successful authentication, prohibiting screen mirroring, prohibiting screen recording, and prohibiting screen sharing.

[0029] Thirdly, this application provides an electronic device comprising multiple functional modules; the multiple functional modules interact to implement the methods performed by the electronic device in any of the above aspects and their respective embodiments. The multiple functional modules can be implemented based on software, hardware, or a combination of software and hardware, and the multiple functional modules can be arbitrarily combined or divided based on specific implementations.

[0030] Fourthly, this application provides an electronic device including at least one processor and at least one memory, wherein the at least one memory stores computer program instructions, and when the electronic device is running, the at least one processor executes any of the above aspects and the methods executed by the electronic device in its various embodiments.

[0031] Fifthly, this application also provides a computer program product containing instructions that, when the computer program product is run on a computer, cause the computer to perform the method executed by the electronic device in any of the above aspects and embodiments.

[0032] Sixthly, this application also provides a computer-readable storage medium storing a computer program that, when executed by a computer, causes the computer to perform the method executed by the electronic device in any of the above aspects and embodiments.

[0033] In a seventh aspect, this application also provides a chip for reading a computer program stored in a memory and executing the method executed by the electronic device in any of the above aspects and embodiments.

[0034] Eighthly, this application also provides a chip system including a processor for supporting a computer device in implementing the methods executed by electronic devices in any of the above aspects and their embodiments. In one possible design, the chip system further includes a memory for storing programs and data necessary for the computer device. The chip system may be composed of chips or may include chips and other discrete devices. Attached Figure Description

[0035] Figure 1 is a schematic diagram of a scenario in which a file access control method provided in an embodiment of this application is applicable;

[0036] Figure 2 is a schematic diagram of the structure of an electronic device provided in an embodiment of this application;

[0037] Figure 3 is a software structure block diagram of an electronic device provided in an embodiment of this application;

[0038] Figure 4 is a schematic diagram of a file access permission control method provided in an embodiment of this application;

[0039] Figure 5 is a schematic diagram of a file access control method provided in an embodiment of this application;

[0040] Figure 6 is a schematic diagram of the architecture of a file access control system provided in an embodiment of this application;

[0041] Figure 7 is a flowchart of a file access control method provided in an embodiment of this application;

[0042] Figure 8 is a flowchart of a file access control method provided in an embodiment of this application. Detailed Implementation

[0043] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the embodiments of this application will be further described in detail below with reference to the accompanying drawings. In the description of the embodiments of this application, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Therefore, a feature defined with "first" and "second" may explicitly or implicitly include one or more of that feature.

[0044] It should be understood that in the embodiments of this application, "at least one" means one or more, and "more than one" means two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can represent: a, b, c, a and b, a and c, b and c, or a, b, and c, where a, b, and c can be single or multiple.

[0045] File security is a critical issue in current enterprise office settings, but existing file access control solutions are relatively simple, such as allowing users to set file passwords or set file permissions to read-only. These solutions suffer from limited consideration of factors and insufficient risk prevention capabilities.

[0046] To address the aforementioned issues, this application provides a file access control method. Figure 1 illustrates a scenario applicable to the file access control method provided in this application. Referring to Figure 1, the scenario may include a server and at least one electronic device. The server can be implemented using a computing device cluster, which may include at least one computing device. The server can be used to manage at least one electronic device. For example, the server can issue file management policies to at least one electronic device. At least one electronic device can store the received file management policies. Upon responding to a user-triggered file opening operation, any electronic device performs risk detection and access control based on the file management policy. Furthermore, the electronic device can continuously monitor the file access environment during the user's file usage and promptly control file access permissions based on file management monitoring.

[0047] In this embodiment, when an electronic device manages file access permissions according to a file management policy, the electronic device can perform risk detection and file access permission control based on file management measurement and control. In response to a user's first operation on an already opened first file, the electronic device detects the risk of its device access permissions and determines its first security status information. This device access permission risk detection may include at least one of the following: device unauthorized access risk, connection status risk, network environment risk, or geographical location risk. When the first security status information indicates that the device access permission risk has increased, the electronic device adjusts the file access permission of the first file to a restricted file access permission. This restricted file access permission is more restricted than the file access permission of the first file before the user performed the first operation. Through this scheme, when a user performs a first operation on an already opened first file, the electronic device can detect the risk of its device access permissions to determine its current security status information. If the device access risk has increased, the file access permission of the first file is adjusted to a more restricted file access permission. This ensures that even when a file is open, if the device access risk increases, the file access permission can be adjusted promptly, thereby ensuring file security.

[0048] The following describes an electronic device and embodiments for using such an electronic device. The electronic device in this application embodiment includes a touchscreen, such as a foldable full-touchscreen laptop, tablet, mobile phone, in-vehicle device, augmented reality (AR) / virtual reality (VR) device, ultra-mobile personal computer (UMPC), netbook, personal digital assistant (PDA), wearable device, etc. This application embodiment does not limit the specific type of electronic device.

[0049] In some embodiments of this application, the electronic device may also be a portable terminal device that includes other functions such as a personal digital assistant and / or a music player. Exemplary embodiments of the portable terminal device include, but are not limited to, devices equipped with... Or portable terminal devices with other operating systems.

[0050] Figure 2 is a schematic diagram of the structure of an electronic device 100 provided in an embodiment of this application. As shown in Figure 2, the electronic device 100 may include a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, a headphone jack 170D, a sensor module 180, buttons 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and a subscriber identification module (SIM) card interface 195, etc.

[0051] Processor 110 may include one or more processing units, such as an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural network processing unit (NPU). Different processing units may be independent devices or integrated into one or more processors. The controller may serve as the central nervous system and command center of the electronic device 100. The controller can generate operation control signals based on instruction opcodes and timing signals to control instruction fetching and execution. Processor 110 may also include memory for storing instructions and data. In some embodiments, the memory in processor 110 is a cache memory. This memory can store instructions or data that processor 110 has recently used or is repeatedly used. If processor 110 needs to reuse an instruction or data, it can directly retrieve it from the memory. This avoids repeated access, reduces the waiting time of processor 110, and thus improves system efficiency.

[0052] USB interface 130 is a USB standard compliant interface, specifically a Mini USB interface, Micro USB interface, USB Type-C interface, etc. USB interface 130 can be used to connect a charger to charge electronic device 100, and can also be used for data transfer between electronic device 100 and peripheral devices. Charging management module 140 receives charging input from the charger. Power management module 141 connects battery 142, charging management module 140, and processor 110. Power management module 141 receives input from battery 142 and / or charging management module 140, providing power to processor 110, internal memory 121, external memory, display 194, camera 193, and wireless communication module 160, etc.

[0053] The wireless communication function of electronic device 100 can be implemented through antenna 1, antenna 2, mobile communication module 150, wireless communication module 160, modem processor, and baseband processor. Antenna 1 and antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in electronic device 100 can be used to cover one or more communication frequency bands. Different antennas can also be multiplexed to improve antenna utilization. For example, antenna 1 can be multiplexed as a diversity antenna for a wireless local area network. In some other embodiments, the antennas can be used in conjunction with tuning switches.

[0054] The mobile communication module 150 can provide solutions for wireless communication, including 2G / 3G / 4G / 5G, applied to the electronic device 100. The mobile communication module 150 may include at least one filter, switch, power amplifier, low noise amplifier (LNA), etc. The mobile communication module 150 can receive electromagnetic waves via antenna 1, and perform filtering, amplification, and other processing on the received electromagnetic waves before transmitting them to a modem processor for demodulation. The mobile communication module 150 can also amplify the signal modulated by the modem processor and convert it into electromagnetic waves for radiation via antenna 1. In some embodiments, at least some functional modules of the mobile communication module 150 may be housed in the processor 110. In some embodiments, at least some functional modules of the mobile communication module 150 and at least some modules of the processor 110 may be housed in the same device.

[0055] The wireless communication module 160 can provide solutions for wireless communication applications on the electronic device 100, including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), and infrared (IR) technologies. The wireless communication module 160 can be one or more devices integrating at least one communication processing module. The wireless communication module 160 receives electromagnetic waves via antenna 2, performs frequency modulation and filtering of the electromagnetic wave signals, and sends the processed signal to processor 110. The wireless communication module 160 can also receive signals to be transmitted from processor 110, perform frequency modulation and amplification, and convert them into electromagnetic waves for radiation via antenna 2.

[0056] In some embodiments, antenna 1 of electronic device 100 is coupled to mobile communication module 150, and antenna 2 is coupled to wireless communication module 160, enabling electronic device 100 to communicate with networks and other devices via wireless communication technology. The wireless communication technology may include Global System for Mobile Communications (GSM), General Packet Radio Service (GPRS), Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), Time-Division Code Division Multiple Access (TD-SCDMA), Long Term Evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technologies, etc. The GNSS may include the Global Positioning System (GPS), the Global Navigation Satellite System (GLONASS), the BeiDou Navigation Satellite System (BDS), the Quasi-Zenith Satellite System (QZSS), and / or satellite-based augmentation systems (SBAS).

[0057] The display screen 194 is used to display the display interface of an application, such as the display page of an application installed on the electronic device 100. The display screen 194 includes a display panel. The display panel can be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a MiniLED, a MicroLED, a Micro-OLED, a quantum dot light-emitting diode (QLED), etc. In some embodiments, the electronic device 100 may include one or N display screens 194, where N is a positive integer greater than 1.

[0058] Camera 193 is used to capture still images or videos. An object is projected onto a photosensitive element by generating an optical image through the lens. The photosensitive element can be a charge-coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the light signal into an electrical signal, which is then passed to an ISP for conversion into a digital image signal. The ISP outputs the digital image signal to a DSP for processing. The DSP converts the digital image signal into image signals in standard RGB, YUV, or other formats. In some embodiments, the electronic device 100 may include one or N cameras 193, where N is a positive integer greater than 1.

[0059] Internal memory 121 can be used to store computer executable program code, which includes instructions. Processor 110 executes various functional applications and data processing of electronic device 100 by running the instructions stored in internal memory 121. Internal memory 121 may include a program storage area and a data storage area. The program storage area may store the operating system and software code for at least one application program. The data storage area may store data generated during the use of electronic device 100 (e.g., captured images, recorded videos, etc.). Furthermore, internal memory 121 may include high-speed random access memory and may also include non-volatile memory, such as at least one disk storage device, flash memory device, universal flash storage (UFS), etc.

[0060] The external storage interface 120 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the electronic device. The external memory card communicates with the processor 110 through the external storage interface 120 to perform data storage functions. For example, images, videos, and other files can be saved on the external memory card.

[0061] Electronic device 100 can implement audio functions, such as music playback and recording, through audio module 170, speaker 170A, receiver 170B, microphone 170C, headphone jack 170D, and application processor.

[0062] The sensor module 180 may include a pressure sensor 180A, an acceleration sensor 180B, a touch sensor 180C, etc.

[0063] The pressure sensor 180A is used to sense pressure signals and can convert the pressure signals into electrical signals. In some embodiments, the pressure sensor 180A may be disposed on the display screen 194.

[0064] Touch sensor 180C, also known as a "touch panel," can be located on display screen 194. The touch sensor 180C and display screen 194 together form a touchscreen, also known as a "touch screen." Touch sensor 180C detects touch operations applied to or near it. The touch sensor can transmit the detected touch operation to the application processor to determine the type of touch event. Visual output related to the touch operation can be provided through display screen 194. In other embodiments, touch sensor 180C may also be located on the surface of electronic device 100, in a different position than display screen 194.

[0065] Buttons 190 include a power button, volume buttons, etc. Buttons 190 can be mechanical buttons or touch buttons. Electronic device 100 can receive button inputs and generate key signal inputs related to user settings and function control. Motor 191 can generate vibration alerts. Motor 191 can be used for incoming call vibration alerts or for touch vibration feedback. For example, touch operations applied to different applications (such as taking photos, audio playback, etc.) can correspond to different vibration feedback effects. Touch vibration feedback effects can also be customized. Indicator 192 can be an indicator light, used to indicate charging status, battery level changes, or to indicate messages, missed calls, notifications, etc. SIM card interface 195 is used to connect a SIM card. The SIM card can be inserted into or removed from the SIM card interface 195 to achieve contact and separation with electronic device 100.

[0066] It is understood that the components shown in Figure 2 do not constitute a specific limitation on the electronic device 100. The electronic device may include more or fewer components than shown, or combine some components, or separate some components, or have different component arrangements. Furthermore, the combination / connection relationships between the components in Figure 2 can also be adjusted and modified.

[0067] Figure 3 is a software structure block diagram of an electronic device provided in an embodiment of this application. As shown in Figure 3, the software structure of the electronic device can be a layered architecture. For example, the software can be divided into several layers, each with a clear role and division of labor. The layers communicate with each other through software interfaces. In some embodiments, the operating system is divided into four layers, from top to bottom: the application layer, the application framework layer (framework, FWK), the runtime and system libraries, and the kernel layer.

[0068] The application layer can include a series of application packages. As shown in Figure 3, the application layer can include camera, settings, skin modules, user interface (UI), third-party applications, etc. Third-party applications can include gallery, calendar, call, map, navigation, WLAN, Bluetooth, music, video, SMS, etc.

[0069] The application framework layer provides application programming interfaces (APIs) and a programming framework for applications in the application layer. The application framework layer can include some predefined functions. As shown in Figure 3, the application framework layer can include a window manager, content provider, view system, phone manager, resource manager, and notification manager.

[0070] The window manager is used to manage windowed applications. It can obtain the screen size, determine if a status bar is present, lock the screen, and capture screenshots. The content provider stores and retrieves data, making this data accessible to applications. This data may include videos, images, audio, made and received phone calls, browsing history and bookmarks, phone books, etc.

[0071] A view system includes visual controls, such as controls for displaying text and controls for displaying images. View systems can be used to build applications. A display interface can consist of one or more views. For example, a display interface including a text notification icon could include views for displaying text and views for displaying images.

[0072] A phone manager is used to provide communication functions for electronic devices. For example, it manages call status (including connection and disconnection).

[0073] The file explorer provides applications with various resources, such as localized strings, icons, images, layout files, video files, and more.

[0074] The notification manager allows applications to display notifications in the status bar. These notifications can be used to deliver informational messages and can disappear automatically after a short pause, requiring no user interaction. For example, the notification manager can be used to notify users of completed downloads or message alerts. The notification manager can also display notifications as icons or scrolling text in the top status bar, such as notifications from background applications, or as dialog boxes on the screen. Examples include displaying text messages in the status bar, emitting sounds, vibrating electronic devices, and flashing indicator lights.

[0075] The runtime includes the core libraries and the virtual machine. The runtime is responsible for the scheduling and management of the operating system.

[0076] The core library consists of two parts: one part contains the functionalities that the Java language needs to call, and the other part contains the core libraries of the operating system. The application layer and application framework layer run in the virtual machine. The virtual machine executes the Java files of the application layer and application framework layer as binary files. The virtual machine is used to perform functions such as object lifecycle management, stack management, thread management, security and exception management, and garbage collection.

[0077] System libraries can include multiple functional modules. For example: surface manager, media libraries, 3D graphics processing libraries (e.g., OpenGL ES), 2D graphics engines (e.g., SGL), image processing libraries, etc.

[0078] The Surface Manager is used to manage the display subsystem and provides the blending of 2D and 3D layers for multiple applications.

[0079] The media library supports playback and recording of various common audio and video formats, as well as still image files. It supports multiple audio and video encoding formats, such as MPEG4, H.264, MP3, AAC, AMR, JPG, and PNG.

[0080] The 3D graphics processing library is used to implement 3D graphics drawing, image rendering, compositing, and layer processing.

[0081] A 2D graphics engine is a graphics engine for 2D drawing.

[0082] The kernel layer is the layer between hardware and software. The kernel layer contains at least the display driver, camera driver, audio driver, and sensor driver.

[0083] The hardware layer can include various types of sensors, such as accelerometers, gyroscopes, and touch sensors.

[0084] It should be noted that the structures shown in Figures 2 and 3 are merely examples of electronic devices provided in the embodiments of this application, and cannot be used to limit the electronic devices provided in the embodiments of this application. In specific implementations, electronic devices may have more or fewer devices or modules than those shown in Figures 2 or 3.

[0085] The file access control method provided in the embodiments of this application is described below.

[0086] In the file access control method provided in this application embodiment, a file management policy can be deployed on the server. This file management policy can be a system-preconfigured policy or a user-defined policy. Optionally, the file management policy can be configured according to at least one of file security level, protection scenario, or access permission. For example, the file management policy may include: "Files with the highest security level can only be accessed in read-only mode when the user is not in administrator privileges, not in debug mode, and when the USB port is not open," and "Files with lower security levels are allowed to be accessed after user authentication."

[0087] Optionally, in this embodiment, the enterprise administrator can customize file control policies. After the enterprise administrator uploads the file access policies to the server, the server can distribute the file access policies to at least one electronic device, which is an electronic device managed by the server. In this way, the server can distribute the deployed file access policies to at least one electronic device managed by the server, so that at least one electronic device can ensure the security of file access in accordance with the file access policies.

[0088] In this embodiment of the application, when a user triggers the operation of opening a file on any of the above-mentioned at least one electronic device, the electronic device responds to the user's operation and can detect the device usage permission risk of the electronic device to obtain the third security status information of the electronic device. The device usage permission risk may include at least one of the following: device unauthorized access risk, connection status risk, network environment risk, or geographical location risk. The third security status information may include the detection result corresponding to at least one risk factor.

[0089] In one optional implementation, when performing risk detection, the electronic device can detect the risk of unauthorized access. The third security status information includes the detection result corresponding to this risk. This unauthorized access risk includes the risk of exceeding the scope of the first device usage permissions, which is the scope of device usage permissions authorized to the user account logged into the electronic device. For example, after logging into the electronic device, the user account can be authorized to use the permissions of the electronic device. If the first device usage permissions can be the scope of ordinary user permissions, detecting the unauthorized access risk includes detecting whether the electronic device has exceeded its permissions from ordinary user permissions to administrator (root) permissions. When the electronic device is in ordinary user permissions, it can be said to be in a non-root state; when it is in administrator permissions, it can be said to be in a root state. When the electronic device is in a non-root state, the user can usually only perform operations that affect their own user space, such as managing personal files and using authorized software. However, when the electronic device is in a root state, the user can perform any operation on the electronic device, including modifying system files, installing software, and managing system servers. Therefore, when the electronic device has an unauthorized access risk, it indicates that the environment in which the electronic device accesses files is relatively insecure.

[0090] Furthermore, the risk detection performed by the electronic device may include at least one of connection status risk detection, network environment risk detection, and geographical location risk detection. Therefore, the third security status information may include the detection result of at least one of these risk detection methods. Specifically, connection status risk detection is used to detect whether the electronic device is connected to other electronic devices or equipment, such as detecting whether the USB port of the electronic device is turned on; network environment risk detection is used to detect the current network status of the electronic device, such as detecting whether the electronic device is currently connected to an internal or external network; and geographical location risk detection is used to detect the current geographical location information of the electronic device, such as determining whether the electronic device is located within a preset office area based on its current geographical location information.

[0091] Through the above embodiments, when a user triggers an operation related to the first file, the electronic device can perform risk detection. Only when it is determined that the electronic device does not pose an unauthorized risk, i.e., the electronic device is trustworthy, can other risk factors be detected. This prevents the problem of inaccurate risk detection caused by obtaining tampered attribute information when the electronic device is untrustworthy. In addition, in this embodiment, the electronic device can store file management policies and perform risk detection and access control locally, thereby preventing the increase of data interaction costs during the process of file management of the electronic device through the server, and reducing the risks generated during the interaction with the server.

[0092] In another optional implementation, when performing risk detection, the electronic device can also determine third security status information based on at least one risk factor, such as a risk level. The at least one risk factor can include at least one of device unauthorized access risk, connection status risk, network environment risk, and geographical location risk. Optionally, the electronic device can determine its risk level based on a risk detection model. For example, the electronic device can input at least one risk factor into the risk detection model and obtain the risk level output by the model.

[0093] In this embodiment, the electronic device can determine the file access permissions of the first file based on a file management policy according to third security status information. Optionally, when the third security status information indicates that the risk of the electronic device's device usage permissions has increased, the electronic device adjusts the file access permissions of the first file to restricted file access permissions. The restricted file access permissions are more restrictive than the file access permissions of the first file before the user performed the first operation. In this embodiment, file access permissions may include: prohibiting opening files, prohibiting file transfer, allowing read-only access to files, allowing file editing, allowing access to files after successful authentication, prohibiting screen mirroring, prohibiting screen recording, and prohibiting screen sharing. Successful authentication may include authentication of the user account logged into the electronic device and authentication of the user's biometric information.

[0094] For example, if the file access permissions of the first file were set to allow read-only access before the user performed the first operation, the restricted file access permissions of the first file after the adjustment will be set to prohibit opening the file; or if the file access permissions of the first file were set to allow editing before the user performed the first operation, the restricted file access permissions of the first file after the adjustment will be set to allow read-only access or prohibit opening the file; or if the file access permissions of the first file were set to allow screen casting, screen recording, or screen sharing before the user performed the first operation, the restricted file access permissions of the first file after the adjustment will be set to prohibit screen casting, screen recording, or screen sharing.

[0095] Optionally, when the third security status information indicates that the risk of the electronic device's access permissions has decreased, the electronic device adjusts the file access permissions of the first file to an upgraded file access permission, wherein the upgraded file access permission is higher than the original file access permission. For example, the original file access permission of the first file allowed read-only access, while the upgraded file access permission allows editing; or the original file access permission of the first file prohibited screen casting, screen recording, or screen sharing, while the upgraded file access permission allows screen casting, screen recording, or screen sharing.

[0096] In this embodiment, when a first file is already open on the electronic device, and the user triggers a first operation related to the first file on the electronic device, the electronic device, in response to the user's first operation, can detect the device access permission risk and obtain the first security status information of the electronic device. The device access permission risk may include at least one of the following: device unauthorized access risk, connection status risk, network environment risk, or geographical location risk. The first security status information may include the detection result corresponding to at least one risk factor. It should be noted that "the first file is already open on the electronic device" can mean that the electronic device opened the first file and did not close it, or it can mean that the electronic device closed the first file and then reopened it.

[0097] In one optional implementation, when performing device access permission risk detection, the electronic device can detect the risk of unauthorized access. The first security status information includes the detection result corresponding to the unauthorized access risk. This unauthorized access risk includes the risk of exceeding the scope of the first device access permission, which is the scope of device access permission authorized to the user account logged into the electronic device. For example, after logging into a user account on the electronic device, the user account can be authorized to use the permissions of the electronic device. If the first device access permission scope can be the scope of ordinary user permissions, detecting the unauthorized access risk includes detecting whether the electronic device has exceeded its permissions from ordinary user permissions to administrator (root) permissions. When the electronic device is in ordinary user permissions, it can be said to be in a non-root state; when it is in administrator permissions, it can be said to be in a root state. When the electronic device is in a non-root state, the user can usually only perform operations that affect their own user space, such as managing personal files and using authorized software. However, when the electronic device is in a root state, the user can perform any operation on the electronic device, including modifying system files, installing software, and managing system servers. Therefore, when the electronic device has an unauthorized access risk, it indicates that the environment in which the electronic device accesses files is relatively insecure.

[0098] Furthermore, the risk detection performed by the electronic device may include at least one of connection status risk detection, network environment risk detection, and geographical location risk detection. Therefore, the first security status information may include the detection result of at least one of these risk detection methods. Specifically, connection status risk detection is used to detect whether the electronic device is connected to other electronic devices or equipment, such as detecting whether the USB port of the electronic device is turned on; network environment risk detection is used to detect the current network status of the electronic device, such as detecting whether the electronic device is currently connected to an internal or external network; and geographical location risk detection is used to detect the current geographical location information of the electronic device, such as determining whether the electronic device is located within a preset office area based on its current geographical location information.

[0099] Through the above embodiments, when a user triggers an operation related to the first file, the electronic device can perform risk detection. Only when it is determined that the electronic device does not pose an unauthorized risk, i.e., the electronic device is trustworthy, can other risk factors be detected. This prevents the problem of inaccurate risk detection caused by obtaining tampered attribute information when the electronic device is untrustworthy. In addition, in this embodiment, the electronic device can store file management policies and perform risk detection and access control locally, thereby preventing the increase of data interaction costs during the process of file management of the electronic device through the server, and reducing the risks generated during the interaction with the server.

[0100] In another optional implementation, when performing device access permission risk detection, the electronic device can also determine first security status information based on at least one risk factor, such as a risk level. The at least one risk factor may include at least one of device unauthorized access risk, connection status risk, network environment risk, and geographical location risk. Optionally, the electronic device can determine its risk level based on a risk detection model. For example, the electronic device can input at least one risk factor into the risk detection model and obtain the risk level output by the model.

[0101] After obtaining the first security status information, if the risk of the electronic device's access permissions indicated by the first security status information increases, the electronic device can adjust the file access permission of the first file to a restricted access permission. The restricted file access permission is more restrictive than the file access permission of the first file before the user performed the first operation. In this embodiment, file access permissions may include: prohibiting opening files, prohibiting file transfer, allowing read-only access to files, allowing file editing, allowing access to files after successful authentication, prohibiting screen mirroring, prohibiting screen recording, and prohibiting screen sharing. Successful authentication may include authentication of the user account logged into the electronic device and authentication of the user's biometric information.

[0102] For example, if the file access permissions of the first file were restricted to read-only access before the user performed the first operation, the adjusted restricted file access permissions of the first file will be to prohibit opening the file; or if the file access permissions of the first file were restricted to editable access before the user performed the first operation, the adjusted restricted file access permissions of the first file will be to allow read-only access or prohibit opening the file; or if the file access permissions of the first file were restricted to screen mirroring, screen recording, or screen sharing before the user performed the first operation, the adjusted restricted file access permissions of the first file will be to prohibit screen mirroring, screen recording, or screen sharing.

[0103] Optionally, when the first security status information indicates that the risk of device access permissions for the electronic device has decreased, the electronic device adjusts the file access permissions of the first file to an upgraded file access permission, wherein the upgraded file access permission is higher than the original file access permission. For example, the original file access permission for the first file was read-only access, while the upgraded file access permission allows editing; or the original file access permission for the first file was prohibiting screen casting, screen recording, or screen sharing, while the upgraded file access permission allows screen casting, screen recording, or screen sharing.

[0104] In some scenarios applicable to the embodiments of this application, after a user opens the first file with an electronic device, the user may leave the current location with the electronic device, or the network status of the electronic device may change, or the electronic device may be attacked. In such cases, the risk of access permissions of the electronic device may change. Through the solution provided by the above embodiments of this application, it is ensured that if the risk of access permissions of the electronic device increases or decreases while the file is open, the electronic device can adjust the file access permissions of the file in a timely manner, thereby ensuring file security.

[0105] In this embodiment, when a second file is opened on an electronic device, in response to a third operation by the user on the opened second file, the electronic device performs a device permission risk detection to obtain first security status information. When the first security status information indicates an increased risk to the device's access permissions, the electronic device adjusts the file access permissions of the second file to restricted file access permissions. The adjusted file access permissions of the second file are different from the restricted file access permissions of the first file before the user performed the third operation. Optionally, in this embodiment, the file access permissions determined by the electronic device may be the same or different for different files. For example, the electronic device can set different file security levels for different files. Even if the security status information of the electronic device is the same, the file access permissions determined by the electronic device for files with different security levels can be different. For example, for a file with a low security level, when the device's access permission risk increases, the electronic device can adjust the file access permissions of that file from allowing editing to allowing read-only access; while for a file with a high security level, when the device's access permission risk increases, the electronic device can adjust the file access permissions of that file from allowing editing to prohibit opening. Through this design, differentiated management of different files can be achieved to meet the user's risk control needs for files with various security levels.

[0106] It should be noted that the file access permissions described in the above embodiments of this application are only examples and not limitations. In specific implementations, electronic devices may also support other file access permissions, and this application does not limit them.

[0107] In this embodiment, the electronic device can continuously monitor its file access environment during the access to the first file. Optionally, the electronic device can perform device access permission risk detection at a preset period to obtain fourth security status information. When the electronic device determines that its security status has changed based on the fourth security status information, it adjusts the file access permissions for the first file. Optionally, the electronic device can determine the risk detection period for the file based on its security level. For example, for files with higher security levels, the risk detection period is shorter, thereby further ensuring the security of file access. The device access permission risk detection method performed by the electronic device during file access can be found in the foregoing embodiments, and will not be repeated here.

[0108] Optionally, when the security status of an electronic device changes, the monitoring module within the device can report a security event. This security event can indicate a change in a risk factor, such as indicating that the device's USB port is open. The device can determine its fourth security status information based on the security event corresponding to at least one risk factor. When the device determines that its security status has changed based on this fourth security status information, it can adjust the file access permissions for the first file according to the file management policy. In this way, when the security status of the electronic device changes, it can promptly adjust file access permissions, ensuring a timely response to security events and further enhancing the security of file access.

[0109] In this embodiment, during the access to the first file, when the electronic device obtains the fourth security status information indicating a change in its security status (such as detecting unauthorized access risks, USB port connections, or risks associated with connected devices), the electronic device can adjust the file access permissions for the first file. The response action corresponding to the adjusted file access permissions may include at least one of the following: closing the file, displaying a risk warning message, or displaying a mask on the display interface. The risk warning message displayed by the electronic device can alert the user to the current device status as potentially risky and suggest that the user close the file. In this way, the electronic device can continuously perform risk detection during file access to prevent data leakage risks caused by changes in the access environment after the file is opened, further enhancing file access security.

[0110] For example, Figure 4 is a schematic diagram of a file access permission control method provided in an embodiment of this application. Referring to Figure 4, when a user accesses a file using an electronic device, if the risk detection result of the electronic device indicates that the device status of the electronic device has changed, such as the electronic device switching from connecting to the internal network of an enterprise to connecting to an external network, the electronic device can display a risk warning message in a pop-up window. As shown in Figure 4, the electronic device can display a warning message in a pop-up window that says "The current access environment does not meet the security requirements. Please restore and click 'OK' to continue accessing or directly click 'Cancel' to close the file."

[0111] In some scenarios, the file access control method provided in this application embodiment may further include a file transfer policy when the electronic device transfers files to other electronic devices. This file transfer policy may include requirements for the device security status of the receiving electronic device during file transfer. For example, the file transfer policy may allow the electronic device to transfer files to the receiving electronic device when the receiving electronic device is in a normal user privilege state and the USB port is not enabled. In this example, taking the user triggering a file transfer operation to the second electronic device from the first electronic device as an example, the user triggers a second operation on the first electronic device. This second operation is an operation performed by the user on the first file and associated with the second electronic device. For example, the second operation may be an operation triggered by the user to send the first file to the second electronic device, or an operation triggered by the user to cast or share the screen to the second electronic device when the first electronic device is displaying the first file. In response to the above second operation, the first electronic device can obtain the security status information of the second electronic device. The security status information of the second electronic device may be generated after the second electronic device performs a device usage permission risk detection. For example, the security status information of the second electronic device may include at least one of the following: whether there is a risk of device unauthorized access, connection status information, network environment information, and geographical location information. The first electronic device can determine whether the security status of the second electronic device meets the security requirements for the receiving electronic device based on the security status information of the second electronic device. After determining that the security status of the second electronic device meets the requirements, the first electronic device can execute the response action corresponding to the second operation. This response action is used to manage the first file. For example, when the second operation is used to send the first file to the second electronic device, the response action executed by the first electronic device is to send the first file to the second electronic device. Similarly, when the second operation is used to project or share the screen to the second electronic device, the response action executed by the first electronic device can be to project or share the screen to the second electronic device. Optionally, if the security status of the second electronic device does not meet the requirements, the first electronic device is prohibited from executing the response action corresponding to the second operation. For example, the first electronic device may prohibit the transmission of the first file to the second electronic device or prohibit projecting or sharing the screen to the second electronic device. In this case, the first electronic device can also display a reminder message to remind the user that the second electronic device does not meet the security requirements for sharing files.

[0112] For example, Figure 5 is a schematic diagram of a file access control method provided in an embodiment of this application. Referring to Figure 5, a user triggers an operation to send a file to a second electronic device on a first electronic device. The first electronic device sends a request message to the second electronic device, which requests to obtain the security status information of the second electronic device. After receiving the request message from the first electronic device, the second electronic device can perform a device access permission risk detection on the second electronic device and determine the second security status information of the second electronic device based on the device access permission risk detection result. The second electronic device then sends the second security status information of the second electronic device to the first electronic device. The first electronic device determines whether the device security status of the second electronic device meets the requirements of the file control policy for the device security status of the receiving electronic device. For example, if the second security status information of the second electronic device indicates that the second electronic device is connected to a USB, but the file control policy requires the receiving device to be in a state without a USB connection, then the first electronic device determines that the device security status of the second electronic device does not meet the requirements and prohibits sending files to the second electronic device. For example, a pop-up reminder message can be displayed on the first electronic device. Referring to Figure 5, the reminder message can be "The second electronic device does not meet the security requirements for file transmission, and file transmission is prohibited."

[0113] Based on the file access control method provided in this application embodiment, Figure 6 is a schematic diagram of the architecture of a file access control system provided in this application embodiment. Referring to Figure 6, the file access control system includes a server and electronic devices. Figure 6 uses one electronic device as an example to introduce the modules involved in the file access control method in this application embodiment. In specific implementation, the server can be used to manage multiple electronic devices. The structure of each electronic device can be seen in the structure of the electronic device shown in Figure 6, and repeated parts will not be described again. Referring to Figure 2, the server may include a policy distribution module, which can be used to distribute the configured file management policy to at least one electronic device. The electronic device may include a policy storage module, a device status processing module, a device status monitoring module, an access control module, a system resource management module, a user credential processing module, and a transmission policy management module. The system comprises several modules: a policy storage module for storing file management policies issued by the server; a device status processing module for detecting device access risks to determine the security status of electronic devices; a device status monitoring module for continuously detecting access risks while an electronic device displays a file to monitor its security status; an access control module for executing corresponding access control based on the file management policies; a system resource management module for scheduling system resources (e.g., the access control module can schedule the system resource management module to close files or display risk warning pop-ups on the display interface); a user credential processing module for storing and managing user credentials (e.g., the access control module can call the user credential processing module during file opening to decrypt encrypted files using the user credential key); and a transmission policy management module for managing file transmission policies within the file management policies. When an electronic device requires file transmission, the module obtains the security status information of the receiving electronic device and determines whether the receiving electronic device meets the security requirements for file transmission based on the file management policies.

[0114] Based on the above embodiments, Figure 7 is a flowchart of a file access control method provided in this application embodiment. Referring to Figure 7, the method can be executed by a server, a first electronic device, and a second electronic device, and the method includes the following steps:

[0115] S701: The server sends file management policies to at least one electronic device.

[0116] At least one electronic device includes a first electronic device and a second electronic device.

[0117] Alternatively, S701 can be executed by the policy distribution module in the server shown in Figure 6.

[0118] S702: First electronic device storage file management strategy.

[0119] Alternatively, S702 can be executed by the policy storage module in the electronic device shown in Figure 6.

[0120] S703: In response to the user-triggered operation of opening the first file, the first electronic device detects the risk of unauthorized access and determines that the first electronic device does not have the risk of unauthorized access.

[0121] S704: The first electronic device detects the risk of access permission to at least one other device and determines the third security status information of the first electronic device.

[0122] Optionally, the third security status information may include the detection results of device unauthorized access risk and the detection results of at least one other risk factor. The at least one other device access risk may include at least one of connection status risk, network environment risk, or geographical location risk.

[0123] Optionally, S703-S704 can be executed by the device status processing module in the electronic device shown in Figure 6.

[0124] S705: When the third security status information of the first electronic device indicates that the risk of the device usage permission of the first electronic device has increased, the first electronic device adjusts the file access permission of the first file to a restricted file access permission.

[0125] Among them, the restricted file access permissions are more restricted than the file access permissions of the first file before the user performs the operation of opening the first file.

[0126] Optionally, S705 can be executed by the access control module in the electronic device shown in Figure 6.

[0127] S706: In response to the user's first operation on the first opened file, the first electronic device detects the risk of device access rights of the first electronic device and determines the first security status information of the first electronic device.

[0128] Among them, device usage permission risks include at least one of the following: device unauthorized access risk, connection status risk, network environment risk, or geographical location risk.

[0129] Optionally, S706 can be executed by the device state processing module in the electronic device shown in FIG6.

[0130] S707: When the first security status information of the first electronic device indicates that the risk of the device use permission of the first electronic device has increased, the first electronic device adjusts the file access permission of the first file to a restricted file access permission.

[0131] Among them, the restricted file access permissions are more restricted than the file access permissions of the first file before the user performs the first operation.

[0132] Optionally, S707 can be executed by the access control module in the electronic device shown in Figure 6.

[0133] S708: When the first file is open, the first electronic device performs a device usage permission risk detection according to a preset cycle, or the first electronic device obtains a security event and determines the fourth security status information of the first electronic device.

[0134] Alternatively, S708 can be executed by the device status monitoring module in the electronic device shown in Figure 6.

[0135] S709: When the first electronic device determines that the security status of the first electronic device has changed based on the fourth security status information of the first electronic device, it adjusts the file access permissions of the first file.

[0136] Optionally, S709 can be executed by the access control module and the system resource management module in the electronic device shown in Figure 6.

[0137] S710: In response to the user's second operation, the first electronic device sends a request message to the second electronic device.

[0138] The second operation is an operation performed on the file and associated with the second electronic device, such as sending the first file to the second electronic device, or casting or sharing the screen to the second electronic device when displaying the first file. The request message sent by the first electronic device to the second electronic device is used to request the security status information of the second electronic device.

[0139] Alternatively, S710 can be executed by the transmission policy management module in the electronic device shown in Figure 6.

[0140] S711: The second electronic device detects the risk of device access rights of the second electronic device and determines the second security status information of the second electronic device.

[0141] S712: The second electronic device sends the second security status information to the first electronic device.

[0142] S713: The first electronic device determines, based on the second security status information of the second electronic device, that the risk of the second electronic device's device usage rights meets the device security status requirements of the receiving electronic device.

[0143] Optionally, S713 can be executed by the transmission policy management module in the electronic device shown in Figure 6.

[0144] S714: The first electronic device performs the response action corresponding to the second operation.

[0145] The response action corresponding to the second operation is a response action used to control the first file, such as sending the first file to the second electronic device; or casting or sharing the screen to the second electronic device when displaying the first file.

[0146] It should be noted that the embodiment shown in Figure 7 is only an example provided by this application and is not a limitation. The execution method of each step in the specific implementation can be referred to the foregoing embodiments of this application, and repeated parts will not be described again.

[0147] Based on the same concept, this application also provides a file access control method, which can be executed by a first electronic device. Figure 8 is a flowchart of a file access control method provided by this application. Referring to Figure 8, the method includes the following steps:

[0148] S801: In response to the user's first operation on the first opened file, detect the device access permission risk of the first electronic device and determine the first security status information of the first electronic device;

[0149] Among them, device usage permission risks include at least one of the following: device unauthorized access risk, connection status risk, network environment risk, or geographical location risk.

[0150] S802: When the device access risk of the first electronic device indicated by the first security status information is increased, the file access permission of the first file is adjusted to restricted file access permission.

[0151] Among them, the restricted file access permissions are more restricted than the file access permissions of the first file before the user performs the first operation.

[0152] It should be noted that the file access control method shown in Figure 8 of this application can be referred to the above embodiments of this application in specific implementation, and repeated parts will not be described again.

[0153] Based on the above embodiments, this application also provides an electronic device, which includes multiple functional modules. These multiple functional modules interact to implement the functions performed by the electronic device in the methods described in the embodiments of this application. For example, executing steps S702-S710 and S713-S714 performed by the first electronic device in the embodiment shown in FIG. 7, or executing steps S711-S712 performed by the second electronic device in the embodiment shown in FIG. 7, or executing steps performed by the first electronic device in the embodiment shown in FIG. 8. The multiple functional modules can be implemented based on software, hardware, or a combination of software and hardware, and can be arbitrarily combined or divided based on specific implementations.

[0154] Based on the above embodiments, this application also provides an electronic device, which includes at least one processor and at least one memory. The at least one memory stores computer program instructions. When the electronic device is running, the at least one processor executes the functions performed by the electronic device in the various methods described in the embodiments of this application. For example, executing steps S702-S710 and S713-S714 performed by the first electronic device in the embodiment shown in FIG. 7, or executing steps S711-S712 performed by the second electronic device in the embodiment shown in FIG. 7, or executing steps performed by the first electronic device in the embodiment shown in FIG. 8.

[0155] Based on the above embodiments, this application also provides a computer program product containing instructions, which, when run on a computer, causes the computer to execute the methods described in the embodiments of this application.

[0156] Based on the above embodiments, this application also provides a computer-readable storage medium storing a computer program, which, when executed by a computer, causes the computer to perform the methods described in the embodiments of this application.

[0157] Based on the above embodiments, this application also provides a chip for reading computer programs stored in a memory to implement the methods described in the embodiments of this application.

[0158] Based on the above embodiments, this application provides a chip system including a processor for supporting a computer device in implementing the methods described in the embodiments of this application. In one possible design, the chip system further includes a memory for storing necessary programs and data of the computer device. This chip system may be composed of chips or may include chips and other discrete devices.

[0159] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0160] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in one or more blocks of the flowchart illustrations and / or one or more blocks of the block diagrams.

[0161] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means that implement the functions specified in one or more flowcharts and / or one or more block diagrams.

[0162] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, such that the instructions, which execute on the computer or other programmable apparatus, provide steps for implementing the functions specified in one or more flowcharts and / or one or more block diagrams.

[0163] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the scope of protection of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. A file access control method, characterized in that, Applied to a first electronic device, the method includes: In response to the user's first operation on the first opened file, the device access permission risk of the first electronic device is detected, and the first security status information of the first electronic device is determined; the device access permission risk includes at least one of the following: device unauthorized access risk, connection status risk, network environment risk, or geographical location risk. When the first security status information indicates an increased risk to the device usage rights of the first electronic device, the file access permission of the first file is adjusted to a restricted file access permission, which is a restricted file access permission compared to the file access permission of the first file before the user performed the first operation.

2. The method as described in claim 1, characterized in that, After adjusting the file access permissions of the first file to restricted file access permissions, while the first file is still open, the method further includes: When the risk of device usage permission of the first electronic device indicated by the first security status information is reduced, the file access permission of the first file is adjusted to an upgraded file access permission.

3. The method as described in claim 2, characterized in that, The first file being still open includes either the already opened first file not being closed, or the already opened first file being closed and then reopened.

4. The method according to any one of claims 1-3, characterized in that, When the file access permissions of the first file are restricted to allow read-only access before the user performs the first operation, the restricted file access permissions are to prohibit opening the file; or When the file access permissions of the first file are restricted to allow editing of the file before the user performs the first operation, the restricted file access permissions are either allow reading-only access to the file or prohibit opening the file; or When the file access permissions of the first file are restricted to allowing screen casting, screen recording, or screen sharing before the user performs the first operation, the restricted file access permissions are disallowing screen casting, disallowing screen recording, or disallowing screen sharing.

5. The method according to any one of claims 1-4, characterized in that, When the restricted file access permission is to prohibit opening the file, after adjusting the file access permission of the first file to restricted file access permission, the method further includes: Perform at least one of the following response actions: The system may close the first file, display a risk warning message, or display a mask on the display interface; wherein the risk warning message is used to remind the user that the first electronic device is currently at risk and to suggest that the user close the first file.

6. The method according to any one of claims 1-5, characterized in that, The method further includes: In response to a second user action, the system obtains second security status information for the second electronic device. The second action is an operation performed on the first file and associated with the second electronic device. The second security status information is used to indicate the device access risk of the second electronic device. Based on the second security status information, it is determined that the device usage permission risk of the second electronic device meets the device security status requirements for the receiving electronic device. Execute the response action corresponding to the second operation, wherein the response action is a response action used to control the first file.

7. The method as described in claim 6, characterized in that, The second operation is used to send the first file to the second electronic device, or the second operation is used to project the screen to the second electronic device when displaying the first file, or the second operation is used to share the screen to the second electronic device when displaying the first file.

8. The method as described in claim 6 or 7, characterized in that, The response action corresponding to the execution of the second operation includes: Send the first file to the second electronic device; or Projecting the screen to the second electronic device while the first file is being displayed; or The screen is shared with the second electronic device while the first file is being displayed.

9. The method as described in claim 1, characterized in that, The method further includes: In response to a third operation by the user on an already opened second file, when the device access risk of the first electronic device indicated by the first security status information is increased, the file access permission of the second file is adjusted to a restricted file access permission. The adjusted file access permission of the second file is different from the restricted file access permission of the second file before the user performed the third operation, and the adjusted file access permission of the second file is different from the adjusted file access permission of the first file.

10. The method according to any one of claims 1-9, characterized in that, The file access permissions for the first file include at least one of the following: Disallow opening files, prohibit file transfer, allow read-only access to files, allow file editing, allow file access after successful authentication, prohibit screen mirroring, prohibit screen recording, and prohibit screen sharing.

11. A file access control method, characterized in that, Applied to a first electronic device, the method includes: In response to the user's fourth operation, the device privilege escalation risk of the first electronic device is detected, and the third security status information of the first electronic device is determined. The fourth operation is used to open the first file. The device privilege escalation risk includes the risk of exceeding the scope of the first device's usage permissions. The scope of the first device's usage permissions is the scope of device usage permissions authorized to the user account logged in on the first electronic device. When the third security status information indicates that the first electronic device has a risk of unauthorized access, the file access permission of the first file is adjusted to a restricted file access permission, which is more restricted than the file access permission of the first file before the user performs the fourth operation.

12. The method as described in claim 11, characterized in that, The third security status information also includes the detection result of at least one of the following risk detection methods: connection status risk detection, network environment risk detection, or geographical location risk detection. The restricted file access permissions are determined based on the detection result of at least one of the following risk detection methods: device unauthorized access risk detection, connection status risk detection, network environment risk detection, or geographical location risk detection.

13. The method as described in claim 11 or 12, characterized in that, After adjusting the file access permissions of the first file to restricted file access permissions, the method further includes: The device access risk of the first electronic device is detected according to a preset period to determine the fourth security status information of the first electronic device; the device access risk includes at least one of the following: device unauthorized access risk, connection status risk, network environment risk, or geographical location risk; When the security status of the first electronic device changes based on the fourth security status information, the file access permissions of the first file are adjusted.

14. The method as described in claim 13, characterized in that, After adjusting the file access permissions of the first file, the method further includes: Perform at least one of the following response actions: The system may close the first file, display a risk warning message, or display a mask on the display interface; wherein the risk warning message is used to remind the user that the first electronic device is currently at risk and to suggest that the user close the first file.

15. The method according to any one of claims 11-14, characterized in that, The method further includes: In response to a second user action, second security status information of the second electronic device is obtained, wherein the second action is an operation performed on the file and associated with the second electronic device, and the second security status information is used to indicate the device access permission risk of the second electronic device; Based on the second security status information, it is determined that the device usage permission risk of the second electronic device meets the device security status requirements for the receiving electronic device. Execute the response action corresponding to the second operation, wherein the response action is a response action used to control the first file.

16. The method as described in claim 15, characterized in that, The second operation is used to send the first file to the second electronic device, or the second operation is used to project the screen to the second electronic device when displaying the first file, or the second operation is used to share the screen to the second electronic device when displaying the first file.

17. The method as described in claim 15 or 16, characterized in that, The response action corresponding to the execution of the second operation includes: Send the first file to the second electronic device; or Projecting the screen to the second electronic device while the first file is being displayed; or The screen is shared with the second electronic device while the first file is being displayed.

18. The method according to any one of claims 11-17, characterized in that, The file access permissions for the first file include at least one of the following: Disallow opening files, prohibit file transfer, allow read-only access to files, allow file editing, allow file access after successful authentication, prohibit screen mirroring, prohibit screen recording, and prohibit screen sharing.

19. An electronic device, characterized in that, The method includes at least one processor coupled to at least one memory, the at least one processor being configured to read a computer program stored in the at least one memory to perform the method as described in any one of claims 1-10, or to perform the method as described in any one of claims 11-18.

20. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores instructions that, when executed on a computer, cause the computer to perform the method as described in any one of claims 1-10, or the method as described in any one of claims 11-18.

Citation Information

Patent Citations

  • Terminal and data protection method of terminal

    CN108763900A

  • Method for simultaneously displaying selective display annotations on multiple terminals by using same OFD (Open Forwarding Detection) file

    CN116737101A

  • Access control method and device, electronic equipment and storage medium

    CN118233117A

  • Control of access to files

    US20140130180A1