Methods, devices, and storage media for downloading mini-programs
By verifying the security of the mini-program package under the new call system through the business management server and utilizing the certificate verification mechanism of the certificate management server, the problem of illegal mini-programs being downloaded by terminal devices was solved, thus improving the security of mini-program downloads.
Patent Information
- Application Number
- CN202411188885.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-27
- Publication Date
- 2026-01-30
- Estimated Expiration
- 2044-08-27
AI Technical Summary
Under the new calling system, terminal devices may download illegal mini-programs from complex network environments, affecting the security of downloaded mini-programs.
After confirming the security of the preset mini-program, the business management server requests the mini-program package from the business server and requests a certificate from the certificate management server. The certificate is used to verify the security of the mini-program package, and the NCP decides whether to send the mini-program package to the terminal device based on the certificate.
It improves the security of mini-program downloads during calls on terminal devices, ensuring that the downloaded mini-program packages are safe.
Smart Images

Figure CN119182564B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communications, and more particularly to a method, apparatus, and storage medium for downloading applets. Background Technology
[0002] Fifth-generation mobile communication technology (5G) offers new communication services characterized by high definition, visual connectivity, and interactivity. 5G can leverage the data channels of the Long Term Evolution (LTE)-based Voice over LTE (VoLTE) / Voice over New Radio (VoNR) network to achieve high-definition, interactive, and immersive native video calls, enhancing the user experience.
[0003] In related technologies, under the new call system, terminal devices can download mini-programs from third-party business servers via a data channel. However, the current public network environment is rapidly changing and contains a large number of illegal mini-programs. Terminal devices may download illegal mini-programs from complex network environments, seriously affecting the security of mini-program downloads. Therefore, how to improve the security of mini-program downloads during terminal device calls remains a technical problem to be solved. Summary of the Invention
[0004] This application provides a method, apparatus, and storage medium for downloading mini-programs to improve the security of mini-program downloads.
[0005] To achieve the above objectives, this application adopts the following technical solution:
[0006] Firstly, this application provides a method for downloading a mini-program, applied in a new communication service call scenario. The method includes: after determining that the preset mini-program is secure, a service management server sends a first request message to a service server and requests a certificate management server to issue a certificate for the preset mini-program; the first request message is used to request the download of the preset mini-program package, and the service server stores the preset mini-program package; the service management server receives the preset mini-program package sent from the service server and the preset mini-program certificate sent from the certificate management server; the service management server sends the preset mini-program package and the preset mini-program certificate to the new communication control plane network element (NCP); the preset mini-program certificate is used to verify the security of the preset mini-program package.
[0007] In one possible implementation, a second request message is received from the NCP; the second request message is used to request the download of a preset mini-program; based on the identification information of the preset mini-program and the application rules in the second request message, a business server is determined; the application rules include the identification information of at least one mini-program and the business server corresponding to the identification information of at least one mini-program.
[0008] In one possible implementation, a first key corresponding to the preset mini-program is determined based on the identification information and application rules of the preset mini-program in the second request information; the application rules also include a key corresponding to the identification information of at least one mini-program; the first key is added to the first request information; the first key is used to verify the validity of the first request information.
[0009] In one possible implementation, the initial packet loss rate and initial latency of the preset mini-program are determined based on the identification information and application rules of the preset mini-program in the second request information; the application rules include the identification information of at least one mini-program, and the initial packet loss rate and initial latency corresponding to the identification information of at least one mini-program; if the preset mini-program is determined to be secure, a first request information and a negotiation request information are sent to the business server, and a certificate management server is requested to issue a certificate for the preset mini-program; the negotiation request information includes the initial packet loss rate and initial latency of the preset mini-program; the negotiation request information is used to negotiate the packet loss rate and latency of the preset mini-program.
[0010] In one possible implementation, the system receives a mini-program package of a preset mini-program sent by a business server, negotiation response information, and a certificate of the preset mini-program sent by a certificate management server. The negotiation response information includes the negotiation packet loss rate and negotiation latency of the preset mini-program. The negotiation packet loss rate of the preset mini-program is negotiated between the business management server and the business server based on the initial packet loss rate of the preset mini-program. The negotiation latency of the preset mini-program is negotiated between the business management server and the business server based on the initial latency of the preset mini-program.
[0011] In one possible implementation, the NCP sends the profile information of a preset mini-program to the new communication unified media plane network element UMF; the profile information includes: the negotiation packet loss rate and the negotiation delay of the preset mini-program; the profile information is used to determine the communication service quality level of the preset mini-program.
[0012] In one possible implementation, the certificate of the pre-set mini-program includes the identification information and validity information of the pre-set mini-program.
[0013] Secondly, this application provides an apparatus for downloading a mini-program, comprising: a processing unit and a communication unit: the processing unit is configured to, upon determining that a preset mini-program is secure, send a first request message to a business server and request a certificate management server to issue a certificate for the preset mini-program; the first request message is used to request the download of the mini-program package of the preset mini-program, and the business server stores the mini-program package of the preset mini-program; the communication unit is further configured to receive the mini-program package of the preset mini-program sent from the business server and the certificate of the preset mini-program sent from the certificate management server; the communication unit is further configured to send the mini-program package of the preset mini-program and the certificate of the preset mini-program to an NCP; the certificate of the preset mini-program is used to verify the security of the mini-program package of the preset mini-program.
[0014] In one possible implementation, the communication unit is further configured to receive a second request message from the NCP; the second request message is used to request the download of a preset applet; the processing unit is further configured to determine the business server based on the identification information of the preset applet and the application rules in the second request message; the application rules include the identification information of at least one applet and the business server corresponding to the identification information of at least one applet.
[0015] In one possible implementation, the processing unit is further configured to determine a first key corresponding to the preset mini-program based on the identification information and application rules of the preset mini-program in the second request information; the application rules also include a key corresponding to the identification information of at least one mini-program; the processing unit is further configured to add the first key to the first request information; the first key is used to verify the validity of the first request information.
[0016] In one possible implementation, the processing unit is further configured to determine the initial packet loss rate and initial latency of the preset mini-program based on the identification information and application rules of the preset mini-program in the second request information; the application rules include the identification information of at least one mini-program, and the initial packet loss rate and initial latency corresponding to the identification information of at least one mini-program; the processing unit is further configured to, if the preset mini-program is determined to be secure, send the first request information and the negotiation request information to the business server, and request the certificate management server to issue a certificate for the preset mini-program; the negotiation request information includes the initial packet loss rate and initial latency of the preset mini-program; the negotiation request information is used to negotiate the packet loss rate and latency of the preset mini-program.
[0017] In one possible implementation, the communication unit is further configured to receive a mini-program package of a preset mini-program sent from the business server, negotiation response information, and a certificate of the preset mini-program sent from the certificate management server; the negotiation response information includes the negotiation packet loss rate and negotiation latency of the preset mini-program; the negotiation packet loss rate of the preset mini-program is negotiated between the business management server and the business server based on the initial packet loss rate of the preset mini-program; the negotiation latency of the preset mini-program is negotiated between the business management server and the business server based on the initial latency of the preset mini-program.
[0018] In one possible implementation, the communication unit is further configured to send the profile information of the preset applet to the UMF via NCP; the profile information includes: the negotiation packet loss rate of the preset applet and the negotiation delay of the preset applet; the profile information is used to determine the communication service quality level of the preset applet.
[0019] In one possible implementation, the certificate of the pre-set mini-program includes the identification information and validity information of the pre-set mini-program.
[0020] Thirdly, embodiments of this application provide an apparatus for downloading a mini-program. The apparatus includes a processor and a memory. The memory stores computer execution instructions. When the apparatus for downloading the mini-program is running, the processor executes the computer execution instructions stored in the memory to cause the apparatus for downloading the mini-program to perform the method for downloading the mini-program as described in the first aspect and any possible implementation thereof.
[0021] Fourthly, embodiments of this application provide a computer-readable storage medium storing instructions that, when executed by a processor of a device for downloading an applet, enable the device for downloading the applet to perform the method for downloading the applet as described in the first aspect and any possible implementation thereof.
[0022] Fifthly, embodiments of this application provide a chip, which includes a processor and a communication interface, the communication interface and the processor being coupled together. The processor is used to run computer programs or instructions to implement the method for downloading applets described in the first aspect and any possible implementation thereof.
[0023] In a sixth aspect, a computer program product containing instructions is provided that, when run on a computer, enables the computer to execute the method for downloading the applet described in the first aspect and any possible implementation thereof.
[0024] In this disclosure, the name of the device for downloading the app does not limit the device or functional module itself. In actual implementation, these devices or functional modules may appear under other names. As long as the function of each device or functional module is similar to that of this disclosure, it falls within the scope of the claims of this disclosure and its equivalents.
[0025] These or other aspects of this application will become more readily apparent in the following description.
[0026] The above solution offers at least the following advantages: In this application, the business management server, upon determining the security of the preset mini-program, requests the download of the preset mini-program package from the business server and requests the certificate of the preset mini-program from the certificate management server. Therefore, the certificate of the preset mini-program received by the business management server can characterize the security of the preset mini-program package. Consequently, when the business management server sends the preset mini-program package and certificate to the NCP, the NCP can determine the security of the preset mini-program package based on the certificate, and choose whether to send the preset mini-program package to the terminal device based on its security, thereby improving the security of the terminal device downloading mini-programs during a call. Attached Figure Description
[0027] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0028] Figure 1 This application provides a schematic diagram of the structure of a system for downloading mini-programs.
[0029] Figure 2 A schematic diagram of a device for downloading a mini-program provided in an embodiment of this application;
[0030] Figure 3 A flowchart illustrating a method for downloading a mini-program provided in this application embodiment;
[0031] Figure 4 A flowchart illustrating a method for downloading a mini-program provided in this application embodiment;
[0032] Figure 5 A flowchart illustrating a method for downloading a mini-program provided in this application embodiment;
[0033] Figure 6 A flowchart illustrating a method for downloading a mini-program provided in this application embodiment;
[0034] Figure 7 A flowchart illustrating a method for downloading a mini-program provided in this application embodiment;
[0035] Figure 8 A flowchart illustrating a method for downloading a mini-program provided in this application embodiment;
[0036] Figure 9 This is a schematic diagram of a new 5G communication architecture provided in an embodiment of this application;
[0037] Figure 10 A flowchart illustrating a method for downloading a mini-program provided in this application embodiment;
[0038] Figure 11 This is a schematic diagram of another device for downloading applets provided in an embodiment of this application. Detailed Implementation
[0039] In this article, the term "and / or" is merely a description of the relationship between related objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone.
[0040] The terms "first" and "second," etc., used in the specification and drawings of this application are used to distinguish different objects or to distinguish different treatments of the same object, rather than to describe a specific order of objects.
[0041] Furthermore, the terms "comprising" and "having," and any variations thereof, used in the description of this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the steps or units listed, but may optionally include other steps or units not listed, or may optionally include other steps or units inherent to such process, method, product, or apparatus.
[0042] It should be noted that in the embodiments of this application, the words "exemplary" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of the words "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.
[0043] In the description of this application, unless otherwise stated, "a plurality of" means two or more.
[0044] The following is a definition of the terms used in this application.
[0045] 1. New communication services
[0046] 5G new communication services, also known as 5G real-time communication services, refer to service innovations based on the operator's IP Multimedia Subsystem (IMS) network, enabling individuals to obtain immersive experiences and enterprises to improve user experience. These new communication services add a data channel (IMS DATA CHANNEL) to the existing IMS audio and video channels, enabling interactive information during calls and upgrading the user's call experience to a more immersive one. Currently, major operators are developing and piloting new communication services including caller ID cards and simultaneous interpretation, enriching the call experience and increasing the enjoyment of calls.
[0047] The above is an explanation of the terms used in this application.
[0048] 5G new communication services are characterized by high definition, visual connectivity, and interactivity. 5G new communications can utilize the data channels of the VoLTE / VoNR basic network to achieve high-definition, interactive, and immersive native video calls, enhancing the user experience.
[0049] In related technologies, under the new call system, terminal devices can download mini-programs from third-party business servers via a data channel. However, the current public network environment is rapidly changing and contains a large number of illegal mini-programs. Terminal devices may download illegal mini-programs from complex network environments, seriously affecting the security of mini-program downloads. Therefore, how to improve the security of mini-program downloads during terminal device calls remains a technical problem to be solved.
[0050] To address the technical problems existing in related technologies, this application addresses the issue that, upon determining the security of a pre-defined mini-program, the business management server requests the download of the mini-program package from the business server and requests the certificate of the pre-defined mini-program from the certificate management server. Therefore, the certificate of the pre-defined mini-program received by the business management server can characterize the security of the pre-defined mini-program package. Consequently, when the business management server sends the pre-defined mini-program package and certificate to the NCP, the NCP can determine the security of the pre-defined mini-program package based on the certificate and, based on the security of the pre-defined mini-program package, choose whether to send the pre-defined mini-program package to the terminal device, thereby improving the security of downloading mini-programs during calls.
[0051] The following, in conjunction with the appendix Figure 1 This application provides a detailed description of a system 10 for downloading mini-programs, as illustrated in the embodiments below. Figure 1As shown, the system 10 for downloading the mini-program includes: a business management server 11, a business server 12, a certificate management server 13, and an NCP 14.
[0052] The business management server 11 is configured to: send a first request message to the business server and request the certificate management server to issue a certificate for the preset mini-program; the first request message is used to request the download of the preset mini-program package, which is stored on the business server; receive the preset mini-program package and the certificate from the certificate management server; send the preset mini-program package and the certificate to the new communication control plane network element (NCP); and use the certificate to verify the security of the preset mini-program package.
[0053] Business server 12 is configured to: receive the first request information sent by business management server 11, and send the mini-program package of the preset mini-program to business management server 11.
[0054] Certificate management server 13 is configured to send the certificate of the preset applet to business management server 11.
[0055] NCP14 is configured to: receive the preset mini-program package and the preset mini-program certificate sent by the business management server 11, and receive the request information from the terminal device to download the preset mini-program package.
[0056] It should be noted that a terminal device is a device with wireless communication capabilities that can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted. It can also be deployed on water (such as on ships) or in the air (such as on airplanes, balloons, and satellites). Terminal devices are also known as mobile stations (MS), mobile terminals (MT), and terminals, and are devices that provide voice and / or data connectivity to users. For example, terminal device 12 includes handheld devices and vehicle-mounted devices with wireless connectivity. Currently, terminal device 12 can be: mobile phone, tablet computer, laptop computer, PDA, mobile internet device (MID), wearable device (e.g., smartwatch, smart bracelet, pedometer, etc.), in-vehicle device (e.g., car, bicycle, electric vehicle, airplane, ship, train, high-speed rail, etc.), virtual reality (VR) device, augmented reality (AR) device, wireless terminal in industrial control, smart home device (e.g., refrigerator, television, air conditioner, electricity meter, etc.), smart robot, workshop equipment, wireless terminal in self-driving, wireless terminal in remote medical surgery, wireless terminal in smart grid, wireless terminal in transportation safety, wireless terminal in smart city, or wireless terminal in smart home, flying device (e.g., smart robot, hot air balloon, drone, airplane), etc. In one possible application scenario of this application, the terminal device is a terminal device that frequently works on the ground, such as an in-vehicle device. In this application, for ease of description, the chip deployed in the above-mentioned device, such as a system-on-a-chip (SOC), a baseband chip, or other chip with communication functions, may also be referred to as a terminal device.
[0057] Optionally, the terminal device can be an embedded communication device or a user's handheld communication device, including mobile phones, tablets, etc.
[0058] As an example, in this embodiment, the terminal device can also be a wearable device. Wearable devices, also known as wearable smart devices, are a general term for devices that utilize wearable technology to intelligently design and develop everyday wearables, such as glasses, gloves, watches, clothing, and shoes. Wearable devices are portable devices that are worn directly on the body or integrated into the user's clothing or accessories. Wearable devices are not merely hardware devices; they achieve powerful functions through software support, data interaction, and cloud interaction. Broadly defined, wearable smart devices include those that are feature-rich, large in size, and can achieve complete or partial functionality without relying on a smartphone, such as smartwatches or smart glasses, as well as those that focus on a specific application function and require the use of other devices such as smartphones, such as various smart bracelets and smart jewelry for vital sign monitoring.
[0059] This embodiment provides a device for downloading a mini-program, which is applied to a system that executes the mini-program downloading method provided in this embodiment. Figure 2 This is a schematic diagram of a device for downloading a mini-program, provided as an embodiment of this application. Figure 2 As shown, the device 200 for downloading the app includes at least one processor 201, a communication line 202, and at least one communication interface 204, and may also include a memory 203. The processor 201, memory 203, and communication interface 204 can be connected via the communication line 202.
[0060] The processor 201 may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of this application, such as one or more digital signal processors (DSPs), or one or more field-programmable gate arrays (FPGAs).
[0061] Communication line 202 may include a path for transmitting information between the aforementioned components.
[0062] The communication interface 204 is used to communicate with other devices or communication networks and can use any transceiver-like device, such as Ethernet, radio access network (RAN), WLAN, etc.
[0063] The memory 203 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of including or storing desired program code having the form of instructions or data structures and accessible by a computer, but not limited thereto.
[0064] In one possible design, the memory 203 can exist independently of the processor 201, meaning the memory 203 can be an external memory of the processor 201. In this case, the memory 203 can be connected to the processor 201 via the communication line 202 to store execution instructions or application code, and its execution is controlled by the processor 201 to implement the method for downloading applets provided in the following embodiments of this application. In another possible design, the memory 203 can also be integrated with the processor 201, meaning the memory 203 can be an internal memory of the processor 201. For example, the memory 203 can be a cache, which can be used to temporarily store some data and instruction information.
[0065] As one possible implementation, processor 201 may include one or more CPUs, for example Figure 2 CPU0 and CPU1 in the example. Alternatively, the device 200 for downloading the app may include multiple processors, such as... Figure 2 The processors 201 and 207 are included. Alternatively, the device 200 for downloading the app may also include an output device 205 and an input device 206.
[0066] The following, in conjunction with the appendix Figure 3 The method for downloading a mini-program provided in the embodiments of this application will be described in detail, such as... Figure 3 As shown, the methods for downloading the mini-program include:
[0067] S301. After confirming the security of the preset mini-program, the business management server sends a first request to the business server and requests the certificate management server to issue a certificate for the preset mini-program.
[0068] The first request information is used to request the download of the preset mini-program package, which is stored on the business server.
[0069] In one possible implementation, in response to the mini-program package download request, the business management server, after determining that the preset mini-program is secure, sends a first request message to the business server through the Application Data Channel (ADC); the business management server then sends a request message to the certificate management server through the ADC, the request message being used to request the issuance of a certificate for the preset mini-program.
[0070] It should be explained that the ADC can be established between the calling terminal device and the called terminal device, or between the calling terminal device and the IMS network, and is used to transmit application data of the data channel application between the two ends of the device.
[0071] Understandably, the business management server can analyze the information of the mini-program package to be downloaded in the mini-program package download request to determine whether the preset mini-program is safe.
[0072] S302. The business management server receives the mini-program package of the preset mini-program sent from the business server and the certificate of the preset mini-program sent from the certificate management server.
[0073] The certificate for the preset mini-program includes the mini-program's identification information and validity information.
[0074] Optional, valid information may include time information or number of times the data was parsed.
[0075] It's important to explain that whenever a device accesses the content of a pre-defined mini-program's certificate, the certificate records the number of times it is parsed. If the number of parsed instances exceeds a first threshold, the certificate may have been illegally stolen, and the pre-defined mini-program's certificate is considered invalid. The pre-defined mini-program's certificate also records its valid usage period. If the current time is outside this period, the pre-defined mini-program's certificate is considered invalid.
[0076] S303. The business management server sends the preset mini-program package and the preset mini-program certificate to the NCP.
[0077] The certificate of the preset mini-program is used to verify the security of the mini-program package of the preset mini-program.
[0078] In one possible implementation, when the mini-program package download request is a data channel (DC) call request, the service management server sends the pre-set mini-program package and the pre-set mini-program certificate to the new calling platform (NCP).
[0079] It's important to explain that after receiving the certificate for a pre-installed mini-program, the NCP can determine that the mini-program package is secure. Therefore, the NCP can directly send the pre-installed mini-program package to the terminal device and / or store it in the application list. This allows the terminal device to directly download the pre-installed mini-program from the application list according to its own needs.
[0080] Optionally, the list of downloadable applications includes the name of at least one mini-program and the mini-program package of at least one mini-program.
[0081] The above solution offers at least the following advantages: In this embodiment, the business management server, upon determining the security of the preset mini-program, requests the download of the preset mini-program package from the business server and requests the certificate of the preset mini-program from the certificate management server. Therefore, the certificate of the preset mini-program received by the business management server can characterize the security of the preset mini-program package. In this way, when the business management server sends the preset mini-program package and certificate to the NCP, the NCP can determine the security of the preset mini-program package based on the certificate, and choose whether to send the preset mini-program package to the terminal device based on its security, thereby improving the security of the terminal device downloading mini-programs during a call.
[0082] In one possible implementation, combining Figure 3 ,like Figure 4 As shown, before the business management server sends the first request information to the business server and requests the certificate management server to issue the certificate for the preset mini-program in S301 above, the business management server determines the business server. The process of the business management server determining the business server can be specifically implemented through the following S401-S402.
[0083] S401, The business management server receives the second request information from the NCP.
[0084] The second request information is used to request the download of a preset mini-program.
[0085] It needs to be explained that when the calling terminal device and the called terminal device establish a voice call, a Bootstrap Data Channel (BDC) is also established. The calling terminal device downloads the application list through the BDC. The calling terminal device can download mini-programs from the NCP based on the identification information of the mini-programs in the application list. When the identification information of a preset mini-program is not found in the application list, the NCP requests information from the service management server.
[0086] It should be noted that BDC is the process of establishing a data channel between the terminal device and the IMS network.
[0087] Optionally, the second request information includes the identifier information of the preset mini-program, the "a=content" field, and the 3gpp-qos-hint field. The 3gpp-qos-hint field contains two Automatic Voice Processing (AVP) parameters: loss and latency. The loss is the initial packet loss rate of the mini-program, and the latency is the initial delay of the mini-program. The 3gpp-qos-hint field is also used to indicate the establishment of an ADC between the calling terminal and the called terminal.
[0088] It should be explained that when the "a=content" field is unicom.webrtc-datachannel.adc, the NCP receives a DC call from the terminal device.
[0089] S402. The business management server determines the business server based on the identifier information and application rules of the preset mini-program in the second request information.
[0090] The application rules include at least one mini-program's identification information and at least one business server corresponding to the mini-program's identification information.
[0091] In one possible implementation, the business management server parses the second request information to obtain the identification information of the preset mini-program; based on the identification information of the preset mini-program and the application rules, it determines the device information of the business server.
[0092] Optionally, the device information of the business server includes at least one of the following: the identification (ID) of the business server, the capacity of the business server, the resource usage of the business server, the remaining resource of the business server, and the network interconnection protocol (Internet Protocol, IP) of the business servers.
[0093] The above solution offers at least the following advantages: In this embodiment, the NCP receives a mini-program download request from a terminal device and sends a second request message to the business management server. Since the business management server determines the business server based on the identifier information and application rules of the preset mini-program in the second request message, the business management server can send a first request message to the business server storing the mini-program package containing the preset mini-program, thus improving the download efficiency of the mini-program.
[0094] In one possible implementation, combining Figure 4 ,like Figure 5 As shown, in S402, after the business management server determines the business server based on the preset mini-program identification information and application rules in the second request information, the business management server modifies the first request information. The process of the business management server modifying the first request information can be specifically implemented through the following S501-S502.
[0095] S501. The business management server determines the first key corresponding to the preset mini-program based on the identifier information and application rules of the preset mini-program in the second request information.
[0096] The application rules also include a key corresponding to the identification information of at least one mini-program.
[0097] In one possible implementation, after the business management server retrieves the application rules from the storage unit, it determines the first key corresponding to the preset mini-program based on the identifier information of the preset mini-program and the application rules.
[0098] It should be noted that the storage unit can be located in the business management server or outside the business management server, and this application does not impose any further restrictions on this.
[0099] In another possible implementation, after the business management server determines the second key corresponding to the preset mini-program, it determines the first time-limited information based on the identification information of the preset mini-program, and adds the first time-limited information to the second key to obtain the first key.
[0100] It should be explained that, since the first key includes first validity information, the business management service can specify the validity of the first key to improve the accuracy of NCP's use of the first key.
[0101] S502, The business management server adds the first key to the first request information.
[0102] The first key is used to verify the validity of the first request information.
[0103] In one possible implementation, the business management server adds a first key to the header of the first message. The first message carries the first request information. Thus, when the NCP receives the first message from the business management server, it can preferentially parse the first key within the message and verify the validity of the first request information based on the first key. If the validity verification of the first request information fails, the first message can be discarded promptly. The NCP does not need to parse the entire content of the first message, avoiding resource waste and improving the download efficiency of the mini-program package.
[0104] In another possible implementation, the business management server adds the first key to the first request information based on preset rules.
[0105] Optionally, the preset rule can be an encryption rule.
[0106] It should be explained that the business management server adds the first key to the first request information. This allows the business server to verify the legitimacy of the first request information based on the first key. If the first request information passes the legitimacy verification, the pre-defined mini-program package can be sent to the business server; if the first request information fails the legitimacy verification, the sending of the pre-defined mini-program package to the business server will be refused, thus improving the security of mini-program downloads.
[0107] The above solution brings at least the following beneficial effects: In this embodiment of the application, the business management server determines and sends a first key to the business server, so that after the business server receives the first request information, it can verify the legality of the first request information based on the first key, thereby improving the security of the mini-program download.
[0108] In one possible implementation, combining Figure 3 ,like Figure 6 As shown, the process of the business management server sending the first request information to the business server and requesting the certificate management server to issue the certificate for the preset applet can be specifically implemented through the following S601-S602.
[0109] S601. The business management server determines the initial packet loss rate and initial latency of the preset mini-program based on the identification information and application rules of the preset mini-program in the second request information.
[0110] The application rules include the identification information of at least one mini-program, the initial packet loss rate and initial latency corresponding to the identification information of at least one mini-program.
[0111] In one possible implementation, the business management server obtains the type of the preset mini-program, and determines the initial packet loss rate and initial latency of the preset mini-program based on the identification information, application rules, and type of the preset mini-program.
[0112] It should be noted that different types of mini-programs have different initial packet loss rates and initial latency.
[0113] For example, the initial packet loss rate and initial latency of game-type mini-programs are lower than those of video-type mini-programs; the initial packet loss rate and initial latency of video-type mini-programs are lower than those of audio-type mini-programs; the initial packet loss rate and initial latency of audio-type mini-programs are lower than those of image-type mini-programs; and the initial packet loss rate and initial latency of image-type mini-programs are lower than those of text-type mini-programs.
[0114] S602. The business management server sends the first request information and negotiation request information to the business server, and requests the certificate management server to issue the certificate for the preset applet.
[0115] The negotiation request information includes the initial packet loss rate and initial latency of the preset mini-program; the negotiation request information is used to negotiate the packet loss rate and latency of the preset mini-program.
[0116] It should be explained that the business server stores the mini-program package of the preset mini-program, which allows for a clearer understanding of the packet loss rate and latency requirements of the preset mini-program. Therefore, the business server can determine the negotiated packet loss rate and negotiated latency of the preset mini-program based on its initial packet loss rate and initial latency, thus more accurately determining the required packet loss rate and latency of the preset mini-program.
[0117] The above solution brings at least the following beneficial effects: In this embodiment of the application, the service management server determines and sends the initial packet loss rate and initial latency of the preset applet to the service server, so that the service server and the service management server can negotiate the packet loss rate and latency of the preset applet and provide suitable network resources for the terminal device.
[0118] In one possible implementation, combining Figure 6 ,like Figure 7 As shown, the process of the business management server receiving the mini-program package of the preset mini-program sent from the business server and the certificate of the preset mini-program sent from the certificate management server in S302 can be specifically implemented through the following S701.
[0119] S701, the business management server receives the mini-program package of the preset mini-program sent by the business server, the negotiation response information, and the certificate of the preset mini-program sent by the certificate management server.
[0120] The negotiation response information includes the negotiated packet loss rate and the negotiated latency of the preset mini-program. The negotiated packet loss rate of the preset mini-program is obtained by the business management server and the business server based on the initial packet loss rate of the preset mini-program. The negotiated latency of the preset mini-program is obtained by the business management server and the business server based on the initial latency of the preset mini-program.
[0121] Optionally, the default negotiation packet loss rate of the mini program is LOSS rev, and the default negotiation latency of the mini program is latencyrev.
[0122] The above solution brings at least the following beneficial effects: In this embodiment, when the service management server receives the mini-program package and certificate of the preset mini-program, it can also receive negotiation response information. Since the negotiation response information includes the negotiation packet loss rate and negotiation latency of the preset mini-program, the packet loss rate and latency of the preset mini-program can be determined more accurately, thus providing suitable network resources for the terminal device.
[0123] In one possible implementation, combining Figure 7 ,like Figure 8 As shown, after the business management server sends the pre-defined mini-program package and certificate to the NCP in S303, the business management server sends the pre-defined mini-program's file information to the UMF. The process of the business management server sending the pre-defined mini-program's file information to the UMF can be specifically implemented through the following S801.
[0124] S801, the business management server sends the file information of the preset applet to the UMF via NCP.
[0125] The archive information includes: the packet loss rate and negotiation latency of the preset mini-program; the archive information is used to determine the communication service quality level of the preset mini-program.
[0126] It needs to be explained that after the service management server sends the file information of the preset applet to the new unified media plane network element (UMF) via NCP, the UMF can, for example, Figure 9 Interface 2, as shown, sends the profile information of the preset mini-program to the Policy Control Function (PCF) in the 5G network. Based on the profile information of the preset mini-program, the PCF can determine the communication service quality level of the preset mini-program, thereby dynamically configuring the quality of service (QoS) parameters in the preset mini-program network to enable communication of the preset mini-program.
[0127] The above solution brings at least the following beneficial effects: In this embodiment of the application, the service management server sends the file information of the preset applet to the UMF through NCP. Since the file information includes the negotiation packet loss rate and negotiation latency of the preset applet, the UMF can send the negotiation packet loss rate and negotiation latency of the preset applet to the PCF, so that the PCF can provide more accurate network resources for the preset applet in the terminal device.
[0128] The following, in conjunction with the appendix Figure 10 The method for downloading a mini-program provided in the embodiments of this application will be described in detail, such as... Figure 10 As shown, the methods for downloading the mini-program include:
[0129] S1001, BDC for establishing a voice call between the calling terminal equipment and the called terminal equipment.
[0130] S1002, The calling terminal device downloads the application list from the NCP.
[0131] In one possible implementation, the calling terminal device downloads the application list from the NCP via the BDC.
[0132] S1003, The calling terminal device downloads the application to the NCP.
[0133] In one possible implementation, the calling terminal device downloads the application to the NCP via the BDC.
[0134] S1004. The calling terminal equipment and the called terminal equipment establish an ADC.
[0135] S1005, NCP sends a second request to the business management server.
[0136] In one possible implementation, the NCP searches for the preset mini-program in the application list. If the identifier information of the preset mini-program is not found in the application list, it requests information from the business management server.
[0137] S1006, The business management server sends the first request information to the third-party application server.
[0138] The first request information includes the first key corresponding to the preset mini-program.
[0139] S1007. The business management server receives the mini-program package of the preset mini-program sent by the third-party application and the certificate of the preset mini-program sent by the certificate management server.
[0140] S1008. The business management server sends the preset mini-program package and the preset mini-program certificate to the NCP.
[0141] S1009. The preset applet in the calling user equipment communicates via ADC.
[0142] In one possible implementation, after the pre-installed mini-program on the calling user's device is launched, it can send a joint game request to the called user's device and connect to the game server together.
[0143] The above solution offers at least the following advantages: In this application, the business management server, upon determining the security of the preset mini-program, requests the download of the preset mini-program package from the business server and requests the certificate of the preset mini-program from the certificate management server. Therefore, the certificate of the preset mini-program received by the business management server can characterize the security of the preset mini-program package. Thus, when the business management server sends the preset mini-program package and certificate to the NCP, the NCP can determine the security of the preset mini-program package based on the certificate, and choose whether to send the preset mini-program package to the terminal device based on its security, thereby improving the security of the terminal device downloading the mini-program during a call. After the terminal device downloads the preset mini-program, it can launch the mini-program and communicate normally.
[0144] As can be seen, the above mainly describes the technical solutions provided by the embodiments of this application from a methodological perspective. To achieve the above functions, it includes hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should readily recognize that, in conjunction with the modules and algorithm steps of the various examples described in the embodiments disclosed herein, the embodiments of this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this invention.
[0145] This application embodiment can divide the device for downloading mini-programs into functional modules based on the above method example. For example, each function can be divided into its own functional module, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. Optionally, the module division in this application embodiment is illustrative and only represents one logical functional division; other division methods may be used in actual implementation.
[0146] like Figure 11 The diagram shown is a structural schematic of a device 110 for downloading mini-programs according to an embodiment of this application. The device 110 for downloading mini-programs includes a processing unit 1101 and a communication unit 1102.
[0147] Processing unit 1101 is configured to send a first request message to the business server and request the certificate management server to issue a certificate for the preset mini-program when the security of the preset mini-program is determined; the first request message is used to request the download of the mini-program package of the preset mini-program, and the business server stores the mini-program package of the preset mini-program; communication unit 1102 is further configured to receive the mini-program package of the preset mini-program sent from the business server and the certificate of the preset mini-program sent from the certificate management server; communication unit 1102 is further configured to send the mini-program package of the preset mini-program and the certificate of the preset mini-program to NCP; the certificate of the preset mini-program is used to verify the security of the mini-program package of the preset mini-program.
[0148] Optionally, the communication unit 1102 is further configured to receive a second request information from the NCP; the second request information is used to request the download of a preset applet; the processing unit 1101 is further configured to determine the business server based on the identification information of the preset applet and the application rules in the second request information; the application rules include the identification information of at least one applet and the business server corresponding to the identification information of at least one applet.
[0149] Optionally, the processing unit 1101 is further configured to determine the first key corresponding to the preset mini-program based on the identification information and application rules of the preset mini-program in the second request information; the application rules also include the key corresponding to the identification information of at least one mini-program; the processing unit 1101 is further configured to add the first key to the first request information; the first key is used to verify the validity of the first request information.
[0150] Optionally, the processing unit 1101 is further configured to determine the initial packet loss rate and initial latency of the preset mini-program based on the identification information and application rules of the preset mini-program in the second request information; the application rules include the identification information of at least one mini-program, and the initial packet loss rate and initial latency corresponding to the identification information of at least one mini-program; the processing unit 1101 is further configured to send the first request information and negotiation request information to the business server when the security of the preset mini-program is determined, and request the certificate management server to issue a certificate for the preset mini-program; the negotiation request information includes the initial packet loss rate and initial latency of the preset mini-program; the negotiation request information is used to negotiate the packet loss rate and latency of the preset mini-program.
[0151] Optionally, the communication unit 1102 is further configured to receive a mini-program packet, negotiation response information, and a certificate of the preset mini-program sent by the certificate management server; the negotiation response information includes the negotiation packet loss rate and negotiation latency of the preset mini-program; the negotiation packet loss rate of the preset mini-program is negotiated between the business management server and the business server based on the initial packet loss rate of the preset mini-program; the negotiation latency of the preset mini-program is negotiated between the business management server and the business server based on the initial latency of the preset mini-program.
[0152] Optionally, the communication unit 1102 is also used to send the profile information of the preset applet to the UMF via NCP; the profile information includes: the negotiation packet loss rate of the preset applet and the negotiation delay of the preset applet; the profile information is used to determine the communication service quality level of the preset applet.
[0153] Optionally, the certificate for the preset mini-program includes the preset mini-program's identification information and validity information.
[0154] The processing unit 1101 can be a processor or a controller. It can implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. The processor can also be a combination of functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc. The communication unit 1102 can be a transceiver circuit or a communication interface, etc. The storage module can be a memory. When the processing unit 1101 is a processor, the communication unit 1102 is a communication interface, and the storage module is a memory, the device for downloading a small program involved in the embodiments of this application can be... Figure 2 The device shown is for downloading mini-programs.
[0155] Through the above description of the implementation methods, those skilled in the art will clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the network node can be divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, modules, and network nodes described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0156] This application also provides a computer-readable storage medium storing instructions. When a computer executes these instructions, the computer performs each step of the method flow shown in the above-described method embodiments.
[0157] This application also provides a chip, which includes a processor and a communication interface. The communication interface and the processor are coupled. The processor is used to run computer programs or instructions to implement the method of downloading applets in the above method embodiments.
[0158] Embodiments of this application provide a computer program product containing instructions that, when executed on a computer, cause the computer to perform the method for downloading a small program as described in the above method embodiments.
[0159] The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of computer-readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), registers, hard disks, optical fibers, compact disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing, or any other form of computer-readable storage medium in the art. An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium may also be a component of the processor. The processor and the storage medium may reside in an application-specific integrated circuit (ASIC). In embodiments of the present invention, a computer-readable storage medium may be any tangible medium that contains or stores a program that may be used by or in conjunction with an instruction execution system, apparatus, or device.
[0160] Since the apparatus, device, computer-readable storage medium, and computer program product in the embodiments of the present invention can be applied to the above methods, the technical effects that can be obtained can also be referred to the above method embodiments. The embodiments of this application will not be repeated here.
[0161] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method of downloading an applet, characterized by, The method is applied to a scenario of a new communication service call, and comprises the following steps: receiving second request information from a control plane network element (NCP); the second request information is used to request downloading a preset applet; determining a service server based on identification information of the preset applet in the second request information and an application rule; the application rule comprises identification information of at least one applet and a service server corresponding to the identification information of the at least one applet; determining a first key corresponding to the preset applet based on the identification information of the preset applet in the second request information and the application rule; the application rule further comprises a key corresponding to the identification information of the at least one applet; adding the first key into first request information; the first key is used to verify validity of the first request information; in a case where the preset applet is determined to be safe, sending the first request information to the service server and requesting a certificate management server to issue a certificate of the preset applet; the first request information is used to request downloading an applet package of the preset applet, and the service server stores the applet package of the preset applet; receiving the applet package of the preset applet sent by the service server and the certificate of the preset applet sent by the certificate management server; sending the applet package of the preset applet and the certificate of the preset applet to a new communication NCP; the certificate of the preset applet is used to verify safety of the applet package of the preset applet.
2. The method of claim 1, wherein, The step of, in a case where the preset applet is determined to be safe, sending the first request information to the service server and requesting the certificate management server to issue the certificate of the preset applet, comprises the following steps: determining an initial packet loss rate and an initial delay of the preset applet based on the identification information of the preset applet in the second request information and the application rule; the application rule comprises identification information of at least one applet, an initial packet loss rate and an initial delay corresponding to the identification information of the at least one applet; in a case where the preset applet is determined to be safe, sending the first request information and negotiation request information to the service server and requesting the certificate management server to issue the certificate of the preset applet; the negotiation request information comprises the initial packet loss rate and the initial delay of the preset applet; the negotiation request information is used to negotiate a packet loss rate and a delay of the preset applet.
3. The method of claim 2, wherein, The step of receiving the applet package of the preset applet sent by the service server and the certificate of the preset applet sent by the certificate management server comprises the following steps: receive the preset applet package and the certificate of the preset applet sent by the certificate management server; the negotiation response information includes a negotiation packet loss rate of the preset applet and a negotiation time delay of the preset applet; the negotiation packet loss rate of the preset applet is obtained by the certificate management server and the service server based on an initial packet loss rate of the preset applet; and the negotiation time delay of the preset applet is obtained by the certificate management server and the service server based on an initial time delay of the preset applet.
4. The method of claim 3, wherein, After the preset applet package and the certificate of the preset applet are sent to the NCP, the method further includes: sending, by the NCP, profile information of the preset applet to a new communication unified media plane network element (UMF); the profile information includes the negotiation packet loss rate of the preset applet and the negotiation time delay of the preset applet; and the profile information is used to determine a communication service quality level of the preset applet.
5. The method according to any one of claims 1 to 4, characterized in that, The certificate of the preset applet includes identification information and validity information of the preset applet.
6. An apparatus for downloading an applet, characterized by The apparatus includes a processing unit and a communication unit. The processing unit is configured to receive second request information from a control plane network element (NCP); the second request information is used to request to download a preset applet. Based on the identification information of the preset applet in the second request information and an application rule, a service server is determined; the application rule includes identification information of at least one applet and a key corresponding to the identification information of the at least one applet. Based on the identification information of the preset applet in the second request information and the application rule, a first key corresponding to the preset applet is determined; the application rule further includes the key corresponding to the identification information of the at least one applet. The first key is added to the first request information. The first key is used to verify validity of the first request information. In a case where the preset applet is determined to be safe, the first request information is sent to the service server, and a certificate management server is requested to issue a certificate of the preset applet. The first request information is used to request to download an applet package of the preset applet; and the service server stores the applet package of the preset applet. The communication unit is further configured to receive the applet package of the preset applet sent by the service server and the certificate of the preset applet sent by the certificate management server. The communication unit is further configured to send, to the NCP, the applet package of the preset applet and the certificate of the preset applet; and the certificate of the preset applet is used to verify security of the applet package of the preset applet.
7. An apparatus for downloading an applet, characterized by The apparatus includes a processor and a memory; the memory is used to store computer execution instructions; when the apparatus for downloading an applet is running, the processor executes the computer execution instructions stored in the memory, so that the apparatus for downloading an applet executes the method for downloading an applet in any one of claims 1-5. 8. A computer-readable storage medium, characterized in that, The computer readable storage medium comprises instructions which, when executed by the applet downloading device, cause the computer to perform the method of any of claims 1-5.
Citation Information
Patent Citations
Service management method, device and system thereof, electronic equipment and storage medium
CN116406028A
Authority management method and device, target equipment and medium
CN116910736A