IP Library Granted Patent US 9,870,463
Granted Patent B2
US 9,870,463 · App. 15/439,470 · Granted Jan 16, 2018

Permission management method, apparatus, and terminal

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,870,463
App. No.
15/439,470
Granted
Jan 16, 2018
Kind
B2
Abstract

A permission management method, apparatus, and terminal. The permission management method includes obtaining an installation package of a first application program, where the installation package carries a first certificate and permission request information of the first application program, determining, according to the permission request information, a first permission that the first application program requires during running, where the first permission is a system administrator permission of a system, and granting the first permission to the first application program according to the first certificate of the first application program. In this way, the first permission that the first application program requires during running is granted to the first application program.

Claims (51)

1. An application program installation method, comprising:

certifying, by a terminal, an installation package received by the terminal using a first certificate, wherein the installation package comprises the first certificate for a first application program and a request for a first permission of the first application program, wherein the first certificate comprises an index, and wherein the first application program requires the first permission when running in the terminal;

determining, by the terminal, whether a second certificate is stored in a trustworthy certificate list according to the index when the installation package has been certified, wherein the trustworthy certificate list is pre-configured;

granting, by the terminal, the first permission to the first application program when the second certificate is stored in the trustworthy certificate list according to the index;

receiving, by the terminal, update information, wherein the update information comprises an index of a third certificate, a third permission configured in the third certificate, and an operation instruction, wherein the operation instruction adds the third permission, and wherein the third certificate has been set in the trustworthy certificate list;

adding, by the terminal, according to the update information, the third permission corresponding to the third certificate; and

granting, by the terminal, the third permission to a second application program, wherein the second application program is signed using the third certificate.

2. The method according to claim 1 , wherein installation information indicates that a second permission is granted to the first application program when the second certificate is not stored in the trustworthy certificate list, wherein the first permission is a system administrator permission of a system in the terminal, and wherein the second permission is a permission opened to the first application program by a system developer and a manufacturer of the terminal.

3. The method according to claim 2 , further comprising terminating all operations when the installation package of the first application program is not complete.

4. The method according to claim 1 , wherein certifying the installation package using the first certificate comprises determining, by the terminal and according to the first certificate and signature information in the first application program, whether the installation package of the first application program is complete.

5. The method according to claim 1 , wherein before granting the first permission to the first application program, the method further comprises:

prompting, by the terminal, a user to add the second certificate into a user trustworthy certificate list when the terminal determines that the second certificate is not stored in the trustworthy certificate list; and

granting, by the terminal, the first permission to the first application program after the second certificate is added in the user trustworthy certificate list, wherein a certificate trusted by the user is stored in the user trustworthy certificate list.

6. The method according to claim 1 , wherein the index is an index of an upper-level certificate of the first certificate, and wherein the second certificate is the same as the upper-level certificate of the first certificate.

7. The method according to claim 1 , wherein the index is an index of the first certificate, and wherein the second certificate is the same as the first certificate.

8. An application program installation method, comprising:

certifying, by a terminal, an installation package received by the terminal using a first certificate, wherein the installation package comprises the first certificate for a first application program and a request for a first permission of the first application program, wherein the first certificate comprises an index, and wherein the first application program requires the first permission when running in the terminal;

determining, by the terminal, whether a second certificate is stored in a trustworthy certificate list according to the index when the installation package has been certified, wherein the trustworthy certificate list is pre-configured;

granting, by the terminal, the first permission to the first application program when the second certificate is stored in the trustworthy certificate list according to the index;

receiving, by the terminal, update information, wherein the update information comprises an index of a third certificate, a third permission configured in the third certificate, and an operation instruction, wherein the operation instruction deletes the third permission, and wherein the third certificate has been set in the trustworthy certificate list;

deleting, by the terminal, according to the update information, the third permission corresponding to the third certificate; and

skipping, by the terminal, granting the third permission to a second application program, wherein the second application program is signed using the third certificate.

9. The method according to claim 8 , wherein installation information indicates that a second permission is granted to the first application program when the second certificate is not stored in the trustworthy certificate list, wherein the first permission is a system administrator permission of a system in the terminal, and wherein the second permission is a permission opened to the first application program by a system developer and a manufacturer of the terminal.

10. The method according to claim 8 , wherein certifying the installation package using the first certificate comprises determining, by the terminal and according to the first certificate and signature information in the first application program, whether the installation package of the first application program is complete.

11. The method according to claim 8 , wherein before granting the first permission to the first application pro, am, the method further comprises:

prompting, by the terminal, a user to add the second certificate into a user trustworthy certificate list when the terminal determines that the second certificate is not stored in the trustworthy certificate list; and

granting, by the terminal, the first permission to the first application program after the second certificate is added in the user trustworthy certificate list, wherein a certificate trusted by the user is stored in the user trustworthy certificate list.

12. The method according to claim 8 , wherein the index is an index of an upper-level certificate of the first certificate, and wherein the second certificate is the same as the upper-level certificate of the first certificate.

13. The method according to claim 8 , wherein the index is an index of the first certificate, and wherein the second certificate is the same as the first certificate.

14. A terminal, comprising:

a receiver configured to:

receive an installation package comprising a first certificate for a first application program and a request for a first permission of the first application program;

receive update information, wherein the first certificate comprises an index, wherein the first application program requires the first permission when running in the terminal, wherein the update information comprises an index of a third certificate, a third permission configured in the third certificate, and an operation instruction, wherein the operation instruction is used to delete or add the third permission corresponding to the third certificate, and wherein the third certificate has been set in a trustworthy certificate list; and

a processor coupled to the receiver and configured to:

certify the installation package using the first certificate in response to receiving the installation package;

determine whether a second certificate is stored in the trustworthy certificate list according to the index when the installation package has been certified, wherein the trustworthy certificate list is pre-configured;

grant the first permission to the first application program when the second certificate is stored in the trustworthy certificate list according to the index;

add the third permission according to the update information;

grant the third permission to a second application program when the operation instruction adds the third permission, wherein the second application program is signed using the third certificate;

delete the third permission according to the update information; and

skip granting the third permission to the second application program when the operation instruction deletes the third permission.

15. The terminal according to claim 14 , wherein installation information indicates that a second permission is granted to the first application program when the second certificate is not stored in the trustworthy certificate list, wherein the first permission is a system administrator permission of a system in the terminal, and wherein the second permission is a permission opened to the first application program by a system developer and a manufacturer of the terminal.

16. The terminal according to claim 14 , wherein the processor is further configured to:

determine, according to the first certificate and signature information in the first application program, whether the installation package of the first application program is complete;

terminate all operations when the installation package of the first application program is not complete; and

determine whether the second certificate is stored in the trustworthy certificate list when the installation package of the first application program is complete.

17. The terminal according to claim 14 , wherein the processor is further configured to:

prompt, before the processor records installation information, a user to add the second certificate into a user trustworthy certificate list when the processor determines that the second certificate is not stored in the trustworthy certificate list; and

record the installation information after the second certificate is added in the user trustworthy certificate list, wherein a certificate trusted by the user is stored in the user trustworthy certificate list.

18. The terminal according to claim 14 , wherein the index is an index of an upper-level certificate of the first certificate, and wherein the second certificate is the same as the upper-level certificate of the first certificate.

19. The terminal according to claim 14 , wherein the index is an index of the first certificate, and wherein the second certificate is the same as the first certificate.

Assignments (3)
CHANGE OF NAME Recorded Mar 11, 2019
From: HUAWEI DEVICE (DONGGUAN) CO.,LTD.
To: HUAWEI DEVICE CO.,LTD.
Reel/Frame 048555/0951 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 5, 2017
From: HUAWEI DEVICE CO., LTD.
To: HUAWEI DEVICE (DONGGUAN) CO., LTD.
Reel/Frame 043750/0393 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 22, 2017
From: HUANG, XI; WU, HUANGWEI
To: HUAWEI DEVICE CO., LTD.
Reel/Frame 041345/0408 →