A method and apparatus for managing applications

By acquiring user tag information to manage a secure app store, the app list is only displayed to users with the required permissions, which solves the problem of insufficient security in existing app stores and improves the security of mobile office work.

CN115835217BActive Publication Date: 2025-12-16CHINA UNITED NETWORK COMM GRP CO LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211013590.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-23
Publication Date
2025-12-16
Estimated Expiration
2042-08-23

AI Technical Summary

Technical Problem

Existing app stores are open to all end users in mobile office scenarios, resulting in low security and an inability to effectively protect the business security of specific user groups.

Method used

By acquiring user tag information, the application management device manages the secure app store, displaying the app list only to users with the required permissions, thus achieving secure end-user permission management.

Benefits of technology

It enhances the security of mobile work by ensuring that only authorized applications are visible in the secure app store, preventing unauthorized users from accessing sensitive applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115835217B_ABST
    Figure CN115835217B_ABST
Patent Text Reader

Abstract

The embodiment of the application provides an application management method and device, relates to the technical field of communication, and can enable only applications meeting the user authority to be used when the user performs mobile office on a terminal device, and can realize safe mobile office. The specific scheme is as follows: when a terminal device requests to register a safe application store, an application management device verifies that a user of the terminal device is a safe terminal user who has registered the safe application store, and the application management device is used for managing the safe application store; the application management device obtains user label information of the user from a safe terminal management device; and the application management device indicates an application list corresponding to the user label information to the terminal device according to the user label information. The embodiment of the application is used for the process of viewing and downloading safe applications in the safe application store.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present application relate to the field of communication technology, and in particular to a management method and device of an application. BACKGROUND

[0002] With the development of mobile Internet and mobile terminals, the scenario of mobile office using mobile phones becomes more and more common. However, due to the openness of the Internet, the uncontrollability of mobile terminals and the diversity of business applications, mobile office also faces high security risks. The existing security mobile office solution usually guarantees the security of mobile office from aspects of a security private network, a security terminal, a security operating system and a security business application. For different enterprises, departments or user groups, specific security application viewing and downloading services need to be provided, and such security applications should be invisible to terminal users other than authorized users.

[0003] With the continuous development and maturation of mobile communication, mobile Internet technology and smart mobile terminals, application stores have developed into the main channel for information and data retrieval, application software publishing, downloading and other services of application software. However, when the current application store is used for mobile office, the application store can provide rich mobile application downloading services to all smart mobile terminal users, and the security of users when performing mobile office on the mobile terminal is low. SUMMARY

[0004] Embodiments of the present application provide a management method and device of an application, which can realize that a security terminal user can only view an application list conforming to his own authority in the interface of a security application store, and an application not conforming to his own authority is invisible to the user. In this way, when the user performs mobile office on the terminal device, only the application conforming to the user's authority can be used, and secure mobile office can be realized.

[0005] To achieve the above object, embodiments of the present application adopt the following technical solutions:

[0006] In a first aspect, a management method of an application is provided, comprising: when a terminal device requests to register a security application store, an application management device verifies that a user of the terminal device is a security terminal user who has registered the security application store, and the application management device is used to manage the security application store; the application management device obtains user tag information of the user from a security terminal management device; and the application management device indicates an application list corresponding to the user tag information to the terminal device according to the user tag information.

[0007] Thus, in the present application, by obtaining and identifying the user tag information and setting the authority of the application, the requirement of issuing a specific security business application to a specific user group in a security operating system can be realized.

[0008] In a possible design, the method further includes: when the terminal device requests to register the secure application store, the application management device verifies that the user of the terminal device is a secure terminal user who has registered the secure application store, and the application management device is configured to manage the secure application store, including: the application management device receiving a registration request sent by the terminal device, the registration request including user identity information of the user; when the application management device determines that the user is a subscribed user according to the user identity information, the application management device returns verification pass information to the terminal device, where the verification pass information is used to indicate that the user is a secure terminal user who has registered the secure application store.

[0009] That is, the application management device returns the verification pass information to the terminal device only when the user who requests to register is a secure terminal user who has registered the secure application store.

[0010] In a possible design, the method further includes: the application management device obtaining user tag information of the user from the secure terminal management device, including: the application management device sending the user identity information to the secure terminal management device to request to obtain the user tag information of the user, where the user tag information includes user organization information, and the user organization information includes at least one of an enterprise type to which the user belongs, an enterprise name to which the user belongs, and a department name to which the user belongs; and the application management device receiving the user tag information fed back by the secure terminal management device.

[0011] That is, the application management device can obtain the tag information of the registered user from the secure terminal management device, and store the tag information of the user.

[0012] In a possible design, the method further includes: the application management device indicating the application list corresponding to the user tag information to the terminal device according to the user tag information, including: the application management device receiving a first query request sent by the terminal device, where the first query request includes the user identity information, and the first query request is used to query the application list within the permission range of the user; the application management device determining the user tag information according to the user identity information; the application management device determining the application list according to the user tag information; and the application management device sending the application list corresponding to the user tag information to the terminal device.

[0013] That is, the application management device sends the application list that meets the user tag information to the terminal device after two queries.

[0014] In a second aspect, an application management method is provided, including: a terminal device requesting a secure application store to an application management device to verify that a user of the terminal device is a secure terminal user who has registered the secure application store, where the application management device is configured to manage the secure application store; and the terminal device obtaining an application list that meets a user permission from the application management device according to user identity information.

[0015] That is, the registered user can query whether he is a registered user through the terminal device, and view the application list that meets his authority.

[0016] In a possible design, the method further includes: the application list is determined by the application management device according to user identity identification information and user tag information; and the user tag information includes user organization information, and the user organization information includes at least one of a type of enterprise to which the user belongs, a name of the enterprise to which the user belongs, and a department name to which the user belongs.

[0017] In a third aspect, an application management method is provided, including: receiving, by a secure terminal management device, a query request sent by an application management device, the query request being used to request to obtain user tag information of a user, the user being a secure terminal user of a registered secure application store, and the application management device being used to manage the secure application store; and sending, by the secure terminal management device, a query feedback to the application management device, the query feedback including the user tag information, and the user tag information being used to obtain an application list corresponding to the user tag information.

[0018] That is, after receiving the query request from the application management device, the secure terminal device synchronizes the user tag information to the application management device.

[0019] In a fourth aspect, an application management device is provided, including: a verification unit, configured to verify, when a terminal device requests to register a secure application store, that a user of the terminal device is a secure terminal user of a registered secure application store, the application management device being used to manage the secure application store; an information obtaining unit, configured to obtain user tag information of the user from a secure terminal management device; and a list indicating unit, configured to indicate, according to the user tag information, an application list corresponding to the user tag information to the terminal device.

[0020] In a possible design, the verification unit is configured to receive a registration request sent by the terminal device, the registration request including user identity identification information of the user; and the application management device is configured to return verification pass information to the terminal device when it is determined according to the user identity identification information that the user is a registered user, the verification pass information being used to indicate that the user is a secure terminal user of a registered secure application store.

[0021] In a possible design, the information obtaining unit is configured to send the user identity identification information to the secure terminal management device to request to obtain the user tag information of the user, the user tag information including at least one of user organization information but not limited to a type of organization to which the user belongs, a name of an enterprise to which the user belongs, and a department name to which the user belongs; and the application management device is configured to receive the user tag information fed back by the secure terminal management device.

[0022] In a possible design,

[0023] a list indication unit, configured to receive a first query request sent by the terminal device, the first query request comprising user identity information, the first query request being used to query an application list within the authority scope of the user; determine user tag information according to the user identity information; determine the application list according to the user tag information; and send the application list corresponding to the user tag information to the terminal device.

[0024] In a fifth aspect, a terminal device is provided, comprising:

[0025] a registration unit, configured to request a secure application store to register the terminal device, so as to verify that a user of the terminal device is a secure terminal user of the secure application store, and the application management device is configured to manage the secure application store;

[0026] a list query unit, configured to acquire an application list conforming to the authority of the user from the application management device according to the user identity information.

[0027] In a possible design, the application list is determined by the application management device according to the user identity information and the user tag information; and the user tag information comprises user organization information, and the user organization information comprises at least one of an enterprise type to which the user belongs, an enterprise name to which the user belongs, and a department name to which the user belongs.

[0028] In a sixth aspect, a secure terminal management device is provided, comprising: a receiving unit, configured to receive a query request sent by an application management device, the query request being used to request to acquire user tag information of a user, the user being a secure terminal user of a secure application store, and the application management device being configured to manage the secure application store; and a sending unit, configured to send a query feedback by the application management device, the query feedback comprising the user tag information.

[0029] In a seventh aspect, a computer readable storage medium is provided, comprising computer instructions, when the computer instructions run on an electronic device, the electronic device executes the application management method in the first aspect and any possible implementation manner.

[0030] In an eighth aspect, a computer readable storage medium is provided, comprising computer instructions, when the computer instructions run on an electronic device, the electronic device executes the application management method in the second aspect and any possible implementation manner.

[0031] In a ninth aspect, a computer readable storage medium is provided, comprising computer instructions, when the computer instructions run on an electronic device, the electronic device executes the application management method in the third aspect and any possible implementation manner.

[0032] In a tenth aspect, the embodiments of the present application provide a computer program product, which, when executed on a computer or a processor, causes the computer or the processor to perform the application management method in the first aspect, the second aspect, the third aspect, and any possible implementation manner.

[0033] In an eleventh aspect, the embodiments of the present application provide a communication system, which can include the wireless access device and the at least one electronic device in any possible implementation manner of any of the above aspects. The electronic device and the wireless access device can perform the application management method in any of the above aspects and any possible implementation manner.

[0034] It can be understood that any of the above provided secure terminal management device, terminal device, application management device, computer readable storage medium, or computer program product, etc. can be applied to the corresponding method provided above, and thus the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding method, which will not be repeated here.

[0035] These aspects or other aspects of the present application will be more apparent in the following description. BRIEF DESCRIPTION OF DRAWINGS

[0036] Figure 1 A network architecture schematic diagram of an application management method provided by the embodiments of the present application;

[0037] Figure 2 A network architecture schematic diagram of an application management method provided by the embodiments of the present application;

[0038] Figure 3 A network architecture schematic diagram of an application management method provided by the embodiments of the present application;

[0039] Figure 4 A network architecture schematic diagram of an application management method provided by the embodiments of the present application;

[0040] Figure 5 A network architecture schematic diagram of an application management method provided by the embodiments of the present application;

[0041] Figure 6 A network architecture schematic diagram of an application management method provided by the embodiments of the present application;

[0042] Figure 7 A network architecture schematic diagram of an application management method provided by the embodiments of the present application;

[0043] Figure 8 A network architecture schematic diagram of an application management method provided by the embodiments of the present application;

[0044] Figure 9A display effect schematic diagram of a safe application store interface provided by an embodiment of the present application;

[0045] Figure 10 A structure schematic diagram of an application management device provided by an embodiment of the present application;

[0046] Figure 11 A structure schematic diagram of a terminal device provided by an embodiment of the present application;

[0047] Figure 12 A structure schematic diagram of a safe terminal management device provided by an embodiment of the present application;

[0048] Figure 13 A structure schematic diagram of a communication device provided by an embodiment of the present application. DETAILED DESCRIPTION

[0049] The technical solutions in the embodiments of the present application will be described below with reference to the drawings in the embodiments of the present application. In the description of the embodiments of the present application, unless otherwise specified, " / " represents the meaning of or, for example, A / B can represent A or B; "and / or" in this document only represents a description of the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B, which means that there are three cases of A alone, A and B together, and B alone. In addition, in the description of the embodiments of the present application, "multiple" means two or more than two.

[0050] Hereinafter, the terms "first" and "second" are only used for descriptive purposes, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of indicated technical features. Therefore, the features defined with "first" and "second" can explicitly or implicitly include one or more features. In the description of the embodiments, unless otherwise specified, the meaning of "multiple" is two or more than two.

[0051] With the development of mobile communication, mobile Internet and smart mobile terminals, the industry as a whole is developing towards content quality, platform integration and mode innovation. Application store, i.e. mobile Internet application store, refers to a business system that provides mobile smart terminal application software information and data retrieval, application software publishing, downloading and other services directly to the users of the terminal through public communication networks such as the Internet and mobile Internet, and is the most important distribution channel for application software.

[0052] At present, the mainstream application store is mainly provided by mobile phone manufacturers, third parties, system operators and network operators. Various application stores are aimed at all smart mobile terminal users, and are designed to provide rich mobile applications and services for Internet users.

[0053] The application store management platform can provide management functions such as review, on-shelf and off-shelf of the mobile application in the application store. The application store open platform provides functions such as qualification registration and application submission for the developer. The application store mobile client provides functions and services such as search, browse and download of various mobile applications for the mobile terminal user.

[0054] With the increasing requirement of the user on the security of mobile office in life, if the existing application store continues to provide application download and service for all mobile terminal users or all mobile terminal registered users, the security of the special terminal user may be affected when the special terminal user uses the mobile office due to the high requirement on the business security.

[0055] Therefore, the application provides an application management method and device based on the security application store of the security operating system for user permission management. The user tag information is acquired and identified, and the visible range of the security application in the security application store to the terminal user is set, so that the management and distribution channel of the security business application are provided, the function of distributing different types of security business applications for different user groups is realized, and the security of the mobile office is further improved.

[0056] Figure 1 A network architecture of the application management method is provided, which includes a security terminal management device 10, an application management device 11 and a terminal device 12.

[0057] The security terminal management device can also be referred to as a security terminal management platform, which is a Web terminal used for registering and recording user information and user tag information. The security terminal management device can also send the user tag information to the application management device according to the user information of the application management device.

[0058] The application management device, which can also be referred to as an application store management platform, is used for managing the security application store and managing the security terminal user. For example, the administrator can publish a new application or application update on the application management device, set the user organization range of the visible application, so that the user can obtain the application list that the user has the permission to view according to the user tag information when the terminal device logs in the security application store.

[0059] The terminal device, which can also be referred to as a security terminal device, can be used by the security terminal user. The terminal device includes an application store mobile client, which can be understood as an application (Application, APP) including the security application store. The security terminal user can view the application list that meets the permission of the security terminal user itself when logging in the security application store successfully.

[0060] Further, in some embodiments, as shown in Figure 2 The application management device in the present application includes a user management module and an application management module. The user management module can be used to request the secure terminal management device to obtain user tag information, store the user tag information, and send the user tag information to the terminal device when the user logs in the application store mobile client, and the like.

[0061] The application management module can be used to set and edit the business application permissions, and the like, and can provide the terminal device with the application download permissions when the user logs in the application store mobile client, and the like.

[0062] Based on the network architecture provided in the present application, the embodiments of the present application are introduced as follows.

[0063] The present application provides an application management method, as shown in Figure 3 The method includes the following steps.

[0064] 301. When the terminal device requests to register the secure application store, the application management device checks whether the user of the terminal device is a registered secure terminal user of the secure application store. The application management device is used to manage the secure application store.

[0065] The secure application store in the present application can provide the viewing and downloading services of the secure applications for different secure terminal users. The secure terminal user can be understood as an enterprise, a department, or a user group, and the like, which has the special permission to view the application corresponding to the user tag information.

[0066] When the secure terminal user needs to download the required application on the terminal device, in order to check whether the secure terminal user has the permission to use the secure application store, the user of the terminal device needs to register the secure application store first. After receiving the registration information of the user, the application management device checks the user information stored in the secure terminal management device to determine whether the user is a registered secure terminal user. If the user is a registered secure terminal user, the user can successfully register the secure application store mobile client. If the user is not a registered secure terminal user, the user cannot register the secure application store mobile client.

[0067] 302. The application management device obtains the user tag information of the user from the secure terminal management device.

[0068] When the application management device determines that the user logging in the secure application store is a registered secure terminal user, the application management device can obtain the user tag information of the user from the secure terminal management device. In this way, when the user wants to view the application permission range of the user in the secure application store, the application management device can determine the application permission range available to the user according to the user tag information.

[0069] 303、The application management device indicates an application list corresponding to the user tag information to the terminal device according to the user tag information.

[0070] The application list corresponding to the user tag information can be understood as the application permission range that the user can view and download in the secure application store.

[0071] In some embodiments, in the secure application store, the administrator can set the user permission range of each application in the application management device. In this way, when the secure terminal user views and downloads the application in the secure application store, the terminal device displays the application list that meets the user permission, and the secure terminal user can only view and download the application list corresponding to the user tag information of the secure terminal user.

[0072] Thus, in the present application, when the application management device checks that the user of the terminal device is a secure terminal user who has registered the secure application store when the terminal device requests to register the secure application store, the application list corresponding to the user tag information of the secure terminal user can be obtained by obtaining the user tag information of the secure terminal user, and the application list is indicated to the terminal device. The secure terminal user can only view the application list that meets the user permission in the interface of the secure application store, and the application that does not meet the user permission is invisible to the user. In this way, when the user performs mobile office on the terminal device, only the application that meets the user permission can be used, and the security of mobile office can be realized, and the security of mobile office is improved.

[0073] The application embodiment provides an application management method, as shown in Figure 4 The method comprises the following steps:

[0074] 401、The terminal device requests to register the secure application store to the application management device to check that the user of the terminal device is a secure terminal user who has registered the secure application store, and the application management device is used to manage the secure application store.

[0075] The terminal device can be understood as a secure terminal device. The user using the secure terminal device needs to request to register the secure application store to view the secure application store on the secure terminal device, so that the user can view and download the application that meets the user permission in the secure application store when the application management device checks that the user is a secure terminal user who has registered.

[0076] 402、The terminal device queries the user tag information of the user to the application management device.

[0077] In the present application, the user tag information is the information registered by the terminal user or enterprise on the security terminal management device. When the user wants to view and download the application in the security application store, the user tag information of the user needs to be queried from the application management device, so as to find the application meeting the user authority according to the user tag information.

[0078] 403. The terminal device queries the application list corresponding to the user tag information from the application management device according to the user tag information.

[0079] Therefore, in the present application, when the security terminal user logs in the security application store, if the verification is that the security terminal user has been registered, the application list meeting the user tag information can be viewed in the terminal device. The present application can realize that the registration authority of the security application store is only open to the specific security terminal user, and in the case that the security application store only provides the application list meeting the user tag information to the security terminal user, the different security service applications can support the viewing and downloading service provided to the user organization with different authorities. In other words, the security application store on the terminal device can only display the application list meeting the security user's own authority, and the application not meeting the security user's own authority is invisible. For example, when the user uses the application in the security application store for mobile office, the security of the mobile office can be improved.

[0080] The embodiment of the present application provides an application management method, as shown in the method, the method comprises the steps of: Figure 5

[0081] 501. The security terminal management device receives the query request sent by the application management device, the query request is used for requesting to obtain the user tag information of the user, the user is the security terminal user who has registered the security application store, and the application management device is used for managing the security application store.

[0082] In the present application, the user tag information of the user or enterprise can be registered on the security terminal management platform, when the security terminal device wants to query the application list, the user tag information can be obtained from the security terminal management device, so as to obtain the corresponding application list according to the user tag information.

[0083] 502. The security terminal management device sends the query feedback to the application management device, the query feedback comprises the user tag information, and the user tag information is used for obtaining the application list corresponding to the user tag information.

[0084] ​Thus, for the security terminal management device in the present application, when it is determined that the user has successfully registered the security application store, the user tag information of the user can be fed back to the application management device, so that the application management device acquires the application list that the user can view or download according to the user tag information. In this way, when the user tag information is different, it is equivalent to supporting different security service applications to provide viewing and downloading services for users with different permissions. For example, when the user uses the application in the security application store for mobile office, the security of mobile office can be improved.

[0085] The embodiment of the present application provides an application management method, as shown in the method comprises the following steps. Figure 6

[0086] 601. A terminal user or an enterprise registers user tag information in a security terminal management device.

[0087] For example, when the terminal user holds a security terminal device, the terminal user can be a security terminal user. Different types of security terminal users correspond to different user tag information. Once the user tag information is registered on the security terminal management platform, the security terminal user can use the application in the security application store corresponding to the user tag information.

[0088] For example, the user tag information includes user organization information, and can also include other types of tag information.

[0089] The user organization information includes at least one of the organization type to which the user belongs, the enterprise name to which the user belongs, and the department name to which the user belongs. Of course, the user organization information can also include other types of user organization information, which is not limited in the present application.

[0090] In some embodiments, when the user tag information is registered, the relationship between the user identity information and the user tag information can be established. The user identity information can be a mobile phone number, for example.

[0091] 602. The terminal device registers the security application store with the application management device.

[0092] In some embodiments, when the terminal device logs in the security application store, the terminal device can send a registration request to the application management device, and the registration request includes user identity information of the user. For example, the user identity information can be a mobile phone number of the terminal device.

[0093] When the application management device determines that the user is a contracted user according to the user identity information, the application management device returns verification pass information to the terminal device, and the verification pass information is used to indicate that the user is a security terminal user who has registered the security application store. For example, the verification pass information can be a verification code.

[0094] ​In this way, the terminal device successfully registers the secure application store.

[0095] 603. The application management device applies to the secure terminal management device for obtaining user tag information.

[0096] For example, the application management device sends user identity identification information to the secure terminal management device to request obtaining user tag information of the user. The application management device receives the user tag information fed back by the secure terminal management device.

[0097] That is, the application management device can send the registered mobile phone number to the secure terminal management device to obtain the user tag information corresponding to the mobile phone number.

[0098] In some embodiments, step 603 can be that the user management module in the application management device sends the mobile phone number to the secure terminal management device.

[0099] For example, the user management module can obtain the user tag information corresponding to the mobile phone number from the secure terminal management device through the API interface of the application management device. Moreover, the user management module can manage and store the user tag information.

[0100] Further, the application management module can directly call the user tag information stored by the user management module of the application management device.

[0101] 604. The administrator sets the permission of the application in the secure application store on the application management device.

[0102] For example, the administrator can publish a new application or update an existing application in the secure application store, and needs to set the permission of the application, i.e. limit the user tag range in which the application is visible, such as the user organization range.

[0103] The user organization range in which the application is visible can include enterprise type, enterprise name, department name, etc., and the selection method can be, for example, a drop-down option.

[0104] For example, as shown in Figure 7 For a certain application A in the secure application store, if the administrator selects the enterprise type as general, the enterprise name as all enterprises, and the department name as all departments in the drop-down option, the application will be visible to all registered secure terminal users.

[0105] For another example, as shown in Figure 8As shown, for an application B in the security application store, if the administrator selects the enterprise type a in the pull-down option, then all the enterprise lists belonging to the enterprise type a will be listed in the drop-down box of the enterprise name. However, if the administrator further selects the enterprise b in the enterprise list and selects the department c in the department name, then the user organization scope of the application B or the visible scope of the application B is limited to the department c under the enterprise b in the enterprise type a.

[0106] 605、The security terminal device logs in the security application store to query the application list.

[0107] For example, the security terminal user clicks the icon of the security application store in the display interface of the terminal device, enters the interface of the security application store, and clicks the login option to log in the security application store. Specifically, the login can be performed by using the mobile phone number that has been registered in the security application store.

[0108] After the login is successful, the process of querying the application list can include the following steps 606-609.

[0109] 606、The terminal device sends a first query request to the application management device, the first query request including user identity identification information, the first query request being used to query the application list within the permission scope of the user.

[0110] For example, as shown in 606 in Figure 6 , the terminal device can send the first query request to the application management module in the application management device, the first query request including the mobile phone number of the terminal device, and the application management module can feed back the application list corresponding to the mobile phone number.

[0111] 607、The application management device determines the user tag information according to the user identity identification information, and determines the application list according to the user tag information.

[0112] The process of step 607 can refer to steps 607a-607d in Figure 6 .

[0113] 607a、The application management module of the application management device sends a second query request to the user management module of the application management device, the second query request including the user identity identification information, the second query request being used to query the user tag information corresponding to the user identity identification information.

[0114] 607b、The user management module of the application management device queries the user tag information corresponding to the user identity identification information.

[0115] The user management module of the application management device queries the user tag information corresponding to the user identity identification information according to the user identity identification information.

[0116] 607c, the user management module of the application management device feeds back the user tag information to the application management module of the application management device.

[0117] 607d, the application management module of the application management device determines the application list according to the user tag information.

[0118] For example, the user management module sends a second query feedback to the application management module, and the second query feedback includes the application list corresponding to the user tag information.

[0119] 608, the application management device sends the application list corresponding to the user tag information to the terminal device.

[0120] For example, the application management module of the application management device feeds back the application list corresponding to the user tag information to the terminal device.

[0121] 609, the terminal device displays the application list in the interface of the secure application store.

[0122] For example, the display effect of the interface of the secure application store of the terminal device can be as shown in the following figure. Figure 9 The interface includes an application search box and an application list composed of a plurality of secure applications, for example, the application list includes application 1-application 9. For example, the user tag information of the user can also be displayed in the interface.

[0123] In this way, the terminal user can only view the application list that meets his own authority, and the application that does not meet his own authority is invisible to the user.

[0124] Therefore, in the application management method provided by the application, different user tag information is matched with different application authority in the secure application store through the secure terminal management device, the application management device and the terminal device, so as to realize the management of the visible range of different secure applications to different organizations. When the secure application user moves office, the security of mobile office can be improved.

[0125] It can be understood that, in order to realize the above functions, the electronic device contains the corresponding hardware and / or software modules for executing each function. The electronic device can be one of the above-mentioned secure terminal management device, application management device and terminal device. The algorithm steps of each example described in combination with the embodiments disclosed herein can be realized in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the form of hardware or computer software driven hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application in combination with the embodiments, but such implementation should not be considered beyond the scope of the application.

[0126] The embodiments can divide the function modules of the electronic device according to the method examples described above. For example, each function module can be divided according to each function, or two or more functions can be integrated into one processing module. The integrated module can be implemented in the form of hardware. It should be noted that the division of the modules in the embodiments is illustrative, and is only a logical function division. In actual implementation, another division manner can be used.

[0127] In the case of dividing each function module according to each function, Figure 10 A possible composition of the application management device 100 involved in the above embodiments is shown, as shown in Figure 10 The application management device 100 can include a verification unit 1001, an information acquisition unit 1002, and a list indication unit 1003.

[0128] The verification unit 1001 can be used to support the application management device 100 to perform the above steps 301, 602, 504, etc., and / or other processes of the technology described herein.

[0129] The information acquisition unit 1002 can be used to support the application management device 100 to perform the above steps 302, 603, 607, etc., and / or other processes of the technology described herein.

[0130] The list indication unit 1003 can be used to support the application management device 100 to perform the above steps 303, 608, etc., and / or other processes of the technology described herein.

[0131] It should be noted that all related content of each step involved in the above method embodiments can be cited in the function description of the corresponding function module, which will not be repeated here.

[0132] The application management device 100 provided by the embodiments is used to perform the above application management method, and thus can achieve the same effect as the above implementation method.

[0133] In the case of dividing each function module according to each function, Figure 11 A possible composition of the terminal device 110 involved in the above embodiments is shown, as shown in Figure 11 The terminal device 110 can include a registration unit 1101 and a list query unit 1102.

[0134] The registration unit 1101 can be used to support the terminal device 110 to perform the above steps 401, 602, etc., and / or other processes of the technology described herein.

[0135] The list query unit 1102 can be configured to support the terminal device 110 to perform the step 403, the step 605, the step 608, and the like described above, and / or other procedures of the technologies described herein.

[0136] It should be noted that all related content of each step involved in the above method embodiments can be referred to the function description of the corresponding function module, which will not be repeated here.

[0137] The terminal device 110 provided in the embodiment is configured to perform the management method of the application described above, and thus can achieve the same effect as the implementation method described above.

[0138] In the case of dividing each function module according to each function, Figure 12 A possible composition schematic diagram of the security terminal management device 120 involved in the above embodiment is shown, as shown in the figure, the security terminal management device 120 can include a receiving unit 1201 and a sending unit 1202. Figure 12

[0139] The receiving unit 1201 can be configured to support the security terminal management device 120 to perform the step 501 and the like described above, and / or other procedures of the technologies described herein.

[0140] The sending unit 1202 can be configured to support the security terminal management device 120 to perform the step 502 and the like described above, and / or other procedures of the technologies described herein.

[0141] It should be noted that all related content of each step involved in the above method embodiments can be referred to the function description of the corresponding function module, which will not be repeated here.

[0142] The security terminal management device 120 provided in the embodiment is configured to perform the management method of the application described above, and thus can achieve the same effect as the implementation method described above.

[0143] In the case of adopting an integrated unit, the application management device 100, the terminal device 110, and the security terminal management device 120 can include a processing module, a storage module, and a communication module. The processing module can be configured to control and manage the actions of the application management device 100, the terminal device 110, and the security terminal management device 120, for example, can be configured to support the application management device 100 to perform the steps performed by the verification unit 1001, the information acquisition unit 1002, and the list indication unit 1003. The storage module can be configured to support the application management device 100 to store program codes and data, etc. The communication module can be configured to support the application management device 100 to communicate with other devices, for example, to communicate with the terminal device 110 or the security terminal management device 120.

[0144] ​The processing module can be a processor or a controller. It can implement or execute various exemplary logical blocks, modules, and circuits described in combination with the disclosure of the present application. The processor can also be a combination of computing functions, such as a combination of one or more microprocessors, a combination of a digital signal processing (DSP) and a microprocessor, and the like. The storage module can be a memory. The communication module can be a device for interacting with other electronic devices, such as a radio frequency circuit, a Bluetooth chip, a Wi-Fi chip, and the like.

[0145] In one embodiment, when the processing module is a processor, the storage module is a memory, and the communication module is a transceiver, the application management device 100, the terminal device 110, and the secure terminal management device 120 involved in the embodiment can be a communication device with the structure shown in the figure. Figure 13

[0146] Embodiments of the present application also provide a computer-readable storage medium having computer instructions stored therein, when the computer instructions are executed on a communication device (such as the application management device 100, the terminal device 110, and the secure terminal management device 120), the electronic device executes the above-mentioned related method steps to implement the application management method in the above-mentioned embodiments.

[0147] Embodiments of the present application also provide a computer program product, when the computer program product is executed on a computer, the computer executes the above-mentioned related steps to implement the application management method executed by the communication device (such as the application management device 100, the terminal device 110, and the secure terminal management device 120) in the above-mentioned embodiments.

[0148] In the embodiments, the application management device, the terminal device, the secure terminal management device, the computer storage medium, and the computer program product are used to execute the corresponding methods provided above, and thus the beneficial effects achieved thereby can refer to the beneficial effects of the corresponding methods provided above, which will not be described herein again.

[0149] Another embodiment of the present application provides a communication system, which can include the above-mentioned application management device, terminal device, and secure terminal management device, and can be used to implement the above-mentioned application management method.

[0150] Through the description of the above embodiments, those skilled in the art can understand that, for the convenience and brevity of description, only the division of the above functional modules is taken as an example for illustration, and in actual application, the above functions can be completed by different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.

[0151] ​In several embodiments provided in the present application, it should be understood that the disclosed apparatus and method can be implemented by other manners. For example, the apparatus embodiments described above are merely illustrative, for example, the division of the modules or units is merely a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another apparatus, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units or components shown or discussed can be indirect coupling or communication connection through some interfaces, apparatuses or units, and can be electrical, mechanical or other forms.

[0152] The units described as separate components can or can not be physically separate, and the components shown as units can be one physical unit or multiple physical units, that is, can be located in one place or distributed to multiple different places. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.

[0153] In addition, the functional units in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.

[0154] The integrated unit, if realized in the form of a software functional unit and sold or used as an independent product, can be stored in a readable storage medium. Based on this understanding, the technical solutions of the embodiments of the present application essentially or the parts that make contributions to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product, which is stored in a storage medium and includes a plurality of instructions for causing an apparatus (which can be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the method described in the embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various storage medium that can store program codes.

[0155] The above is merely a specific implementation of the present application, but the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A management method of applications, characterized in that, The application management device is used for managing the secure application store, and comprises: The application management device sends user identity information of the user to a secure terminal management device to request to obtain user tag information of the user, the user tag information comprising user organization information, and the user organization information comprising at least one of an enterprise type to which the user belongs, an enterprise name to which the user belongs, and a department name to which the user belongs; The application management device receives the user tag information fed back by the secure terminal management device; The application management device indicates an application list corresponding to the user tag information to the terminal device according to the user tag information. The application management device is used for managing the secure application store, and comprises:

2. The method of claim 1, wherein, The application management device receives a registration request sent by the terminal device, the registration request comprising user identity information of the user; When the application management device determines that the user is a contracted user according to the user identity information, the application management device returns verification pass information to the terminal device, the verification pass information being used for indicating that the user is a secure terminal user who has registered the secure application store. The application management device indicates an application list corresponding to the user tag information to the terminal device according to the user tag information, and comprises:

3. The method of claim 2, wherein, The application management device receives a first query request sent by the terminal device, the first query request comprising the user identity information, and the first query request being used for querying an application list within a permission range of the user; The application management device determines the user tag information according to the user identity information; The application management device determines the application list according to the user tag information; The application management device sends the application list corresponding to the user tag information to the terminal device. The method comprises:

4. A management method of applications, characterized in that, A terminal device requests a secure application store to an application management device to check whether a user of the terminal device is a secure terminal user who has registered the secure application store, and the application management device is used for managing the secure application store; ​ The terminal device acquires an application list conforming to user authority from the application management device according to user identity recognition information; the application management device is configured to send user identity recognition information of the user to a secure terminal management device to request user tag information of the user, the user tag information including user organization information, the user organization information including at least one of an enterprise type to which the user belongs, an enterprise name to which the user belongs, and a department name to which the user belongs; the application management device is further configured to receive the user tag information fed back by the secure terminal management device; and the application management device is further configured to indicate an application list corresponding to the user tag information to the terminal device according to the user tag information.

5. A management method of applications, characterized in that, The method comprises: The secure terminal management device receives a query request sent by the application management device, the query request being used to request user tag information of a user, the user being a secure terminal user who has registered a secure application store, and the application management device being used to manage the secure application store; the user tag information including user organization information, the user organization information including at least one of an enterprise type to which the user belongs, an enterprise name to which the user belongs, and a department name to which the user belongs; The secure terminal management device sends a query feedback to the application management device, the query feedback including the user tag information, the user tag information being used to acquire an application list corresponding to the user tag information.

6. An application management device characterized by comprising: Comprise: The checking unit is configured to check that a user of a terminal device is a secure terminal user who has registered a secure application store when the terminal device requests to register the secure application store, and the application management device is used to manage the secure application store; The information acquisition unit is configured to send user identity recognition information of the user to a secure terminal management device to request user tag information of the user, the user tag information including user organization information, the user organization information including at least one of an enterprise type to which the user belongs, an enterprise name to which the user belongs, and a department name to which the user belongs; The information acquisition unit is further configured to receive the user tag information fed back by the secure terminal management device; The list indication unit is configured to indicate an application list corresponding to the user tag information to the terminal device according to the user tag information.

7. The application management device according to claim 6, wherein The checking unit is configured to: Receive a registration request sent by the terminal device, the registration request including user identity recognition information of the user; When it is determined according to the user identity recognition information that the user is a contracted user, return verification pass information to the terminal device, the verification pass information being used to indicate that the user is a secure terminal user who has registered the secure application store.

8. The application management device according to claim 6 or 7, characterized by, The list indication unit is configured to: Receive a first query request sent by the terminal device, the first query request including the user identity recognition information, and the first query request being used to query an application list within an authority range of the user; Determine the user tag information according to the user identity recognition information; Determine the application list according to the user tag information; The application list corresponding to the user label information is sent to the terminal device.

9. A terminal device, comprising: The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device.

10. A secure terminal management device, characterized by comprising: The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal device. The application list corresponding to the user label information is sent to the terminal

Citation Information

Patent Citations

  • Method, related device and system for installing applications in working area of mobile terminal

    CN103713904A