Graphical Application Access Control Strategy for Android Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing access control solutions for Android operating systems are complex and difficult for common users to implement, leading to security threats due to the need for intricate operation details and technical language, making it hard to formulate effective access control strategies between applications.
Innovation Solution
A graphical method for users to input and edit access strategies, where graphics indicate access rules between applications, allowing for the conversion of these graphics into system-identifiable access control strategies, enabling simple and flexible management of application access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a traditional access control solution based on SELinux and SEAndroid is used, then security control capability is improved, but system complexity and difficulty of operation increase significantly
Solution Approach 1:
The patent introduces a graphical interface as an intermediary between users and the complex SELinux/SEAndroid access control system. Users interact with visual elements (dragging application icons to security level zones) rather than directly configuring complex policy files. This intermediary layer translates simple user actions into the complex security configurations required by the underlying system, resolving the contradiction between maintaining strong security control and reducing system complexity.
Solution Approach 2:
The patent replaces the mechanical system of manually editing complex policy files and configuration parameters with a graphical user interface. Instead of requiring users to write and compile text-based security policies, the system uses visual drag-and-drop operations where application icons are moved to different security zones. This substitution transforms a complex text-based configuration task into an intuitive visual interaction, significantly reducing the perceived system complexity while maintaining the same security control capabilities.
2Reliability
If a traditional access control solution based on SELinux and SEAndroid is used, then security control capability is improved, but ease of operation deteriorates
Solution Approach 1:
The graphical interface serves as an intermediary that translates complex security management tasks into simple visual operations. Users drag application icons to security level zones (untrusted, semi-trusted, trusted) instead of configuring policy files. This intermediary layer handles the complexity of SELinux/SEAndroid policy compilation and enforcement in the background, presenting only simple drag-and-drop operations to the user, thereby dramatically improving ease of operation while preserving security control capability.
Solution Approach 2:
The patent uses visual copies or representations of applications (icons) in the graphical interface instead of requiring direct manipulation of application identifiers or policy file entries. Users interact with visual copies of applications in security zones, and the system translates these visual representations into the actual security configurations. This copying approach makes the operation intuitive and easier to understand, while the underlying system processes the actual security policies.
3Ease of operation
If graphical input method is used, then ease of operation is improved, but conversion complexity increases
Solution Approach 1:
The system introduces an automatic conversion module as an intermediary between the simple graphical input (dragged icons and security zones) and the complex output (SELinux/SEAndroid policy files). This conversion module handles the complexity of translating visual configurations into compilable security policies, including determining which applications to grant permissions to, what permissions to assign, and generating the appropriate policy file syntax. Users benefit from simple graphical operation without needing to understand the conversion complexity, as the intermediary module handles this automatically.
Data Source
Figure 1~2
Figure 3~4A
Figure 4B~5
AI summary
The present invention discloses an application access control method and apparatus. The method includes: acquiring a graphic input by a user; generating an access strategy graphic according to the graphic, where the access strategy graphic indicates an access rule of whether at least two applications are allowed to access each other; converting the access strategy graphic into an access control strategy that can be identified by a system, where the access control strategy is used to indicate whether applications are allowed to access each other; and controlling access between the at least two applications according to the access control strategy. According to the application access control method and apparatus in embodiments of the present invention, a graphic input by a user is acquired, and an access strategy graphic formed by the graphic is converted into an access control strategy that can be identified by a system, so as to control application access according to the access control strategy; in this way, the user can compile access control strategies of applications in the system in a simple, visual, and flexible graphical manner, thereby improving security performance of the system and further improving user experience.