Application signature method, system, transaction terminal and service platform
The application is signed online through the service platform, and the transaction terminal is packaged, combined and checked, solving the problems of application installation security and reliability on the transaction terminal, and achieving safe and reliable installation of the application.
Patent Information
- Application Number
- CN202111633858.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-28
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2041-12-28
AI Technical Summary
How to safely and reliably install applications from various industries on trading terminals to improve the security and reliability of applications in trading terminals.
The application is signed online through the service platform, and the transaction terminal receives the installation package and signature data, packages and combines it, obtains the signed application package, and installs the installation package after the signature verification is passed.
Ensures safe and reliable installation of applications in various industries, and improves the security and reliability of transaction terminal installation applications.
Smart Images

Figure CN114329358B_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the field of computer application technology, and in particular, relates to an application signature method, system, transaction terminal and electronic device. Background Art
[0002] With the development of the Internet, the use of terminal devices in various industries is becoming more and more popular. In the field of payment transactions, in order to meet the different needs of users, transaction terminals can have multiple functions such as transactions, payments, industry applications and social networking. The security and reliability of its application software has become particularly important. At the same time, the requirements for security control of transaction terminals are becoming higher and higher. Therefore, it is extremely important to ensure that applications in various industries are safely and reliably installed on transaction terminals. Summary of the invention
[0003] The embodiments of the present application provide an application signing method, system, service platform and transaction terminal, which can ensure that applications in various industries are safely and reliably installed on the transaction terminal, thereby improving the security and reliability of application installation on the transaction terminal.
[0004] In a first aspect, the present application provides an application signing method, which may include:
[0005] The transaction terminal sends a download request to the service platform, wherein the download request includes an identifier of the application to be installed;
[0006] The service platform receives the download request, and determines the installation package of the application to be installed corresponding to the download request according to the identifier;
[0007] The service platform obtains signature data associated with the installation package, and sends the installation package and the signature data to the transaction terminal;
[0008] The transaction terminal receives the installation package and the signature data, packages and combines the installation package and the signature data to obtain a signed application package, and installs the installation package after the signature of the signed application package is verified.
[0009] In a second aspect, the present application provides an application signing method, which is applied to a service platform. The method may include:
[0010] Receiving a download request sent by a transaction terminal, wherein the download request includes an identifier of an application to be installed;
[0011] Determining, according to the identifier, the installation package of the application to be installed corresponding to the download request;
[0012] Acquire signature data related to the installation package, and send the installation package and the signature data to the transaction terminal;
[0013] The signature data and the installation package are used to instruct the transaction terminal to package and combine the installation package and the signature data to obtain a signed application package, and to install the installation package after the signed application package is verified.
[0014] In a possible implementation manner of the second aspect, the download request further includes agent information to which the transaction terminal belongs; after receiving the download request sent by the transaction terminal, the method further includes:
[0015] Sending an agent certificate to the transaction terminal according to the agent information;
[0016] The agent certificate is obtained by signing the agent public key with the manufacturer's private key, and the agent public key is generated by the service platform for the agent.
[0017] In a possible implementation of the second aspect, the signature data includes a manufacturer signature file and an agent signature file;
[0018] Before acquiring the signature data related to the installation package, the method further includes:
[0019] Based on the identifier of the application to be installed, use the manufacturer's private key to sign the application to be installed, and generate the manufacturer's signature file associated with the application to be installed;
[0020] According to the agent information in the download request, the application to be installed is signed using the agent private key to generate the agent signature file associated with the application to be installed.
[0021] In a third aspect, the present application provides an application signature method, which is applied to a transaction terminal. The method may include:
[0022] Sending a download request to the service platform, wherein the download request includes an identifier of the application to be installed;
[0023] Receiving the installation package and signature data of the to-be-installed package application corresponding to the download request, which are sent by the service platform based on the identifier;
[0024] Packaging and combining the signature data and the installation package to obtain a signed application package;
[0025] The signed application package is verified, and after the verification passes, the installation package is installed.
[0026] In a possible implementation manner of the third aspect, the download request further includes agent information to which the transaction terminal belongs;
[0027] After sending the download request to the service platform, the method further includes:
[0028] Receiving an agent certificate sent by the service platform based on the agent information;
[0029] The agent certificate is obtained by signing the agent public key with the manufacturer's private key, and the agent public key is generated by the service platform for the agent.
[0030] In a possible implementation of the third aspect, the signature data includes a manufacturer signature file and an agent signature file;
[0031] The verifying the signature of the signed application package includes:
[0032] Use the manufacturer's certificate to verify the manufacturer's signature file. If the verification passes, it is determined that the installation package contains the manufacturer's signature;
[0033] The agent certificate is verified using the manufacturer certificate that has passed the signature verification. If the signature verification passes, it is determined that the agent certificate is obtained based on the manufacturer private key signature;
[0034] The agent signature file is verified using the agent certificate that has passed the verification. If the verification passes, it is determined that the agent signature file is obtained based on the agent private key signature.
[0035] In a fourth aspect, the present application provides an application signature system, the system comprising a service platform and a transaction terminal;
[0036] The transaction terminal is used to send a download request to the service platform, wherein the download request includes an identifier of the application to be installed;
[0037] The service platform is used to receive the download request and determine the installation package of the application to be installed corresponding to the download request according to the identifier;
[0038] The service platform is further used to obtain signature data associated with the installation package, and send the installation package and the signature data to the transaction terminal;
[0039] The transaction terminal is further used to receive the installation package and the signature data, package and combine the installation package and the signature data to obtain a signed application package, and install the installation package after the signed application package is verified.
[0040] In a fifth aspect, an embodiment of the present application provides a service platform, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method described in the second aspect when executing the computer program.
[0041] In a sixth aspect, an embodiment of the present application provides a transaction terminal, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method described in the third aspect when executing the computer program.
[0042] In a seventh aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method described in the first aspect or the second aspect is implemented.
[0043] In an eighth aspect, an embodiment of the present application provides a computer program product, which, when executed on a terminal device, enables the terminal device to execute the method described in the first or second aspect above.
[0044] It can be understood that the beneficial effects of the second to eighth aspects mentioned above can be found in the relevant description of the first aspect and will not be repeated here.
[0045] Compared with the prior art, the present application has the following beneficial effects: in the embodiment of the present application, the transaction terminal sends a download request to the service platform, and the download request includes an identifier of the application to be installed; the service platform receives the download request, and determines the installation package of the application to be installed corresponding to the download request according to the identifier; the service platform obtains signature data associated with the installation package, and sends the installation package and the signature data to the transaction terminal; the transaction terminal receives the installation package and the signature data, packages and combines the installation package and the signature data to obtain a signed application package, and installs the installation package after the signed application package is verified; it can ensure that applications in various industries are safely and reliably installed on the transaction terminal, and improve the security and reliability of application installation on the transaction terminal; it has strong ease of use and practicality. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.
[0047] Figure 1 It is a schematic diagram of the architecture of the system application scenario provided by the embodiment of the present application;
[0048] Figure 2 It is a schematic diagram of the implementation process of the application signing method provided in the embodiment of the present application;
[0049] Figure 3This is a schematic diagram of an interface for a service platform providing a method for generating signature data.
[0050] Figure 4 It is a schematic diagram of the implementation flow of the software upgrade method provided in the embodiment of the present application;
[0051] Figure 5 It is a schematic diagram of the interactive process of the software upgrade method provided in the embodiment of the present application;
[0052] Figure 6 It is a structural diagram of the service platform provided in the embodiment of the present application;
[0053] Figure 7 It is a structural diagram of the transaction terminal provided in an embodiment of the present application. DETAILED DESCRIPTION
[0054] In the following description, specific details such as specific system structures, technologies, etc. are provided for the purpose of illustration rather than limitation, so as to provide a thorough understanding of the embodiments of the present application. However, it should be clear to those skilled in the art that the present application may also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to prevent unnecessary details from obstructing the description of the present application.
[0055] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of described features, wholes, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or combinations thereof.
[0056] It should also be understood that the term “and / or” used in the specification and appended claims refers to any and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0057] As used in the specification and appended claims of this application, the term "if" can be interpreted as "when" or "uponce" or "in response to determining" or "in response to detecting", depending on the context. Similarly, the phrase "if it is determined" or "if [described condition or event] is detected" can be interpreted as meaning "uponce it is determined" or "in response to determining" or "uponce [described condition or event] is detected" or "in response to detecting [described condition or event]", depending on the context.
[0058] In addition, in the description of the present application specification and the appended claims, the terms "first", "second", "third", etc. are only used to distinguish the descriptions and cannot be understood as indicating or implying relative importance.
[0059] References to "one embodiment" or "some embodiments" etc. described in the specification of this application mean that one or more embodiments of the present application include specific features, structures or characteristics described in conjunction with the embodiment. Therefore, the statements "in one embodiment", "in some embodiments", "in some other embodiments", "in some other embodiments", etc. that appear in different places in this specification do not necessarily refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "including", "comprising", "having" and their variations all mean "including but not limited to", unless otherwise specifically emphasized in other ways.
[0060] At present, application software providing platforms based on web technology need to ensure the security of application software when providing services such as application uploading, testing, management, authentication and downloading, so as to protect the application software from static or dynamic attacks and improve the security performance of the system interaction process.
[0061] The embodiment of the present application provides an application signing method, which signs the application online through a service platform, and then the transaction terminal further packages and combines the data and verifies it, thereby improving the security and reliability of the transaction terminal when downloading and installing application software.
[0062] See also Figure 1 , Figure 1 Provides a schematic diagram of the system application scenario. Figure 1 As shown, the system may include a service platform 10 and a transaction terminal 20. The service platform 10 may obtain application software uploaded by application developers and manage the type and version of the application software; the transaction terminal 20 may download and install the required application software from the service platform 10; through the interaction between the service platform 10 and the transaction terminal 20, the application software may be downloaded and installed safely and reliably.
[0063] Exemplarily, the service platform may be a PAXSTORE platform, and the transaction terminal may be a POS terminal.
[0064] In some embodiments, after receiving the download instruction or update instruction input by the user, the transaction terminal 20 may send a download request to the service platform 10, and the download request includes the identifier of the application to be installed. After receiving the download request, the service platform 10 determines the installation package of the application to be installed corresponding to the download request according to the identifier; at the same time, it obtains the signature data associated with the installation package, and sends the signature data and the installation package to the transaction terminal 20. After receiving the installation package and the signature data, the transaction terminal 20 combines and packages the installation package again to obtain a signed application package, and installs the installation package after the signed application package is verified. The security of the application and the correspondence with the transaction terminal are guaranteed, and malicious downloads and installations by other terminals can be avoided.
[0065] Based on the above overview, the process of the application signing method provided by this application is described in detail below.
[0066] like Figure 2 As shown, the implementation flow diagram of the application signature method provided in the embodiment of the present application is as follows. The execution subject of the method may be Figure 1 The service platform 10 in the system shown. The method may include the following steps:
[0067] S201, receiving a download request sent by a transaction terminal, wherein the download request includes an identifier of an application to be installed.
[0068] In some embodiments, the service platform can push applications to the transaction terminal; when the service platform obtains a new application uploaded by a third-party developer or updates the version of an uploaded application, the service platform will notify the transaction terminal of the new application or the new version of the application push information. When the transaction terminal needs to install a new application or an installed application needs to be updated, it can receive instructions input by the user by clicking on the download control or the upgrade control, and based on the instruction, the transaction terminal sends a download request to the service platform.
[0069] Exemplarily, the download request may include an identifier of the application to be installed. For example, the identifier may be an application name of the application or a package name of an application package.
[0070] In some embodiments, the download request further includes information of the agent to which the transaction terminal belongs; after receiving the download request sent by the transaction terminal, the method further includes:
[0071] According to the agent information, an agent certificate is sent to the transaction terminal.
[0072] The agent certificate is obtained by signing the agent public key with the manufacturer's private key, and the agent public key is generated by the service platform for the agent.
[0073] Exemplarily, the agent is the owner of the transaction terminal, that is, the party that sells the transaction terminal on behalf of the agent, and the service platform receives the registration of the agent. When a new agent is registered on the service platform, the signature and verification public and private keys of the application will be generated for the agent.
[0074] Exemplarily, the service platform generates a pair of public and private keys for each registered agent. The service platform signs the agent's public key with the manufacturer's private key, assembles it into an agent certificate, and sends it to the transaction terminal represented by the agent; the agent's private key is stored in the service platform.
[0075] Exemplarily, the service platform can provide a unified application signature standard for transaction terminals of different manufacturers, but different signature data can be provided for different manufacturers. The service platform can access transaction terminals produced by multiple manufacturers, and can implement online signatures for applications for multiple manufacturers. For different manufacturers, the manufacturer's signature data can be obtained based on the public key and private key pair uploaded by the manufacturer, as well as the unlocking code (PIN (Personal Identification Number) Unlocking Key, PUK) of the personal identification code uploaded by the manufacturer. Different manufacturers can correspond to different signature data.
[0076] For example, the service platform can receive applications uploaded by application developers. Through the digital certificate certification center (CA) service, the service platform generates the CA certificate of the application developer based on the public key of the application developer. When the service platform receives the application uploaded by the application developer through the developer center, the service platform automatically verifies the signature information of the application developer in the application package (APK) of the application to check the validity and legality of the CA certificate of the application developer.
[0077] Exemplarily, the service platform can also provide an online signature service based on the application market level, and can generate signature data of applications in the application market, for example, the signature data can be a code signing certificate PVK. The service platform can send the signature data to the client application of the transaction terminal. The signature data is used to instruct the transaction terminal to assemble the installation package of the application with the signature data.
[0078] S202: Determine, according to the identifier, an installation package of the application to be installed corresponding to the download request.
[0079] In some embodiments, the service platform may determine the installation package of the application to be installed corresponding to the download request according to the identifier of the application to be installed in the download request.
[0080] The application to be installed may be an application that has not been installed in the transaction terminal or an application of a new version to be updated corresponding to an installed application.
[0081] For example, the service platform includes installation packages corresponding to applications developed by third-party developers or applications in the application market; the installation package can be an installation package of a newly developed application or an installation package of an updated version of an existing application. The service platform locates the installation package corresponding to the application to be installed, that is, the original package of the application, according to the identifier in the download request.
[0082] S203: Acquire signature data related to the installation package, and send the installation package and the signature data to the transaction terminal.
[0083] The signature data and the installation package are used to instruct the transaction terminal to package and combine the installation package and the signature data to obtain a signed application package, and to install the installation package after the signed application package is verified.
[0084] In some embodiments, when the application to be installed is uploaded to the service platform, the service platform has generated relevant signature data for the application; when the transaction terminal needs to download the application to be installed, the service platform regenerates the signature data of the application to be installed based on the transaction terminal requesting the download. Therefore, the service platform will obtain all signature data related to the application to be installed and send all signature data to the transaction terminal requesting the download.
[0085] In some embodiments, the signature data includes a manufacturer signature file and an agent signature file; before obtaining the signature data related to the installation package, the method further includes:
[0086] Based on the identification of the application to be installed, the application to be installed is signed using the manufacturer's private key to generate the manufacturer's signature file associated with the application to be installed; according to the agent information in the download request, the application to be installed is signed using the agent's private key to generate the agent's signature file associated with the application to be installed.
[0087] Exemplarily, after receiving the uploaded application, the service platform reviews the application package of the application and verifies the signature information of the application developer in the application package; after the review and verification are passed, the service platform uses the previously stored manufacturer's private key to sign the application package (or installation package) and generate a manufacturer signature file S1. The manufacturer signature file is to prevent the manufacturer's machine (transaction terminal) from installing other applications at will. The application must contain the manufacturer's private key signature before it can be installed. Each transaction terminal comes with a manufacturer certificate when it leaves the factory, which is used to verify the manufacturer's signature.
[0088] Exemplarily, when the service platform receives a download request, after determining the installation package of the application to be installed, it can also determine the agent to which the transaction terminal belongs based on the agent information in the download request. The service platform signs the application package online according to the stored agent private key corresponding to the agent, and generates an agent signature file S2. The agent signature file can ensure that applications between different agents cannot be installed on each other. If different agents use machines from the same manufacturer, if there is only a manufacturer signature file, it cannot be guaranteed that applications between different agents cannot be installed on each other. This can improve the security and reliability of installing applications between different agents.
[0089] In some embodiments, the service needs to maintain the original installation package (or application package) of each application to be installed, as well as different signature data, and can dynamically switch the signature data at any time.
[0090] Exemplarily, the service platform may receive signature data of a custom signature input by an administrator of the web page through general settings, or signature data input through a global signature mechanism.
[0091] Among them, based on the signature mechanism of custom signature, the service platform needs to receive the public key encryption standard (Public-Key Cryptography Standards12, P12) file uploaded by the administrator, such as Figure 3 The display interface diagram of the service platform shown in FIG. Figure 3 As shown, after the service platform turns on the custom signature mode, it can select the signature mechanism, such as the signature server corresponding to PAX. In this custom signature mode, the service platform can receive the signature certificate P12 file; since the P12 file is a personal key, a password is required to open the file, so the interface also includes a control for entering the password of the P12 file.
[0092] Exemplarily, the Uniform Resource Locator (URL) of the remote API called by the signature server corresponding to PAX when signing; wherein the public certificate file of the signature server can be used to authenticate the signature server, and the certificate can be uploaded selectively.
[0093] Exemplarily, the display interface of the service platform also includes an upload control for the unlocking password PUK corresponding to the personal identification code of each manufacturer, such as the PUK codes used by manufacturers such as Yanghao, PAXBPS and PAX. After receiving the PUK code corresponding to the manufacturer, the service platform verifies the legitimacy of the PUK code.
[0094] It should be noted that before the service platform approves or allows the administrator to subscribe to an application, it is necessary to first configure the signature service based on the prompt control of the display interface of the service platform. After receiving the above configuration information, the service platform implements an online signing mechanism for the uploaded application based on the configuration information.
[0095] In addition, the service platform receives an instruction from the administrator to change the signature based on the general settings (for example, through Figure 3 After receiving the change instruction from the reset control of the interface), the signature data can be regenerated, and the corresponding market program file (such as Android APK (AndroidPackage)) can be re-signed, and the online signing of the application is performed asynchronously. It should be noted that the service platform also has a whitelist mechanism for uploaded applications; when changing the signature data, the applications in the whitelist will not be signed.
[0096] like Figure 4 As shown, the implementation flow diagram of the application signature method provided in the embodiment of the present application is as follows. The execution subject of the method may be Figure 1 The transaction terminal 20 in the system shown in FIG. The parts of the method that are the same as the implementation principles of the above embodiment are not repeated here. Figure 4 The method may include the following steps:
[0097] S401: Send a download request to a service platform, where the download request includes an identifier of an application to be installed.
[0098] In some embodiments, when the transaction terminal needs to install a new application or an installed application needs to be updated, it can receive an instruction input by the user by clicking a download control or an upgrade control. Based on the instruction, the transaction terminal sends a download request to the service platform.
[0099] Exemplarily, the transaction terminal may provide a client application for the user to log in. After receiving the installation or upgrade instructions input by the user based on the client application, the transaction terminal may run the client application to manage the applications on the transaction terminal, such as interacting with the service platform and downloading applications to be installed.
[0100] In some embodiments, the download request also includes agent information to which the transaction terminal belongs; after sending the download request to the service platform, the method further includes: receiving an agent certificate sent by the service platform based on the agent information.
[0101] The agent certificate is obtained by signing the agent public key with the manufacturer's private key, and the agent public key is generated by the service platform for the agent.
[0102] Exemplarily, the service platform generates a pair of private key and public key corresponding to each agent, signs the public key with the manufacturer's private key, and obtains an agent certificate; the transaction terminal receives the agent certificate sent by the service platform.
[0103] S402: Receive the installation package and signature data of the to-be-installed package application corresponding to the download request and sent by the service platform based on the identifier.
[0104] In some embodiments, the transaction terminal may receive all signature data related to the application to be installed sent by the service platform.
[0105] S403, packaging and combining the signature data and the installation package to obtain a signed application package.
[0106] S404: Verify the signature of the signed application package, and install the installation package after the signature verification passes.
[0107] In some embodiments, the signature data includes a manufacturer signature file and an agent signature file; and verifying the signature of the signed application package includes:
[0108] The manufacturer's signature file is verified using the manufacturer's certificate. If the verification passes, it is determined that the installation package contains the manufacturer's signature; the agent certificate is verified using the manufacturer's certificate that has passed the verification. If the verification passes, it is determined that the agent certificate is obtained based on the manufacturer's private key signature; the agent signature file is verified using the agent certificate that has passed the verification. If the verification passes, it is determined that the agent signature file is obtained based on the agent's private key signature.
[0109] Exemplarily, when the transaction terminal downloads the application, it will obtain the original package of the application, the manufacturer's signature file S1 and the agent's signature file S2 provided by the service platform. After obtaining these three files, the transaction terminal will repackage the three files to generate a signed application package. Then, the transaction terminal verifies S1 through the manufacturer's certificate to ensure that the application contains the signature of the manufacturer's private key. The transaction terminal comes with its own manufacturer's certificate, and verifies the agent's certificate through the manufacturer's certificate to ensure that the agent's certificate is issued by the manufacturer's private key. The transaction terminal uses the agent's certificate to verify S2 to ensure that S2 is issued by the agent's private key. After all verifications are completed, it can be ensured that the application to be installed can be installed and cannot be installed on other agents' transaction terminals.
[0110] like Figure 5 As shown, a schematic diagram of the interactive process of the application signing method provided in an embodiment of the present application is provided. The principle of the implementation process is the same as that of the above embodiment and will not be repeated here.
[0111] like Figure 5As shown, the interactive process diagram may include the following steps:
[0112] 1. The trading terminal sends a download request to the service platform;
[0113] 2. The service platform determines the installation package of the application to be installed corresponding to the download request according to the identifier in the download request;
[0114] 3. The service platform obtains the signature data associated with the installation package;
[0115] 4. The service platform sends the installation package and signature data to the transaction terminal;
[0116] 5. The transaction terminal packages and combines the installation package and the signature data to obtain a signed application package, and installs the installation package after the signed application package is verified.
[0117] Through the embodiments of the present application, the original transaction status only belongs to the business logic of the payment application itself, and other applications are invisible. The transaction status of the payment application can be known to the client managing the transaction terminal before the application is upgraded. The traditional application management platform does not consider whether the application itself is in an idle state when upgrading the application; thus, the loss of transaction data due to the upgrade can be avoided.
[0118] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0119] Corresponding to the application signing method described in the above embodiment, the embodiment of the present application provides an application signing device. For the sake of convenience, only the parts related to the embodiment of the present application are described.
[0120] The device includes:
[0121] A receiving unit, configured to receive a download request sent by a transaction terminal, wherein the download request includes an identifier of an application to be installed;
[0122] A processing unit, configured to determine, according to the identifier, an installation package of the application to be installed corresponding to the download request;
[0123] A signature unit, used to obtain signature data related to the installation package, and send the installation package and the signature data to the transaction terminal;
[0124] The signature data and the installation package are used to instruct the transaction terminal to package and combine the installation package and the signature data to obtain a signed application package, and to install the installation package after the signed application package is verified.
[0125] Corresponding to the application signing method described in the above embodiment, the application signing device provided in the embodiment of the present application, for the sake of convenience, only describes the parts related to the embodiment of the present application.
[0126] The device includes:
[0127] A sending unit, configured to send a download request to the service platform, wherein the download request includes an identifier of the application to be installed;
[0128] A receiving unit, configured to receive the installation package and signature data of the package application to be installed corresponding to the download request and sent by the service platform based on the identifier;
[0129] A processing unit, used to package and combine the signature data and the installation package to obtain a signed application package;
[0130] The verification unit is used to verify the signature of the signed application package and install the installation package after the signature verification passes.
[0131] It should be noted that the information interaction, execution process, etc. between the above-mentioned devices / units are based on the same concept as the method embodiment of the present application. Their specific functions and technical effects can be found in the method embodiment part and will not be repeated here.
[0132] The technicians in the relevant field can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In practical applications, the above-mentioned function allocation can be completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated in a processing unit, or each unit can exist physically separately, or two or more units can be integrated in one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of this application. The specific working process of the units and modules in the above-mentioned system can refer to the corresponding process in the aforementioned method embodiment, which will not be repeated here.
[0133] The embodiment of the present application also provides an application signature system, the system comprising a service platform and a transaction terminal;
[0134] The transaction terminal is used to send a download request to the service platform, wherein the download request includes an identifier of the application to be installed;
[0135] The service platform is used to receive the download request and determine the installation package of the application to be installed corresponding to the download request according to the identifier;
[0136] The service platform is further configured to obtain signature data associated with the installation package and send the installation package and the signature data to the transaction terminal;
[0137] The transaction terminal is further configured to receive the installation package and the signature data, package and combine the installation package and the signature data to obtain a signed application package, and install the installation package after passing the verification of the signed application package.
[0138] An embodiment of the present application further provides a computer-readable storage medium storing a computer program, which when executed by a processor, can implement the steps in the above method embodiments.
[0139] An embodiment of the present application provides a computer program product, which when running on a mobile terminal, enables the mobile terminal to implement the steps in the above method embodiments when executed.
[0140] Figure 6 It is a schematic structural diagram of a service platform 6 provided in an embodiment of the present application. As Figure 6 shown, the service platform 6 in this embodiment includes at least one processor 60 ( Figure 6 only one is shown in the figure), a memory 61, and a computer program 62 stored in the memory 61 and executable on the at least one processor 60. When the processor 60 executes the computer program 62, the steps in the above embodiment are implemented.
[0141] The service platform 6 may be a computing device such as a desktop computer, a notebook, a palm computer, or a cloud server. The service platform 6 may include, but is not limited to, a processor 60 and a memory 61. Those skilled in the art can understand that Figure 6 merely examples of the service platform 6, which do not constitute a limitation to the service platform 6. It may include more or fewer components than shown in the figure, or combine some components, or different components. For example, it may further include input / output devices, network access devices, etc.
[0142] The processor 60 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc.
[0143] In some embodiments, the memory 61 may be an internal storage unit of the service platform 6, such as a hard disk or memory of the service platform 6. In other embodiments, the memory 61 may also be an external storage device of the service platform 6, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the service platform 6. Further, the memory 61 may also include both an internal storage unit and an external storage device of the service platform 6. The memory 61 is used to store an operating system, an application program, a boot loader (BootLoader), data, and other programs, such as the program code of the computer program. The memory 61 may also be used to temporarily store data that has been output or is to be output.
[0144] Figure 7 This is a schematic diagram of the structure of a transaction terminal 7 provided in an embodiment of the present application. Figure 7 As shown, the transaction terminal 7 of this embodiment includes: at least one processor 70 ( Figure 7 Only one is shown in the figure), a memory 71, and a computer program 72 stored in the memory 71 and executable on the at least one processor 70, wherein the processor 70 implements the steps in the above-mentioned embodiments when executing the computer program 72.
[0145] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the processes in the above-mentioned embodiment method, which can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium, and the computer program can implement the steps of the above-mentioned various method embodiments when executed by the processor. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium can at least include: any entity or device that can carry the computer program code to the camera / terminal device, recording medium, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, RandomAccess Memory), electric carrier signal, telecommunication signal and software distribution medium. For example, a USB flash drive, a mobile hard disk, a magnetic disk or an optical disk. In some jurisdictions, according to legislation and patent practice, computer-readable media cannot be electric carrier signals and telecommunication signals.
[0146] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0147] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0148] In the embodiments provided in the present application, it should be understood that the disclosed devices / network equipment and methods can be implemented in other ways. For example, the device / network equipment embodiments described above are merely schematic. For example, the division of the modules or units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0149] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0150] The embodiments described above are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, a person skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. Such modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.
Claims
1. An application signing method, It is characterized in that The method comprises: The transaction terminal sends a download request to the service platform, wherein the download request includes an identifier of the application to be installed; The service platform receives the download request, and determines the installation package of the application to be installed corresponding to the download request according to the identifier; The service platform obtains signature data associated with the installation package, and sends the installation package and the signature data to the transaction terminal; The transaction terminal receives the installation package and the signature data, packages and combines the installation package and the signature data to obtain a signed application package, and installs the installation package after the signed application package is verified; The signature data includes a manufacturer signature file and an agent signature file; the signature verification of the signature application package includes: The manufacturer's signature file is verified using the manufacturer's certificate, the agent's certificate is verified using the verified manufacturer's certificate, and the agent's signature file is verified using the verified agent's certificate; the agent's certificate is obtained by signing the agent's public key with the manufacturer's private key, and the agent's public key is generated by the service platform for the agent.
2. An application signing method, It is characterized in that Applied to a service platform, the method comprises: Receiving a download request sent by a transaction terminal, wherein the download request includes an identifier of an application to be installed; Determining, according to the identifier, the installation package of the application to be installed corresponding to the download request; Acquire signature data associated with the installation package, and send the installation package and the signature data to the transaction terminal; The signature data and the installation package are used to instruct the transaction terminal to package and combine the installation package and the signature data to obtain a signed application package, and install the installation package after the signature application package is verified; the signature data includes a manufacturer signature file and an agent signature file; the signature verification of the signed application package includes: The manufacturer's signature file is verified using the manufacturer's certificate, the agent's certificate is verified using the verified manufacturer's certificate, and the agent's signature file is verified using the verified agent's certificate; the agent's certificate is obtained by signing the agent's public key with the manufacturer's private key, and the agent's public key is generated by the service platform for the agent.
3. The method according to claim 2, It is characterized in that The download request also includes information about the agent to which the transaction terminal belongs; after receiving the download request sent by the transaction terminal, the method further includes: According to the agent information, an agent certificate is sent to the transaction terminal.
4. The method according to claim 2 or 3, It is characterized in that Before acquiring the signature data associated with the installation package, the method further includes: Based on the identifier of the application to be installed, use the manufacturer's private key to sign the application to be installed, and generate the manufacturer's signature file associated with the application to be installed; According to the agent information in the download request, the application to be installed is signed using the agent private key to generate the agent signature file associated with the application to be installed.
5. A method for signing an application, It is characterized in that Applied to a transaction terminal, the method comprises: Sending a download request to the service platform, wherein the download request includes an identifier of the application to be installed; Receiving the installation package of the application to be installed corresponding to the download request and the signature data associated with the installation package, which is sent by the service platform based on the identifier; Packaging and combining the signature data and the installation package to obtain a signed application package; Verify the signature of the signed application package, and install the installation package after the signature verification passes; The signature data includes a manufacturer signature file and an agent signature file; the signature application package verification includes: The manufacturer's signature file is verified using the manufacturer's certificate, the agent's certificate is verified using the verified manufacturer's certificate, and the agent's signature file is verified using the verified agent's certificate; the agent's certificate is obtained by signing the agent's public key with the manufacturer's private key, and the agent's public key is generated by the service platform for the agent.
6. The method according to claim 5, It is characterized in that The download request also includes information about the agent to which the transaction terminal belongs; After sending the download request to the service platform, the method further includes: Receiving an agent certificate sent by the service platform based on the agent information; The agent certificate is obtained by signing the agent public key with the manufacturer's private key, and the agent public key is generated by the service platform for the agent.
7. The method according to claim 5, It is characterized in that The signature data includes a manufacturer signature file and an agent signature file; the method further includes: If the manufacturer's signature file is verified using the manufacturer's certificate, it is determined that the installation package contains the manufacturer's signature; If the agent certificate is verified by using the manufacturer certificate that has passed the signature verification, it is determined that the agent certificate is obtained based on the manufacturer private key signature; If the agent signature file is verified by using the agent certificate that has passed the signature verification, it is determined that the agent signature file is obtained based on the agent private key signature.
8. An application signature system, It is characterized in that The system includes a service platform and a transaction terminal; The transaction terminal is used to send a download request to the service platform, wherein the download request includes an identifier of the application to be installed; The service platform is used to receive the download request and determine the installation package of the application to be installed corresponding to the download request according to the identifier; The service platform is further used to obtain signature data associated with the installation package, and send the installation package and the signature data to the transaction terminal; The transaction terminal is further used to receive the installation package and the signature data, package and combine the installation package and the signature data to obtain a signed application package, and install the installation package after the signature of the signed application package is verified; the signature data includes a manufacturer signature file and an agent signature file; The signature verification of the signed application package includes: using the manufacturer's certificate to verify the manufacturer's signature file, using the manufacturer's certificate that has passed the verification to verify the agent's certificate, and using the agent's certificate that has passed the verification to verify the agent's signature file; the agent certificate is obtained by signing the agent's public key with the manufacturer's private key, and the agent public key is generated by the service platform for the agent.
9. A service platform, It is characterized in that The service platform includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the method according to any one of claims 2 to 4 when executing the computer program.
10. A transaction terminal, It is characterized in that The transaction terminal comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the method according to any one of claims 5 to 7 when executing the computer program.
Citation Information
Patent Citations
Multi-party authorized APK signature method and system
CN103944903A