Permission management and control method and apparatus, electronic device, medium and product

WO2026175298A1PCT designated stage Publication Date: 2026-08-27VIVO MOBILE COMM CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2026/078784
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-02-18
Filing Date
2026-02-12
Publication Date
2026-08-27

Smart Images

  • Figure CN2026078784_27082026_PF_FP_ABST
    Figure CN2026078784_27082026_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of artificial intelligence, and discloses a permission management and control method and apparatus, an electronic device, a medium, and a product. The method comprises: acquiring user requirement information, the user requirement information being used for indicating a requirement of a user for using a multi-modal large model; on the basis of the user requirement information, determining user data related to the user requirement information; generating an authorization policy on the basis of a data hierarchy of the user data, the authorization policy being used for indicating whether to prompt the user for authorization when the multi-modal large model reads the user data, and the data hierarchy being used for representing a security level of the user data; and displaying authorization prompt information on the basis of the authorization policy.
Need to check novelty before this filing date? Find Prior Art

Description

Access control methods, devices, electronic equipment, media and products

[0001] Cross-reference to related applications

[0002] This application claims priority to Chinese patent application 202510181130.8, filed on February 18, 2025, entitled “Access Control Method, Apparatus, Electronic Device, Media and Product”, the entire contents of which are incorporated herein by reference. Technical Field

[0003] This application belongs to the field of artificial intelligence technology, specifically relating to a method, device, electronic device, medium, and product for access control. Background Technology

[0004] More and more multimodal big models can be set up in electronic devices such as mobile phones and tablets to provide users with simple services such as sending text messages, making phone calls and setting reminders, as well as logically complex services such as health management, text creation assistance and financial services. In order to ensure the security of user data, authorization from users must be requested before using this user data.

[0005] In related technologies, user data authorization is typically implemented using a single data type authorization method. For example, when a user is navigating, they are prompted to grant permission to access a location, or when a user is taking a picture, they are prompted to grant permission to access local photos. However, multimodal big data services often use a large amount of different types of user data. Using the aforementioned methods, users would be prompted to grant permission for each type of user data individually. This not only increases the amount of manual authorization required by the user and reduces the efficiency of permission control, but also affects the overall efficiency of multimodal big data services. Summary of the Invention

[0006] The purpose of this application is to provide a method, device, electronic device, medium, and product for access control, which can reduce the manual authorization operations of users and improve the efficiency of access control and the use of multimodal large models.

[0007] Firstly, embodiments of this application provide an access control method, including:

[0008] Obtain user demand information, which is used to indicate the user's need for using a multimodal large model;

[0009] Based on user demand information, determine the user data related to user demand information;

[0010] Based on the data hierarchy of user data, an authorization policy is generated. The authorization policy is used to indicate whether to prompt the user for authorization when the multimodal large model reads user data. The data hierarchy is used to represent the security level of user data.

[0011] The authorization prompt message is displayed according to the authorization policy.

[0012] Secondly, embodiments of this application provide an access control device, including:

[0013] The acquisition module is used to acquire user demand information, which is used to indicate the user's need for using the multimodal large model.

[0014] The determination module is used to determine user data related to user needs information based on user needs information;

[0015] The generation module is used to generate authorization policies based on the data hierarchy of user data. The authorization policy is used to indicate whether to prompt the user for authorization when the multimodal large model reads user data. The data hierarchy is used to represent the security level of user data.

[0016] The display module is used to display authorization prompts based on the authorization policy.

[0017] Thirdly, embodiments of this application provide an electronic device, which includes a processor, a memory, and a program or instructions stored in the memory and executable on the processor. When the program or instructions are executed by the processor, they implement the steps of the access control method as described in the first aspect.

[0018] Fourthly, embodiments of this application also provide an electronic device configured to perform the image processing method as described in the first aspect.

[0019] Fifthly, embodiments of this application provide a readable storage medium on which a program or instruction is stored, and when the program or instruction is executed by a processor, it implements the steps of the access control method as shown in the first aspect.

[0020] In a sixth aspect, embodiments of this application provide a chip, which includes a processor and a display interface. The display interface and the processor are coupled, and the processor is used to run programs or instructions to implement the steps of the access control method as shown in the first aspect.

[0021] In a seventh aspect, embodiments of this application provide a computer program product stored in a storage medium, which is executed by at least one processor to implement the steps of the access control method as described in the first aspect.

[0022] In this embodiment of the application, user data related to the obtained user demand information can be determined, wherein the user demand information is used to indicate the user demand for using the multimodal large model; then, based on the data hierarchy of the user data, an authorization policy is generated, the authorization policy is used to indicate whether to prompt the user for authorization when the multimodal large model reads the user data, the data hierarchy is used to represent the security level of the user data, and authorization prompt information is displayed according to the authorization policy. This approach leverages the multimodal big data model's understanding of user needs to determine the model's purpose in accessing user data. Combined with an understanding of user data hierarchy, it dynamically assesses the appropriateness of the model's use of user data. An authorization strategy instructs the model whether to prompt the user for authorization when reading user data. For user data requiring authorization, an authorization prompt can be displayed, assisting users in better and more meticulously managing whether user data can be read by untrusted multimodal big data models, thus improving data security. For user data that does not require authorization, it can directly participate in the multimodal big data model's operations related to user needs, reducing the need for manual authorization and improving the efficiency of access control. This also increases the speed at which the multimodal big data model reads user data, thereby enhancing its overall efficiency. Attached Figure Description

[0023] Figure 1 is a schematic diagram of an access control system provided in some embodiments of this application;

[0024] Figure 2 is a flowchart of the permission control method provided in some embodiments of this application;

[0025] Figure 3 is a schematic diagram of the data hierarchy and data categories of user data provided in some embodiments of this application for the permission control method;

[0026] Figure 4 is a flowchart illustrating the access control method provided in some embodiments of this application;

[0027] Figure 5 is a schematic diagram of the access control device provided in some embodiments of this application;

[0028] Figure 6 is a schematic diagram of the structure of an electronic device provided in some embodiments of this application;

[0029] Figure 7 is a schematic diagram of the hardware structure of an electronic device provided in some embodiments of this application. Detailed Implementation

[0030] The technical solutions of the embodiments of this application will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application are within the scope of protection of this application.

[0031] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such terms can be used interchangeably where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first," "second," etc., are generally of the same class and the number of objects is not limited; for example, a first object can be one or more. Furthermore, in the specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.

[0032] To address the problems in related technologies, embodiments of this application provide a method, apparatus, electronic device, and storage medium for access control. The access control method provided by these embodiments will be described in detail below with reference to Figures 1 to 4, through specific examples and application scenarios.

[0033] First, a permission control system provided in this application embodiment will be described in detail with reference to Figure 1.

[0034] Figure 1 is a schematic diagram of an access control system provided in some embodiments of this application.

[0035] As shown in Figure 1, the access control system in this embodiment can be installed in an electronic device. The access control system can utilize the operating system framework, kernel, and device hardware in the electronic device to execute the steps of the access control method.

[0036] In this embodiment, considering the exit point of user data, a multimodal large model (AI agent) hierarchy can be set between the user data hierarchy in the operating system framework and the application hierarchy of the various applications involved. This allows the AI ​​agent to understand user needs and determine the purpose of the multimodal large model accessing user data. Combined with an understanding of the user data's hierarchical structure, it dynamically judges whether the multimodal large model's use of user data is reasonable. An authorization policy is then used to instruct the multimodal large model whether to prompt the user for authorization when reading user data. For user data requiring authorization, the AI ​​agent can trigger the device hardware to display authorization prompts. This helps users better and more meticulously manage whether user data can be read by untrusted applications and the AI ​​agent itself, improving user data security. For user data that does not require authorization, the AI ​​agent can generate operation flow information, which can be completed with the assistance of any number of applications in the electronic device, such as application A, application B, application C, and application D. This reduces the need for users to manually authorize these user data operations, improving the efficiency of access control and increasing the speed at which the multimodal large model reads user data, thus improving the overall efficiency of the multimodal large model.

[0037] For example, an AI agent can acquire user demand information, such as purchasing an Americano. Based on the Americano, the AI ​​agent can determine user data, such as the user's location, their Americano-eating habits (e.g., whether they add milk or sugar), and which coffee shop sells the Americano. These habits can be obtained from applications like A, B, C, and D that provide coffee ordering services. Then, the AI ​​agent determines the data hierarchy of the user's location and behavioral habits, and determines whether it has the necessary permissions to access the user's location and the behavioral habits within each application. If it does, the AI ​​agent and / or applications within the electronic device (e.g., A, B, C, D) can execute the user's instructions related to their demand information.

[0038] Therefore, when users use multimodal big data models to process various services on electronic devices, the models, after acquiring user demand information such as ordering coffee or buying tickets, can understand user needs and the purpose of using user data related to those needs. They can dynamically determine whether the use of user data by the multimodal big data model is reasonable, and through authorization policies, instruct the model whether to prompt the user for authorization when reading user data. For user data requiring authorization, the AI ​​agent can trigger the device hardware to display authorization prompts. This helps users better and more meticulously manage whether user data can be read by untrusted applications and the AI ​​agent itself, improving user data security. Furthermore, for user data that does not require authorization, the AI ​​agent can perform related operations. For users, these operations related to user needs are imperceptible, reducing the need for manual authorization and improving the efficiency of access control. This also increases the speed at which the multimodal big data model reads user data, thus improving the overall efficiency of the multimodal big data model.

[0039] Secondly, a permission control method provided by the embodiments of this application will be described in detail with reference to Figure 2.

[0040] Figure 2 is a flowchart of the permission control method provided in some embodiments of this application.

[0041] As shown in Figure 2, the permission control method provided in this application embodiment can be applied to the permission control system shown in Figure 1. Based on this, the permission control method may include steps 210, 220, 230 and 240, as shown below.

[0042] Step 210: Obtain user requirement information, which indicates the user's need to use the multimodal large model; Step 220: Determine user data related to the user requirement information based on the user requirement information; Step 230: Generate an authorization policy based on the data hierarchy of the user data, which indicates whether to prompt the user for authorization when the multimodal large model reads user data, and the data hierarchy represents the security level of the user data; Step 240: Display authorization prompt information according to the authorization policy.

[0043] For example, an electronic device can obtain user demand information through an AI agent, such as when purchasing a cup of Americano. Based on this information, the AI ​​agent can determine user data such as the user's location, coffee preferences, frequently visited coffee shops, and contact information. If the data level for the user's coffee preferences and frequently visited coffee shops is S2, the user's location data is S3, and the user's contact information is S4, then the number of data levels can be used to determine whether user authorization is required. Specifically, if the number of data levels is greater than or equal to four (referencing levels), the multimodal large model can be instructed to prompt the user for authorization when reading user data. In this case, the AI ​​agent can directly access and use the user's coffee preferences, frequently visited coffee shops, and location data, and a pop-up window will ask the user for authorization to use their contact information. Thus, if the user authorizes the AI ​​agent to access and use their contact information, operations related to the user's demand information can be performed.

[0044] Therefore, by fully leveraging the understanding of user needs information by the multimodal big data model, the purpose of the multimodal big data model accessing user data can be determined. Combined with the understanding of user data hierarchy, the rationality of the multimodal big data model's use of user data can be dynamically judged. The authorization policy can then instruct the multimodal big data model whether to prompt the user for authorization when reading user data. For user data that requires user authorization, it can help users better and more meticulously manage whether user data can be read by untrusted multimodal big data models, thus improving the security of user data. For user data that does not require user authorization, it can directly participate in the multimodal big data model's execution of operations related to user needs information, reducing the need for users to manually authorize these user data operations, improving the efficiency of access control, and also increasing the speed at which the multimodal big data model reads user data, thereby improving the overall efficiency of the multimodal big data model.

[0045] The steps described above are explained in detail below.

[0046] Regarding step 210, in some embodiments of this application, the electronic device can obtain user demand information through an AI agent. The AI ​​agent in these embodiments can be a model of the operating system within the electronic device, or a model within any application of the electronic device.

[0047] It should be noted that the user demand information in this application embodiment refers to information about how users use a multimodal large model to meet specific goals or solve problems, such as asking someone to buy a cup of Americano or play music. User demand information includes, but is not limited to, information in formats such as images, text, and audio.

[0048] Regarding step 220, after the user obtains the user demand information, it is possible to analyze what user data is needed for the user demand information. Based on this, in some embodiments of this application, step 220 may specifically include steps 2201 and 2202.

[0049] Step 2201 involves identifying user demand information using a multimodal large model to obtain the user's intention instructions for operating the electronic device. In this embodiment, the intention instruction refers to a defined user expression of intent for achieving natural interaction with the user. Here, using a multimodal large model to identify user demand information allows for a more accurate understanding of the user's intent, providing more precise responses and services.

[0050] For example, if the user's request information includes an image of coffee, the image can be recognized using a multimodal large model to obtain the user's intention to operate the electronic device, such as ordering coffee; if the user's request information includes audio, the audio can be recognized using a multimodal large model to obtain the user's intention to operate the electronic device, such as buying a cup of Americano.

[0051] Step 2202: Determine the user data required for the user to operate the electronic device based on the intent instruction.

[0052] For example, an AI agent can determine user data such as the user's geographical location, coffee preferences, frequently visited coffee shops, and contact information based on a cup of Americano.

[0053] Therefore, the embodiments of this application can identify multimodal user demand information to obtain intent instructions, thereby determining the user data required for the user to operate the electronic device. This not only allows for a more accurate understanding of the user's intent and provides more precise responses and services, but also expands the permission control from applications in electronic devices to the permission control of a multimodal large model set between application layers of various applications, thus improving the versatility of the permission control method.

[0054] In some embodiments, prior to step 220, the access control method may further include steps 2401 to 2403.

[0055] Step 2401: Determine the data category of the user data based on its content. In this embodiment, the data category reflects the nature and characteristics of the user data. In this embodiment, the data category includes at least one of the following: biometric data, personal data, device data, health and medical data, location data, contact information, internet browsing history, media files, public interest data, account and device data, financial information, behavioral and social activity information, education and work information, and information and communication data.

[0056] For example, as shown in Figure 3, if the user data is the user's geographic location data, the data category of the user data can be location tracking; if the user data is the user's coffee preference data, the data category of the user data can be behavioral habits and social activity information; if the user data is the user's communication number data, the data type of the user data can be information and communication.

[0057] Step 2402: Based on the association information between reference data categories and reference data levels, determine the data level associated with the data category. In this embodiment, the data levels include S1, S2, S3, S4, and S5, which are related to the sensitivity, importance, or security level of the data, representing progressively increasing sensitivity, importance, or security levels. Specifically, S1 represents public-level data, which has public dissemination attributes and can be publicly released and forwarded. S2 represents internal-level data, which is typically shared and used within the organization and among stakeholders, and can be shared externally after authorization from relevant parties. S3 represents sensitive-level data, which can only be accessed by authorized individuals. S4 represents important-level data, which requires strict management according to an approved authorization list and can only be shared or disseminated within a controlled scope after user authorization. S5 represents core-level data, which is prohibited from being shared or disseminated externally.

[0058] Reference data categories are pre-defined data categories used to reflect the nature and characteristics of user data. Their function is to classify and describe user data, ensuring data standardization and consistency.

[0059] Reference data levels are pre-defined data levels used to represent progressively increasing levels of sensitivity, importance, or security of data. Their purpose is to classify and describe reference data categories, providing a foundation for the standardization and consistency of data categories.

[0060] The association information between reference data categories and reference data levels is a pre-defined mapping relationship between data categories and data levels. This reflects the correspondence between data categories and data levels, enabling matching the corresponding data level to a known data category, or vice versa. This enhances data understandability and usability, and promotes data standardization and consistency. For example, location data can be associated with S3, behavioral habits and social activity information can be associated with S2, and information communication data can be associated with S4. Step 2403: The data level associated with the data category is determined as the data level of the user data.

[0061] For example, if the location data is associated with S3, then the data level associated with the user's geographic location data is determined to be S3; if the behavior and social activity information data is associated with S2, then the data level associated with the user's coffee preference data is determined to be S2; if the communication data is associated with S4, then the data level associated with the user's communication number data is determined to be S4.

[0062] Therefore, user data, its data categories, and its data hierarchy can be strongly managed. By determining whether user authorization is required based on the user data's own dimensions, the multimodal big data model can fully leverage its understanding of user needs to determine the purpose of accessing user data. It can also dynamically judge whether the multimodal big data model's use of user data is reasonable. For user data that requires user authorization, it can help users better and more meticulously manage whether user data can be read by untrusted multimodal big data models, thereby improving the security of user data.

[0063] Regarding step 230, in some embodiments of this application, since individual users have different levels of sensitivity to data, for example, some users are highly sensitive to geographical location, so the static framework can be used to disable the calling of such data by any scene or command. This ensures that such data will not be used regardless of the result of the dynamic permission use framework. Based on this, the user's required permission policy can be adjusted by the preset static usage permission policy set by the static framework to obtain an accurate authorization policy. Based on this, step 230 may specifically include steps 2301 and 2302.

[0064] Step 2301: Determine the user requirement permission policy based on the data hierarchy of user data.

[0065] For example, the data hierarchy of a user's coffee preference data and frequently visited coffee shop data is S2, the data hierarchy of a user's geographical location data is S3, and the data hierarchy of a user's contact number data is S4. The user request permission policy may include allowing access to and use of the user's coffee preference data, frequently visited coffee shop data, and geographical location data, while disallowing access to the user's contact number data and prompting the user through a pop-up window to ask whether they authorize the use of the user's contact number data.

[0066] Step 2302: Generate an authorization policy based on the user-defined permission policy and the preset static usage permission policy. The preset static usage permission policy is a data access permission policy pre-set by the user. This preset static usage permission policy includes which data the user sets to be prohibited from being shared or disseminated externally, or which data the user sets to require a pop-up window to prompt the user and authorization before it can be shared or disseminated.

[0067] For example, if the AI ​​agent is a service of the operating system in an electronic device, the preset static usage permission policy can be that after the electronic device is started, the user manually sets the permission for the AI ​​agent to read user data. In this way, the user demand permission policy obtained from the analysis of user demand information can be adjusted through the preset static usage permission policy. That is, if the user data corresponding to the preset static usage permission policy is user geolocation data, then the user geolocation data is not allowed to be read by the AI ​​agent and a pop-up window needs to ask the user whether to authorize its use. At this time, the authorization policy can include allowing access to and use of the user's coffee preference data and the user's frequently visited coffee shop data, disallowing access to the user's communication number data and the user's geolocation data, and asking the user whether to authorize the use of the user's communication number data and the user's geolocation data through a pop-up window.

[0068] It should be noted that the user request permission policy, preset static usage permission policy and authorization policy involved in the embodiments of this application may include user data or data hierarchy, which allows access and reading; or user data or user hierarchy, which does not allow access and reading and requires user consent.

[0069] Therefore, by instructing the multimodal big data model whether to prompt the user for authorization when reading user data through the authorization policy, users can better and more meticulously manage whether their user data can be read by untrusted multimodal big data models, thus improving the security of user data. For user data that does not require user authorization, it can directly participate in the multimodal big data model to perform operations related to user needs, reducing the need for users to manually authorize these user data operations, improving the efficiency of access control, and also increasing the speed of reading user data by the multimodal big data model, thereby improving the utilization efficiency of the multimodal big data model.

[0070] In some embodiments, the user request permission policy in this application includes at least one of the following: a first request permission policy and a second request permission policy. Based on this, step 2301 may specifically include:

[0071] When the number of data levels is greater than or equal to the reference number of levels, the permission policy used to prompt the user for authorization when the multimodal large model reads user data is determined as the primary required permission policy. The reference number of levels refers to a pre-set standard number of levels to trigger user authorization when reading user data. If the number of data levels is greater than or equal to the reference number of levels, it indicates that the data's sensitivity, importance, or security level is higher than the standard, requiring a pop-up window to prompt the user and authorization before reading.

[0072] When the number of data levels is less than the reference number of levels, the permission policy that indicates a multimodal large model can read user data without prompting the user for authorization is determined as the second required permission policy. Specifically, if the number of data levels is greater than or equal to the reference number of levels, it indicates that the data's sensitivity, importance, or security level is lower than the standard, and it can be read without prompting the user through a pop-up window.

[0073] For example, the number of reference levels can be four. That is, when the number of data levels is greater than or equal to four reference levels, the multimodal large model can prompt the user for authorization when reading user data. In this case, the AI ​​agent can directly access and use the user's coffee preference data, frequently visited coffee shop data, and user location data, and a pop-up window will ask the user whether to authorize the use of the user's contact number data. Thus, if it is determined that the user has authorized the AI ​​agent to access and use the user's contact number data, operations related to the user's requested information can be performed.

[0074] In some embodiments, the preset static usage permission policy in this application is used to prompt the user for authorization when the multimodal large model reads user data. The user request permission policy includes at least a second request permission policy. Based on this, step 2302 above may specifically include:

[0075] If the first user permission data related to the second requirement permission policy includes the second user permission data related to the preset static usage permission policy, the permission policy related to the second user permission data will be adjusted to the first requirement permission policy.

[0076] For example, the first user permission data is the data to be accessed determined based on the data hierarchy of user data, and the second user permission data is the data pre-set by the user in a preset static usage permission policy. For instance, if the first user permission data includes the user's coffee preference data, the user's frequently visited coffee shop data, and the user's geographical location data, and the second user permission data is the user's geographical location data, then the permission policy related to the second user permission data can be adjusted to the first requirement permission policy, that is, changing the permission to allow access to the user's geographical location data to not allow access to the user's geographical location data, and a pop-up window can be used to ask the user whether to authorize the use of the user's geographical location data.

[0077] In some embodiments of this application, since individual users have different levels of sensitivity to data, for example, some users are highly sensitive to geographical location, so any scene or command can be turned off by a static framework to prevent the invocation of such data. This ensures that such data will not be used regardless of the result of the dynamic permission use framework. Based on this, a process for determining a preset static usage permission policy is provided before step 230. Based on this, before step 230, the permission control method also includes steps 2501 to 2504.

[0078] Step 2501: Receive the first input from the user to select the first data level from N data levels. N is a positive integer. Each of the N data levels has a different security level, as shown in Figure 3. N is 5, and the security levels can be arranged from largest to smallest as S5, S4, S3, S2, S1.

[0079] Step 2502: In response to the first input, display M data categories corresponding to the first data level, where M is a positive integer.

[0080] It should be noted that the N data levels and M data categories in the embodiments of this application can be classified according to standards, such as the TC260 national standard GB / T 43697 "Data Security Technology Data Classification and Grading Rules".

[0081] Step 2503: Receive the second input from the user to select the first data category from M data categories.

[0082] Step 2504: In response to the second input, the permission policy used to instruct the multimodal large model not to prompt the user for authorization when reading user data of the first data category is determined as the preset static usage permission policy.

[0083] For example, users can define specific data type permissions through a static data access permission framework. Users can define that location information is unavailable, while other permissions can be authorized through an AI agent. This framework can be the operating system's own permission framework, meaning it has clear and fixed control rules for data. For instance, for geolocation data access, permission switches in the settings can explicitly indicate whether an application can use that data.

[0084] This allows users to better and more meticulously manage whether user data can be read by untrusted applications and the AI ​​agent itself, improving the security of user data. Furthermore, for user data that does not require user authorization, the AI ​​agent can perform relevant operations. For users, performing operations related to user needs is imperceptible, thereby reducing the need for users to manually authorize this user data, improving the efficiency of access control, and also increasing the speed of reading user data in multimodal large models, thus improving the utilization efficiency of multimodal large models.

[0085] Furthermore, after step 230, the access control method provided in this application embodiment may also include steps 2601 and 2602.

[0086] Step 2601: Generate operation flow information according to the authorization policy. The operation flow information refers to a series of orderly and coherent steps or operations performed according to the authorization policy to complete the reading of a specific item of user data.

[0087] For example, if the authorization policy includes direct access to and use of the user's coffee preference data, frequently visited coffee shop data, and user location data, and a pop-up window asks the user whether to authorize the use of the user's contact number data, then, upon determining that the user has authorized the AI ​​agent to access and use the user's contact number data, operation flow information can be generated. This operation flow information includes "launch the B coffee shop application," "select the specific location of B coffee shop: B coffee shop at subway station A," "coffee type: Americano," "quantity: 1," "remarks: takeaway," "order account number 12345678910," "initiate payment via payment account 610123456789," and "display order completion information after payment."

[0088] Step 2602: Using the multimodal large model, perform operations related to the operation process information according to the operation process information.

[0089] For example, the application for coffee shop B can be run in the background of an electronic device, and coffee shop B at subway station A can be selected. An Americano can be ordered through the communication number with the ordering account number 123, with a note indicating that it can be taken away.

[0090] In some embodiments of this application, after step 2602, the access control method provided in this application may further include steps 2603 and 2604.

[0091] Step 2603: Store records of multimodal large model operations related to user demand information.

[0092] For example, taking the above example again, the record of performing an operation related to user demand information may include running the B coffee shop application in the background of the electronic device, selecting B coffee shop at subway station A, ordering an Americano through the communication number with the ordering account number 123, and noting that it can be taken away.

[0093] Step 2604: Upon receiving the user's third input, based on the record of operations related to the user's needs performed by the multimodal large model, display the interface of the multimodal large model performing operations related to the user's needs.

[0094] For example, since the above operations are invisible to the user, the above operations can be recorded and displayed when the user wants to view them, showing the interface of the B coffee shop application, the interface of selecting B coffee shop at subway station A, the interface of ordering an Americano with the note "takeaway" through the communication number with the order account number 123, and the interface of successful payment.

[0095] This allows users to easily view records of operations performed by the multimodal large model that are related to their needs, thereby improving the usability of the multimodal large model.

[0096] In some embodiments of this application, there may be situations where user data is uploaded to a server for processing or processed by an untrusted third-party application. In such cases, to ensure data security, user data or operation process information can be anonymized to avoid excessive use of user data. Based on this, before step 2602, the permission control method provided in this application embodiment may further include step 2605, performing data anonymization processing on the operation process information to obtain anonymized operation process information. Data anonymization refers to transforming sensitive information according to anonymization rules to achieve reliable protection of sensitive privacy data. In this application embodiment, sensitive information includes, but is not limited to, the user's payment account, communication number, etc.

[0097] For example, before a multimodal large model can transmit data related to operation flow information to the corresponding application or server, it can perform anonymization, desensitization, or privacy computation processing on user data or operation flow information through an intermediate layer to prevent user data from being transmitted to the application in plaintext. For instance, if the operation flow information includes a weather query, it can provide city-level geographic location information instead of location information down to the specific street level.

[0098] Based on this, step 2602 may specifically include:

[0099] Using a multimodal large model, operations related to the desensitization process are executed according to the desensitization process information to obtain the operation result information.

[0100] For example, the operation flow information includes "Launch the B coffee shop application", "Select the specific location of B coffee shop: B coffee shop at subway station A", "Coffee type: Americano", "Quantity: 1", "Remarks: Takeaway", "Ordering account number: 12345678910", "Initiate payment via payment account 610123456789", and "Order completion information is displayed after payment". The operation result information could be "One Americano for takeaway has been ordered from B coffee shop at subway station A".

[0101] Therefore, this application provides a method and system for authorizing data based on the understanding of the hierarchical and classification of user data by a multimodal big model of electronic devices, and the understanding of the purpose of user data use. The purpose is to help users better and more meticulously manage whether their data can be used by third parties or untrusted multimodal big models. In this way, compared with the authorization method of a single data class in related technologies, the authorization management of user data categories, data levels, and the purpose of data use can be automated.

[0102] Based on this, in order to better illustrate the permission control method provided in the embodiments of this application, a detailed description will be given below with reference to Figure 4.

[0103] As shown in Figure 4, the access control method in this application embodiment can be described as follows: steps 1 to 6.

[0104] Step 1: Users define specific preset static access permission policies through the data static access permission framework. For example, users can define that user geolocation data in the information and communication category of data level S2 is not allowed, while other permissions can be authorized through the AI ​​agent.

[0105] Step 2: The user issues a command through the AI ​​agent interface. After receiving the command, the AI ​​agent analyzes which data the command requires and then analyzes the level and type of the data used according to the defined data classification standards. For example, as shown in Figure 3, by classifying user data into data categories and levels, a certain type of user data can be identified. Then, according to the user's settings, data of type S4 or higher cannot be automatically granted through dynamic understanding of the command; a pop-up window requires the user to click confirmation before that type of data can be used.

[0106] Step 3: Based on the type and hierarchy of the data used, and the understanding of the purpose of using the data, the AI ​​agent determines whether it can authorize the use of the data. For example, after a user issues a command to the AI ​​agent to order coffee, it can be anticipated that the command will use: 1. the user's geographical location data; 2. the user's coffee preference data; 3. the user's frequently visited coffee shop data; and 4. the user's contact number data. Now, assuming that the user's coffee preference data and frequently visited coffee shop data are S2 data, geographical location data is S3 data, and the user's contact number data is S4 data, then the AI ​​agent directly obtains and uses the coffee preference data, frequently visited coffee shop data, and the user's geographical location data, and pops up a window asking the user whether to authorize the use of the user's contact number data.

[0107] Step 4: Combining the AI ​​agent's user-defined permission policies and user-defined static usage permission policies, a dynamic data usage authorization policy is provided. As in the example in Step 3 above, after receiving a coffee order command, the AI ​​agent correctly categorizes and classifies the data used in the command. Then, combining this with the user's settings in the static permission framework (e.g., geolocation data is unavailable), it determines whether the command can be completed and whether a further pop-up window is needed to request user authorization.

[0108] Step 5: Record the operations performed by the multimodal large model related to user needs information in the monitoring system so that users can view them later.

[0109] Step 6: Before the multimodal big model determines that data can be passed to the corresponding application according to the authorization policy, the user data and / or operation process information generated according to the authorization policy will be desensitized, anonymized or privacy-preserving processed through an intermediate layer to prevent user data from being passed to the application in plaintext.

[0110] Therefore, the embodiments of this application can fully utilize the AI ​​agent's understanding of commands, data classification and grading, and the purpose of data use to dynamically and automatically determine whether the use of user data is reasonable, thereby automatically authorizing the use of data without requiring manual authorization from the user. This reduces the need for users to manually authorize these user data, improves the efficiency of permission control, and also increases the speed of reading user data in multimodal large models, thus improving the efficiency of using multimodal large models.

[0111] It should be noted that the permission control method provided in this application can be executed by electronic devices such as mobile phones, tablets, laptops, PDAs, and wearable devices. Some embodiments of this application use electronic devices as the executing entity to illustrate the permission control method provided in this application.

[0112] The permission control method provided in this application can be executed by a permission control device. This application uses the example of a permission control device executing the permission control method to illustrate the device for the permission control method provided in this application.

[0113] This application also provides an access control device. A detailed description is provided in conjunction with Figure 5.

[0114] Figure 5 is a schematic diagram of the access control device provided in some embodiments of this application.

[0115] As shown in Figure 5, the access control device 50 can be applied to electronic devices, and the access control device 50 may specifically include:

[0116] The acquisition module 501 is used to acquire user demand information, which is used to indicate the user's need to use the multimodal large model.

[0117] The determination module 502 is used to determine user data related to user demand information based on user demand information;

[0118] The generation module 503 is used to generate an authorization policy based on the data hierarchy of user data. The authorization policy is used to indicate whether to prompt the user for authorization when the multimodal large model reads user data. The data hierarchy is used to represent the security level of user data.

[0119] Display module 504 is used to display authorization prompt information according to the authorization policy.

[0120] The permission control device 50 in the embodiments of this application will be described in detail below.

[0121] In some embodiments of this application, the generation module 503 may be specifically used to determine user request permission policies based on the data hierarchy of user data;

[0122] Authorization policies are generated based on user-demand permission policies and preset static usage permission policies.

[0123] In some embodiments of this application, when the user request permission policy includes at least one of the following: a first request permission policy and a second request permission policy, the determining module 502 may specifically be used to determine the permission policy used to prompt the user for authorization when the multimodal large model reads user data as the first request permission policy when the number of data levels is greater than or equal to the number of reference levels.

[0124] When the number of data levels is less than the number of reference levels, the permission policy that indicates that the user should not be prompted for authorization when the multimodal large model reads user data is determined as the second required permission policy.

[0125] In some embodiments of this application, the generation module 503 may be specifically used to, when a preset static usage permission policy is used to instruct a multimodal large model to read user data, prompt the user for authorization, and the user request permission policy includes at least a second request permission policy, and the first user permission data related to the second request permission policy includes the second user permission data related to the preset static usage permission policy, adjust the permission policy related to the second user permission data to the first request permission policy.

[0126] In some embodiments of this application, the access control device 50 may further include a receiving module and a display module; wherein,

[0127] The receiving module is used to receive the first input from the user to select the first data level from N data levels, where N is a positive integer, when there are N data levels.

[0128] The display module is used to respond to the first input and display M data categories corresponding to the first data level, where M is a positive integer;

[0129] The receiving module can also be used to receive a second input from the user selecting a first data category from M data categories;

[0130] The determination module 502 can also be used, in response to the second input, to determine the permission policy that does not prompt the user for authorization as a preset static usage permission policy, and the permission policy that does not prompt the user for authorization is the permission policy used to instruct the multimodal large model to read user data of the first data category.

[0131] In some embodiments of this application, the determining module 502 can also be used to determine the data category of the user data based on the content of the user data;

[0132] Based on the association information between reference data categories and reference data levels, determine the data level associated with the data category;

[0133] The data hierarchy associated with the data category is determined as the data hierarchy for user data.

[0134] In some embodiments of this application, the access control device 50 may further include an identification module and a determination module; wherein,

[0135] The recognition module is used to identify user demand information through a multimodal large model to obtain the user's intention instructions for operating electronic devices;

[0136] The determination module can also be used to determine the user data required for a user to operate an electronic device based on intent instructions.

[0137] In some embodiments of this application, the access control device 50 may further include a generation module and an execution module; wherein,

[0138] The generation module is used to generate operation process information according to the authorization policy;

[0139] The execution module is used to perform operations related to the operation process information based on the multimodal large model.

[0140] In some embodiments of this application, the access control device 50 may further include a storage module and a display module; wherein,

[0141] The storage module is used to store records of operations performed by the multimodal large model related to user needs information;

[0142] The display module is used to display the interface of the multimodal large model performing operations related to user needs information based on the records of operations performed by the multimodal large model in response to a third user input.

[0143] In some embodiments of this application, the access control device 50 in the embodiments of this application may further include a processing module for performing data desensitization processing on the operation process information to obtain desensitized operation process information;

[0144] Specifically, the execution module can be used to perform operations related to the desensitization operation process information through a multimodal large model, and obtain operation result information.

[0145] The access control device in this application embodiment can be an electronic device or a component within an electronic device, such as an integrated circuit or a chip. The electronic device can be a terminal or other devices besides a terminal. For example, the electronic device can be a mobile phone, tablet computer, laptop computer, PDA, in-vehicle electronic device, mobile internet device (MID), augmented reality (AR) / virtual reality (VR) device, robot, wearable device, ultra-mobile personal computer (UMPC), netbook, or personal digital assistant (PDA), etc. It can also be a server, network attached storage (NAS), personal computer (PC), television set (TV), ATM, or self-service machine, etc. This application embodiment does not specifically limit the scope of the device.

[0146] The access control device in this application embodiment can be a device with an operating system. This operating system can be Android, iOS, or other possible operating systems; this application embodiment does not specifically limit it.

[0147] The access control device provided in this application embodiment can implement all the processes implemented in the access control method embodiments shown in Figures 1 to 4, and achieve the same technical effect. To avoid repetition, it will not be described again here.

[0148] Based on this, the permission control device provided in this application embodiment can determine user data related to the user demand information based on the obtained user demand information, wherein the user demand information is used to indicate the user demand for using the multimodal large model; then, based on the data hierarchy of the user data, an authorization policy is generated, the authorization policy is used to indicate whether to prompt the user for authorization when the multimodal large model reads the user data, the data hierarchy is used to represent the security level of the user data, and authorization prompt information is displayed according to the authorization policy. This approach leverages the multimodal big data model's understanding of user needs to determine the model's purpose in accessing user data. Combined with an understanding of user data hierarchy, it dynamically assesses the appropriateness of the model's use of user data. An authorization strategy instructs the model whether to prompt the user for authorization when reading user data. For user data requiring authorization, an authorization prompt can be displayed, assisting users in better and more meticulously managing whether user data can be read by untrusted multimodal big data models, thus improving data security. For user data that does not require authorization, it can directly participate in the multimodal big data model's operations related to user needs, reducing the need for manual authorization and improving the efficiency of access control. This also increases the speed at which the multimodal big data model reads user data, thereby enhancing its overall efficiency.

[0149] Optionally, as shown in FIG6, this application embodiment also provides an electronic device 60, including a processor 601 and a memory 602. The memory 602 stores a program or instructions that can run on the processor 601. When the program or instructions are executed by the processor 601, they implement the various steps of the above-described permission control method embodiment and can achieve the same technical effect. To avoid repetition, they will not be described again here.

[0150] It should be noted that the electronic devices in the embodiments of this application include the aforementioned mobile electronic devices and non-mobile electronic devices.

[0151] Figure 7 is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of this application.

[0152] The electronic device 700 includes, but is not limited to, components such as: radio frequency unit 701, network module 702, audio output unit 703, input unit 704, sensor 705, display unit 706, user input unit 705, interface unit 708, memory 709, and processor 710.

[0153] Those skilled in the art will understand that the electronic device 700 may also include a power supply (such as a battery) for supplying power to various components. The power supply may be logically connected to the processor 710 through a power management system, thereby enabling functions such as managing charging, discharging, and power consumption through the power management system.

[0154] The electronic device structure shown in Figure 7 does not constitute a limitation on the electronic device. The electronic device may include more or fewer components than shown, or combine certain components, or have different component arrangements, which will not be elaborated here.

[0155] In this embodiment, processor 710 is used to acquire user demand information, which indicates the user's need to use the multimodal large model. Processor 710 can also be used to determine user data related to the user demand information. Processor 710 can also be used to generate an authorization policy based on the data hierarchy of the user data. The authorization policy indicates whether to prompt the user for authorization when the multimodal large model reads user data, and the data hierarchy represents the security level of the user data. Display unit 706 is used to display authorization prompt information according to the authorization policy.

[0156] The electronic device 700 is described in detail below.

[0157] In some embodiments of this application, the processor 710 may specifically be used to determine user request permission policies based on the data hierarchy of user data.

[0158] Authorization policies are generated based on user-demand permission policies and preset static usage permission policies.

[0159] In some embodiments of this application, when the user request permission policy includes at least one of the following: a first request permission policy and a second request permission policy, the processor 710 can be used to determine the permission policy used to prompt the user for authorization when the multimodal large model reads user data as the first request permission policy when the number of data levels is greater than or equal to the number of reference levels.

[0160] When the number of data levels is less than the number of reference levels, the permission policy that indicates that the user should not be prompted for authorization when the multimodal large model reads user data is determined as the second required permission policy.

[0161] In some embodiments of this application, the processor 710 may specifically be used to, when a preset static usage permission policy is used to instruct a multimodal large model to read user data, prompt the user for authorization, and the user request permission policy includes at least a second request permission policy, and the first user permission data related to the second request permission policy includes the second user permission data related to the preset static usage permission policy, adjust the permission policy related to the second user permission data to the first request permission policy.

[0162] In some embodiments of this application, the user input unit 705 is configured to receive a first input from a user selecting a first data level from N data levels, where N is a positive integer, when the data level includes N data levels.

[0163] Display unit 706 is configured to respond to a first input and display M data categories corresponding to the first data level, where M is a positive integer;

[0164] User input unit 705 can also be used to receive a second input from a user selecting a first data category from M data categories;

[0165] The processor 710 can also be used, in response to the second input, to determine the permission policy that does not prompt the user for authorization as a preset static usage permission policy, wherein the permission policy that does not prompt the user for authorization is the authorization policy used to instruct the multimodal large model to read user data of the first data category.

[0166] In some embodiments of this application, the processor 710 may also be used to determine the data category of the user data based on the content of the user data;

[0167] Based on the association information between reference data categories and reference data levels, determine the data level associated with the data category;

[0168] The data hierarchy associated with the data category is determined as the data hierarchy for user data.

[0169] In some embodiments of this application, the processor 710 can also be used to identify user demand information through a multimodal large model to obtain the user's intention instructions for operating the electronic device.

[0170] Based on the intent command, determine the user data required for the user to operate the electronic device.

[0171] In some embodiments of this application, the processor 710 can also be used to generate operation flow information in accordance with the licensing policy;

[0172] Using a multimodal large model, operations related to the operation process information are executed according to the operation process information.

[0173] In some embodiments of this application, memory 709 is used to store records of multimodal large models performing operations related to user demand information;

[0174] Display unit 706 is used to display the interface of the multimodal large model performing operations related to user demand information based on the record of operations performed by the multimodal large model according to the user's third input.

[0175] In some embodiments of this application, the processor 710 is used to perform data desensitization processing on the operation process information to obtain desensitized operation process information.

[0176] Using a multimodal large model, operations related to the desensitization process are executed according to the desensitization process information to obtain the operation result information.

[0177] It should be understood that the input unit 704 may include a graphics processing unit (GPU) 7041 and a microphone 7042. The GPU 7041 processes image data of still images or videos acquired by an image capture device (such as a camera) in video capture mode or image capture mode. The display unit 706 may include a display panel, which may be configured in the form of a liquid crystal display, an organic light-emitting diode, or the like. The user input unit 705 includes at least one of a touch panel 7051 and other input devices 7052. The touch panel 7051 is also called a touch screen. The touch panel 7051 may include two parts: a touch detection device and a touch display. Other input devices 7052 may include, but are not limited to, a physical keyboard, function keys (such as volume display buttons, power buttons, etc.), a trackball, a mouse, and a joystick, which will not be described in detail here.

[0178] The memory 709 can be used to store software programs and various data. The memory 709 may primarily include a first storage area for storing programs or instructions and a second storage area for storing data. The first storage area may store the operating system, application programs or instructions required for at least one function (such as sound playback, image playback, etc.). Furthermore, the memory 709 may include volatile memory or non-volatile memory, or both. The non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM), static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct memory bus RAM (DRRAM). The memory 709 in the embodiments of this application includes, but is not limited to, these and any other suitable types of memory.

[0179] Processor 710 may include one or more processing units; optionally, processor 710 integrates an application processor and a modem processor, wherein the application processor mainly handles operations involving the operating system, user interface, and applications, and the modem processor mainly handles wireless display signals, such as a baseband processor. It is understood that the aforementioned modem processor may also not be integrated into processor 710.

[0180] This application also provides a readable storage medium storing a program or instructions. When the program or instructions are executed by a processor, they implement the various processes of the above-described permission control method embodiments and achieve the same technical effect. To avoid repetition, they will not be described again here.

[0181] The processor is the processor in the electronic device described in the above embodiments. The readable storage medium includes computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk.

[0182] In addition, this application embodiment provides another chip, which includes a processor and a display interface. The display interface and the processor are coupled. The processor is used to run programs or instructions to implement the various processes of the above-described permission control method embodiments and can achieve the same technical effect. To avoid repetition, it will not be described again here.

[0183] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.

[0184] This application provides a computer program product that is stored in a storage medium and executed by at least one processor to implement the various processes of the above-described permission control method embodiments, and can achieve the same technical effect. To avoid repetition, it will not be described again here.

[0185] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0186] Furthermore, it should be noted that the scope of the methods and apparatus in the embodiments of this application is not limited to performing functions in the order shown or discussed, but may also include performing functions substantially simultaneously or in the reverse order, depending on the functions involved. For example, the described methods may be performed in a different order than described, and various steps may be added, omitted, or combined. In addition, features described with reference to certain examples may be combined in other examples.

[0187] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a computer software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods of the various embodiments of this application.

[0188] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without falling within the scope of the spirit and claims of this application, and all of these forms are within the protection scope of this application.

Claims

1. An access control method, comprising: Obtain user demand information, which is used to indicate the user's need to use a multimodal large model; Based on the user demand information, determine the user data related to the user demand information; Based on the data hierarchy of the user data, an authorization policy is generated. The authorization policy is used to indicate whether the multimodal large model should prompt the user for authorization when reading the user data. The data hierarchy is used to represent the security level of the user data. According to the authorization policy, display authorization prompt information.

2. The method according to claim 1, wherein, The generation of authorization policies based on the data hierarchy of the user data includes: Based on the data hierarchy of the user data, determine the user's required permission strategy; The authorization policy is generated based on the user requirement permission policy and the preset static usage permission policy.

3. The method according to claim 2, wherein, The user request permission policy includes at least one of the following: a first request permission policy and a second request permission policy. The determination of user permission policies based on the data hierarchy of the user data includes: If the number of data levels is greater than or equal to the number of reference levels, the permission policy used to prompt the user for authorization when the multimodal large model reads the user data will be determined as the first required permission policy. If the number of data levels is less than the number of reference levels, the permission policy that instructs the multimodal large model not to prompt the user for authorization when reading user data will be determined as the second required permission policy.

4. The method according to claim 3, wherein, The preset static usage permission policy is used to instruct the user to grant authorization when the multimodal large model reads user data, and the user request permission policy includes at least the second request permission policy; The process of generating the authorization policy based on the user-demand permission policy and the preset static usage permission policy includes: If the first user permission data related to the second demand permission policy includes the second user permission data related to the preset static usage permission policy, the permission policy related to the second user permission data shall be adjusted to the first demand permission policy.

5. The method according to claim 2, wherein, The data hierarchy includes N data levels; The method further includes: Receive the first input from the user, who selects the first data level from N data levels, where N is a positive integer; In response to the first input, M data categories corresponding to the first data level are displayed, where M is a positive integer; Receive a second input from the user to select a first data category from the M data categories; In response to the second input, the permission policy that does not prompt the user for authorization is determined as the preset static usage permission policy. The permission policy that does not prompt the user for authorization is the permission policy used to instruct the multimodal large model to read user data of the first data category.

6. The method according to claim 1 or 2, wherein, Before generating the authorization policy based on the data hierarchy of the user data, the method further includes: Based on the content of the user data, determine the data category of the user data; Based on the association information between reference data categories and reference data levels, determine the data level associated with the data category; The data level associated with the data category is determined as the data level of the user data.

7. The method according to claim 1, wherein, The step of determining user data related to the user demand information based on the user demand information includes: The user demand information is identified through the multimodal large model to obtain the user's intention instructions for operating electronic devices; Based on the intent instruction, determine the user data required for the user to operate the electronic device.

8. The method according to claim 1, wherein, The method further includes: According to the authorization strategy, generate operation process information; Using the multimodal large model, operations related to the operation process information are executed according to the operation process information.

9. The method according to claim 8, wherein, The method further includes: Store records of operations performed by the multimodal large model related to the user's needs information; Upon receiving a third input from the user, the system records the operations performed by the multimodal large model related to the user's needs information, and displays an interface showing the multimodal large model performing operations related to the user's needs information.

10. The method according to claim 8, wherein, Before executing operations related to the operation flow information according to the operation flow information using the multimodal large model, the method further includes: The operation process information is subjected to data desensitization processing to obtain desensitized operation process information; The step of executing operations related to the operation process information through the multimodal large model, according to the operation process information, includes: Using the multimodal large model, operations related to the desensitization operation process information are executed according to the desensitization operation process information to obtain operation result information.

11. An access control device, comprising: The acquisition module is used to acquire user demand information, which is used to indicate the user's need to use the multimodal large model. The determination module is used to determine user data related to the user demand information based on the user demand information. The generation module is used to generate an authorization policy based on the data hierarchy of the user data. The authorization policy is used to instruct whether to prompt the user for authorization when the multimodal large model reads the user data. The data hierarchy is used to represent the security level of the user data. The display module is used to display authorization prompt information according to the authorization policy.

12. An electronic device, comprising: A processor and a memory, the memory storing a program or instructions that can run on the processor, the program or instructions, when executed by the processor, implement the steps of the access control method as described in any one of claims 1-10.

13. A readable storage medium storing a program or instructions that, when executed by a processor, implement the steps of the access control method as described in any one of claims 1-10.

14. A computer program product stored in a storage medium, the program product being executed by at least one processor to implement the steps of the access control method as claimed in any one of claims 1-10.

15. An electronic device configured to perform the steps of the access control method as claimed in any one of claims 1-10.

16. A chip, the chip comprising a processor and a communication interface, the communication interface being coupled to the processor, the processor being configured to run a program or instructions to implement the steps of the access control method as described in any one of claims 1-10.