Mobile terminal containerization method and system
By building a global APP container in mobile applications, access barriers, impaired user experience, security and compliance issues caused by external links and third-party application embeddings, and failures in native function calls are solved, achieving higher user experience and security.
Patent Information
- Application Number
- CN202510276025.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-10
- Publication Date
- 2025-06-27
AI Technical Summary
In a mobile application environment, the embedding of external links and third-party applications leads to access barriers, impaired user experience, security and compliance issues, and failure of native feature calls.
By building a global APP container, unified management and processing of external links and third-party applications are realized. The container is automatically registered and initialized when the APP is started, and is responsible for domain name legality verification, content preloading and security detection, user authorization requests, and native capability calls and forwarding.
It effectively solves the problems of access barriers and impaired user experience, enhances security and compliance, improves the success rate of native capability calls, and improves the usability of user experience and applications.
Smart Images

Figure CN120216097A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of mobile terminals and mobile application (APP) development, specifically to mobile terminal container technology, and particularly to methods and systems for mobile terminal containerization. Background Art
[0002] When embedding external links or third-party applications in a mobile application (APP) environment, a series of technical challenges and user experience problems are faced. Specifically, without proper processing, such content cannot be accessed normally, because there is a lack of an effective "container" mechanism to carry and parse these external resources. This defect causes error messages to appear when users try to access, significantly reducing the user experience.
[0003] Furthermore, if an external link or third-party application needs to call the native functions of a device, such as "camera shooting", "geographical location positioning", and "audio recording", it is also not feasible to directly access these underlying system capabilities. For this reason, many existing technologies provide mediation mechanisms to achieve the forwarding and adaptation of the underlying capabilities of the mobile phone system. For example:
[0004] CN202311303311.0 discloses a method for containerizing mobile terminal components and an APP container system (publication date: November 10, 2023); CN202310134022.6 discloses a containerization-based SAAS application resource management system (publication date: August 25, 2023); CN202110243800.6Web discloses a communication method between a web end and a mobile terminal, a mobile terminal, and a system (publication date: March 5, 2021); CN202211352527.1 discloses a method and device for automatically assembling mobile terminal pages (publication date: February 3, 2021); the above solutions are all based on mediation mechanisms to ensure that external links and third-party applications can smoothly utilize these functions, thus ensuring the fluency and functionality of user access.
[0005] However, there are several core problems in current technical practices:
[0006] (1) Access barriers and impaired user experience: Due to the lack of an effective integration strategy for the numerous external links and third-party applications frequently embedded in an APP, users frequently encounter errors when trying to access, which has a serious negative impact on the user experience.
[0007] (2) Security and compliance issues: The embedding of external links and third-party applications introduces illegal or non-compliant content, such as malicious links or unauthorized user information collection behaviors, which not only threatens user data security but also leads to legal and compliance risks.
[0008] (3) Native function call failure: When an external link or a third-party application needs to call the native capabilities of the mobile phone system, due to the lack of appropriate call interfaces or permission management, the function often fails to work properly, leading to page errors and further damaging the user experience.
[0009] To this end, the present invention proposes a method and system for mobile containerization. Summary of the Invention
[0010] In view of this, the present invention aims to provide a method and system for mobile containerization to solve or alleviate the technical problems existing in the prior art, namely, how to solve the access barriers and damaged user experience based on an integration strategy, and at the same time, when an external link or a third-party application needs to call the native capabilities of the mobile phone system, how to appropriately adjust the call interface or permission management to avoid native function call failure, and also meet the security and compliance issues. The technical solution of the present invention is implemented as follows:
[0011] In the first aspect, a method for mobile containerization:
[0012] (1) Overview:
[0013] The present invention aims to construct a global "APP container" as the core component for processing access requests from external links and third-party applications. By automatically registering and initializing this container when the APP is launched, it is ensured that it can manage the user's access behavior in real-time and effectively. The solution emphasizes the importance of security, and through multiple mechanisms such as domain name legitimacy verification, content preloading, and security detection, it strictly checks the security of external links and third-party applications to prevent users from being attacked by malicious programs or exposed to bad information. At the same time, the solution also pays attention to the user experience. Through the step of user authorization request, the user can independently decide whether to continue the access, ensuring the user's right to know and the right to choose. In addition, the solution also realizes the call and forwarding of native capabilities, enabling external links and third-party applications to smoothly use the native functions of the mobile phone system, improving the usability and convenience of the application.
[0014] (2) Technical solution:
[0015] To achieve the above technical goals, the solution selected by the present invention is as described below. When implementing this solution, first, based on the given relevant solution activation instruction input by the user when launching the APP (that is, opening the APP to trigger the mechanism for automatically registering the global APP container), the following operation steps can be executed.
[0016] 2.1 Step S1, container registration:
[0017] When the APP is launched, it automatically detects and executes the registration program of the global APP container; after the registration is completed, the APP container is initialized to prepare for receiving and processing access requests from external links and third-party applications;
[0018] When the user clicks on an external link or attempts to access a third - party application within the APP, the request sent is redirected to the global APP container, and step S2 begins to execute.
[0019] 2.1.1 Step S100, Container Initialization:
[0020] Perform initialization settings on the global APP container, including loading configuration files, initializing data structures, and preparing interfaces with external systems.
[0021] Ensure that the global APP container is in a ready - to - go state before receiving and processing requests, capable of efficiently handling various access requests.
[0022] 2.1.2 Step S101, Request Redirection:
[0023] The execution timing is: when the user clicks on an external link or attempts to access a third - party application within the APP.
[0024] The operation content is: through the redirection mechanism, redirect the request sent by the user to the global APP container. This step is crucial to ensure that all access requests for external links and third - party applications can be uniformly processed through the global APP container, so as to perform subsequent domain name legality verification, content pre - loading and security detection, user authorization, and native capability invocation and other operations.
[0025] The redirection mechanism is divided into the following types according to the type:
[0026] (1) HTTP Redirection: It is achieved by using specific status codes and Location headers in the HTTP response. Such as status codes or Location headers:
[0027] (1.1) Status Codes:
[0028] 1) 301 Moved Permanently: Permanent redirection. It means that the requested resource has been permanently moved to a new location, and all future requests for this resource should use the new URL. Search engines will update the index and replace the old URL with the new one;
[0029] 2) 302 Found: Temporary redirection. It means that the requested resource is temporarily responding to the request from a different URI, but the user agent (such as a browser) should continue to use the original URI for subsequent requests;
[0030] 3) 303 See Other: Mainly used for the scenario of redirecting to a GET request after a POST or PUT request, telling the client to use the GET method to obtain the resource;
[0031] 4) 307 Temporary Redirect: Similar to 302, but requires the client to keep the request method unchanged in subsequent requests.
[0032] (1.2) Location Header: Include a Location header in the HTTP response, whose value points to the new URL address. After receiving the redirect response, the browser will automatically send a request to the new URL.
[0033] (2) Server-Side Redirect: Implemented based on the server configuration file, such as using the.htaccess file or the main configuration file httpd.conf to configure the redirect rules. Or use the rewrite directive or return directive in the nginx.conf configuration file to achieve redirection.
[0034] (3) Client-Side Redirect: Not the preferred method (because it depends on client support and is not as efficient as server-side redirect), but still useful in some cases (such as JavaScript redirect).
[0035] (3.1) HTML meta Element: Add the <meta> element in the part of the HTML document, and use the http-equiv="refresh" attribute to set the redirection. For example, <meta http-equiv="Refresh"content="0;URL=http: example.com "> .
[0036] (3.2) JavaScript: Trigger the redirection by modifying the window.location object or
[0037] the window.location.href attribute. For example, window.location =
[0038] 'http: / / example.com / '; or window.location.href = 'http: / / example.com / ';.
[0039] (4) Cloud Service Redirection: Implement redirection based on the built-in redirection module of the cloud server. For example, AWS's CloudFront, Azure's CDN, etc. all provide similar functions.
[0040] 2.2 Step S2, Domain Name Legality Verification:
[0041] The APP container extracts the domain name information of the external link or third-party application; matches it with the domain name whitelist configured in the background to verify the legality of the domain name; if the legality passes, execute Step S3; if the legality fails, enter Step S4.
[0042] 2.2.1 Step S200, Extract domain name information:
[0043] The execution timing is: when the user clicks an external link or tries to access a third - party application within the APP, the APP container receives a redirected request.
[0044] The operation content is: The APP container parses the URL from the request and extracts the domain name information of the external link or third - party application. This provides the basic data for subsequent matching with the domain name whitelist configured in the background.
[0045] 2.2.2 Step S201, Match with the domain name whitelist:
[0046] The execution timing is: after the domain name information is extracted;
[0047] The operation content is: The APP container matches the extracted domain name information with the domain name whitelist configured in the background through string comparison or regular expressions to verify whether the domain name is within the allowed range, that is, whether it belongs to the known and trustworthy domain name list.
[0048] 2.2.3 Step S202, Verify legality:
[0049] The execution timing is: after the domain name and the whitelist are matched.
[0050] The operation content is: According to the matching result, judge the legality of the domain name. If the domain name is in the whitelist, the domain name is considered legal; otherwise, the domain name is considered illegal.
[0051] 2.3 Step S3, Pre - load and detection:
[0052] The APP container pre - loads the page content of the external link or relevant data of the third - party application to the local; starts the security detection program (semantic detection algorithm and image detection algorithm) of the APP container to scan the pre - loaded content and check for security risks such as sensitive words and illegal images; if no security risks are found, go to Step S5; if security risks are found, go to Step S4.
[0053] 2.3.1 Step S300, Start the security detection program:
[0054] The execution timing is: after the content pre - loading is completed.
[0055] The operation content is: The APP container starts the built - in security detection program, including the existing semantic detection algorithm and image detection algorithm, to comprehensively scan the pre - loaded content. Check whether there are security risks such as sensitive words and illegal images in the pre - loaded content.
[0056] 2.3.2 Step S301, Judge security risks:
[0057] The execution time is: after the content scan is completed.
[0058] The operation is to determine whether there are security risks in the preloaded content based on the scanning results of the security detection program. If no security risk is found, the content is considered safe; if a security risk is found, the content is considered unsafe. The subsequent processing flow is determined based on the security risk judgment result.
[0059] 2.4 Step S4, user authorization request:
[0060] The APP container sends a request instruction to the user to confirm whether to continue access; if the instruction is agreed, step S5 is performed; if the instruction is rejected, access to the APP is terminated, the user is prompted with corresponding information, and the native capabilities of the APP are disabled.
[0061] 2.4.1 Step S400, sending a user authorization request:
[0062] The execution time is: when the domain name legitimacy check in step S2 fails, or when the preloading and detection in step S3 finds a security risk.
[0063] The operation content is: the APP container sends a clear request instruction to the user, asking the user whether he is willing to continue to access the external link or third-party application. This request is usually presented in the form of a pop-up window, dialog box or full-screen notification, containing necessary warning information and risk reminders for continued access. Let the user understand the risks of the current access and seek the user's explicit consent to respect the user's right to know and right to choose.
[0064] 2.4.2 Step S401, processing user response:
[0065] The execution time is: the user responds after receiving the authorization request.
[0066] The operation content is: if the user agrees to continue access, the APP container records the user's choice and prepares to execute the next step (step S5). If the user refuses to continue access, the APP container immediately terminates access to the current external link or third-party application and displays a corresponding prompt message to the user, indicating that access has been blocked. That is, according to the user's wishes, it decides whether to continue accessing the risky link or application to ensure that the user's security and privacy are protected.
[0067] 2.4.3 Step S402: disable the native capabilities of the APP:
[0068] The execution time is: when the user refuses to continue access and some native capabilities of the app need to be disabled according to business logic.
[0069] The operation content is as follows: The APP container disables the APP native capabilities related to the current access according to the preset logic, including network requests and file access. This is to prevent users from accessing risky content through other means without their knowledge. Further enhance the security protection measures to ensure that after the user refuses access, they will not bypass the security restrictions through other functions of the APP.
[0070] 2.5 Step S5, Native Capability Invocation and Forwarding:
[0071] If an external link or a third-party application needs to use the native capabilities of the mobile system, the APP container uniformly invokes the native capabilities according to the integration rules and forwards them to the external link or the third-party application to enable the normal realization of the APP native capabilities.
[0072] 2.5.1 Step S500, Identify Native Capability Requirements:
[0073] The execution timing is: when an external link or a third-party application needs to invoke the native capabilities of the mobile system.
[0074] The operation content is as follows: The APP container analyzes the requests of the external link or the third-party application, identifies the native capabilities that need to be invoked, including the camera, microphone, and / or location information, etc. Determine the native capabilities that need to be invoked for subsequent unified invocation and forwarding.
[0075] 2.5.2 Step S501, Invoke Native Capabilities According to the Integration Rules:
[0076] The execution timing is: after identifying the native capability requirements.
[0077] The operation content is as follows: The APP container invokes the corresponding native capabilities of the mobile system according to the preset integration rules; including how to communicate with the mobile system, transfer parameters, and receive return results. Ensure that the invocation of the native capabilities complies with the design specifications of the APP and the security requirements of the mobile system.
[0078] 2.5.3 Step S502, Forward Native Capabilities to the External Link or Third-Party Application:
[0079] The execution timing is: after the native capabilities are successfully invoked.
[0080] The operation content is as follows: The APP container encapsulates and forwards the successfully invoked native capabilities and their returned results according to the requirements of the external link or the third-party application. This includes data format conversion and / or encryption and decryption operations. Enable the external link or the third-party application to normally use the native capabilities of the mobile system to achieve its intended functions.
[0081] 2.5.4 Step S503, Handle Exceptions and Errors:
[0082] The execution timing is as follows: during the process of native capability invocation and forwarding, if an exception or error occurs.
[0083] The operation content is as follows: The APP container captures exception and error information and performs corresponding processing, including retrying, backing off, and prompting the user. At the same time, exception and error logs are recorded for subsequent analysis and resolution. Ensure the stability and reliability of native capability invocation and forwarding, and improve the user experience.
[0084] (3) Mechanism for solving technical problems:
[0085] 3.1 Construction and integration strategy of the global APP container:
[0086] Automatically register and initialize a global "APP container" when the APP starts. This container serves as the core hub for handling all external link and third-party application access requests.
[0087] Through the centralized management of the container, unified scheduling and processing of access requests are achieved, effectively avoiding problems such as access barriers and impaired user experience. At the same time, the existence of the container also provides a basic platform for subsequent security verification, content preloading, and other functions.
[0088] 3.2 Domain name legality verification and security detection:
[0089] When the user attempts to access an external link or a third-party application, the container first extracts the domain name information and matches it with the domain name whitelist configured in the background to verify the legality of the domain name. For legal domain names, the container preloads the page content or application data locally and starts a security detection program (including semantic detection algorithms and image detection algorithms) for scanning to identify and filter security risks such as sensitive words and illegal images. Through domain name legality verification, illegal access paths are effectively blocked; through content preloading and security detection, it is ensured that the content accessed by the user is safe and harmless, thus enhancing the user experience and security.
[0090] 3.3 User authorization mechanism:
[0091] After the external link or third-party application passes the domain name legality verification, the container pops up an authorization dialog box to ask the user to confirm whether to continue the access. Through the user authorization mechanism, the user's right to know and right to choose are fully respected, allowing the user to independently decide whether to continue the access, thus enhancing the user experience. At the same time, this mechanism also provides the basis for user authorization for subsequent native capability invocation.
[0092] 3.4 Native capability invocation and permission management:
[0093] If the user agrees to the access and the external link or third - party application needs to call the native capabilities of the mobile system (such as taking pictures, positioning, recording, etc.), the container will uniformly call these native capabilities according to the integration strategy and ensure the legality and security of the call through appropriate permission management strategies. Through the centralized call and permission management of the container, effective control of the native - capability call is achieved, avoiding the problem of impaired user experience caused by call failures. At the same time, strict permission management strategies also ensure the legality and security of the call, meeting relevant compliance requirements.
[0094] In a second aspect, a mobile - terminal containerized system includes:
[0095] A processor and a memory connected to the processor. Program instructions are stored in the memory. When the program instructions are executed by the processor, the processor executes the mobile - terminal containerization method as described above. The processor is connected to:
[0096] (1) A request receiving and redirection module responsible for capturing requests sent by the user when clicking an external link or attempting to access a third - party application within the APP and redirecting these requests to the global APP container: It closely cooperates with the global APP container to ensure that all external requests are correctly processed and responded to.
[0097] (2) A domain - name legality verification module that extracts the domain - name information of the external link or third - party application and matches it with the domain - name whitelist configured in the background to verify the legality of the domain name: It is connected to the request receiving and redirection module to receive the redirected request; it is connected to the subsequent content pre - loading module and decides whether to perform content pre - loading according to the verification result.
[0098] (3) For requests that pass the legality verification, a content pre - loading and security detection module that pre - loads the page content of the external link or relevant data of the third - party application to the local and scans the pre - loaded content: It is connected to the domain - name legality verification module to receive the requests that pass the verification; it is connected to the user authorization request module and decides whether to send an authorization request to the user according to the security detection result.
[0099] (4) A user authorization request module that sends a request instruction to the user to confirm whether to continue the access and decides subsequent operations according to the user's response: It is connected to the content pre - loading and security detection module to receive the security detection result; it is connected to the native - capability call module and decides whether to perform a native - capability call according to the user authorization result.
[0100] (5) A native - capability call module that uniformly calls the native capabilities of the mobile terminal according to the integration rules and forwards them to the external link or third - party application: It is connected to the user authorization request module to receive the user authorization result; it is connected to the hardware - system interface and calls the hardware function through the API provided by the operating system.
[0101] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0102] I. Improve user experience: Through the centralized management of the global APP container, the present invention avoids access obstacles encountered by users when accessing external links or third-party applications, such as slow page loading and failed jumps, thereby improving the user experience. The user authorization mechanism allows users to independently decide whether to continue accessing, enhancing the user's sense of participation and control, and further improving the user experience.
[0103] II. Enhance security: The domain name legality verification, content preloading, and security detection mechanism of the present invention effectively block illegal access paths, ensure the safety and harmlessness of the content accessed by users, and reduce the risk of users being attacked maliciously or being infringed by bad information. The strict permission management strategy ensures the legality and security of native capability calls, avoiding security issues caused by call failures or abuse.
[0104] III. Improve the success rate of native capability calls: Through the unified call and permission management of the global APP container, the present invention realizes effective control of native capability calls, avoiding call failure problems caused by interface mismatches, insufficient permissions, etc. BRIEF DESCRIPTION OF THE DRAWINGS
[0105] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0106] Figure 1 It is a schematic flowchart of the method of the present invention;
[0107] Figure 2 It is a schematic diagram of the APP container of the present invention;
[0108] Figure 3 It is a schematic diagram of the system composition of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0109] In order to make the above objects, features, and advantages of the present invention more obvious and understandable, the following will provide a detailed description of the specific embodiments of the present invention with reference to the drawings. Many specific details are set forth in the following description to facilitate a full understanding of the present invention. However, the present invention can be implemented in many other ways different from those described herein. Those skilled in the art can make similar improvements without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below;
[0110] It should be noted that the various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments, and the same or similar parts among the embodiments can be referred to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the description of the method part.
[0111] Explanation of related terms:
[0112] (1) (Global) APP Container: A component that is automatically registered and initialized when the APP starts, used to manage and process user access requests to external links and third-party applications.
[0113] (2) External Link: A hyperlink within the APP that points to an external website or resource. When the user clicks on it, they will be redirected to these external pages.
[0114] (3) Third-Party Application: An independent application or service that is not provided by the APP itself but can be accessed or used through the APP.
[0115] (4) Access Domain Name Whitelist Request: A security mechanism that performs a legality check on access requests to external links or third-party applications by including legitimate domain names in the whitelist.
[0116] (5) Security Detection Program (Semantic Detection Algorithm and Image Detection Algorithm): Used to scan and analyze the preloaded content to identify and filter out security risks such as sensitive words and illegal images.
[0117] (6) Native Capability: The underlying functions provided by the mobile phone system, such as taking pictures, positioning, and recording, which can be integrated through the APP container and forwarded for use by external links or third-party applications.
[0118] Embodiment 1: As Figures 1-2 shown, this embodiment will provide a mobile containerization technology aimed at performing security monitoring on online car-hailing APPs in the market to ensure the access security of external links and third-party applications while providing a smooth user experience. The solution includes the following steps S1 to S5.
[0119] In this embodiment, regarding step S1: Container Registration: When the user first opens the online car-hailing APP, the APP automatically executes the registration process of the global APP container. During the registration process, the APP container is initialized to prepare for receiving and processing access requests to external links and third-party applications. The successful registration of the global APP container lays the foundation for subsequent processing of external link and third-party application requests.
[0120] Step S100: Container initialization: After registration is completed, the APP container loads the configuration file, initializes the data structure, and prepares the interface with the external system. The global APP container is in a ready state and can efficiently process various access requests.
[0121] Step S101: Request redirection: When a user clicks an external link (such as a restaurant promotion link) in the APP, the request is redirected to the global APP container, ensuring that all external links and access requests from third-party applications are uniformly processed through the global APP container.
[0122] In this embodiment, regarding step S2: domain name legitimacy verification: the APP container parses the URL from the link clicked by the user and extracts the domain name information. The APP container matches the extracted domain name information with the domain name whitelist configured in the background. Ensure that the external links or third-party applications accessed by the user belong to the known and trusted domain name list to prevent access to malicious links.
[0123] In this embodiment, regarding step S3: preloading and detection: starting the security detection program APP container preloads the page content of the external link, and starts the built-in security detection program to scan the preloaded content.
[0124] The security detection program monitors security risks such as sensitive words and illegal images, ensuring that the content accessed by users is safe and preventing the spread of malicious content.
[0125] In this embodiment, regarding step S4: user authorization request: when a user attempts to access a risky external link or third-party application (for example, the domain name legitimacy check fails in step S2, or security risks are discovered during preloading and detection in step S3), the online car-hailing APP will enter the user authorization request stage to ensure that the user makes an informed decision.
[0126] Step S400: Send user authorization request: The APP container sends a clear request instruction to the user, asking the user whether he is willing to continue to access the external link or third-party application. This request is usually presented in the form of a pop-up window, dialog box or full-screen notification, containing necessary warning information and risk reminders for continued access. The user can clearly understand the risks of the current access and make a decision on whether to continue access based on his personal wishes.
[0127] Step S401: Processing user response: If the user agrees to continue access, the APP container will record the user's choice and call and forward the native capabilities according to the subsequent steps (such as step S5). If the user refuses to continue access, the APP container will immediately terminate the access to the current external link or third-party application and display the corresponding prompt information to the user, indicating that the access has been blocked.
[0128] That is, respect the user's right to know and right to choose, ensure that the user makes a decision after fully understanding the risks. At the same time, prevent the user from accessing potentially dangerous content without knowledge, and protect the user's safety and privacy.
[0129] Step S402 (optional, determined according to business requirements): Disable the native capabilities of the APP: In some cases, if the user refuses to continue accessing and certain native capabilities of the APP need to be disabled according to the business logic, the APP container will disable these capabilities according to the preset logic. That is, further enhance the security protection measures to prevent the user from bypassing security restrictions through other functions of the APP after refusing to access. Improve the user's sense of security and trust.
[0130] In this embodiment, regarding step S5: Native capability invocation and forwarding: The user clicks on a restaurant link through the online car-hailing APP and hopes to use the positioning function of the APP to share the current location with the restaurant to obtain discounts.
[0131] Step S500: Identify the native capability requirements: The APP container analyzes the request of the restaurant link and identifies that the positioning information of the mobile phone needs to be invoked.
[0132] Step S501: Invoke the native capability according to the integration rules: The APP container invokes the positioning function of the mobile phone according to the preset integration rules.
[0133] Step S502: Forward the native capability to the external link or third-party application: The APP container encapsulates the successfully invoked positioning information and forwards it to the restaurant link.
[0134] It can be understood that through the integration strategy, the APP container can uniformly invoke and forward the native capabilities of the mobile phone system to ensure that the external link or third-party application can use these functions normally. During the invocation process, the APP container performs parameter passing and result reception according to the integration rules to ensure the stability and reliability of the invocation. By appropriately adjusting the invocation interface or permission management, avoid failure of native function invocation, and at the same time meet the requirements of security and compliance.
[0135] Embodiment 2: This embodiment further provides a python execution program of the mobile containerization technology as described in Embodiment 1:
[0136]
[0137]
[0138]
[0139]
[0140]
[0141] In the above program, it includes:
[0142] The AppContainer class: Represents the global APP container, responsible for handling access requests for external links and third-party applications.
[0143] The __init__ method: Performs container initialization operations, including loading the domain name whitelist and other necessary settings.
[0144] The redirect_request method: The request redirection process, redirects the request sent by the user to the APP container for processing.
[0145] The process_request method: Performs steps such as domain name legality verification, content preloading and security detection, user authorization request, and native capability invocation and forwarding according to the URL.
[0146] Other auxiliary methods: extract_domain, is_domain_whitelisted, preload_content, detect_security_risks, request_user_authorization, invoke_native_capabilities, and disable_native_capabilities, respectively implement the specific operations of each step.
[0147] In the above program, the execution process is as follows:
[0148] Initialize an AppContainer instance and pass in the domain name whitelist.
[0149] The user clicks on an external link, and the redirect_request method is called.
[0150] According to the domain name and content of the URL, each step is executed in sequence, and the corresponding processing results are output.
[0151] All of the above embodiments only express the implementation manners of the relevant actual applications of the present invention. Their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several deformations and improvements can still be made, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the present invention patent shall be subject to the appended claims.
[0152] For those skilled in the art, it can be further realized that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Skilled professionals can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of the present invention.
[0153] At the same time, those skilled in the art can understand that all or part of the processes of implementing the methods of all the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium provided in the present application and used in the embodiments can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (SSRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
Claims
1. A method for containerizing a mobile terminal, characterized in that: Based on the activation instructions given by the user when launching the APP, the following steps are executed: S1, based on the request sent by the user when clicking an external link in the APP or trying to access a third-party application, is redirected to the global APP container and starts executing S2; S2, the APP container extracts the domain name information of external links or third-party applications and verifies the legitimacy of the domain name; If the legality is passed, execute step S3; If the legality fails, proceed to step S4; S3: The APP container preloads the page content of external links or related data of third-party applications to the local computer and scans the preloaded content. If no security risk is found, go to S5; If a security risk is found, enter S4; S4, the APP container sends a request instruction to the user to confirm whether to continue access; if approved, proceed to S5; if rejected, terminate the access to the current external link or third-party application; S5: If the external link or third-party application needs to use the native capabilities of the mobile phone system, the APP container will call the native capabilities uniformly according to the integration rules and forward them to the external link or third-party application.
2. The containerization method according to claim 1, characterized in that: The implementation method of S1 includes: S100, initializing the global APP container, including loading configuration files, initializing data structures, and preparing interfaces with external systems; S101, redirecting the request sent by the user to the global APP container through the redirection mechanism.
3. The containerization method according to claim 2, characterized in that: The redirection mechanism includes HTTP redirection, server-side redirection, client-side redirection and / or cloud service redirection.
4. The containerization method according to claim 1, characterized in that: The implementation method of S2 includes: S200, the APP container parses the URL from the request and extracts the domain name information of the external link or third-party application; S201, the APP container matches the extracted domain name information with the domain name whitelist configured in the background through string comparison or regular expression to verify whether the domain name is within the allowed range; S202, judging the legitimacy of the domain name according to the matching result; if the domain name is in the whitelist, the domain name is considered to be legal; otherwise, the domain name is considered to be illegal.
5. The containerization method according to claim 1, characterized in that: The implementation method of S3 includes: S300: The APP container starts the built-in security detection program to perform a comprehensive scan of the preloaded content; S301, judging whether there is a security risk in the preloaded content according to the scanning result of the security detection program; if no security risk is found, the content is considered safe; if a security risk is found, the content is considered unsafe.
6. The containerization method according to claim 5, characterized in that: The security detection program includes a semantic detection algorithm and a picture detection algorithm.
7. The containerization method according to claim 1, 2, 4 or 5, characterized in that: The implementation method of S4 includes: S400, the APP container sends a clear request instruction to the user, asking the user whether he is willing to continue accessing the external link or third-party application; S401, if the user agrees to continue accessing, S5 is executed; otherwise, the APP container terminates access to the current external link or third-party application and enters S402; S402, the APP container disables the APP native capabilities related to the current access, including network requests and file access, according to preset logic.
8. The containerization method according to claim 7, characterized in that: The implementation method of S5 includes: S500, the APP container analyzes the external link or the request of the third-party application, and identifies the native capabilities that need to be called, including the camera, the microphone and / or the location information; S501, the APP container calls the corresponding native capabilities of the mobile phone system according to the preset integration rules, including how to communicate with the mobile phone system, pass parameters and receive return results; S502, the APP container will encapsulate and forward the successfully called native capabilities and the results returned according to the requirements of the external link or third-party application; including data format conversion and / or encryption and decryption operations; so that the external link or third-party application can normally use the native capabilities of the mobile phone system.
9. A system for implementing the containerization method according to any one of claims 1 to 8, characterized in that: The system comprises: Responsible for capturing requests sent by users when they click external links in the app or try to access third-party applications, and redirecting these requests to the request receiving and redirecting module of the global app container; A domain name legitimacy verification module that extracts domain name information of external links or third-party applications and matches it with the domain name whitelist configured in the background to verify the legitimacy of the domain name; For requests that pass the legality check, the content preloading and security detection module preloads the page content of the external link or the relevant data of the third-party application to the local computer and scans the preloaded content; A user authorization request module that sends a request instruction to the user to confirm whether to continue access and determines subsequent operations based on the user's response.
10. The system according to claim 9, characterized in that: It also includes a native capability calling module that uniformly calls the native capabilities of the mobile terminal according to the integration rules and forwards them to external links or third-party applications.
Citation Information
Patent Citations
Mobile terminal page automatic assembly method and device
CN115686516A
Software as service (SAAS) application resource management system based on containerization
CN116643839A
Containerization method of mobile terminal component and APP container architecture
CN117032907A