Method and system for controlling application installation permission in device

By applying a multi-level certificate system and signature tools, unified management of application installation permissions for different entities on POS devices is achieved, solving the problems of management complexity and high cost in existing technologies, and providing flexible and secure access control.

CN114491487BActive Publication Date: 2025-12-19SHANGHAI SUMI TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210100301.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-27
Publication Date
2025-12-19
Estimated Expiration
2042-01-27

AI Technical Summary

Technical Problem

In devices shared or jointly operated by multiple entities, how to achieve unified and differentiated management of application installation permissions for different entities, especially in complex POS device scenarios, is a challenge. Existing technologies lack effective control solutions, leading to high maintenance costs.

Method used

It adopts a multi-level certificate system with root certificates and secondary certificates, and issues identity verification certificates and application verification certificates through signing tools. It controls the installation permissions of applications according to the requests of different subjects, supports the issuance and revocation of multi-level certificates, and ensures security and flexibility.

Benefits of technology

It provides a unified application installation permission differentiation management solution to meet the needs of different users, improve management efficiency, reduce maintenance costs, and adapt to complex operating models while ensuring security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114491487B_ABST
    Figure CN114491487B_ABST
Patent Text Reader

Abstract

The application provides a control method and a control system for application installation permission in a device, wherein the device has a root certificate or a root certificate and a secondary certificate issued according to the root certificate. The control method comprises the following steps: a signing tool issues an identity signature verification certificate corresponding to a first subject to a first terminal according to the root certificate or the secondary certificate in response to a request from the first terminal associated with the first subject; and based on an applied operation, the signing tool issues an application signature verification certificate to the first terminal or a second terminal associated with a second subject according to the identity signature verification certificate, wherein the first terminal or the second terminal with the application signature verification certificate is allowed to install a signed application in the device through the application signature verification certificate. The control method and the control system can provide a unified installation permission differentiation management scheme and meet different requirements of different use subjects in the same device.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application mainly relates to the field of information security, and in particular to a method and system for controlling application installation permissions in a device. BACKGROUND

[0002] For some multi-subject shared or co-operated devices, how to control the use permissions of different subjects for the same device is a problem that needs to be considered in the process of device use. Taking the most common POS (Point of Sale) device as an example, in the actual application scenario of the POS device, there are complex combination scenarios between the purchase user of the POS device and the operator of the POS device, for example:

[0003] Scenario one: the purchase user is responsible for the POS operation, and the purchase user has the control right of the application installation permissions of the POS;

[0004] Scenario two: the purchase user has multiple operation partners, and each operation partner has the control right of the application installation permissions of the respective POS;

[0005] Scenario three: the purchase user has multiple operation partners, and each operation partner has the control right of the application installation permissions of the respective POS, and all of them allow the installation of the application program of the purchase user;

[0006] Scenario four: two partners jointly operate the POS, and both of them have the control right of the application installation permissions of the POS, but the application market and the application signing tool are independent of each other;

[0007]

[0008] It can be found from the above enumeration that it is difficult for the purchase user or the operator of the POS device to uniformly control the installation permissions of the application program in the POS device. On the other hand, for the POS manufacturer, since each purchase user can have the above different combination scenarios, it further evolves into thousands of application scenarios with different needs. On this basis, for the POS device manufacturer, there are often multiple POS device models. Under such demand, if the above requirements are realized by customizing the POS program, the workload is terrible, and the maintenance cost rises exponentially due to thousands of complex combinations. Therefore, there is still a lack of an application program installation permission control scheme that can solve the complex combination demand scenarios. SUMMARY

[0009] The technical problem to be solved by the present application is to provide a method and system for controlling application installation permissions in a device, which can provide a unified installation permission differentiation management scheme to meet the different needs of different use subjects in the same device.

[0010] To solve the above technical problems, the present application provides a control method of application installation permission in a device having a root certificate, or the root certificate and a secondary certificate issued according to the root certificate, comprising the following steps:

[0011] The signing tool issues an identity signature verification certificate corresponding to the first subject to the first terminal according to the root certificate or the secondary certificate in response to a request from the first terminal associated with the unique first subject; and

[0012] Based on the application operation, the signing tool issues an application signature verification certificate to the first terminal or a second terminal associated with a unique second subject according to the identity signature verification certificate, wherein the first terminal or the second terminal having the application signature verification certificate is allowed to install a signed application in the device through the application signature verification certificate.

[0013] In an embodiment of the present application, if the signing tool issues the application signature verification certificate to the first terminal associated with the first subject, the control method further comprises issuing an affiliated signature verification certificate to the second terminal associated with the second subject, or the second terminal and one or more third terminals associated with one or more third subjects according to the application signature verification certificate based on the application operation of the first subject, wherein the second terminal, or the second terminal and the third terminals are also adapted to install a signed application in the device through the affiliated signature verification certificate while the first terminal is allowed to install a signed application in the device through the application signature verification certificate.

[0014] In an embodiment of the present application, if the signing tool issues the application signature verification certificate to the second terminal associated with the second subject, the control method further comprises issuing an affiliated signature verification certificate to one or more third terminals associated with one or more third subjects according to the application signature verification certificate based on the application operation of the second subject, wherein the one or more third terminals are also allowed to install a signed application in the device through the affiliated signature verification certificate while the second terminal is allowed to install a signed application in the device through the application signature verification certificate.

[0015] In an embodiment of the present application, it further comprises configuring the root certificate, or the root certificate and a secondary certificate issued according to the root certificate in the device by a zeroth terminal associated with a zeroth subject, and configuring an initial signature verification certificate issued according to the root certificate or the secondary certificate in the device, wherein the zeroth terminal is allowed to install a signed application in the device before leaving the factory through the initial signature verification certificate.

[0016] In an embodiment of the application, the identity signing certificate is invalidated after the application signing certificate is issued.

[0017] In an embodiment of the application, the initial signing certificate is invalidated after the identity signing certificate is issued, and the identity signing certificate is invalidated after the application signing certificate is issued.

[0018] In an embodiment of the application, if the signing tool issues the application signing certificate to the second terminal associated with the second principal, before the identity signing certificate is issued to the first terminal, further comprising deploying a first signing tool in the first terminal, the first terminal being adapted to manage keys for signing the application signing certificate by the first signing tool, and the second terminal also being adapted to manage keys for signing the application and the dependent signing certificate by the first signing tool.

[0019] In an embodiment of the application, if the signing tool issues the application signing certificate to the second terminal associated with the second principal, further comprising:

[0020] before the identity signing certificate is issued to the first terminal, further comprising deploying a first signing tool in the first terminal, the first terminal being adapted to manage keys for signing the application signing certificate by the first signing tool; and

[0021] before the application signing certificate is issued to the second terminal, further comprising deploying a second signing tool in the second terminal, the second terminal being adapted to manage keys for signing the application and the dependent signing certificate by the second signing tool.

[0022] In an embodiment of the application, further comprising installing a signed application in the device by the first terminal or the second terminal possessing the application signing certificate, through the application signing certificate, specifically comprising the following steps:

[0023] submitting a file to be signed to the signing tool by the first terminal or the second terminal;

[0024] signing the file to be signed by the signing tool using a key, wherein the file to be signed contains information of an application to be installed;

[0025] returning the signed file to the first terminal or the second terminal;

[0026] The first terminal or the second terminal uploads the application signing certificate and the signed file to a network, and the device downloads the application signing certificate and the signed file from the network; and

[0027] The application signing certificate is installed in the device, the signed file is verified for legality by using the application signing certificate, and if the signed file is legal, the application included in the signed file is installed in the device.

[0028] To solve the above technical problems, another aspect of the present application also proposes a system for controlling application installation authority in a device, the device having a root certificate, or the root certificate and a secondary certificate issued according to the root certificate, comprising: a signing tool, a first terminal associated with a unique first subject, or the first terminal and a second terminal associated with a unique second subject, wherein the signing tool is configured to issue an identity signing certificate corresponding to the first subject to the first terminal according to the root certificate or the secondary certificate in response to a request from the first terminal; and the signing tool is further configured to issue an application signing certificate to the first terminal or the second terminal associated with a unique second subject according to the identity signing certificate based on an application operation, wherein the first terminal or the second terminal having the application signing certificate is allowed to install a signed application in the device through the application signing certificate.

[0029] In an embodiment of the present application, one or more third terminals associated with a third subject are further included, wherein if the signing tool issues the application signing certificate to the first terminal associated with the first subject, the signing tool is further configured to issue a subordinate signing certificate to the second terminal associated with the second subject, or the second terminal and one or more third terminals associated with one or more third subjects according to the application signing certificate based on an application operation of the first subject, wherein the second terminal, or the second terminal and the third terminal are also adapted to install a signed application in the device through the subordinate signing certificate while the first terminal is allowed to install a signed application in the device through the application signing certificate.

[0030] If the signing tool issues the application signature certificate to the second terminal associated with the second principal, the signing tool is further configured to issue, based on an application operation of the second principal, the subsidiary signature certificate to one or more third terminals associated with one or more third principals according to the application signature certificate, wherein the one or more third terminals are allowed to install the signed application in the device through the subsidiary signature certificate at the same time that the second terminal is allowed to install the signed application in the device through the application signature certificate.

[0031] In an embodiment of the present application, a zeroth terminal associated with a zeroth principal is further included, the zeroth terminal is configured to configure the root certificate, or the root certificate and a secondary certificate issued according to the root certificate, in the device, and the zeroth terminal is further configured not to configure an initial signature certificate issued according to the root certificate or the secondary certificate in the device, and the zeroth terminal is allowed to install the signed application in the device before leaving the factory through the initial signature certificate. Compared with the prior art, the present application has the following advantages:

[0032] The method and system for controlling application installation permission in the device of the present application provide a unified application installation permission differentiation management scheme for actual purchase users and other operators and other multi-principals, and meet the complex installation permission control requirements of device manufacturers, purchase customers, and operators according to different actual operation modes. On the other hand, the multi-level certificate and application signature mode provided by the scheme of the present application are safe and reliable, and the signing tool is easy to install and use. On the basis of ensuring safety, the maintenance cost is reduced, and the management efficiency is improved. BRIEF DESCRIPTION OF DRAWINGS

[0033] The accompanying drawings are included to provide a further understanding of the present application, and are incorporated in and constitute a part of this application, illustrate embodiments of the present application, and together with the description serve to explain the principle of the present application. In the drawings:

[0034] Figure 1 is a flow diagram of a method for controlling application installation permission in a device according to an embodiment of the present application;

[0035] Figure 2 is a certificate hierarchy logic diagram in a method for controlling application installation permission in a device according to an embodiment of the present application;

[0036] Figure 3 is a conceptual diagram of the implementation principle of a method for controlling application installation permission in a device according to an embodiment of the present application; and

[0037] Figure 4is a system block diagram of a control system of application installation permission in a device according to an embodiment of the present application. DETAILED DESCRIPTION

[0038] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed to be used in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some examples or embodiments of the present application, and for those skilled in the art, the present application can also be applied to other similar scenarios without creative labor on the basis of the drawings. Unless the context clearly indicates otherwise or otherwise stated, the same reference numbers in the drawings represent the same structures or operations.

[0039] As shown in the present application and claims, unless the context clearly indicates otherwise or otherwise stated, the words "one", "a", "an", and / or "the" do not specifically refer to the singular, but can also include the plural. Generally speaking, the terms "comprise" and "include" only indicate the inclusion of the steps and elements explicitly identified, and these steps and elements do not constitute an exclusive list, and the method or device can also include other steps or elements.

[0040] Unless otherwise specifically stated, the relative arrangement of the components and steps, numerical expressions, and numerical values set forth in these embodiments do not limit the scope of the present application. At the same time, it should be understood that the sizes of the various parts shown in the drawings are not drawn in proportion to the actual proportions. The technology, methods and devices known to those skilled in the relevant art can not be discussed in detail, but under appropriate circumstances, the technology, methods and devices should be considered as part of the authorized description. In all examples shown and discussed here, any specific value should be interpreted as merely exemplary, and not as a limitation. Therefore, other examples of exemplary embodiments can have different values. It should be noted that similar reference numbers and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further discussed in subsequent drawings.

[0041] In the description of the present application, it should be understood that the orientation words such as "front, back, up, down, left, right", "horizontal, vertical, perpendicular, horizontal" and "top, bottom" and the like indicate the orientation or positional relationship shown in the drawings, and are only for the convenience of describing the present application and simplifying the description, and in the absence of contrary indications, these orientation words do not indicate and imply that the indicated device or element must have a particular orientation or be constructed and operated in a particular orientation, and therefore cannot be understood as limiting the scope of protection of the present application; the orientation words "inner, outer" refer to the inner and outer relative to the contour of the parts themselves.

[0042] For purposes of the description hereinafter, spatially relative terms, such as "above", "below", "up", "down", "between", "within", "left", "right", "rear", "front", "upper", "lower", "horizontal", "vertical", "above", "below", "on", "under", "in", "above", "below", "over", "under" and the like, can be used herein for ease of description to describe one element's or feature's relation to another element(s) or feature(s) as illustrated in the figures. It will be understood that the spatially relative terms are intended to encompass different orientations of the device in use or operation in addition to the orientations depicted in the figures. For example, if a device in the figures is inverted, elements described as "above" or "over" other elements or features would then be oriented "below" or "under" the other elements or features. Thus, the exemplary term "above" can encompass both an orientation of above and below. The device can be otherwise oriented (rotated 90 degrees or at other orientations) and the spatially relative descriptors used herein interpreted accordingly. The terms "first", "second", "third", etc. can be used herein to describe various elements, components, regions and / or sections. These designations are merely used for the convenience of description and do not have special meanings. Thus, the terms "first", "second", "third", etc. cannot be interpreted as limiting the scope of the present application. In addition, although the terms used in the present application are selected from generally known and used terms, some of the terms mentioned in the description of the present application can be completely invented by the applicant or used by the public to date, and thus, their detailed meanings can be determined by the corresponding portions in the description of the present application.

[0043] In addition, it should be noted that the use of "first", "second", etc. words to define parts is merely for the convenience of distinguishing the corresponding parts, and the above words have no special meanings unless otherwise stated. Therefore, it cannot be understood as limiting the scope of the present application. In addition, although the terms used in the present application are selected from generally known and used terms, some of the terms mentioned in the description of the present application can be completely invented by the applicant or used by the public to date, and thus, their detailed meanings can be determined by the corresponding portions in the description of the present application. In addition, the present application is required to be understood not only by the terms used, but also by the meanings contained in each term.

[0044] An embodiment of the present application refers to Figure 1 A control method 10 of application installation authority in a device (hereinafter referred to as "control method 10") is proposed. The control method 10 can provide a unified installation authority differentiation management scheme to meet different needs of different use subjects in the same device.

[0045] In the present application Figure 1 Flowcharts are used herein to illustrate the operations performed by the system according to the embodiments of the present application. It should be understood that the preceding or subsequent operations are not necessarily performed in sequence. On the contrary, various steps can be processed in reverse order or simultaneously. Meanwhile, other operations can be added to these processes, or one or more steps of operations can be removed from these processes.

[0046] The following is based on Figure 1The control method 10 of the present application is described in detail. First, in the device involved in the control method 10, there is a root certificate, or a root certificate and a secondary certificate issued according to the root certificate. This means that if there is only a root certificate, the next level of certificate is issued by the root certificate according to the steps below, and if there is a root certificate and a secondary certificate issued according to the root certificate in the device, the next level of certificate is issued by the secondary certificate according to the steps below, and in such a setting, the security of the root certificate can be better protected. On the other hand, the root certificate or the secondary certificate can be built into the firmware program of the device before it leaves the factory, or installed before the steps of the control method 10 proposed below are required to be performed, which is not limited by the present application.

[0047] As shown in Figure 1 Step 11 is a signature tool that responds to a request from a first terminal associated with a unique first principal, and issues an identity signature certificate corresponding to the first principal to the first terminal according to the root certificate or the secondary certificate.

[0048] Step 12 is an application-based operation, and the signature tool issues an application signature certificate to the first terminal or a second terminal associated with a unique second principal according to the identity signature certificate. And the first terminal or the second terminal with the application signature certificate is allowed to install the signed application in the device through the application signature certificate.

[0049] In combination with the actual application scenario of the device, such as the POS device commonly seen in the market, the first principal in the above step 11 can be the actual purchase user of the POS device, as introduced in the background section above, the actual purchase user can also be the operator of the device, or can be assigned to other partners to operate the device simultaneously or independently, and thus the corresponding second principal can be the operating partner of the purchase user. In such a setting, as the actual purchase user (first principal) of the POS device, when there is a need to configure the application installation permission in the device, a request is sent to the signature tool in the terminal, and the signature tool issues an identity signature certificate corresponding to the first principal to the first terminal according to the root certificate or the secondary certificate, which means that the first principal is given the control right of the installation permission at this time. For example, using the secondary certificate to issue the identity signature certificate, the identity signature certificate can be signed using the private key of the secondary certificate to generate the identity signature certificate, which contains the public key matching the private key used by the secondary certificate for signing.

[0050] Further, the first principal who has obtained the identity verification certificate has the control right of the next level certificate issuance. At this time, the first principal can issue application verification certificates to himself or other principals through the signature tool according to the needs of the actual application scene. That is, the application verification certificate is issued to the first terminal or the second terminal associated with the unique second principal in step 12.

[0051] Preferably, in order to better realize the accuracy and security of the control method 10 for the device application installation permission control, in some embodiments of the present application, after the application verification certificate is issued in step 12, a step of invalidating the identity verification certificate is further included. This means that after this, only the principal with the application verification certificate can be allowed to install the application in the device through the terminal where he is located. It can be understood that such a configuration is more suitable for application scenarios where the direct purchaser of the device and the subsequent operator (the principal who needs to install the application in the device) are relatively independent. When the purchase user (the first principal) issues the application verification certificate to the operator (the second principal) through his identity (reflected as having the identity verification certificate), the identity verification certificate owned by the purchase user is invalidated, which ensures that the purchase user no longer has the right to issue a unified application verification certificate to other principals when the device is actually used by the subsequent operator, thereby fundamentally guaranteeing the security of the device when used by the operator.

[0052] It should be noted that in steps 11 and 12, it is mentioned that the first principal and the second principal are each unique, which means that in the control method 10 of the present application, the number of principals with control rights for the same device is determined and unique. Such a setting can better protect the security and controllability of the device when the use permission is configured, for devices with relatively high security requirements. As mentioned above, the control method 10 with steps 11 and 12 can already meet the needs of device control permissions in most application scenarios for devices such as common POS machines.

[0053] However, although it has high security, it can be understood that it will also bring certain limitations. Based on this, in some preferred embodiments of the present application, on the basis of the above-mentioned only first principal or second principal, the configuration of the terminal corresponding to one or more third principals and the corresponding installation permission is further introduced.

[0054] Exemplarily, in some embodiments of the present application, if the signing tool issues the application signing certificate to the first terminal associated with the first principal, the control method further comprises, based on the application operation of the first principal, issuing, according to the application signing certificate, an affiliated signing certificate to the second terminal associated with the second principal, or the second terminal and one or more third terminals associated with one or more third principals, wherein, while the first terminal is allowed to install the signed application in the device through the application signing certificate, the second terminal, or the second terminal and the third terminals are also adapted to install the signed application in the device through the affiliated signing certificate. The following will make a detailed description of the configuration process.

[0055] First, in such embodiments, the holder of the application signing certificate is the first principal, which means that the direct purchaser of the device has the need to install the application in the device after purchasing the device, and therefore, after applying to the signing tool, the first terminal corresponding to the first principal has the right to install the application in the device. At this time, if the first principal wants to allow other operation partners to install the application in the device, it can apply to the signing tool again for an affiliated signing certificate and issue it to the second principal or one or more third principals other than the second principal. It can be understood that, in order to be consistent and complete with the scheme, the name of "second principal" is continued to be used here according to the above-mentioned embodiments with reference Figure 1 to. In fact, if the first terminal corresponding to the first principal has the application signing certificate at the same time, it can issue an affiliated signing certificate to any trusted principal other than the first principal, thereby further expanding the complex application scenarios applicable to the present scheme on the basis of the above-mentioned control method 10 with reference Figure 1 to, so as to obtain better universality. Exemplarily, in some embodiments of the present application, the number of principals holding the affiliated signing certificate is not more than 3 or not more than 5, and specific modifications can be made according to the changes in actual application scene requirements.

[0056] Similarly, if the signing tool issues the application signing certificate to the second terminal associated with the second principal, the control method further comprises, based on the application operation of the second principal, issuing, according to the application signing certificate, a subsidiary signing certificate to one or more third terminals associated with one or more third principals, wherein the one or more third terminals are allowed to install the signed application in the device through the subsidiary signing certificate at the same time that the second terminal is allowed to install the signed application in the device through the application signing certificate. This means that, when the direct purchaser of the device is not the principal who needs to install the application in the device, by applying for the signing tool to issue the application signing certificate to the second principal, the first principal transfers the control of the certificate issuance to the second principal, so that when the second principal has the need to license the installation of the application to other principals (operational partners) in the process of using the device, the subsidiary signing certificate can be issued to the other principals by applying, and thus a more complex application scenario is realized.

[0057] In order to better explain the above-mentioned certificate issuance logic, Figure 2 A logical diagram for issuing certificates to a principal with an identity signing certificate C1 and two devices 21 and 22 in an embodiment of the present application is shown. The exemplary certificate issuance logic is shown in the following table. Figure 2 The certificates of each level are described in order from top to bottom level as shown by the arrows.

[0058] 1) Root certificate: located at the top of the certificate chain, used to sign the lower level certificate, built into the firmware program of the device, and can be set to be non-deletable and shielded;

[0059] 2) Secondary certificate: issued by the root certificate private key, used to sign the lower level certificate, similar to the root certificate, the secondary certificate is built into the firmware program of the device, and can also be set to be non-deletable and shielded;

[0060] 3) Identity signing certificate C1: issued by the private key of the secondary certificate, used to sign the lower level certificate, according to the setting of the present application, only one C1 is allowed to exist in the same device;

[0061] 4) Application signing certificate C2: issued by the private key of C1, used to sign the lower level certificate and the application that the principal who owns C2 wants to install in the device; and

[0062] 5) Subsidiary signing certificate C2sub: issued by the private key of C2, used to sign the application that the principal who owns C2sub wants to install in the device.

[0063] According to Figure 2It can be seen that the first principal can deploy subordinate certificates in different devices, the same C1 private key can issue multiple C2s, but only one C2 is allowed to exist for the same device. Specifically, for device 21 and device 22, each has an independent C2, but both C2s can be issued by the same C1 corresponding to the first principal. On the other hand, there can be one or more C2s for the same device, and the present application does not limit this. The reasons for such settings and more details have been described in detail above and will not be repeated here.

[0064] By Figure 2 It can be clearly seen that the control method of the present application makes a detailed investigation and research on the specific scenarios of device use, and designs a certificate hierarchy as shown in Figure 2 which is suitable for various complex scenarios. While strictly ensuring security, the present application expands the feasibility of the prior art for multiple principal installation of application programs in the same device.

[0065] Further, in order to more comprehensively cover the different principal installation of application programs in the same device that may occur during the entire process from factory to use of the device, in some embodiments of the present application, the control method of the present application further comprises configuring a root certificate, or a root certificate and a secondary certificate issued according to the root certificate, in the device by a zero terminal associated with a zero principal, and configuring an initial signing certificate issued according to the root certificate or the secondary certificate in the device, and the zero terminal is allowed to install a signed application program in the device before factory by the initial signing certificate. For example, the above-mentioned zero principal can be a manufacturer of the device in some embodiments of the present application.

[0066] In order to better illustrate the principle logic of the present application in such embodiments, the following refers to Figure 3 for further explanation of the implementation principle of the embodiment with a zero principal, a first principal, a second principal and a third principal.

[0067] According to Figure 3 , according to the device from factory to use and different time nodes of use, it is explained in order from stages S1-S3. First, in stage S1, before the device is shipped, the root certificate and the secondary certificate are installed in the firmware program of the device by the zero terminal of the manufacturer. At the same time, considering the need of the manufacturer to install application programs in the device, in this stage S1, the manufacturer can apply for an initial signing certificate through the terminal thereof and install a signed application program in the device through the initial signing certificate. In order to better understand the present application, the device in stage S1 can also be considered as a "manufacturer mode". At this time, the installation permission of the application program in the device is controlled by the manufacturer.

[0068] Further, when the device is delivered to the purchasing user for use, if the user has a demand to install an application in the device at this time, it enters stage S2. As described above with reference to Figure 1 and Figure 2 The first subject (purchasing user) obtains the identity verification certificate C1 by applying, and is thus endowed with the function of issuing a next-level certificate (controlling the right to distribute the application installation right in the device). Since no step of installing an application in the device by a legal certificate is involved in this stage S2, stage S2 can be simply understood as an "intermediate mode", and its main role is to issue the identity verification certificate C1 to the purchasing user (i.e. the first subject) of the device to endow him with the installation right control. From this, the first subject can issue a next-level certificate to himself or other subjects according to the actual application scenario, thereby providing a legal and reliable channel for installing an application in the device.

[0069] Finally, in the actual use of installing an application in the device, according to different application scenarios, it can be divided into single-certificate mode and multi-certificate mode according to whether the subsidiary verification certificate C2sub is included. That is, if the first subject or the second subject who has the application verification certificate C2 wants to further issue a subsidiary verification certificate C2sub to other subjects (such as the third subject) in addition to himself, the device can be considered as a multi-certificate mode, otherwise it is a single-certificate mode. When the subject who has the application verification certificate C2 wants to recover the installation right of the device of other subjects, since the certificate level he has is higher than that of the subsidiary verification certificate C2sub, he can also revoke the issued C2sub, so that the device can be flexibly switched between single-certificate mode and multi-certificate mode.

[0070] Similarly, in order to better ensure the security of the installation right control of the device in the scheme with the zeroth subject, in such embodiments, the initial verification certificate is invalidated after issuing the identity verification certificate, and the identity verification certificate is invalidated after issuing the application verification certificate. Referring to Figure 3 That is, after entering stage S2 from stage S1, the initial verification certificate of the zeroth subject is invalidated, and after entering stage S3 from stage S2, the identity verification certificate C1 is also invalidated, and only the terminal of the subject who has the application verification certificate C2 and the subsidiary verification certificate C2sub has the qualification to legally install an application in the device.

[0071] From the above description, in the embodiment with the zeroth subject, the first subject, the second subject and the third subject, the control method of the present application can comprehensively cover the needs of different subjects to install application programs in the same device, the certificates of different levels are linked layer by layer, and different certificate use modes are flexibly converted according to different needs of users, which has high security, high reliability, and strong advantages in universality.

[0072] More specifically, with reference to Figure 3 , the signature tool of the present application has a complete account management system, and different subjects can have different signing and certificate issuing permissions. For example, in an embodiment of the present application, the C1 public key and private key are generated by the signature tool, the second-level certificate private key issues the C1 public key certificate, and the process is that the C1 public key is signed by the second-level certificate private key to generate the C1 public key certificate; the C2 public key and private key are generated by the signature tool, the C1 private key issues the C2 public key certificate, and the process is that the C2 public key is signed by the C1 private key in the signature tool to generate the C2 public key certificate; and the C2sub public key and private key are generated by the signature tool, the C2 private key issues the C2sub public key certificate, and the process is that the C2sub public key is signed by the C2 private key in the FSK to generate the C2sub public key certificate.

[0073] Therefore, in some embodiments of the present application, if the signature tool issues the application program signature certificate C2 to the second terminal associated with the second subject, before issuing the identity signature certificate C1 to the first terminal, it further includes deploying a first signature tool in the first terminal, and the first terminal is adapted to manage the key for verifying the application program signature certificate C2 by the signature tool, and the second terminal is also adapted to manage the key for verifying the application program and the subordinate signature certificate C2sub by the first signature tool. This means that in such embodiments, the key management of the second terminal is entrusted to the first signature tool corresponding to the first terminal, which saves the work task of redeploying the signature tool in the second terminal. However, the present application is not limited thereto.

[0074] Correspondingly, in some other embodiments of the present application, the second terminal corresponding to the second subject can also deploy a signature tool and independently manage the key. For example, in such a scheme, before issuing the identity signature certificate to the first terminal, it further includes deploying a first signature tool in the first terminal, and the first terminal is adapted to manage the key for verifying the application program signature certificate by the first signature tool; and before issuing the application program signature certificate to the second terminal, it further includes deploying a second signature tool in the second terminal, and the second terminal is adapted to manage the key for verifying the application program and the subordinate signature certificate by the second signature tool.

[0075] To better illustrate the practicability of the control method of the present application, exemplary, in some embodiments of the present application, further comprising the first terminal or the second terminal having the application signing certificate installs the signed application in the device through the application signing certificate, specifically comprising the following steps: submitting the to-be-signed file to the signing tool by the first terminal or the second terminal; signing the to-be-signed file by the signing tool using the corresponding key, wherein the to-be-signed file contains the information of the to-be-installed application; returning the signed file to the first terminal or the second terminal; uploading the application signing certificate and the signed file by the first terminal or the second terminal through the network, and downloading the application signing certificate and the signed file by the device through the network; and installing the application signing certificate in the device, verifying the legality of the signed file by using the application signing certificate, and installing the application contained in the signed file in the device if the signed file is legal.

[0076] Corresponding to the control method of the application installation permission in the device described above, with reference to Figure 4 Another aspect of the present application further proposes a control system 40 of application installation permission in a device (hereinafter referred to as "control system 40"), which has a root certificate, or a root certificate and a secondary certificate issued according to the root certificate. The control system 40 mainly comprises a signing tool 400, a first terminal 41, a second terminal 42, a third terminal 43 and a zeroth terminal 44.

[0077] Specifically, the first terminal 41 and the second terminal 42 are each associated with a unique first subject and a unique second subject, and the third terminal 43 can have one or more. Among them, the signing tool 400 is configured to issue an identity signing certificate corresponding to the first subject to the first terminal 41 according to the root certificate or the secondary certificate in response to the request issued by the first terminal 41. Further, the signing tool 400 is further configured to issue an application signing certificate to the second terminal 42 associated with the first terminal 41 or the unique second subject according to the identity signing certificate based on the application operation, wherein the first terminal 41 or the second terminal 42 having the application signing certificate is allowed to install the signed application in the device through the application signing certificate.

[0078] As Figure 4As shown, the control system includes one or more third terminals 43 associated with third subjects, and in such embodiments, if the signing tool issues the application signing certificate to the first terminal 41 associated with the first subject, the signing tool 400 is further configured to issue, based on the application operation of the first subject, a subsidiary signing certificate to the second terminal 42 associated with the second subject, or the second terminal 42 and the one or more third terminals 43 associated with the one or more third subjects, according to the application signing certificate, wherein the second terminal 42, or the second terminal 42 and the third terminal 43 are also adapted to install the signed application in the device through the subsidiary signing certificate, while the first terminal 41 is allowed to install the signed application in the device through the application signing certificate. If the signing tool 400 issues the application signing certificate to the second terminal 42 associated with the second subject, the signing tool 400 is further configured to issue, based on the application operation of the second subject, a subsidiary signing certificate to the one or more third terminals 43 associated with the one or more third subjects, according to the application signing certificate, wherein the one or more third terminals 43 are also allowed to install the signed application in the device through the subsidiary signing certificate, while the second terminal 42 is allowed to install the signed application in the device through the application signing certificate.

[0079] Finally, in the control system 40, there is also a zeroth terminal 44 associated with a zeroth subject, the zeroth terminal 44 is configured to configure the root certificate, or the root certificate and the secondary certificate issued according to the root certificate, in the device, and the zeroth terminal 44 is also configured to configure the initial signing certificate issued according to the root certificate or the secondary certificate in the device, and the zeroth terminal 44 is allowed to install the signed application in the device before leaving the factory through the initial signing certificate.

[0080] It can be understood that, in Figure 4 In the embodiment shown, there are complete zeroth terminals, first terminals, second terminals and one or more third terminals, but it can be understood that, with reference to the above description of the control method, in the scheme of the present application, in some use modes of the device, there can be no third terminal or second terminal. For other details of the control system 40, reference can be made to the above description of the control method part, which will not be repeated here.

[0081] The control method and control system of the application program installation permission in the device of the present application aim to abstract the needs of different subjects such as device manufacturers, device purchase customers and device operators, establish a differentiated management scheme of application security permissions based on the specification of PKI (Public Key Infrastructure), and unify the scheme design and management standards. For the subjects such as manufacturers, customers and operators, it not only meets the needs of complex application scenarios, but also reduces production and operation costs.

[0082] In the prior art, although some improvements are made for allowing multiple users to use the same device at the same time, it is often difficult to have a targeted and relatively complete permission control scheme for all subjects involved in the use of the device. In particular, compared with the prior art, the scheme of the present application can meet the scenario that a device allows multiple operators to have application installation permission control at the same time, but the application market and the application signing private key are independent of each other, which cannot be achieved by a simple and traditional certificate design mode. Moreover, the present application improves the problems of too many certificate levels, complex relationships between certificates, and difficult management of the relationship between certificates and customers or operators. The present scheme can meet the control requirements of hundreds of application scenarios for application installation permission in the device through 2-3 levels of certificate issuing hierarchy, and has high universality.

[0083] It should be noted that some examples in the above are exemplified by POS devices, because in the actual use scenario of the POS device, the purchase user of the POS device often has the need to prevent the device from being cut off, especially when the POS device is put into the market for transaction, safety is also the first consideration. Therefore, the POS device is a relatively ideal application object of the control method and control system of the present application, but the present application is not limited thereto. Any device with similar or identical requirements can use the control method and control system of the present application, and the protection scope of the present application should not change due to the specific types of the applied device objects.

[0084] The above has described the basic concepts, and it is obvious that the above disclosure of the present application is only used as an example and does not constitute a limitation on the present application. Although it is not explicitly stated here, those skilled in the art can make various modifications, improvements and corrections to the present application. Such modifications, improvements and corrections are suggested in the present application, so such modifications, improvements and corrections still belong to the spirit and scope of the exemplary embodiments of the present application.

[0085] At the same time, specific words are used in the present application to describe the embodiments of the present application. For example, “one embodiment”, “an embodiment”, and / or “some embodiments” means a certain feature, structure or characteristic related to at least one embodiment of the present application. Therefore, it should be emphasized and noted that the “one embodiment” or “one embodiment” or “one alternative embodiment” mentioned in different places in the specification does not necessarily refer to the same embodiment. In addition, some features, structures or characteristics in one or more embodiments of the present application can be properly combined.

[0086] Aspects of the application can be implemented in, completely, in hardware, completely in software (including firmware, resident software, micro-code, etc.), or combinations thereof. The foregoing hardware or software can be referred to as a "data block", "module", "engine", "unit", "component", or "system". The processor can be one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DAPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), processors, controllers, micro-controllers, microprocessors, or combinations thereof. Furthermore, aspects of the application can be presented in a computer program product, which can include a computer-readable medium having stored computer program codes. For example, the computer-readable medium can include, but is not limited to, magnetic storage devices (e.g., hard disk, floppy disk, magnetic strips...), optical disks (e.g., compact disk (CD), digital versatile disk (DVD)...), smart cards, and flash memory devices (e.g., card, stick, key drive...).

[0087] The computer readable medium can include a propagated data signal with computer program code embodied therein, for example, in baseband or as part of a carrier wave. Such a propagated signal can take any of a variety of forms, including, but not limited to, electro-magnetic, optical, or any suitable combination thereof. Computer readable medium can be any medium that can be read by a computer, including, but not limited to, storage devices, memory devices, and communication devices. The computer program code can be transmitted in any suitable format, including, but not limited to, radio frequency, light, electrical, or any suitable combination thereof.

[0088] Similarly, it is to be noticed that the term "comprising", used in the description, is not intended to exclude other features but to include other features. Other expressions, such as "containing" or "including", should be construed in a like manner. Furthermore, the above description of the various embodiments of the application has been presented for the purpose of illustration and description. It is not intended to be exhaustive or to limit the application to the precise form disclosed. Many modifications and variations are possible in light of the above teachings. It is intended that the scope of the application be limited not with this detailed description, but rather by the claims appended hereto.

[0089] In some embodiments, numbers that describe dimensions, quantities of ingredients, etc. are used. It should be understood that the numbers used in this description of the embodiments are intended, in some examples, to be modified by the modifier "approximately" or "about" in conformance with the numbered parameters as would be recognized by one skilled in the art to have a reasonable amount that the dimension, amount, etc. can vary. Unless otherwise indicated, "approximately" or "about" means ±20% of the value stated. Accordingly, the numerical parameters used in the specification and claims have a reasonable variability that can occur inasmuch as each numerical parameter can and typically does encompass a range of values close to the value it describes. In some embodiments, individual numerical limitations can allow for the inclusion of a specified valid number of significant figures by considering the stated number of significant figures and employing the normal rules of significant figure retention. Notwithstanding that the numerical ranges and parameters setting forth the broadest scope of the application in some embodiments are approximations, the numerical values set forth in the specific examples are reported as precisely as possible. Any numerical value, however, can contain certain errors necessarily resulting from the standard deviation found in their respective testing measurements.

[0090] While the application has been described with reference to the currently preferred embodiments, those skilled in the art will recognize various changes in form and equivalent substitutions of elements without departing from the spirit and scope of the application. Accordingly, the application is not to be limited as described above but is to only be limited as required by the appended claims.

Claims

1. A method of controlling application installation authority in a device having a root certificate, or the root certificate and a secondary certificate issued based on the root certificate, in the device, characterized by, The method comprises the following steps: The signature tool issues an identity signature certificate corresponding to the first subject to the first terminal according to the root certificate or the secondary certificate in response to a request from the first terminal associated with the unique first subject; And Based on the application operation of the first subject, the signature tool issues an application signature certificate to the first terminal or a second terminal associated with a unique second subject according to the identity signature certificate, wherein the first terminal or the second terminal that possesses the application signature certificate is allowed to install a signed application in the device through the application signature certificate, Wherein, the first subject includes a purchase user, and the second subject includes an operator; The root certificate is located at the top of the certificate chain and is used to verify the signatures of lower-level certificates; The secondary certificate is issued by the root certificate private key and is used to verify the signatures of lower-level certificates; The identity signature certificate is issued by the private key of the root certificate or the private key of the secondary certificate and is used to verify the signatures of lower-level certificates; The application signature certificate is issued by the private key of the identity signature certificate and is used to verify the signatures of lower-level certificates.

2. The control method of claim 1, wherein, if the signature tool issues the application signature certificate to the first terminal associated with the first subject, the control method further comprises issuing an auxiliary signature certificate to the second terminal associated with the second subject, or the second terminal and one or more third terminals associated with one or more third subjects according to the application signature certificate based on the application operation of the first subject, wherein the second terminal, or the second terminal and the third terminals are also adapted to install a signed application in the device through the auxiliary signature certificate while the first terminal is allowed to install a signed application in the device through the application signature certificate.

3. The control method of claim 1, wherein, if the signature tool issues the application signature certificate to the second terminal associated with the second subject, the control method further comprises issuing an auxiliary signature certificate to one or more third terminals associated with one or more third subjects according to the application signature certificate based on the application operation of the second subject, wherein the one or more third terminals are also allowed to install a signed application in the device through the auxiliary signature certificate while the second terminal is allowed to install a signed application in the device through the application signature certificate. If the signature tool issues the application signature certificate to the second terminal associated with the second subject, before issuing the identity signature certificate to the first terminal, it further comprises deploying a first signature tool in the first terminal, the first terminal is adapted to manage the key for verifying the application signature certificate through the signature tool, and the second terminal is also adapted to manage the key for verifying the application and the auxiliary signature certificate through the first signature tool. ​ 4. The control method according to claim 3, characterized by, ​ 5. The control method according to claim 3, characterized by, if the signing tool issues the application signing certificate to the second terminal associated with the second principal, further comprising: before the identity signing certificate is issued to the first terminal, further comprising deploying a first signing tool in the first terminal, the first terminal being adapted to manage a key for verifying the application signing certificate by the first signing tool; and before the application signing certificate is issued to the second terminal, further comprising deploying a second signing tool in the second terminal, the second terminal being adapted to manage a key for verifying the application and the subsidiary signing certificate by the second signing tool.

6. The control method according to claim 1, characterized by, further comprising the first terminal or the second terminal having the application signing certificate installing a signed application in the device by the application signing certificate, specifically comprising the following steps: submitting a file to be signed to the signing tool by the first terminal or the second terminal; signing the file to be signed by the signing tool using a key, wherein the file to be signed contains information of an application to be installed; returning the signed file to the first terminal or the second terminal; uploading the application signing certificate and the signed file by the first terminal or the second terminal through a network, and downloading the signing certificate and the signed file by the device through the network; and installing the application signing certificate in the device, verifying the legality of the signed file by the application signing certificate, and installing the application contained in the signed file in the device if the signed file is legal.

7. The control method according to any one of claims 1 to 6, characterized by, further comprising configuring the root certificate, or the root certificate and a secondary certificate issued according to the root certificate, in the device by a zeroth terminal associated with a zeroth principal, and configuring an initial verification certificate issued according to the root certificate or the secondary certificate in the device, the zeroth terminal being allowed to install a signed application in a device before leaving the factory by the initial verification certificate.

8. The control method according to claim 1, characterized by, after the application signing certificate is issued, invalidating the identity signing certificate.

9. The control method according to claim 7, characterized by, after the identity signing certificate is issued, invalidating the initial verification certificate, and after the application signing certificate is issued, invalidating the identity signing certificate.

10. A system for controlling application installation authority in a device having a root certificate, or the root certificate and a secondary certificate issued based on the root certificate, characterized by, comprising: a signing tool, a first terminal associated with a unique first principal, or the first terminal and a second terminal associated with a unique second principal, wherein the signing tool is configured to issue an identity signing certificate corresponding to the first principal to the first terminal according to the root certificate or the secondary certificate in response to a request from the first terminal; the signing tool is further configured to issue an application signing certificate to the first terminal or a second terminal associated with a unique second principal by the first principal according to the identity signing certificate based on an application operation, wherein the first terminal or the second terminal having the application signing certificate is allowed to install a signed application in the device by the application signing certificate, wherein the first principal includes a purchase user, and the second principal includes an operator; The root certificate is located at the top of the certificate chain and is used to verify the signatures of lower-level certificates; The second-level certificate is issued by the root certificate private key and is used to verify the signatures of lower-level certificates; The identity verification certificate is issued by the private key of the root certificate or the private key of the second-level certificate and is used to verify the signatures of lower-level certificates; The application verification certificate is issued by the private key of the identity verification certificate and is used to verify the signatures of lower-level certificates.

11. The control system of claim 10, wherein, Also included is one or more third terminals associated with a third principal, wherein, If the signing tool issues the application verification certificate to the first terminal associated with the first principal, the signing tool is further configured to, based on an application operation of the first principal, issue an additional verification certificate to the second terminal associated with the second principal, or the second terminal and one or more third terminals associated with one or more third principals, according to the application verification certificate, wherein the second terminal, or the second terminal and the third terminals, are also adapted to install a signed application in the device through the additional verification certificate while the first terminal is allowed to install a signed application in the device through the application verification certificate; If the signing tool issues the application verification certificate to the second terminal associated with the second principal, the signing tool is further configured to, based on an application operation of the second principal, issue the additional verification certificate to one or more third terminals associated with one or more third principals, according to the application verification certificate, wherein the one or more third terminals are also allowed to install a signed application in the device through the additional verification certificate while the second terminal is allowed to install a signed application in the device through the application verification certificate.

12. The control system of claim 10 or 11, wherein, Also included is a zeroth terminal associated with a zeroth principal, the zeroth terminal is configured to configure the root certificate, or the root certificate and a second-level certificate issued according to the root certificate, in the device, the zeroth terminal is also configured to not configure an initial verification certificate issued according to the root certificate or the second-level certificate in the device, and the zeroth terminal is allowed to install a signed application in the device before factory shipment through the initial verification certificate.

Citation Information

Patent Citations

  • Security verification method and device for APK signature information and POS machine

    CN112134711A

  • Method for realizing APK unified signature by using three-level certificate authentication

    CN112560017A