WO2017016211A1 - 对终端权限的控制方法、系统及存储介质 - Google Patents

对终端权限的控制方法、系统及存储介质 Download PDF

Info

Publication number
WO2017016211A1
WO2017016211A1 PCT/CN2016/073752 CN2016073752W WO2017016211A1 WO 2017016211 A1 WO2017016211 A1 WO 2017016211A1 CN 2016073752 W CN2016073752 W CN 2016073752W WO 2017016211 A1 WO2017016211 A1 WO 2017016211A1
Authority
WO
WIPO (PCT)
Prior art keywords
authority
terminal
information
attribute
rights
Prior art date
Application number
PCT/CN2016/073752
Other languages
English (en)
French (fr)
Inventor
黄勤波
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2017016211A1 publication Critical patent/WO2017016211A1/zh

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication

Definitions

  • the invention belongs to the field of intelligent terminals, and in particular relates to a method, a system and a computer storage medium for controlling terminal rights.
  • smart terminals With the rapid development of mobile Internet, smart terminals have become popular, and various applications based on smart terminals include office software, financial software, social software, game software, and the like. A wide variety of applications have greatly changed people's work, life and communication methods, but also deeply plagued users, such as work and life can not be separated, frequent security incidents and so on.
  • the system rights and/or application rights of the smart terminal used by the user may not be applicable to all environments or occasions.
  • the system rights and/or application rights of the smart terminal are different.
  • the operation uses permission restrictions, and existing smart terminals cannot automatically adjust these permissions according to changes in the environment.
  • the embodiments of the present invention provide a method, a system, and a computer storage medium for controlling terminal rights.
  • An embodiment of the present invention provides a method for controlling a terminal authority, where the terminal stores a first attribute for a first right, and the first right includes at least a system right and/or an application right of the terminal.
  • the first attribute is used to describe an opening and closing condition of the first authority, and the Methods include:
  • first information of the terminal where the first information is information used to describe an environment in which the terminal is located;
  • the obtaining the permission control policy based on the obtained first information and the first attribute stored by the terminal for the first permission including:
  • the first information is time information and/or location information of the terminal, and the opening and closing conditions of the first permission are an allowed time range of the first permission to be turned on and off and/or Allowable range of locations;
  • the method further includes:
  • the terminal When the terminal is triggered to generate a state adjustment command for the first privilege, it is determined whether the first privilege is configured with a security authentication policy, and if a security authentication policy is configured, performing a security authentication based on the security authentication policy After the adoption, the state adjustment of the first authority is performed according to the state adjustment instruction; if the security authentication policy is not configured, the state adjustment of the first authority is performed according to the state adjustment instruction.
  • the method before the obtaining the first information of the terminal, the method further includes:
  • the manner of setting the first attribute for the first permission is at least one of the following:
  • At least one of the first rights to execute the opening and closing conditions is selected from system rights and/or application rights of the terminal.
  • An embodiment of the present invention further provides a terminal authority control system, where the system includes: an initialization unit, a first information obtaining unit, a policy control unit, and an authority control unit;
  • the initializing unit is configured to store a first attribute for the first right, the first right includes at least a system right and/or an application right of the terminal, and the first attribute is used to describe the first right Turn the conditions on and off;
  • the first information obtaining unit is configured to obtain first information of the terminal, where the first information is information used to describe an environment in which the terminal is located;
  • the policy control unit is configured to obtain an authority control policy based on the obtained first information and the first attribute for the first authority stored by the terminal, and represent that the rights control policy needs to be Notifying the authority control unit when the first authority performs state adjustment;
  • the authority control unit is configured to perform an opening or closing operation for the first authority according to the notification of the policy control unit.
  • the policy control unit obtains the rights control policy based on the obtained first information and the first attribute stored by the terminal for the first right, including:
  • the first information is time information and/or location information of the terminal, and the opening and closing conditions of the first permission are an allowed time range of the first permission to be turned on and off and/or Allowable range of locations;
  • the policy control unit compares the obtained first information with the first attribute for the first right, and determines whether the first information meets the opening and closing conditions of the first permission described by the first attribute, including:
  • the privilege control unit is further configured to: when triggered to generate a state adjustment instruction for the first privilege, determine whether the first privilege is configured with a security authentication policy, and if the security authentication is configured The policy, after performing the security authentication based on the security authentication policy, performing state adjustment on the first authority according to the state adjustment instruction; if the security authentication policy is not configured, performing the state adjustment instruction according to the state adjustment instruction State adjustment of the first privilege.
  • system further includes a setting unit configured to set a first attribute for the first right when triggered to generate the first attribute setting instruction;
  • the manner of setting the first attribute for the first permission is at least one of the following:
  • At least one of the first rights to execute the opening and closing conditions is selected from system rights and/or application rights of the terminal.
  • the embodiment of the invention further provides a computer storage medium, wherein the computer storage medium stores computer executable instructions, and the computer executable instructions are used to execute the foregoing method for controlling terminal rights.
  • the method, system and computer storage medium for controlling the terminal authority determine whether the first authority needs to be performed by setting the first attribute for the first authority and based on the obtained first information of the intelligent terminal. State adjustment, and adaptively turn the first permission on or off when it is judged that adjustment is needed. Therefore, it is possible to automatically adjust the opening or closing of the first authority according to the change of the environment, and to ensure the security of the functional diversity and ease of use of the intelligent terminal, or to have a good diversity. Easy-to-use applications and related functions provide better security and enhance the user experience.
  • FIG. 1 is a schematic flowchart of a method for controlling terminal authority according to Embodiment 1 of the present invention
  • FIG. 2 is a schematic structural diagram of a control system for terminal authority according to Embodiment 2 of the present invention.
  • FIG. 3 is a schematic flowchart of a method for controlling terminal authority according to Embodiment 3 of the present invention.
  • FIG. 4 is a schematic flowchart of a method for controlling terminal authority according to Embodiment 4 of the present invention.
  • FIG. 5 is a schematic flowchart of a method for controlling terminal authority according to Embodiment 5 of the present invention.
  • a method for controlling terminal rights is provided in the first embodiment of the present invention, as shown in FIG. 1 , wherein the terminal stores a first attribute for the first right, and the first right includes at least the terminal.
  • System rights and/or application rights, the first attribute is used to describe the opening and closing conditions of the first authority; the method mainly includes:
  • Step 101 Obtain first information of the terminal, where the first information is information used to describe an environment in which the terminal is located.
  • the system authority refers to an operation permission of various functions of an operating system (such as an Android system, an Apple IOS operating system, a Windows operating system, etc.) of an intelligent terminal, such as a wireless local area network (WiFi) of a smart terminal.
  • an operating system such as an Android system, an Apple IOS operating system, a Windows operating system, etc.
  • WiFi wireless local area network
  • the application permissions refer to the operational usage rights of the applications installed in the smart terminal, such as: operating rights of the application. , the operational usage rights of a function of the application, and so on.
  • the smart terminal pre-stores a first attribute for the first privilege, where the first attribute includes: opening and closing conditions for system rights of the smart terminal, and/or opening of application rights for the smart terminal Close conditions and so on.
  • the conditions for opening and closing the system rights of the smart terminal such as: opening and closing conditions for the wifi operation permission of the smart terminal, opening and closing conditions of the file deletion authority for the SD card of the smart terminal, and the opening and closing conditions for the smart card terminal
  • the opening and closing conditions of the application authority for the smart terminal such as: the opening and closing conditions of the game application for the smart terminal, The opening and closing conditions of the video call function in the social application of the smart terminal, and the like.
  • the first attribute of the first privilege of the embodiment of the present invention is preset and saved in the smart terminal, and the setting and saving operation is performed before step 101, and specifically includes:
  • the manner of setting the first attribute for the first permission is at least one of the following:
  • At least one of the first rights to execute the opening and closing conditions is selected from system rights and/or application rights of the terminal.
  • the first attribute setting instruction may be generated by the smart terminal when the physical button of the smart terminal is triggered or the virtual function button is triggered; after the triggering the first attribute setting instruction is triggered, the smart terminal provides the setting of the first attribute
  • the interface is for the user to select the first permission and the setting of the first attribute.
  • the embodiment of the present invention does not limit the specific setting manner or process of the first attribute. The foregoing is only two implementation manners of the embodiment of the present invention, and the foregoing two implementable manners may also be used in combination.
  • the first authority is selected from the system authority and/or the application authority of the terminal, and the corresponding opening and closing conditions are set for the first authority. For example, selecting the mobile data link authority of the smart terminal, and setting corresponding opening and closing conditions for the mobile data link authority; for example, selecting a file deletion permission of the SD card of the smart terminal, and Determining the opening and closing conditions corresponding to the file deletion permission setting of the SD card; for example, selecting the usage operation authority of the game application of the smart terminal, and setting the corresponding opening and closing conditions for the usage operation authority of the game application And, for example, selecting a video call function in a social application of the smart terminal, and setting a corresponding open and close condition for the video call function in the social application.
  • At least one first authority for performing the opening and closing conditions is selected from the system authority and/or the application authority of the terminal. For example, first set the permission opening and closing conditions, and then select the permissions that apply the above conditions, the permission package Including SD card file deletion permissions, the use of a game-like application, the video call function in a social application. That is to say, the file deletion permission of the selected SD card, the operation permission of a game application, and the video call function in a social application are all applicable to the same opening and closing conditions described above.
  • the smart terminal may obtain first information for describing the environment in which it is located periodically or non-periodically, and the first information may be where the smart terminal is located.
  • the location information may also be the time information of the smart terminal, the noise coefficient of the environment in which the smart terminal is located, or even the light intensity of the environment in which the smart terminal is located.
  • the embodiment of the present invention does not limit the type and content of the first information, and may be extended according to actual needs. Similarly, the embodiment of the present invention does not limit the manner in which the first information is obtained, and the first information that is applicable to the embodiment of the present invention. The manner of obtaining should all fall within the scope to be protected by the embodiments of the present invention.
  • Step 102 Obtain an authority control policy based on the obtained first information and the first attribute stored by the terminal for the first authority.
  • step 102 includes:
  • the first information may be time information and/or location information of the terminal, and the opening and closing conditions of the first permission are an allowed time range of the first permission to be turned on and off. And/or allowable range of locations;
  • Step 103 Perform, according to the rights control policy, that when the state adjustment needs to be performed on the first authority, perform an opening or closing operation for the first authority.
  • the closing operation for the first authority when it is determined that the first authority needs to be closed, the closing operation for the first authority is performed; when it is determined that the first authority needs to be opened, the opening operation for the first authority is performed.
  • the embodiment of the present invention is not limited to the control of the opening and closing operations of the system rights and/or the application rights. Any practical application is applicable to the controlling party of the embodiment of the present invention. The formula should all fall within the scope to be protected by the embodiments of the present invention.
  • the method further includes:
  • the terminal When the terminal is triggered to generate a state adjustment command for the first privilege, it is determined whether the first privilege is configured with a security authentication policy, and if a security authentication policy is configured, performing a security authentication based on the security authentication policy After the adoption, the state adjustment of the first authority is performed according to the state adjustment instruction; if the security authentication policy is not configured, the state adjustment of the first authority is performed according to the state adjustment instruction.
  • the embodiment of the present invention also supports manual adjustment of the first privilege state.
  • the smart terminal When the user triggers manual state adjustment on a certain privilege, the smart terminal generates a state adjustment instruction for the first privilege;
  • the terminal is pre-configured with the security authentication policy for the first privilege manual state adjustment, and the state adjustment of the first privilege can be performed according to the adjustment command after the authentication is passed; if the smart terminal is not configured in advance for the first
  • a security authentication policy for privilege manual state adjustment the state adjustment of the first authority may be performed according to the adjustment instruction without authentication.
  • the smart terminal can provide a security authentication operation interface for the user to input the authentication information. After the authentication information input by the user is collected, the security authentication is performed based on the authentication information input by the user.
  • the second embodiment of the present invention further provides a control system for terminal rights, as shown in FIG. 5, the system includes: an initialization unit 10, a first information obtaining unit 20, Policy control unit 30 and authority control unit 40; wherein
  • the initializing unit 10 is configured to store a first attribute for the first right, the first right includes at least a system right and/or an application right of the terminal, and the first attribute is used to describe the first right Opening and closing conditions;
  • the first information obtaining unit 20 is configured to obtain first information of the terminal, where the A message is information for describing an environment in which the terminal is located;
  • the policy control unit 30 is configured to obtain an privilege control policy based on the obtained first information and the first attribute stored by the terminal for the first privilege, and the characterization of the privilege control policy needs to be performed Notifying the authority control unit 40 when the first authority performs state adjustment;
  • the authority control unit 40 is configured to perform an opening or closing operation for the first authority according to the notification of the policy control unit 30.
  • system further includes a setting unit 50 configured to set a first attribute for the first right when triggered to generate a first attribute setting instruction;
  • the manner of setting the first attribute for the first permission is at least one of the following:
  • At least one of the first rights to execute the opening and closing conditions is selected from system rights and/or application rights of the terminal.
  • the first attribute setting instruction may be generated by the setting unit 50 of the smart terminal when the physical button of the smart terminal is triggered or the virtual function button is triggered; and the setting of the smart terminal after triggering the generation of the first attribute setting instruction
  • the unit 50 provides a setting interface of the first attribute for the user to select the first right and the setting of the first attribute.
  • the embodiment of the present invention does not limit the specific setting manner or process of the first attribute. The foregoing is only two implementation manners of the embodiment of the present invention, and the foregoing two implementable manners may also be used in combination.
  • the policy control unit 30 obtains the rights control policy based on the obtained first information and the first attribute stored by the terminal for the first right, including:
  • the first information is time information and/or location information of the terminal, and the opening and closing conditions of the first permission are an allowed time range of the first permission to be turned on and off and/or Allowable range of locations;
  • the policy control unit 30 compares the obtained first information with the first attribute for the first right, and determines whether the first information meets the opening and closing conditions of the first permission described by the first attribute, including:
  • the privilege control unit 40 is further configured to: when triggered to generate a state adjustment instruction for the first privilege, determine whether the first privilege is configured with a security authentication policy, if a security authentication is configured The policy, after performing the security authentication based on the security authentication policy, performing state adjustment on the first authority according to the state adjustment instruction; if the security authentication policy is not configured, performing the state adjustment instruction according to the state adjustment instruction State adjustment of the first privilege.
  • the embodiment of the present invention also supports manual adjustment of the first privilege state.
  • the privilege control unit 40 of the smart terminal When the user triggers manual state adjustment of a certain privilege, the privilege control unit 40 of the smart terminal generates a state for the first privilege. If the setting unit 50 of the smart terminal is preset with a security authentication policy for the first authority manual state adjustment, the rights control unit 40 needs to perform the first permission according to the adjustment command after the authentication is passed. State adjustment; if the setting unit 50 of the smart terminal does not previously set the security authentication policy for the first authority manual state adjustment, the rights control unit 40 may perform the state adjustment of the first authority according to the adjustment instruction without authentication.
  • the smart terminal can provide a security authentication operation interface for the user to input the authentication information. After the authentication information input by the user is collected, the security authentication is performed based on the authentication information input by the user.
  • the adaptive A permission is turned on or off.
  • the intelligent terminal of the embodiment of the present invention can automatically adjust the opening or closing of the first authority according to the change of the environment, thereby ensuring the security of the intelligent terminal while ensuring the functional diversity and ease of use, or Provides better security while having a very versatile, easy-to-use application and related features.
  • the first information of the embodiment of the present invention is used to describe the ring where the smart terminal is located.
  • the environment information may be the location information of the smart terminal, or the time information of the smart terminal, the noise coefficient of the environment in which the smart terminal is located, or even the light intensity of the environment in which the smart terminal is located.
  • the embodiment of the present invention does not limit the type and content of the first information, and may be extended according to actual needs.
  • the embodiment of the present invention does not limit the manner in which the first information is obtained, and the first information that is applicable to the embodiment of the present invention. The manner of obtaining should all fall within the scope to be protected by the embodiments of the present invention.
  • the initialization unit 10, the first information obtaining unit 20, the policy control unit 30, and the authority control unit 40 may each be a central processing unit (CPU), or a digital signal processing (DSP, Digital Signal Processor). ), or a microprocessor (MPU, Micro Processor Unit), or a Field Programmable Gate Array (FPGA).
  • CPU central processing unit
  • DSP Digital Signal Processor
  • MPU Micro Processor Unit
  • FPGA Field Programmable Gate Array
  • the following takes the first information as the location information and/or the time information of the terminal as an example, and further describes the method for controlling the terminal authority according to the embodiment of the present invention.
  • the end user has different requirements for the opening and/or closing of system rights and/or application rights in the terminal in different geographical locations, such as in a workplace, a home place or a strange location;
  • the terminal user has certain rules for the opening and/or closing habits of the terminal system rights and/or the application rights, that is, the terminal users usually have the same permission opening and/or closing habits in the same location area;
  • Regularly adjusting the operating and operating rights of the application and the system can save many manual operations of the user, save user time and improve the operating experience.
  • the method for controlling the terminal authority based on the geographical location change according to the third embodiment of the present invention is as shown in FIG. 3, and the method mainly includes:
  • step 301 the parameter configuration is initialized.
  • the terminal After setting and saving the first attribute for the first privilege (the opening and closing conditions of the first privilege), the above parameter configuration is initialized. That is to say, after the initialization, the terminal can know which rights should belong to the on or off state when in the location range.
  • step 302 the terminal monitors the location change.
  • the basic function of the terminal combined with the map, the position and the like may be used to calibrate the automatically-acquired position reference reference point, and the position range may be determined by the effective radius on the basis of the reference point, and the position range may be the area within the effective radius. It can also be an area outside the radius, or it can be a union or intersection of multiple areas.
  • the position range may be the area within the effective radius. It can also be an area outside the radius, or it can be a union or intersection of multiple areas.
  • other methods for monitoring the location range of the terminal may be used, which are not described in the embodiment of the present invention.
  • step 303 the terminal determines whether to manually restrict the rights. If yes, go to step 308. If no, go to step 304.
  • the terminal determines whether the state adjustment command for generating the authority is triggered (manual adjustment), and if so, proceeds to step 308, and if no, proceeds to step 304.
  • Steps 304-305 Monitor the rights currently used by the terminal, determine whether the rights meet the current location range of the terminal, and if yes, go to step 309, if no, go to step 306.
  • the on or off state of the currently used permission of the monitoring terminal is consistent with the requirement of the permission status corresponding to the location range in which the terminal is currently located. If yes, go to step 309, if not, go to step 306.
  • the terminal is required to turn off the photographing and recording function in the user's office area, and the photographing and recording functions are turned on at other times.
  • the position change of the terminal and the permission of the photographing and recording function it is determined whether the current location range of the terminal is current with the terminal. The status of the photo and recording functions match.
  • Step 306 Calculate the rights control policy, that is, compare the current location range of the terminal with the initialized parameters to determine the current permission to make the state adjustment, and generate a corresponding rights control policy.
  • step 307 it is determined whether automatic permission restriction is required. If yes, go to step 308. If no, go to step 309.
  • the terminal determines whether it is necessary to perform automatic permission restriction based on the permission control policy.
  • Step 308 restricting permissions as needed.
  • step 308 of step 303 the terminal performs state adjustment of the corresponding authority according to the manual operation of the user;
  • step 308 to step 307 the terminal performs a state adjustment of the corresponding authority according to the rights control policy.
  • step 309 the permissions of the terminal are normally used.
  • the terminal user has different requirements for opening and/or closing system rights and/or application rights in the terminal in different time ranges, such as daytime and nighttime; and, the terminal user is on the terminal.
  • the system permission and/or application permission opening and/or closing habits have certain rules to follow, that is, the terminal user usually has the same permission opening and/or closing habits in the same time range; then the application is adaptively adjusted according to the law.
  • the operation permission of the system can save many manual operations of the user, save user time and improve the operation experience.
  • a method for controlling terminal rights based on time change according to Embodiment 4 of the present invention is as shown in FIG. 4, and the method mainly includes:
  • step 401 the parameter configuration is initialized.
  • the time range of the terminal user, the automatic permission control switch, and the application related to the automatic permission control are configured to complete the first attribute setting for the first authority.
  • the above parameter configuration is initialized. That is to say, after the initialization, the terminal can know which rights should belong to the on or off state when it is within the time range.
  • step 402 the terminal monitors the time change.
  • step 403 the terminal determines whether the permission is manually restricted. If yes, go to step 408. If no, go to step 404.
  • the terminal determines whether the state adjustment command for generating the authority is triggered (manual adjustment), and if so, proceeds to step 408, and if no, proceeds to step 404.
  • Steps 404-405 Monitor the rights currently used by the terminal, determine whether the rights meet the current time range of the terminal, and if yes, go to step 409. If no, go to step 406.
  • the on or off state of the currently used permission of the monitoring terminal is consistent with the requirement of the permission status corresponding to the time range in which the terminal is currently located. If yes, go to step 409, if not, go to step 406.
  • the terminal is required to turn off the photographing and recording function during the user's working hours, and the photographing and recording functions are turned on at other times.
  • the time change of the terminal and the permission of the photographing and recording function it is determined whether the current time range of the terminal is current with the terminal. The status of the photo and recording functions match.
  • Step 406 Calculate the rights control policy, that is, compare the current time range of the terminal with the initialized parameters to determine the current permission to make the state adjustment, and generate a corresponding rights control policy.
  • step 407 it is determined whether automatic permission restriction is required. If yes, go to step 408. If no, go to step 409.
  • the terminal determines whether it is necessary to perform automatic permission restriction based on the permission control policy.
  • step 408 the permissions are restricted as needed.
  • step 408 of step 403 the terminal performs state adjustment of the corresponding authority according to the manual operation of the user;
  • step 408 which goes to step 407, the terminal performs state adjustment of the corresponding authority according to the authority control policy.
  • step 409 the rights of the terminal are normally used.
  • the end user has different requirements for the opening and/or closing of system rights and/or application rights in the terminal at different time and location ranges; and, the terminal user has authority on the terminal system and / or the opening and/or closing habits of the application rights have a certain rule, that is, the terminal users are usually in the same time range and location range (that is, the terminal users usually move in a specific time range within a fixed time range, There are certain rules to follow, such as working hours in the unit, after work, at home, the permission to open and / or close the habits are the same; then adaptively adjust the application and system operating rights according to the law, can save a lot of manual users Operation, saving user time and improving the operating experience.
  • the method for controlling the terminal authority based on the geographical location and the time change according to the fifth embodiment of the present invention is as shown in FIG. 5, and the method mainly includes:
  • step 501 the parameter configuration is initialized.
  • the time range of the terminal user, the range of the active location, the automatic permission control switch, and the application related to the automatic permission control are configured to complete the first attribute setting for the first permission.
  • the terminal After setting and saving the first attribute for the first privilege (the opening and closing conditions of the first privilege), the above parameter configuration is initialized. That is to say, after the initialization, the terminal can know which rights should belong to the on or off state when the time range and the location range are located.
  • step 502 the terminal monitors location and time changes.
  • step 503 the terminal determines whether the permission is manually restricted. If yes, go to step 509. If no, go to step 504.
  • the terminal determines whether the state adjustment command for generating the authority is triggered (manual adjustment), and if so, proceeds to step 509, and if no, proceeds to step 504.
  • Steps 504-505 Monitor the rights currently used by the terminal, determine whether the rights meet the current time range of the terminal, and if yes, go to step 506. If no, go to step 507.
  • step 507 If they match, go to step 506. If they do not match, go to step 507.
  • Step 506 Determine whether the privilege meets the location range in which the terminal is currently located. If yes, go to step 510. If no, go to step 507.
  • the on or off status of the currently used permission of the monitoring terminal is consistent with the requirement of the permission status corresponding to the location range in which the terminal is currently located. If yes, go to step 510, if not, go to step 507.
  • Step 507 Calculate the permission control policy, that is, compare the current time range and the location range of the terminal with the initialized parameters to determine the current permission to make the state adjustment, and generate a corresponding permission control policy.
  • step 508 it is determined whether automatic permission restriction is required. If yes, go to step 509. If no, go to step 510.
  • the terminal determines whether it is necessary to perform automatic permission restriction based on the permission control policy.
  • step 509 the permissions are restricted as needed.
  • the terminal performs state adjustment on the corresponding authority according to the manual operation of the user; if the user is particularly sensitive, if the state is manually adjusted, the user identity information may be authenticated to ensure security.
  • step 509 to step 508 the terminal performs state adjustment of the corresponding authority according to the rights control policy.
  • step 510 the rights of the terminal are normally used.
  • steps 505 and 506 in the actual application may also be reversed, that is, whether the right is consistent with the current location range of the terminal, and then whether the right is consistent with the current time range of the terminal.
  • the embodiment of the present invention determines whether the first authority needs to be adjusted according to the first information of the first authority, and based on the obtained first information of the smart terminal, and determines When the adjustment needs to be adjusted, the first permission is turned on or off adaptively.
  • the intelligent terminal of the embodiment of the present invention can automatically adjust the opening or closing of the first authority according to the change of the environment, thereby ensuring the security of the intelligent terminal while ensuring the functional diversity and ease of use, or It provides better security while providing a very versatile and easy-to-use application and related functions, thereby enhancing the user experience.
  • the embodiment of the invention further provides a computer storage medium, wherein the computer storage medium stores computer executable instructions, and the computer executable instructions are used to execute the foregoing method for controlling terminal rights.
  • embodiments of the present invention can be provided as a method, system, or computer program product. Accordingly, the present invention can take the form of a hardware embodiment, a software embodiment, or a combination of software and hardware. Moreover, the invention can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage and optical storage, etc.) including computer usable program code.
  • the computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture comprising the instruction device.
  • the apparatus implements the functions specified in one or more blocks of a flow or a flow and/or block diagram of the flowchart.
  • These computer program instructions can also be loaded onto a computer or other programmable data processing device such that a series of operational steps are performed on a computer or other programmable device to produce computer-implemented processing for execution on a computer or other programmable device.
  • the instructions provide steps for implementing the functions specified in one or more of the flow or in a block or blocks of a flow diagram.
  • the method, system and computer storage medium for controlling the terminal authority determine whether the first authority needs to be performed by setting the first attribute for the first authority and based on the obtained first information of the intelligent terminal. State adjustment, and adaptively turn the first permission on or off when it is judged that adjustment is needed. Therefore, it is possible to automatically adjust the opening or closing of the first authority according to the change of the environment, and to ensure the security of the functional diversity and ease of use of the intelligent terminal, or to have a good diversity. Easy-to-use applications and related functions provide better security and enhance the user experience.

Abstract

一种对终端权限的控制方法,终端中存储有针对第一权限的第一属性,第一权限至少包括终端的系统权限和/或应用权限,第一属性用于描述第一权限的开启和关闭条件,该方法包括:获得终端的第一信息,第一信息为用于描述终端所处环境的信息(101);基于获得的第一信息、以及终端存储的针对第一权限的第一属性,获得权限控制策略(102);根据权限控制策略确定需要对第一权限进行状态调整时,执行针对第一权限的开启或关闭操作(103)。还涉及一种对终端权限的控制系统及计算机存储介质。

Description

对终端权限的控制方法、系统及存储介质 技术领域
本发明属于智能终端领域,尤其涉及一种对终端权限的控制方法、系统及计算机存储介质。
背景技术
随着移动互联网的飞速发展,智能终端已经普及,基于智能终端的各种应用也越来越多,这些应用包括:办公软件、理财软件、社交软件、游戏软件等等。各式各样的应用在极大地改变着人们的工作、生活及沟通方式的同时,也在深深的困扰着用户,如工作生活无法分开,安全事故频发等等。例如:用户所使用的智能终端的系统权限和/或应用权限并不一定适用于所有环境或场合,通常当用户身处不同的环境时,对其智能终端的系统权限和/或应用权限有着不同的操作使用权限限制,而现有智能终端无法根据环境的变化来自动的适应性调整这些权限。
因此,如何在保证智能终端的功能多样性、易用性的同时尽量提高安全性,或者在具有很好的多样性、易用性的应用及相关功能的同时能够提供更好的安全性,是目前亟待解决的技术问题。
发明内容
为解决现有存在的技术问题,本发明实施例提供一种对终端权限的控制方法、系统和计算机存储介质。
本发明实施例提供了一种对终端权限的控制方法,所述终端中存储有针对第一权限的第一属性,所述第一权限至少包括所述终端的系统权限和/或应用权限,所述第一属性用于描述所述第一权限的开启和关闭条件,该 方法包括:
获得所述终端的第一信息,所述第一信息为用于描述所述终端所处环境的信息;
基于获得的所述第一信息、以及所述终端存储的所述针对第一权限的第一属性,获得权限控制策略;
根据所述权限控制策略确定需要对所述第一权限进行状态调整时,执行针对第一权限的开启或关闭操作。
在一可行方式中,所述基于获得的第一信息、以及终端存储的针对第一权限的第一属性,获得权限控制策略,包括:
将获得的所述第一信息与所述针对第一权限的第一属性进行比较,判断所述第一信息是否满足所述第一属性所描述的所述第一权限的开启和关闭条件,并依据所述终端的第一权限的当前状态,判断是否需要对所述第一权限进行状态调整;
基于判断结果生成所述权限控制策略,所述权限控制策略描述了是否对所述第一权限进行状态调整。
在一可行方式中,所述第一信息为所述终端的时间信息和/或位置信息,所述第一权限的开启和关闭条件为所述第一权限开启和关闭的允许时间范围和/或允许位置范围;
所述将获得的第一信息与针对第一权限的第一属性进行比较,判断第一信息是否满足第一属性所描述的第一权限的开启和关闭条件,包括:
将获得的所述终端的时间信息和/或位置信息与所述第一权限的开启和关闭条件进行比较,判断所述终端的时间信息和/或位置信息是否属于所述第一权限开启和关闭的允许时间范围和/或允许位置范围。
在一可行方式中,在执行针对第一权限的开启或关闭操作后,所述方法还包括:
当所述终端被触发产生针对所述第一权限的状态调整指令时,判断所述第一权限是否配置有安全认证策略,如果配置有安全认证策略,则在基于所述安全认证策略执行安全认证通过后,按所述状态调整指令执行对所述第一权限的状态调整;如果没有配置安全认证策略,则按所述状态调整指令执行对所述第一权限的状态调整。
在一可行方式中,在所述获得终端的第一信息之前,所述方法还包括:
当所述终端被触发产生第一属性设置指令时,获得设置的针对所述第一权限的第一属性;
其中,设置针对所述第一权限的第一属性的方式为以下至少一种:
从所述终端的系统权限和/或应用权限中选择所述第一权限,并为所述第一权限设置对应的开启和关闭条件;或者,
设置权限的开启和关闭条件后,从所述终端的系统权限和/或应用权限中选择执行所述开启和关闭条件的至少一个所述第一权限。
本发明实施例还提供了一种终端权限的控制系统,所述系统包括:初始化单元、第一信息获得单元、策略控制单元和权限控制单元;
所述初始化单元,配置为存储针对第一权限的第一属性,所述第一权限至少包括所述终端的系统权限和/或应用权限,所述第一属性用于描述所述第一权限的开启和关闭条件;
所述第一信息获得单元,配置为获得所述终端的第一信息,所述第一信息为用于描述所述终端所处环境的信息;
所述策略控制单元,配置为基于获得的所述第一信息、以及所述终端存储的所述针对第一权限的第一属性,获得权限控制策略,并在所述权限控制策略表征需要对所述第一权限进行状态调整时通知权限控制单元;
所述权限控制单元,配置为根据所述策略控制单元的通知执行针对第一权限的开启或关闭操作。
在一可行方式中,所述策略控制单元基于获得的第一信息、以及终端存储的针对第一权限的第一属性,获得权限控制策略,包括:
将获得的所述第一信息与所述针对第一权限的第一属性进行比较,判断所述第一信息是否满足所述第一属性所描述的所述第一权限的开启和关闭条件,并依据所述终端的第一权限的当前状态,判断是否需要对所述第一权限进行状态调整;
基于判断结果生成所述权限控制策略,所述权限控制策略描述了是否对所述第一权限进行状态调整。
在一可行方式中,所述第一信息为所述终端的时间信息和/或位置信息,所述第一权限的开启和关闭条件为所述第一权限开启和关闭的允许时间范围和/或允许位置范围;
所述策略控制单元将获得的第一信息与针对第一权限的第一属性进行比较,判断第一信息是否满足第一属性所描述的第一权限的开启和关闭条件,包括:
将获得的所述终端的时间信息和/或位置信息与所述第一权限的开启和关闭条件进行比较,判断所述终端的时间信息和/或位置信息是否属于所述第一权限开启和关闭的允许时间范围和/或允许位置范围。
在一可行方式中,所述权限控制单元,还配置为,在被触发产生针对所述第一权限的状态调整指令时,判断所述第一权限是否配置有安全认证策略,如果配置有安全认证策略,则在基于所述安全认证策略执行安全认证通过后,按所述状态调整指令执行对所述第一权限的状态调整;如果没有配置安全认证策略,则按所述状态调整指令执行对所述第一权限的状态调整。
在一可行方式中,所述系统还包括设置单元,配置为在被触发产生第一属性设置指令时,设置针对所述第一权限的第一属性;
其中,设置针对所述第一权限的第一属性的方式为以下至少一种:
从所述终端的系统权限和/或应用权限中选择所述第一权限,并为所述第一权限设置对应的开启和关闭条件;或者,
设置权限的开启和关闭条件后,从所述终端的系统权限和/或应用权限中选择执行所述开启和关闭条件的至少一个所述第一权限。
本发明实施例还提供一种计算机存储介质,所述计算机存储介质中存储有计算机可执行指令,所述计算机可执行指令用于执行前述的对终端权限的控制方法。
本发明实施例提供的一种对终端权限的控制方法、系统和计算机存储介质,通过为第一权限设置第一属性,并基于获得的智能终端的第一信息,判断是否需要对第一权限进行状态调整,并在判断需要调整时,自适应的将第一权限开启或关闭。从而,能够根据所处环境的变化来自动的适应性调整第一权限的开启或关闭,在保证智能终端的功能多样性、易用性的同时尽量提高安全性,或者在具有很好的多样性、易用性的应用及相关功能的同时能够提供更好的安全性,进而达到提升用户体验的目的。
附图说明
图1为本发明实施例一的对终端权限的控制方法流程示意图;
图2为本发明实施例二的对终端权限的控制系统的结构示意图;
图3为本发明实施例三的对终端权限的控制方法流程示意图;
图4为本发明实施例四的对终端权限的控制方法流程示意图;
图5为本发明实施例五的对终端权限的控制方法流程示意图。
具体实施方式
下面结合附图和具体实施例对本发明的技术方案进一步详细阐述。
实施例一
本发明实施例一提供的一种对终端权限的控制方法,如图1所示,其中,所述终端中存储有针对第一权限的第一属性,所述第一权限至少包括所述终端的系统权限和/或应用权限,所述第一属性用于描述所述第一权限的开启和关闭条件;所述方法主要包括:
步骤101,获得所述终端的第一信息,所述第一信息为用于描述所述终端所处环境的信息。
本发明实施例中,所述系统权限是指智能终端的操作系统(如安卓系统、苹果的IOS操作系统、windows操作系统等)各项功能的操作使用权限,如智能终端的无线局域网(wifi)权限、移动数据链路权限、安全数字(SD,Secure Digital)卡的文件删除权限等等;所述应用权限是指智能终端中安装的应用程序的操作使用权限,如:应用程序的操作使用权限、应用程序的某项功能的操作使用权限等等。
本发明实施例中,智能终端预先存储针对第一权限的第一属性,所述第一属性包括:针对智能终端的系统权限的开启和关闭条件、和/或针对智能终端的应用权限的开启和关闭条件等等。其中,针对智能终端的系统权限的开启和关闭条件,如:针对智能终端的wifi使用操作权限的开启和关闭条件、针对智能终端的SD卡的文件删除权限的开启和关闭条件、针对智能终端的拍照功能的开启和关闭条件、针对智能终端的录音功能的开启和关闭条件等等;针对智能终端的应用权限的开启和关闭条件,如:针对智能终端的游戏类应用的开启和关闭条件、针对智能终端的社交类应用中的视频通话功能的开启和关闭条件等等。
也就是说,本发明实施例的针对第一权限的第一属性是预先设置并保存在智能终端的,所述设置和保存的操作是在步骤101之前,具体可以包括:
当所述终端被触发产生第一属性设置指令时,获得设置的针对所述第一权限的第一属性;
其中,设置针对所述第一权限的第一属性的方式为以下至少一种:
从所述终端的系统权限和/或应用权限中选择所述第一权限,并为所述第一权限设置对应的开启和关闭条件;或者,
设置权限的开启和关闭条件后,从所述终端的系统权限和/或应用权限中选择执行所述开启和关闭条件的至少一个所述第一权限。
所述第一属性设置指令可以是智能终端的物理按键被触发或虚拟功能按键被触发时,由所述智能终端产生的;在触发产生第一属性设置指令后,智能终端提供第一属性的设置界面,供用户进行第一权限的选择及其第一属性的设置。本发明实施例不对第一属性的具体设置方式或过程进行限制,以上所举仅为本发明实施例的两种可实施方式,上述两种可实施方式也可结合使用。
其中,对于从终端的系统权限和/或应用权限中选择第一权限,并为第一权限设置对应的开启和关闭条件这种方式。例如:选择所述智能终端的移动数据链路权限,并为所述移动数据链路权限设置对应的开启和关闭条件;再例如:选择所述智能终端的SD卡的文件删除权限,并为所述SD卡的文件删除权限设置对应的开启和关闭条件;还例如:选择所述智能终端的游戏类应用的使用操作权限,并为所述游戏类应用的使用操作权限设置对应的开启和关闭条件;又例如:选择所述智能终端的某社交类应用中的视频通话功能,并为所述社交类应用中的视频通话功能设置对应的开启和关闭条件。
对于设置权限的开启和关闭条件后,从终端的系统权限和/或应用权限中选择执行开启和关闭条件的至少一个第一权限这种方式。例如:首先设置权限的开启和关闭条件,然后再选择适用上述条件的权限,所述权限包 括SD卡的文件删除权限、某游戏类应用的使用操作权限、某社交类应用中的视频通话功能等等。也就是说,选择的上述SD卡的文件删除权限、某游戏类应用的使用操作权限、某社交类应用中的视频通话功能,都适用于上述同一个开启和关闭条件。
在设置并存储针对第一权限的第一属性后,智能终端可以周期性的或非周期性的获得用于描述其所处环境的第一信息,所述第一信息可以是智能终端所处的位置信息,也可以是智能终端所处的时间信息,还可以是智能终端所处环境的噪声系数,甚至也可以是智能终端所处环境的光强度等等。本发明实施例不对第一信息的类型和内容进行限制,可以根据实际需要进行扩展;同样,本发明实施例也不对第一信息的获得方式进行限制,凡是适用于本发明实施例的第一信息获得方式应当都属于本发明实施例所要保护的范围。
步骤102,基于获得的所述第一信息、以及所述终端存储的所述针对第一权限的第一属性,获得权限控制策略。
在一实施方式中,步骤102包括:
将获得的所述第一信息与所述针对第一权限的第一属性进行比较,判断所述第一信息是否满足所述第一属性所描述的所述第一权限的开启和关闭条件,并依据所述终端的第一权限的当前状态,判断是否需要对所述第一权限进行状态调整;
基于判断结果生成所述权限控制策略,所述权限控制策略描述了是否对所述第一权限进行状态调整。
也就是说,判断第一信息满足第一权限的开启条件、且智能终端的第一权限当前为开启状态时,无需状态调整;判断第一信息满足第一权限的开启条件、且智能终端的第一权限当前为关闭状态时,需要状态调整;判断第一信息满足第一权限的关闭条件、且智能终端的第一权限当前为开启 状态时,需要状态调整;判断第一信息满足第一权限的关闭条件、且智能终端的第一权限当前为关闭状态时,无需状态调整。
另外,在一实施方式中,所述第一信息可以为所述终端的时间信息和/或位置信息,所述第一权限的开启和关闭条件为所述第一权限开启和关闭的允许时间范围和/或允许位置范围;
所述将获得的第一信息与针对第一权限的第一属性进行比较,判断第一信息是否满足第一属性所描述的第一权限的开启和关闭条件,包括:
将获得的所述终端的时间信息和/或位置信息与所述第一权限的开启和关闭条件进行比较,判断所述终端的时间信息和/或位置信息是否属于所述第一权限开启和关闭的允许时间范围和/或允许位置范围。
也就是说,判断终端的时间信息和/或位置信息属于第一权限开启的允许时间范围和/或允许位置范围、且智能终端的第一权限当前为开启状态时,无需状态调整;判断终端的时间信息和/或位置信息属于第一权限开启的允许时间范围和/或允许位置范围、且智能终端的第一权限当前为关闭状态时,需要状态调整;判断终端的时间信息和/或位置信息属于第一权限关闭的允许时间范围和/或允许位置范围、且智能终端的第一权限当前为开启状态时,需要状态调整;判断终端的时间信息和/或位置信息属于第一权限关闭的允许时间范围和/或允许位置范围、且智能终端的第一权限当前为关闭状态时,无需状态调整。
步骤103,根据所述权限控制策略确定需要对所述第一权限进行状态调整时,执行针对第一权限的开启或关闭操作。
根据权限控制策略,在确定需要对第一权限进行关闭时,执行针对第一权限的关闭操作;在确定需要对第一权限进行开启时,执行针对第一权限的开启操作。其中,针对系统权限和/或应用权限的开启和关闭操作控制,本发明实施例不做限制,实际应用中的任何适用于本发明实施例的控制方 式应当都属于本发明实施例所要保护的范围。
在一实施方式中,在执行针对第一权限的开启或关闭操作后,所述方法还包括:
当所述终端被触发产生针对所述第一权限的状态调整指令时,判断所述第一权限是否配置有安全认证策略,如果配置有安全认证策略,则在基于所述安全认证策略执行安全认证通过后,按所述状态调整指令执行对所述第一权限的状态调整;如果没有配置安全认证策略,则按所述状态调整指令执行对所述第一权限的状态调整。
也就是说,本发明实施例也支持对第一权限状态的手动调整,当用户触发对某第一权限进行手动的状态调整时,智能终端产生针对所述第一权限的状态调整指令;如果智能终端预先配置有针对所述第一权限手动状态调整的安全认证策略,则需要在认证通过后,才能按调整指令执行对所述第一权限的状态调整;如果智能终端预先没有配置针对所述第一权限手动状态调整的安全认证策略,则无需认证即可按调整指令执行对所述第一权限的状态调整。其中,智能终端可以提供安全认证的操作界面,以供用户进行认证信息的输入,待采集完用户输入的认证信息后,基于用户输入的认证信息进行安全认证。
实施例二
对应本发明实施例的终端权限的控制方法,本发明实施例二还提供了一种终端权限的控制系统,如图5所示,所述系统包括:初始化单元10、第一信息获得单元20、策略控制单元30和权限控制单元40;其中,
所述初始化单元10,配置为存储针对第一权限的第一属性,所述第一权限至少包括所述终端的系统权限和/或应用权限,所述第一属性用于描述所述第一权限的开启和关闭条件;
所述第一信息获得单元20,配置为获得所述终端的第一信息,所述第 一信息为用于描述所述终端所处环境的信息;
所述策略控制单元30,配置为基于获得的所述第一信息、以及所述终端存储的所述针对第一权限的第一属性,获得权限控制策略,并在所述权限控制策略表征需要对所述第一权限进行状态调整时通知权限控制单元40;
所述权限控制单元40,配置为根据所述策略控制单元30的通知执行针对第一权限的开启或关闭操作。
在一实施方式中,所述系统还包括设置单元50,配置为在被触发产生第一属性设置指令时,设置针对所述第一权限的第一属性;
其中,设置针对所述第一权限的第一属性的方式为以下至少一种:
从所述终端的系统权限和/或应用权限中选择所述第一权限,并为所述第一权限设置对应的开启和关闭条件;或者,
设置权限的开启和关闭条件后,从所述终端的系统权限和/或应用权限中选择执行所述开启和关闭条件的至少一个所述第一权限。
所述第一属性设置指令可以是智能终端的物理按键被触发或虚拟功能按键被触发时,由所述智能终端的设置单元50产生的;在触发产生第一属性设置指令后,智能终端的设置单元50提供第一属性的设置界面,供用户进行第一权限的选择及其第一属性的设置。本发明实施例不对第一属性的具体设置方式或过程进行限制,以上所举仅为本发明实施例的两种可实施方式,上述两种可实施方式也可结合使用。
在一实施方式中,所述策略控制单元30基于获得的第一信息、以及终端存储的针对第一权限的第一属性,获得权限控制策略,包括:
将获得的所述第一信息与所述针对第一权限的第一属性进行比较,判断所述第一信息是否满足所述第一属性所描述的所述第一权限的开启和关闭条件,并依据所述终端的第一权限的当前状态,判断是否需要对所述第 一权限进行状态调整;
基于判断结果生成所述权限控制策略,所述权限控制策略描述了是否对所述第一权限进行状态调整。
也就是说,判断第一信息满足第一权限的开启条件、且智能终端的第一权限当前为开启状态时,无需状态调整;判断第一信息满足第一权限的开启条件、且智能终端的第一权限当前为关闭状态时,需要状态调整;判断第一信息满足第一权限的关闭条件、且智能终端的第一权限当前为开启状态时,需要状态调整;判断第一信息满足第一权限的关闭条件、且智能终端的第一权限当前为关闭状态时,无需状态调整。
在一实施方式中,所述第一信息为所述终端的时间信息和/或位置信息,所述第一权限的开启和关闭条件为所述第一权限开启和关闭的允许时间范围和/或允许位置范围;
所述策略控制单元30将获得的第一信息与针对第一权限的第一属性进行比较,判断第一信息是否满足第一属性所描述的第一权限的开启和关闭条件,包括:
将获得的所述终端的时间信息和/或位置信息与所述第一权限的开启和关闭条件进行比较,判断所述终端的时间信息和/或位置信息是否属于所述第一权限开启和关闭的允许时间范围和/或允许位置范围。
也就是说,判断终端的时间信息和/或位置信息属于第一权限开启的允许时间范围和/或允许位置范围、且智能终端的第一权限当前为开启状态时,无需状态调整;判断终端的时间信息和/或位置信息属于第一权限开启的允许时间范围和/或允许位置范围、且智能终端的第一权限当前为关闭状态时,需要状态调整;判断终端的时间信息和/或位置信息属于第一权限关闭的允许时间范围和/或允许位置范围、且智能终端的第一权限当前为开启状态时,需要状态调整;判断终端的时间信息和/或位置信息属于第一权限关闭的允 许时间范围和/或允许位置范围、且智能终端的第一权限当前为关闭状态时,无需状态调整。
在一实施方式中,所述权限控制单元40进一步配置为,在被触发产生针对所述第一权限的状态调整指令时,判断所述第一权限是否配置有安全认证策略,如果配置有安全认证策略,则在基于所述安全认证策略执行安全认证通过后,按所述状态调整指令执行对所述第一权限的状态调整;如果没有配置安全认证策略,则按所述状态调整指令执行对所述第一权限的状态调整。
也就是说,本发明实施例也支持对第一权限状态的手动调整,当用户触发对某第一权限进行手动的状态调整时,智能终端的权限控制单元40产生针对所述第一权限的状态调整指令;如果智能终端的设置单元50预先设置有针对所述第一权限手动状态调整的安全认证策略,则权限控制单元40需要在认证通过后,才能按调整指令执行对所述第一权限的状态调整;如果智能终端的设置单元50预先没有设置针对所述第一权限手动状态调整的安全认证策略,则权限控制单元40无需认证即可按调整指令执行对所述第一权限的状态调整。其中,智能终端可以提供安全认证的操作界面,以供用户进行认证信息的输入,待采集完用户输入的认证信息后,基于用户输入的认证信息进行安全认证。
上述本发明实施例,通过为第一权限设置第一属性,并基于获得的智能终端的第一信息,判断是否需要对第一权限进行状态调整,并在判断需要调整时,自适应的将第一权限开启或关闭。本发明实施例的智能终端能够根据所处环境的变化来自动的适应性调整第一权限的开启或关闭,从而,在保证智能终端的功能多样性、易用性的同时尽量提高安全性,或者在具有很好的多样性、易用性的应用及相关功能的同时能够提供更好的安全性。
需要说明的是,本发明实施例的第一信息用于描述智能终端所处的环 境信息,可以是智能终端所处的位置信息,也可以是智能终端所处的时间信息,还可以是智能终端所处环境的噪声系数,甚至也可以是智能终端所处环境的光强度等等。本发明实施例不对第一信息的类型和内容进行限制,可以根据实际需要进行扩展;同样,本发明实施例也不对第一信息的获得方式进行限制,凡是适用于本发明实施例的第一信息获得方式应当都属于本发明实施例所要保护的范围。
在实际应用中,所述初始化单元10、第一信息获得单元20、策略控制单元30和权限控制单元40均可由中央处理单元(CPU,Central Processing Unit)、或数字信号处理(DSP,Digital Signal Processor)、或微处理器(MPU,Micro Processor Unit)、或现场可编程门阵列(FPGA,Field Programmable Gate Array)等来实现。
下面以第一信息为终端所处的位置信息和/或时间信息为例,对本发明实施例的对终端权限的控制方法进一步详细阐述。
实施例三
考虑到在实际应用中,终端使用者在不同的地理位置,如在工作场所、家庭场所或陌生位置,对终端中的系统权限和/或应用权限的开启和/或关闭需求是不同的;并且,终端使用者对终端系统权限和/或应用权限的开启和/或关闭习惯均有一定的规律可循,即终端使用者通常在同一位置区域的权限开启和/或关闭习惯相同;那么根据该规律来自适应地调整应用及系统的操作使用权限,可以节省用户的很多手动操作,节省用户时间,提升操作体验。
本发明实施例三的基于地理位置变化的终端权限的控制方法,如图3所示,该方法主要包括:
步骤301,初始化参数配置。
配置终端使用者经常活动的位置范围、自动权限控制开关、自动权限 控制所涉及的应用等相关参数,完成针对第一权限的第一属性设置。
在设置并保存针对第一权限的第一属性(第一权限的开启和关闭条件)后,对上述参数配置进行初始化。也就是说,经过所述初始化后,终端能够获知在位于什么位置范围内时哪些权限应当属于开启或关闭状态。
步骤302,终端监测位置变化。
本发明实施例中,可以采用结合地图、位置定位等终端的基础功能来标定自动加密的位置基准参考点,在参考点基础上通过有效半径来确定位置范围,位置范围可以是有效半径内的区域,也可以是半径外的区域,也可以是多个区域的并集或者交集。当然,也可采用其他监测终端位置范围的方法,本发明实施例不做一一说明。
步骤303,终端判断是否手动限制权限,如是,转到步骤308,如否,转到步骤304。
即终端判断是否被触发产生权限的状态调整指令(手动调整),如是,转到步骤308,如否,转到步骤304。
步骤304~305,监控终端当前使用的权限,判断权限是否符合终端当前所处的位置范围,如是,转到步骤309,如否,转到步骤306。
即监控终端当前使用的权限的开启或关闭状态,是否与终端当前所处的位置范围所对应的权限状态的要求相符,如果相符,转到步骤309,如果不相符,转到步骤306。例如:要求终端在用户办公区域关闭拍照和录音功能,其他时间开启拍照和录音功能,则通过监测终端位置变化、以及拍照和录音功能的权限,判断终端当前所处的位置范围是否与终端当前的拍照和录音功能的状态相符。
步骤306,计算权限控制策略,即将终端当前所处的位置范围与上述初始化的参数进行比较,以确定当前需要做出状态调整的权限,并以此生成相应的权限控制策略。
步骤307,判断是否需要自动权限限制,如是,转到步骤308,如否,转到步骤309。
即终端判断当前是否需要基于所述权限控制策略执行自动权限限制。
步骤308,根据需要限制权限。
对于步骤303转到的步骤308,终端根据用户的手动操作执行对相应权限的状态调整;
对于步骤307转到的步骤308,终端根据权限控制策略执行对相应权限的状态调整。
步骤309,正常使用终端的各项权限。
实施例四
考虑到在实际应用中,终端使用者在不同的时间范围,如白天、夜晚,对终端中的系统权限和/或应用权限的开启和/或关闭需求是不同的;并且,终端使用者对终端系统权限和/或应用权限的开启和/或关闭习惯均有一定的规律可循,即终端使用者通常在同一时间范围的权限开启和/或关闭习惯相同;那么根据该规律来自适应地调整应用及系统的操作使用权限,可以节省用户的很多手动操作,节省用户时间,提升操作体验。
本发明实施例四的基于时间变化的终端权限的控制方法,如图4所示,该方法主要包括:
步骤401,初始化参数配置。
配置终端使用者的时间范围、自动权限控制开关、自动权限控制所涉及的应用等相关参数,完成针对第一权限的第一属性设置。
在设置并保存针对第一权限的第一属性(第一权限的开启和关闭条件)后,对上述参数配置进行初始化。也就是说,经过所述初始化后,终端能够获知在位于什么时间范围内时哪些权限应当属于开启或关闭状态。
步骤402,终端监测时间变化。
步骤403,终端判断是否手动限制权限,如是,转到步骤408,如否,转到步骤404。
即终端判断是否被触发产生权限的状态调整指令(手动调整),如是,转到步骤408,如否,转到步骤404。
步骤404~405,监控终端当前使用的权限,判断权限是否符合终端当前所处的时间范围,如是,转到步骤409,如否,转到步骤406。
即监控终端当前使用的权限的开启或关闭状态,是否与终端当前所处的时间范围所对应的权限状态的要求相符,如果相符,转到步骤409,如果不相符,转到步骤406。例如:要求终端在用户上班时间关闭拍照和录音功能,其他时间开启拍照和录音功能,则通过监测终端时间变化、以及拍照和录音功能的权限,判断终端当前所处的时间范围是否与终端当前的拍照和录音功能的状态相符。
步骤406,计算权限控制策略,即将终端当前所处的时间范围与上述初始化的参数进行比较,以确定当前需要做出状态调整的权限,并以此生成相应的权限控制策略。
步骤407,判断是否需要自动权限限制,如是,转到步骤408,如否,转到步骤409。
即终端判断当前是否需要基于所述权限控制策略执行自动权限限制。
步骤408,根据需要限制权限。
对于步骤403转到的步骤408,终端根据用户的手动操作执行对相应权限的状态调整;
对于步骤407转到的步骤408,终端根据权限控制策略执行对相应权限的状态调整。
步骤409,正常使用终端的各项权限。
实施例五
考虑到在实际应用中,终端使用者在不同的时间和位置范围,对终端中的系统权限和/或应用权限的开启和/或关闭需求是不同的;并且,终端使用者对终端系统权限和/或应用权限的开启和/或关闭习惯均有一定的规律可循,即终端使用者通常在同一时间范围和位置范围(即终端使用者通常会在固定的时间范围活动在特定的位置范围,有一定的规律可循,如工作时间在单位,下班以后在家中)的权限开启和/或关闭习惯相同;那么根据该规律来自适应地调整应用及系统的操作使用权限,可以节省用户的很多手动操作,节省用户时间,提升操作体验。
本发明实施例五的基于地理位置和时间变化的终端权限的控制方法,如图5所示,该方法主要包括:
步骤501,初始化参数配置。
配置终端使用者的时间范围、活动位置范围、自动权限控制开关、自动权限控制所涉及的应用等相关参数,完成针对第一权限的第一属性设置。
在设置并保存针对第一权限的第一属性(第一权限的开启和关闭条件)后,对上述参数配置进行初始化。也就是说,经过所述初始化后,终端能够获知在位于什么时间范围、位置范围内时哪些权限应当属于开启或关闭状态。
步骤502,终端监测位置和时间变化。
步骤503,终端判断是否手动限制权限,如是,转到步骤509,如否,转到步504。
即终端判断是否被触发产生权限的状态调整指令(手动调整),如是,转到步骤509,如否,转到步骤504。
步骤504~505,监控终端当前使用的权限,判断权限是否符合终端当前所处的时间范围,如是,转到步骤506,如否,转到步骤507。
即监控终端当前使用的权限的开启或关闭状态,是否与终端当前所处 的时间范围所对应的权限状态的要求相符,如果相符,转到步骤506,如果不相符,转到步骤507。
步骤506,判断权限是否符合终端当前所处的位置范围,如是,转到步骤510,如否,转到步骤507。
即监控终端当前使用的权限的开启或关闭状态,是否与终端当前所处的位置范围所对应的权限状态的要求相符,如果相符,转到步骤510,如果不相符,转到步骤507。
步骤507,计算权限控制策略,即将终端当前所处的时间范围、位置范围与上述初始化的参数进行比较,以确定当前需要做出状态调整的权限,并以此生成相应的权限控制策略。
步骤508,判断是否需要自动权限限制,如是,转到步骤509,如否,转到步骤510。
即终端判断当前是否需要基于所述权限控制策略执行自动权限限制。
步骤509,根据需要限制权限。
对于步骤503转到的步骤509,终端根据用户的手动操作执行对相应权限的状态调整;对于用户特别敏感的权限,如果手动调整状态,可以进行用户身份信息认证,以确保安全性。
对于步骤508转到的步骤509,终端根据权限控制策略执行对相应权限的状态调整。
步骤510,正常使用终端的各项权限。
需要说明的是,实际应用中步骤505和506的执行顺序也可以颠倒,即先判断权限是否符合终端当前所处的位置范围,再判断权限是否符合终端当前所处的时间范围。
综上所述,本发明实施例通过为第一权限设置第一属性,并基于获得的智能终端的第一信息,判断是否需要对第一权限进行状态调整,并在判 断需要调整时,自适应的将第一权限开启或关闭。本发明实施例的智能终端能够根据所处环境的变化来自动的适应性调整第一权限的开启或关闭,从而,在保证智能终端的功能多样性、易用性的同时尽量提高安全性,或者在具有很好的多样性、易用性的应用及相关功能的同时能够提供更好的安全性,进而达到提升用户体验的目的。
本发明实施例还提供一种计算机存储介质,所述计算机存储介质中存储有计算机可执行指令,所述计算机可执行指令用于执行前述的对终端权限的控制方法。
本领域内的技术人员应明白,本发明的实施例可提供为方法、系统、或计算机程序产品。因此,本发明可采用硬件实施例、软件实施例、或结合软件和硬件方面的实施例的形式。而且,本发明可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器和光学存储器等)上实施的计算机程序产品的形式。
本发明是参照根据本发明实施例的方法、设备(系统)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。
这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。
这些计算机程序指令也可装载到计算机或其他可编程数据处理设备上,使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。
以上所述,仅为本发明的较佳实施例而已,并非用于限定本发明的保护范围。
工业实用性
本发明实施例提供的一种对终端权限的控制方法、系统和计算机存储介质,通过为第一权限设置第一属性,并基于获得的智能终端的第一信息,判断是否需要对第一权限进行状态调整,并在判断需要调整时,自适应的将第一权限开启或关闭。从而,能够根据所处环境的变化来自动的适应性调整第一权限的开启或关闭,在保证智能终端的功能多样性、易用性的同时尽量提高安全性,或者在具有很好的多样性、易用性的应用及相关功能的同时能够提供更好的安全性,进而达到提升用户体验的目的。

Claims (11)

  1. 一种对终端权限的控制方法,所述终端中存储有针对第一权限的第一属性,所述第一权限至少包括所述终端的系统权限和/或应用权限,所述第一属性用于描述所述第一权限的开启和关闭条件,该方法包括:
    获得所述终端的第一信息,所述第一信息为用于描述所述终端所处环境的信息;
    基于获得的所述第一信息、以及所述终端存储的所述针对第一权限的第一属性,获得权限控制策略;
    根据所述权限控制策略确定需要对所述第一权限进行状态调整时,执行针对第一权限的开启或关闭操作。
  2. 根据权利要求1所述终端权限的控制方法,其中,所述基于获得的第一信息、以及终端存储的针对第一权限的第一属性,获得权限控制策略,包括:
    将获得的所述第一信息与所述针对第一权限的第一属性进行比较,判断所述第一信息是否满足所述第一属性所描述的所述第一权限的开启和关闭条件,并依据所述终端的第一权限的当前状态,判断是否需要对所述第一权限进行状态调整;
    基于判断结果生成所述权限控制策略,所述权限控制策略描述了是否对所述第一权限进行状态调整。
  3. 根据权利要求2所述终端权限的控制方法,其中,所述第一信息为所述终端的时间信息和/或位置信息,所述第一权限的开启和关闭条件为所述第一权限开启和关闭的允许时间范围和/或允许位置范围;
    所述将获得的第一信息与针对第一权限的第一属性进行比较,判断第一信息是否满足第一属性所描述的第一权限的开启和关闭条件,包括:
    将获得的所述终端的时间信息和/或位置信息与所述第一权限的开启和关闭条件进行比较,判断所述终端的时间信息和/或位置信息是否属于所述第一权限开启和关闭的允许时间范围和/或允许位置范围。
  4. 根据权利要求1、2或3所述终端权限的控制方法,其中,在执行针对第一权限的开启或关闭操作后,所述方法还包括:
    当所述终端被触发产生针对所述第一权限的状态调整指令时,判断所述第一权限是否配置有安全认证策略,如果配置有安全认证策略,则在基于所述安全认证策略执行安全认证通过后,按所述状态调整指令执行对所述第一权限的状态调整;如果没有配置安全认证策略,则按所述状态调整指令执行对所述第一权限的状态调整。
  5. 根据权利要求1、2或3所述终端权限的控制方法,其中,在所述获得终端的第一信息之前,所述方法还包括:
    当所述终端被触发产生第一属性设置指令时,获得设置的针对所述第一权限的第一属性;
    其中,设置针对所述第一权限的第一属性的方式为以下至少一种:
    从所述终端的系统权限和/或应用权限中选择所述第一权限,并为所述第一权限设置对应的开启和关闭条件;或者,
    设置权限的开启和关闭条件后,从所述终端的系统权限和/或应用权限中选择执行所述开启和关闭条件的至少一个所述第一权限。
  6. 一种终端权限的控制系统,所述系统包括:初始化单元、第一信息获得单元、策略控制单元和权限控制单元;
    所述初始化单元,配置为存储针对第一权限的第一属性,所述第一权限至少包括所述终端的系统权限和/或应用权限,所述第一属性用于描述所述第一权限的开启和关闭条件;
    所述第一信息获得单元,配置为获得所述终端的第一信息,所述第一 信息为用于描述所述终端所处环境的信息;
    所述策略控制单元,配置为基于获得的所述第一信息、以及所述终端存储的所述针对第一权限的第一属性,获得权限控制策略,并在所述权限控制策略表征需要对所述第一权限进行状态调整时通知权限控制单元;
    所述权限控制单元,配置为根据所述策略控制单元的通知执行针对第一权限的开启或关闭操作。
  7. 根据权利要求6所述终端权限的控制系统,其中,所述策略控制单元基于获得的第一信息、以及终端存储的针对第一权限的第一属性,获得权限控制策略,包括:
    将获得的所述第一信息与所述针对第一权限的第一属性进行比较,判断所述第一信息是否满足所述第一属性所描述的所述第一权限的开启和关闭条件,并依据所述终端的第一权限的当前状态,判断是否需要对所述第一权限进行状态调整;
    基于判断结果生成所述权限控制策略,所述权限控制策略描述了是否对所述第一权限进行状态调整。
  8. 根据权利要求7所述终端权限的控制系统,其中,所述第一信息为所述终端的时间信息和/或位置信息,所述第一权限的开启和关闭条件为所述第一权限开启和关闭的允许时间范围和/或允许位置范围;
    所述策略控制单元将获得的第一信息与针对第一权限的第一属性进行比较,判断第一信息是否满足第一属性所描述的第一权限的开启和关闭条件,包括:
    将获得的所述终端的时间信息和/或位置信息与所述第一权限的开启和关闭条件进行比较,判断所述终端的时间信息和/或位置信息是否属于所述第一权限开启和关闭的允许时间范围和/或允许位置范围。
  9. 根据权利要求6、7或8所述终端权限的控制系统,其中,所述权 限控制单元还配置为,在被触发产生针对所述第一权限的状态调整指令时,判断所述第一权限是否配置有安全认证策略,如果配置有安全认证策略,则在基于所述安全认证策略执行安全认证通过后,按所述状态调整指令执行对所述第一权限的状态调整;如果没有配置安全认证策略,则按所述状态调整指令执行对所述第一权限的状态调整。
  10. 根据权利要求6、7或8所述终端权限的控制系统,其中,所述系统还包括设置单元,配置为在被触发产生第一属性设置指令时,设置针对所述第一权限的第一属性;
    其中,设置针对所述第一权限的第一属性的方式为以下至少一种:
    从所述终端的系统权限和/或应用权限中选择所述第一权限,并为所述第一权限设置对应的开启和关闭条件;或者,
    设置权限的开启和关闭条件后,从所述终端的系统权限和/或应用权限中选择执行所述开启和关闭条件的至少一个所述第一权限。
  11. 一种计算机存储介质,所述计算机存储介质中存储有计算机可执行指令,所述计算机可执行指令用于执行权利要求1至5任一项所述的对终端权限的控制方法。
PCT/CN2016/073752 2015-07-24 2016-02-14 对终端权限的控制方法、系统及存储介质 WO2017016211A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201510443986.4A CN106709292A (zh) 2015-07-24 2015-07-24 一种对终端权限的控制方法及系统
CN201510443986.4 2015-07-24

Publications (1)

Publication Number Publication Date
WO2017016211A1 true WO2017016211A1 (zh) 2017-02-02

Family

ID=57885646

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2016/073752 WO2017016211A1 (zh) 2015-07-24 2016-02-14 对终端权限的控制方法、系统及存储介质

Country Status (2)

Country Link
CN (1) CN106709292A (zh)
WO (1) WO2017016211A1 (zh)

Families Citing this family (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107465662A (zh) * 2017-07-04 2017-12-12 深信服科技股份有限公司 移动终端策略管理方法、移动终端及计算机可读存储介质
CN107862201A (zh) * 2017-10-26 2018-03-30 深信服科技股份有限公司 权限控制方法、电子终端以及计算机可读存储介质
CN108513007A (zh) * 2018-03-27 2018-09-07 维沃移动通信有限公司 一种控制飞行模式的方法及移动终端
CN109145580A (zh) * 2018-08-31 2019-01-04 北京奇虎科技有限公司 软件权限管理方法、装置、计算设备及计算机存储介质
CN109005507A (zh) * 2018-09-26 2018-12-14 中国联合网络通信集团有限公司 禁止操作的控制方法、系统和终端设备
CN111562535A (zh) * 2020-04-07 2020-08-21 国网上海市电力公司 一种用于提高电能表检定速度的协调方法及系统

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1633192A (zh) * 2003-12-25 2005-06-29 仁宝电脑工业股份有限公司 无线便携式电子装置的情境模式自动管理方法及系统
CN101986677A (zh) * 2010-10-22 2011-03-16 浙江大学 位置相关的手机游戏运行限制方法
CN102137514A (zh) * 2010-01-25 2011-07-27 宏碁股份有限公司 决定来电通知方式的方法及应用此方法的便携式通信装置
CN102427492A (zh) * 2011-11-08 2012-04-25 华为终端有限公司 自动设置服务功能的方法及移动装置

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1633192A (zh) * 2003-12-25 2005-06-29 仁宝电脑工业股份有限公司 无线便携式电子装置的情境模式自动管理方法及系统
CN102137514A (zh) * 2010-01-25 2011-07-27 宏碁股份有限公司 决定来电通知方式的方法及应用此方法的便携式通信装置
CN101986677A (zh) * 2010-10-22 2011-03-16 浙江大学 位置相关的手机游戏运行限制方法
CN102427492A (zh) * 2011-11-08 2012-04-25 华为终端有限公司 自动设置服务功能的方法及移动装置

Also Published As

Publication number Publication date
CN106709292A (zh) 2017-05-24

Similar Documents

Publication Publication Date Title
WO2017016211A1 (zh) 对终端权限的控制方法、系统及存储介质
US11283803B2 (en) Incremental compliance remediation
US9942753B2 (en) Method and system for monitoring and restricting use of mobile devices
US9825956B2 (en) Systems and methods for access permission revocation and reinstatement
US9825945B2 (en) Preserving data protection with policy
KR102265123B1 (ko) 콘텍스트-기반 데이터 보호용 시스템
US11349878B2 (en) Method for handling security settings in a mobile end device
US20140208397A1 (en) Geographical restrictions for application usage on a mobile device
WO2016045328A1 (zh) 终端应用控制方法及装置、存储介质
WO2015131559A1 (zh) 终端及其功能控制方法、装置和通信系统
WO2013184799A1 (en) Evaluating whether to block or allow installation of a software application
CN110958397A (zh) 一种控制智能摄像头的方法及装置
CN105262823A (zh) 一种终端的控制方法、装置和系统
CN107302626B (zh) 一种针对安卓智能手机麦克风的管控方法
WO2017166781A1 (zh) 一种应用程序锁定方法、装置及电子设备
EP3779747A1 (en) Methods and systems to identify a compromised device through active testing
WO2016201884A1 (zh) 智能手机wifi分级管理方法
WO2013190736A1 (ja) 携帯端末、プログラム、及び制御方法
WO2016184213A1 (zh) 一种提高无线网络接入安全性的方法、装置及移动终端
US20150326536A1 (en) System and method for execution of dedicated personas in mobile technology platforms
US11954203B2 (en) Methods and systems for identifying a compromised device through its unmanaged profile
US11645402B2 (en) Methods and systems for identifying compromised devices from file tree structure
WO2017036200A1 (zh) 一种多域用户文件系统加密方法及系统
Dhillon et al. Intelligent and Dynamic Permission Model for User Permissions
CN104636646A (zh) 一种基于安全情景的智能手机安全保护方法

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16829579

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 16829579

Country of ref document: EP

Kind code of ref document: A1