Method and device for realizing trusted installation on open source operating system based on certificate management mechanism in offline environment
By adopting the certificate management mechanism in the open source operating system, the signature and digest information files are generated for local verification, the trusted installation problem of applications in offline environments is solved, and secure installation and diversified compatibility is achieved without network connection.
Patent Information
- Application Number
- CN202510929239.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-07
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2045-07-07
AI Technical Summary
In open source operating systems, the existing technology cannot realize trusted installation of applications in offline environments, and there are problems such as the proliferation of pirated software, threat of shelling software, dependence on centralized servers and networks, complex processes, and ecological closure.
The certificate management mechanism in an offline environment is adopted, and signature and summary information files are generated through development tools, and local verification is carried out in combination with operating system installation services to ensure the credibility of the application installation package.
It realizes trusted installation without server support in offline environments, reduces deployment costs, is compatible with diverse development tools, prevents tampering and repeated installation risks, and supports multiple open source package formats.
Smart Images

Figure CN120408598A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of application software development, and particularly to a method and device for realizing trusted installation on an open-source operating system based on a certificate management mechanism in an offline environment. Background Art
[0002] In open-source operating systems, the installation of application programs usually lacks strict security checks and normative requirements, resulting in the prevalence of pirated software and shelled software, which seriously threatens the data security and system stability of users. Currently, some solutions rely on a centralized application market server, and all software needs to be uploaded to the server and can only be released in the application market after passing the review. Although this method can, to a certain extent, curb the problems of pirated and shelled software, it has the following significant defects: Dependence on a centralized server: It is necessary to build and maintain server resources, increasing the implementation cost and management burden.
[0003] Forced online environment: Users must be in an online state to download and install software, unable to meet the requirements of the offline scenario.
[0004] Single channel: The release of software completely depends on the application market, restricting the freedom of choice for developers and users.
[0005] Another solution realizes double review of developer identities and application software through the collaborative work of a signature server, a developer server, and an application mall server, thereby improving the security of software distribution. Specifically, developers need to register and obtain a signature certificate through the developer server, and then submit their identity information and software packages for review. After passing the review, the software can be released to the application mall for users to download. Although this method can effectively curb the spread of insecure software, it has the following significant defects: Dependence on a centralized server and an online environment: The entire process must rely on the online collaboration of the developer server, the signature server, and the application mall, and cannot run in an offline environment, increasing the deployment and operation and maintenance costs.
[0006] Complex process: Developers need to go through multiple registration, signature, and review steps, and users must obtain software through the application mall, lacking flexibility.
[0007] Ecological closure: Similar to the closed-source ecosystem of iOS, this solution requires developers to use specific tools and certificate systems, making it difficult to adapt to the diverse development environments of open-source operating systems.
[0008] Therefore, there is an urgent need for a method that can achieve the trusted installation of open-source operating system applications in an offline environment, which can not only avoid dependence on servers and networks, but also ensure the authenticity of software sources and content through a multi-dimensional certificate management mechanism, while being compatible with diverse development tools and installation scenarios. Summary of the Invention
[0009] To solve the above technical problems, the present invention proposes a method and device for achieving trusted installation on an open-source operating system based on a certificate management mechanism in an offline environment.
[0010] The first aspect of the present invention discloses a method for achieving trusted installation on an open-source operating system based on a certificate management mechanism in an offline environment; the method includes: Step S1, compile and output an application installation package APP_pack file through a development tool; Step S2, generate a signature information file through a single-machine signature tool; the signature information file includes: enterprise legal person information, software copyright information, developer information, and identification information of the application installation package APP_pack file; Step S3, generate a digest information file through a single-machine digest tool; Step S4, combine the signature information file and the digest information file through a development tool to generate a certificate file, and recompile the application installation package APP_pack file according to the certificate file to output an application installation package APP_pack_new file; Step S5, perform verification and installation on the application installation package APP_pack_new file through the operating system installation service according to the certificate file.
[0011] According to the method of the first aspect of the present invention, the development tool, the single-machine signature tool, and the single-machine digest tool operate independently on the developer's terminal without the need for network or server support.
[0012] According to the method of the first aspect of the present invention, the operating system installation service runs on the user's terminal to achieve trusted installation in an offline environment through local verification.
[0013] According to the method of the first aspect of the present invention, in step S3, the digest information file includes: software name, identification information, function brief introduction, title, content, business type, constituent elements, and expiration time.
[0014] According to the method of the first aspect of the present invention, in step S5, performing verification and installation on the application installation package APP_pack_new file through the operating system installation service according to the certificate file specifically includes: The operating system installation service checks whether the application installation package APP_pack_new file contains the signature information file and the digest information file; If so, query whether there is a record in the installation record table stored in the local database that is the same as the digest information file in the application installation package APP_pack_new file; If there is, check whether the content of the signature information file in the application installation package APP_pack_new file is standard; If it is determined that the content of the signature information file in the application installation package APP_pack_new file is standard, directly overwrite and install without updating the installation record table.
[0015] According to the method of the first aspect of the present invention, if there is no record in the installation record table that is the same as the digest information file in the application installation package APP_pack_new file, query whether there is a record in the installation record table that is similar to the digest information file in the application installation package APP_pack_new file; wherein, if the content of any record in the installation record table is partially the same as the content of the digest information file in the application installation package APP_pack_new file, it is determined that there is a record in the installation record table that is similar to the digest information file in the application installation package APP_pack_new file; If it is determined that there is a record in the installation record table that is similar to the digest information file in the application installation package APP_pack_new file, prompt that there is a risk software.
[0016] According to the method of the first aspect of the present invention, if it is determined that there is no record in the installation record table that is similar to the digest information file in the application installation package APP_pack_new file, check whether the content of the signature information file in the application installation package APP_pack_new file is standard; If it is determined that the content of the signature information file in the application installation package APP_pack_new file is standard, directly install, and insert a record in the installation record table after successful installation.
[0017] The second aspect of the present invention discloses a device for realizing trusted installation on an open-source operating system based on a certificate management mechanism in an offline environment. The device includes: A development tool, configured to compile and output an application installation package APP_pack file, combine a signature information file and a digest information file to generate a certificate file, and recompile the application installation package APP_pack file according to the certificate file to output an application installation package APP_pack_new file; A single-machine signature tool, configured to generate a signature information file; the signature information file includes: enterprise legal person information, software copyright information, developer information, and identification information of the application installation package APP_pack file; A single-machine digest tool, configured to generate a digest information file; An operating system installation service, configured to verify and install the application installation package APP_pack_new file according to a certificate file.
[0018] The third aspect of the present invention discloses an electronic device. The electronic device includes a memory and a processor. The memory stores a computer program. When the processor executes the computer program, the steps in a method for realizing trusted installation on an open-source operating system based on a certificate management mechanism in any one of the first aspects of the present disclosure are realized.
[0019] The fourth aspect of the present invention discloses a computer-readable storage medium. A computer program is stored on the computer-readable storage medium. When the computer program is executed by a processor, the steps in a method for realizing trusted installation on an open-source operating system based on a certificate management mechanism in any one of the first aspects of the present disclosure are realized.
[0020] In summary, the solution proposed by the present invention has the following technical effects: Offline available: No need for a server or network connection, ensuring security through local certificate verification; Lightweight: Both the developer tool and the installation service run on a single machine, reducing deployment costs; Multi-dimensional verification: Combining triple verification of signature, summary, and installation record table to prevent risks of tampering and repeated installation. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for use in the description of the specific embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0022] Figure 1 It is a flowchart of a method for realizing trusted installation on an open-source operating system based on a certificate management mechanism in an offline environment according to an embodiment of the present invention; Figure 2 It is a structural diagram of a device for realizing trusted installation on an open-source operating system based on a certificate management mechanism in an offline environment according to an embodiment of the present invention; Figure 3 It is a structural diagram of an electronic device according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0023] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are only a part rather than all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0024] According to an embodiment of the present invention, in a first aspect, a method for implementing trusted installation on an open-source operating system based on a certificate management mechanism in an offline environment is provided; please refer to Figure 1 , the method includes: Step S1, compiling and outputting an application installation package APP_pack file through a development tool; Step S2, generating a signature information file through a single-machine signature tool; the signature information file includes: corporate legal person information, software copyright information, developer information, and identification information of the application installation package APP_pack file; Step S3, generating a digest information file through a single-machine digest tool; According to the method of the first aspect of the present invention, in the step S3, the digest information file includes: software name, identification information, function brief introduction, title, content, business type, constituent elements, and expiration time.
[0025] Step S4, combining the signature information file and the digest information file through a development tool to generate a certificate file, and recompiling the application installation package APP_pack file according to the certificate file to output an application installation package APP_pack_new file; Step S5, verifying and installing the application installation package APP_pack_new file through an operating system installation service according to the certificate file.
[0026] According to the method of the first aspect of the present invention, in the step S5, verifying and installing the application installation package APP_pack_new file through an operating system installation service according to the certificate file specifically includes: The operating system installation service checks whether the application installation package APP_pack_new file contains a signature information file and a digest information file; If so, it queries whether there is a record in the installation record table stored in the local database that is the same as the digest information file in the application installation package APP_pack_new file; If there is, it checks whether the content of the signature information file in the application installation package APP_pack_new file is standardized; If it is determined that the content of the signature information file in the application installation package APP_pack_new file is in compliance, it is directly overwritten and installed without updating the installation record table.
[0027] According to the method of the first aspect of the present invention, if there is no record in the installation record table that is the same as the digest information file in the application installation package APP_pack_new file, then it is checked whether there is a record in the installation record table that is similar to the digest information file in the application installation package APP_pack_new file; wherein, if the content of any record in the installation record table is partially the same as the content of the digest information file in the application installation package APP_pack_new file, it is determined that there is a record in the installation record table that is similar to the digest information file in the application installation package APP_pack_new file; If it is determined that there is a record in the installation record table that is similar to the digest information file in the application installation package APP_pack_new file, a risk software is prompted.
[0028] According to the method of the first aspect of the present invention, if it is determined that there is no record in the installation record table that is similar to the digest information file in the application installation package APP_pack_new file, then it is checked whether the content of the signature information file in the application installation package APP_pack_new file is in compliance; If it is determined that the content of the signature information file in the application installation package APP_pack_new file is in compliance, it is directly installed, and a record is inserted into the installation record table after successful installation.
[0029] According to the method of the first aspect of the present invention, the development tool, the stand-alone signature tool, and the stand-alone digest tool run independently on the developer's terminal without the need for network connection or server support.
[0030] According to the method of the first aspect of the present invention, the operating system installation service runs on the user's terminal and realizes trusted installation in an offline environment through local verification.
[0031] Embodiment 1: Developer-side certificate generation and software packaging Step 1: Generate an application installation package (APP_pack) The developer compiles the source code using conventional development tools (such as GCC, CMake, etc.) to generate a standard application installation package file (such as.deb,.rpm, or binary executable file), denoted as APP_pack.
[0032] Step 2: Generate a signature information file (sign) The developer runs the stand-alone signature tool (an independent program that does not require network connection) and inputs the following information: Enterprise legal person information (such as unified social credit code) Software copyright information (such as registration number) Developer identity identifier (such as digital certificate or PGP public key) Application unique identifier (such as package name, version number) The signature tool uses an asymmetric encryption algorithm (such as RSA or ECC) to generate a digital signature and outputs a sign file. This file ensures that the software source is trustworthy and has not been tampered with.
[0033] Step 3: Generate summary information file (summary) The developer runs a stand-alone summary tool (also runs independently) and inputs the following metadata: Software name, version number Function overview, dependencies Business type (such as finance, healthcare, etc.) Valid time (such as expiration date) The summary tool uses a hashing algorithm (such as SHA-256) to generate a summary file for content verification during subsequent installation.
[0034] Step 4: Combine certificate files (cert) and generate the final installation package The developer uses an application development tool to package the sign and summary files into a certificate file cert and recompiles it with the original APP_pack to generate the final secure installation package APP_pack_new.
[0035] Example 2: User-side installation verification (no conflict scenario) Step 1: Installation package parsing The user runs an installation command (such as sudo dpkg -i APP_pack_new). The operating system installation service first checks whether APP_pack_new contains sign and summary files. If either file is missing, the installation is terminated directly and an error message is reported: "The certificate is incomplete and the installation is rejected."
[0036] Step 2: Signature verification If it is found that both sign and summary exist during file parsing, the initial verification passes, and the following verification steps are performed: Query the installed_tab installation record table in the local database to check if there is a record identical to summary. If so, the installation service uses a preset public key (such as a system-built CA certificate) to verify the legality of the sign file: If the check passes, the installation is directly overwritten without updating the installed_tab table; If the check fails, prompt the user that the information of the new installation package APP_pack_new is incomplete. The prompt message can be: "The software signature verification fails, and there may be risks."
[0037] When parsing the sign file during the installation service, if one of the following problems is found, it is determined that the content of the sign file is not standardized: The developer certificate has been revoked The software copyright information does not match the abstract The expiration date has passed Handling method: Terminate the installation and record the security log; Prompt the user: "The software certificate is invalid. Please contact the developer to obtain an updated version."
[0038] Embodiment 3: Installation verification on the user side (conflict scenario) Scenario: Similar software (summary') is detected The installation service discovers a record in installed_tab that is similar but not exactly the same as summary (such as different business types but the same otherwise), indicating that there may be a conflict. At this time: Pop up a prompt to the user: "Similar software [Software A] has been detected as installed. Do you want to uninstall it and then install the new version [Software A']?" User selection: Keep the old version: Terminate the installation.
[0039] Uninstall and then install: Uninstall the old version, continue to install APP_pack_new, and update the record in installed_tab.
[0040] If there is no summary’, start checking the content standardization of the sign file. If the check passes, directly install and insert a record summary into the installation record table installed_tab after successful installation; The second aspect of the present invention discloses a device for realizing trusted installation on an open-source operating system based on a certificate management mechanism in an offline environment. Please refer to Figure 2 , the device includes: A development tool, configured to compile and output an application installation package APP_pack file, combine a signature information file and an abstract information file to generate a certificate file, and recompile the application installation package APP_pack file according to the certificate file to output an application installation package APP_pack_new file; A single-machine signature tool, configured to generate a signature information file; the signature information file includes: corporate legal person information, software copyright information, developer information, and identification information of the application installation package APP_pack file; A single - machine summary tool, configured to generate a summary information file; An operating system installation service, configured to verify and install the application installation package APP_pack_new file according to a certificate file.
[0041] In a third aspect of the present invention, an electronic device is disclosed. The electronic device includes a memory and a processor. The memory stores a computer program. When the processor executes the computer program, the steps in a method for realizing trusted installation on an open - source operating system based on a certificate management mechanism in an offline environment in any one of the first aspects of the present disclosure are implemented.
[0042] Figure 3 The structure diagram of an electronic device according to an embodiment of the present invention is as follows. As Figure 3 shown, the electronic device includes a processor, a memory, a communication interface, a display screen, and an input device connected through a system bus. Among them, the processor of the electronic device is used to provide computing and control capabilities. The memory of the electronic device includes a non - volatile storage medium and an internal memory. The non - volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non - volatile storage medium. The communication interface of the electronic device is used to communicate with an external terminal in a wired or wireless manner. The wireless manner can be implemented through WIFI, a carrier network, near - field communication (NFC), or other technologies. The display screen of the electronic device can be a liquid crystal display screen or an electronic ink display screen. The input device of the electronic device can be a touch layer covered on the display screen, or a button, a trackball, or a touchpad provided on the housing of the electronic device, or an external keyboard, a touchpad, or a mouse, etc.
[0043] Those skilled in the art can understand that Figure 3 the structure shown in is only a structure diagram of a part related to the technical solution of the present disclosure, and does not constitute a limitation on the electronic device to which the solution of the present application is applied. A specific electronic device may include more or fewer components than those shown in the figure, or combine some components, or have a different component layout.
[0044] In a fourth aspect of the present invention, a computer - readable storage medium is disclosed. A computer program is stored on the computer - readable storage medium. When the computer program is executed by a processor, the steps in a method for realizing trusted installation on an open - source operating system based on a certificate management mechanism in an offline environment in any one of the first aspects of the present disclosure are implemented.
[0045] In summary, the technical solution proposed by the present invention has the following technical effects: Offline availability: All tools (signing, summarizing, installation service) run independently on a single machine, without the need for a server or network connection, and ensure security through local certificate verification; Lightweight: Both the developer tools and the installation service run on a single machine, reducing deployment costs; Multi-dimensional verification: Combining signature (sign), summary, and the installation record table for triple verification to prevent risks of tampering and repeated installation; Compatibility: Supports multiple open-source package formats (such as DEB, RPM) and is adapted to different Linux distributions.
[0046] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that the technical solutions described in the foregoing embodiments can still be modified, or some or all of the technical features can be equivalently replaced, and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for realizing trusted installation on an open-source operating system based on a certificate management mechanism in an offline environment, characterized in that The method includes: Step S1: Compile and output the application installation package APP_pack file through a development tool; Step S2: Generate a signature information file through a stand-alone signature tool; the signature information file includes: enterprise legal person information, software copyright information, developer information, and identification information of the application installation package APP_pack file; Step S3: Generate a digest information file through a stand-alone digest tool; Step S4: Combine the signature information file and the digest information file through a development tool to generate a certificate file, and recompile the application installation package APP_pack file according to the certificate file to output the application installation package APP_pack_new file; Step S5: Check and install the application installation package APP_pack_new file through the operating system installation service according to the certificate file.
2. The method for realizing trusted installation on an open-source operating system based on a certificate management mechanism in an offline environment according to claim 1, characterized in that The development tool, the stand-alone signature tool, and the stand-alone digest tool run independently on the developer's terminal without the need for network or server support.
3. A method for implementing a trusted installation on an open-source operating system based on a certificate management mechanism in an offline environment, characterized in that, The operating system installation service runs on the user's terminal and realizes trusted installation in an offline environment through local verification.
4. The method for realizing trusted installation on an open-source operating system based on a certificate management mechanism in an offline environment according to claim 1, wherein In the said Step S3, the digest information file includes: software name, identification information, function brief introduction, title, content, business type, constituent elements, and valid time.
5. A method for implementing a trusted installation on an open-source operating system based on a certificate management mechanism in an offline environment, characterized in that, In Step S5, checking and installing the application installation package APP_pack_new file through the operating system installation service according to the certificate file specifically includes: The operating system installation service checks whether the application installation package APP_pack_new file contains the signature information file and the digest information file; If so, query whether there is a record in the installation record table stored in the local database that is the same as the digest information file in the application installation package APP_pack_new file; If it exists, check whether the content of the signature information file in the application installation package APP_pack_new file is standard; If it is determined that the content of the signature information file in the application installation package APP_pack_new file is standard, directly overwrite and install without updating the installation record table.
6. A method for implementing a trusted installation on an open-source operating system based on a certificate management mechanism in an offline environment, characterized in that, If there is no record in the installation record table that is the same as the digest information file in the application installation package APP_pack_new file, query whether there is a record in the installation record table that is similar to the digest information file in the application installation package APP_pack_new file; wherein, if the content of any record in the installation record table is partially the same as the content of the digest information file in the application installation package APP_pack_new file, it is determined that there is a record in the installation record table that is similar to the digest information file in the application installation package APP_pack_new file; If it is determined that there is a record in the installation record table that is similar to the digest information file in the application installation package APP_pack_new file, prompt that there is a risk software.
7. A method for implementing trusted installation on an open-source operating system based on a certificate management mechanism in an offline environment, characterized in that, [[ID=~16]]If it is determined that there is no record in the installation record table that is similar to the digest information file in the application installation package APP_pack_new file, check whether the content of the signature information file in the application installation package APP_pack_new file is standard; If it is determined that the content of the signature information file in the application installation package APP_pack_new file is compliant, it is directly installed, and a record is inserted into the installation record table after successful installation.
8. A device for realizing trusted installation on an open-source operating system based on a certificate management mechanism in an offline environment, characterized in that, The device includes: A development tool configured to compile and output an application installation package APP_pack file, combine a signature information file and a digest information file to generate a certificate file, and recompile the application installation package APP_pack file according to the certificate file to output an application installation package APP_pack_new file; A single-machine signature tool configured to generate a signature information file; the signature information file includes: corporate legal person information, software copyright information, developer information, and identification information of the application installation package APP_pack file; A single-machine digest tool configured to generate a digest information file; An operating system installation service configured to perform verification and installation on the application installation package APP_pack_new file according to the certificate file.
9. An electronic device, characterized in that, The electronic device includes a memory and a processor. When the processor executes the computer program stored in the memory, it implements the steps in the method for realizing trusted installation on an open-source operating system based on a certificate management mechanism in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium. When the computer program is executed by a processor, it implements the steps in the method for realizing trusted installation on an open-source operating system based on a certificate management mechanism in any one of claims 1 to 7.
Citation Information
Patent Citations
Security data processing method and device, and electronic equipment
CN107301343A
Android application installation package signing and signature verification methods
CN107463806A
Method and system for checking APK signatures of POS (Point of Sale) machines
CN107769924A
Application installation method, computing device and storage medium
CN115185547A
Software package management method and device, equipment and storage medium
CN119829114A