Software development kit update method, device, electronic device and storage medium

By obtaining and applying the patch package and code tags of the software development toolkit, automatically replacing the code with functional vulnerabilities, solving the cumbersome problem of the software development toolkit update process and improving the user experience.

CN113987510BActive Publication Date: 2025-05-09CHUANGSHENG SHILIAN DIGITAL TECH BEIJING CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202111262858.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-10-28
Publication Date
2025-05-09
Estimated Expiration
2041-10-28

AI Technical Summary

Technical Problem

The update process of existing software development toolkits is cumbersome and complicated, affecting the user experience.

Method used

By obtaining the patch package of the SDK and the corresponding code tags, when running the SDK, the code in the patch package is executed to replace the code with functional vulnerabilities.

Benefits of technology

It simplifies the update process and operations of the software development toolkit, improves the user experience, and does not require users to directly participate in the update process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113987510B_ABST
    Figure CN113987510B_ABST
Patent Text Reader

Abstract

The embodiment of the present application provides a method, device, electronic device and storage medium for updating a software development kit, which, when applied to a first terminal, includes: obtaining a first patch package of the software development kit installed on the first terminal; determining a code tag in the software development kit corresponding to the first patch package, wherein the code tag identifies the code with functional vulnerabilities in the software development kit; and according to the code tag, when running the software development kit, executing the code in the first patch package to replace the code with functional vulnerabilities in the software development kit. This solution can realize imperceptible repair of functional vulnerabilities in the software development kit without upgrading the software development kit when the customer accesses the functional vulnerabilities in the software development kit, so that the user can use the repaired functions imperceptibly, thereby improving the fault tolerance rate of the software development kit.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of computer technology, and in particular to a method, device, electronic device and storage medium for updating a software development tool kit. Background Art

[0002] A software development kit (SDK) is a collection of development tools used by software engineers to build application software for a specific software package, software framework, hardware platform, operating system, etc. The software development kit integrated in the application may have functional vulnerabilities, thus affecting the normal use of the application.

[0003] Currently, functional vulnerabilities in software development kits are usually fixed by releasing new versions of the software development kits.

[0004] However, the process of releasing a new version of the software development kit is cumbersome and complicated, requiring users to update the software development kit by modifying the dependent version number, resulting in a poor user experience. Summary of the invention

[0005] In view of this, embodiments of the present application provide a method, device, electronic device and storage medium for updating a software development kit to at least partially solve the above-mentioned problems.

[0006] According to a first aspect of an embodiment of the present application, a method for updating a software development kit is provided, which is applied to a first terminal and includes: obtaining a first patch package of the software development kit installed on the first terminal; determining a code tag in the software development kit corresponding to the first patch package, wherein the code tag identifies a code with a functional vulnerability in the software development kit; and according to the code tag, when running the software development kit, executing the code in the first patch package to replace the code with a functional vulnerability in the software development kit.

[0007] Optionally, obtaining the first patch package of the software development kit installed on the first terminal includes: obtaining first version information of the software development kit; obtaining second version information of a second patch package of the software development kit that has been obtained; detecting whether the first patch package exists on the server based on the first version information and the second version information, wherein the first patch package is different from the second patch package; if the first patch package exists, determining whether the first patch package complies with rules; if the first patch package complies with the rules, downloading the first patch package from the server.

[0008] Optionally, the updating method of the software development kit also includes: decrypting an encryption key randomly generated by a symmetric encryption algorithm by using a public key or a private key of a preset asymmetric encryption algorithm to obtain the encryption key; decrypting the first patch package by using the encryption key to obtain the code in the first patch package.

[0009] Optionally, the method of the software development kit also includes: during the running of the software development kit, detecting whether the code in the first patch package can be executed normally; if the code in the first patch package cannot be executed normally, executing the code with functional vulnerabilities in the software development kit.

[0010] According to a second aspect of an embodiment of the present application, a method for updating a software development kit is provided, which is applied to a second terminal and includes: determining a code tag for identifying a code having a functional vulnerability in the software development kit; generating a first patch package based on the code having the functional vulnerability; associating the first patch package with the code tag so that the first terminal can obtain the first patch package based on the code tag, and when the first terminal runs the software development kit, executing the code in the first patch package to replace the code having the functional vulnerability in the software development kit.

[0011] Optionally, the method of the software development kit also includes: randomly generating an encryption key through a preset symmetric encryption algorithm; encrypting the code in the first patch package through the encryption key to obtain the encrypted first patch package; encrypting the encryption key through a public key or private key of a preset asymmetric encryption algorithm to obtain the encrypted encryption key; and packaging the encrypted first patch package and the encrypted encryption key and uploading them to the server.

[0012] According to a third aspect of an embodiment of the present application, there is provided an updating device for a software development kit, which is applied to a first terminal and includes: an acquisition unit, for acquiring a first patch package of the software development kit installed on the first terminal; a first identification unit, for determining a code tag in the software development kit corresponding to the first patch package, wherein the code tag identifies the code having a functional vulnerability in the software development kit; and an execution unit, for executing the code in the first patch package when running the software development kit according to the code tag, to replace the code having a functional vulnerability in the software development kit.

[0013] According to a fourth aspect of an embodiment of the present application, there is provided an updating device for a software development kit, which is applied to a second terminal and includes: a second identification unit, for determining a code tag for identifying a code having a functional vulnerability in the software development kit; a generation unit, for generating a first patch package based on the code having the functional vulnerability; and an association unit, for associating the first patch package with the code tag so that the first terminal can obtain the first patch package based on the code tag, and when the first terminal runs the software development kit, execute the code in the first patch package to replace the code having the functional vulnerability in the software development kit.

[0014] According to the fifth aspect of the embodiments of the present application, there is provided an electronic device, comprising: a processor, a memory, a communication interface and a communication bus, wherein the processor, the memory and the communication interface communicate with each other through the communication bus; the memory is used to store at least one executable instruction, and the executable instruction enables the processor to perform operations corresponding to the updating method of the software development kit as described in the first aspect or the second aspect.

[0015] According to a sixth aspect of an embodiment of the present application, a computer storage medium is provided, on which a computer program is stored. When the program is executed by a processor, the software development kit update method as described in the first aspect or the second aspect is implemented.

[0016] It can be seen from the above technical solution that when there is a code with a functional vulnerability in the software development kit, a first patch package that can repair the code with the functional vulnerability is obtained, and a code label used to identify the code with the functional vulnerability is obtained. During the running of the software development kit, when the code identified by the code label is executed, the code in the first patch package is executed to replace the code identified by the code label, thereby solving the functional vulnerability problem in the software development kit. It can be seen that when repairing the functional vulnerability in the software development kit, the first patch package is automatically obtained, and during the running of the software development kit, the code in the first patch package is used to replace the code with the functional vulnerability. The whole process does not require user participation, thereby simplifying the process and operation of updating the software development kit, thereby improving the user experience. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the embodiments of the present application. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.

[0018] Figure 1 A schematic diagram of an exemplary system for a method for updating a software development kit applicable to an embodiment of the present application;

[0019] Figure 2 is a flowchart of a method for updating a software development kit applied to a first terminal according to an embodiment of the present application;

[0020] Figure 3 is a flowchart of a method for updating a software development kit applied to a second terminal according to an embodiment of the present application;

[0021] Figure 4 is a structural block diagram of a software development kit update device according to an embodiment of the present application;

[0022] Figure 5 is a structural block diagram of an updating device for a software development kit according to another embodiment of the present application;

[0023] Figure 6 It is a schematic diagram of the structure of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION

[0024] In order to enable those skilled in the art to better understand the technical solutions in the embodiments of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments in the embodiments of the present application should fall within the scope of protection of the embodiments of the present application.

[0025] The specific implementation of the embodiment of the present application is further explained below in conjunction with the accompanying drawings of the embodiment of the present application.

[0026] Figure 1 This is a schematic diagram of an implementation environment of a software development kit update method provided in an embodiment of the present application, see Figure 1 , the implementation environment includes: a first terminal 101, a server 102 and a second terminal 103.

[0027] The server 102 is directly or indirectly connected to the first terminal 101 and the second terminal 103 through wired or wireless communication. The first terminal 101 and the second terminal 103 can be smart phones, tablet computers, laptop computers, desktop computers, smart speakers, smart watches, etc., but are not limited thereto.

[0028] The first terminal 101 may generally refer to one of a plurality of first terminals, and this embodiment is only illustrated by taking the first terminal 101. Those skilled in the art may know that the number of the first terminals may be more or less, for example, the first terminal may be only one, or the first terminals may be dozens or hundreds, or more, and the embodiment of the present application does not limit the number and device type of the first terminals.

[0029] Server 102 can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud servers, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (CDN), and big data and artificial intelligence platforms. It can be known to those skilled in the art that the number of the above servers can be more or less, and this application does not limit this. Of course, server 102 can also include servers with other functions in order to provide more comprehensive and diversified services.

[0030] The second terminal 103 may generally refer to one of a plurality of second terminals, and this embodiment is only illustrated by the second terminal 103. Those skilled in the art may know that the number of the second terminals may be more or less, for example, the second terminal may be only one, or the second terminals may be dozens or hundreds, or more, and the embodiment of the present application does not limit the number and device type of the second terminals.

[0031] It should be noted that, unless otherwise specified, the first terminal involved in the following embodiment of a method for updating a software development kit may be the above-mentioned first terminal 101, the server involved in the following embodiment of a method for updating a software development kit may be the above-mentioned server 102, and the second terminal involved in the following embodiment of a method for updating a software development kit may be the above-mentioned second terminal 103.

[0032] It should be understood that the technical solutions of the embodiments of the present application can be applied to various electronic devices, such as portable or mobile computing devices such as smart phones, laptops, tablet computers, gaming devices, and other electronic devices, as well as electronic databases, automobiles, bank automated teller machines (ATMs), etc., but the embodiments of the present application are not limited to this.

[0033] Based on the above system, an embodiment of the present application provides a method for updating a software development kit, which is described below through multiple embodiments.

[0034] To facilitate better understanding, the technical terms involved in the embodiments of the present application are first briefly introduced.

[0035] A software development kit (SDK) is a collection of development tools used by software engineers to build application software for a specific software package, software framework, hardware platform, operating system, etc. The software development kit integrated in the application may have functional vulnerabilities, thus affecting the normal use of the application.

[0036] Reflection technology is provided by the Java development language. It is a technology that dynamically modifies class-related information through the bytecode object of the class during program execution.

[0037] Combine the following Figure 2 , a method for updating a software development kit applied to a first terminal is specifically described. Specifically, Figure 2 is a flowchart of a method for updating a software development kit applied to a first terminal provided in an embodiment of the present application, such as Figure 2 As shown, the method includes:

[0038] Step 201: Obtain a first patch package of a software development kit installed on a first terminal.

[0039] The first patch package is used to repair functional vulnerabilities existing in the software development kit installed on the first terminal.

[0040] When obtaining the first patch package, it is possible to query whether there is a patch package for repairing the software development kit installed on the first terminal based on the identification information of the software development kit. If so, the patch package for repairing the software development kit is obtained as the first patch package.

[0041] Step 202: Determine a code tag in the software development kit corresponding to the first patch package, wherein the code tag identifies the code in the software development kit that has a functional vulnerability.

[0042] The code in the software development kit has a corresponding code tag, and the code in the software development kit can be located through the code tag. According to the code tag corresponding to the first patch package, the code that can repair the functional vulnerability through the first patch package can be located in the software development kit.

[0043] Step 203: According to the code tag, when the software development kit is run, the code in the first patch package is executed to replace the code with the functional vulnerability in the software development kit.

[0044] During the execution of the software development kit, when the code identified by the aforementioned code tag in the software development kit is executed, the code of the first patch package is executed to replace the code with the functional vulnerability in the software development kit, thereby resolving the functional vulnerability in the software development kit.

[0045] In an embodiment of the present application, when a software development kit has a code with a functional vulnerability, a first patch package that can repair the code with the functional vulnerability is obtained, and a code label for identifying the code with the functional vulnerability is obtained. During the running of the software development kit, when the code identified by the code label is executed, the code in the first patch package is executed to replace the code identified by the code label, thereby solving the functional vulnerability problem in the software development kit. It can be seen that when the functional vulnerability in the software development kit is repaired, the first patch package is automatically obtained, and during the running of the software development kit, the code in the first patch package is used to replace the code with the functional vulnerability. The whole process does not require user participation, thereby simplifying the process and operation of updating the software development kit, thereby improving the user experience.

[0046] In a possible implementation, when obtaining the first patch package, the first patch package for updating the software development kit can be obtained according to the version information of the software development kit and the version information of the patch package that has been obtained before. Specifically, obtaining the first patch package can be implemented by the following steps:

[0047] S1. Obtain the first version information of the software development kit.

[0048] The first version information is used to indicate the version of the software development kit installed on the first terminal. Based on the first version information, a patch package applicable to the software development kit installed on the first terminal can be identified.

[0049] S2. Obtain second version information of the second patch package of the obtained software development kit.

[0050] If the second patch package applied to the software development kit installed on the first terminal has been obtained before, the second version information of the second patch package is obtained.

[0051] It should be understood that if a plurality of second patch packages applied to the software development kit installed on the first terminal have been obtained before, the second version information of each second patch package is obtained respectively.

[0052] S3. According to the first version information and the second version information, detect whether the first patch package exists on the server. If yes, execute S4; otherwise, terminate the current process.

[0053] The patch packages stored on the server are associated with the software development kit, so all patch packages applicable to the software development kit can be found according to the first version information. After all patch packages applicable to the software development kit are found, the second patch packages that have been obtained before are filtered out according to the second version information, and then it is detected whether there are patch packages applicable to the software development kit but not obtained before. If there are patch packages that meet the condition, the patch packages that meet the condition are used as the first patch packages.

[0054] S4: Determine whether the first patch package complies with the rules. If yes, execute S5; otherwise, end the current process.

[0055] Determining whether the first patch package complies with the rules may include querying a patch database using the information requested by the first terminal. If the first patch package contains the information requested by the first terminal, it is determined to comply with the rules and S5 is executed. If the first patch package does not contain the information requested by the first terminal, it is determined to not comply with the rules and the current process ends.

[0056] S5. Download the first patch package from the server.

[0057] In the embodiment of the present application, based on the first version information of the software development kit to be updated, all patch packages applicable to the software development kit can be searched on the server, and then based on the second version information of the second patch package that has been obtained before, the second patch package that has been obtained before can be filtered out from each patch package that has been found, and then the patch packages other than the second patch package in each patch package that has been found are used as the first patch package. Based on the first version information, it is guaranteed that all patch packages that can be used for the software development kit can be obtained, and based on the second version information, the second patch package that has been obtained before can be filtered out, and then the newly released first patch package can be obtained. On the basis of a more comprehensive solution to the functional vulnerabilities existing in the software development kit, it is possible to avoid obtaining duplicate patch packages, avoid wasting storage resources on the first terminal, and ensure that the software development kit can operate normally.

[0058] In a possible implementation, when S3 detects whether the first patch package exists on the server according to the first version information and the second version information, the first version information can be compared with the version information of each patch package on the server to determine the patch package that can be used for the software development kit on the server. The first version information and the version information of the patch package both include fields such as sdk_name, sdk_version, and patch_version, where sdk_name is the name of the software development kit, sdk_version is the first version information of the software development kit to be updated, and patch_version is the patch package version information.

[0059] For any patch package on the server, if the version information of the patch package is the same as the values ​​corresponding to the sdk_name, sdk_version, patch_version and other fields of the first version information, it is determined that the patch package can be used for the software development kit identified by the first version information; if the version information of the patch package is different from the first version information in the value corresponding to at least one field, it is determined that the patch package cannot be used for the software development kit identified by the first version information.

[0060] In a possible implementation, when determining whether the first patch package complies with the rules in S4, the patch database can be queried according to the request information of the first terminal. If a first patch package in the patch database matches the request information, it is determined that the first patch package complies with the rules, otherwise it is determined that the first patch package does not comply with the rules. The request information of the first terminal includes but is not limited to platform, hotfix_enable, app_package_name, and app_package_version, where platform is platform information, hotfix_enable is a prerequisite, which means that if the first terminal does not enable hot fix, then empty data is directly returned without querying the database, app_package_name is the application patch package name, and app_package_version is the application patch version information.

[0061] After determining that a first patch package meets the rule according to the request information of the first terminal, the download information returned by the server is received, and then the first patch package is downloaded from the server according to the download information. The download information includes but is not limited to url, pKey, sdk_version_name, patch_version, and platform, where url is the download address of the first patch package, pKey is the key information used to decrypt the first patch package, sdk_version_name is the name of the first version information of the software development kit to be updated, patch_version is the patch package version information, and platform is the platform information.

[0062] In an embodiment of the present application, when the software development kit is started, the patch information is checked to determine whether there is a first patch package that can be used for the software development kit and complies with the rules. The first patch package that can be used for the software development kit is queried through fields such as sdk_name, sdk_version, and patch_version. The queried first patch package is checked through fields such as platform, hotfix_enable, app_package_name, and app_package_version to see whether it complies with preset rules. After determining that the first patch package complies with the rules, the first patch package is downloaded from the server to ensure that the downloaded first patch package can be applied to the software development kit and resolve functional vulnerabilities in the software development kit.

[0063] In a possible implementation, during the process of running the software development kit on the first terminal, the first terminal uses a patch loader to load the first patch package, and obtains the code (methodA1) inside the first patch package through the reflection technology provided by the Java development language. When the program executes methodA of ClassA identified by the code label, it is determined according to the code label that methodA needs to be repaired, and then methodA is redirected to methodA1 in the first patch package, thereby changing the method logic flow, replacing the previous old logic, and executing the new logic, thereby achieving the purpose of repair.

[0064] According to the software development kit update method provided in the embodiment of the present application, when a customer accesses a functional vulnerability in the software development kit, the code inside the first patch package is obtained based on the reflection technology, and the class to be repaired in the software development kit is determined based on the code label. The old method in the class to be repaired will be redirected to the patch method of the patch class in the first patch package, and the new code logic will be executed to achieve code repair. It is possible to update the program code in the software development kit without upgrading the software development kit, and the modified code will take effect in real time (hot plugging), thereby realizing hot update of the software development kit and imperceptibly repairing the functional vulnerability in the software development kit, so that users can use the repaired functions imperceptibly, thereby improving the fault tolerance of the software development kit.

[0065] In a possible implementation, in order to ensure the security of the software development kit, the first patch package obtained is encrypted by an asymmetric encryption algorithm and a symmetric encryption algorithm. After obtaining the first patch package, the first patch package is decrypted by a corresponding decryption algorithm to obtain the code information in the first patch package. Specifically, the first patch package can be decrypted in the following manner:

[0066] A1: Decrypt the encryption key obtained together with the first patch package using a public key or a private key of a preset asymmetric encryption algorithm to obtain an encryption key.

[0067] When encrypting the first patch package, if the encryption key is encrypted by the public key of the asymmetric encryption algorithm, the encryption key is decrypted by the private key of the asymmetric encryption algorithm; if the encryption key is encrypted by the private key of the asymmetric encryption algorithm, the encryption key is decrypted by the public key of the asymmetric algorithm.

[0068] In the process of encrypting the first patch package, an encryption key is randomly generated by a preset symmetric encryption algorithm, and the first patch package is encrypted by the encryption key. After the encryption key is encrypted by the public key or private key of the asymmetric encryption algorithm, the encrypted encryption key is released together with the encrypted first patch package.

[0069] The asymmetric encryption algorithm may be an RSA encryption algorithm, and the symmetric encryption algorithm may be an AES encryption algorithm.

[0070] A2: Decrypt the first patch package using the encryption key to obtain the code in the first patch package.

[0071] After the encryption key is decrypted by the public key or private key of the asymmetric encryption algorithm to obtain the plain text of the encryption key, the first patch package is decrypted by the encryption key to obtain the code and other contents in the first patch package.

[0072] In the embodiment of the present application, when encrypting the first patch package, the first patch package is first encrypted by an encryption key generated by a symmetric encryption algorithm, and then the encryption key is encrypted by a public key or a private key of an asymmetric encryption algorithm. Accordingly, when decrypting the first patch package, the encryption key is first decrypted by a public key or a private key of an asymmetric encryption algorithm to obtain a plaintext of the encryption key, and then the first patch package is decrypted by the plaintext of the encryption key to obtain the content of the first patch package. By performing dual encryption and decryption on the first patch package through an asymmetric encryption algorithm and a symmetric encryption algorithm, the security of the data in the first patch package can be improved.

[0073] In a possible implementation, during the running of the software development kit, it is detected whether the code in the first patch package can be executed normally. If the code in the first patch package cannot be executed normally, the code with the functional vulnerability in the software development kit is executed.

[0074] In an embodiment of the present application, during the running of the software development kit, it is detected whether the code in the first patch package can be executed normally. If the code in the first patch package cannot be executed normally, the original code with functional vulnerabilities in the software development kit is executed to ensure that the software development kit can continue to run and the software development kit will not crash, thereby ensuring the user experience.

[0075] Combine the following Figure 3 The updating method of the software development kit applied to the second terminal is specifically described. Specifically, Figure 3 is a flowchart of a method for updating a software development kit applied to a second terminal provided in an embodiment of the present application, such as Figure 3 As shown, it includes:

[0076] Step 301: Determine a code tag for identifying code with functional vulnerabilities in a software development kit.

[0077] By determining the code label for identifying the code with functional vulnerabilities in the software development kit, the code label can not only locate the functional vulnerability, but also be used to generate a patch package and establish an association between the patch package code and the code with the functional vulnerability.

[0078] Step 302: Generate a first patch package based on the code with functional vulnerabilities in the software development kit.

[0079] According to the functional vulnerabilities in the software development kit, the code to be repaired in the software development kit can be known, and then the repair code that can solve the functional vulnerabilities in the software development kit can be generated according to the code to be repaired, and then the first patch package that guarantees the repair code can be generated.

[0080] Step 303: associate the first patch package with the code tag.

[0081] After the first patch package is associated with the code label, when the first terminal runs the software development kit, the first patch package that matches the code label of the functional vulnerability can be found, and then when the code with the functional vulnerability identified by the code label is executed, the code with the functional vulnerability is replaced with the code in the first patch package. This enables the first terminal to obtain the first patch package according to the code label, and when the first terminal runs the software development kit, the code in the first patch package is executed to replace the code with the functional vulnerability in the software development kit.

[0082] In an embodiment of the present application, a code tag for identifying a code with a functional vulnerability in a software development kit is determined. The code tag can not only locate the functional vulnerability, but also be used to generate a patch package, and is also used to establish an association between the patch package code and the code with the functional vulnerability. According to the functional vulnerability in the software development kit, the code to be repaired can be known, and then the code that can play a repair role can be generated according to the code to be repaired, and then the first patch package is generated. The first patch package is associated with the code tag so that the first terminal can obtain the first patch package according to the code tag, and when the first terminal runs the software development kit, the code in the first patch package is executed to replace the code with the functional vulnerability in the software development kit. It can be seen that when the functional vulnerability in the software development kit is repaired, the first patch package is automatically obtained, and the code in the first patch package is used to replace the code with the functional vulnerability during the operation of the software development kit. The whole process does not require user participation, thereby simplifying the process and operation of updating the software development kit, thereby improving the user experience.

[0083] In a possible implementation, in a software development kit, a plug-in Gradle-plugin is executed to generate patch application-related code in classes and methods, and a patch repair logic (if (changeQuickRedirect == null) -else) is inserted before each method to determine whether to redirect quickly. The method (methodA) with a functional vulnerability of the class to be repaired (ClassA) is marked according to the code label, and a first patch package is generated through a patch plug-in (Auto-Patch-Plugin). When the first terminal executes the method (methodA) with a functional vulnerability of the class to be repaired (ClassA) identified by the code label in the software development kit, and the logic for patch repair is not empty (changeQuickRedirect!= null), it is determined that the method (methodA) with a functional vulnerability needs to be repaired, and then the method (methodA) with a functional vulnerability is redirected to the repair method (methodA1) in the first patch package.

[0084] The embodiment of the present application provides a method for updating a software development kit, which dynamically inserts code into each method through a plug-in to add patch repair logic to each class. When generating a patch package, the patch package is generated by scanning the tag method that needs to be repaired. When repair is required, the repair class is loaded, and the method with functional vulnerabilities is redirected to the repair class. By executing the new logic generated by the redirection, the functional vulnerability is repaired.

[0085] In a possible implementation, after the first patch is generated, the first patch package may be encrypted to ensure the security of the first patch package. Specifically, an encryption key is randomly generated by a preset symmetric encryption algorithm, the code in the first patch package is encrypted by the encryption key to obtain the encrypted first patch package, and then the encryption key is encrypted by a public key or a private key of a preset asymmetric encryption algorithm to obtain the encrypted encryption key, and then the encrypted first patch package and the encrypted encryption key are packaged and uploaded to the server.

[0086] The code implementation for encrypting the first patch package may be as follows:

[0087] aesKey=Random(16): randomly generates a 16-bit encryption key;

[0088] AES(file,aesKey): encrypt the patch package with aes using the encryption key;

[0089] pKey=RSA(aesKey,publicKey): encrypt the encryption key with RSA.

[0090] In the embodiment of the present application, the encryption method of the patch package adopts RSA+AES. RSA is an asymmetric encryption algorithm. Public key encryption requires private key decryption, and private key encryption requires public key decryption. AES is a symmetric encryption algorithm, and one secret key can complete encryption and decryption. If only AES is used for data encryption and decryption, if the secret key is leaked, it will bring security risks. RSA and AES are selected to realize encryption and decryption, and the randomly generated AES secret key is used to encrypt data, and the randomly generated AES secret key is encrypted with RSA, which can protect data security to a certain extent.

[0091] In one possible implementation, after generating the first patch package, the first patch package is associated with the first version information of the software development kit, and the associated first patch package and first version information are uploaded to the server so that the first terminal can query and download the first patch package from the server according to the first version information.

[0092] In one possible implementation, after the first patch package is generated, the file is first uploaded to OSS (object storage service), and then a link address patchUrl is obtained. This address is then combined with baseVersion (base package version) and patchVersion (patch) and uploaded to the interface server for background management of the patch version.

[0093] In a possible implementation, the first patch package may include the code of the previously released second patch package, thereby better achieving the compatibility of hot updates of the software development kit.

[0094] Combine the following Figure 4 A software development kit update device in an embodiment of the present application is specifically described. Specifically, Figure 4 is a schematic diagram of an updating device for a software development kit applied to a first terminal provided in an embodiment of the present application, such as Figure 4 As shown, the device comprises:

[0095] An acquisition unit 401 is used to acquire a first patch package of a software development kit installed on a first terminal;

[0096] A first identification unit 402 is used to determine a code tag in the software development kit corresponding to the first patch package, wherein the code tag identifies the code in the software development kit that has a functional vulnerability;

[0097] The execution unit 403 executes the code in the first patch package to replace the code with the functional vulnerability in the software development kit when running the software development kit according to the code tag.

[0098] The software development kit update device of this embodiment is used to implement the software development kit update method applied to the first terminal, and has the beneficial effects of the corresponding method embodiment, which will not be repeated here. In addition, the functional implementation of each module in the software development kit update device of this embodiment can refer to the description of the corresponding part in the aforementioned method embodiment, which will not be repeated here.

[0099] Combine the following Figure 5 Another software development kit update device in the embodiment of the present application is specifically described. Specifically, Figure 5 is a schematic diagram of an updating device for a software development kit applied to a second terminal provided in an embodiment of the present application, such as Figure 5 As shown, the device comprises:

[0100] A second identification unit 501 is used to determine a code tag for identifying a code having a functional vulnerability in a software development kit;

[0101] A generating unit 502, configured to generate a first patch package according to the code having a functional vulnerability;

[0102] The association unit 503 is used to associate the first patch package with the code tag so that the first terminal can obtain the first patch package according to the code tag, and when the first terminal runs the software development kit, execute the code in the first patch package to replace the code with functional vulnerabilities in the software development kit.

[0103] The software development kit update device of this embodiment is used to implement the aforementioned software development kit update method applied to the second terminal, and has the beneficial effects of the corresponding method embodiment, which will not be repeated here. In addition, the functional implementation of each module in the software development kit update device of this embodiment can refer to the description of the corresponding part in the aforementioned method embodiment, which will not be repeated here.

[0104] Reference Figure 6 , shows a schematic diagram of the structure of an electronic device according to an embodiment of the present application. The specific embodiment of the present application does not limit the specific implementation of the electronic device.

[0105] like Figure 6 As shown, the electronic device may include: a processor (processor) 602 , a communication interface (Communications Interface) 604 , a memory (memory) 606 , and a communication bus 608 .

[0106] in:

[0107] The processor 602 , the communication interface 604 , and the memory 606 communicate with each other via a communication bus 608 .

[0108] The communication interface 604 is used to communicate with other electronic devices or servers.

[0109] The processor 602 is used to execute the program 610, and specifically can execute the relevant steps in the above-mentioned software development kit update method embodiment.

[0110] Specifically, the program 610 may include program codes, which include computer operation instructions.

[0111] The processor 602 may be a central processing unit (CPU), or an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application. The one or more processors included in the smart device may be processors of the same type, such as one or more CPUs; or processors of different types, such as one or more CPUs and one or more ASICs.

[0112] The memory 606 is used to store the program 610. The memory 606 may include a high-speed RAM memory, and may also include a non-volatile memory (non-volatile memory), such as at least one disk memory.

[0113] The specific implementation of each step in program 610 can refer to the corresponding description of the corresponding steps and units in the update method embodiment of the software development kit, which will not be repeated here. Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working process of the above-described devices and modules can refer to the corresponding process description in the above-mentioned method embodiment, which will not be repeated here.

[0114] An embodiment of the present application also provides a computer program product, including computer instructions, which instruct a computing device to execute operations corresponding to any one of the software development toolkit update methods in the above-mentioned multiple method embodiments.

[0115] It should be pointed out that, according to the needs of implementation, the various components / steps described in the embodiments of the present application can be split into more components / steps, or two or more components / steps or partial operations of components / steps can be combined into new components / steps to achieve the purpose of the embodiments of the present application.

[0116] The above-mentioned method according to the embodiment of the present application can be implemented in hardware, firmware, or implemented as software or computer code that can be stored in a recording medium (such as a CD ROM, RAM, floppy disk, hard disk or magneto-optical disk), or implemented as a computer code originally stored in a remote recording medium or a non-temporary machine-readable medium downloaded through a network and stored in a local recording medium, so that the method described herein can be stored in such software processing on a recording medium using a general-purpose computer, a special-purpose processor or programmable or special-purpose hardware (such as an ASIC or FPGA). It can be understood that a computer, a processor, a microprocessor controller or programmable hardware includes a storage component (e.g., RAM, ROM, flash memory, etc.) that can store or receive software or computer code, and when the software or computer code is accessed and executed by a computer, a processor or hardware, the verification code generation method described herein is implemented. In addition, when a general-purpose computer accesses a code for implementing the verification code generation method shown here, the execution of the code converts the general-purpose computer into a special-purpose computer for executing the verification code generation method shown here.

[0117] Those of ordinary skill in the art will appreciate that the units and method steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the embodiments of the present application.

[0118] The above implementation methods are only used to illustrate the embodiments of the present application, and are not limitations on the embodiments of the present application. Ordinary technicians in the relevant technical field can make various changes and modifications without departing from the spirit and scope of the embodiments of the present application. Therefore, all equivalent technical solutions also belong to the scope of the embodiments of the present application. The scope of patent protection of the embodiments of the present application should be limited by the claims.

Claims

1. A method for updating a software development kit, applied to a first terminal, characterized in that: include: Obtaining a first patch package of a software development kit installed on the first terminal; Determining a code tag in the software development kit corresponding to the first patch package, wherein the code tag identifies a code in the software development kit having a functional vulnerability; According to the code tag, when running the software development kit, the code in the first patch package is executed to replace the code with the functional vulnerability in the software development kit; The first patch package is used to repair functional vulnerabilities in the software development kit installed on the first terminal; When obtaining the first patch package, it is possible to query whether there is a patch package for repairing the software development kit according to the identification information of the software development kit installed on the first terminal, and if so, obtain the patch package for repairing the software development kit as the first patch package; The code in the software development kit has a corresponding code tag, and the code in the software development kit can be located by the code tag; according to the code tag corresponding to the first patch package, the code that can repair the functional vulnerability through the first patch package can be located in the software development kit; Wherein, during the execution of the software development kit, when the code identified by the code tag in the software development kit is executed, the code of the first patch package is executed to replace the code with the functional vulnerability in the software development kit, thereby resolving the functional vulnerability in the software development kit; The step of obtaining a first patch package of a software development kit installed on the first terminal includes: Obtaining first version information of the software development kit; Obtaining the second version information of the second patch package of the software development kit; According to the first version information and the second version information, detecting whether the first patch package exists on the server, wherein the first patch package is different from the second patch package; If the first patch package exists, determining whether the first patch package complies with the rule; If the first patch package meets the rule, downloading the first patch package from the server; The first version information is used to indicate the version of the software development kit installed on the first terminal, and a patch package applicable to the software development kit installed on the first terminal can be identified based on the first version information; The patch packages stored on the server are associated with the software development kit, so all patch packages applicable to the software development kit can be found according to the first version information; after all patch packages applicable to the software development kit are found, the second patch packages that have been obtained before are filtered out according to the second version information, and then it is detected whether there are patch packages applicable to the software development kit but not obtained before, and if there are patch packages that meet the condition, the patch packages that meet the condition are used as the first patch packages; The determining whether the first patch package complies with the rules includes querying a patch database using the information requested by the first terminal. If the first patch package contains the information requested by the first terminal, it is determined that the patch package complies with the rules.

2. The method according to claim 1, wherein: The method further comprises: Decrypting the encryption key randomly generated by the symmetric encryption algorithm using the public key or private key of the preset asymmetric encryption algorithm to obtain the encryption key; The first patch package is decrypted using the encryption key to obtain the code in the first patch package.

3. The method according to any one of claims 1-2, characterized in that: The method further comprises: During the running of the software development kit, detecting whether the code in the first patch package can be executed normally; If the code in the first patch package cannot be executed normally, the code with the functional vulnerability in the software development kit is executed.

4. A method for updating a software development kit, applied to a second terminal, characterized in that: include: Identify code tags that identify code in software development kits that contain functional vulnerabilities; Generate a first patch package according to the code with functional vulnerabilities; Associating the first patch package with the code tag so that the first terminal can obtain the first patch package according to the code tag, and when the first terminal runs the software development kit, execute the code in the first patch package to replace the code with the functional vulnerability in the software development kit; The generating of the first patch package according to the code with functional vulnerabilities in the software development kit includes: obtaining the code to be repaired in the software development kit according to the functional vulnerabilities in the software development kit, and then generating the repair code that can solve the functional vulnerabilities in the software development kit according to the code to be repaired, and then generating the first patch package that guarantees the repair code; In a software development kit, a patch repair logic is inserted before each method to determine whether to redirect quickly; a method with a functional vulnerability in a class to be repaired is marked according to a code tag, and a first patch package is generated through a patch plug-in; when a first terminal executes a method with a functional vulnerability in a class to be repaired identified by a code tag in the software development kit, and the patch repair logic is not empty, it is determined that the method with a functional vulnerability needs to be repaired, and then the method with a functional vulnerability is redirected to a repair method in the first patch package; The first terminal can obtain the first patch package according to the code tag, and when the first terminal runs the software development kit, execute the code in the first patch package to replace the code with functional vulnerability in the software development kit, including: Obtaining a first patch package of a software development kit installed on the first terminal; Determining a code tag in the software development kit corresponding to the first patch package, wherein the code tag identifies a code in the software development kit having a functional vulnerability; According to the code tag, when running the software development kit, the code in the first patch package is executed to replace the code with the functional vulnerability in the software development kit; The first patch package is used to repair functional vulnerabilities in the software development kit installed on the first terminal; When obtaining the first patch package, it is possible to query whether there is a patch package for repairing the software development kit according to the identification information of the software development kit installed on the first terminal, and if so, obtain the patch package for repairing the software development kit as the first patch package; The code in the software development kit has a corresponding code tag, and the code in the software development kit can be located by the code tag; according to the code tag corresponding to the first patch package, the code that can repair the functional vulnerability through the first patch package can be located in the software development kit; Wherein, during the execution of the software development kit, when the code identified by the code tag in the software development kit is executed, the code of the first patch package is executed to replace the code with the functional vulnerability in the software development kit, thereby resolving the functional vulnerability in the software development kit; The step of obtaining a first patch package of a software development kit installed on the first terminal includes: Obtaining first version information of the software development kit; Obtaining the second version information of the second patch package of the software development kit; According to the first version information and the second version information, detecting whether the first patch package exists on the server, wherein the first patch package is different from the second patch package; If the first patch package exists, determining whether the first patch package complies with the rule; If the first patch package meets the rule, downloading the first patch package from the server; The first version information is used to indicate the version of the software development kit installed on the first terminal, and a patch package applicable to the software development kit installed on the first terminal can be identified based on the first version information; The patch packages stored on the server are associated with the software development kit, so all patch packages applicable to the software development kit can be found according to the first version information; after all patch packages applicable to the software development kit are found, the second patch packages that have been obtained before are filtered out according to the second version information, and then it is detected whether there are patch packages applicable to the software development kit but not obtained before, and if there are patch packages that meet the condition, the patch packages that meet the condition are used as the first patch packages; The determining whether the first patch package complies with the rules includes querying a patch database using the information requested by the first terminal. If the first patch package contains the information requested by the first terminal, it is determined that the patch package complies with the rules.

5. The method according to claim 4, characterized in that The method further comprises: Randomly generate encryption keys through a preset symmetric encryption algorithm; Encrypt the code in the first patch package by using the encryption key to obtain the encrypted first patch package; Encrypting the encryption key using a public key or a private key of a preset asymmetric encryption algorithm to obtain an encrypted encryption key; The encrypted first patch package and the encrypted encryption key are packaged and uploaded to the server.

6. A software development kit update device, applied to a first terminal, characterized in that: include: An acquiring unit, configured to acquire a first patch package of a software development kit installed on the first terminal; A first identification unit is used to determine a code tag in the software development kit corresponding to the first patch package, wherein the code tag identifies the code in the software development kit that has a functional vulnerability; an execution unit, which executes the code in the first patch package to replace the code with the functional vulnerability in the software development kit when running the software development kit according to the code tag; The first patch package is used to repair functional vulnerabilities in the software development kit installed on the first terminal; When obtaining the first patch package, it is possible to query whether there is a patch package for repairing the software development kit according to the identification information of the software development kit installed on the first terminal, and if so, obtain the patch package for repairing the software development kit as the first patch package; The code in the software development kit has a corresponding code tag, and the code in the software development kit can be located by the code tag; according to the code tag corresponding to the first patch package, the code that can repair the functional vulnerability through the first patch package can be located in the software development kit; Wherein, during the execution of the software development kit, when the code identified by the code tag in the software development kit is executed, the code of the first patch package is executed to replace the code with the functional vulnerability in the software development kit, thereby resolving the functional vulnerability in the software development kit; The step of obtaining a first patch package of a software development kit installed on the first terminal includes: Obtaining first version information of the software development kit; Obtaining the second version information of the second patch package of the software development kit; According to the first version information and the second version information, detecting whether the first patch package exists on the server, wherein the first patch package is different from the second patch package; If the first patch package exists, determining whether the first patch package complies with the rule; If the first patch package meets the rule, downloading the first patch package from the server; The first version information is used to indicate the version of the software development kit installed on the first terminal, and a patch package applicable to the software development kit installed on the first terminal can be identified based on the first version information; The patch packages stored on the server are associated with the software development kit, so all patch packages applicable to the software development kit can be found according to the first version information; after all patch packages applicable to the software development kit are found, the second patch packages that have been obtained before are filtered out according to the second version information, and then it is detected whether there are patch packages applicable to the software development kit but not obtained before, and if there are patch packages that meet the condition, the patch packages that meet the condition are used as the first patch packages; The determining whether the first patch package complies with the rules includes querying a patch database using the information requested by the first terminal. If the first patch package contains the information requested by the first terminal, it is determined that the patch package complies with the rules.

7. A software development kit update device, applied to a second terminal, characterized in that: include: a second identification unit, for determining a code tag for identifying a code having a functional vulnerability in the software development kit; A generating unit, configured to generate a first patch package according to the code having a functional vulnerability; an associating unit, configured to associate the first patch package with the code tag, so that the first terminal can obtain the first patch package according to the code tag, and execute the code in the first patch package to replace the code with the functional vulnerability in the software development kit when the first terminal runs the software development kit; The generating of the first patch package according to the code with functional vulnerabilities in the software development kit includes: obtaining the code to be repaired in the software development kit according to the functional vulnerabilities in the software development kit, and then generating the repair code that can solve the functional vulnerabilities in the software development kit according to the code to be repaired, and then generating the first patch package that guarantees the repair code; In a software development kit, a patch repair logic is inserted before each method to determine whether to redirect quickly; a method with a functional vulnerability in a class to be repaired is marked according to a code tag, and a first patch package is generated through a patch plug-in; when a first terminal executes a method with a functional vulnerability in a class to be repaired identified by a code tag in the software development kit, and the patch repair logic is not empty, it is determined that the method with a functional vulnerability needs to be repaired, and then the method with a functional vulnerability is redirected to a repair method in the first patch package; The first terminal can obtain the first patch package according to the code tag, and when the first terminal runs the software development kit, execute the code in the first patch package to replace the code with functional vulnerability in the software development kit, including: Obtaining a first patch package of a software development kit installed on the first terminal; Determining a code tag in the software development kit corresponding to the first patch package, wherein the code tag identifies a code in the software development kit having a functional vulnerability; According to the code tag, when running the software development kit, the code in the first patch package is executed to replace the code with the functional vulnerability in the software development kit; The first patch package is used to repair functional vulnerabilities in the software development kit installed on the first terminal; When obtaining the first patch package, it is possible to query whether there is a patch package for repairing the software development kit according to the identification information of the software development kit installed on the first terminal, and if so, obtain the patch package for repairing the software development kit as the first patch package; The code in the software development kit has a corresponding code tag, and the code in the software development kit can be located by the code tag; according to the code tag corresponding to the first patch package, the code that can repair the functional vulnerability through the first patch package can be located in the software development kit; Wherein, during the execution of the software development kit, when the code identified by the code tag in the software development kit is executed, the code of the first patch package is executed to replace the code with the functional vulnerability in the software development kit, thereby resolving the functional vulnerability in the software development kit; The step of obtaining a first patch package of a software development kit installed on the first terminal includes: Obtaining first version information of the software development kit; Obtaining the second version information of the second patch package of the software development kit; According to the first version information and the second version information, detecting whether the first patch package exists on the server, wherein the first patch package is different from the second patch package; If the first patch package exists, determining whether the first patch package complies with the rule; If the first patch package meets the rule, downloading the first patch package from the server; The first version information is used to indicate the version of the software development kit installed on the first terminal, and a patch package applicable to the software development kit installed on the first terminal can be identified based on the first version information; The patch packages stored on the server are associated with the software development kit, so all patch packages applicable to the software development kit can be found according to the first version information; after all patch packages applicable to the software development kit are found, the second patch packages that have been obtained before are filtered out according to the second version information, and then it is detected whether there are patch packages applicable to the software development kit but not obtained before, and if there are patch packages that meet the condition, the patch packages that meet the condition are used as the first patch packages; The determining whether the first patch package complies with the rules includes querying a patch database using the information requested by the first terminal. If the first patch package contains the information requested by the first terminal, it is determined that the patch package complies with the rules.

8. An electronic device, comprising: A processor, a memory, a communication interface and a communication bus, wherein the processor, the memory and the communication interface communicate with each other via the communication bus; The memory is used to store at least one executable instruction, and the executable instruction enables the processor to perform operations corresponding to the updating method of the software development kit according to any one of claims 1-3 or claims 4-5.

9. A computer storage medium having a computer program stored thereon, wherein when the program is executed by a processor, the updating method of the software development kit according to any one of claims 1 to 3 or claims 4 to 5 is implemented.

Citation Information

Patent Citations

  • Method and device for installing patch packets

    CN102087607A

  • Vulnerability automatic fixing method and mobile terminal

    CN107506647A

  • Software development kit SDK hot repair method and device and electronic equipment

    CN112650521A